Contact salesSign inSign up
AuthsignalAuthsignal
Product
Passwordless / multi-factor authentication (MFA)
Drop-in authentication
Risk-based authentication
Passkeys
Biometric authentication
WhatsApp OTP
Authenticator apps (TOTP)
Push authentication
SMS OTP
Email OTP
Magic links
See all authenticators
See less authenticators
Palm biometrics
Contactless payments & identity verification
Flexible integration modes
Pre-built UI
Low code
UI components
Customizable
Custom UI
Flexible
Digital credentials API Beta
Authenticate customers instantly using digital credentials
Session management
Keep users signed in across web and mobile after authentication
Fraud Controls
Rules and policies engine
Step-up authentication
No-code rule creation
Risk alerts
User observability
Audit trails
Dynamic linking
Why Authsignal?
Complete authentication infrastructure from enrollment to step-up auth, modular by design
Solutions
By USE CASE
View All
Account takeovers (ATO)
Go passwordless
Call center
SMS cost optimization
Existing apps
QR code payments
Step-up MFA
Palm biometrics payments
By INDUSTRY
View All
Financial services
Marketplace
e-Commerce
FinTech
Crypto
Healthcare
By Integration (identity provider)
Amazon Cognito
Azure AD B2C
Duende IdentityServer
Keycloak
Auth0
NextAuth.js
Custom identity provider
By ROLe
Engineers
Product
Passwordless / Multi-factor Authentication (MFA)
Flexible Integration Modes
Pre-built UI · Low code
UI Components · Customizable
Custom UI · Flexible
Digital credentials API Beta
Authenticate customers instantly using digital credentials
Session management
Issue JWT access and refresh tokens
Why Authsignal?
Plug in Authsignal to elevate your IDP — effortless integration with any architecture.
Drop-in Authentication
Risk-based authentication
Passkeys
Biometric authentication
WhatsApp OTP
SMS OTP
Email OTP
Magic links
Authenticator apps (TOTP)
Push notifications
Palm Biometrics
Contactless payments & identity verification
Fraud Controls
Rules and Policies Engine
Step-up Authentication
No Code Rule Creation
Risk Alerts
User Observability
Audit Trails
Use Cases
Financial services
Account takeovers (ATO)
Marketplace
Go passwordless
e-Commerce
Solutions
By Use Case
Account takeovers (ATO)
Go passwordless
Call center
SMS cost optimization
Existing apps
QR code payments
Step-up MFA
Palm Biometric Payments
View all Use Cases
By Industry
Financial services
Marketplace
e-Commerce
FinTech
Crypto
Healthcare
View all Industries
By Integration (identity provider)
Amazon Cognito
Azure AD B2C
Duende IdentityServer
Keycloak
Auth0
NextAuth.js
Custom identity provider
By Role
Engineers
PricingAboutDocsBlog
Schedule a call
Try Authsignal
AUS Flag

Authsignal secures millions of passkey transactions out of our hosted Sydney region.

AUS Flag

Authsignal secures millions of passkey transactions out of our hosted Sydney region.

Join us today!
Right icon
Blog
/
Current article
Multi-factor authentication
Passwordless authentication

Increased digitization, increased fraud risk

Paul Bickley
⬤
May 13, 2025
Share

While digitization was already making strong progress in many sectors, the COVID-19 pandemic accelerated its adoption for every sector and each consumer out of necessity. While the mass acceptance enabled most of the world to continue business as usual in some form, it opened up the doors to much greater fraud risk as tech was hastily put together for function but security was left behind on the priority list. Today, while security is slowly catching up, it’s time that businesses help customers become fully aware of the risks and steps to reduce it that’s possible on their end.

Digitization show no signs of slowing down

We are firmly in the era of digital as more becomes available online; we’ve gone beyond shopping and into the realms of learning, work, entertainment, socialising and even well-being and health. While the pandemic pushed this into sixth gear, the world has remained with the foot on the pedal with no signs of slowing down as heavier focus is placed on the digital experience for better customer experience. We need only look at recent initial ventures across the world into central bank digital currencies (CBDCs) and the rise of blockchain and the metaverse to realise the reach and direction the digital space is all going in.

Much of the fuel behind digitization today lies in fintech and personal finance offerings as they serve as the critical connection between other apps - without money and personally identifiable information available online, other apps can’t be accessed nor items paid for or validated. In 2021, VCs invested $133bn into fintech startups worldwide while by end-2025, digital transformation spend is forecasted at $2.8tn - a 56% increase from 2022’s projection. The sector is indeed only increasing and becoming more prominent.

The inevitable fraud that follows

Sadly, whenever technology advances to create more accessibility, efficiency and productivity, security risks also advance. Bad actors and malicious attackers are always aware of the latest tech, the holes in its infrastructure and the best way to infiltrate to steal data, attack businesses and commit identity fraud for personal gain.

The year to September 2021 saw 5.1mn fraud offences in the UK, a 36% y-o-y increase. This included a large increase within consumer and retail fraud. (Source: ONS)

As the fintech sector has grown at exponential rates, fraud costs are hitting new records. The UK’s Justice Committee announced that consumers were scammed out of a record £1.3bn last year alone. One of the reasons for rising fraud comes down to the very benefits that new fintech offers - more efficient and seamless customer experiences, with faster decision making and payments. It would seem that as behaviours change, more blind spots are being created for the user.

Educating customers on fraud risk

While there are technological methods to help minimise the risk of fraud, fighting it must start with educating customers so that measures and necessary behaviour changes are fully understood and so well-practised they become second nature.  

For the most part today, consumers are aware of dodgy email addresses and peculiar or unexpected messages requesting banking information but there is a lack of awareness on the newest trends in fraudulent behaviour. Educating customers on the new angles that bad actors are using today, and keeping them abreast of new methods as they are discovered, is key.

For example, as One-Time Passcodes (OTP) are commonplace via SMS for all financial institutions and Fintechs, they are therefore expected and considered safe in the user flow; however, this is fast becoming a high-risk method of authentication. Fraudulent activity like SIM swapping, which entails acquiring a user’s mobile number for OTPs, means the previously most secure method has fast become one of the least.

Another new activity is account pre-hijacking, which shows how far ahead fraudsters think and take action. By using a valid and live email address, hackers will use it to create accounts on a platform or with a company before the email’s true owner has. The account is only valuable once personal information and payment data is entered, however the hacker would be alerted once they’re added and can begin using them. There are continuously new and creative ways for fraud to take place, which customers need to be aware of so they can take extra precaution around their personal data and management of it.

Another element to educate customers on is that the more apps they use, the more risk they’re exposed to. As nearly everything in our day-to-day is digital, the reliance and even unconscious use of our apps is growing meaning that things can easily slip through the net. Having customers aware of this seemingly obvious fact will help them to question some out-of-the-ordinary steps or unfamiliar interfaces they come across, and it may also encourage them to engage with fewer apps so that tracking is made easier should there be any suspicious activity.

Best practices to help mitigate fraud risk

For fintechs, alongside ensuring a continuous educational journey for your customers, there are best practices you can implement to reduce the risk of fraud and its effects on your business and your customers.

Additional authentication

Multi-Factor Authentication (MFA) is widely acknowledged as a basic requirement now, however it’s worth regularly questioning whether there are enough methods within your process and if they are the best ones available. Passwordless authentication is far stronger today than even the automatically and randomly created ones, whether this is through biometric authentication or a piece of hardware that authenticates.

Authsignal's best in class UI and UX

Additional authentication can also look like adding challenge flows in other parts of the customer journey that step-up the authentication altogether.

Data enrichment for better behaviour analysis

Data should be utilised in its fullest in order to get the best idea of your customers, individually and collectively. Going beyond the standard data entered when the customer signed up, other data points should be included in your collection such as their IP address, device, and most common merchants used. The fuller the picture, the more in-depth behaviour analysis can take place so you remain ahead of any risk and fully in the know.

Risk scoring

While you can see the red light flash indicating a risk, it will quickly become near impossible to adequately address or understand all of the issues presented. Here is where risk scoring comes in.

With the help of better knowing your customer’s behaviour, risk scoring not only helps to prioritise the alerts that flash up but also adds to the customer’s data record helping to inform you of their risk profile. For example, if it is the same time once a month that their risk score increases, you can review any changes in their behaviour or external factors and implement additional authentication measures during these times.

<blog-button>Book Your Free Risk Assesment With Authsignal<blog-button>

Question icon
Have a question?
Talk to an expert
NewsletterDemo PasskeysView docs
Multi-factor authentication
Passwordless authentication

You might also like

How to add push authentication to your app with Authsignal and React Native
Push authentication
React native
Node.js
Multi-factor authentication
Guides

How to add push authentication to your app with Authsignal and React Native

March 27, 2026
BSP Circular 1213: Philippine banks must replace SMS OTPs by June 2026
BSP Circular 1213
Philippine banking
SMS OTP
Risk based authentication

BSP Circular 1213: Philippine banks must replace SMS OTPs by June 2026

March 18, 2026
How to add adaptive MFA and passkeys to any web app with Authsignal and Lambda@Edge
AWS
Authentication
Security

How to add adaptive MFA and passkeys to any web app with Authsignal and Lambda@Edge

March 10, 2026

Secure your customers’ accounts today with Authsignal

Passkey demoCreate free account

Authsignal delivers passwordless and multi-factor authentication as a service. Focused on powering mid-market and enterprise businesses to rapidly deploy optimized good customer flows that enable a flexible and risk-based approach to authentication.

AICPA SOCFido Certified
LinkedInTwitter
Passwordless / multi-factor authentication (MFA)
Pre-built UI (low code)UI components (customizable)Custom UI (flexible)
Why Authsignal?
Drop-in authentication
Risk-based authentication PasskeysBiometric authenticationWhatsApp OTPSMS OTPEmail OTPMagic linksAuthenticator apps (TOTP)Push authenticationPalm biometricsDigital Credential Verification API
Rules and policies engine
User observability
Industries
Financial services
Marketplace
e-Commerce
FinTech
Crypto
View all industries
Teams
Engineers
Use cases
Account takeovers (ATO)
Go passwordless
Call center
SMS cost optimization
Existing apps
View all use cases
Identity providers (IDPs)
Amazon Cognito
Auth0
Azure AD B2C
Custom identity provider
Duende IdentityServer
Keycloak
NextAuth.js
Integrations
ASP.NET
C#
Java
Node.js
Open ID Connect (OIDC)
PHP
Python
React
Ruby
Ruby on Rails
Compare
Twilio Verify vs AuthsignalAuth0 vs AuthsignalAWS Cognito vs Authsignal + AWS Cognito
Resources
BlogDeveloper docsFree Figma mobile passkeys templateFree Figma desktop passkeys templateFree Figma webapp passkeys template
Company
About usWhy AuthsignalCareersPress releasesPartnersContact us
What is
SMS OTP
Risk Based Authentication
IP Spoofing
Passwordless authentication
Multi-Factor Authentication (MFA)
United States
+1 214 974-4877
Ireland
+353 12 676529
Australia
+61 387 715 810
New Zealand
+64 275 491 983
© 2026 Authsignal - All Rights Reserved
Terms of servicePrivacy policySecuritySystem statusCookies