Fighting AI deepfakes and identity risk in financial services

Fighting AI deepfakes and identity risk in financial services

As financial institutions adopt AI and digital assets, a new risk is emerging in verifying who or what is participating in financial systems. At the same time, Generative AI is enabling more sophisticated impersonation, from synthetic identities to deepfakes and autonomous agents operating within these environments. Olli Krebs, SVP EMEA at Incode, explores how this convergence of breached data and AI-driven impersonation is reshaping financial risk.

How is AI-driven impersonation reshaping financial risk for institutions today?

    The nature of financial risk is undergoing a fundamental shift. Historically, institutions focused on securing assets – protecting accounts, transactions and infrastructure from unauthorised access. But today, attackers are increasingly bypassing those controls altogether by targeting identity itself.

    Generative AI has made it possible to convincingly impersonate real users, employees and even entire organisations at scale. Deepfake video calls and AI-generated documents are becoming mainstream attack tools. This creates a scenario where systems can be technically secure, but still compromised because they are interacting with what appears to be a legitimate user.

    As a result, identity has become the new security perimeter. The key challenge is no longer simply preventing access, but ensuring organisations can reliably verify who is interacting with their systems at any given moment.

    How is this shift to identity-based attacks impacting key moments in the financial customer journey?

      Across the financial customer journey, attackers are targeting the key moments where trust is established and acted upon. Synthetic identities and AI-generated documents are enabling fraudsters to pass onboarding checks and enter systems appearing legitimate from the outset. From there, impersonation techniques such as deepfakes can be used to bypass authentication processes, particularly in higher-touch interactions like customer support or video verification.

      The risk then escalates at the transaction stage, where attackers shift from access to manipulation, convincing legitimate users or internal stakeholders to approve payments or transfers. At this point, the activity appears valid within the system, making it significantly harder to detect.

      What makes this particularly challenging for financial institutions is that each stage may appear secure in isolation. This is why organisations need a more continuous and connected approach to verification, rather than relying on controls at a single point in time.

      How are attackers moving beyond traditional fraud techniques in this new era of AI-driven identity attacks?

        We’re seeing a clear move away from traditional tactics like phishing or credential stuffing, toward more sophisticated forms of social engineering and impersonation – ‘Fraud 2.0.’

        Instead of hacking systems directly, attackers manipulate legitimate users into taking actions themselves, approving transactions, sharing sensitive information or granting access. AI significantly accelerates this. Fraudsters can now deploy automated agents that test thousands of attack paths simultaneously, refining their methods in real-time.

        Deepfakes are a particularly powerful tool here. An attacker can impersonate an individual on a video call to authorise a payment or mimic a customer during a verification process. These attacks are highly targeted and increasingly difficult to detect with traditional security measures.

        What role do AI agents and automation play in increasing these risks?

          AI agents introduce a new layer of complexity because they can act autonomously within financial systems. On one hand, this brings efficiency and innovation. On the other hand, it raises important questions around accountability and trust.

          If an AI agent is initiating transactions, making investment decisions or interacting with customers, institutions need to verify intent as well as identity.

          At the same time, attackers are using AI to automate fraud at scale. What once took months of manual effort can now be executed in minutes, across thousands or even millions of attempts. This creates an asymmetry where attackers only need to succeed once, while defenders must stop every attempt.

          The combination of autonomous systems and automated attacks means that identity verification can no longer be a one-time event, it has to be continuous.

          What does ‘continuous identity’ look like in practice for financial institutions?

            Continuous identity is about moving from point-in-time verification to ongoing, real-time assurance. Instead of verifying a user once at onboarding, institutions need to assess identity and risk signals throughout the entire lifecycle of an interaction.

            This involves combining multiple layers of intelligence – biometric verification, device signals and contextual data – to build a dynamic picture of trust.

            The goal is to detect risk earlier, ideally before a transaction is authorised or a user is compromised. Importantly, this needs to be done in a way that minimises friction. Security cannot come at the expense of usability, especially in highly competitive financial environments.

            Ultimately, continuous identity is about embedding trust into every step of the user journey, rather than relying on a single checkpoint.

            What practical steps should financial institutions take to stay ahead of these threats?

              The first step is recognising that identity is now central to fraud prevention. Institutions need to shift their mindset from reactive detection to proactive prevention, identifying risks before they materialise.

              This means investing in technologies that can analyse signals in real time and at scale, including AI-driven detection and advanced biometrics. It also requires breaking down internal silos so that data can be shared across systems, enabling a more holistic view of user activity.

              Equally important is education, both internally and for customers. Many modern attacks exploit human behaviour, so awareness is a critical line of defence.

              Finally, collaboration will be key. Fraud is a networked problem, with attackers sharing techniques and moving quickly between platforms. Financial institutions, technology providers, and regulators need to work together to share intelligence and build more resilient, collective defence strategies.

              In this new landscape, trust is no longer a given, it has to be continuously earned and verified.

              Browse our latest issue

              Intelligent Fin.tech

              View Magazine Archive