ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Challenges in voice biometrics: Vulnerabilities in the age of deepfakes

February 15, 2024
Reading Time: 4 mins read
Challenges in voice biometrics: Vulnerabilities in the age of deepfakes

Weak identity authentication and verification protocols can result in compromised online accounts and diminished information security.

By Dominic Forrest

Accelerated by the global pandemic, the number of digital banking users has increased exponentially in recent years. In fact, research shows that the number of users is expected to exceed 3.6 billion by 2024, representing a 54 percent increase from 2020. Much of this growth can be attributed to online banking adoption by those who were previously unbanked.

This shift to more remote financial services has created a hurdle in the form of identity verification that must be overcome. When a remote user applies for an account, product, or service, how can a financial institution verify the user is the real owner of a genuine identity? How can a bank ensure that a remote customer is the same person each time they return rather than an imposter or a synthetic identity? Coupled with the sharp global growth of cyber-related financial crime and the result is a huge challenge.

In the digital landscape, voice biometrics technology has become the most common method for verifying identity through voice analysis. The technology was initially embraced for its potential to expedite and secure customer authentication within the financial sector, the premise behind it being that an individual’s voice is both ever-present and uniquely their own. In addition, customer service calls have traditionally been the main form of communication and using voice biometrics has meant that customer authentication could take place over the same channel. However, malicious actors have employed generative AI voice clips, known as ‘vishing’ or voice deepfakes, to infiltrate financial accounts. This unsettling trend has ignited concerns about the diminishing reliability of voice biometrics, earning it a reputation as one of the most vulnerable forms of biometric authentication.

This proliferation and widespread availability of generative AI tools has led to a substantial upswing in the development and accessibility of voice cloning technology, which can convincingly replicate authentic voices and is one of the key factors contributing to the frailties of voice biometrics. Studies from MIT and Google have demonstrated that merely one minute of voice data suffices to generate persuasive, human-quality audio. The apprehension regarding voice biometrics’ efficacy is so pronounced that earlier this year Senators questioned leading financial institutions about their strategies and planned actions to counter deepfake voice fraud.

While synthesized voice technology has a range of wider user applications, here our focus centers on its role in organizational security, with specific reference to remote authentication and identity verification. As mentioned, voice biometrics predominantly serves to authenticate returning customers by passively analyzing speech patterns as they speak. It is also deployed in applications where users are prompted to tap a button or utter a passphrase such as for step-up authentication. Further critical shortcomings of voice biometrics include issues relating to identity assurance, performance and user accessibility leading to further doubt being cast on its suitability for safeguarding large-scale transactions and critical operations.

Looking at biometrics more broadly it certainly offers a far more dependable means of identity assurance versus traditional methods such as one-time passcodes. But it does still face the ongoing challenge of an evolving threat landscape. Failure to confirm an individual’s real-time presence (liveness) and authentication will leave the technology vulnerable to spoofing or “biometric attacks.” There are several different liveness detection solutions available on the market today and careful attention should be given to selecting the most effective approach.

Facial biometric technology provides a robust and considerably more secure alternative to voice biometrics. It’s versatile and can facilitate the verification of unknown customer identities at onboarding, ongoing user verification and transaction authentication. Additionally, it can be cross-referenced with government-issued ID documents, a capability not available to voice biometrics. Another significant drawback of voice biometrics is its ineffectiveness in securing the most vulnerable point in the user journey: onboarding. Consequently, it provides no defense against the most pervasive and damaging identity fraud, such as synthetic identity fraud, thus failing to furnish both users and organizations with the requisite identity assurance.

Liveness detection is a crucial feature embedded in facial biometric solutions, which distinguishes between a genuine live user and presented artifacts, like photographs or masks, as well as generative AI created deepfakes. The proliferation of digitally injected synthetic media such as deepfake videos and images, generated by sophisticated AI software, depicting individuals engaging in actions they never undertook, is burgeoning. It’s an attack vector that is being used to defraud banks and their customers. Identifying these attacks or even more recent phenomena such as face swaps has become exceptionally difficult. They are almost impossible to spot by the naked eye and that’s why relying solely on human judgement alone is woefully insufficient.

Such technology enables bad actors to move beyond presentation attacks, circumventing face verification technology by digitally injecting synthetic media into the authentication process. This so-called crime-as-a-service economy is growing fast across the globe. In 2022 injection attacks occurred five times more frequently than persistent presentation attacks across the web. Detection is only possible with advanced tools and expert analysis. Considerable responsibility rests with technology companies, which must implement rigorous measures to monitor and counter the potential exploitation of this technology by criminals.

The issue of online identity verification carries profound implications and is a significant task for financial organizations to overcome in today’s digital economy. Weak authentication and verification protocols can result in compromised online accounts, diminished information security, and weakened defenses at digital borders.

Regrettably, voice biometrics falls short in providing the essential identity assurance measures to withstand the ever-evolving threat landscape. Similarly face-to-face video calls are also an inadequate defense against synthetic imagery, as the human eye can be spoofed. Specialized technology is required. The deployment of passive one-time face biometrics during verification and authentication sequences have proven to be the most effective, usable and inclusive way to safeguard against the threat of digital injection attacks. And while facial biometrics is still viewed by many as science fiction, it undeniably offers the most secure means of safeguarding online identities. Financial organizations should recognize its imperative role in today’s digital landscape, where identity assurance is more crucial than ever.

Dominic Forrest is chief technology officer for iProov.

Tags: Artificial intelligenceBiometricsDigital bankingFraudIdentity fraudVoice banking
ShareTweetPin

Related Posts

Personalized Marketing? Not Without Email

Bank marketers ramp up email marketing prowess

Retail and Marketing
June 17, 2026

Emerging opportunities are in behavioral triggers, abandonment follow-up, predictive next-best-action and segmented journeys.

FDIC delays deadline for compliance with new signage requirements

Government watchdog agency suggests changes to FDIC supervision, HUD disaster recovery

Compliance and Risk
June 16, 2026

The FDIC should take further steps to strengthen its bank supervision, and HUD should take steps to mitigate fraud in federal disaster recovery and improve manufactured housing financing, the Government Accountability Office concluded in separate reports.

Bank, credit union groups unite against Welch-Gooden bill

ABA Viewpoint: Higher upfront APRs were a policy choice

Policy
June 15, 2026

Three key choices by lawmakers and regulators pushed credit card pricing toward higher annual percentage rates. Rate caps would have even more unintended consequences for consumers.

Four Ways Banks Protect Seniors by Reducing Social Isolation

A national campaign to fight impostor scams targeting seniors

Compliance and Risk
June 15, 2026

By participating, banks can help ensure that more consumers are better prepared to recognize and avoid fraud.

ABA urges FinCEN to reevaluate BOI collection burden on banks

FinCEN updates guidance for financial institutions on sharing information about fraud

Compliance and Risk
June 12, 2026

FinCEN issued an updated fact sheet to clarify how financial institutions can share information with each other about suspected fraud under the provisions of the USA PATRIOT Act.

Reports explore information exposure, costs of data breaches

Report: Software vulnerabilities become top vector for data breaches

Compliance and Risk
June 12, 2026

Exploitation of software vulnerabilities has become the most common initial access vector for data breaches, according to the most recent Data Breach Investigations Report by Verizon.

NEWSBYTES

Senate, House committee leaders reach agreement on housing bill

June 16, 2026

OCC revises how it designates minority depository institutions

June 16, 2026

Government watchdog agency suggests changes to FDIC supervision, HUD disaster recovery

June 16, 2026

SPONSORED CONTENT

Why Your Systems Keep Slowing Down — and What to Do About It

Examiners Are Now Looking at Your Non-Core Systems

June 11, 2026
Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

June 1, 2026
A Modern Blueprint for Serving High-Net-Worth Families

A Modern Blueprint for Serving High-Net-Worth Families

May 28, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

AI Is in Your Bank. Is Your Cloud Contract Governing It?

May 20, 2026

PODCASTS

Podcast: Understanding bank regulators’ guidance on illegal immigration

June 11, 2026

Podcast: Creating a feeling of welcome, for customers and new bankers

May 28, 2026

Podcast: How consumer deposits drive full relationship banking

May 14, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.