In the second quarter of 2026, 2.74 billion rubles were stolen from bank clients through the Fast Payments System (FPS) — a record amount since observations began. Banks managed to return only 2.1% of this money, with over 129,000 theft incidents recorded — almost three times more than a year earlier. Compared to the first quarter, the damage increased by 4%, and on an annual basis — by 25%.
Meanwhile, other channels of theft show the opposite trend. Losses from bank cards amounted to about 1.3 billion rubles — 17% less than a year earlier, and the share of funds returned to clients here reached 13.3%. Remote banking services saw 2.17 billion rubles stolen, which is 7% lower than last year's figure. As a result, the total volume of transactions without the voluntary consent of clients did not exceed 7.4 billion rubles with 458,700 recorded cases, and banks during the same period repelled 17.5 million attempted thefts totaling about 1.9 trillion rubles. The share of compensation for victims across all segments increased to 7%.
Why Cards Are Better Protected Than Transfers
The reduction in thefts from cards and accounts is largely related to the "cooling-off period" mechanism: a bank has the right to suspend a suspicious transfer for up to two days based on signs approved by the Bank of Russia and warn the client. After reconfirmation, the transaction is executed — but only if the recipient's details are not in the database of fraudulent accounts. For card payments, there is also a chargeback mechanism that allows disputing a transaction retroactively: the card infrastructure has been improving for years, and the reduction in thefts through this channel seems a natural outcome of this work. An additional role is played by the fact that in a transfer, funds are first blocked on the sender's card, not immediately debited — this gives the bank time to prevent fraud and return the money.
The FPS is structured differently. The transfer goes directly to an individual's account or an intermediary's account, after which the funds are often split into smaller amounts and moved further along the chain. Such transfers are instant, and there is no chargeback equivalent for them — money can only be returned with the recipient's consent or through the court. The service was initially created to be as fast and convenient as possible, so fraud protection became a secondary task: the client initiates the transfer themselves, and the bank merely executes the operation instantly without the possibility of a rollback, which is exploited by criminals using social engineering.
Social Engineering Gains Momentum
The vulnerability of the FPS is directly linked to the growth of attacks using social engineering methods: in the second quarter, their number reached 28,700 — a two-year high. This is almost one and a half times more than the previous quarter and more than double the figure from a year ago. Since the client themselves initiates the FPS transfer, criminals bet precisely on persuading the victim, not on hacking technical protection.
The Regulator Changes the Rules
Part of the effect on cards and accounts is related to new requirements for banks. Since the beginning of the year, the list of signs of fraudulent operations has been expanded from 6 to 12 items, including suspicious transfers to oneself via FPS before sending funds to third parties.
At the end of June, Russian President Vladimir Putin signed the second package of anti-fraud measures — the "Anti-Fraud 2.0" system, which changes the rules for banks and telecom operators. The key innovation is the expansion of banks' powers: if the system detects signs of a client's device being infected with malware, the credit institution will have the right to suspend a transfer or completely refuse to execute it. The law also introduces a compensation mechanism for victims of fraud if a bank or telecom operator violates the established requirements for preventing theft — provided that the client did not transfer money to the criminals independently. The norms come into force gradually, with the main block from 2027.
AI Opinion
From the perspective of machine data analysis, the Russian case is not unique: a similar vulnerability of instant payments has manifested in Britain, where Faster Payments remained the main channel for fraudsters using social engineering for many years. After the introduction of mandatory compensation for victims from October 2024, the regulator recorded a decrease in losses through this channel by about 21%, and the share of compensated cases increased from 54% to 65%. This shows that shifting financial responsibility to banks can change system behavior faster than technical restrictions alone.
The British experience also demonstrates the downside: even after the reform, the scheme covered only about a tenth of all the country's payment transactions, leaving cards and other channels unprotected. Russia's "Anti-Fraud 2.0" is coming into force gradually and covers a wider range of operations — the question is whether the expanded responsibility of banks will lead to a similar gap between protected and unprotected payment channels.
end-content





