On August 3, 2026, Visa announced a definitive agreement to acquire BioCatch for $2.4 billion in cash.
The transaction remains subject to regulatory approvals and customary closing conditions. Visa expects the acquisition to close by the end of its fiscal second quarter of 2027.
The price of the transaction is significant, but the technology behind the acquisition provides a more interesting indication of how fraud prevention is evolving.
BioCatch operates early in the digital customer journey. Its technology analyses how users interact with their devices and financial applications in order to identify unusual behaviour before a payment is completed.
This approach becomes increasingly important as instant payments and other digital payment methods grow. When a transaction can be authorised or funds transferred within seconds, the time available to detect fraud becomes extremely limited.
Fraud prevention therefore needs to intervene earlier.
BioCatch analyses what happens before the payment
Traditional fraud systems already examine transaction characteristics such as amount, frequency, location, merchant, beneficiary, device and previous customer activity.
BioCatch adds another layer: the behaviour of the user during the digital session itself.
According to Visa, the platform analyses thousands of application, behavioural, device and network signals.
These can include keystrokes, mouse movements, touch gestures, device handling and aspects of the technical environment.
BioCatch says it collects more than 3,000 anonymised data points during digital banking sessions.
The objective is to understand how a legitimate user normally interacts with a digital environment and identify deviations that may indicate fraud.
This does not replace authentication. Instead, it provides additional context.
A customer may have the correct credentials, the correct device and successfully complete an authentication process while still being exposed to fraud.
In an account takeover, a criminal may possess valid credentials.
In a manipulation scam, the legitimate customer may personally authenticate and authorise a payment while acting under the influence of a fraudster.
The European Banking Authority and the European Central Bank highlighted this shift in their 2025 report on payment fraud. Strong customer authentication continues to reduce several traditional forms of fraud, while payer manipulation is increasing and requires additional protection measures.
Source: EBA and ECB, Joint Report on Payment Fraud
Fraudsters increasingly want the victim to authorise the payment
Visa's Spring 2026 threat report provides another indication of this change.
Visa says it identified almost $1 billion in scam-related activity between July and December 2025.
Many of these attacks increasingly rely on social engineering, where criminals attempt to manipulate legitimate users rather than directly bypass security controls.
This creates a different challenge for banks, fintechs and payment providers.
Correct credentials do not necessarily mean a session is safe.
A successfully entered OTP does not reveal whether the customer is being manipulated.
Successful biometric authentication cannot explain why a trusted customer suddenly decides to make an unusual payment.
Fraud prevention therefore requires more context around customer behaviour and intent.
Source: Visa, Spring 2026 Biannual Threats Report
Instant payments compress the fraud decision window
Instant payment systems are growing rapidly.
Their value comes from speed and continuous availability.
Those same characteristics reduce the amount of time available to detect and stop fraudulent transactions.
The World Bank notes that perpetrators of authorised push payment scams frequently move stolen funds rapidly after receiving them, often through money mule accounts.
For instant payments, fraud systems therefore need to make decisions while the customer is preparing and authorising the transaction.
The same principle increasingly applies to card payments, e-commerce and digital wallets.
Behavioural intelligence can help identify unusual activity before the final authorisation decision.
Fraud prevention starts inside the digital session
Modern fraud prevention increasingly combines several layers of control.
1. The digital session
Behavioural and device intelligence can begin during login or while the customer navigates an application.
2. Identity and authentication
Authentication controls continue to verify access and the customer's ability to use the account or payment method.
3. Transaction context
Amount, merchant, beneficiary, channel, location and customer history provide additional signals.
4. Real-time scoring
Institutional, network and payment-system data can be combined to assign a risk level before authorisation or execution.
5. Post-payment monitoring
For some fraud scenarios, especially account-to-account payments, monitoring receiving accounts and subsequent fund movements can help identify mule accounts and rapid dispersal patterns.
The challenge is to connect these layers quickly enough to support a decision before the transaction becomes difficult to stop or recover.
Visa is already applying part of this approach through Visa A2A Protect, a real-time risk-scoring capability designed for account-to-account payments.
BioCatch could extend this visibility further upstream by providing deeper information about the customer's digital behaviour.
Source: Visa A2A Protect
The issue is becoming increasingly relevant for Africa
Africa's instant payment ecosystem is growing rapidly.
According to AfricaNenda's SIIPS 2025 report, 36 instant payment systems were live across 31 African countries as of June 2025.
These systems processed approximately 64 billion transactions worth nearly $2 trillion in 2024.
As instant payments become more important for person-to-person transfers, merchant payments and broader financial services, fraud management increasingly becomes an infrastructure issue.
AfricaNenda has also highlighted trust, fraud management and dispute resolution as important elements in the design and development of instant payment systems.
Source: AfricaNenda, SIIPS Report 2025
This raises several questions for African markets.
Do banks have enough data?
Large international banks generally have substantial volumes of transaction and behavioural data.
Smaller banks, fintechs and institutions operating in smaller markets may have less information available.
That does not necessarily mean each institution needs to build fraud models entirely from its own data.
Shared or network-level models can provide an initial layer of intelligence, although local calibration remains essential.
Visa says A2A Protect can provide initial risk-scoring capabilities without requiring large volumes of historical data from each institution.
This remains a vendor claim and should be evaluated during implementation.
Local feedback will still matter: confirmed fraud, false positives, customer behaviour, device types, channels and market-specific patterns.
How far should behavioural monitoring go?
Technology capable of analysing thousands of behavioural signals naturally raises data-protection questions.
BioCatch says the data it processes is anonymised.
Financial institutions and regulators still need clear rules governing collection, retention, access, auditability and the use of automated risk decisions.
Fraud prevention therefore needs to develop alongside strong data governance.
Could fraud intelligence be shared across institutions?
This may become one of the most important questions for instant payments.
Fraud frequently crosses institutional boundaries.
One bank may see the sending account, another the receiving account, while a third institution may see the money moved again moments later.
BioCatch says real-time intelligence sharing between participating institutions can improve behavioural risk detection.
For national or regional instant payment systems in Africa, this creates an opportunity to explore shared fraud-intelligence capabilities.
Such infrastructure could consolidate signals related to suspicious beneficiaries, mule accounts, compromised devices and emerging fraud patterns.
However, strong governance would be required.
Data standards, confidentiality, responsibility, latency, model performance and false-positive management would all need to be addressed.
Visa is moving earlier in the risk chain
BioCatch says its technology currently protects 760 million users across 1.8 billion devices, serving more than 350 financial institutions in 21 countries.
The company also says it analyses around 19 billion user sessions every month.
These figures show that Visa is seeking access to technology already deployed at significant scale.
More importantly, the acquisition illustrates how fraud prevention is expanding beyond the transaction itself.
Risk analysis can begin when a customer logs in, continue throughout the session, assess the payment and then monitor what happens afterwards.
For instant and digital payments, this evolution is becoming increasingly important.
An investigation that begins several minutes or hours after a fraudulent payment may already be too late.
Visa's acquisition of BioCatch has not yet closed.
The strategic direction, however, is already visible: as payments become faster, fraud intelligence must also move earlier and operate in real time.




