Visa Raises Its Cybersecurity Defenses as AI-Enabled Fraud Targets Human Trust
- Sophie Larsen

- Aug 13
- 13 min read
Visa is expanding its cybersecurity defenses as AI-enabled attacks move beyond stolen card numbers and target the people authorizing payments. For google news readers following the story, the conflict is sharper than a routine security upgrade. Stronger authentication is reducing some familiar fraud, yet generative AI is helping criminals scale impersonation, phishing, and other forms of social engineering.
Visa’s latest threat data captures that reversal. Fraud involving device tokens fell 9.6% between July and December 2025, compared with the same period in 2024. However, the company says scams have become the dominant consumer threat as criminals redirect their attention from technical controls to human judgment.
That movement is pressuring banks, merchants, payment processors, technology platforms, and consumers at once. Visa can inspect activity across its network, but a convincing phone call or fraudulent message can persuade a legitimate customer to approve an illegitimate payment. The attacker does not always need to defeat the payment system when the customer can be manipulated into opening the door.
Visa’s answer combines network-level controls with a newer threat intelligence service for financial institutions. The company is trying to connect cyber signals, such as malware, exposed credentials, and brand impersonation, with the payment fraud that follows. The central question is whether defenders can make those connections before an attacker reaches a customer.
What Visa Changed in Its Cybersecurity Strategy
Visa is moving payment security earlier in the attack cycle, before stolen information becomes a fraudulent transaction.
The company launched the Visa Threat Intelligence Platform, or VTIP, for financial institutions in Europe on July 2, 2026. The service combines cybersecurity intelligence with information about potential payment risks. Visa says the platform uses capabilities developed and tested while protecting its own network.
Traditional payment fraud systems often concentrate on the final transaction. They examine its amount, location, merchant, device, and relationship to the customer’s earlier behavior. That process remains important, but it can begin too late when a cyber incident occurred days or weeks earlier.
A criminal might first steal employee credentials, impersonate a bank, compromise a merchant, or distribute malware. The stolen information can then circulate through criminal markets before anyone attempts a payment. Each step creates evidence, but that evidence may remain scattered across security, fraud, and risk teams.
VTIP is designed to bring those signals closer together. Its threat intelligence component identifies malware-related indicators of compromise, meaning technical evidence that a system may have been breached. Vulnerability intelligence highlights relevant software exposures and known exploits.
The platform also includes brand intelligence, which looks for impersonation and misuse of an institution’s identity. Digital identity intelligence monitors threats aimed at executives and employees. Those targets matter because privileged users can provide access to systems, data, or trusted communication channels.
According to Visa’s threat platform announcement, the company blocks approximately 90 million cyberattacks and 11 million phishing emails each month. Those figures cover operations across more than 200 countries. They illustrate the network visibility behind Visa’s product, although customers will still need to prove its effectiveness inside their own environments.
This is not a replacement for transaction scoring. It extends the defense perimeter by treating fraud as a downstream result of earlier cyber activity. A suspicious transaction becomes one event in a longer chain, rather than the first observable sign of trouble.
Visa has also continued investing in controls operating at authorization time. Visa Advanced Authorization uses machine learning to evaluate transactions against more than 400 risk factors within milliseconds. The company says the system processes billions of transactions annually using intelligence from issuers and merchants.
That layered structure matters because no individual control catches every attack. Authentication can confirm that the correct device or account approved a transaction. It cannot always determine whether a criminal deceived the person holding that device.
Visa’s strategy therefore connects three distinct moments: the initial cyber intrusion, the manipulation of a target, and the resulting payment. The first major change is organizational as much as technical. Cybersecurity and fraud teams need shared evidence, faster escalation, and a common view of risk.
Why AI-Enabled Fraud Is Moving Toward People
Better network security is forcing attackers toward a target that cannot be patched like software: human trust.
Visa’s Spring 2026 Biannual Threats Report says its network blocked a 13% increase in unique enumeration attacks during the preceding six months. Enumeration is a card-testing technique in which criminals make repeated attempts to discover which combinations of account information remain valid.
Despite the higher attack volume, losses associated with enumeration fell 16%, according to Visa. The company attributes much of that improvement to suspected fraud blocked by its Risk Operations Center. Device-token fraud also declined 9.6% year over year.
Those results support Visa’s claim that network controls are improving. They do not mean the total threat is receding. Attackers are changing their methods when established routes become less profitable.
Visa identified nearly $1 billion in scam-related fraud attempts between July and December 2025. Its threat report describes a structural shift from technical compromise toward behavioral manipulation.
In a traditional account takeover, the attacker tries to impersonate the customer to the bank. In an authorized payment scam, the attacker persuades the real customer to complete the transaction. The payment can therefore pass checks designed to confirm account ownership.
Generative AI makes that deception cheaper and easier to personalize. Criminals can create grammatically polished messages, imitate familiar writing styles, generate fake websites, and adapt scripts for different targets. Synthetic audio and video can add another layer of apparent legitimacy.
AI does not need to invent a new category of crime to change the economics. A fraud group can use it to research more targets, produce more variations, and respond more quickly during a conversation. Even modest productivity gains become significant when applied across thousands of attempted scams.
Michael Jabbara, Visa’s senior vice president for payment ecosystem risk and control, said AI has lowered the barrier to entering fraud. His sharper point was that activity once requiring deeper technical skill can increasingly begin with a prompt.
Google Threat Intelligence Group has documented a similar development beyond payments. In May, it reported what it believed was the first observed threat actor use of an AI-developed zero-day exploit. A zero-day is a previously unknown software flaw that defenders have had no opportunity to patch.
The group’s AI threat tracker also describes generative models becoming integrated across reconnaissance, initial access, and malware operations. That evidence broadens the issue beyond better phishing copy. Attackers are beginning to apply AI throughout the attack lifecycle.
Still, social engineering remains especially attractive because it avoids a direct contest with hardened infrastructure. An attacker who cannot defeat tokenization or transaction encryption can pose as a bank employee. Another can impersonate an executive and create an urgent request for payment.
These methods exploit normal human behavior. People respond to authority, fear, scarcity, and time pressure. AI helps a criminal tailor those triggers using details gathered from breached data, public profiles, or earlier conversations.
This is why Visa’s security improvements contain an uncomfortable reversal. Success against one class of fraud can redirect activity rather than eliminate it. The stronger the technical gate becomes, the more valuable a believable story can be.
What the Google News Headline Leaves Out
The important contest is not simply AI against AI, but integrated defense against fragmented evidence.
The phrase “AI is enabling these attacks” captures the urgency, but it can obscure the practical challenge. Financial institutions already collect large amounts of security and transaction data. Their problem is often that the evidence arrives in different systems, under different ownership, and at different times.
A security operations team might see malware communicating with an employee’s computer. A brand-protection service might discover a fake banking website. A fraud team might later observe unusual transfers. Without coordination, each event can look less serious than the combined pattern.
Visa’s approach tries to turn its network position into an advantage. A single bank sees activity involving its customers and accounts. Visa can observe patterns spanning merchants, issuers, acquirers, regions, and payment channels.
That wider view helps identify coordinated attacks whose individual transactions appear ordinary. It also creates an opportunity to distribute defensive intelligence after a pattern emerges in one market. Visa describes this approach as detecting a threat once and defending against it globally.
The company says it invested $13 billion in technology and infrastructure during the five years leading into 2026. It also reports dismantling more than 25,000 scam merchants through Visa Scam Disruption, representing more than $1 billion in attempted fraud.
Visa’s network defense account says it blocked nearly twice as many fraudulent ecommerce transactions in 2025 as in the previous year. It also says the ecommerce fraud rate across its network fell 8%.
These are company-reported figures, not independent evaluations of every control. Still, they show the scale at which Visa is deploying automated defense. Machine learning can compare current activity with patterns drawn from a large payment network, often faster than a human analyst can investigate a single alert.
Speed has become the central mechanism on both sides. Attackers can automate target discovery, message generation, credential testing, and parts of exploit development. Defenders can automate risk scoring, pattern detection, and the distribution of indicators across institutions.
The difference is that defenders operate under tighter constraints. A criminal can send thousands of poor messages if only a few succeed. A bank must avoid blocking large numbers of legitimate customers while meeting regulatory, privacy, and operational requirements.
False positives therefore matter. A model that stops fraud but repeatedly declines genuine purchases can damage customer trust and increase support costs. An overly sensitive identity system can also create barriers for people whose behavior does not match a narrow historical pattern.
Defenders must also explain and audit important decisions. Financial institutions need controls for model access, data retention, escalation, and human review. They cannot simply deploy an AI model and assume that more automation produces better security.
Visa’s platform addresses another constraint: relevance. Security teams receive threat intelligence from many sources, but much of it may have little connection to their systems or customers. VTIP says it filters malware, vulnerability, brand, and identity signals for the financial sector.
That focus can reduce noise, but customers will need evidence that the intelligence changes outcomes. Earlier alerts only matter when an institution can investigate and act before money moves. Integration speed, staff capacity, and response procedures remain decisive.
The google news framing also risks presenting Visa’s work as a single product launch. It is better understood as a shift in where payment companies draw the security boundary. Fraud prevention now reaches backward into cybersecurity, identity protection, and online impersonation.
That expanded boundary puts Visa into a wider competitive field. Mastercard, banks, cloud providers, security vendors, and identity companies all analyze portions of the same attack chain. The contest centers on who can connect the clearest signals without creating excessive friction.
No organization sees everything. Telecommunications providers may detect fraudulent calls or text messages. Technology platforms can find fake accounts and malicious advertising. Banks understand customer behavior, while payment networks see transactions moving among institutions.
The winning model therefore depends on coordination, not one company’s dataset. Visa’s platform can improve the financial sector’s view, but scam prevention also requires action from social networks, domain registrars, telecom companies, law enforcement, and regulators.
Visa’s AI Defense Still Has a Verification Problem
Visa has credible scale, but its public figures do not establish how much AI uniquely contributes to each security improvement.
The company’s report combines several trends that need careful interpretation. Device-token fraud declined, enumeration losses fell, and Visa blocked more attacks. Those outcomes support a case for stronger controls, but they do not isolate the effect of AI from other changes.
Tokenization, authentication, network rules, analyst intervention, merchant controls, and law enforcement can all influence fraud rates. Visa’s security system uses multiple layers. Assigning an outcome to one model or platform would require more detailed measurement.
The threat data also comes from Visa’s own network and operations. That provides valuable visibility, but it does not represent every payment method, geographic market, or financial institution equally. Fraud displaced outside the network may not appear in the same metrics.
Visa reports that global ransomware activity rose 26% from July through December 2025 compared with the same period one year earlier. Only 23% of victims paid a ransom, which the company describes as the lowest rate on record.
The two numbers point in different directions. Criminals attempted more ransomware operations, while victims became less willing or less compelled to pay. Better recovery capabilities may explain part of that resistance, but attackers can still steal and expose data even when an organization refuses payment.
This pattern reinforces a distinction between prevention and resilience. An organization cannot assume that every intrusion will be stopped. It needs tested recovery processes, protected backups, clear decision authority, and communication plans for customers and partners.
The same caution applies to AI-generated cyberattacks. Google has documented a suspected AI-assisted zero-day, yet that does not mean autonomous systems now conduct most intrusions. Many criminals still use familiar phishing, credential theft, unpatched vulnerabilities, and established malware.
IBM security researchers have offered a useful counterweight to broader claims. Their malware analysis argues that current AI often improves attacker productivity without enabling fundamentally impossible techniques. The researchers identify impersonation and phishing as more immediate concerns than fully autonomous malware.
That distinction matters for defensive priorities. Organizations should not abandon basic controls while pursuing specialized AI products. Multifactor authentication, patch management, network segmentation, employee verification procedures, and incident recovery remain essential.
AI can also create new weaknesses inside defensive systems. Models can make mistakes, inherit biased data, expose sensitive information, or become targets themselves. Attackers may attempt prompt injection, which uses hidden or malicious instructions to manipulate an AI system’s behavior.
Security teams need to control which data an AI service can access and which actions it can take. A system summarizing threat reports creates limited operational risk. An autonomous service blocking accounts or changing infrastructure requires much stricter oversight.
Financial institutions must also decide how Visa’s intelligence fits existing tools. A new feed that duplicates current alerts may add workload instead of reducing it. The platform becomes valuable when its payment context helps teams prioritize threats they would otherwise miss.
Visa has not publicly provided broad customer outcome data for VTIP. The launch announcement says the company tested the platform internally, but internal validation is not the same as independent performance across varied banks.
Useful evidence would include detection lead time, false-positive rates, prevented losses, analyst workload, and the number of incidents connected across cyber and payment systems. Results should also distinguish model-driven findings from traditional rules and human analysis.
Another uncertainty concerns cross-border cooperation. Criminal infrastructure, victims, platforms, and financial institutions often sit in different jurisdictions. Sharing intelligence can encounter privacy requirements, inconsistent reporting rules, and delays in legal coordination.
Visa recognizes this fragmentation in its threat report. The company says consequential failures increasingly occur at ecosystem boundaries where incentives and visibility do not align. That diagnosis is persuasive, but resolving the boundaries requires more than a commercial platform.
Banks may hesitate to share sensitive incident information. Technology platforms can have different definitions of harmful activity. Smaller institutions may lack staff to investigate alerts quickly, even when the intelligence is accurate.
The critical test is therefore operational. Can the platform shorten the time between an early warning and a protective action? Can institutions act together without shifting fraud toward a less-protected participant?
Until those answers emerge, Visa’s claims should be treated as a strategic direction backed by meaningful scale, not final proof that the payment industry has solved AI-enabled fraud.
What to Watch After Visa’s Cybersecurity Push
Three signals will show whether Visa is closing the gap between detecting cyber activity and preventing financial loss.
The first signal is measurable adoption and performance for VTIP. Visa should provide customer examples showing how early cyber intelligence prevented a later fraud event. Detection speed and false-positive rates will matter more than the volume of collected indicators.
A strong result would show that an institution identified compromised infrastructure or impersonation before customers lost money. It would also demonstrate that analysts could act without disrupting large numbers of legitimate transactions.
The absence of those metrics would weaken Visa’s argument. Financial institutions already buy numerous security feeds, and another dashboard does not guarantee a faster response. The platform must improve prioritization, investigation, or coordinated action.
The second signal is the balance between scam growth and improvement in traditional fraud controls. Visa’s current data shows device-token fraud and enumeration losses declining while scams become more prominent. Future reports should reveal whether behavioral defenses can reproduce those earlier gains.
The most meaningful change would be a decline in scam attempts that reach payment authorization. That would suggest banks and payment networks are identifying deception before the customer completes a transfer.
A decline in reported losses alone would require context. Criminals might move to different payment methods, platforms, or institutions. Visa should explain whether its controls stopped the activity or merely displaced it.
Merchant data provides another useful check. The 2026 Global eCommerce Payments and Fraud Report found that 98% of surveyed merchants experienced at least one type of fraud attack during the previous year. However, the average number of attack types declined from 4.2 to 3.8.
Those findings show why a single trend cannot define the market. Some attack categories can fall while nearly every merchant still encounters fraud. Improvement must be measured across attack incidence, losses, operational cost, and customer friction.
The third signal is evidence about attacker use of AI. The key question is whether AI remains primarily a productivity tool or starts producing repeatable capabilities that bypass established defenses.
Google’s suspected AI-developed zero-day is an important marker. Similar cases would strengthen the argument that attackers are moving beyond faster research and better social engineering. Defenders would then face shorter patching windows and a larger pool of actors capable of exploiting unknown flaws.
If those cases remain rare, the immediate priority should stay focused on scalable impersonation, phishing, credential abuse, and manipulated payments. Those attacks already work, and AI can increase their reach without introducing a new technical method.
The distinction affects budgets. Security leaders must decide how much to invest in model-specific controls versus identity, recovery, staff training, and system integration. Fear-driven spending can leave familiar weaknesses untouched.
Visa’s strategy points toward a sensible foundation: connect signals earlier, analyze them at network scale, and treat deception as part of payment security. Its own data suggests that isolated technical controls cannot cover the full path from intrusion to fraud.
For consumers, the change means a valid account and trusted device no longer guarantee a legitimate payment. Requests involving urgency, secrecy, unexpected account changes, or unusual payment methods deserve independent verification through a known channel.
For businesses, payment approval procedures need to account for convincing impersonation. A voice, video, or polished message should not override established verification rules. High-risk changes should require confirmation through a separate system or person.
For developers, the story highlights the importance of designing security around workflows rather than individual model outputs. Systems should limit privileges, log sensitive actions, and preserve a route for human review. Those controls remain useful even when the attacker’s exact AI tools are unknown.
The next Visa threat report deserves attention beyond the google news cycle. It should indicate whether scams continue growing as technical fraud declines. It may also reveal whether earlier intelligence is producing measurable results across participating institutions.
Visa has identified the defining tradeoff clearly. Network defenses are getting better, but that progress redirects attackers toward people and organizational gaps. AI accelerates that migration by making deception easier to produce, personalize, and repeat.
The response cannot rely on AI alone. It requires better intelligence, disciplined verification, recovery planning, and cooperation across the systems criminals exploit. Watch the next customer results, fraud trends, and independently documented AI attacks. Together, those signals will show whether Visa is getting ahead of the shift or simply describing it faster.


