Debit card fraud remains a substantial payments risk. Federal Reserve Financial Services’ 2026 Risk Officer Report found that 75% of surveyed financial institutions had encountered debit card fraud attempts during the prior year, 56% had sustained losses, and respondents attributed 40% of their payments fraud losses to debit cards. Consumer reports of bank impersonation scams, although not limited to cards, show how criminals use trusted communications to obtain credentials or induce payments.
The Federal Trade Commission received reports of about $16 billion in consumer fraud losses in 2025, including $3.5 billion from impostor scams. Consumers reported nearly $1 billion in losses to business impersonators, with bank impersonators accounting for the highest losses in that category. Some of the costliest schemes began with a false security alert and instructions to move money. Other bank impersonators send phony fraud alerts asking customers to confirm account details or share personal information. The reported losses span many payment methods, but the tactics warrant attention from card issuers because they exploit customers’ trust in their banks.
Card-not-present debit fraud has continued to rise. A February 2026 Federal Reserve Bank of Kansas City analysis found that the fraud rate for non-prepaid debit card transactions increased from 2021 to 2023 on both single-message and dual-message networks. The analysis draws on the Federal Reserve Board’s latest biennial debit card data, published in December 2025.
Industry data do not establish why fraud rates increased or describe every community bank’s experience. Banks need their own measures of attempted fraud, realized losses, and prevention costs by channel and transaction type. Those measures can identify concentrations of loss, guide investment, and give policymakers evidence that better reflects smaller issuers.
Controls should follow the bank’s loss patterns. Real-time alerts can prompt customers to review unusual activity, while customer-controlled settings can let them restrict card use. Card verification value (CVV) checks can help screen remote purchases, while 3-D Secure can provide additional authentication. Network analytics can flag transactions that depart from established patterns.
Availability will vary by bank and service provider. Banks should tell customers what they will never ask them to disclose or do and provide a reliable way to verify an unexpected call, text, or e-mail. Management should compare control performance with loss data and adjust accordingly.
Fraud that crosses institutions may appear unrelated when each bank sees only its own transactions. FinCEN’s June 2026 guidance confirms that institutions may share information under Section 314(b), including in real time, when they suspect activity may involve fraud, money laundering, terrorist financing, or other specified unlawful activity. Participation is voluntary, and the safe harbor depends on compliance with the program’s requirements. The ICBA–International Association of Financial Crimes Investigators framework for partnerships between community banks and law enforcement likewise recommends ongoing communication with law enforcement, timely reporting, evidence gathering, and intelligence sharing.
A fraudulent message, a remote card transaction, and activity at another institution may be parts of the same scheme. Linking loss data, customer verification, transaction controls, and external reporting can help management recognize that sequence.
The broader priority for community banks is to treat fraud prevention as a coordinated, strategic function rather than a collection of separate controls. That approach can help banks identify related activity sooner, intervene before losses escalate, and provide stronger evidence to law enforcement. ICBA’s fraud and scams resources offer customer awareness materials and connections with other community bankers working on the same problems.
Scott Anchin is senior vice president, strategic initiatives and policy at ICBA.