The COVID-19 pandemic has accelerated the move toward digital banking platforms, but this has come with an increased risk for fraud. The percentage of risky worldwide transactions in the financial services industry increased by 11% since early March, according to a recent TransUnion study.
“The lockdown has forced people to use digital banking channels for payments, and banks are creating better platforms to facilitate customers’ needs,” said Uri Rivner, chief cyber officer of BioCatch, a behavioral biometrics company that profiles users to catch fraudulent activities. “But, as we know, whenever there is innovation from a banking perspective, there’s also innovation from the criminal perspective.”
In 2019, $1.9 billion was lost to digital scams and the projections for 2020 are poised to surpass $2.5 billion, according to a Federal Trade Commission report.
One in six people in the U.S. have fallen victim to digital fraud in the past 12 months, with 33% of them losing more than $500, according to a recent Marqeta study. And more than $77 million has been lost to fraudulent transactions since the start of the pandemic, according to Vidya Peters, chief marketing officer at Marqeta. “Users believe that banks and financial institutions should do more to protect customers,” Peters said.
Rise of synthetic ID fraud
“Banks evolved in the past couple of years by providing biometric scanning for payments and transactions, but so did the criminals,” Rivner said. “Rather than hacking your account, they steal essential information and create a synthetic ID, which they use to steal funds from a customer’s account or open a new credit line.”
Customers often download rogue applications onto their devices, Rivner said, adding that such installations provide criminals with a gateway to remote access.
Account opening and account takeover are two specific types of fraud that have increased lately, growing by 33% and 47%, respectively, between January and April, Rivner said. Criminals are actively targeting account opening or personal loan origination by using customers’ real names along with synthetic IDs.
Neocova, a digital banking solutions company, uses both shallow and deep machine learning to track consumer behavior and flag accounts believed to be created with a synthetic ID.
“There were about 3.5 million identity theft events last year and we are expecting a 30% to 50% increase in identity theft this year,” said Sultan Meghji, co-founder of Neocova.
The company’s AI verifies bank accounts and transactions by cross-referencing them against the huge data banks they have generated over time to find similar patterns of synthetic IDs.
“The majority of banks in the space are using technology that is not equipped for the digital age,” Meghji said. “When a bank has to analyze its customer base for synthetic identity, most of the banks can’t do that.”
Phishing scam hikes
Phishing scams have skyrocketed since the start of the pandemic with a 667% increase in phishing attacks year-over-year, with more than 29% of Americans reporting being targeted, according to a TransUnion study.
“Criminals trick customers by pretending to be bankers and convince them into sharing their account information, which [criminals] can exploit, and take out a loan in their name or transfer funds from their accounts,” Rivner said. “They especially like these kinds of attacks because it gives them instant access to your money.”
Banks and other financial institutions are adopting behavioral biometrics to safeguard their customers from these fraudulent activities.
The Tel Aviv-based BioCatch, which works with banks like RBS, NatWest and Itau, tracks how quickly users respond to questions relating to personal information, and how they interact with digital forms. Customers and fraudsters interact very differently in a banking app, Rivner said, a discrepancy that can be detected by BioCatch’s artificial intelligence. The company tracks a user’s behavior on the banking platform every 20 milliseconds and is able to compare it to existing records of criminal behavior and interactions.
“When a customer is asked to input personal information like date of birth and address, they will be quick because they know it by heart, whereas a criminal will take time in verifying the information they have entered,” Rivner said. “Similarly, when asked to fill a form, a customer will take time to go over all the fields whereas a fraudster will be quick since they know the procedure very well.”
Who is responsible?
A Marqeta study that surveyed 4,000 users across the U.S. and U.K. found that 51% of digital banking fraud victims believe that they are responsible for protecting themselves against card fraud. However, while customers may accept the responsibility of safeguarding themselves against fraudulent activities, banks and FIs should do more to protect users, Peters said.
“I think that the fraudsters are going to get only more sophisticated in how they attack digital transactions,” Peters said. “The burden now falls on companies, banks, and on card issuers to ensure that the platform that they’re using is as secure as possible.”
To do so, banks must evolve their cybersecurity systems or risk losing customer confidence, Peters said. Only 31% of respondents said the risk of fraud was a fair trade-off for the convenience provided by new digital methods of payment, the report stated.
“The way digital fraud is happening today is very new and legacy platforms are challenged with meeting these new forms of fraud,” Peters said. “The problem is, when banks try to build new and modern tools on their legacy platforms, they spend way too much in resources and time.”






