TAMPA, Fla. — The biggest fraud risk facing credit unions in 2026 may not come from hackers breaking in — but from members themselves unknowingly (or sometimes knowingly) helping fraud happen, according to Karen Postma, senior vice president of risk solutions at Velera.
That shift — what Postma describes as the rise of “consumer-engaged fraud” — is forcing a fundamental rethink of how fraud detection works. For years, fraud systems have been designed around a simple assumption: if something looks suspicious, ask the consumer.
But as scams, first-party fraud and intentional misuse blur together, she argues that reaching out to the cardholder is no longer always the safest move. In many cases, the consumer is already part of the transaction flow, whether as a victim manipulated by scammers or as an active participant exploiting loopholes.
“We’ve built all our models around getting to the consumer as quickly as possible,” Postma said. “But when the consumer is engaged, that methodology has to change.”
The Fraud Shift Few Expected
Postma traces the trend back to the post-pandemic migration from card-present to card-not-present commerce. As online transactions surged, confusion over merchant names, digital billing and returns created openings that some consumers initially exploited unintentionally. Over time, she said, those behaviors evolved.
Consumers, Postma explained, learned what dispute processes would allow — and, in some cases, what they could get away with. On the merchant side, return fraud became a growing issue, with customers returning used goods or manipulated shipments. On the issuing side, similar behavior appears as first-party fraud, where legitimate cardholders falsely claim transactions are unauthorized.
Compounding the issue are online “teaching” websites that walk consumers through dispute tactics and chargeback strategies. Postma noted that some younger consumers view these actions as harmless, framing them as pushing back against large financial institutions rather than committing theft. Meanwhile, scam operations have become more sophisticated, leveraging advanced technology, AI-generated content and global communications infrastructure to make fraud feel more credible and harder to detect.
The result, she said, is an environment where traditional fraud signals no longer tell the full story.
Why Old Models Break Down
Historically, fraud detection has relied on transaction patterns, Postma reminded. If a member suddenly buys expensive furniture or makes a large withdrawal, systems flag it and send a verification alert. But in scam situations, that process can backfire.
“A consumer might be told by a scammer to buy gift cards or withdraw cash,” Postma explained. “When we ask, ‘Did you make this transaction?’ they say yes — because they did.”
That creates a blind spot. Instead of validating transactions through quick alerts, institutions increasingly need systems that distinguish between third-party fraud and scenarios where the member is being manipulated, Postma said.
In suspected scam situations, Postma argued, credit unions may need to pause activity, involve trained staff and treat the event more like a counseling interaction than a traditional fraud call.
She emphasized that the psychology is delicate. Telling someone outright they are being scammed often triggers defensiveness. Effective intervention requires trained agents who understand how to guide conversations without confrontation — a major cultural and operational shift for credit union fraud teams.
Velera’s Multi-Year Infrastructure Bet
Responding to these shifts, Velera has spent the past three years building a new fraud-risk ecosystem designed to be more flexible and adaptable than traditional platforms. The company began rolling out components in 2025 and plans broader deployments in 2026.
One early use case involves balance consolidation requests — transactions that previously required manual review. Under the new system, alerts and validation workflows can happen in near real time, with some interactions triggered in less than a second. The platform is expanding to include data from 3-D Secure and authorization streams, creating a unified view of risk across channels.
Postma said the company is also launching a standardized credit union alerting platform aimed at delivering consistent notifications to both credit unions and members. Standardized messaging, she said, may help members better recognize legitimate communications and reduce susceptibility to impersonation scams.
The underlying goal is agility. Fraud trends evolve quickly — from collusive schemes involving both issuing and merchant accounts to emerging threats tied to new commerce models — and static rules are no longer enough.
Fraud Trends Credit Unions Should Watch In 2026
Looking ahead, Postma believes credit unions should focus on three key trends:
1. Continued growth of consumer-engaged fraud.
Scam participation — whether intentional or manipulated — will likely rise, requiring fraud programs to balance security with member experience and counseling skills.
2. Collusive fraud ecosystems.
Fraud increasingly involves coordinated activity between multiple accounts and channels, making isolated transaction analysis less effective.
3. Agentic commerce and AI-driven transactions.
As autonomous purchasing technologies enter mainstream commerce, Postma expects fraudsters to exploit consumer confusion around how these systems operate.
Education, she said, will be critical. Credit unions that train staff and members early on emerging technologies may reduce vulnerability before bad actors capitalize on uncertainty.
A Strategic, Not Just Operational, Issue
For credit unions, the implications extend beyond fraud losses. Consumer-engaged fraud challenges long-held assumptions about trust, member behavior and the role institutions play in protecting people from increasingly sophisticated manipulation, she said.
Postma’s broader message is that fraud prevention is no longer just about stopping outsiders — it’s about understanding how consumer behavior itself is evolving.
“The weakest link isn’t always a third party anymore,” she said. “Fraud has evolved, and we have to evolve with it.”
In 2026, that evolution may require credit unions to rethink not just their tools, but their philosophy — shifting from simple transaction verification toward a more nuanced, human-centered approach to risk.
