Blog

Behind Enemy Lines: What Financial Institutions Can Learn From the Mind of a Scammer

September 9, 2026 by Sune Gabelgård & Sanne Fahnøe

This piece is based on a three-hour recorded interview with a former fraudster and insider in the telemarketing business, later edited into two podcast episodes of the Danish podcast ‘Deceived by a Scammer’ sponsored by Nasdaq Verafin.

In the financial industry we often approach fraud as a technical problem; something that happens in milliseconds at a payment gateway, detected (or not caught) by an algorithm trained on historical patterns.

When we sat down with a fraudster to discuss their practices, we learned more about how the mind of the perpetrator works — and what this means for risk mitigation.

The man we interviewed was not a stereotypical fraudster. Before becoming a full-time scammer, he worked in telemarketing, where he had legitimate access to customer information and spent years learning how to build trust, navigate financial systems and understand human behaviour.

He later used those same skills to commit fraud at scale. He frequently scanned the financial systems around him, identified assumptions he could exploit, and adapted his approach accordingly — an example of how fraudsters are successfully scamming banking customers out of billions annually.


Hear the podcast, Deceived by a Scammer, for more insights on how criminals are exploiting your fraud defenses.


Digital Identity is a Confidence Game & Fraudsters Know It

The fraudster we spoke to had a script, twenty years of experience reading people and in some instances, a better understanding of security gaps than the banking security teams he was circumventing. He knew how to establish trust fast, balance urgency with panic and how to frame requests so that his victim would comply, feeling entirely in control.

Meanwhile, the banking industry has invested enormously in digital identity verification, such as MitID in Denmark. The assumption embedded in this investment is that when victims authenticate payments, they are doing so freely and with full understanding of what they are authorizing. Modern fraudsters have learned they don’t need to infiltrate your authentication system, they just need to infiltrate your customer.

This is not a niche case; authorized push payment scams are quickly becoming a dominant fraud typology of our era, and yet when we look at the roadmaps of financial institutions building toward a digitally secure future, we still are not prepared for a world where the customer is the attack vector, and consent is manufactured.

Institutions Are Only Screening in One Direction

For years, the financial industry has systematically invested in screening outgoing payments and rarely invested in screening incoming ones. The logic behind outgoing payment screening is simple — you want to prevent your customer’s assets from being stolen from your institution.

However, fraudsters are using sophisticated technologies to outmaneuver controls around outgoing payments and targeting customers with access to resources. Since these customers have decades-long transaction histories and stable behavioral patterns, institutions are less adept at identifying scams because the customer is the one initiating it — and they might not even realize they’re being manipulated.

When a fraudster cashes the payment out of the receiving account, they are not trying to preserve the account, which is different behavior than an anti-money laundering analyst might observe. While money launderers are more careful because the account has to survive to maintain the lie of legitimacy. However, a fraudster does not care; they will burn the account and easily buy another one.

Looking at the behavioral profile of the receiving account, including the velocity of inflows and any deviation from the account’s normal pattern, is likely to yield more risk indicators than outgoing payment screening for this type of money movement. The signal is stronger and the deviations are easy to detect, yet few institutions are monitoring incoming payments for red flags.

They Know the Rules… And How to Break Them

Fraudsters will take advantage of any legal loophole. Originally, the fraudster had acted as an insider in a telemarketing company, tapping customers for their personal information in his daytime legal job, and using the data later to defraud the same customers out of millions in his spare time.

He knew exactly how to circumvent the behavioral indicators we typically train insider threat programs to look for. He did not extract gigabytes of customer data, he wrote down account details by hand on paper, specifically to avoid leaving a digital trace. He did not transfer large sums, or show visible signs of unexplained income. He took his vacation. He was collegial and professional. He received good performance reviews. He was even promoted.

Later he quit his job to scam people full time. He understood the transaction monitoring logic, and he was meticulous about how he exploited that knowledge.

The playbook for insider threat detection was written for a different kind of insider, the person who is angry, careless, or greedy in visible ways. But what the industry is facing now is someone who understands that playbook as well as we do. This suggests the next frontier in financial crime prevention means going beyond the payment layer to uncover payee risk, and to transform the way we detect illicit activity.

What This Means for the Anti-Financial Crime Landscape

The industry conversation about financial crime tends to circle between two registers: the macrocosm of $4.4 trillion in estimated illicit flows and the need for collective action; and the microcosm transaction anomalies that help us mitigate the problem, such as payment size and history.

This interview forced us to confront the legal gaps that make illicit activity a rational business decision; a reminder to look more carefully at both sides of transactions; understanding that monitoring incoming transactions is a key layer in fraud prevention.

These are questions about shared responsibility, and how well we are collaborating with each other within the industry. How can we work together, both within the industry and through public-private partnerships, to improve this?

The interview reinforced a broader lesson: fraud is rarely the result of a single failure. It succeeds when weaknesses across people, processes, institutions, and systems align. Effective prevention requires better visibility across the fraud lifecycle, stronger intelligence sharing, closer public-private collaboration, and greater attention to behavioral indicators that emerge before losses occur.

Hear the full podcast for more insights from this conversation, sponsored by Nasdaq Verafin (Danish language only). 

 

About the Experts

Sanne Fahnøe, Journalist & Podcast Host, Deceived by a Scammer


Sune Gabelgård, Fraud Industry Expert & Podcast Host, Deceived by a Scammer 

Subscribe for curated expert perspectives and industry insights, sent directly to you.