# The rise of passive authentication in the fight against fraud
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2019-02-19
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: The Rise of Biometric Authentication &amp; Synthetic Identity Fraud
Meta Description: Learn how biometric authentication and anomaly detection can safeguard your information from cyber criminals and prevent identity fraud. Stay ahead of the
URL: https://financedigest.com/rise-passive-authentication-fight-fraudhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/fd230318-1-2-1736839154542-compressed.jpg)

_By **Antony Bream**, Global Head of Enterprise Sales, AimBrain_

In the four years since AimBrain was born, we have seen a meteoric rise in the capabilities of today’s wider biometric authentication modules, but similarly a staggering rise in the sophistication of fraud capabilities. No longer opportunities or curious hackers looking to exploit bugs for fun, today’s fraud rings are as capable and organised as legitimate enterprises

**You have been pwned**

Credential breaches are reaching staggering figures; this month both Quora with 100 million users breached and Marriott with 500 million users’ personal information including passport details and in some cases c [redit card information](https://wealth.globalbankingandfinance.com/creditcards/)…there is no doubt about it, it is extremely unlikely that you have not been breached. Worryingly, even those who have been breached continue to use passwords that they know to have been stolen, one study showed [86% of Cashcrate subscribers](https://www.troyhunt.com/86-of-passwords-are-terrible-and-other-statistics/) continued logging in with passwords already leaked in other data breaches.

**Can we take it all back?**

![Antony Bream](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/anthony-450x675-1736839154550-compressed.jpg)

Antony Bream

So how do we ‘unfeed the data dragon’ and reclaim our [personal](https://www.financedigest.com/data-privacy-and-navigation-how-our-personal-data-is-used-in-navigation-apps.html "Data Privacy and Navigation: How our personal data is used in Navigation Apps.") data that is in the public domain; copies of passports, scans of birth certificates, medical records, bank statements? How do we ensure that it’s not our information being sold on the dark web; name, social security/national insurance number, last known address?

We can’t. Which makes it all the harder to counter an increasingly smart synthetic identity business. Using stolen, fraudulent and real identities, or combinations thereof, criminals are now applying for credit cards, bank accounts and other financial [services open](https://www.financedigest.com/facilitating-open-finance-through-secure-services.html "Facilitating open finance through secure services") to them. Mule accounts assist the quick dissemination of money gathered through illicit means, often making the recuperation difficult or impossible, and at the mercy of the financial [services](https://www.financedigest.com/how-advanced-self-service-technologies-are-changing-the-face-of-finance.html "How Advanced Self-Service Technologies are Changing the Face of Finance") organisation to repay.

**A united front**

I’m pleased to see that there is more and more consolidation of both [data and experience in the industry](https://www.financedigest.com/average-annual-uk-grocery-bill-highest-since-at-least-2008-industry-data.html "Average annual UK grocery bill highest since at least 2008 -industry data"), particularly around problems like mule accounts. Suspicious individuals and historic account behaviour is helping [today’s banks](https://www.financedigest.com/bridging-the-gap-between-banking-and-digital-accessibility-in-todays-digital-by-default-world.html "Bridging the Gap Between Banking and Digital Accessibility in Today’s ‘Digital by Default’ World") identify dormant mule accounts and stop the abuse before it happens, with data sharing helping to paint wider and richer pictures of the fraud ecosystem.

Alongside this, [machine learning and deep](https://www.financedigest.com/deep-fryer-machine-market-one-the-most-booming-industry-in-upcoming-years-due-to-global-demand-in-industry-by-2028.html "Deep Fryer Machine Market| One the Most Booming Industry in Upcoming Years Due to Global Demand in Industry by 2028") learning are increasingly being deployed in order to pinpoint specific behaviours attributed to criminals. The obvious indicators are well documented; fraudsters’ preferences for long weekends for example, or keystroke patterns for particular pieces of personal information. But deep learning is self-evolving, which means that it can now consume unprecedented volumes of [data and spot patterns that humans could never hope](https://www.financedigest.com/oil-eases-as-weak-asian-data-more-lockdowns-dampen-demand-hopes.html "Oil eases as weak Asian data, more lockdowns dampen demand hopes") to, continually refining to create ever more precise models.

These models can now be used at the new account opening stage in the [fight against synthetic identity fraud](https://www.financedigest.com/why-an-orchestrated-digital-identity-strategy-is-vital-for-financial-organisations-in-fighting-fraud.html "Why an orchestrated digital identity strategy is vital for financial organisations in fighting fraud"), to be able to pinpoint patterns in manual fraud, not just protect against bots.

**Anomaly detection as a first sweep**

Using anomaly detection such as this, to identify fraud before a user’s profile exists, stops fraud from getting into an organisation and setting down roots. But what about those that seek to exploit legitimate customers? Account takeover or phishing attacks for example?

This is where other [biometric authentication](https://www.financedigest.com/why-latin-america-chose-biometric-authentication-for-payment-cards.html "Why Latin America Chose Biometric Authentication for Payment Cards") factors come in. Behavioural authentication for example continuously and passively authenticates a [user’s behaviour – across any device](https://www.financedigest.com/signalling-device-market-competitive-growth-strategies-based-on-type-applications-end-user-and-region.html "Signalling Device Market Competitive Growth Strategies Based on Type, Applications, End User and Region") with a keypad, touchscreen, mouse or keyboard – and monitors for signs of change. Too far away from the behavioural template, and a bank can invoke another [security challenge; a password reentry or active authentication step like fingerprint or selfie](https://www.financedigest.com/education-security-in-2022-hybrid-cloud-device-management-drives-it-challenges.html "Education Security in 2022: Hybrid-Cloud, Device Management Drives IT Challenges").

**Passive and active**

Abnormal transactions or changes to personal information such as address, email or back-up [phone numbers](https://www.financedigest.com/your-phone-number-on-google-search-giant-now-takes-removal-demands.html "Your phone number on Google? Search giant now takes removal demands") for example, could use a combination of passive and active steps. Behaviour authentication can invisibly be paired with device location or ID, and if either falls out of a risk tolerance levels, an active step be invoked [demanding the user](https://www.financedigest.com/catharanthine-market-2022-research-on-user-demand-size-applications-key-players.html "Catharanthine Market 2022 Research on User Demand, Size, Applications, Key Players:") fulfil a particular activity such as a voice authentication or facial authentication.

What’s more, these authentication tools are more often than not delivered via APIs, which means that they slot easily into a [bank’s risk](https://www.financedigest.com/selfie-awareness-the-cyber-risk-going-undetected-in-banks.html "Selfie-awareness: the cyber risk going undetected in banks") engine. The bank can adjust its own decisioning trees for specific use cases, configuring passive and active [biometrics as part of its wider multifactor authentication](https://www.financedigest.com/behavioral-biometrics-simple-and-secure-way-to-authenticate-consumers-digital-identities.html "Behavioral Biometrics: Simple and Secure way to Authenticate Consumers’ Digital Identities") strategy. They work with risk scores to construct the risk models that suit the impact and likelihood of a breach, yet the complexity of the security is all but invisible to the [end user](https://www.financedigest.com/sodium-tetraborate-market-key-players-end-user-demand-and-consumption-by-2030.html "Sodium Tetraborate Market Key Players, End User, Demand and Consumption by 2030").

**It’s a [bright future](https://www.financedigest.com/german-home-solar-power-firm-sees-bright-future-as-demand-soars.html "German home solar power firm sees bright future as demand soars") for algorithms**

Furthermore, we’re [seeing developments](https://www.financedigest.com/the-next-upcoming-years-to-see-the-dental-lasers-market-develop-on-an-organic-note.html "The Next Upcoming Years To See The Dental Lasers Market Develop On An Organic Note") in deep learning to be able to learn from existing annotated data – data that has correctly been previously categorised as fraud for example. Whilst the financial [services industry](https://www.financedigest.com/financial-services-industry-blazes-the-trail-for-cloud-migration-post-pandemic.html "Financial services industry blazes the trail for cloud migration post-pandemic") only has a finite amount of records, and whilst this can’t be scaled beyond the fraud that they’re capturing, our Machine Learning team are seeing more effort go into reusing data. One way is through transfer learning (training models on one task and using this as a starting point for different, typically more complex tasks), as well as unsupervised and self-supervised learning, models drawing inferences from unlabelled or uncategorised data, and prediction modelling using part-labelled data, respectively.

It’s an extremely exciting time for fintechs as financial [services firms](https://www.financedigest.com/how-financial-services-firms-can-mitigate-against-their-top-data-security-threats.html "How Financial Services Firms Can Mitigate Against Their Top Data Security Threats") see the real-world benefits of machine learning in fraud detection. The pairing is complementary; AI-focused fintechs like ours can continue to focus on research and development for fraud detection, whilst [banks can benefit](https://www.financedigest.com/online-banking-benefits-and-risks-of-managing-your-finances-online.html "Online banking: benefits and risks of managing your finances online") from our solutions, and the modelling capabilities can continue to evolve to help solve the fraud of tomorrow.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

