The Great Shift: How Navy Federal is Battling the Evolution from Fraud to Scams

The financial services landscape is undergoing a fundamental transformation. For years, the primary objective for banking institutions was the mitigation of "fraud"—unauthorized transactions where a third party gains access to a customer’s credentials. Today, however, the battlefield has shifted. As financial institutions bolster their digital fortresses, criminals are increasingly abandoning the technical hurdles of hacking in favor of psychological manipulation.

This phenomenon, described by industry experts as "squeezing the crime balloon," suggests that as defenses against traditional fraud tighten, illicit actors are redirecting their energy toward more sophisticated, harder-to-detect scams. Among the leaders in this new theater of conflict is Navy Federal Credit Union, the nation’s largest credit union, which is pioneering a combination of artificial intelligence and policy shifts to protect its members from an increasingly complex threat environment.


The Anatomy of the Threat: Fraud vs. Scams

To understand the current crisis, one must first distinguish between two terms often conflated by the public. Carrie Foran Sepulveda, Navy Federal’s vice president of fraud and physical security, notes that while the end result for a consumer—financial loss—is identical, the methodology of the criminal is vastly different.

"The puzzle for fraud is really straightforward compared to scams," Foran Sepulveda explains. "We’ve done a ton of work on fraud. We have great defenses."

Fraud typically involves a breach of security protocols. It is a technical event characterized by unauthorized access. Because the patterns of fraudulent behavior—such as anomalous login locations, sudden spikes in spending, or unusual device signatures—are quantifiable, institutions have developed highly effective automated systems to stop them. Data from Navy Federal reflects this success, with fraud attempts against its members dropping by approximately 25% between 2024 and 2025.

Scams, conversely, involve the account holder acting of their own volition. In these scenarios, the victim is often manipulated through social engineering, impersonation, or fear tactics into authorizing a transaction themselves. Because the customer is the one initiating the transfer, the "signals" that trigger security alerts in traditional fraud detection do not apply. Detecting a scam requires identifying not just a technical anomaly, but a psychological one.


Chronology of an Evolving Defense

The shift toward scam prevention has not happened overnight. It has been a strategic pivot necessitated by the changing tactics of global criminal syndicates.

  • Pre-2023: Institutions focused heavily on hardware-based security, two-factor authentication, and machine learning models designed to detect unauthorized access to accounts.
  • Early 2024: As fraudulent login attempts became harder for criminals to execute, a surge in impersonation scams—where perpetrators pose as bank employees or law enforcement—was recorded globally.
  • January 2025: Navy Federal formally integrated the Cube AI platform into its defensive architecture. This marked a major milestone in moving from reactive victim assistance to proactive, offensive intervention.
  • Mid-2025 to Present: The credit union transitioned its internal policy regarding suspicious transfers, moving from a system of member affidavits to an outright refusal to facilitate transactions that show clear hallmarks of scam-related activity.

The Offensive AI Strategy: Turning the Tables

Perhaps the most innovative aspect of Navy Federal’s current defense is its use of "offensive" artificial intelligence. By partnering with Cube AI, the credit union is essentially deploying "honey pots" to trap criminals in their own webs.

The platform utilizes AI bots programmed to engage with suspected scammers in real-time. When a scammer believes they have successfully hooked a victim and provides instructions—typically a bank account number or a digital wallet handle—the bot captures this information. This data is then fed directly into the credit union’s backend systems.

"It’s all just AI bots who are pretending to fall for scams," Foran Sepulveda says. "They were getting told where to send the money, so we’re very confident in that account being a scammer’s."

This intelligence allows Navy Federal to create a real-time blacklist. When a legitimate member attempts to send money to a flagged account, the credit union can provide an immediate, data-driven warning. This removes the "hunch" from the equation. It is no longer about a bank employee feeling that a story "doesn’t add up"; it is about the institution having verified, actionable intelligence that the destination account is part of an active criminal network.


Supporting Data and Financial Impact

The scale of the threat is massive, but the counter-efforts are yielding quantifiable results. Navy Federal, which manages over $204 billion in assets, has reported the prevention of approximately $125 million in potential wire scam losses over the last 19 months.

How Navy Federal harnesses AI to confront scam activity

This success is supported by a multi-layered collaborative effort. Navy Federal maintains active partnerships with:

  • The Global Anti-Scam Alliance: To stay abreast of international trends in social engineering.
  • Social Media Platforms: To mitigate the spread of fraudulent advertisements and impersonation accounts.
  • Law Enforcement: To ensure that intelligence gathered from AI interventions leads to real-world investigations.

Despite these efforts, the volume of attempted scams continues to rise. Criminals are increasingly using deepfake technology and sophisticated phishing campaigns to bypass traditional verification methods, forcing financial institutions to re-examine the very nature of their relationship with customer autonomy.


Policy Implications and the "Safe Harbor" Debate

One of the most controversial, yet necessary, changes at Navy Federal has been the modification of its intervention policy. Previously, if a member insisted on sending money despite being warned by the credit union that the transaction appeared to be a scam, the member would be asked to sign an affidavit acknowledging the risk. The credit union would then process the transfer.

Following a series of legal challenges and a deeper realization of the harm caused, the credit union decided to stop facilitating these transfers altogether.

"If I feel that sure that you shouldn’t have done it, at some point, we need to not do it," Foran Sepulveda states. "That was a big change, but we’ve rallied around it."

However, this proactive approach hits a legal wall. While the credit union can block a wire transfer, it often has limited power to stop a customer from withdrawing funds via a cashier’s check or through other liquid means. This creates a regulatory gap that Foran Sepulveda believes needs to be addressed through federal policy.

The Need for a Regulatory Framework

Foran Sepulveda is advocating for "safe harbor" provisions—legal protections that would allow financial institutions more latitude to hold funds when they have reasonable, data-backed suspicions of a scam.

"What can we do to hold funds when we think that something looks suspicious?" she asks. "If we won’t send the wire, but if they say they want a cashier’s check for their balance, there’s nothing we can do. We don’t have the right to withhold their funds from them."

The "rules of the road" currently favor the customer’s immediate access to their funds, a principle that is being weaponized by sophisticated criminals. Establishing a framework where banks can act as a circuit breaker without facing litigation for restricting account access is the next major hurdle for the financial industry.


Conclusion: The Future of the Conflict

As artificial intelligence becomes a standard tool in the arsenal of both the perpetrator and the protector, the nature of banking security is shifting toward a cat-and-mouse game of "novel threats and novel solutions."

Navy Federal’s strategy demonstrates that the future of fraud prevention lies not in building higher walls, but in smarter, more proactive intelligence gathering. By using AI to infiltrate the scammer’s ecosystem and by being willing to make difficult, sometimes unpopular, decisions regarding customer transaction flow, institutions like Navy Federal are setting a new standard.

Yet, the success of these measures remains contingent on a broader societal and regulatory shift. Until there is a consensus on how to balance consumer privacy and autonomy with the urgent need for institutional intervention, the "crime balloon" will continue to expand in new directions. For now, the credit union remains vigilant, treating every transaction as a potential opportunity to interdict a life-altering loss.