By Ray Birch
CHICAGO—As digital fraud grows more sophisticated, credit unions are facing a tougher version of an old problem: how to stop more fraud without piling on the kinds of login hurdles, step-up checks and false positives that frustrate legitimate members.
That tension is becoming more acute as fraudsters use automation, AI and stolen identity data to attack the full member lifecycle—from account opening to login to payments—pushing credit unions toward more passive, behavior-based tools that can spot risk in the background rather than forcing members through more hoops. TransUnion is the latest to argue that the next phase of fraud defense will hinge less on adding friction and more on improving precision.
That broader shift matters because the numbers are moving in the wrong direction. TransUnion said suspected digital fraud represented 5.4% of all transactions in 2024, while its H1 2025 Omnichannel Fraud Report found suspected digital account-takeover attempts rose 20% globally from 2023 to 2024 and that financial transactions suspected to be digital fraud climbed 11% year-over-year.
In a separate H2 2025 fraud update, the company said digital account takeover rose 21% from H1 2024 to H1 2025 and 141% since H1 2021, underscoring how quickly credential-based and session-level attacks are scaling.
In an interview with CUToday.info, Clint Lowry, TransUnion’s VP and head of global fraud strategy, said that for credit unions the real challenge is no longer simply recognizing that digital fraud is rising—it is finding ways to respond without damaging the member experience.
Lowry said fraudsters are “constantly looking for ways to attack digital channels across the entire consumer lifecycle,” including account origination, account takeover and money movement, while many traditional fraud tools remain too invasive. He said some controls may reduce losses but also make it harder for legitimate members to open accounts, log in or complete transactions, creating the constant balancing act between fraud prevention and member friction.
That is the context behind TransUnion’s latest upgrade to its Device Risk platform, which the company describes as a significant enhancement—not a brand-new product—to a long-standing category of device intelligence tools. Lowry said the changes are designed to improve recognition of returning devices even as browsers and privacy settings evolve, better distinguish human activity from bots and other automated traffic, add more consortium-based device reputation signals, and use adaptive machine-learning models trained on thousands of device signals and fraud feedback.
TransUnion said the updated models can improve fraud capture by up to 50% while reducing the volume and complexity of manually maintained rules, which in turn can lower false positives and operational drag.
No High-Friction Checkpoints
That matters for credit unions because device-based detection can be deployed passively across the full member journey—at account opening, login, account management and payments—rather than relying solely on high-friction checkpoints, Lowry explained.
Still, the bigger takeaway for credit unions is not any one vendor’s enhancement but the direction the market is heading. Fraud teams increasingly need layered signals—device, identity, behavior, consortium intelligence and anomaly detection—because fraudsters are getting better at looking like legitimate users, Lowry noted.
Lowry said traditional device fingerprinting has been weakened by privacy-driven technology changes and by tactics that let fraudsters appear as “new” users “with just a few clicks,” a dynamic that makes static rules less effective.
That is also why credit unions are likely to hear more about “passive” fraud controls: tools that quietly evaluate device trust, behavioral anomalies and session risk in real time, then reserve step-up authentication or manual review for the riskiest interactions instead of treating every member like a suspect, Lowry added.
For credit unions, that may be the most important strategic shift of all. Members increasingly expect fast, low-friction digital experiences, but they also expect their credit union to stop scams, account takeovers and synthetic fraud before losses occur.
The institutions that perform best are likely to be those that stop thinking of fraud controls as a choice between security and convenience and instead invest in more accurate, context-aware detection that applies the most friction only where risk justifies it. As Lowry put it, the goal is straightforward: better detection, fewer false positives and less hassle for members.
