The Shifting Frontline: How Navy Federal Credit Union is Pivoting from Fraud to the Scourge of Scams

the-shifting-frontline-how-navy-federal-credit-union-is-pivoting-from-fraud-to-the-scourge-of-scams

In the evolving landscape of financial crime, the traditional battle against unauthorized account access is undergoing a fundamental transformation. For years, financial institutions have poured billions into sophisticated cybersecurity, biometric authentication, and anomaly detection to stop bad actors from breaking into accounts. These efforts have yielded significant results. However, as the digital fortress surrounding bank accounts has grown increasingly impenetrable, criminals have simply changed tactics. They are no longer breaking in; they are tricking the owners into opening the door.

Carrie Foran Sepulveda, vice president of fraud and physical security at Navy Federal Credit Union—the largest credit union in the United States—describes this phenomenon as "squeezing the crime balloon." As institutions close off one avenue of theft, the pressure forces criminal energy into new, more insidious channels. Today, that channel is the rise of sophisticated, social-engineering-based scams.

The Anatomy of the New Threat: Fraud vs. Scams

To the average consumer, the experience of losing money to a criminal may feel identical regardless of the method. Whether a thief steals login credentials or a scammer convinces a victim to authorize a wire transfer under false pretenses, the result is a depleted balance. However, from the perspective of financial security experts, these are two entirely distinct categories of warfare.

"The puzzle for fraud is really straightforward compared to scams," Foran Sepulveda explains. "We’ve done a ton of work on fraud. We have great defenses."

Fraud typically involves a third party attempting to masquerade as the account holder. Financial institutions use a robust array of data points—device fingerprints, IP geolocation, behavioral biometrics, and velocity checks—to detect these intrusions. If the login pattern deviates from the norm, the system triggers an alarm, and the transaction is blocked.

Scams, by contrast, present a unique, high-stakes dilemma. In these scenarios, the customer is the one taking action. They are the ones initiating the wire, withdrawing the cash, or providing the authorization. When a customer is convinced they are speaking to a government official, a law enforcement officer, or a trusted advisor, they often bypass security protocols voluntarily. This makes detection incredibly difficult because the transaction appears legitimate to the bank’s traditional security algorithms.

"For the most part, it’s a totally different set of signals, data, and tools," Foran Sepulveda notes. The challenge for institutions like Navy Federal is to distinguish between a customer exercising their autonomy and a customer who has been psychologically manipulated.

Chronology of a Strategic Shift

The realization that scams were outpacing traditional fraud prompted a major strategic pivot at the $204 billion-asset credit union.

2024: A Turning Point
Throughout 2024, Navy Federal observed a significant divergence in crime patterns. While traditional unauthorized fraud attempts began to decline—dropping by roughly 25% by early 2025—the volume of consumer-authorized scams began to climb. The credit union recognized that its historical defense-in-depth strategy was highly effective against technical breaches but ill-equipped for the psychological warfare of modern social engineering.

January 2025: Deploying AI Against the Scammers
Acknowledging that manual intervention could not scale to meet the volume of modern scams, Navy Federal initiated a partnership with Cube AI. This partnership marked a shift from passive monitoring to offensive defense.

The strategy involved deploying AI-driven "honeypot" bots. These bots are programmed to pose as potential victims, engaging scammers in conversation. When the scammers inevitably reach the stage of the interaction where they demand funds, they provide the bank accounts or payment handles to receive the money. The AI captures this data and feeds it directly into Navy Federal’s risk engine.

Mid-2025 to Present: Real-time Interdiction
With this data, the credit union can identify specific accounts that are confirmed "hot" or compromised. Rather than guessing whether a member is being scammed, the credit union now has concrete, actionable intelligence. They use this data to warn members in real-time, preventing transfers to accounts known to be controlled by criminal syndicates.

Supporting Data and Technical Efficacy

The results of this strategic pivot are measurable and significant. Navy Federal reports that its multi-faceted approach to scam prevention has successfully interdicted approximately $125 million in potential losses over the past 19 months.

How Navy Federal harnesses AI to confront scam activity

This success is not attributed to a single tool but to a layered ecosystem of defense. By working in tandem with the Global Anti-Scam Alliance, social media platforms, and law enforcement agencies, Navy Federal has broadened its intelligence network. The integration of Cube AI has proven particularly transformative, as it moves the institution away from "hunches" based on behavioral anomalies toward data-backed confirmation.

"This is getting true data to say, ‘this is a scam account,’" says Foran Sepulveda. By validating that an account is indeed linked to a fraudulent operation, the credit union can confidently intercede in transactions that would otherwise have gone through.

Policy Shifts and the Legal Landscape

Perhaps the most controversial, yet necessary, aspect of Navy Federal’s strategy is its stance on "refusal to facilitate." In the past, when an institution suspected a scam, the standard procedure was to provide a warning. If the customer insisted, the bank would require the member to sign an affidavit acknowledging the risk, and then proceed with the transfer to avoid liability.

Following a period of legal scrutiny and a related lawsuit, Navy Federal abandoned this practice. They have adopted a much more proactive, protective stance: if their systems determine with high certainty that a transaction is the result of a scam, they will refuse to process it.

"If I feel that sure that you shouldn’t have done it, at some point, we need to not do it," Foran Sepulveda states. "That was a big change, but we’ve rallied around it."

This shift has created a new set of tensions regarding the balance between consumer autonomy and institutional protection. While the credit union is acting in the best interest of its members, the regulatory framework remains somewhat ambiguous.

Implications: The Road Ahead

The battle against scams is far from over. As financial institutions deploy AI to protect their members, criminals are simultaneously using generative AI to create more convincing impersonations, realistic deepfake voices, and highly personalized phishing campaigns.

Foran Sepulveda emphasizes that this is an arms race: "It’s going to create new, novel threats, and we’re also going to have new, novel solutions."

However, the primary hurdle may not be technological, but legal. To effectively stem the tide of losses, Foran Sepulveda advocates for clearer "rules of the road" regarding financial institution rights. Currently, if a member insists on withdrawing their funds as cash—even if the credit union suspects a scam—the institution has limited legal standing to withhold those assets.

"What can we do to hold funds when we think that something looks suspicious?" she asks. "If we won’t send the wire, but if they say they want a cashier’s check for their balance, there’s nothing we can do. We don’t have the right to withhold their funds from them."

The industry is now looking for a "safe harbor" provision—a regulatory framework that would provide banks and credit unions with the legal protection to pause or freeze suspicious activity without the fear of litigation from customers who may not yet realize they are being victimized.

As the financial services sector continues to adapt, the lesson is clear: the era of purely technical defense is over. The future of financial security lies in a hybrid model—one that combines advanced AI-driven intelligence with clear, empowered policy-making that prioritizes the long-term safety of the consumer over the speed of the transaction. For Navy Federal, the mission is no longer just about securing the account; it is about protecting the member from the most sophisticated threats of the digital age.