The Seconds Before Send: Designing Scam Interventions That Work
A conversation on why generic warnings fail, what behavioral signals reveal a coached payment, and how banks are tuning friction as reimbursement rules shift liability.
In this episode, Lodestar Signals' head of scam research sits down with a former bank fraud-operations lead to talk about the hardest problem in modern payments: stopping a customer from sending money they genuinely intend to send, to someone who has lied to them.
Why warnings get ignored
The guests begin with a blunt observation. Pop-up warnings that say "this could be a scam" are shown so often, on so many legitimate payments, that customers learn to click through them. Worse, scammers now pre-empt them, telling victims in advance that their bank will show a warning and that it should be ignored. Effective interventions are specific: they reference the scam type the signals point to, such as a safe-account or investment scam, and they ask a question the customer has to think about.
Signals of a coached payment
The conversation turns to behavior. Customers being coached on a phone call tend to show distinctive patterns: long pauses on the payee screen, copy-pasted account details, unusual navigation paths, and, in some cases, an active phone call during a banking session. None of these proves fraud alone, but combined with payee-side risk, such as a receiving account opened recently that has seen many first-time payers, they sharpen the picture considerably.
Friction as a dial
The guests argue for treating friction as a dial rather than a switch. A cooling-off delay of a few hours can defuse the urgency scammers depend on; a call-back from a trained agent can break the spell entirely; a hard block may be necessary for the riskiest cases but carries a customer-experience cost. With mandatory reimbursement regimes, such as the UK's, placing more of the cost of APP fraud on payment providers, the economics of that dial have shifted.
The episode closes on data sharing. Scams move money across institutions in minutes, and no single bank sees the whole flow. Both guests see consortium signal-sharing, under proper legal agreements, as the next big lever, particularly for detecting mule accounts before they receive their first stolen payment.
More from the library
Injection Attacks and the Next Phase of Remote Identity Verification
Presentation attacks put something fake in front of the camera. Injection attacks skip the camera entirely. This paper explains the difference and the layered defenses onboarding teams need.
Tap to Phone Goes Mainstream: What Acquirers Learned in Year Three
Tapwell's product lead and a merchant-acquiring executive discuss SoftPOS economics, PIN on glass, device attestation and why micro-merchants are only half the story.
Keystone Ledgerworks Launches Verification of Payee API for Platforms and Marketplaces
Platforms that initiate SEPA transfers on behalf of users can now run payee name checks and show the four standard outcomes inside their own interfaces.