GenAI fraud forcing banks to shift from identity to intent

Issue 6 2025 AI & Data Analytics, Information Security, Financial (Industry)

Despite its history of resilience and globally recognised innovation, the eye-watering pace of cyberthreat evolution, characterised by rapid mutation and increasing sophistication, is forcing South Africa’s banking sector to rethink its approach to security.

In its 2024 Annual Crime Statistics report, the South African Banking Risk Information Centre (SABRIC) notes that digital banking fraud saw a significant escalation, with an 86% increase in incidents and a 74% rise in associated losses, totalling R1,89 billion. Digital banking fraud accounts for almost 70% of recorded financial losses in the banking industry. SABRIC has laid a good deal of the blame on emerging technologies, particularly Generative Artificial Intelligence (GenAI), being leveraged by criminals to craft more sophisticated schemes.

South African (SA) banks have not sat idly by; they have invested heavily in systems, partnerships, and awareness campaigns to combat crime. They, too, have turned to AI technologies to fight fraud, saving billions in fraud losses. However, the pace of fraud innovation has made chasing down the criminals a moving target for local banking leaders.

“Gone are the days when a single technology or a static set of controls can keep fraudsters at bay. The threat landscape today is dynamic, with attackers constantly probing for new vulnerabilities and exploiting gaps in traditional defences,” says Pieter de Swardt, SVP Commercial: SA & Sales Operations at Entersekt. “The complexity and velocity of modern fraud schemes, from deepfakes to fraud and scams involving social engineering, demand more than just investment in new tools. While banks are investing heavily in protecting their clients, the real test lies in their ability to adapt and expand their security net.”

A nuanced approach is required

A deliberate move toward multi-layered, adaptive security is required to mitigate these evolving threats. Rather than relying on a single line of defence, banks are increasingly turning to behavioural analytics and risk profiling to analyse intent in addition to identity.

“By constructing dynamic profiles of customer behaviour, including transaction timing, geolocation, device fingerprinting, and channel usage, banks can detect deviations that may signal fraud, even when individual transactions appear legitimate,” says De Swardt.

Banks that focus on whether the client ‘should’ be doing the transaction by analysing context, device usage, and transaction velocity to distinguish genuine behaviour from suspicious intent are reaping the rewards. According to KPMG’s Global Banking Scam Survey 2025, 60% of banks that monitor customers to understand if they are communicating with a third party while using online or mobile banking rated this as an effective fraud prevention measure.

De Swardt explains that shifting to intent-based fraud-fighting approaches also helps fight chargeback fraud, which is a growing headache for banks.

"We had an example of a bank customer reporting fraud after performing multiple transactions in succession. The first transaction was deemed legitimate, but the customer reported the next two as fraudulent. The subsequent transactions were then found to be legitimate. We were able to assist the bank to confirm that all the transactions were coming from exactly the same browser. With the forensics in place, the bank was able to get the client to confess to first-party fraud. The data is impartial and sometimes there is no third party involved,” De Swardt shares.

Cross-channel is key

Equally critical is the need for cross-channel visibility. Fraudsters increasingly exploit gaps between siloed systems, initiating transactions in one channel and authenticating in another.

De Swardt says security architectures must correlate data across originating and authentication channels with online banking, card payments, mobile apps, and other touchpoints. This holistic view enables the detection of anomalous patterns (such as a transaction initiated from an unfamiliar device and authenticated from a geographically distant location) that would be invisible in a single-channel context.

De Swardt says this nuanced approach, using as many data points as possible, allows banks to intervene only when something is suspicious, maintaining a smooth client experience, while still being vigilant against fraud.

“When risk signals indicate that a transaction matches a customer’s usual behaviour, it can be processed quickly and without extra steps. Only when something appears out of the ordinary does the system need to introduce additional authentication measures or alerts, minimising disruption for clients,” he explains.

Security is the one time that competition should not matter

Consortium intelligence is another pillar of effective cyber defence. By participating in industry-wide data sharing initiatives, banks gain access to a broader spectrum of threat intelligence, including indicators of compromise and emerging attack vectors.

“One of the defining features of SA banking is its collaborative spirit. Local banks have established open lines of communication, sharing intelligence and best practices to collectively combat fraud. One of the positive aspects of the battle against fraud is that it is not seen as a competitive advantage. It is a necessity in a region where attack vectors morph rapidly and fraudsters are quick to adapt,” De Swardt shares.

Summing up, De Swardt says the velocity of fraud evolution means that yesterday’s defences can quickly become obsolete. In this context, the technical challenge is not merely to add more layers, but to architect a security ecosystem that is adaptive, intelligence-driven, and capable of real-time response.

“By leveraging behavioural analytics, cross-channel visibility, and industry collaboration, banks can stay ahead of evolving threats while preserving the trust and satisfaction of their customers. The battle against cybercrime is only beginning, but with a new approach, as well as the right partners, SA banks are well positioned to meet the challenge,” he says.

For more information, go to www.entersekt.com




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Security has an identity problem
Access Control & Identity Management Information Security
Cybersecurity discussions have mainly focused on defence, including stronger firewalls, tighter network controls, and better endpoint security. However, in today's world, those traditional defences have become less relevant.

Read more...
Detect procurement fraud before losses escalate
Security Services & Risk Management News & Events Financial (Industry) Editor's Choice
Organisations need to move procurement fraud prevention closer to the point where suspicious activity occurs, rather than relying primarily on investigations after money has already been lost, according to SAS and FACTS Consulting.

Read more...
Modernising ‘smart’ ports
IoT & Automation Information Security Transport (Industry) Logistics (Industry)
A modern port is part of a much larger digital trade ecosystem where all systems need to work together. If one part of that ecosystem is disrupted, the impact can quickly move through the supply chain.

Read more...
Reinventing cybersecurity
NEC XON News & Events Information Security Commercial (Industry)
NEC XON helps a workforce solutions leader reinvent cybersecurity with an AI-enhanced XDR solution to keep pace with increasingly devious cyberattack techniques, including fileless malware, lateral movement, and credential misuse.

Read more...
AI fraud is outrunning banking defences
Security Services & Risk Management Financial (Industry)
South Africans are increasingly being targeted by AI-generated fraudsters who sound just like bank employees. However, many local banks are still struggling with legacy tech, slow change processes, and limited data visibility.

Read more...
AI assistants learn bad workplace habits
AI & Data Analytics Security Services & Risk Management
An employee under pressure at a logistics firm finds a productivity-boosting shortcut. Instead of manually parsing a 40-page supplier contract, they paste the confidential PDF into a public generative AI tool for a quick summary.

Read more...
Attackers are turning AI to their advantage
Information Security AI & Data Analytics
ESET's H1 2026 Threat Report analysed around 900 000 AI skills and found more than 3000 to be outright malicious, exposing a fast-growing attack surface for organisations experimenting with AI.

Read more...
SA does not have an AI problem, it has a data problem
AI & Data Analytics Asset Management
Organisations are investing in generative AI, predictive analytics and intelligent automation, driven by the promise of increased productivity, faster decision-making and competitive advantage. Yet many businesses discover AI is not delivering the results expected.

Read more...
Shadow AI: The next evolution of Shadow IT
AI & Data Analytics Security Services & Risk Management
Today, as AI gains traction in all aspects of life and business, African organisations face a new challenge, known as ‘Shadow AI’, where employees at all levels make use of AI without considering the potential impact.

Read more...
The growing AI confidence gap
AI & Data Analytics
The rapid evolution of artificial intelligence has ushered in a new era of possibilities for enterprise IT, yet it has also exposed significant vulnerabilities and a widening confidence gap among leaders.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.