HomeMalware & ThreatsAI Deepfakes Force Banks to Move Beyond Voice Authentication

AI Deepfakes Force Banks to Move Beyond Voice Authentication

Published on

spot_img

Finance & Banking,
Fraud Management & Cybercrime,
Fraud Risk Management

ABA’s Paul Benda on Why Most Account Takeovers Stem From Scams, Not Hacks


Paul Benda, executive vice president, risk, fraud and cybersecurity, American Bankers Association

In the realm of banking security, advances in technology have often led to escalated risks, particularly in the area of fraud. Paul Benda, who serves as the executive vice president for risk, fraud, and cybersecurity at the American Bankers Association (ABA), has recently shed light on a growing trend: account takeovers that predominantly result from customer scams rather than sophisticated hacking techniques. As criminal methods evolve, Benda points out that traditional protections, though reinforced, are becoming less effective as fraudsters adapt their tactics. Instead of breaching front doors that banks have fortified, these criminals manipulate people into voluntarily opening their own doors.

According to Benda, recent scams involving bank impersonation and increasingly sophisticated deepfake technologies have enabled criminals to deceive customers into authenticating their identities and transferring funds to fraudulent accounts. “These technologies can mimic human voices and appearances so convincingly that people often fail to detect the deception,” he explains. This unsettling trend highlights the need for banks and customers alike to remain vigilant and informed.

To combat these emerging threats, Benda emphasizes that banks must adopt a multi-layered approach to authentication. The rapid evolution of artificial intelligence necessitates that financial institutions implement various methods to verify user identities. This includes evaluating IP addresses, detecting virtual private network (VPN) usage, and maintaining device consistency during transactions. For instance, while passkeys are an effective way to mitigate the risk of phishing attacks, Benda underscores that banks should still provide alternative login methods for customers who may not have access to smartphones or advanced technology. “It’s critical we offer secure options for all customers, regardless of their technological capabilities,” he states.

“The predominant challenge we face today is that the overwhelming majority of account takeovers occur because the customer unwittingly facilitates the process,” Benda asserts. This remark points to a troubling reality: the potential for fraud is often seeded within customer interactions, making education and awareness indispensable tools in the fight against fraud.

During a recent video interview with Information Security Media Group (ISMG), Benda delved deeper into the multifaceted issues plaguing the banking sector. One significant point discussed was the ongoing struggle between cyber and fraud teams when it comes to sharing relevant data and signals. Despite numerous discussions around establishing fusion centers dedicated to collaboration, these teams still find it challenging to work cohesively. The lack of streamlined communication can hinder effective responses to emerging threats.

  • Additionally, Benda elaborated on how criminals are leveraging stolen personal data to impersonate banks and extract sensitive information, including one-time passcodes from unsuspecting customers.
  • He also highlighted the continued rise of synthetic identity fraud, which has proven particularly elusive for detection systems, especially as stolen identities are increasingly used to bolster “mule accounts.” These accounts facilitate various illicit activities, complicating the landscape further.

Benda’s career trajectory adds an interesting layer to his insights. Beginning as an officer in the U.S. Air Force, he later worked at the Defense Advanced Research Projects Agency (DARPA), where he was pivotal in designing security systems for the Pentagon. His extensive experience also includes a leadership role at the Homeland Security Advanced Research Projects Agency before transitioning to the private sector. For over eight years, he has contributed his expertise to the American Bankers Association, navigating the ever-changing challenges within the banking environment.

As the financial sector grapples with these pressing issues, Benda’s thoughts serve as a critical reminder. Collaboration within the industry, coupled with a solid foundation of customer education and authentication methods, could be essential strategies in countering the rise of fraud driven by technological advancements.

Source link

Latest articles

AiTM Phishing Emerges as Leading Initial Access Threat for Law Firms

Surge in AiTM Phishing Attacks Targeting Law Firms Adversary-in-the-middle (AiTM) phishing has emerged as a...

Keycloak Vulnerability Exposes Users’ Personal Data to Restricted Administrators

Security Flaw in Keycloak Exposes User Data A serious vulnerability in Keycloak has come to...

ISMG Editors: A New Front in the Naming Conflict

Also: The AI Spending Reality Check, Nvidia Takes on Closed...

Google Develops New Names for Threat Actors

Google Unveils New Threat Actor Naming Convention in Cybersecurity In an evolving landscape of cybersecurity,...

More like this

AiTM Phishing Emerges as Leading Initial Access Threat for Law Firms

Surge in AiTM Phishing Attacks Targeting Law Firms Adversary-in-the-middle (AiTM) phishing has emerged as a...

Keycloak Vulnerability Exposes Users’ Personal Data to Restricted Administrators

Security Flaw in Keycloak Exposes User Data A serious vulnerability in Keycloak has come to...

ISMG Editors: A New Front in the Naming Conflict

Also: The AI Spending Reality Check, Nvidia Takes on Closed...