Financial institutions are looking to data-sharing consortiums to defend against financial crime as consumer fraud losses reached nearly $9 billion in 2022 and generative AI is enabling fraudsters to scale their operations exponentially.

Consortiums new to market, including Plaid’s Beacon and Sardine’s SardineX, aggregate vast amounts of user information into databases that enable them to evaluate fraud risk in real time, proactively identifying fraudulent users within FI operations.
However, this model of third-party providers has some FIs raising concerns about the handling and security of consumer data, Ryan Schmiedl, global head of payments, trust and safety at JPMorgan said at Fintech Connect North America last month.
The risk is that consortiums could “turn [the data] against” FIs or “commercialize it, or they’re going to put [FIs’] reputation … [or] clients at risk,” Schmiedl said.
On the other hand, digital bank Brex looks to industry peers for risk management collaboration rather than competition, Camilla Matias Morais, Brex’s senior vice president of operations, told Bank Automation News today.
“When you think about fraud, everyone is combating the same fraudsters,” she said.
Despite agreement on the need for teamwork, the growing anti-fraud data-sharing space is divided by contradictory views as to which techniques should be used, what data-sharing structure would best serve FIs and whether private groups or the government should hold access to the data.
Account blacklists
One tactic that has raised red flags among FIs as potential consortium overreach is the account blacklist, which aggregates identifying information of potentially fraudulent users on FI platforms.
While sharing these blacklists across FI member platforms could help defend against repeat fraud attacks, it also carries the risk of punishing users who have their identities stolen or make foolish but low-stakes decisions, Maria Christina Kelly, head of payments and fraud at Caesar’s Digital, an online gambling website, said at Fintech Connect North America.
“The identity that’s stolen belongs to a real person — they need to do things,” Kelly said. She gave the example of a customer who has had their identity stolen on one platform and then is blocked on other platforms, preventing them from making an important purchase like a new car.
Every industry has specific needs and may not be well served by a one-size-fits-all approach, said Kelly, who joked that “great customers in my [gambling] vertical aren’t such great customers at banks.”
Kelly instead stressed the utility of sharing generalized behavioral patterns over specific accounts, a sentiment echoed by Nate Vanderheyden, executive director of U.S. banks cyber and information security at Morgan Stanley.
“We need to be talking more about tactics, techniques, procedures, trends that we’re seeing,” Vanderheyden said at Fintech Connect North America. “As [fraudsters] go from financial service to financial service, you’re not going to see the same IP addresses.”
Government intervention?
In response to concerns about aggregation of data in private hands, some FIs have called for a solution that would put their consortium colleagues out of business: government intervention.
However, other FIs, including Boston-based Metro Credit Union, have questioned the government’s ability to perform on the same level as the private sector, and express concern that “creative problem solving and resourcing could be an issue if we go in that direction,” Metro Chief Operating Officer Traci Michel told BAN.
Despite this, Metro recently announced its participation in a consortium by fintech FiVerity, which collaborates extensively with regulatory agencies, including the Federal Reserve and the Financial Crimes Enforcement Network on a set of shared objectives.
“The government is not in the business of creating innovative solutions, right? We fintechs are,” FiVerity Chief Executive Greg Woolf told BAN. “That’s why they host tech sprints, right? To get the best ideas from the market.”
The Fed recently convened a working group of more than 20 established and newer fintechs to discuss best practices for fighting fraud, Woolf said. And while he is not looking to turn his company’s data over to regulators, he does see a role for the government in facilitating cooperation among consortiums.
“The last thing we need is to create more silos,” he said, adding that there is a shared desire between government, industry players, and some FIs to “figure out a way to work together.”
In the meantime, some responsibility for fighting fraud will remain with the FIs themselves, Schmiedl said.
“We understand [FIs] all kind of have their own biases and their own perspective. We need to basically put our own oversight on until we get to that utopian solution.”






