The financial services industry is currently navigating a complex evolution in criminal tactics, a phenomenon often described by security experts as the "squeezing of the crime balloon." As financial institutions bolster their technological defenses to effectively thwart traditional fraud, bad actors are pivoting their energy toward more sophisticated and harder-to-detect scams. This shift in the threat landscape has forced organizations like Navy Federal Credit Union—the largest credit union in the United States—to fundamentally rethink their approach to member protection.
Carrie Foran Sepulveda, vice president of fraud and physical security at Navy Federal, emphasizes that the mechanisms required to fight fraud differ significantly from those needed to combat modern scams. While the credit union has achieved substantial success in suppressing traditional fraud—reporting a 25% decrease in such attempts between 2024 and 2025—the challenge posed by consumer-initiated scams has become a primary strategic focus for the institution.
The Divergence of Fraud and Scams
Industry professionals distinguish between fraud and scams by the nature of the transaction. Fraud typically involves unauthorized access or activity where a third party compromises an account. Because these incidents leave behind digital footprints, institutions have developed robust automated defenses to flag and block such activity.
Scams, conversely, involve the account holder themselves acting under duress, deception, or social engineering. When a victim is manipulated into moving their own money, traditional fraud detection tools—which look for "out of character" account behavior—often fail to trigger because the user is performing the transaction. This fundamental difference requires a paradigm shift in data collection and intervention strategies.
"The puzzle for fraud is really straightforward compared to scams," Foran Sepulveda explained. "We’ve done a ton of work on fraud. We have great defenses. But with scams, it is the customer taking action, which prompts further probing as to whether the account holder was duped into moving money or not. While the consumer experience of losing money feels identical, the strategy to combat these two threats is worlds apart."
The Chronology of Modern Defense
Over the past two years, Navy Federal has aggressively expanded its collaborative efforts to mitigate these risks. By partnering with organizations such as the Global Anti-Scam Alliance and maintaining active communication channels with social media platforms, law enforcement, and other financial institutions, the credit union has sought to close the information gap that scammers exploit.
A critical milestone in this defensive evolution occurred in January 2025, when the credit union integrated an artificial intelligence-based crime prevention platform, Cube AI. This technology represents a proactive, "offensive" defensive strategy. Instead of waiting for a victim to report a loss, the platform utilizes AI bots to engage with scammers in real-time.
When a scammer believes they have successfully lured a victim and provides account information for the transfer of funds, the Cube AI system intercepts this data. This allows Navy Federal to compile a verified list of "bad accounts" used by criminal networks. With this actionable intelligence, the institution can warn members against sending money to those specific entities before a transfer is finalized.
Impact and Quantitative Results
The effectiveness of these new tools is reflected in the credit union’s performance metrics. Navy Federal, which holds approximately $204 billion in assets, reports that it has successfully prevented roughly $125 million from being lost to wire scams over the past 19 months.

This $125 million figure serves as a benchmark for the efficacy of interdiction strategies. By shifting from reactive reporting to proactive prevention, the institution has demonstrated that high-fidelity data—specifically the direct identification of criminal accounts—is more effective than simply relying on internal "hunches" or behavioral analysis that might incorrectly flag legitimate member transactions.
The Ethics and Policy of Intervention
The fight against scams has also forced a difficult conversation regarding the balance between member autonomy and institutional protection. Historically, if a member insisted on a transfer despite repeated warnings from their financial institution, the credit union would require the member to sign an affidavit acknowledging the risk before facilitating the movement of funds.
However, the legal landscape surrounding this practice has shifted. Following litigation involving similar practices across the banking sector, Navy Federal has adopted a stricter policy: if the institution is certain that a transaction is the result of a scam, they will refuse to facilitate the transfer entirely.
"If I feel that sure that you shouldn’t have done it, at some point, we need to not do it," Foran Sepulveda said. "That was a big change, but we’ve rallied around it."
This policy shift represents a significant move toward "paternalistic" security, where the institution acts as a gatekeeper to protect the consumer from themselves. However, this raises questions about the limitations of such power. Foran Sepulveda acknowledges that while the credit union can block wire transfers, it remains legally constrained if a member demands a withdrawal in the form of a cashier’s check. In such cases, the institution often lacks the legal authority to withhold the member’s funds, creating a regulatory "gray area."
Broader Industry Implications and Future Outlook
The rise of AI in the hands of criminals has necessitated a corresponding evolution in the tools used by financial institutions. As Foran Sepulveda notes, the future of the industry will be defined by a cycle of "new, novel threats" met by "new, novel solutions."
The broader implications for the banking sector include:
- Regulatory Reform: There is an urgent need for standardized "rules of the road" regarding when a bank can and should hold funds. Financial institutions are currently lobbying for a "safe harbor" provision, which would provide them legal protection when they unilaterally pause or block suspicious transactions at the request of an account holder or based on high-probability risk signals.
- Data Sharing: The success of the Cube AI integration highlights that data sharing between non-traditional tech entities and financial institutions is vital. Future defense strategies will likely rely on consortiums where account-level threat data is shared in real-time across the industry.
- Consumer Education: Despite technological advancements, the human element remains the weakest link. Institutional efforts must continue to emphasize public awareness campaigns to ensure that consumers are as informed as the systems designed to protect them.
As the industry looks toward the next decade, the challenge remains that scammers are agile, often operating across international borders and utilizing emerging technologies like deepfakes and automated social engineering to stay ahead of static defense models.
For Navy Federal, the path forward involves a combination of high-tech interception, a more authoritative stance on transaction blocking, and a push for legislative clarity. As the "crime balloon" continues to shift, the institutions that successfully blend technological intelligence with clear, enforceable policy will be the ones best positioned to shield their members from the increasingly sophisticated digital predators of the modern era. The success of the $125 million saved is not just a financial victory; it is a proof of concept for a more interventionist future in banking security.
