
Some cyberattacks that once took days or weeks can now unfold in minutes. Aditi Sawhney, Senior Vice President for Security Solutions at Mastercard, says organisations that concentrate security at the point of payment risk overlooking compromised credentials, phishing campaigns, and malicious domains that appear earlier in the fraud chain.
In an interview with Frontier Enterprise, Sawhney explains why fraud and cybersecurity teams need to connect their intelligence, reassess risk continuously, and share data quickly enough to disrupt attacks before money moves.
How is trust built in a real-time digital economy?
In a real-time digital economy, trust has to be built into every interaction, rather than checked only at the point of payment. This means knowing who is acting, whether they are authorised, what they intend to do, and whether the transaction fits its context.
As money moves faster, decisions about trust need to be made just as quickly, without creating unnecessary friction for consumers or businesses.
The aim extends beyond preventing fraud. Banks, merchants, businesses, and consumers also need the confidence to participate in digital commerce securely, without unnecessary friction, and at scale. Institutions that continuously assess identity, authorisation, intent, and context will be better able to support the growth of the digital economy.
How does AI change the economics of cybercrime?
AI is making cyberattacks faster, cheaper, more sophisticated, and easier to conduct at scale across borders.
We’re seeing the industrialisation of fraud, as generative AI turns it into an operation that can be automated and expanded. Criminal groups are increasingly operating as coordinated enterprises, using AI to automate phishing campaigns, generate convincing deepfakes, create synthetic identities, and continually refine their methods.
Activities that once took days or weeks can now be carried out in minutes. These are no longer necessarily isolated incidents: Attacks increasingly span multiple channels, institutions, and markets as part of coordinated fraud chains.
Consumers are already feeling the effects. According to the Global Anti-Scam Alliance, Asia-Pacific has become the world’s second most attacked region and accounted for more than two-thirds of global scam losses in 2024. In Southeast Asia alone, US$23.6 billion was lost to scams in 2025. Our global cybersecurity research found that 80% of respondents worldwide had experienced a scam attempt, including 88% of respondents in Singapore, during the same period. Nine in 10 Singapore respondents were also concerned about cyberattacks involving AI tools such as voice cloning and AI-assisted phishing.
Fraud is increasing and becoming more systematised. AI has shifted the advantage towards attackers, unless defenders can match their speed, connections, and intelligence when identifying and disrupting threats.
What capabilities are becoming essential for real-time detection and prevention?
Speed and intelligence have become essential.
Organisations that once had hours to make decisions may now have only milliseconds. To keep pace, they need connected intelligence across cybersecurity, fraud, identity, and transaction systems, rather than tools that operate independently. Effective defences combine real-time data, AI-assisted decisions, and continuous monitoring throughout the customer lifecycle, allowing organisations to reassess risk as threats evolve.
Attacks often begin with compromised credentials, phishing campaigns, or malicious domains, long before a fraudulent transaction occurs. Disrupting them in real time requires organisations to connect these early signals and act before financial losses occur.
However, the intelligence gap between cyber and fraud teams remains a challenge. A global study conducted by Datos Insights and commissioned by Mastercard found that 67% of fraud and risk executives in Asia-Pacific are notified of cyber breaches only after fraud losses have begun. It also found that 83% of financial institution leaders are frustrated by the lack of integrated, real-time cyberthreat intelligence.
Organisations therefore need to identify threats earlier and stop them before money moves through predictive, real-time detection and disruption.
Which trust and security approaches are outdated?
Many organisations still take a transaction-first view of risk and focus their security efforts on the moment of payment rather than the full digital journey leading up to it.
Traditional approaches often rely on static rules, known fraud patterns, and post-event analysis. These methods worked in slower environments but struggle to keep pace with fast-moving, multi-stage attacks.
This separation of cyber and fraud risks also reflects a broader legacy mindset. The same Datos Insights study found that 72% of fraud and risk leaders in Asia-Pacific cited operational silos as a top concern, indicating that fragmented models can restrict visibility and delay responses. Connected intelligence can help organisations anticipate threats and respond before losses occur.
Many institutions also define trust using predefined indicators or historical behaviour. Trust is now more dynamic and must be continually evaluated in context across identities, devices, behaviours, and ecosystems.
An integrated, intelligence-led model assesses trust continuously and bases decisions on connected signals from across the lifecycle. This allows organisations to respond faster and make more confident, real-time judgements about risk.
How can data sharing combat fraud and cybercrime?
No single organisation has enough visibility to stop modern fraud alone. Today’s threats cross organisational boundaries, moving among banks, merchants, technology platforms, payment networks, and jurisdictions. This means data has to work as a network.
Sharing intelligence among financial institutions, merchants, platforms, and law enforcement agencies can help them detect patterns earlier and identify threats that no single participant could see alone. A bank may notice suspicious account activity, a merchant may detect unusual behaviour, and a cybersecurity team may identify a malicious domain. Those signals may appear unrelated individually but, when combined, can reveal a coordinated attack much earlier.
Connecting cyber and fraud signals can help organisations disrupt attacks earlier, reduce losses, and coordinate their responses across institutions and borders. This is increasingly important as fraud operations become more organised, cross-border, and enabled by technology.
The Datos Insights study cited earlier found that 81% of financial institutions investing in cyber-fraud integration reported faster threat responses, while 89% of institutions in Asia-Pacific reported faster fraud responses after integration.
Criminals already collaborate and share information at scale. Legitimate organisations therefore need to connect their intelligence at a similar scale. Sharing trusted intelligence quickly can make it harder for criminals to move money.
Data sharing is therefore a critical capability. It connects otherwise isolated defences and can strengthen trust and resilience across the digital economy.















