Banking · 5 October 2026
Beware the smartphone security threat — new report claims most banking scam attempts now take place on mobile devices
90% of scams are taking place via mobile phone, with banking scams increasing of 35% over the previous year
What happened
A new industry report finds that mobile devices have become the primary channel for banking scams, with smartphones now accounting for roughly 90% of scam attempts tracked. The same research points to a sharp rise in banking-specific fraud, up 35% year-on-year, underlining how quickly scam activity is migrating from desktop and in-branch channels to the phones customers carry everywhere.
The findings, reported by TechRadar, suggest that fraudsters are deliberately targeting the mobile banking experience — the apps, SMS messages and push notifications that have become the default way millions of people manage their money — rather than relying on older channels such as email or desktop phishing.
Why it matters
For banks and fintechs, the shift confirms that mobile is no longer just the preferred channel for everyday banking — it is now the preferred channel for attacking that banking relationship too. Security and fraud teams built around web and card-based threat models may be under-equipped for an environment where the attack surface is the same screen customers use to check their balance or approve a payment.
This is as much an experience and trust problem as it is a technical one. Every scam that succeeds on a banking app erodes confidence not just in that institution, but in mobile banking as a category — at precisely the moment most banks are pushing customers toward self-service, app-first engagement.
By the numbers
- 90% of scam attempts identified in the report now occur on mobile devices.
- 35% year-on-year increase in banking-related scam activity.
The Renascence take
Most fraud reporting treats this as a pure security story — patch the vulnerability, educate the user, move on. That misses the behavioral design question underneath: mobile banking interfaces are built for speed and frictionless convenience, and scammers are simply exploiting the same cognitive shortcuts banks spent years training customers to use.
The real lesson here isn't "add more warnings" — customers already ignore those. It's that banks have optimised mobile journeys so heavily for low-friction convenience that they've also lowered the friction scammers need to succeed. The fix is behavioral, not just technical: introduce deliberate, well-timed friction at the moments scam patterns actually occur — unusual payee, urgent transfer, late-night login — rather than blanket pop-ups customers have learned to dismiss. Institutions that treat fraud prevention as a core part of the mobile experience, not a bolted-on security layer, will protect both customer funds and trust in the channel itself.
Sources
This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
More in Banking
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.
