Close Menu
    • Fintech Startups Malaysia – List of Fintech Startups and Fintech Companies in Malaysia
    • About Fintech News Network
    • Work With Us
    • Contact Us
    • Media Kit
    • Advertise With Us
    • Fintech Malaysia Newsletter
    • Submit Fintech Startup
    • Submit Press Release
    • Submit Interview Request
    • Submit Fintech Event
    • Webinar Inquiry APAC
    LinkedIn Facebook X (Twitter) YouTube RSS
    • About
      • About Fintech News Network
      • Work With Us
    • Contact Us
    • Media Kit
    • Advertise With Us
    • Fintech Malaysia Newsletter
    • Submit Press Release
    • Submit
      • Submit Press Release
      • Submit Fintech Startup
      • Submit Interview Request
      • Submit Fintech Event
      • Submit Your Vacancy
      • Webinar Inquiry APAC
    • Fintech Events in Malaysia
    • MY Fintech Startup Directory
    Fintech News Malaysia
    part of Fintech News Network

    Fintech News Network

    LinkedIn Facebook X (Twitter) Instagram YouTube TikTok RSS
    Free Newsletter
    • Blockchain
    • Digital Banking
    • Lending
    • Payments
    • Insurtech
    • Wealthtech
    • Regtech
    • Report
    • Startups
    • Events
    Fintech News Malaysia

    Fintech News Network

    Home»Security»Once a Fraudster Gets In, the Bank Might Think That They’re You
    Security Sponsored

    Once a Fraudster Gets In, the Bank Might Think That They’re You

    Ryt Bank, Entrust and former Security Bank COO explain why stopping account takeover now requires banks to look beyond the login screen.
    Izzat Najmi AbdullahIzzat Najmi AbdullahAugust 26, 20268 Mins Read
    LinkedIn Facebook Twitter Copy Link Telegram Email
    Account-Takeover-Fraud
    Share
    LinkedIn Facebook Twitter Telegram Copy Link Email
    Free Newsletter

    Get the hottest Fintech Malaysia News once a month in your Inbox

    A bank can authenticate the right customer at 9.01am and still lose control of that session by 9.05am, without a single failed login anywhere in between.

    Those four minutes, the window right after a customer proves who they are, are where account takeover fraud increasingly plays out now, according to bank and security executives speaking on a recent Fintech News Network webinar.

    Banks have spent years tightening the front door with multi-factor authentication, device binding and biometrics. As those defences have improved, fraudsters have started looking for ways around them.

    Some account takeover attacks are now targeting customers after they have already passed those checks, according to Goh Ser Yoong, CISO of Ryt Bank.

    Account Takeover Fraud

    “The password is now not going to be the top prize,” Ser Yoong explained. “The authenticated session will be.”

    Session cookies and other authenticated credentials can let an attacker resume a login without ever entering the customer’s password.

    Ser Yoong pointed to infostealer malware and adversary-in-the-middle attacks as the techniques being used to obtain them. A fake login page, for instance, can sit between a customer and the bank during what looks like a normal login.

    Once an attacker has what they need to hijack the session, the password has already done its job. Everything about that login can still look legitimate long after control of it has actually changed hands.

    Account Takeover Fraud Is Becoming a Trust Problem

    Harvinder Singh, RVP APAC for Identity Security at Entrust, connects this shift to a wider change in account takeover fraud.

    Stolen passwords and OTPs remain useful, though attackers can now combine compromised identity data with malware, social engineering and deepfakes.

    AI now lets fraudsters personalise those attacks using a victim’s own leaked credentials and social media details, writing phishing messages in the customer’s language that are harder to tell apart from a genuine interaction.

    “ATO has moved from stealing credentials to stealing trust,” Harvinder observed.

    Lucose Eralil, former COO of Security Bank Corporation, put it differently.

    “Fraud has moved on from breaking in to exploiting trust gained after entry,” Lucose added.

    Once a fraudster controls something the bank already regards as legitimate, an authenticated session, say, getting through the login screen is no longer the main hurdle.

    Banks then have to decide whether the trust they have already granted still holds.

    One Suspicious Action Rarely Tells the Whole Story

    Keeping track of that trust means watching what happens after authentication.

    Logging in from a new device is not inherently suspicious. Customers change their contact details, add beneficiaries and transfer money every day.

    Harvinder argued that the risk changes when several of those events appear together, such as a customer logging in from a new device, changing contact details and adding a beneficiary.

    A fraud system assessing each event in isolation may see several ordinary actions. Connect them and the pattern becomes harder to dismiss.

    “This is one entire risk story,” Harvinder noted.

    Entrust describes the approach as “continuous trust,” where identity is reassessed as the customer moves through the account rather than settled once onboarding or login is complete.

    The principle sounds straightforward. Putting it into practice is harder when those signals are scattered across different parts of a bank.

    Banks May Already Have the Signals

    Onboarding, authentication, account recovery and transaction monitoring often fall under different teams, each responsible for its own controls.

    A fraudster moving through the same account does not encounter those organisational boundaries.

    Lucose believes this fragmentation is one reason banks can struggle to recognise account takeover fraud even when warning signs already exist somewhere in their systems.

    Account Takeover Fraud

    “It’s not the lack of tools. It’s not the lack of data,” Lucose explained. “It is the absence of what I would call a single decision layer, and a single owner who can convert those signals into actions.”

    Each of those signals might sit with a different system entirely, so no single control has the full picture.

    Lucose later asked who owns the combined decision when several weak signals fire together.

    He argued that better-performing banks are moving towards controls that cover more of the fraud lifecycle, including phishing-resistant authentication, transaction binding and real-time fraud management.

    That matters more as the technology banks use to verify customers comes under attack too.

    Deepfakes Are Going After What Banks Trust

    Biometric verification has made it harder to pass an identity check with a stolen password alone, pushing some attackers toward the biometric process itself.

    Earlier deepfake attacks often centred on fake photos or videos meant to convince someone they were looking at a real person. Harvinder pointed to injection attacks that instead feed manipulated content directly into the verification process, bypassing the camera capture the system expects.

    Entrust’s Identity Fraud Report, cited during the webinar, found deepfakes involved in one in five biometric fraud attempts, with deepfake selfie attacks up 58% and injection attacks up 40% in a year.

    “The face matching is no longer enough,” Harvinder warned.

    A successful match says less if the capture process feeding it has already been tampered with.

    Session hijacking follows the same logic. Strengthen one control, and attackers look for the point where the system starts trusting the customer, then exploit what happens next.

    Continuous monitoring can help, though pushing it too far creates another problem.

    Stronger Fraud Controls Can Quickly Become Customer Friction

    A bank could respond to every change in behaviour with another authentication request, but customers would probably hate it.

    Ser Yoong highlighted the tension between fraud prevention and the experience of legitimate users. Routine activity on a familiar device shouldn’t trigger the same scrutiny as unusual behaviour right after a new login.

    Verification should scale with the risk of the activity, not apply evenly to everything.

    Account Takeover Fraud

    “The answer is not to make every journey painful,” Harvinder stressed.

    Context helps banks tell ordinary behaviour apart from signs that control of the account may have changed, drawing on device information, customer behaviour and recent transaction activity.

    Preventing account takeover increasingly means knowing when to challenge trust again, without making every legitimate customer prove themselves twice.

    Banks are already trying to solve that problem for human customers. Agentic payments could add software to the equation.

    AI Agents Extend the Same Problem

    Agentic payments could allow AI agents to make purchases or carry out financial actions on a customer’s behalf.

    Delegating authority to software changes who is acting on an account, but banks still need to know whether the action being taken matches the authority originally granted.

    Ser Yoong believes attackers could eventually target the agent itself.

    “When the agent is holding a delegated authority, compromising the agent will be the next target,” Ser Yoong warned.

    Prompt injection is one possible attack route. Instead of stealing a password, an attacker could try to manipulate an authorised agent into acting outside the customer’s intent.

    Harvinder said banks would need to know which agent is acting, who authorised it, and under what limits, including when that authority expires or can be revoked.

    “In the agentic world, we will need to authenticate intent, authority and accountability,” Harvinder explained.

    Lucose would rather keep reusable credentials away from the agent altogether.

    “Don’t let the agent possess the credential at all,” Lucose advised.

    A scoped, signed and expiring mandate can define what the software is allowed to do, and for how long.

    Agentic payment volumes remain small today, so most of this is still being worked out. The security problem, however, is already familiar to banks dealing with account takeover fraud.

    Passing authentication establishes trust at one point in time. Keeping that trust valid once someone, or something, begins acting on the account is where the harder work starts.

    Lucose captured the issue in the final minute of the webinar.

    “The fraudster past onboarding is no longer an intruder in the system,” Lucose remarked. “The system already thinks that they are the customer until it is on the onus on us in banks to prove otherwise.”

    Watch the full webinar on YouTube for the complete discussion on how account takeover is evolving beyond onboarding and authentication.

    Entrust will also be hosting an Identity Innovation Forum in Kuala Lumpur, Malaysia, with event details as follows:

    • Theme: From eKYC to ATO Defense: Building Continuous Trust
    • Date: 10th September 2026 (Thursday
    • Time: 9.30am to 2.00pm
    • Venue: VE Hotel, Kuala Lumpur

    Register here to attend the event

     

    Featured image: Edited by Fintech News Singapore based on an image by Magnific.

    Entrust Ryt Bank Security Bank
    Share. LinkedIn Facebook Twitter Telegram Copy Link Email

    Author

    Izzat Najmi
    Izzat Najmi Abdullah

    Izzat Najmi is a Senior Writer for Fintech News Malaysia.

    Related Posts

    Inside the Roundtable Where Malaysian Bank Leaders Admitted Their AI Gaps

    September 7, 2026

    Visa Sets Out Malaysia Security Roadmap for AI-Driven Payment Fraud

    September 4, 2026

    Malaysians Lose RM28.67 Million to QR Code Scams in Six Months

    September 4, 2026

    CIMB Users Need SecureTAC to Approve Online Transactions From 19 Sept

    September 3, 2026

    Ryt Bank Users Can Now Apply for Loans Up to RM100K Through Ryt Credit

    September 3, 2026

    Is Your Money Safe If a Malaysian Digital Bank Suddenly Shuts Down?

    August 28, 2026

    New Malaysia Research Center Targets AI Cybersecurity Challenges

    August 20, 2026

    Ryt Bank Says It Is Now Malaysia’s Largest Digital Bank With 1.5 Million Users

    August 20, 2026
    SecuritySponsored

    Thales Maps Out a Complete Institutional Digital Asset Security Framework

    August 24, 2026
    Fintech Malaysia Newsletter
    Subscribe to the most important Fintech Malaysia News
    Follow Us
    • LinkedIn
    • Facebook
    • X / Twitter
    • Instagram
    • YouTube
    • TikTok
    MY Fintech Startup Directory

    Malaysia Fintech Startup Directory

    Cloud Sponsored

    Multicloud Environments Look Efficient, Until the Clock Starts on Recovery

    Annette RowenaAugust 14, 2026
    Featured Fintech eBook

    Featured Fintech Reports

    Sumsub Report

    LexisNexis Solutions

    Featured Fintech Event

    Hong Kong FinTech Week and StartmeupHK

    Entrust

    Featured Webinar Replay

    Featured Fintech Videos

    TNG Digital

    Featured Fintech Job

    Sales Operations Associate

    Whitepapers & E-Books
    State of Digital Trust: AI Governance Benchmark
    State of Digital Trust: AI Governance Benchmark
    Sumsub
    Upcoming Fintech Events
    BFSI IT Summit 2026
    September 9, 2026
    Malaysia
    -
    Kuala Lumpur
    Cyber Security Summit 2026
    September 10, 2026
    Malaysia
    -
    Kuala Lumpur
    Entrust Identity Innovation Forum — Malaysia 2026
    September 10, 2026
    Malaysia
    -
    Kuala Lumpur
    Featured
    AI Revolution Summit Malaysia 2026
    September 22, 2026
    Malaysia
    -
    Kuala Lumpur
    LIDAC26
    September 24, 2026
    Malaysia
    -
    Kuala Lumpur
    Featured
    Promote Event View More
    Fintech Jobs
    Rating
    Senior Product Manager, AI Automation
    Kuala Lumpur, Full-Time
    Ryt Bank
    Director, Funding & Capital Markets
    Kuala Lumpur, Full-Time
    Fintonia Group
    Head of Banking Operations
    Selangor, Full-Time
    GXBank
    Remittance - Head, Compliance
    Kuala Lumpur, Full-Time
    TNG Digital
    Director, Account Executive
    Kuala Lumpur, Full-Time
    Visa
    Navigation
    • About Fintech News Network
    • Advertise With Us
    • Media Kit
    • Work With Us
    • Contact Us
    • Fintech Malaysia Newsletter
    • Submit Press Release
    • Submit Fintech Startup
    • Submit Fintech Event
    • Submit Your Vacancy
    • Submit Interview Request
    • Fintech Events in Malaysia
    • Malaysia Fintech Startup Directory – List of Fintech Startups and Fintech Companies in Malaysia
    • Privacy Policy / Disclaimer
    Other Fintech News Network Publications
    Fintech News Malaysia
    Fintech News Singapore
    Fintech News Hong Kong
    Fintech News Philippines
    Fintech News Network Indonesia
    Fintech News Network Australia
    Fintech News Switzerland
    Fintech News Baltic
    Fintech News Nordics
    Fintech News America
    Fintech News Network UAE
    Fintech News Africa
    Get Informed

    Subscribe to Updates

    Subscribe to the most important Fintech Malaysia News

    LinkedIn Facebook X (Twitter) YouTube RSS
    • About Fintech News Network
    • Advertise With Us
    • Media Kit
    • Work With Us
    • Contact Us
    • Fintech Malaysia Newsletter
    • Submit Press Release
    • Submit Fintech Startup
    • Submit Fintech Event
    • Submit Your Vacancy
    • Submit Interview Request
    • Fintech Events in Malaysia
    • Malaysia Fintech Startup Directory – List of Fintech Startups and Fintech Companies in Malaysia
    • Privacy Policy / Disclaimer
    © 2015 - 2026 Copyright CK Finanzpro GmbH. All Rights reserved.

    Type above and press Enter to search. Press Esc to cancel.