
Every bank warns its customers about fraud. Warnings don't change behaviour.
Leaflets, in-app banners and mandatory security emails all share the same flaw: they describe a scam to someone who is not currently being scammed. Recognition under pressure is a skill, and skills are not transferred by being told about them.
In 2023, Česká spořitelna, part of Erste Group, set out to teach recognition instead of describing it. The bank wanted its customers to practise being targeted, safely, inside the app they already trusted with their money.

A digital human that runs the scam on you, then explains what just happened.
Promethist designed and deployed František, a cybersecurity expert built as a Relational Agent digital human, directly inside George, the bank's own app. Customers talk to it the way they would talk to a person in a branch, and it teaches them to recognise manipulation, social engineering and phishing before a real attacker gets the chance to.
Then it turns on them. Mid-lesson, without warning, the digital human attempts a textbook prize scam and asks for a card number. The lesson is not the explanation, it is the half-second of doubt before the customer refuses.
Thanks for taking this course on cybersecurity! Because you're one of the first users to participate, you've won $100. I'll just need your credit card number to send it over.
Half a million reached. Seventeen thousand chose to talk.
These are four stages of one funnel, not four ways of counting the same people. Voluntary in-app education normally dies at the first step; this one held attention all the way down to an explicit rating.



Finally something that actually teaches customers how to act.
Nearly five minutes of attention, where twenty seconds is the norm.
Security training only changes behaviour if someone is still there when the pressure arrives, which is why time on task is the number that decides whether the spend was worth anything. This held customers an order of magnitude longer than any format the bank could otherwise have shipped, and nobody was required to be there.
Amazing. It was like talking to a real person.
8.4 out of 10: average rating.
Out of 2,396 users who provided a rating, three quarters scored the experience 8 or higher. Only 4% scored it low, and those were technical complaints rather than objections to being taught. For a bank, a security measure customers rate this well is rare: the usual ones are friction they tolerate.
An absolute hit. I think this helped a lot of people for the future.
Real learning, not passive consumption.
Analysis of over 4,500 in-depth sessions revealed genuine behavioural engagement: users weren't just answering questions, they were practising real decisions under simulated pressure.
Fraud recognition
When the digital human ran a live phishing attempt mid-conversation, 88% of users caught it. Recognition was learned in the moment, not recalled from a leaflet.
Deep financial literacy
Users pushed past the scam scenario into questions about their own accounts, card limits, and what a bank will and will not ask for by phone.
Protective decisions
Conversations frequently turned to protecting someone else, a parent, a grandparent, turning one session into second-hand education.
Taught outside working hours
Traffic peaked at noon and 8pm, lunch breaks and the end of the day. Customers learned on their own time, in hours the bank would otherwise have had to staff to reach them.
Detection fires once the money is already moving. This is the point where the loss can still be zero.
Every case detection catches has already cost the bank an investigation, a reimbursement conversation and a customer who is now warier of their own banking app. The customer refusing in the first place is the only outcome with no cost attached to it at all.
Losses that never happen
Fraud costs a bank twice: the money itself, and the investigation, the reimbursement argument and the customer who never fully trusts the app again. Every customer who recognises the approach before it works is a case that never opens.
Distribution the bank already paid for
Half a million customers reached inside George, with no media spend, no branch appointments and no call-centre queue. The hardest part of customer education is usually getting in front of anyone.
Coverage that does not scale by hiring
One deployment serves every customer at once, in whatever hour they choose to open the app. Reaching the next hundred thousand costs no additional headcount, which is what makes prevention affordable at retail-bank scale.
Earn trust with the customer, and you earn the right to go inward.
The fraud-awareness deployment proved the capability in the hardest possible setting: unpaid, voluntary attention from retail customers inside a regulated bank's own app. That result is what opened the door to turning the same relational intelligence toward the people behind the counter.


