In 2024, an employee at a financial firm in Hong Kong was tricked into wiring $25 million to fraudsters after attending a multiperson videoconference in which all of the other participants were fake. The criminals used deepfake technology to impersonate the employee’s colleagues.
“At its core, digital identity verification is the process of confirming a person’s real-world identity through digital means, often by matching a government-issued ID document with a biometric selfie. However, in a world of deepfakes, proving you are you is getting harder, and verifiable credentials will become the standard for secure identity,” says Gareth Davies, Auth0 chief product officer at Okta.
DISCOVER: This is the key step beyond authentication in identity and access management.
The Growing Complexity of Today’s Fraud Landscape
Historically, fraud attempts involved using stolen passwords to access an account. Stopping this type of fraud relied on blocking unauthorized access. Today, however, fraud attempts have become much more sophisticated, says Davies.
“Some of the most devastating financial losses occur during all-green sessions, where the legitimate accountholder initiates a transaction using correct credentials,” he explains. “Through highly sophisticated social engineering and ‘authorized fraud’ schemes, victims are manipulated into authorizing transactions themselves.”
Generative artificial intelligence and large language models have made it easier both technically and financially for anyone to execute highly sophisticated attacks at unprecedented velocity. According to Davies, AI allows bad actors to automate phishing, credential stuffing and bot attacks at a massive scale that can overwhelm legacy security systems.
What Is Digital Identity Verification, and How Can Banks Support It?
Digital identity verification offers a way to extend the trust models in traditional identity and access management to verification, Davies explains. It’s built in a way that’s tamper proof, privacy preserving and instantly verifiable anywhere. Digital identity verification is “a digital, cryptographically secure way to prove something about yourself,” he says.
According to Davies, financial services institutions rely heavily on digital identity verification for critical operations throughout the customer lifecycle:
- Financial institutions are legally mandated to verify customer identities during account openings under Know Your Customer and Anti-Money Laundering regulations. This includes verifying customer details against government databases to ensure compliance.
- Digital verification is integrated with mobile and web portals, allowing customers to verify their identity and open accounts remotely in minutes.
- When a customer initiates a high-value or unusual action (such as wire transfers, loan applications or password resets), institutions trigger step-up verification. This prevents account takeover and unauthorized transactions before funds can leave the institution.
- As banks deploy autonomous AI agents to process loans or interact with customer accounts, digital identity verification is used to bind those actions to a “human in the loop” and authorize the AI agent as a secure proxy. This ensures clear, compliant audit trails and maintains the principle of least privilege in automated banking environments.
A major difference between traditional identity tools and digital identity verification is the picture provided. Traditional tools provide a one-time snapshot, which isn’t enough in a world of AI impersonation and digital-first interactions.
