Russian banks have almost universally implemented anti-fraud measures for internet and mobile operations, but protection still works in fragments. A study by "Infosystems Jet" showed that individual events are well-detected by systems, but it is not always possible to assemble them into a single picture.
For example, a transfer itself may look ordinary. The same applies to changing a device, calling a call center, or visiting a branch. But if all this happens almost simultaneously, a full-fledged attack scenario can emerge – and this is where banks still have a gap.
Online banking is best covered: 100% of respondents use anti-fraud for individuals, and 80% for legal entities. Acquiring, ATMs, and terminals are covered by 50%, operations in branches by 40%, credit products by 30%, and investment services by only 15%.
Not everything is smooth with the systems themselves. Banks complain about rigid settings, weak analytics, and difficulties in building complex scenarios. Only 13% of study participants use machine learning as the main mechanism – and all of them are dissatisfied with the result.
The next step, according to experts, is to combine customer data within a single circuit. Then anti-fraud will be able to see not just an isolated suspicious episode, but the entire chain of actions. At the same time, 70% of survey participants are banks with a client base of less than 1 million people, so the results primarily reflect the situation among small and medium-sized players.