AI-driven fraud a ticking time bomb for financial institutions

A new report has disclosed AI-driven fraud is a “ticking time bomb” for financial institutions.

Digital identity specialist Signicat’s “The Battle Against AI-driven Identity Fraud” report found that 76% of respondents recognised that AI was a growing threat. Great. But only 22% of those organisations had started to implement measures to protect against such AI-driven frauds.

Those respondents, by the way, are all organisational fraud decision makers.

If this all sounds familiar — knowing a threat exists without doing anything about it — then you’re not wrong. My end-of-year threat roundup recounted that three scary figures. First, 44% of organisations cited a lack of AI-related cybersecurity training for employees as a critical issue. Second, 43% lacked modern AI-powered cybersecurity solutions. Third, 41% struggled with a lack of information from external experts about the evolving AI-related threat landscape.

Or how about when, earlier in December, I quoted Callie Guenther, Senior Manager of the Cyber Threat Research Team at managed detection and response provider Critical Start, as warning that a “703% increase in credential phishing and 141% rise in social engineering attacks align with the expanded use of generative AI”. And this “enables attackers to produce natural-language phishing content at scale, localise campaigns across languages, and automate deep personalisation”.

Closing the AI-driven fraud awareness/action gap

Now Signicat has warned that financial Institutions must close the awareness/action gap and invest in AI-driven identity fraud prevention. If not, companies will be vulnerable to increasingly sophisticated fraud techniques. The research, which surveyed over 1,200 fraud decision-makers from banks, fintechs, payment providers and insurance companies in Europe, is truly scary with regards to some of the findings.

First, 74% admit that they do not have the time to address the problem with the urgency it requires. Yes, really. One of the single biggest security threats facing the financial world and they don’t have the time to address it. Jeez.

Then consider that 76% report insufficient funding to deploy robust fraud prevention technologies. Please see my exasperation as displayed above and apply it here as well.

Identity Is the New Currency of Trust

As fraud grows more sophisticated and customer expectations rise, financial institutions are rethinking how they verify, authenticate, and engage users. This solution guide explores how modern identity strategies can help banks and fintechs

Click through to discover a practical roadmap for CISOs and digital leaders navigating compliance, fraud prevention and customer experience in today’s financial landscape.

Ticking time bomb in financial institutions

“Despite the alarming rise in AI-driven identity fraud techniques like deepfakes, most organisations are stuck in the planning phase,” said Pinar Alpay, Chief Product & Marketing Officer at Signicat. “The gap between awareness and action is widening, creating a ticking time bomb, especially for the financial sector and other regulated industries.”

How much of a time bomb? According to Signicat’s data, Alpay warned, “deepfake attacks only accounted for 0.1% of all fraud attempts we detected three years ago, but today they represent around 6.5%, which is an increase of 2,137% in the last three years.”

Let that sink in for a bit. Now think about the lack of time and money arguments being used by those who are meant to protect our money.

“Relying on obsolete solutions is the opposite of what’s needed,” Alpay concluded, and I can’t argue with that statement. If you are reading this and you are a “fraud decision maker” at a financial institution, then I say get a grip on yourself, do your research, make a convincing argument to find funds and time, and, dare I say it, do your bloody job before it’s too late.

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.