About this report This report is presentedin the following sections: This report offers a comprehensive perspective on the currentthreat landscape and banking fraud trends in the U.S. •Current threat landscapein the U.S.•Behavioral deep dive•Foreign fraud: Where isAmerica’s money going?•The biggest banksaren’talways the biggest targets•Account takeover: Agrowing threat•Case study: Remoteaccess-enabledcross-platform ATO To create this report, BioCatch’s team of experts – led byits global fraud intelligence team and supported by its localadvisory and threat analytics teams – conducted extensiveresearch, compiling proprietary BioCatch data from292financialinstitutionsin theU.S.serving a combined morethan 280 million users. The fraud landscape in the U.S.continues to evolve, withcriminals increasingly relying on impersonation, socialengineering,and credential compromise.Checkfraudand account takeover attacks are continual threats acrossfinancial institutions. Artificial intelligence is accelerating this evolution, enablingmore sophisticated scams that leverage deepfakes,synthetic identities and psychological manipulation oflegitimate account holders. Current threat landscape in the U.S. 78%of U.S. banking leaders report increasingfraud attempts at their institution increase in attempted impersonationscams 2.3x increase in attempted job scams 44% 1.5xincrease phishing attempts Trends More than three-fourths (78%)of U.S.-based participants in BioCatch’ s global industry survey,The futureof digital trust, report increasing fraud attempts at their organization, while 64% say fraud losses at theirinstitution are also increasing. Job scam attempts increased by 44% among BioCatch’s U.S. customers in the last year. Typically,jobscamvictims receiveand respond tounsolicited communications offering simple online work via socialmedia orinstantmessaging applications. After pretending to hire their victims for a legitimate opportunity,fraudsters will request personal details including social security numbers and photo IDs, which, if shared,can result in identity theft. Impersonation scam lossesin the U.S.more than doubled between 2025 and 2026, with fraudsterscommonly posing as representatives of legitimate organizations and conning victims into sending themmoney under a rangeof false pretenses. BioCatch’s U.S. customers also reported a 50% increase in phishing attempts in the past year. Phishingoften provides the foundation for credential theft, with harvesting links distributed via social media,messaging apps, and email — increasingly at great scale, with AI integration enabling more personalizedmaterials aimed at potential victims. The costliest scam types in the U.S. Investmentscams:$46 million in reported attempted losses Although they represent a smaller share of overall fraud attempts, investment scamshave emerged as the costliest fraud type in the U.S. Fraudsters promise high returnson cryptocurrency, forex, and commodities investments, using spoofed websites andfraudulent broker platforms to create a false sense of legitimacy. Purchase scams:$28 millionin reported attempted losses Online marketplaces have become a hub for counterfeit listings and brandimpersonations, with AI-generated content facilitating increasingly convincing fakestorefronts and deepfakes. Fraudsters typically advertise high-demand goods at priceswell below the market average and employ urgency tactics such as flash sales and low-stock alerts to force impulse purchases from unsuspecting buyers. Law enforcement/legal scams:$22 millionin reported attempted losses Government and law enforcement scams typically transpire via email and/or phone calls,with fraudsters using spoofing technology to appear as representatives of legitimateagencies. To increase perceived legitimacy, fraudsters provide fictitious badge numbersand use official agency letterheads. They threaten to arrestaccount holders if thoseaccount holders don'tthey don’t pay fines, demanding payment through untraceablemethods such as gift cards. Behavioral deep dive Drilling into the data from our American customers a little further, we unearth the following trends: 45%increase in active RAT sessions Session trends •Remote access sessions increasedsignificantlyin the U.S. in the last year, grantingfraudstersunauthorized access to bankingapplications,email services, and othersensitive victiminformation. Once a remoteaccess trojan(RAT)has taken hold, every subsequentauthenticated browser session is thenaccessible to the fraudster, who retains thisaccess even following password changes orenabling of multi-factor authentication. 34%increase in on-call sessions 28% increase in fraud sessions wheremoney was sent to a new payee •Digital banking sessions where the user is onanactive phone call while interacting with thebank’s platform also increased significantlyinthe U.S. in the last year, as fraudsterscontinued to pivot from credential theft to thecoaching of po