Skip to main content

Article

How banks prevent cyber fraud with improved threat intelligence

Preventing cyber fraud with improved threat intelligence.

Published: September 30, 2025 | Updated: October 08, 2026

Dan Pastor profile photo

Dan Pastor

VP, Global Product Lead,

Cyber Consulting,

Mastercard

Article at a glance:

  • Fraud is rarely a one-off event. It’s usually the monetization step in a longer chain of cyberattacks. 
  • At many banks, cybersecurity and fraud prevention remain siloed, which can lead to missed warning signs and slower responses.
  • When cyber and fraud teams share intelligence, they may be better positioned to identify patterns that point to potential fraud and disrupt suspicious activity before it escalates. 
  • Payments-specific threat intelligence and industry-wide sharing of attack patterns are essential to preventing cybercrime.

Setting the stage: Why early fraud signals can’t be ignored

Global bank fraud losses are projected to surge 153% over the next five years, climbing from $23 billion in 2025 to $58.3 billion in 2030. Banks could save millions by acting on early warning signs. Yet in many organizations, siloed fraud teams don’t get the right cyber intelligence in time.

Fraud is rarely a standalone incident. A cybercriminal may steal credit card data during a breach and sell it to another bad actor, who then uses it to commit fraud for financial gain.

That breach may serve as an early fraud signal. But if a bank’s cybersecurity team doesn’t flag it to fraud prevention, the opportunity to act is lost. As a result, fraud teams may not become involved until criminals have cashed out and financial and reputational damage is already done.

Without collaboration and shared intelligence, early warning signals stay siloed. To break this cycle, banks need frameworks that connect cybersecurity and fraud prevention, allowing them to disrupt cybercrime and fraud patterns before they impact the customer.

The cybercrime to fraud pipeline: How cybersecurity incidents act as early fraud indicators

Many cybercriminals operate in sophisticated supply chains where different actors focus on each stage of an attack, from initial breach or exploit to monetization.

In this environment, what may seem like low-level cyber incidents often signal larger fraud to come, including:

  • Phishing and social engineering techniques
  • Credential theft via malware
  • Digital skimming attacks
  • Bot-driven card testing

Phishing and social engineering techniques

Attackers impersonate trusted brands or individuals, or create fake websites to trick victims into sharing sensitive data. Phishing-as-a-Service platforms now use generative AI to craft convincing messages and websites, making scams even more difficult for the average person to detect. Information stolen in phishing attacks is often sold or used to gain account access and make unauthorized transactions.

Credential theft via malware

Malware like infostealers and keyloggers capture login credentials from infected devices. Stolen credentials remain one of the most common tools used by attackers, appearing in 65% of breaches that involve hacking activities. Fraudsters use these credentials for account takeover (ATO) attacks, where they gain control of legitimate accounts to move money or commit financial fraud.

Digital skimming attacks

Cybercriminals inject malicious code into e-commerce checkout pages to harvest card data. Stolen details are then either sold or used to make fraudulent purchases.

Groups known as Magecart specialize in these large-scale skimming attacks. In 2025, threat actors posted more than 142 million stolen card records for sale on dark web marketplaces.

Bot-driven card testing

To verify whether stolen card data is valid, fraudsters run small-dollar test transactions on e-commerce sites using automated scripts. Active cards are then sold or used for larger fraud attempts. Validated data is especially valuable on criminal marketplaces, where full identity bundles known as “fullz” (including Social Security numbers, dates of birth, and addresses) can sell for up to $100.

To run these tests, fraudsters exploit Merchant Identification Numbers (MIDs), the unique IDs tied to merchant accounts that allow businesses to process payments.

While tester MIDs are meant to simulate transactions and confirm systems work before going live, criminals abuse them for card-testing. In 2024, the number of identified tester MIDs increased by 48%, giving fraudsters more opportunities to validate stolen card data.

Why do fraud signals go unnoticed? The disconnect between cybersecurity and fraud teams

Cyber incidents often precede fraud, but many signals never make it to the right people. At many banks and financial institutions, the gap comes from several barriers:

  • Organizational silos: Separate reporting lines mean cyber alerts rarely inform fraud models, and fraud events may not be tied back to their cyber origins.
  • Resource constraints: Larger institutions may have cyber fraud fusion programs, but smaller ones often lack the staff and budget for effective integration and data-sharing.
  • Data gaps: Most financial institutions maintain an external threat intelligence feed that covers broad cyber threats, but may overlook, for example, payments-specific indicators tied to fraud.
  • Limited information sharing: Even with strong cyber and fraud intelligence, a lack of sharing across financial institutions delays detection and weakens the industry’s ability to disrupt attacks early.

From reactive to proactive: The future of collaboration between cybersecurity and fraud teams

Many organizations still investigate cyber incidents and fraud events separately, even though they are often connected. A phishing campaign, malware infection or e-skimming attack may appear to be a cybersecurity issue at first, but these incidents can also signal that stolen data is on its way to being monetized. When teams share intelligence and context, they are better positioned to identify these warning signs early and act before fraud occurs. Creating that shared view of risk requires more than one time collaboration. It requires a structured approach to cyber fraud fusion that helps teams consistently connect signals, share intelligence and coordinate response efforts.

However, cyber fraud fusion is not a one-size-fits-all operating model. Organizations should align their approach to their risk profile, maturity level and available resources. Successful programs bring together people, processes and technology to improve visibility, streamline decision-making and strengthen coordination between cyber and fraud teams. For some institutions, that may begin with simple information-sharing routines and evolve over time into more formalized cyber fraud fusion practices.

Regardless of where an organization starts, cyber and fraud teams need consistent ways to share intelligence and coordinate response efforts. 

There are several steps banks can take to close the gap and move to proactive defense:

  • Build information-sharing routines
  • Leverage payments-focused intelligence
  • Expand intelligence sharing across the financial ecosystem

Cybercrime-as-a-service is driving unprecedented collaboration among fraudsters. Financial institutions need the same level of collaboration between cyber and fraud teams if they want to keep pace. Organizations that continue to operate in silos, risk moving slower than the adversaries targeting them.

John Horn, Director, Cybersecurity Practice Datos Insights

Leverage payments-focused intelligence

Payments-specific threat intelligence helps teams tailor threat analysis and response directly to fraud risks. For example, intelligence can flag e-skimmer infections at merchants before card data is stolen. This intel allows banks to proactively monitor at-risk cards, reducing losses and minimizing disruption for customers.

Build cost-effective information-sharing routines

Banks don’t need massive budgets to benefit from intelligence sharing. Fraud and cyber teams at smaller institutions can adopt basic fusion practices, such as weekly joint reviews to analyze data patterns or ad hoc collaboration around specific cyber events. 

These routines build trust between teams, helping them leverage threat intelligence data proactively and establish effective contingency plans.

Expand intelligence sharing across the financial ecosystem

When institutions keep intelligence to themselves or share it only with a handful of partners, the industry struggles to mount a collective defense. Broader information-sharing helps shut down fraud faster across the ecosystem.

Benefits of integrated cyber and fraud intelligence

Improved collaboration between cyber and fraud teams helps banks prevent cyber fraud more effectively and brings clear benefits, including:

  • Faster fraud detection and response
  • Stronger customer trust and retention
  • Clearer ROI for security and fraud leaders

Faster fraud detection and response

Integrated intelligence reduces mean time to detection, allowing teams to understand threats better and act on them faster, before they escalate into large-scale fraud. By spotting attacks earlier, banks may be able to limit financial losses and minimize the impact on their operations and customers.

Stronger customer trust and retention

Reducing fraud incidents may also help minimize customer churn and support long-term customer relationships. Almost two-thirds of bank customers (62%) say how a bank handles fraud has a greater impact on trust than the fraud incident itself.

Clearer ROI for security and fraud leaders

Security teams often struggle to prove their impact on business performance. By tying their work directly to fraud prevention, they may also demonstrate measurable outcomes such as lower churn, preserved customer lifetime value, and reduced financial losses.

Likewise, when fraud and cybersecurity teams work together, both functions can clearly demonstrate their strategic value. Collaboration reinforces their roles in building customer trust and protecting the institution’s bottom line.

Turning hidden signals into a proactive defense

When fraud and cyber teams unite, they can surface early cyber indicators that would otherwise go unseen and act on them before they escalate into fraud. There is no single blueprint for cyber fraud fusion. Success comes from creating the right combination of people, processes and technology that aligns with an organization's unique risk profile and business objectives.

Improving cyber fraud fusion through integrated intelligence allows institutions to allocate resources more effectively by focusing on the signals that matter most for stopping fraud. With defined tools and processes to share intelligence consistently, financial institutions strengthen not just their own internal defenses, but also the collective resilience of the industry.

Looking to enhance your cyber threat intelligence capabilities? Explore  Mastercard’s cybersecurity and cyber intelligence capabilities to learn more. 

FAQs about cybersecurity and fraud prevention

Here’s a closer look at some of the most common questions about the link between cybersecurity and fraud prevention.

Many fraud schemes start with earlier cyber incidents like a phishing attack or malware infection. Spotting these early signals helps banks connect the dots before criminals monetize stolen data through fraud.

Organizational silos, resource limits and poor intelligence sharing often keep fraud and cyber teams apart. Without collaboration, warning signs go unshared, slowing detection and leaving banks more exposed.

By establishing consistent intelligence-sharing frameworks, banks can break down silos between cyber and fraud teams. Sharing payments-specific threat intelligence and coordinating response routines enables earlier detection, faster intervention, and reduced fraud losses.

Shared intelligence helps teams spend less time connecting information across separate systems and more time acting on risk. By providing a common view of emerging threats, it helps investigators prioritize the alerts most likely to result in fraud.

Get in touch

Is your organization ready to close the gap between cyber and fraud? Learn how our solutions can help.

Mastercard logo