As traditional payment security measures become more effective, cybercriminals are shifting their focus to the human element, leading to a sharp rise in manipulation fraud. According to the Observatory for Payment Security (OSMP), the latest annual report published in September 2026 shows that the fraud rate on bank cards has reached its lowest historical level, thanks to stronger authentication protocols. However, the total damage from fraud amounted to 1.241 billion euros in 2025, a 3.8% increase from the previous year, driven by a significant shift in attack methods from social engineering to user manipulation.
Manipulation fraud, which includes scams such as fake bank advisors, fake transfer orders, and altering account numbers (IBAN substitution), rose to 516 million euros in 2025, up from 384 million euros in 2024—a 34% increase in just one year. This type of fraud now accounts for 41.6% of total fraud losses, compared to 32.1% in 2024 and 21.6% in 2021. Over four years, its share of the overall damage has more than doubled.
This shift is largely attributed to the rise of generative artificial intelligence (AI), which has given scammers new tools to manipulate victims more effectively. Denis Beau, First Deputy Governor of the Bank of France and Designated President of the ACPR, noted in a speech that AI enhances the offensive capabilities of attackers. He explained that advanced AI systems can identify vulnerabilities in code, create malicious software, and even scale up social engineering tactics. Additionally, AI systems used by financial institutions and corporations have become targets themselves, potentially granting access to sensitive data.
In 2026, an incident on the Hugging Face platform saw nearly 700 AI agents coordinate to launch a large-scale attack. Meanwhile, enterprises face growing risks from Fake Transfer Orders (FOVI), which involve fraudulent requests for money transfers. The National Direction of Judicial Police (DNPJ) reported 640 major FOVI cases targeting legal entities in 2025, with damages totaling 43 million euros—up from 36 million euros in 2024, a 19% increase.
Two of the most common methods used in these attacks are bank details fraud (RIB change) and president fraud. In RIB change fraud, hackers impersonate legitimate suppliers to provide a new account number and intercept payments. President fraud involves scammers pretending to be company directors or legal advisors, pressuring employees to make urgent transfers. Generative AI is making these attacks more convincing, with perfectly written emails, deepfake voice calls, and video cloning of executives allowing fraudsters to bypass traditional security checks.
To combat these threats, European and French authorities are implementing both regulatory and technical measures. The Digital Operational Resilience Act (DORA) requires financial institutions and their technology providers to manage information risks and conduct regular security assessments. The AI Act, set to take effect in December 2027, will regulate AI use based on risk levels, with high-risk applications such as credit granting requiring stronger oversight. At the national level, the Bank of France has introduced the National File of Reported Accounts for Fraud Risk (FNC-RF), enabling real-time sharing of information about suspected fraudulent accounts.
France is also testing new tools to prevent spoofing and phishing, including the Number Authentication Mechanism (MAN) and the Do Not Originate (DNO) system, which aim to block fraudulent calls before they occur. Additionally, the OSMP is working with tech giants like Google, Meta, and TikTok to enhance fraud detection through collaborative programs. As Denis Beau emphasizes, the success of the technological revolution depends on the collective ability to understand, anticipate, and regulate its use. Companies are now expected to take a broader, more strategic approach to fraud prevention, combining technical safeguards with employee awareness and strict verification processes.
European Fight Against AI-Driven Fraud Intensifies as Cybercriminals Target Human Vulnerabilities
AI-rewritten from original reportingHow it works
cybercrimeai-fraudpayment-securitydeepfakesfraud-preventiondora-regulation



