Scam Prevention Without Surveillance: Why the Next Frontier of Data Security Sits on the Customer’s Device

Boaz Valkin, Co-Founder, Falkin

Banks have spent two decades hardening the perimeter. Device intelligence, identity verification, behavioral biometrics, and transaction monitoring have all matured into serious, wellfunded disciplines. And yet scam losses keep climbing, because the modern scam does not attack the perimeter at all. It attacks the person. The victim is an authenticated customer, on their own device, following instructions they believe to be legitimate, often from someone impersonating the very institution trying to protect them.

This creates an uncomfortable truth for anyone responsible for fraud or data security strategy: the only actor who sees the full threat, across every channel, is the end consumer. The scam begins on Instagram, in a text message, on a marketplace listing or in a spoofed phone call, long before any bank system has a signal to work with. By the time the payment instruction arrives, the manipulation is complete and every downstream control is fighting the customers own conviction.

The instinctive response is to collect more. More telemetry, more message content, more browsing behavior, more of the customers digital life pulled into the institutions data estate so that models have something to work with. I want to argue that this instinct is wrong, and that it is wrong specifically as a matter of data security.

The surveillance trap

Every byte of customer communication a bank ingests becomes a liability the moment it lands. It has to be secured, governed, retained, audited, and eventually defended in front of a regulator or a breach notification letter. Message content is among the most sensitive data that exists: it contains health information, relationships, finances, and the private texture of peoples lives.

Building scam detection on top of centralized content collection means solving one risk by manufacturing another, and the second risk compounds forever.

There is also a trust problem. Scam prevention only works if customers opt in and stay in. A protection feature that reads as surveillance will see weak enrollment, quiet uninstalls, and reputational drag. Customers are being asked to trust their bank at precisely the moment criminals are impersonating that bank daily. The protection itself cannot become another reason for suspicion.

Think “extreme” shift left and be privacy 1st

The alternative is architectural rather than cosmetic: move the intelligence to the data instead of moving the data to the intelligence. Recent platform shifts have made this practical. Antitrust pressure has forced mobile operating systems to open APIs that allow protective extensions to run at the OS level, and small language models have become efficient enough to perform real analysis on the device itself.

That combination changes what is possible. A malicious link can be blocked before the browser loads it. A message can be assessed for manipulation patterns, urgency, impersonation, and coercion cues, without the content ever leaving the phone. What travels back to the institution is a risk outcome, not a transcript. The bank never learns which websites its customer visited or what their messages said, and neither does the vendor. The protective effect is achieved while the sensitive data stays exactly where the customer put it.

This is data security in its most literal form: the strongest control over customer data is never to hold it, while achieving the desired product outcome

Prevention beats detection

No one likes to be told what to do, least of all a customer who has been carefully convinced that the opportunity in front of them is real. A generic warning screen asking are you sure?” gets clicked through, because the scammer has already scripted the answer.

What works is evidence, delivered in plain language, at the moment of decision. Show the customer that the investment site was registered eleven days ago, that the listing they trusted redirects somewhere else, that the message they received matches a known impersonation pattern. Then let them choose. Giving people specific, contextual reasons respects their agency, and in practice it is far more effective at interrupting the psychology of a scam than friction alone. The goal is to break the manipulation.

The same logic applies upstream of the payment journey. Inviting customers to check a URL, a screenshot, or a document before they act turns the institution into an ally in the customers own judgment rather than a gatekeeper at the end of it.

The regulatory direction is already set

The UK moved first on authorized push payment reimbursement, and the pattern is repeating elsewhere. But waiting for a mandate misses the point. Liability frameworks decide who pays after the harm; they do nothing for the customer whose savings are gone and whose trust in digital banking is broken. Institutions that act now, with architectures that protect people without surveilling them, will find they have built something regulation cannot require and competitors cannot quickly copy: customer trust that is earned at the exact moment it matters most.

The industry has proven it can secure data behind the perimeter. The next test is whether we can protect the people outside it without asking them to hand over their digital lives in exchange.

Hot Topics

Related Articles