Technology

Mobile fraud prevention strategies lag as scammers pocket $1.03 trillion

Mobile fraud prevention strategies are failing to keep pace with attackers who have quietly repositioned the mobile app as their primary execution layer, according to an analysis published by Guardsquare. The piece, timed to coincide with Open Banking Expo UK & Europe in London, argues that financial institutions are still treating the mobile client as a trusted black box while attackers have moved well past that assumption.

The scale of the problem is worth stating plainly. The Global Anti-Scam Alliance (GASA) puts total global scam losses in 2024 at $1.03 trillion, a figure that sharpens the piece’s more rounded “over $1 trillion” shorthand. What that headline number does not capture is what happens afterwards: GASA also found that only 4% of scam victims worldwide were able to recover their losses. For the overwhelming majority of people defrauded, the money is simply gone.

There is a further wrinkle in how the public understands its own exposure. GASA’s data shows that 67% of people globally feel confident in their ability to detect scams. That confidence gap (between perceived and actual vulnerability) is precisely the condition that social engineering exploits. Fraudsters do not need to defeat sophisticated detection systems when the victim believes they are too savvy to be deceived.

From bank servers to mobile apps: how the attack surface shifted

Guardsquare’s analysis describes three phases in the evolution of financial fraud. Early attacks targeted backend infrastructure directly: bank servers, databases, payment rails. As those hardened, attackers shifted to manipulating customers into initiating transactions themselves, social engineering, phishing, impersonation. The piece argues a third phase is now under way, in which AI-generated deepfakes, malware, and modified mobile applications allow fraud to be executed at industrial scale.

The mobile application sits at the intersection of all three phases. Even when fraud originates elsewhere (a fake advertisement on social media, a phishing text) execution almost always happens inside a mobile app. That matters, the analysis says, because mobile apps run on devices that financial institutions do not own or control. An attacker who can manipulate the execution environment on a user’s handset does not need to breach the bank’s backend at all. A legitimate, fully patched application can still be abused if the environment it runs in has been compromised.

The piece identifies several recurring mobile-centric fraud patterns: runtime manipulation, app repackaging, debugging hooks, and automated abuse through scripting. What these share, the analysis notes, is that the activity is largely invisible to backend fraud systems until damage has already occurred. By the time a transaction triggers a server-side alert, the manipulation has already happened at the client layer.

Mobile fraud prevention strategies: what backend detection misses

Fraud-as-a-service has accelerated the problem considerably. Malware, phishing kits, and operational playbooks are available through underground marketplaces, lowering the barrier to entry for attackers who previously would have needed deep technical expertise. The result is faster iteration and wider distribution of attack techniques across more targets.

The regional picture reinforces the global trend. GASA’s separate Asia scam report puts estimated losses across the region at $688.42 billion over the past twelve months. That single region accounts for a substantial portion of the global total, which points to the uneven geographic concentration of scam activity and the limitations of any purely national regulatory response.

Guardsquare’s proposed answer centres on extending trust decisions to the mobile layer rather than relying solely on backend detection. App hardening, it argues, raises the cost and complexity of reverse engineering. Runtime protections can detect abnormal execution conditions (debugging, hooking, malicious code injection) that strongly correlate with fraud. App attestation, the piece contends, allows institutions to verify at runtime whether an API request originates from a genuine, untampered application on a trustworthy device, without requiring the app to be rebuilt or redeployed.

Whether those controls perform as described in real-world deployments is a separate question the analysis does not address directly: the piece is, by its nature, a vendor argument. But the underlying diagnosis, that mobile fraud prevention strategies which focus almost entirely on backend signals are structurally blind to client-side manipulation, is consistent with what fraud teams at major institutions have been saying for several years. The argument that the mobile app should function as an enforcement point, not merely a delivery channel, is harder to dismiss than the product pitch wrapped around it.

Guardsquare is exhibiting at Stand G5 at Open Banking Expo UK & Europe on 13-14 October in London.

Show More

Alan Cartwright

Alan Cartwright spent twelve years in academic research before he started writing for a wider audience. He did a PhD in biochemistry, held postdoctoral positions at two Russell Group universities, and spent three years on a public engagement fellowship before realising he was better at explaining science than producing it. He writes about scientific research, health claims, evidence policy, and the gap between what a study actually shows and what the headline says it shows. He has peer-reviewed enough papers to know that 'further research is needed' is the most honest sentence in science. Alan lives in Oxford. He reads preprints before press releases and considers this the correct order of operations.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Close
Close