By MFJ Staff | Source: PYMNTS
Key takeaway: AI makes it easier to fake a customer’s voice, face, or behavior. As a result, banks and processors should expect identity verification to move away from single-point biometric checks and toward continuous, risk-based trust scoring, paired with tokenized, permissioned payment credentials, especially as AI agents begin initiating purchases on customers’ behalf.
Unauthorized-party fraud schemes, where attackers impersonate a legitimate customer rather than steal an isolated transaction, accounted for 71% of fraud incidents and dollar losses in 2025, up from 48% the year before, according to PYMNTS Intelligence research. PYMNTS Intelligence first reported that figure in its “2025 State of Fraud and Financial Crime in the United States” report, produced with Block; the September 2026 Payments Innovation Tracker, produced in collaboration with Paymentology, cites the same PYMNTS Intelligence data as context for a broader look at identity-based fraud. The figures are PYMNTS Intelligence’s own research and are not independently audited.
The Tracker report describes a shift from isolated fraudulent transactions toward persistent, identity-based attacks that can begin well before a payment is initiated, fueled by advances in artificial intelligence. Account takeover, synthetic identities and AI-assisted social engineering increasingly target the customer relationship itself, meaning an attacker may already hold working credentials or a convincing fake identity by the time a payment reaches authorization.
The report points to all three pillars of traditional authentication as increasingly vulnerable. Voice recognition is exposed to synthetic voice impersonation, visual verification faces similar risk as AI-generated imagery becomes more convincing, and behavioral biometrics, which track typing cadence, session duration and navigation patterns, can now be approximated by automated systems designed to mimic legitimate customer behavior.
Rather than relying on a single authentication event, such as one selfie, voice sample or login, the report describes banks moving toward continuous, risk-based verification that evaluates a broader history of interactions, transaction patterns and contextual signals. PYMNTS Intelligence also found that 68% of high-customer-lifetime-value card issuers consider stronger security and fraud prevention necessary for agentic commerce, where AI agents make purchases on a customer’s behalf. One response gaining traction is giving tokenization a larger fraud-prevention role, provisioning payment tokens with defined spending limits, merchant restrictions and permitted uses instead of exposing unrestricted credentials.
Why it matters: The research suggests fraud and risk teams should expect authentication to shift toward ongoing, context-based trust scoring, and toward tokenized, permissioned credentials.
Source: PYMNTS












