Committing fraud has never been simpler or cheaper. Fraud-as-a-service and phishing-as-a-service kits now let any criminal buy organised-crime capability off the shelf, no technical skill required.
Speaking on episode nine of Follow the Money, Bank of China senior financial crime officer (2LOD) Pallavi Kapale and Salv’s CEO Taavi Tamkivi described how that barrier to entry has effectively disappeared.
Inside banks, meanwhile, the opposite instinct dominates: institutions hesitate to share the data that could stop attacks, often for legitimate reasons. Attackers cooperate; defenders don’t. Both speakers argue the real obstacle isn’t law or technology, but a lack of confidence in using the rules and data already available.
Fraud has outgrown the department it started in
Fraud was once a small, tick-box team working after KYC checks. That has changed. It now makes up around 45% of all UK financial crime and has become a board-level issue, shaped by the UK fraud strategy and the FATF 2026–2028 Fraud Strategy. Yet operating models haven’t kept pace: investigations, first-line fraud and beneficiary teams remain siloed, each seeing only part of the picture, while criminals coordinate freely through as-a-service tools.
Privacy is the new excuse, just like friction once was
The friction-versus-fraud debate has largely been resolved, replaced by a new blocker: privacy versus fraud, used as another reason for inaction. Yet flagging a suspicious transaction rarely requires sharing a full KYC profile. Salv’s Taavi Tamkivi said, “You don’t even need to give the name of the customer,” “You just need to refer to a transaction ID, or the IBAN, maybe the amount.”
Some European data providers already treat an IBAN as shareable; others still guard it closely. The gap is one of interpretation, not legislation. Kapale noted that pre-pandemic, banks could quickly compare notes on shared customers. That’s still legal today, just with clearer audit and four-eye requirements, extra steps rather than a ban.
The infrastructure exists; the confidence is what’s new
Rails for compliant, real-time fraud data sharing already exist and have run for years in several countries. What’s shifted is legal clarity. Estonia’s law, effective 1 July, explicitly permits banks to exchange fraud intelligence and delay suspicious instant payments, echoing moves in Norway and France ahead of the EU’s Payment Services Regulation. One EU country completed its entire tender process in three months. That certainty is what pushes teams from manual, case-by-case caution towards automated real-time sharing.
So what?
The starting point is internal. Most banks still can’t give their own fraud teams real-time access to data they already hold, let alone external data. Fixing that, and treating privacy as a design question rather than a veto, is essential.
Otherwise, closing a mule account in one bank simply pushes the problem elsewhere. The collective fraud-fighting network is no longer hypothetical; it’s being built now.
Stay ahead of the threats reshaping financial crime. Subscribe to RegTech Analyst’s newsletter for the strategic intelligence and early insight that senior decision-makers rely on.
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





