Financial Technology (FinTech)

Navy Federal Credit Union Confronts Rising Scams with AI Countermeasures as Criminal Tactics Shift From Traditional Fraud

As financial institutions deploy increasingly sophisticated digital fortresses to protect consumer assets, cybercriminals are forced to adapt, shifting their focus from traditional theft to psychological manipulation. At Navy Federal Credit Union, the nation’s largest credit union, this evolving threat landscape has highlighted a critical dichotomy in modern financial crime: while conventional fraud is steadily declining, consumer-targeted scams are surging.

According to Carrie Foran Sepulveda, Navy Federal’s vice president of fraud and physical security, the financial services sector’s success in blocking unauthorized transactions has essentially squeezed the proverbial crime balloon. When one avenue of illicit activity is blocked, criminal energy is redirected toward vectors that are harder to detect through traditional security protocols. Consequently, while traditional fraud attempts against Navy Federal members dropped by approximately 25% between 2024 and 2025, scams—where account holders are deceived into voluntarily transferring their own funds—have claimed an increasingly prominent share of security resources.

The fundamental distinction between fraud and scams lies in the initiator of the transaction. In standard fraud scenarios, unauthorized third parties infiltrate accounts or intercept payment mechanisms, leaving a clear digital footprint of external interference. Conversely, scams rely heavily on social engineering. Because the customer is the one taking action under false pretenses, automated detection tools must look beyond simple credential theft and analyze behavioral signals, communication channels, and psychological coercion.

The Evolution of Financial Crime and the Shift to Social Engineering

For decades, financial institutions concentrated their defensive investments on perimeter security, authentication protocols, and transaction monitoring to stop unauthorized parties from moving money. These investments have yielded tangible results across the industry, driving down rates of card skimming, account takeovers, and unauthorized wire transfers.

However, criminal organizations have pivoted toward authorized push payment (APP) scams and impersonation schemes. By posing as trusted entities—such as representatives from financial institutions, utility companies, or law enforcement agencies—fraudsters manipulate victims into authorizing payments themselves. From the consumer’s perspective, the emotional and financial fallout of falling victim to a scam closely mirrors that of traditional fraud. Yet, from a defensive operations standpoint, combating a scam requires an entirely different playbook.

To address this challenge, Navy Federal has expanded its collaborative network. The credit union works alongside organizations like the Global Anti-Scam Alliance, maintains open communication channels with peer financial institutions, and coordinates closely with major social media platforms and law enforcement agencies. These partnerships are designed to dismantle the digital infrastructure that scammers use to reach prospective victims, from fraudulent advertisements on social networks to spoofed phone numbers and malicious websites.

Deploying Artificial Intelligence Offensively

In January, the Vienna, Virginia-based institution—which boasts assets totaling $204 billion—adopted an innovative technological countermeasure by partnering with Cube AI, an artificial intelligence-based crime prevention platform. Rather than merely waiting for suspicious transactions to cross its internal systems, Navy Federal utilizes AI bots designed to engage directly with scammers.

These conversational AI bots mimic vulnerable consumers, interacting with fraudsters through chat interfaces, phone calls, or messaging applications. When a scammer believes they have successfully reeled in a target, they typically provide a specific bank account number, digital wallet handle, or payment gateway where the supposed victim should send funds. The Cube AI platform captures this destination information and feeds it directly back to financial institutions.

This operational model flips the script on cybercriminals. By deploying AI offensively, the credit union moves away from relying solely on internal hunches or statistical anomalies that suggest a story does not add up. Instead, security teams receive verified intelligence containing accounts actively utilized by criminal networks.

How Navy Federal harnesses AI to confront scam activity

Consequently, when a real member attempts to send a wire transfer or payment to one of these flagged destinations, Navy Federal can intervene with high confidence. Over the past 19 months, this multi-layered approach to wire scam prevention has enabled the credit union to intercept and protect approximately $125 million that otherwise would have been lost to criminal enterprises.

Navigating the Legal and Operational Dilemmas of Consumer Protection

While technological interventions like AI-driven bot engagement have proven effective, financial institutions face complex operational and legal hurdles when attempting to block transactions initiated by account holders. Intervening in a customer-driven transfer requires a delicate balance between fiduciary protection and customer autonomy.

Historically, if a member insisted on transferring or withdrawing funds despite repeated warnings from credit union staff, Navy Federal required the individual to sign an institutional affidavit acknowledging the risks. However, following a related lawsuit, the credit union altered its operational policy. Rather than asking members to sign liability waivers, Navy Federal now adopts a firm stance of refusal: if internal risk assessments indicate a high probability of a scam, the institution simply refuses to facilitate the transfer.

Foran Sepulveda acknowledges that this policy shift represented a significant operational departure from traditional customer service norms, but emphasizes that the institution has successfully aligned around the imperative of preventing devastating financial loss. When an institution has overwhelming evidence that a member is walking into a trap, exercising the authority to halt the transaction becomes a necessary safeguard.

Nevertheless, this protective authority has its legal boundaries, creating friction points for security professionals. While financial institutions possess broad discretion over wire transfers, their regulatory authority regarding other banking products is more restricted. For instance, if a customer is determined to fall victim to a scam but chooses to withdraw their balance in the form of a cashier’s check or physical cash, institutions often lack the legal right to withhold those funds.

The Need for Regulatory Clarity and Safe Harbors

Looking toward the broader financial ecosystem, industry leaders argue that technological innovation alone is insufficient to stem the tide of sophisticated scams. Establishing robust defenses requires modernizing the regulatory framework to provide financial institutions with clear legal protections—often referred to as safe harbors—when they act to freeze or delay suspicious transactions.

Foran Sepulveda advocates for enhanced regulatory guidance regarding the rights and responsibilities of financial institutions when handling potentially compromised accounts. As scams become more intricate, security teams need definitive rules of the road that clarify how long funds can be held for investigation and what measures can be taken when customers demand liquidity despite clear indicators of ongoing deception.

The intersection of artificial intelligence, social engineering, and financial regulation suggests that the battle against scams will remain dynamic. As fraudsters harness advanced technologies to scale their operations and refine their impersonation techniques, financial institutions are compelled to respond with equally advanced countermeasures.

For Navy Federal Credit Union, the ongoing integration of offensive AI tools, cross-industry intelligence sharing, and stricter internal intervention policies marks a fundamental transformation in how consumer wealth is safeguarded. As the industry looks to the future, the primary challenge will not merely be outsmarting criminals through better algorithms, but forging a cohesive regulatory environment where institutions are legally empowered to protect consumers from the consequences of their own deception.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button