We like to think that history moves through shocks and explosions. Revolutions. Wars. Coups.
In reality the most dangerous changes are the quiet ones.
The ones wrapped in comfort and convenience that slowly lull us to sleep while, step by step, we trade speed, comfort and the illusion of safety for the very thing that makes a human being free.
Five steps of our quiet retreat
About thirty years ago, when the internet was just becoming mainstream, we gave away the first and, perhaps, most invisible layer of our lives: our movements.
The deal looked simple. You carry a small device that lets you call and message anyone. In return, telecoms and, through them, the state gain the ability to reconstruct where you are almost all the time. Professor Anatoly Temkin from Boston University describes this as an informal contract: in exchange for connectivity we accept that our location is constantly logged and correlated with other data sources. It felt like a reasonable price for new possibilities: calling loved ones at any moment, getting a taxi, asking for help, finding your way in a new city. What almost nobody thought about was that along with convenience we were handing over full control of our geography, our routes, our meetings, our patterns of life.
Security expert Bruce Schneier once put it very simply: “If the government said, ‘You must carry a tracking device at all times,’ you would rebel.” Yet every morning we put that device into our pocket and call it a phone.
The second step hid behind the language of security: the fight against terrorism, money laundering, fraud. The first and second Payment Services Directives (PSD2) in the EU started as technical rules about how payments should work and how banks and fintechs should protect users. As they evolved, something else appeared in the background: every card payment and bank transfer, every subscription and refund began to form a single behavioural picture. You can call it, for the sake of argument, a payment behaviour graph. It does not only record what we buy, but also when, where, with whom and how regularly. On paper the system is there to fight fraud. In practice it has become a permanent background check on our right to participate in the financial system. We have not “lost” our money in the sense that someone stole it from our account. What has changed is that access to it now depends not only on property rights, but also on an algorithmic judgement of our acceptability.
The third step was biometrics. Face. Fingerprints. Voice. Iris.
We handed over our bodies in order to unlock a phone faster, go through passport control without queues, pay with a glance. It felt efficient and even safer. What almost no one thought about was that biometric data cannot be changed like a password. If it leaks, it leaks forever.
Security researchers already describe how malware such as GoldPickaxe collects facial scans and ID documents, then uses AI to build realistic digital models of victims in order to access bank accounts and other services. This is still far from a global catastrophe, but the trend is clear: stolen biometrics plus deepfake tools plus intercepted messages create a new layer of risk that we cannot simply “reset” with a new password.
The fourth step was the routine surrender of documents and personal details. Passport numbers. Card details. Addresses. They are entered on websites, in apps, in online forms under the promise that everything is “secure” and compliant with standards. Year after year we read the same headlines: another breach, millions of records exposed, personal data traded in bulk.
Reports from incident response teams and data-loss specialists show the same picture. Social engineering dominates attacks on individuals. In one recent quarter Positive Technologies observed social engineering in over ninety per cent of successful attacks on private users, alongside a rise in theft of biometric data and payment card details. In theory the system exists to protect us. In practice the architecture is built to extract value from behavioural data and only then to think about safety. We enter passwords, card details and one-time codes convinced that the platforms are robust. In reality people are hacked, manipulated and drained of funds via very human vulnerabilities.
Women are especially exposed to such attacks because social engineering exploits exactly the things that are socially demanded from them: trust, responsiveness, care, a desire to help relatives and partners. Educational materials from central banks and regional social services show the same pattern: scammers pretend to be from a bank, a payment service, a social fund, play on fear, urgency and empathy, and the victim voluntarily hands over the keys to her account.
The fifth step is the most dangerous because we hardly noticed it at all. It is the right to doubt. The right to ask questions. The right to say “no”.
The modern scoring ecosystem does not just decide who can access money. It also quietly decides who is considered trustworthy. Algorithms rate our behaviour, assign “risk” levels and determine whether we are “reliable enough”, “obedient enough”, “predictable enough”. Those who resist the spread of monitoring tools are marked as problematic. They are pushed out of key roles, lose jobs, disappear from professional networks.
In my fictional universe, journalist Anna Kravchenko tries to document how the next wave of payment regulation is used not only to protect consumers but also to normalise continuous behavioural tracking. In her notes every third witness quietly leaves their role or is moved sideways. Every fifth either dies early or disappears from public life. The system does not target famous activists. It targets mid-level specialists who understand the architecture from within and have access to the control room.
Shoshana Zuboff, who gave this logic its name, has a very simple way of summing up what happens when we treat human experience as raw material: “Once we searched Google, now Google searches us.”
The frightening part is that payments, phones and everyday services are slowly moving in the same direction.
The 2040 world that might arrive
In my novel “2040”, Munich lives under total supervision from an integrated payment integrity graph. Drones deliver pensions and fines. Algorithms assign each citizen an “optimal tariff of the day”. The system follows every movement of money.
On giant screens the Minister of Financial Freedom explains that this is not control but trust, not surveillance but care, that honest people have nothing to fear. People walk past without raising their heads. They are used to the idea that something distant, clever and “objective” watches each step.
There are also abandoned clusters on the edge of the city where no one has fully migrated to the new infrastructure. Archives accumulate there. Old protocols. Video fragments. Documents from a world that still knew how to doubt. Stalkers search these places for traces of the past.
Max de Vries, a former head of security at a major bank who once refused to transfer customer data without a court order and was marked as “unreliable”, finds a hard drive left there by journalist Anna. On it are traces of how the logic of total behavioural control was designed and how the rhetoric of “fraud prevention” helped to sell that logic to regulators and the public.
This is fiction. Yet the line between fiction and reality is getting thinner.
Reports from the European Payments Council describe how payment fraud prevention increasingly relies on behavioural and contextual analytics. Not just “was the card number correct”, but “does this transaction fit your usual pattern”, “have you recently been in a high risk location”, “do your other interactions raise red flags”. At the same time supervisory bodies in Europe talk more and more about data-driven oversight and real-time monitoring of risks on the basis of live transaction flows.
None of this is automatically bad. Fraud really does exist and people really do lose money to criminals. The worry begins when the same tools are quietly repurposed: from protecting the individual against fraudsters to protecting the system against “inconvenient” individuals.
A different kind of system: from harm to action
There is, however, another possible direction. It begins with something very simple: recording what happens.
Across Europe women regularly face what I would call “micro harm” from banks and fintechs. Hidden fees that appear only after the fact. Card blocks without clear explanations. Exchange rates that are quietly changed during the transaction. Money held back “for checks” for weeks. Service refusal with no reasons. Long delays in releasing funds after a dispute.
The usual reaction is frustration and long conversations with support. Sometimes the issue is resolved. Often it is not. Most of these stories remain private. They are not visible to regulators and rarely reach consumer organisations.
The ecosystem I am working on is not another chat, not another media project and not another “community for the sake of community”. It is a new, very practical layer of consumer economy and risk intelligence built by women and for women.
Its core logic is to convert harm into action, observation and reward.
Women record real incidents as they happen: a screenshot of an unexpected fee, a copy of a refusal letter, a short note when a card is blocked at the wrong moment. The system aggregates these signals, identifies patterns of harm and sells anonymised analytics to banks, fintechs, risk consultants and supervisors. Part of that income funds micro compensation for the women who supply the data.
These are data from users, not data about users.
Regulators are moving towards data-driven supervision anyway. The European Payments Council’s own Payment Threats and Fraud Trends report is built on exactly this principle: tracking what actually happens in the field, identifying typical fraud schemes and weak points in processes. The same logic can be applied from the bottom up.
For participants the more important change is psychological. Anxiety turns into control. Helplessness turns into agency. Isolation turns into community. Shame turns into dignity.
We do not sit down in the evening to “work for the system”. We record things in the flow of life. It can start as something as simple as a diary. A small form where you note what happened today. Everyday fintech harm. What you noticed. What you tried. What actually worked.
Once a week you receive a short selection of real stories from other women, practical steps that helped in similar situations and, perhaps most importantly, a quiet reminder: you are not crazy, and you are not alone. This is documented harm, not “your personal problem”.
The value of such an initiative is not only social. It is also economic. The data already have market value. Banks, fintechs, risk advisors and supervisors are actively looking for early warning signals and behavioural insights, especially now that the sector is moving deeper into advanced analytics.
If that value is created on the backs of users, part of it can and should return to them directly in the form of micro compensation. There is no reason why women should do this as unpaid labour.
While it is still not too late
We are the ones who open the door to our home. It is time to start locking it again, calmly and consciously, while we still can and before we wake up fully inside the 2040 scenario.
Apple’s Tim Cook described the stakes in one sentence that still lands like a punch in the stomach: “Our own information is being weaponized against us with military efficiency.” When this is true, indifference is no longer a neutral position. It becomes a form of consent.
The first step can be small. Start noticing and writing down the quiet shifts. Moments when “protection” comes at the price of disproportionate access. When “convenience” quietly cancels your ability to say no. When “security” is used as a cover word for surveillance.
A fintech harm diary is not just private therapy. It is documentation.
It is evidence.
It is data that can change the system.
When one woman records a hidden fee, it is a personal story.
When thousands record the same type of fee in similar situations, it becomes a pattern. A data set. A lever for pressure.
We really are at a fork in the road.
One direction leads to a world where the system knows almost everything about us, where each decision is scored, where the right to use your own money depends on your obedience, and where chronic anxiety is normalised as “just modern life”.
The other begins with awareness, with recording, with turning harm into action, with collective demands for transparency and accountability.
Every time we type a password, upload a passport scan or tick “I agree” without reading, we make a choice. Every time we stay silent about micro harm we experience, we give the system permission to continue.
But every time we record, speak and connect, we make another choice: in favour of freedom, in favour of dignity, in favour of the right to understand what is being done with our money, our data and our lives.
Writer José Saramago once said that blindness is not the loss of sight, but the refusal to see. For thirty years we have not wanted to see how, one convenience at a time, we were trading away the conditions of our freedom.
It is time to open our eyes while we still can.
To name what is happening.
To build systems in which people matter more than algorithms and where “protection” really means protection, not monitoring dressed in softer language.
A women’s protection ecosystem is not a utopia. It is a practical instrument that can start working now. A way to turn anxiety into control, helplessness into agency, isolation into community, shame into dignity.
A way to tell the system: we see you.
We are documenting.
We are no longer silent.
The 2040 world is a warning, not a sentence.
It is a future that can arrive, but does not have to.
We still have time to change the trajectory, but only if we stop sleepwalking and start recording, documenting and pushing back. The first step is simple: notice, write, speak.
What is at stake is not only our financial safety.
What is at stake is our freedom.
References
“Privacy in a Digital Age” (Bruce Schneier; Carnegie Council for Ethics in International Affairs; 10 May 2017)
https://www.schneier.com/talks/archives/2017/05/privacy_in_a_digital.html“Yearly update of the ‘Payment Threats and Fraud Trends Report’” (European Payments Council; europeanpaymentscouncil.eu; 3 December 2024)
https://www.europeanpaymentscouncil.eu/news-insights/news/yearly-update-payment-threats-and-fraud-trends-report-1“2024 Payment Threats and Fraud Trends Report” (European Payments Council; europeanpaymentscouncil.eu; 22 November 2024)
https://www.europeanpaymentscouncil.eu/document-library/reports/2024-payment-threats-and-fraud-trends-report“2024 Report on Payment Fraud” (European Banking Authority and European Central Bank; eba.europa.eu; 11 July 2024)
https://www.eba.europa.eu/sites/default/files/2024-08/465e3044-4773-4e9d-8ca8-b1cd031295fc/EBA_ECB%202024%20Report%20on%20Payment%20Fraud.pdf“EBA Consumer Trends Report 2024/25” (European Banking Authority; eba.europa.eu; 26 March 2025)
https://www.eba.europa.eu/sites/default/files/2025-03/514b651f-091b-42d3-b738-1fae79264044/Consumer%20Trends%20Report%202024-2025.pdf“EBA’s report highlights key issues impacting EU consumers” (News team; The Paypers; 27 March 2025)
https://thepaypers.com/fraud-and-fincrime/news/ebas-report-highlights-key-issues-impacting-eu-consumers“2024 Data Breach Investigations Report” (Verizon; verizon.com; 5 May 2024)
https://www.verizon.com/business/resources/reports/dbir.html“Verizon 2024 DBIR: Social Engineering” (Editorial team; dmarcian; 29 May 2024)
https://dmarcian.com/verizon-2024-dbir“A Voice Deepfake Was Used To Scam A CEO Out Of $243,000” (Jesse Damiani; Forbes; 3 September 2019)
https://www.forbes.com/sites/jessedamiani/2019/09/03/a-voice-deepfake-was-used-to-scam-a-ceo-out-of-243000“How to guard against voice cloning and deepfake scams” (Michelle Perry; ICAEW Insights; 15 January 2025)
https://www.icaew.com/insights/viewpoints-on-the-news/2025/jan-2025/how-to-guard-against-voice-cloning-and-deepfake-scams“How I fell victim to romance scam using AI deepfake videos and lost £17,000” (Gabriel Pogrund; The Times; 20 December 2024)
https://www.thetimes.co.uk/article/how-i-fell-victim-to-romance-scam-using-ai-deepfake-videos-and-lost-17000-d526zs83g“Once we searched Google. Now it searches us” (Shoshana Zuboff; Le Monde diplomatique; January 2019)
https://mondediplo.com/2019/01/06google“The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power” (Shoshana Zuboff; Profile Books; 31 January 2019)
https://en.wikipedia.org/wiki/The_Age_of_Surveillance_Capitalism“Tim Cook warns of ‘data industrial complex’ in call for comprehensive US privacy laws” (James Vincent; The Verge; 24 October 2018)
https://www.theverge.com/2018/10/24/18017842/tim-cook-data-privacy-laws-us-speech-brussels“Apple’s Tim Cook makes blistering attack on the ‘data industrial complex’” (Natasha Lomas; TechCrunch; 24 October 2018)
https://techcrunch.com/2018/10/24/apples-tim-cook-makes-blistering-attack-on-the-data-industrial-complex“EU clamps down on online fraud and hidden fees affecting online payment platforms” (Sead Fadilpašić; TechRadar Pro; 27 November 2025)
https://www.techradar.com/pro/eu-clamps-down-on-online-fraud-and-hidden-fees-affecting-online-payment-platforms



Thank you, Mila, for this fascinating and slightly scary post. As you say, I think that the world that we're in is getting increasingly closer to fiction like your own and that of Orwell's as well. I had no idea about these micro-harms that affect certain people in terms of online transactions, but I guess as a White man, it's probably something that's not affected me more. Thank you, this is a reminder to check my own positionality and make sure that I'm looking out for and helping others that are affected by these issues.
Thank you for raising some important issues! We are watching fintech transform in different ways, especially given the AI evolution. But we rarely pause to think about the negative offshoots and consequences of convenience as you very well highlighted. It gave me food for thought and a feeling of empathy for the harm it is causing disproportionately.