Jonathan Chew · · 6 min read

Combating fraud in the age of generative AI

In partnership withIMDA Accreditation

Imagine you’re a know-your-customer analyst who works in financial services. Your job is to verify identities, check for fraud, and only then do you digitally onboard the customer.

One day, you receive a video application that seems a little bit strange. You can’t place your finger on it, but something seems off. The person’s cheek is just a little too stiff, their eyes lacking a little bit of expression.

Surprise! You’ve come across a deepfaked video.

Today, generative AI-driven fraud has advanced to a level where it’s virtually indistinguishable from real photos and videos. How can firms prevent such fraud effectively?

“GenAI has triggered a whole new set of challenges for financial institutions. The cost of using tools that can fake your face or ID card has gone down a lot, making them a lot more accessible for malicious actors,” says Dong Shou, co-founder and chairman of Advance.ai, which provides digital identity verification, risk management, and underwriting solutions for enterprise clients.

The deepfake dilemma

Dong recalls that in 2016, many financial institutions, especially in Indonesia, still faced difficulties with remote and digital customer onboarding. This was one of the reasons that contributed to a large underbanked population.

He had a firsthand experience with the problems arising from this reality when he hired a local driver for a trip.

According to Dong, the driver became uncontactable at some point. He then found out that it was because the driver was struggling to get an urgent loan to pay for a relative’s emergency medical bill.

Dong Shou, co-founder and chairman of Advance.ai / Photo credit: Advance.ai

After this incident, Dong realized that many people in the country still didn’t have a credit history with financial institutions. This made it difficult for them to secure loans from formal sources.

As such, he co-founded Advance.ai to help these institutions use the tech – in areas such as the know-your-customer (KYC) process, credit scoring, and underwriting – to digitally onboard and assess the credit worthiness of unbanked and underbanked customers.

It was part of the first big wave of AI in financial services, which included capabilities such as computer vision, natural language processing, and machine learning.

The launch of ChatGPT in 2022 precipitated a new wave – generative AI, which was easier to access and use. As such, malicious actors were quick to take advantage of it. In fact, a report found that deepfake incidents in the fintech sector increased by 700% from 2022 to 2023.

In Southeast Asia, this problem is exacerbated by the fact that many financial institutions haven’t fully incorporated digital tools to combat genAI fraud. They still rely on manual submission of documents for user applications and onboarding.

“Identity fraud is a big challenge in certain markets,” Dong adds. “Some countries lack a centralized government database to verify the authenticity of these documents.”

He also notes that deepfakes are among the most common attack vectors that he and his team have seen. This is where fraudsters swap out their actual face for an AI-generated one.

“These types of attacks are very challenging, as they can bypass most types of verification tech,” Dong explains.

Moreover, with the amount of breached information available and re-sold on places like the dark web, it’s become a lot easier for fraudsters to download someone else’s documents or biometric data and create an avatar that can be used in tricking financial institutions.

Just last year, for instance, an employee at a Hong Kong finance firm fell for a scam that used a deepfake video of their CFO, giving the fraudsters US$25 million.

Dealing with these types of sophisticated fraud attempts at scale, whether they’re carried out through fake loan applications or direct attacks, has “become much more serious for financial institutions,” Dong says.

Attacks on all sides

One of the key reasons why these genAI attacks are so detrimental is that businesses often don’t realize they’ve fallen victim, sometimes even for weeks or months.

Dong points out that this isn’t a sector-specific problem – everything from ecommerce to crypto and ride-hailing firms face similar challenges.

But beyond the financial consequences and the risks that come with information leaks, businesses’ reputations are also at stake when these scams occur.

“Imagine if a bank became a victim of fraudsters and it resulted in not just monetary losses, but also people’s information getting released,” Dong says. “No one would trust the security at that bank anymore.”

Apart from targeting businesses, fraudsters may also copy an individual’s identity and use it for nefarious purposes, like applying for loans under the victim’s name.

At the moment, some measures across the region could help. Dong highlights the AI Verify framework in Singapore, which is meant to encourage key stakeholders to develop responsible AI tech. Ultimately, these developments could help combat genAI fraudsters.

In Indonesia, Otoritas Jasa Keuangan (OJK), the country’s financial services authority, is working with Bank Indonesia and the Ministry of Communication and Digital Affairs to develop measures aimed at protecting consumers against AI-generated scams and fraudsters.

“We need a lot more awareness and education around genAI and related fraud threats, and how people really need to protect their information,” Dong points out.

Fighting the good fight

Dong believes that public-private partnerships play a key role in protecting and educating both businesses and consumers. While companies can offer the most up-to-date information, government agencies can disseminate it nationally.

“We need to share about how deepfakes happen, how it can impact the lending or onboarding process, and also general purpose security best practices, such as how to protect your personal and biometric information,” he says.

Dong also suggests cross-border collaboration between the region’s various regulators, such as OJK and the Monetary Authority of Singapore, so these agencies can pool their resources and increase the effectiveness of new solutions and approaches to combat genAI fraud.

Speaking of solutions, it turns out the best tech to deal with genAI fraud is AI itself. This is because algorithms can pick out details missed by humans.

“With face-swapped photos, for example, it’s so difficult for people to tell the difference between real and AI-generated ones – but AI can do it,” Dong explains.

For example, companies like Advance.ai offer specialized algorithms and a multi-layered approach to detect subtle signs of deepfaked photos and videos.

There’s another benefit to using AI: it can help financial institutions improve user experience.

For example, they can alert users when suspicious transactions take place and provide contextual explanations like, “We noticed this is your first transaction from this device in 3 months. Please confirm.”

True change

To really take protections against genAI fraud to the next level, solutions and education alone won’t be enough.

According to Dong, the shift in attitudes has to come from the top, especially for businesses.

“C-suite leaders need to understand the gravity of the situation and the sophistication of modern fraudsters,” he says.

Then, taking genAI fraud seriously has to extend across all functions and teams within the firm.

In the meantime, solution providers like Advance.ai will keep investing heavily in R&D to stay at the forefront of the latest genAI-powered threats and develop effective countermeasures.

“With genAI being so accessible, the threat possibilities are always evolving, and we all – organizations and individuals – need to be prepared against such threats,” Dong says.


The IMDA Accreditation program was launched in 2014 to accelerate the growth of promising Singapore-based enterprise tech companies and help them establish their credentials, build business traction, compete in the global market, and gain more opportunities to showcase their solutions to spur adoption. Learn more about how IMDA Accreditation can make a difference in your business.

LEARN MORE

Advance.ai is one of Southeast Asia’s leading providers of digital identity verification, KYC/KYB, compliance, risk management, and credit information services. Speak to its experts to learn more about its solutions here.


This content was produced by Tech in Asia Studios, which connects brands with Asia’s tech community. Learn more about partnering with Tech in Asia Studios.

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

How would you feel if you could no longer use Tech in Asia?

Editing by Winston Zhang and Mina Deocareza

(And yes, we’re serious about ethics and transparency. More information here.)

TIA Writer

Jonathan Chew

Has a strange liking for grabbing tiny plastic things on wooden walls