Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Organisations Must Prioritise Identity Verification To Protect Against Fraudsters
Articles

Organisations Must Prioritise Identity Verification To Protect Against Fraudsters

Robert PriggeBy Robert PriggeAugust 9, 2021Updated:December 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The online world and its role in our daily lives has expanded enormously over the last 18 months. People of all ages have embraced online-first living and the advantages it offers, whether that’s cutting down commutes, receiving online food deliveries or setting up bank accounts from home. However, this online activity comes with substantial risk. There is more personally identifiable information (PII) being used to register and utilise online services than ever before. And, unfortunately, fraudsters are getting savvier at finding ways to exploit this.

The Accellion hack from well over six months ago reminds us of this. Despite some time passing since the breach occurred, it’s only just been confirmed that attackers stole personal information belonging to Morgan Stanley’s customers, including addresses and Social Security numbers which likely will have been sold on the dark web for as little as $12-$20. This data can then be used by fraudsters to set up new, and access existing, accounts. This means that it’s no longer a certainty that someone using an online service is who they say they are. For this reason, businesses must take steps to protect themselves and their customers. One crucial way to do this is by investing in strong identity verification across ecosystems.

Embracing digital transformation

Many companies have used the last year to jumpstart their digital transformation efforts, but with a digital problem of this scale, it is vital that organisations continue to accelerate the transition and build in the necessary operational resilience. One area which continues to be overlooked somewhat in corporate digital transformation strategies is digital identity verification. This is massively worrying as it holds the key to combating the threat of stolen PII and can ensure that a person’s digital identity matches their physical identity when conducting any business online.

Industries prime for overhaul

One industry that needs to be particularly cautious of the threat of stolen PII is healthcare. With 67% of UK healthcare organisations having experienced a cybersecurity incident in the last decade, and with 2,550 healthcare breaches having impacted more than 175 million medical records, healthcare is particularly vulnerable. This is due to the significance and the volume of the information available. Medical records can be listed for up to USD $1,000 on the dark web, 10 times more than the average credit card record, making it a tempting target for fraudsters.

Progress is being made and a new study by iGov and BT reveals that the majority of the UK’s leading health providers are accelerating their digital transformation plans this year. However, organisations in the sector must address this important aspect of identity verification to be completely protected.

Verifying your customers

The problem now is quality, not quantity. While data breaches fell by 48% in 2020 compared with the previous year, the volume of records compromised by these breaches jumped by 141% to a whopping 37 billion, the largest number seen by RSB since 2005. The impact each breach can now have is unlike what we have seen before and therefore, being able to accurately establish and authenticate an identity is the key to keeping people’s data safe.

Identity verification can be conducted quickly and easily at account opening stage and on an ongoing basis. The process starts with the customer photographing their government-issued ID (e.g., driver’s license, passport) via their smartphone or webcam and then taking a corroborating selfie. During the selfie-taking process, a biometric face template is created to ensure the person behind the ID is the person creating the account. The identity verification solution ensures that the ID document is authentic and that the person in the selfie is the same as the ID. This method can then be used to verify users as they make further transactions. All the user has to do is take a fresh selfie to generate a new biometric template which is then compared to the original. This then verifies the user’s digital identity in seconds thanks to AI advancements.

Security doesn’t have to stop here. For businesses dealing with more sensitive data, such as financial services organisations or healthcare providers, they can layer in several identity services to improve the level of assurance. However, if the business employs multiple methods, being able to orchestrate them all seamlessly, in line with regulations, is essential.

The growth in how much we use the online world is matched by the growth in opportunity for fraudsters. While companies have taken significant steps to revolutionise the way they work online, it is still not enough. Identity verification continues to be a sticking point and with hacks like Accellion’s causing damage across ecosystems, this technology must become a priority. Companies need not live in fear of fraudsters infiltrating their systems with stolen PII as long as the right systems are put in place to protect them.  

Robert Prigge

CEO

  • Robert Prigge
    Can Identity Verification Build Trust In The UK’s Sharing Economy?

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}