Financial institutions must prioritize multifactor authentication as hackers take advantage of a lack of identity protection.
In 2023, cyberattacks using valid credentials to gain access to user accounts increased 71% from 2022, according to IBM’s 2024 X-Force Threat Intelligence Index.

Rather than hacking, the attackers are able to just log in, Leah Generao, partner at financial services security at IBM, told Bank Automation News.
The spike in attacks, she said, is due to:
- A lack of authentication and identity protection;
- An increase in the compromise of active directories; and
- An increase in malware that steals information and posts it on the dark web.
“All of that gives reason to the rise in these cyberattacks using valid credentials,” Generao said.
To protect their clients’ identities, banks are pushing customers to enable multifactor authentication, including tokenization and biometric solutions, she said.
Banks including $2.5 trillion Bank of America and $3.9 trillion JPMorgan are investing in biometric solutions.
Bank of America’s CashPro platform for its commercial and corporate customers prompts them to utilize biometric solutions to enhance security.
JPMorgan has built an omnichannel payments solution that uses biometrics to create a secure checkout process, Prashant Sharma, executive director of biometric payments and identity solutions at JPMorgan Payments, previously told BAN.






