🛡️
Fintech · Т-Банк

T-Bank: AI protection against phone scammers saved customers 1.2 billion rubles

The financial trajectory of 'Protect or Refund' has been published in stages: in its first six months it saved customers 170 million rubles; by May 2025 the cumulative amount reached 1.2 billion rubles, with 12.3 million rubles paid out in compensation. The ratio of those two figures — roughly one to a hundred — is effectively the system's public accuracy: for every ruble paid out on missed scammers there are about a hundred rubles of prevented damage. The bank estimates the expected ecosystem-wide effect at roughly 2.5 billion rubles per year. 'Fraud Roulette' produced its own numbers over a year of closed testing: 2,000+ participants, more than 3 million calls taken, 44,000 hours of scammers' time burned, and an estimated 490–500 million rubles of prevented damage (the bank's estimate, cited by Forbes and Vedomosti). Frame this correctly: all figures are the bank's own reporting, not an independent audit. 'Prevented damage' is a calculated value (what could have been stolen had the call reached a victim), and the bank does not disclose the methodology. The paid compensations (12.3 million rubles), however, are real money that went to customers — and they are what makes the rest of the reporting credible: a bank that pays for every miss has no incentive to overstate its system's quality. In our view, the case's main innovation is not the models but the economic construction. A financial guarantee turns AI quality from an internal metric into a P&L line: every false negative costs the bank real money, so the incentives of the team, the bank, and the customer are aligned automatically. That construction transfers to any industry where AI protects customers from losses — from insurance to cybersecurity — and it is a stronger trust signal than any accuracy certificate. The second observation: 'Fraud Roulette' is a rare example of an offensive antifraud strategy. Classic protection reduces victims' losses; the roulette attacks the economics of the criminal business, where an hour of call-center time has a concrete cost. The 44,000 hours scammers spent talking to trained volunteers are hours not spent on real victims. Whether the model scales and whether scammers adapt to the interception is an open question worth watching in 2026.

1,2 млрд ₽
saved for customers cumulatively (by May 2025)
62 млн
scam calls detected monthly by Neuroshield
44 000 ч
of scammers' time burned by Fraud Roulette in testing
12,3 млн ₽
paid out in guarantee compensations
Sources
Verified: 2026-07-11

Background

T-Bank (ex-Tinkoff) is one of Russia's largest digital banks, operating without branches: the entire customer experience lives in the app and on the phone. That is why phone fraud for it is not an abstract industry risk but a direct attack on its primary customer channel.

The market-wide scale of the problem is documented by the regulator: per Central Bank data, Russian banks prevented 9.2 trillion rubles in theft in 2024. The fraud itself is concentrated: per T-Bank data, 99% of phone fraud in Russia falls into four main schemes — calls impersonating government agencies and companies, extortion, fake job offers, and sham investments.

T-Bank made scam-fighting not a security department but a product line with public reporting: since 2023 the bank has been launching customer-facing protection services, stating their results in rubles, and regularly updating the figures. The effort has been publicly fronted by the bank's ecosystem security leaders — Oleg Zamiralov, and later Vice President Alexei Baklanov.

That product logic is the key to the case. Most banks build antifraud as an invisible internal system; T-Bank turned protection into a marketing asset: a service with a financial guarantee, public counters of prevented damage, and even a gamified service where customers themselves burn scammers' time.

Problem

Most customer losses come not from hacks but from social engineering: scammers persuade a person to transfer money or reveal codes themselves. That fundamentally changes the bank's task. Classic antifraud watches transactions — amounts, recipients, patterns — and catches anomalies. But when a customer voluntarily, guided by a 'security officer', transfers their own money, the transaction looks legitimate: right device, right geolocation, code confirmation. Transaction antifraud fires too late — the money is already gone.

The scale of the attacks shows in the bank's own data: the 'Neuroshield' technology detects around 62 million scam calls per month. These are not rare incidents but an industrial stream: scammer call centers run like conveyor belts, churning through phone databases.

Protection also runs into a trust problem: customers under stress ignore warnings ('you may be talking to a scammer') — social engineering is precisely built on seizing attention and creating panic. So a scam conversation must be detected earlier and more confidently than the customer would do it — with active intervention, up to terminating the call.

Finally, incentives: a customer cannot verify whether the bank's 'invisible' protection works. As long as antifraud is an internal system with no obligations, the bank bears no cost of error and the customer has no grounds for trust. Only a financial guarantee breaks that loop: if the protection misses a scammer — the bank pays.

Solution

T-Bank built layered AI protection where each layer has its own mechanics and metric.

The first layer is 'Neuroshield' — fraud detection at call time. The system identifies a scam conversation from the call's sound wave, warns the customer of the danger, and can terminate the conversation; after it fires, all the customer's subsequent operations go under enhanced monitoring. Per the bank, detection accuracy for scam calls reaches 99%, and the system detects around 62 million such calls per month. The layer's key idea: analyze the communication channel, not just transactions — intervene at the moment of deception, not after it.

The second layer is the 'Protect or Refund' service, launched August 30, 2023, first on the market. Its essence is a financial guarantee on top of the AI protection: if the system misses a scammer and a customer who met the service terms loses money, the bank compensates the loss out of its own pocket. In May 2025 coverage was expanded: extortion and sham investments were added, and, per the bank, the service now covers all four most widespread phone fraud schemes — that is, by the bank's own data, 99% of cases.

The third layer is 'Fraud Roulette', which takes the fight on the offensive. The service intercepts scammers' calls in real time and anonymously redirects them to project participants — volunteers whose task is to keep the scammer on the line as long as possible without revealing themselves. Every call starts with a warning; the limit is three calls per participant per day; volunteers are advised to take a psychology course developed with the bank's experts — recognizing manipulation and keeping composure. Closed testing ran for a year: over 2,000 participants (including the pranksters Vovan and Lexus) took more than 3 million calls. The public launch for all Russians came on November 27, 2025; the project website runs a counter of activity and prevented damage.

The logic of the stack matters more than any single layer: Neuroshield reduces the attack flow, the guarantee aligns the bank's and the customer's incentives, and Fraud Roulette raises the cost of attack for the scammers themselves — every hour spent talking to a volunteer is paid out of the criminal call center's economics.

Result

The financial trajectory of 'Protect or Refund' has been published in stages: in its first six months it saved customers 170 million rubles; by May 2025 the cumulative amount reached 1.2 billion rubles, with 12.3 million rubles paid out in compensation. The ratio of those two figures — roughly one to a hundred — is effectively the system's public accuracy: for every ruble paid out on missed scammers there are about a hundred rubles of prevented damage. The bank estimates the expected ecosystem-wide effect at roughly 2.5 billion rubles per year.

'Fraud Roulette' produced its own numbers over a year of closed testing: 2,000+ participants, more than 3 million calls taken, 44,000 hours of scammers' time burned, and an estimated 490–500 million rubles of prevented damage (the bank's estimate, cited by Forbes and Vedomosti).

Frame this correctly: all figures are the bank's own reporting, not an independent audit. 'Prevented damage' is a calculated value (what could have been stolen had the call reached a victim), and the bank does not disclose the methodology. The paid compensations (12.3 million rubles), however, are real money that went to customers — and they are what makes the rest of the reporting credible: a bank that pays for every miss has no incentive to overstate its system's quality.

In our view, the case's main innovation is not the models but the economic construction. A financial guarantee turns AI quality from an internal metric into a P&L line: every false negative costs the bank real money, so the incentives of the team, the bank, and the customer are aligned automatically. That construction transfers to any industry where AI protects customers from losses — from insurance to cybersecurity — and it is a stronger trust signal than any accuracy certificate.

The second observation: 'Fraud Roulette' is a rare example of an offensive antifraud strategy. Classic protection reduces victims' losses; the roulette attacks the economics of the criminal business, where an hour of call-center time has a concrete cost. The 44,000 hours scammers spent talking to trained volunteers are hours not spent on real victims. Whether the model scales and whether scammers adapt to the interception is an open question worth watching in 2026.

Technology stack
«Нейрощит» — детекция мошенничества по звуковой волне звонка (точность 99%, по данным банка)Сервис «Защитим или вернём деньги» (ИИ + финансовая гарантия)«Фрод-рулетка» — перехват и переадресация звонков мошенников добровольцамУсиленный мониторинг операций после сработки детекции
Timeline
August 30, 2023 — 'Protect or Refund' launch (the market's first service with a financial guarantee); first six months — 170M RUB saved; 2024 — closed testing of 'Fraud Roulette' (2,000+ participants, 3M+ calls over a year); May 2025 — 1.2B RUB cumulative, 12.3M RUB in compensations paid, coverage expanded to extortion and sham investments (all 4 main schemes); November 27, 2025 — public launch of 'Fraud Roulette' for all Russians.

Lessons learned

  1. A financial guarantee is the strongest signal of confidence in AI: the bank pays out of pocket for every system miss, so the team has no incentive to overstate model quality.
  2. The right antifraud metric is prevented damage in rubles (170M → 1.2B), not internal model scores: customers, the regulator, and the press all understand it.
  3. The 'prevented to paid out' ratio (roughly 100:1) is a public analogue of system accuracy; the paid compensations make the other figures credible.
  4. Social engineering requires analyzing the communication channel (the call's sound wave), not just transactions — money leaves 'voluntarily', so transaction antifraud fires too late.
  5. Fraud is concentrated (99% falls into four schemes), so coverage can grow scenario by scenario: from the basic schemes in 2023 to extortion and sham investments in 2025.
  6. An offensive strategy ('Fraud Roulette') attacks the criminal call center's economics: 44,000 hours spent on trained volunteers are hours not spent on victims.
  7. Regular staged public reporting (six months → 1.2B → new service launches) builds a verifiable track record instead of a one-off press release — and turns security into a marketing asset.

Frequently asked questions

How much money has T-Bank's AI protection saved customers?

Per the bank, the 'Protect or Refund' service saved 170 million rubles in its first six months and 1.2 billion rubles cumulatively by May 2025, with 12.3 million rubles paid in compensation. The expected ecosystem-wide effect is about 2.5 billion rubles per year.

How does T-Bank's Neuroshield work?

The system identifies a scam conversation from the call's sound wave, warns the customer, can terminate the call, and puts the customer's subsequent operations under enhanced monitoring. Per the bank, detection accuracy is 99%, with around 62 million scam calls detected monthly.

What is 'Fraud Roulette'?

A T-Bank service (public launch November 27, 2025) that intercepts scammers' calls and anonymously redirects them to volunteers who keep the scammer on the line. In a year of testing, 2,000+ participants took over 3 million calls and kept scammers busy for 44,000 hours; the bank estimated roughly 490–500 million rubles in prevented damage. The limit is three calls per participant per day.

Does T-Bank really refund money if the protection misses a scammer?

Yes, subject to the 'Protect or Refund' service terms: by May 2025 the bank had paid 12.3 million rubles in compensation. Since May 2025 coverage includes all four most widespread phone fraud schemes, including extortion and sham investments.

Does T-Bank use graph neural networks in antifraud?

The bank has not publicly confirmed this. What is documented: Neuroshield (call sound-wave analysis), 'Protect or Refund', and 'Fraud Roulette'. Graph models are an industry trend in banking antifraud, but T-Bank does not disclose its specific stack.

← Cases