Consumers think the most concerning types of payments fraud are card or card data theft (named by 45%), identity theft (also named by 45%) and account takeover (41%). Threat perceptions could change, however, if Canada’s new real-time payment rail increases the risk of authorized push payments through mechanisms such as impersonation, social engineering and deep-fake enabled fraud.
“Prevention of payment fraud such as account takeover must continue to evolve from the static monitoring of credentials at the log-in stage, towards risk-based continuous authentication and cross-channel identity orchestration”, says Woolham. “This will mean layering behavioral analytics, digital identities, adaptive MFA, and biometric identity verification as well as building a more cohesive enterprise-wide strategy.”
Capco’s survey suggests that consumer confidence in fraud protection needs strengthening. Only 33% of our respondents feel ‘very confident’ that their primary financial institution will protect them from payment fraud, while 52% are ‘somewhat confident’ – and 16% feel neutral or lack confidence.
Institutions that strengthen consumer confidence in fraud protection could find this is a key marketplace differentiator in the years ahead, says Woolham.
What kind of payment fraud concerns you most?
(4 selections permitted)
Fill in your email address to read on and learn:
© Capco 2026, A Wipro Company
Back to Top
August 2026
Winning the arms race in a real-time, AI-enabled consumer fraud landscape
Canada Payment Fraud Survey
With Canada preparing for the introduction of its real-time payment rail (RTR), Capco surveyed 1,000 Canadian consumers to explore their experience of payment fraud, fears about 'deep fake' threats, desired balance between security and convenience, and attitudes to fraud prevention.
Key findings include:
Which security protocols frustrate consumers most
What percentage of consumers have suffered each type of payment fraud
If deep fake technologies are eroding confidence in biometrics and facial ID
Download PDF with full results and recommendations
Payment fraud in Canada is becoming more sophisticated and automated, with faster new payment rails and AI-enabled scams threatening to compress detection and prevention windows to seconds.
Gaelan Woolham, Partner & Canada Head of Financial Crime, Risk, Regulation & Finance at Capco, says organizations must avoid fighting yesterday’s battle. He thinks it is critical to create a pipeline of insights to drive future fraud prevention strategies, based on customers’ fraud experiences and attitudes and how emerging technologies and payment rails are transforming both fraudster tactics and fraud prevention.
Banks must quickly incorporate AI into their own operations to orchestrate the detection of complex patterns and behaviors across product and operational silos and enable real-time decision-making as the fraud arms race speeds up.
Gaelan Woolham, Partner
Canada Head of Financial Crime, Risk, Regulation & Finance
Brand reputation
31%
Accessibility (e.g. 24/7 support)
36%
Transaction speed and reliability
36%
Customer service quality and responsiveness
39%
Advanced fraud protection
46%
Security
60%
Capco’s survey highlights the priorities of Canadian consumers. Respondents told us that the most important factors when choosing a financial institution offering payment services are security (60%) and advanced fraud protection (46%) – well ahead of factors such as customer service quality (39%) and brand reputation (31%).
Which are the most important factors when choosing a financial institution that offers payment services? (Top 6 answers; 4 selections permitted)
Impersonation or social engineering
17%
Transfer payment you did not make
24%
Phishing
27%
Purchase you did not make
38%
Account takeover
41%
Identity theft
45%
Card or card data theft
45%
'Deep fake' or AI-enabled fraud
17%
Fake or spoofed online stores/marketplaces
17%
Push payment fraud,e.g. getting you to transfer money
14%
Employment scam
13%
Money muling
8%
Romance scam
6%
Not concerned with payment fraud
6%
Other
0%
Our survey captures a degree of frustration with some of today’s security protocols, for example:
33% of respondents find complex passwords frustrating or inconvenient to use
27% of respondents find being sent security codes frustrating or inconvenient.
Institutions face a continuing challenge as they try to balance improved security with greater speed and convenience, not least because customer attitudes vary. In Capco’s survey, while the largest number (40%) made security their absolute priority, many others looked for some kind of trade-off.
Capco’s Woolham says that new technologies mean trade-offs between security and convenience are not always necessary. “The aim should be to prevent fraud through stronger but lower-friction authentication,” he says, “with advanced biometrics, digital wallets, tokenization and passkeys all helping to strengthen security while preserving or enhancing convenience.”
This will mean taking practical steps such as encouraging wallet provisioning, biometric approval setup, tokenized card-on-file payments, passkeys for digital banking access, and lifecycle controls such as instant card freezes, card replacement and merchant token management.
“Well-executed step-up measures during transaction initiation such as push notifications, transaction confirmation, and real-time card controls can prevent fraud while also making customers feel protected rather than punished,” says Woolham.
Over a third of Capco’s survey respondents (36%) had experienced attempted payment fraud in the past two years: most often purchases they did not make (37%), phishing (32%), and card or card data theft (20%). Significant numbers noted more elaborate scams such as fake online stores (18%), impersonation or social engineering (14%) and employment scams (12%).
Make sure messaging to customers and employees is simple and actionable – and move it closer to the potentially insecure activity.
Data often continues to be held in silos across the organization with no single detection platform creating a truly enterprise-wide view – potentially allowing fraudsters to exploit weaknesses by adjusting tactics in real time.
“Modern fraud prevention must increasingly span products and channels as well as functional teams, with improved information exchange across business teams, financial products and across payment fraud, cybersecurity and AML teams,” says Woolham.
48%
All respondents
Has your financial institution provided you with any information or guidance about 'deep fake' threats and how to reduce the associated risks.
age 25-35
age 55-65
34%
18%
To strengthen defenses in an increasingly AI-enabled, real-time payment environment, organizations must overhaul their operating model to align with four key trends, says Woolham. “They must shift their focus from post-event detection towards prevention; detect fraud across ecosystems rather than within product and operational silos; prepare for ‘fraud at scale’ as AI and agentic automation opens new avenues of fraud; and quickly adopt and incorporate AI into their own operations and investigations,” he says.
When fraudsters do get through, the recovery experience becomes a trust moment for the customer, says Woolham, so institutions should also aim to make recovery radically easier. This means tactics such as enabling customers to file in-app reports, identify and report multiple suspicious transactions simultaneously, upload contextual information, receive provisional credit, track claim status, and request physical card replacement or easily provision a new card to a wallet.
“Customers should feel believed, guided and protected rather than feeling they are entering an administrative maze,” says Woolham. “Payment market participants who apply the right strategy, tactics and tools can win the payment fraud arms race at the same time as strengthening customer confidence and differentiating themselves in the market,” he says.
Convenience is my absolute priority
1%
Convenience first and decent levels of security
3%
Balance of security & convenience
26%
Security first and decent levels of convenience
31%
Security is my absolute priority
40%
When it comes to balancing security and convenience, which statement best captures your attitude?
Very concerned
53%
How concerned are you that personal data available online could make it easier for someone to impersonate you or find answers to security questions?
Concerned
Not Concerned
10%
38%
Download the in-depth PDF version of this report to access a full set of survey results, deep dives into five key fraud types, and recommendations on how to win the payment fraud arms race using layered defenses and the latest AI-enabled technologies, strategies and partnerships.
Full report offers:
4 infographics with full survey results
5 deep dives into key fraud types: account takeover; authorized push payment (APP); payment card fraud; identity & synthetic fraud; and insider-driven fraud
Recommendations on how to win the payment fraud arms race
Download the Whitepaper
Security (60%) and advanced fraud protection (46%) are the most frequently cited ‘important factors’ when choosing a financial institution offering payment services.
The payment frauds that concern consumers most are card & card data theft (45%), identity theft (45%) and account takeover (41%).
52% say their financial institution has not informed them about the 'deep fake' threat in payments and how to reduce the risk, or do not recall that advice.
Not confident at all
1%
Less than confident
3%
Neutral
12%
Somewhat confident
52%
Very confident
33%
How confident are you that your primary financial institution will protect you from payment fraud?
■ Yes, I have been informed ■ No, I have not been informed ■ I don’t recall
51%
35%
13%
41%
33%
27%
Harley Wonder
Managing Principal, Canada Financial Crime, Risk, Regulation & Finance
“
“
Gaelan Woolham
Partner & Canada Head of Financial Crime, Risk, Regulation & Finance
Our experts
Levels of concern that online information will be used by fraudsters
Other
3%
Deepfake or AI-enabled fraud
8%
Romance scam
9%
Money muling
9%
Identity theft
10%
Employment scam
12%
Account takeover
13%
Impersonation or social engineering
14%
Push payment fraud,e.g. getting you to transfer money
15%
Transfer payment you did not make
17%
Fake online stores/marketplaces
18%
Card or card data theft
20%
Phishing
32%
Purchase you did not make
37%
Which type of payment fraud was attempted?
(Multiple selections permitted)
The results highlight that payment fraud takes many different forms and is conducted across different communication channels and payment rails. However, current applications are not set up to capture complex, cross-system fraud signals, says Woolham.
Other
12%
In person
12%
Social media
25%
Phone
38%
Text
39%
Email
45%
Which communication channels were used to attempt the fraud?
(Multiple selections permitted)
'Deep fakes' are beginning to enable many other fraudster tactics, including impersonation. However, most of our respondents (52%) say they have not been informed about the 'deep fake' threat by their financial institution or cannot recall such an educational effort – rising to 60% of those aged 55-65.
“It is easy for fraud education, awareness and training to become routine, boring and forgettable for both customers and employees,” says Woolham. “Institutions need to make sure messaging is simple and actionable – and move it closer to the potentially insecure activity, for example, through pop-up warnings when making payments to new payees,” he says.
“We also advocate the creation of a fraud risk score for new customers – similar to credit risk scores – to help banks make decisions such as reducing credit exposure for higher risk profiles,” says Woolham. Without such a score, it can be hard to develop a truly risk-based approach to fraud prevention.
As 'deep fakes' and chat bots make it easier to circumvent bank defenses and compromise customers through social engineering, institutions must prepare to combat fraud at scale. “Banks must quickly incorporate AI into their own operations,” says Woolham, “because AI can orchestrate the detection of complex patterns across product and operational silos and enable real-time decision-making as the fraud arms race speeds up.”
Consumers know that personal data is fueling scams and identity fraud. Nine in ten respondents (91%) are concerned that personal data available online could make it easier for someone to impersonate them or find answers to security questions. Most respondents (78%) also worry that authentication through biometrics and facial ID is under threat from 'deep fake' technologies, now or in the future.