Markets Closed
Global Markets
S&P 500 7,736.52 ▲ +1.8% DOW 54,085.88 ▲ +1.7% NASDAQ 26,584.99 ▲ +2.6% RUSSELL 2K 3,036.98 ▲ +1.8% VIX 16.78 ▲ +1.7% GOLD 4,263.5 ▲ +4.1% CRUDE OIL 76.37 ▲ +0.8% EUR/USD 1.16 ▲ +0.4% BTC 64,433 ▲ +0.8% ETH 1,878.57 ▲ +0.1%
Fintech

Visa BioCatch acquisition targets fraud risks before payments begin

Visa has agreed to pay $2.4 billion in cash for BioCatch, seeking session-level fraud signals before payment initiation.

Rafael Ortiz

By Rafael Ortiz · Fintech Correspondent

· 3 min read

Visa BioCatch acquisition targets fraud risks before payments begin
Photo: PYMNTS

The Visa BioCatch acquisition remains pending: Visa said on August 3 it signed a definitive agreement to buy the fraud-intelligence provider for $2.4 billion in cash from funds advised by Permira and other shareholders. The proposed deal could give Visa access to risk signals generated during digital-banking activity before a payment is initiated, alongside conventional transaction-level monitoring.

The transaction requires customary closing conditions and applicable regulatory approvals. Visa expects it to close by the end of its fiscal second quarter of 2027, while warning that timing, integration and expected benefits are forward-looking statements subject to uncertainty. Visa’s announcement does not mean a combined product is currently available.

What would Visa gain from buying BioCatch?

BioCatch says its technology analyses thousands of application, behavioural, device and network signals during a digital-banking session. Visa cites examples including keystrokes, mouse activity, touch gestures and device handling. The company says those inputs are assessed in real time to identify indications of scams, account takeovers, money-mule activity and application fraud.

The distinction is the point of intervention. Traditional payment-fraud systems generally assess a transaction after it has been initiated, using data such as payment amount, merchant, location, device and a customer’s spending history, according to PYMNTS. Session-level analysis instead looks at activity during account opening, login and use of a banking application.

That may be relevant where the final payment does not resemble a simple stolen-card event. An account takeover can involve valid credentials and a familiar device, while a scam can lead a genuine customer to approve a transfer after being manipulated. Visa says the purchase is intended to help its financial-institution clients identify such threats earlier in the customer journey.

Why is fraud prevention described as moving upstream?

Visa has framed the shift as fraudsters moving from payment data toward account data and social-engineering attacks, as tokenisation, EMV chips and fraud models have strengthened protections around card credentials. That is Visa’s assessment of changing criminal methods, rather than an independently established measure of the whole market.

Andras Cser, a Forrester vice-president and principal analyst, told Inc. that transaction monitoring does not address pre-payment risks including identity theft, account takeovers and scams. He said BioCatch could fill capabilities Visa previously had only in an early and incomplete form.

Behavioural intelligence is not proof that a user is a criminal. James E. Lee, president of the Identity Theft Resource Center, told Inc. that the technology can identify activity that differs from a customer’s normal pattern but cannot determine with certainty who is on the other side of a session.

Visa reports that BioCatch serves more than 350 financial institutions in 21 countries, protects more than 760 million users across more than 1.8 billion devices, and analyses 19 billion user sessions a month. Those are company-reported figures. The available material provides no independent evidence on detection rates, false positives, privacy implications or the eventual scope of any Visa integration.

This story draws on original reporting from PYMNTS.

More from Fintech

All Fintech →