Skip to main content
The Signicat Blog
Thais Guillen

Expert writer on digital identity

AI in banking: are your defences ready for AI-generated identity fraud?

AI in banking is changing how financial institutions defend against increasingly complex threats. This article explores how banks must upgrade their identity verification and continuous monitoring to stop AI-generated attacks and protect their customers.

The state of banking security: why 70% of banks are seeing more identity fraud

The current state of banking security reflects a landscape where digital convenience often exposes new vulnerabilities. Signicat's recent study of 900 companies across regulated sectors, including a specific panel of banking institutions, reveals that 70% of the banks surveyed report an increase in identity fraud attempts over the past year, and 64% report attacks being more successful. Traditional, static security measures struggle to manage these modern, AI-generated threats. Criminal networks now operate with high sophistication, targeting the weakest points in the customer journey. Financial organisations must adapt their defences quickly to prevent substantial financial losses and maintain customer trust.

Signicat banking fraud stats: 70% of companies saw more identity-fraud attempts, and 64% reported more successful cases.

Anatomy of an attack: from synthetic identities to AI-generated deepfakes

Synthetic identity fraud and deepfakes are advanced attack methods where criminals combine real and fake data, or use artificial intelligence, to bypass standard checks. Fraudsters no longer rely solely on stolen passports. They build entirely new, fabricated identities using fragments of legitimate information. Furthermore, AI-generated deepfakes allow criminals to impersonate genuine customers during video verification steps. Understanding these specific, technology-driven tactics is the first step in building a resilient defence system.

Beyond onboarding: the hidden risk of account takeover (ATO) in banking

Account takeover (ATO) in banking occurs when a criminal gains unauthorised access to a legitimate user's online bank account. While many institutions focus heavily on the initial onboarding phase, criminals frequently target existing, trusted accounts using automated scripts and AI tools. Once they compromise an account, fraudsters can drain funds, apply for loans, or use the account for money laundering. Securing the perimeter is necessary, but monitoring the activity inside the account is equally vital to stop ATO.

According to our study, 34% of the banking decision-makers interviewed reported ATO as the costliest drain, followed by social engineering (28%) and ID forgery (27%).

The AI arms race: using machine learning for real-time risk scoring

Real-time risk scoring is an automated process that uses machine learning algorithms to evaluate the threat level of a transaction or login attempt instantly. According to our recent research, 73% of banking institutions believe AI is actively being used against them by criminal networks. As fraudsters apply artificial intelligence to scale their attacks, banks must respond with equally advanced technologies. Machine learning models analyse thousands of data points in milliseconds, identifying unusual patterns that human investigators would miss. This approach allows institutions to block fraudulent activity before it causes harm.

Modernising your identity fraud detection framework: a 2026 strategic guide for banking

A modern identity fraud detection framework is a structured approach that integrates multiple layers of security to monitor users from their first application through every subsequent transaction. Building this framework requires a shift from isolated security tools to a unified strategy. As we look toward 2026 and 2027, financial institutions need robust systems that provide high security without complicating the customer experience. 

Below is a summary of the key challenges and the primary targets for fraud, based on insights from the banking leaders interviewed in our broader study of 900 regulated institutions.

Fraud trends in the banking sector

Fraud categoryPrimary targetImpact on institutionDetection method
Account takeover (ATO)Existing user accountsLoss of customer trustContinuous assurance
ID forgeryOnboarding checkpointsCompliance failureAdvanced document checks
Synthetic identityCredit applicationsHigh financial lossBehavioural analysis
Social engineeringCustomer credentialsUnauthorised accessReal-time risk scoring
Loan fraudLending productsDirect financial drainIdentity verification (IDV)
Digital wallet fraudMobile transactionsReputational damageContinuous assurance
Credential stuffingLogin portalsHigh support costsReal-time risk scoring

Layer 1: identity verification (IDV) and automated digital onboarding

Identity verification (IDV) and automated digital onboarding are the first lines of defence, using biometric and document checks to confirm a user's true identity. A strong start is critical. By applying robust checks at the very beginning of the customer relationship, banks can keep bad actors and AI-generated personas out of their systems entirely. This layer relies on high-quality data and sophisticated document analysis to ensure that the person applying for an account is exactly who they claim to be.

Layer 2: implementing continuous assurance for the entire customer lifecycle

Continuous assurance is the ongoing monitoring of user behaviour and device data after the initial login to detect anomalies indicative of fraud. Trust is not a permanent state. A user who passes initial verification might have their device compromised a week later. By evaluating risk at every interaction, banks can detect sudden changes in behaviour, location, or device usage. This ongoing vigilance ensures that the true customer remains in control of their account at all times.

Frequently asked questions (FAQ)

  • Banks use a combination of identity verification (IDV) during onboarding and continuous assurance throughout the customer lifecycle. This includes advanced biometric liveness checks to catch deepfakes, alongside machine learning models that analyse user behaviour to detect anomalies.

  • Identity theft involves stealing a real person's complete identity. Synthetic identity fraud involves combining real and fake information to create an entirely new, fictitious persona, making it much harder for traditional systems to detect.

  • Initial checks only confirm identity at the point of entry. Continuous monitoring evaluates risk during every login and transaction, allowing banks to detect account takeovers and compromised credentials long after the onboarding process is complete.