Identity

Why yesterday’s identity security standards no longer work for banks

(Adobe Stock)

COMMENTARY: Banks are at a cybersecurity inflection point. Anthropic’s powerful Mythos model has prompted alarm throughout the industry.

The power of agentic agents has also become another important concern. Banks and bad actors alike are deploying autonomous agents — each with its own identity — to scale and streamline their operations. The result has been a crowded and tenuous security landscape that demands change before disaster strikes.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

Traditional authentication methods like passwords have long been vulnerable to phishing and other attacks, but AI has created extra urgency as identity-based methods take center stage. Static login methods that verify identity just once no longer offer enough security when those signals are easily faked or stolen.

Instead, identity security needs to become a dynamic, ongoing practice that scrutinizes user and agent identities without introducing more friction.

That’s a delicate line to walk, but a business-critical one. User experience has become one of the cornerstones of trust in the banking world, as 91% of global customers rate a bank’s customer experience as important as its products, and 28% of those people say it’s more important. Nearly half (47%) said they’d leave a bank over poor user experience. Customers want their money to feel secure while also being able to transact freely.

Account takeover (ATO) and authorized push payment (APP) fraud are two of the most common traditional methods for bad actors to target banks and their customers. ATO occurs when an attacker gains unauthorized access to a legitimate user’s account, often through phishing, stolen credentials, social engineering, malware, or session hijacking. APP fraud occurs when a bad actor manipulates a legitimate user into sending them money rather than giving them access to their account. Both are experiencing a resurgence as AI makes them easier to execute at speed and scale.

These social engineering attacks are less about brute force and more about manipulating customers themselves. In late 2025, the FBI warned that ATO losses for the year exceeded $262 million, with attackers creating convincing duplicates of legitimate sites to coerce login information from users.

The barrier-to-entry for these sorts of schemes have lowered in recent years. It’s especially true as AI has reached a level where it can mask some of the traditional telltale signs of phishing and other malicious activity. With the help of AI, bad actors can disguise their communications and impersonate banks in direct engagements with the user, possibly even resorting to deepfakes. Victims are pressured into making instant payments to what they think are legitimate parties, only to find that they are fraudulent and they’ve lost the money.

That’s made all the more important by AI agents that can adeptly handle tasks like these and become activated by attackers in attempts to exploit vulnerabilities. According to KPMG, 81% of businesses have experienced attempted or successful AI-powered fraud. Even a well-trained eye can easily get tricked when attackers use AI and financial pressure to their advantage.

Teams need to make their long-term goal reducing reliance on passwords and other shared secrets by adopting phishing-resistant authentication while also protecting account recovery and authenticated sessions.

Phishing-resistant passwordless methods, such as passkeys, use public-key cryptography to reduce the risk of credential theft and offer a simpler user experience than passwords. According to the FIDO Alliance, 63% of IT professionals rank passkeys as a priority investment area and believe they can create significant cost savings and efficiency gains. Of those who had already adopted passkeys, 85% reported strong satisfaction. With reducing customer friction a core priority for banks, passkeys offer a dual benefit: a simpler user experience and stronger protection against phishing and credential theft.

Many countries, like the United Kingdom, have adopted legislation requiring banks to reimburse victims’ fraud losses, a massive drain on funds. Legislation like this represents an important shift and potential reckoning for unprepared banks. We need to bind transactions to signals that attackers can’t steal or fake. Here’s where an identity-centric strategy needs to take center stage, and that might mean relying more on cryptography, biometrics, or device-bound authentication.

The threat landscape has evolved past what traditional authentication and security methods can manage, especially for the financial services industry. We are at a watershed moment where banks cannot afford to stay complacent. They must build robust, identity-centric capabilities to protect themselves and their customers as AI creates new threats and supercharges existing ones.

Ashish Jain, chief technology officer, OneSpan

SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

You can skip this ad in 5 seconds