
Visa's $2.4B BioCatch acquisition targets fraud before payments move, adding behavioral intelligence to counter account takeovers and authorized push payment scams.
Visa said Monday it agreed to buy behavioral-intelligence provider BioCatch for $2.4 billion in cash, a deal that moves payment security beyond the transaction itself and into the digital session that precedes it.
The acquisition gives Visa access to thousands of signals generated while a customer uses a banking app: typing rhythm, device handling, mouse movement, navigation patterns. Those details help distinguish a legitimate customer from an attacker who has taken over an account, or from a genuine account holder being manipulated by a scammer. BioCatch protects 760 million users across 1.8 billion devices and serves more than 350 financial institutions in 21 countries.
The purchase follows Bank of America's July 30 announcement that it plans to acquire MDSec Consulting, an England-based information security specialist. Bank of America is buying technical expertise. Visa is buying behavioral intelligence. Both moves suggest the largest financial institutions no longer treat cybersecurity as a defensive utility that can be assembled from standardized external tools.
Traditional payment fraud systems assess a transaction once it has been initiated, examining amount, merchant, location, device and historical spending pattern before deciding whether to approve, decline or challenge. That approach misses a growing share of fraud. Account takeover attacks give criminals control of legitimate credentials and devices. Authorized push payment scams persuade actual customers to approve transfers themselves. Money mule networks use accounts that appear legitimate until behavioral patterns reveal unusual intent.
PYMNTS Intelligence, in collaboration with Visa DPS on "The Issuer Risk Playbook," found that 42% of bank and nonbank issuers rank fraud and disputes as either their biggest or second-biggest platform-related operating cost after employees. Roughly 60% of issuers across customer lifetime value tiers are either deploying or enhancing AI-powered card fraud detection and prevention, a sign that the capability is becoming a basic requirement of modern issuing.
AI is compressing the time between discovering a vulnerability and exploiting it. At the same time, financial firms are embedding data and payment capabilities into more third-party applications, APIs and automated systems. The attack surface is expanding in both directions. Criminals can operate faster, while legitimate financial activity becomes more distributed.
The PYMNTS Intelligence report "Scale Amplification: How Revenue Amplifies Agent-Driven Identity" showed that large enterprises, with their larger digital footprints, can be more susceptible to AI-powered spoofing of identity documents due to the industrialization of deepfakes and automated data scraping by adversarial fraudsters.
That changes the value of proprietary security capabilities. The institutions with the best view of user behavior, agent activity, device intelligence and emerging vulnerabilities may be able to identify risk before it appears in conventional transaction data. In an agentic financial system, trust cannot be established once at login. It has to be recalculated throughout the entire journey from conversation to decision to payment.
As financial activity moves from banking applications into AI-powered conversations and automated workflows, the same APIs that let consumers share financial data with budgeting apps, lenders and payments providers are now being connected to agents capable of interpreting that data and acting on it. The result is a powerful but uncomfortable tradeoff. Financial information is becoming more useful precisely as it becomes harder to contain.
Visa's own market analysis points to the same conclusion: the companies that understand how customers behave before authorizing money movement will have the strongest defense against AI-enabled fraud and scams. The deal is expected to close in the coming months, subject to regulatory approval.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.