Nine in ten scam sessions now happen on mobile, says BioCatch
BioCatch says nine in ten scam sessions in its global customer data are now on mobile, as UK banks weigh behavioural checks against APP reimbursement rules that split scam costs 50:50.
- Published

BioCatch, a behavioural biometrics vendor that supplies fraud-detection technology to banks, said on 30 September 2026 that nine in ten scam sessions recorded across its customer base in the 12 months covered by its 2026 Global Scams report originated from a mobile device — five percentage points higher than in its previous report. The company also said attempted banking scams reported by its customers rose 35% globally over the same period, down from 65% growth a year earlier.
Both figures describe BioCatch's own dataset: more than 370 customer financial institutions serving more than 760 million users across 21 countries, as measured at the end of the first half of 2026. BioCatch has not published a UK-only breakdown on its accessible report page, so neither statistic should be read as a measure of UK scam incidence specifically. The company is a vendor describing results from banks that already use its technology, which is a narrower and self-selected sample than the UK market as a whole.
The findings still matter to UK readers because they bear directly on how banks design fraud controls under the country's mandatory reimbursement regime for authorised push payment (APP) scams, which has applied since 7 October 2024. If genuine customers are increasingly manipulated into sending money from a phone, the question for banks is whether behavioural and device signals can flag coercion before a payment leaves the account — and UK rules now give both the sending and receiving bank a direct financial stake in getting that right.
What the mobile figure actually measures
BioCatch's 90% figure appears to concern mobile scam sessions within its customer dataset, but the accessible material does not establish exactly what the company is measuring: whether it is the device used for the banking session in which a scam attempt was detected, or the channel where the scam began. A fraudster can make first contact by social media message, a cloned website, an email or a phone call, and the victim may only open their banking app later to send the money. The evidence available does not establish that 90% of scams started on mobile, and framing the finding that way risks overstating what BioCatch has shown. BioCatch has not disclosed the precise point in a scam's lifecycle at which its systems record the device used, so the statistic is best read as describing mobile scam sessions in its dataset rather than a confirmed account of where scams originate.
BioCatch has not disclosed the raw number of attempted scam sessions underlying its percentages, a country-by-country breakdown, or its full classification methodology in the material reviewed for this article. That makes it difficult to judge how representative the sample is of UK banking customers, or whether any UK institutions were among the 370-plus contributors.
The UK picture looks different from the global one
BioCatch's reported 35% global rise in attempted scams sits in tension with UK-specific data from UK Finance, the banking trade body. UK Finance reported £257.5m in UK APP fraud losses for January to June 2025, up 12% on the same period in 2024, while the number of reported cases fell 8% to 110,747. That is a pattern of fewer cases but higher losses, which is not the same shape as BioCatch's global growth figure.
These two data sources are not directly comparable. BioCatch measures attempted scam sessions across a global, vendor-selected customer base; UK Finance measures reported, completed UK fraud losses and case counts from its member banks. The two should be read as separate, non-interchangeable trend lines rather than as evidence that one confirms or contradicts the other.
Why reimbursement changes the economics of prevention
Since 7 October 2024, qualifying Faster Payments transfers between relevant UK accounts have been covered by a mandatory reimbursement regime under rules set by the Payment Systems Regulator (PSR), with the Bank of England setting a corresponding reimbursement requirement for CHAPS transfers. The protections apply to individuals, microenterprises and charities; credit unions, municipal banks and national savings banks are excluded from the arrangements, and intra-firm ("on-us") transfers sit outside these Faster Payments and CHAPS requirements, though the Financial Conduct Authority (FCA) has said Consumer Duty obligations can still apply to those transfers.
| Feature | Detail | Effective date |
|---|---|---|
| Maximum reimbursement | £85,000 per qualifying claim | 7 October 2024 |
| Optional excess | Up to £100 (not applied to qualifying vulnerable consumers) | 7 October 2024 |
| Standard decision deadline | Five business days | 7 October 2024 |
| Extended deadline (stop-the-clock enquiries) | Up to 35 business days overall | 7 October 2024 |
| Cost split between firms | 50:50, sending and receiving payment firm | 7 October 2024 |
The 50:50 cost split is the mechanism that most directly incentivises prevention on both sides of a payment: a sending bank pays half the reimbursement cost if its customer is scammed, and a receiving bank pays half if a scammer's account sits on its books. The PSR has described this as giving both parties reason to detect fraud and identify mule accounts before money moves or lands.
In the first 12 months of the regime, the PSR reported that 88% of money lost in in-scope APP claims was returned, equal to £173m, out of roughly 269,000 reported claims, of which 188,000 were in scope. That leaves a reported 12% of in-scope losses not returned to claimants, a reminder that reimbursement is not automatic or guaranteed in every case, and that scams outside the regime's scope — cash, cheques, card payments and transfers that fail the eligibility criteria — are subject to separate protections.
Detection before the customer authorises the payment
BioCatch's report describes signals its technology can use to flag that a genuine account holder may be acting under instruction from a scammer rather than making an independent decision: an active telephone call running during the banking session, remote-access software operating on the device, and the pattern in which a customer adds a new payee. The company frames these as potential markers of coercion rather than account takeover by a stranger.
The FCA has separately recognised behavioural biometrics, device monitoring, risk-based warnings and staff intervention before high-risk payments as potentially useful elements of a bank's anti-fraud controls. The regulator has not endorsed a specific vendor or technology, and the evidence available for this article does not include independently published figures on detection accuracy, false-positive rates or prevented-loss value for BioCatch's tools specifically. The case for behavioural monitoring is therefore a plausible one grounded in what signals can theoretically reveal, not a proven causal record of losses avoided.
The FCA's Consumer Duty, in force since 31 July 2023 for products and services open to sale or renewal, requires regulated firms to avoid causing foreseeable harm to customers. The regulator has said that inadequate scam-detection systems, or warning messages that are poorly designed, tested or monitored, can themselves constitute foreseeable harm — meaning weak controls can expose a firm to conduct risk quite separately from the reimbursement cost of a successful scam.
When a bank can pause a payment
Separately from the reimbursement regime, UK law has given payment firms a specific power to slow a payment down. Since 30 October 2024, when the Payment Services (Amendment) Regulations 2024 took effect, a payer's payment service provider may delay an outbound sterling payment until no later than the end of the fourth business day following receipt, where it has reasonable grounds to suspect third-party fraud or dishonesty and needs time to make enquiries with the payer or another party.
This is a permissive power, not a requirement to delay every suspicious-looking payment. A firm that uses it must notify the payer and is liable for qualifying interest and charges the customer incurs because of the delay. In practice, this gives banks a legal route to pause a payment for a short, bounded period if behavioural or device signals raise concern during a mobile banking session.
Evidence and its limits
BioCatch's own framing attributes the slowdown in its growth figure, from 65% a year earlier to 35% in the current report, to its behavioural intelligence tools taking effect. Separately, the company has said artificial intelligence is lowering the barrier to entry for criminals and adding to the scale and persuasiveness of scams more generally. Both points are attributed assessments from BioCatch rather than independently verified findings. A slower growth rate within a customer base that already uses BioCatch's technology could also reflect changes in how scams are reported, changes in criminal tactics, or changes in the composition of the sample over time — the available material does not rule these alternative explanations out.
The PSR's own reimbursement figures also need careful reading. Different PSR publications report rates for different windows and denominators — an 86% figure for an earlier three-month period, 88% for the first 12 months — and some releases separate money "claimed back" from total losses reported. These are different measures of different periods, not successive revisions of one single number, and should be read that way.
What to watch next
The PSR has signalled an independent evaluation of the reimbursement regime, which would help separate the effect of the rules themselves from the effect of any specific prevention technology on claim volumes; no final version of that evaluation was available at the time of writing. Readers who want the current, official detail on reimbursement eligibility, the £85,000 cap and how to bring a claim should consult the PSR's consumer-facing guidance directly rather than relying on a bank's marketing materials or a technology vendor's report.
Anyone who believes they have been the victim of an APP scam on a UK account should report it to their bank as soon as possible, since the five-business-day standard decision window and the 35-business-day overall deadline both run from the point a claim is made.
Sources
- Global banking scams increase by 35% (opens in a new tab)
BioCatch · · Accessed
- BioCatch report: 2026 Global Scams (opens in a new tab)
BioCatch · · Accessed
- Over £600 million stolen by fraudsters in first half of 2025 (opens in a new tab)
UK Finance · · Accessed
- APP fraud reimbursement protections (opens in a new tab)
Payment Systems Regulator · Accessed
- PS24/7 Faster Payments APP scams reimbursement requirement: Confirming the maximum level of reimbursement (opens in a new tab)
Payment Systems Regulator · · Accessed
- 2024 APP scam performance data – before the reimbursement requirement was implemented (opens in a new tab)
Payment Systems Regulator · · Accessed
- Anti-fraud controls and complaint handling in firms (with a focus on APP Fraud) (opens in a new tab)
Financial Conduct Authority · · Accessed
- Dear CEO letter: Banks and building societies – expectations on APP fraud reimbursement (opens in a new tab)
Financial Conduct Authority · · Accessed
- Reducing and preventing financial crime (opens in a new tab)
Financial Conduct Authority · · Accessed
- The Payment Services (Amendment) Regulations 2024 (opens in a new tab)
The National Archives · · Accessed
- The Payment Services (Amendment) Regulations 2024 (opens in a new tab)
HM Treasury · · Accessed


