MAGNUSContact
← All posts
Practical Application

Fraudsters Are Recruiting Your Employees, Not Just Hacking Your Systems. Here's Where AI Fits In

Sophia JungSeptember 4, 2026

Most fraud prevention conversations start from the assumption that the threat is external: a hacker, a scammer, a stolen card number. A newer, quieter problem is growing alongside that one, and it starts on the inside. Fraud syndicates and organized crime rings are increasingly recruiting frontline bank and credit union employees to do the work for them, according to Lenny Gusel, North American head of fraud solutions at fraud mitigation provider Feedzai.

The mechanics, per Gusel, are usually simple. A fraudster contacts an employee and asks for something that looks small in the moment: pull a customer's personal information, lift a freeze on an account, or send a password reset that the fraudster then intercepts. None of it requires technical sophistication. It requires an employee willing to do it, often because they're under financial pressure and the ask feels low-risk compared to the payoff.

The number that makes this a genuine institutional problem, not an edge case

This isn't a rare scenario dressed up to sound scarier than it is. The ACFE's Occupational Fraud 2026 report found that the median internal fraud loss to banks between September 2025 and April 2026 was $100,000, with the average loss reaching $1.5 million. Those numbers reflect fraud that made it through existing controls, which is exactly the population you'd expect insider-recruited schemes to hide inside, since the employee involved already has legitimate system access and isn't triggering the alerts built to catch outside intruders.

Why this is genuinely hard to catch with traditional controls

Standard fraud detection is built to flag unusual behavior from an account or a device that doesn't belong to your institution. An employee using their own valid login, in their normal work hours, to pull up a customer record they'd normally have a reason to access, doesn't look unusual to that kind of system. That's precisely the gap insider recruiting is designed to exploit.

Where AI genuinely helps, and where it doesn't

This is one of the clearer cases where AI-powered monitoring adds real value rather than marketing gloss. Behavioral and access-pattern analysis, the kind that learns what normal looks like for a specific employee's role, can flag a departure from that pattern (an employee pulling records for accounts outside their normal book of business, or removing holds at an unusual frequency or time) even when every individual action would pass a manual review. That's a genuinely different capability than a rules-based system checking a fixed list of red flags.

What AI doesn't do is replace the harder, more human part of this problem: a workplace culture where a financially stressed employee has somewhere to go before a stranger's offer starts looking reasonable. The technology closes the detection gap. It doesn't close the reason the gap gets exploited in the first place.

What this means for your credit union

If your fraud monitoring today is built entirely around external threats, that's worth revisiting with your risk or compliance team, specifically asking whether your current tools would catch a trusted employee's own valid login being used slightly outside its normal pattern. If the honest answer is "probably not," that's a concrete, fixable gap, and one worth closing before it becomes the kind of six- or seven-figure loss the ACFE numbers describe.

Sources

About the author

Sophia Jung is the founder of Magnus, with a background in full-stack engineering and business intelligence leadership across the automotive and credit union industries.

More about our founder →