FB pixel

Passkeys offer potential solution to increased deepfake attacks on financial services

Identity Policy Forum panel says agents are the next frontier of GenAI-driven fraud
Passkeys offer potential solution to increased deepfake attacks on financial services
 

Among sectors vulnerable to AI-assisted fraud attacks, the financial industry is perhaps the ripest. With high-stakes remote transactions occurring at scale, increasingly involving AI agents, there are countless attack surfaces, and potentially massive payoffs.

At the FIDO Alliance’s Identity Policy Forum, a panel led by the Better Identity Coalition unpacks a paper it drafted with the American Bankers Association within the Financial Services Sector Coordinating Commission (FSSCC), focusing on the threat of generative AI to the financial services digital identity system.

Grant begins with a key distinction when talking about “AI” and how it’s dangerous,

When people talk about AI related threats, you know, it really is focusing largely on generative AI, which is something that’s really only emerged in the last couple years. We’ve been using AI for years, more on the defense side. You know, machine learning tools have been really important in things like fraud detection used in financial services and other sectors for quite some time.”

It’s important to differentiate because machine learning systems will be key in helping enterprises manage the deluge of deepfakes GenAI has wrought. The coalition’s paper aims to support the effort, in laying out how to quantify and define attacks, and making recommendations for effective protection.

The paper breaks GenAI attacks into three different broad categories: deepfake driven social engineering and impersonation, synthetic identity creation and AI agents as attack surrogates. The latter is still an emerging concern; John Carlson of the American Bankers Association says  “we’re probably going to see a lot of the threat vector escalate in the future once agentic AI really starts to take off.” That means trying to make recommendations on threat mitigation without knowing the full extent of the threat.

In the meantime, certain security measures are now table stakes: liveness detection, multifactor authentication, and a layered model for identity fraud detection. More tools are becoming available, or at least coming to prominence – one of which is FIDO’s passkey model, and another is digital credentials such as mobile driver’s licenses (mDL).

Grant notes that, while a deepfake can pretty convincingly spoof a video, a photo, a voice, or an ID card, “one thing deepfakes can’t spoof yet at least is public key cryptography. And so because mDLs much like passkeys, are rooted in public key cryptography, it’s a technology that, while quite old and mature, can stand up against some of these more sophisticated attacks.”

Finally, the project is to “raise the tide of security for firms of all sizes,” says Ben Amsterdam, a senior vice president with DNC financial services, representing FSSCC. “Clearly multiple technological tools are going to be required to control some of this, but it also includes governance frameworks, which I think are really useful for firms to understand where they are in their journey relative to their peers and relative to where the threat is.”

Related Posts

Article Topics

 |   |   |   |   |   |   |   |   | 

Latest Biometrics News

 

Photo ID, proof of citizenship take center stage in US voting fight

The Safeguard American Voter Eligibility Act (SAVE) has become the centerpiece of a renewed congressional fight over who sets the…

 

AI fakery is turning fear into a voter suppression tool ahead of US elections

In the months leading up to the 2026 midterm elections which could see Democrats sweeping both the House and Senate,…

 

Alcatraz partners with gun violence group on school, workplace safety

Alcatraz has joined the Active Shooter Prevention Project (ASPP), a U.S.-based initiative that develops strategies to reduce risks in schools,…

 

V-Key gets PE firm backing to expand mobile digital identity security footprint

Singapore-headquartered digital identity and Mobile Application Protection and Security (MAPS) provider V-Key has a new majority investor, with Tower Capital…

 

IDfy secures $52M to pursue digital ID trust services ambitions

Digital ID verification firm IDfy has obtained funding of 476 crore Indian rupees, approximately US$52 million, to pursue its digital…

 

WSO2 to help MOSIP’s passwordless authentication platform eSignet Go Thunder

IIIT-Bangalore, home to India’s burgeoning digital public goods efforts, has formed a partnership through the MOSIP initiative it hosts with…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events