/

Banks on the Frontline as Digital Fraud Outpaces Security: “The Savings of a Lifetime Had Vanished”

A surge in sophisticated online scams, from fake investment platforms to AI-driven impersonation, is pushing financial institutions and victims into a growing legal and technological battle over lost savings.

4 mins read
Representational Image [Photo: Clay Banks/Unsplash]

The image of bank robberies once defined public perceptions of financial crime: masked figures, armed raids, and dramatic escapes. Today, that image has been replaced by a quieter but far more pervasive threat. Money is no longer taken at gunpoint inside a branch but extracted remotely, often from thousands of kilometres away, through screens, phones, and digital networks. As banking continues its migration into online platforms, reducing physical branches and reshaping operations, it has also opened the door to a new class of criminals who operate across borders and jurisdictions with increasing sophistication.

Among those affected is Marta Fernández, a 35-year-old whose experience illustrates the human cost of these evolving schemes. Fernández had only recently begun exploring investment opportunities when she was drawn into what appeared to be a credible financial service. The introduction came through her father, who had already been contacted by individuals posing as financial agents from an online brokerage. After engaging with them over repeated phone calls, he invested his savings and encouraged his daughter to follow suit.

At first, Fernández was persuaded by what seemed like professionalism and consistency. The supposed brokers maintained frequent communication, provided detailed explanations, and even shared visual updates suggesting her investments were growing. The conversations were persistent and familiar, reinforcing a sense of legitimacy that gradually lowered her suspicions. Over time, however, inconsistencies began to emerge. When she independently contacted the legitimate brokerage firm, she discovered that she had never been registered as a client. By then, the money had already been moved through a complex network of transactions and shell structures, reportedly spanning offshore jurisdictions. Her personal losses amounted to around 50,000 euros, while the broader impact on her family and close contacts reached approximately 300,000 euros.

“The world collapsed around us,” Fernández said. “The savings of a lifetime had vanished. You feel a deep sense of vulnerability when you realise you have been targeted by networks with such resources. There was a point where we spoke to them every day, and then suddenly, they disappeared.”

Her case is far from isolated. Authorities describe a broader surge in similar schemes, particularly those involving fake financial advisors and fraudulent investment platforms. These scams often operate through phone calls, messaging apps, or social media advertisements, frequently promoting complex financial products such as cryptocurrencies. The scale of the problem is difficult to fully measure due to the nature of the crimes and the challenges of tracing cross-border digital transactions.

According to the Balance of Criminality published by the Ministerio del Interior, online fraud continued to rise sharply, reaching 430,493 reported cases in 2025, an increase of 4.3% compared with the previous year. Meanwhile, data from the memory of complaints compiled by the Banco de España shows that around 8,000 fraud-related complaints were filed with the financial supervisor during the past year. Together, these figures point to a rapidly expanding ecosystem of digital financial crime that is increasingly difficult to contain.

Banks, however, argue that many of these incidents occur outside their direct control. In their view, the majority of fraud cases take place when customers either authorise transfers themselves or unintentionally share access credentials with criminals. As a result, financial institutions have placed growing emphasis on public awareness campaigns, encouraging users to recognise suspicious activity and avoid sharing sensitive information. They also participate in coordinated efforts such as the so-called antifraud brigade, working alongside the Ministry of Economy and telecommunications companies to detect threats, coordinate responses, and block fraudulent activity before it spreads.

Experts note that these scams are becoming increasingly complex. Jaime García de Biedma, a lawyer at Asufin specialising in financial fraud cases, explains that one of the most common forms remains phishing. In these cases, criminals impersonate banks through text messages or phone calls, convincing victims that their accounts are under attack. Under pressure, individuals may transfer funds to fraudulent accounts or disclose sensitive credentials.

A newer and more alarming development, according to García de Biedma, is the use of artificial intelligence to replicate voices or generate convincing financial updates. These tools allow criminals to mimic legitimate agents with greater precision, increasing the credibility of their deception and making it harder for victims to distinguish between real and fake communications.

While individual consumers are frequent targets, companies are also increasingly exposed. One such method is known in financial circles as the “man in the middle” attack. In this type of fraud, criminals infiltrate corporate email chains and alter key details, such as bank account information on invoices. Juan Álvarez, whose name has been changed, encountered this tactic when his company received an invoice for computer equipment. Unbeknownst to the business, cybercriminals had inserted themselves into the email correspondence with the supplier and replaced the legitimate account number with one controlled by the attackers.

In this case, the affected company successfully pursued legal action, resulting in a ruling by a court in Gijón ordering the bank to reimburse 39,490 euros lost in the scam. The court found that banks have a heightened duty of care towards corporate clients and determined that the financial institution had failed to take sufficient steps to mitigate the loss after being alerted to the fraud.

As more victims seek redress, a parallel battle has emerged in the courts. Legal pathways typically involve either criminal proceedings against the perpetrators or civil claims against banks. Criminal cases are often difficult due to the international nature of cybercrime networks, which frequently operate from jurisdictions with limited cooperation mechanisms. Civil proceedings, meanwhile, require victims to first submit complaints through bank customer service channels and then enter mediation processes before potentially going to court. According to observers at Asufin, banks often reject reimbursement claims, directing customers to pursue litigation instead, a process that can take more than a year.

Court decisions in these cases vary widely. Legal practitioners note that judges generally focus on two main questions: whether the customer acted with gross negligence, and whether the bank implemented adequate safeguards to prevent fraud. Outcomes often depend on the specifics of each case. In incidents involving impersonation of banks, rulings tend to favour customers more frequently. However, in cases linked to cryptocurrency or online investment platforms, judicial positions remain less consistent, reflecting the evolving nature of the fraud landscape.

Some legal experts argue that financial institutions should be more proactive when detecting unusual transactions, particularly large international transfers that deviate from a customer’s typical behaviour. They contend that such anomalies should trigger alerts and additional verification measures to prevent potential fraud. In this ongoing tension between evolving criminal tactics and institutional safeguards, the boundaries of responsibility remain a central issue, as courts, banks, and victims continue to confront a rapidly changing digital financial world.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog