Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Identity And AI: The Recipe For A Strong Fraud Defence
Articles

Identity And AI: The Recipe For A Strong Fraud Defence

Sundeep TengurBy Sundeep TengurSeptember 24, 2019Updated:December 30, 20214 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Sibos has kicked off in London this week and the theme for this year is “Thriving in a hyper-connected world.” The market has long demanded quicker and more convenient payment methods, and the industry is now answering with ubiquitous payments. Yet at what cost? PSD2 and open banking are now established in the legislative framework, and many third-party providers are springing up with new offerings that democratise access to payments and offer complementary value-added services.

Banks and other financial organisations are already seeing a surge in the volume and value of electronic transactions through digitalisation. And new channels, like PSD2, are set to exacerbate the pressure on existing fraud defences. Faster payments, through SWIFT gpi and other means, virtually eliminate the window of investigation. And, therefore, necessitate automated real-time detection.

Fraud detection has become a very different ballgame. It now requires the use of advanced analytics and AI to compete with the ruthless agility of fraudsters and organised crime. The 2016 Bank of Bangladesh heist that used SWIFT channels to steal $81 million is a sore reminder of this fact.

Catch me if you can

The 1980s book, and subsequent Hollywood movie, based on the early exploits of ex-fraudster Frank Abagnale Jr. is a good reminder of the speed of monetary transactions in the modern world. Payments through fast channels such as Faster Payments (UK), SEPA Instant Credit or the recent SWIFTNET Instant are made in a matter of minutes, if not faster.

It’s a race to the finish line. Can systems thwart fraud attempts in time, or will they risk unrecoverable losses and customer attrition? Fraudsters are also now better than ever at impersonating legitimate entities through phishing and identity theft.

A multidimensional view of a customer profile is, therefore, critical. It should encompass personal identity, device profiles and other attributes, such as biometric footprints. More importantly, organizations must cross-reference and update this “golden record” in real time to be truly effective.

Trust is the new currency

Identity validation is a real conundrum for the industry. Fraudsters now invest more time in grooming synthetic identities or harvesting valuable information from compromised accounts to appear legitimate. They aim to use similar points of exit – such as local ATMs and preferred online merchants – to funnel money away from their victims’ accounts. Organised fraud rings can also spoof IP addresses and other data attributes to circumvent common fraud controls.

With so many threat vectors, how do we discover the owner of an identity? There’s no holy grail in identity verification. Most techniques, including passwords, biometrics, knowledge-based authentication or device tokens, are flawed in isolation but offer effective defence when used together. True identity validation surfaces through a covert, multidimensional score to create a unique score for each individual, with overlapping data assets and strong entity resolution.

The vast majority of what third-party fraud organisations witness downstream in their transactional systems indicates identity manipulation. To help resolve downstream issues – like card-not-present or authorised push payments – it’s important to conduct identity checks upstream at the onboarding stage and throughout the customer life cycle.

AI to the rescue?

AI is overhyped in the fraud domain. Sadly, it isn’t effective against new fraud types, customer behaviours or channels without existing data sets to train models with. However, it can be a powerful addition to a fraud management ecosystem, helping uncover more complex frauds and reducing false alarms.

Transparency and interpretability are key to the process. That’s why many organisations are investing in “data labs” to empower fraud experts and distill their knowledge into models. The key question now is how to operationalise AI. How do you transform a score into a meaningful and actionable outcome?

Humans can no longer compete with machines when it comes to sifting through huge volumes of highly complex data. The optimal solution is to use AI to do the heavy lifting. AI can provide ample intelligence that humans can use to make more effective nonbinary decisions.

Achieving balance

In a hyperconnected world, the recipe for success in curbing fraud goes beyond the traditional data, people and technology mix. It’s about defining a fraud strategy road map with pragmatic milestones and supporting it with advanced analytics and AI. With most organisations hosting a diverse landscape of homegrown models, vendor solutions and third-party data, it’s critical to interlace these assets into a decision fabric that drives consistency, robustness and operational effectiveness in end-to-end fraud management.

Yet there must also be a fine balance between robust fraud security and a frictionless customer experience. This way you can achieve new business targets while keeping fraud actors at bay, as well as meet regulatory expectations without undue constraints. In short, it’s less about what you do and more about how you do it.

Sundeep Tengur

Senior Business Solutions Manager,

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    New Phishing Kit Starkiller Defeats Multi-Factor Authentication

    February 23, 20264 Mins Read

    ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

    January 22, 20266 Mins Read

    What Happens after a Phishing Email Lands in Your Inbox?

    January 5, 20266 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}