GenAI fraud forcing banks to shift from identity to intent

Issue 6 2025 AI & Data Analytics, Information Security, Financial (Industry)

Despite its history of resilience and globally recognised innovation, the eye-watering pace of cyberthreat evolution, characterised by rapid mutation and increasing sophistication, is forcing South Africa’s banking sector to rethink its approach to security.

In its 2024 Annual Crime Statistics report, the South African Banking Risk Information Centre (SABRIC) notes that digital banking fraud saw a significant escalation, with an 86% increase in incidents and a 74% rise in associated losses, totalling R1,89 billion. Digital banking fraud accounts for almost 70% of recorded financial losses in the banking industry. SABRIC has laid a good deal of the blame on emerging technologies, particularly Generative Artificial Intelligence (GenAI), being leveraged by criminals to craft more sophisticated schemes.

South African (SA) banks have not sat idly by; they have invested heavily in systems, partnerships, and awareness campaigns to combat crime. They, too, have turned to AI technologies to fight fraud, saving billions in fraud losses. However, the pace of fraud innovation has made chasing down the criminals a moving target for local banking leaders.

“Gone are the days when a single technology or a static set of controls can keep fraudsters at bay. The threat landscape today is dynamic, with attackers constantly probing for new vulnerabilities and exploiting gaps in traditional defences,” says Pieter de Swardt, SVP Commercial: SA & Sales Operations at Entersekt. “The complexity and velocity of modern fraud schemes, from deepfakes to fraud and scams involving social engineering, demand more than just investment in new tools. While banks are investing heavily in protecting their clients, the real test lies in their ability to adapt and expand their security net.”

A nuanced approach is required

A deliberate move toward multi-layered, adaptive security is required to mitigate these evolving threats. Rather than relying on a single line of defence, banks are increasingly turning to behavioural analytics and risk profiling to analyse intent in addition to identity.

“By constructing dynamic profiles of customer behaviour, including transaction timing, geolocation, device fingerprinting, and channel usage, banks can detect deviations that may signal fraud, even when individual transactions appear legitimate,” says De Swardt.

Banks that focus on whether the client ‘should’ be doing the transaction by analysing context, device usage, and transaction velocity to distinguish genuine behaviour from suspicious intent are reaping the rewards. According to KPMG’s Global Banking Scam Survey 2025, 60% of banks that monitor customers to understand if they are communicating with a third party while using online or mobile banking rated this as an effective fraud prevention measure.

De Swardt explains that shifting to intent-based fraud-fighting approaches also helps fight chargeback fraud, which is a growing headache for banks.

"We had an example of a bank customer reporting fraud after performing multiple transactions in succession. The first transaction was deemed legitimate, but the customer reported the next two as fraudulent. The subsequent transactions were then found to be legitimate. We were able to assist the bank to confirm that all the transactions were coming from exactly the same browser. With the forensics in place, the bank was able to get the client to confess to first-party fraud. The data is impartial and sometimes there is no third party involved,” De Swardt shares.

Cross-channel is key

Equally critical is the need for cross-channel visibility. Fraudsters increasingly exploit gaps between siloed systems, initiating transactions in one channel and authenticating in another.

De Swardt says security architectures must correlate data across originating and authentication channels with online banking, card payments, mobile apps, and other touchpoints. This holistic view enables the detection of anomalous patterns (such as a transaction initiated from an unfamiliar device and authenticated from a geographically distant location) that would be invisible in a single-channel context.

De Swardt says this nuanced approach, using as many data points as possible, allows banks to intervene only when something is suspicious, maintaining a smooth client experience, while still being vigilant against fraud.

“When risk signals indicate that a transaction matches a customer’s usual behaviour, it can be processed quickly and without extra steps. Only when something appears out of the ordinary does the system need to introduce additional authentication measures or alerts, minimising disruption for clients,” he explains.

Security is the one time that competition should not matter

Consortium intelligence is another pillar of effective cyber defence. By participating in industry-wide data sharing initiatives, banks gain access to a broader spectrum of threat intelligence, including indicators of compromise and emerging attack vectors.

“One of the defining features of SA banking is its collaborative spirit. Local banks have established open lines of communication, sharing intelligence and best practices to collectively combat fraud. One of the positive aspects of the battle against fraud is that it is not seen as a competitive advantage. It is a necessity in a region where attack vectors morph rapidly and fraudsters are quick to adapt,” De Swardt shares.

Summing up, De Swardt says the velocity of fraud evolution means that yesterday’s defences can quickly become obsolete. In this context, the technical challenge is not merely to add more layers, but to architect a security ecosystem that is adaptive, intelligence-driven, and capable of real-time response.

“By leveraging behavioural analytics, cross-channel visibility, and industry collaboration, banks can stay ahead of evolving threats while preserving the trust and satisfaction of their customers. The battle against cybercrime is only beginning, but with a new approach, as well as the right partners, SA banks are well positioned to meet the challenge,” he says.

For more information, go to www.entersekt.com




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Growing adoption of AI at work
News & Events AI & Data Analytics
AI adoption accelerates worldwide, with South Africa making gains amid uneven diffusion. Locally, South Africa ranks 46th of 147 economies measured, and its AI usage increased to 23,1% in Q1 2026.

Read more...
Enterprise AI hits the wall
News & Events AI & Data Analytics
Demands for AI privacy and sovereignty expose the limits of architectures built for centralised and borderless data flows. Organisations that redesign early are gaining a measurable edge in AI readiness and scale.

Read more...
71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...
Cyber resilience is the real defence
Security Services & Risk Management Information Security Infrastructure
Cyber resilience has evolved into a form of strategic agility, ensuring that when an interruption occurs, the business does not just survive; it snaps back into place before the market even notices a pause.

Read more...
Video accelerates smart manufacturing processes
Hikvision South Africa AI & Data Analytics
Combined with the reliability of video systems and industrial IoT connectivity, large-scale AI transforms video from a record-keeping tool into a core intelligence engine for the factory.

Read more...
Enabling the next wave of intelligent innovation
Altron Arrow AI & Data Analytics
Across the African continent, organisations are increasingly recognising AI as a catalyst for economic growth, operational efficiency, and digital transformation. Yet, one critical challenge continues to slow adoption: access to the right infrastructure.

Read more...
AI trust depends on resilient data foundations in critical industries
AI & Data Analytics
The latest South African Generative AI Roadmap 2025 found that 67% of respondents reported current GenAI adoption, up from 45% in 2024, a sharp shift from planning to active use.

Read more...
Employees are SA’s biggest cyber threat
Security Services & Risk Management Information Security
South Africa experienced a 46% increase in insider cyber risk in 2026, surpassing the global average of 44%. What is more, 63% of South African companies surveyed expect insider-driven data losses to increase.

Read more...
Surge in AI-enabled cybercrime and a 389% increase in ransomware
News & Events Information Security
Cybercrime no longer functions as a series of isolated campaigns; it operates as a system, with malicious hackers operating across an end-to-end life cycle and compressing the attack life cycle with shadow agents.

Read more...
Taking control of IAM in the AI era
Access Control & Identity Management AI & Data Analytics
AI and Shadow AI are proliferating, creating a series of new risks for organisations. To gain control over who and what has access to corporate data, organisations need unified control over their entire environment.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.