Menu
Banking Exchange Magazine Logo
Menu

Social Engineering Is Changing the Fraud Prevention Game for Banks and Credit Unions

Fraud prevention has traditionally focused on one fundamental question: Is this customer really who they say they are?

  • |
  • Written by  Frank Moreno, Chief Marketing Officer at Entersekt
 
 
Social Engineering Is Changing the Fraud Prevention Game for Banks and Credit Unions

For banks and credit unions, fraud prevention has traditionally focused on one fundamental question: Is this customer really who they say they are? That question still matters. But in an era of increasingly sophisticated social engineering and AI-generated scams, it is no longer enough.

Today, a legitimate customer can be sitting behind a legitimate device, using legitimate credentials and passing a legitimate authentication challenge, while being manipulated into authorizing a fraudulent transaction. This changes the game for financial institutions as the priority can no longer be simply detecting suspicious activity after the fact. Prevention has to move to the center of the fraud strategy.

Social engineering is making authentication harder to trust

Social engineering attacks work because they target people, not just technology.

Bank impersonation, investment scams, romance scams, phishing, and other forms of manipulation can convince consumers to hand over credentials, approve authentication requests, or authorize payments themselves. A recent State of Digital Banking Security survey highlights that these attacks can result in authorized push payment (APP) fraud: transactions that appear legitimate to traditional security systems because the customer has technically authorized them.

AI is making these attacks increasingly convincing. Generative AI can help fraudsters create highly personalized phishing messages, convincing fake websites, cloned voices, and deepfake video, producing an attack that can feel remarkably authentic to the recipient.

This matters because traditional authentication was designed primarily to establish identity. Social engineering attacks exploit something different: intent. If a fraudster can persuade a genuine customer to authenticate a fraudulent transaction, successfully authenticating that customer does not make the transaction safe.

The SMS OTP problem

One-time passwords (OTPs) delivered by SMS have been a mainstay of digital banking authentication for years. They are familiar, relatively inexpensive, and easy to deploy — but familiarity does not equal security.

New research exposes a striking disconnect: 46.7% of financial institutions still use SMS OTP as an authentication method, yet only 18.2% of consumers consider it the most secure method. This gap should give banks and credit unions pause.

SMS OTPs were never designed to defend against today's sophisticated social engineering landscape. A customer can be tricked into sharing a code with a fraudster, entering it into a convincing phishing site, or approving a request they believe is legitimate. The authentication mechanism may work exactly as intended, while the criminal gets exactly what they want. As AI makes impersonation and manipulation more credible, relying on a security control that can be socially engineered becomes harder to justify.

The answer isn't necessarily to eliminate authentication challenges altogether. It is to make authentication smarter, more contextual, and more closely connected to fraud prevention.

From detecting fraud to preventing it

The traditional model often separates authentication from fraud detection: first verify the customer, then look for signs that something is suspicious. Social engineering exposes the weakness in that approach.

If the customer has been manipulated before the transaction reaches the fraud engine, the transaction may look perfectly normal — their credentials are valid, their device may be recognized, their OTP is correct, and their behavior may even appear consistent with previous activity. The question becomes: Does this transaction make sense in context?

This requires financial institutions to look beyond the authentication event and consider the wider signals around it, including device, behavioral, and transaction data, as well as real-time risk intelligence. Combining authentication methods such as biometrics and passkeys with device signals, customer behavior, and real-time fraud analysis creates multiple security checkpoints and enables ongoing threat surveillance.

In other words, prevention isn’t about finding one perfect replacement for the OTP. It is about building an intelligent security layer that can recognize risk before a fraudulent transaction is completed.

Consumers are already telling FIs what they expect

Another factor giving banks and credit unions a reason to rethink their approach is that consumers are paying attention. In the same survey, more than 90% of consumers said security is an important factor when choosing a financial institution, and 43% said they would consider leaving their financial institution based on its authentication methods alone.

At the same time, consumers don't necessarily want more security at the expense of convenience. They want their financial institution to protect them intelligently, while giving them an experience that is simple and seamless. That is where adaptive, risk-based authentication can make a difference.

Instead of treating every login or transaction as an isolated authentication event, financial institutions can continuously assess context and risk. Low-risk activity can remain frictionless. Higher-risk activity can trigger additional verification or intervention. And suspicious transactions can be stopped before the customer unknowingly authorizes fraud.

The future of fraud prevention is proactive

There is no single authentication method that can solve every fraud problem. Fraudsters adapt quickly, and AI is accelerating that evolution.

A more comprehensive approach requires that financial institutions need to move away from siloed authentication and fraud identification toward solutions that can analyze the broader fraud picture. The industry needs to stop looking at authentication and fraud as separate parts and instead take a comprehensive view.

For banks and credit unions, that means moving beyond the question of “Did the customer authenticate?” The more important question is: “Is this customer safe to trust with this transaction, right now?”

That is the shift from detection to prevention. In a world where an AI-generated scam can be convincing enough to fool a real person, it’s a shift that financial institutions can no longer afford to ignore.


Author Bio:

Frank Moreno headshotFrank Moreno is Chief Marketing Officer at Entersekt, a market-leading provider of award-winning fraud prevention solutions for financial services organizations around the world. With over 10 years’ experience in fintech and financial services, he shares industry insights and domain expertise in digital banking and payment fraud across retail and commercial banking, credit unions, payment processors, and payment service providers.

 

 

 

back to top

Sections

About Us

Connect With Us

Resources

WEBINAR:
Your Deposits Are Going Digital

Thursday, October 8, 2026 1:00 pm – 2:00 pm ET

What community and regional banks need to understand about tokenized deposits, stablecoins, and the regulatory framework taking shape right now.

REGISTER NOW!

SPEAKER


Dana Weinstein
Dana Weinstein,
Head of Product at Tesser

Dana Weinstein is Head of Product at Tesser, bringing eight years of experience building payments products across US domestic and cross-border rails.

She launched Visa Direct Payouts, architecting a payout capability that now reaches 11 billion endpoints across cards, accounts, and digital wallets...