Identity fraud has evolved from simple account takeovers to sophisticated AI-powered impersonation techniques. All these challenge traditional security measures.
At the sidelines of the Singapore Fintech Festival 2025, LexisNexis Risk Solutions’ director of fraud & identity in APAC, Thanh Tai Vo, also revealed a trend that demands immediate attention from tech and financial sectors.
“Most fraud was third-party fraud, where someone takes over an account without the owner’s consent,” he explained. “Now, we’re seeing an increasing trend of impersonation scams and authorised push payment fraud, where victims are coerced into sending money themselves.”
The most notorious example he highlighted is a sophisticated scam where fraudsters “impersonated the CFO of a Hong Kong company during a very convincing teleconference meeting and convinced a finance employee to send over USD25 million.” This 2024 incident demonstrates the potential scale of AI-driven impersonation.
Over a year later, this journalist has still not heard of a satisfying enough solution that could have prevented that incident (or even future ones) from happening.
AI as a double-edged sword
Thanh also shared about the use of deepfake technology during the customer onboarding process to generate fictitious documents or manipulate them.
A comprehensive analysis of LNRS’ digital identity network from May 2024 uncovered a startling statistic: “Sixty-eight percent of onboarding touchpoints involve some level of AI manipulation.”
We look at whether the identity is authentic during KYC (know-your-customer) processes, check if the account has been compromised, and analyse transaction behaviour.
Thanh Tai Vo
This includes generating fictitious documents and using AI to create forged documents that look legitimate. This is a trend that is growing “by 50 to 100% year-on-year,” according to Thanh.
Thanh sees fraud from two aspects, the first being the human that initiates the fraud process and the second being bots that are predictable and therefore easier to detect. It is with human-initiated activities that LNRS takes a multi-layered approach to defense.
Multi-layer approach and industry collaboration
The key to combating these advanced threats lies in a nuanced approach. “We use a multi-layer approach,” Thanh noted. “We look at whether the identity is authentic during KYC (know-your-customer) processes, check if the account has been compromised, and analyse transaction behaviour.
“Information sharing is one of the most powerful tools of (detection),” Thanh emphasised. This involves creating consortiums where financial institutions share fraud anomalies, flagging suspicious accounts, phone numbers, and email addresses.
Here, LNRS has played its role by facilitating industry information sharing in Singapore, Hong Kong, and Japan.
Balancing customer friction and verification
Thanh voiced a strong opinion about intervening into the customer journey – it is not good for business.
Here is where the multi-layer approach comes in, and risk signals; or resignals; are monitored throughout the customer journey, from the moment they login till they make payment at checkout.
If these risk signals (resignal) fall within the range of normal customer behaviour, the transaction is allowed to proceed uninterrupted. However, if a signal stands out as unusual or suspicious compared to a customer’s historical patterns, LNRS may apply added checks, mitigation steps, or even block the transaction to prevent fraud and financial crime.
In this way, its solutions can create a more seamless experience for customers, for example bypassing the need for OTP or one-time pin codes that authenticate the account user, when there is low risk.
This is where risk appetite and risk assessment comes in; for small value transactions of USD1, there may be no need for OTP.
Regulatory priorities
Thanh wanted to call out the APAC reality; the absence of regulations that are standard across the different countries in the region. “Some (country) regulators require you to have a real-time fraud detection system, other regulators do not have that requirement.”
The lack of regulatory standards in APAC is challenging for fraud detection because different countries and regions have varying requirements, making it difficult to implement consistent, real-time fraud detection systems across borders.
This fragmentation prevents the adoption of unified, effective controls to combat impersonation in digital as well as in-person scenarios. Information sharing is currently one of the most powerful collaboration tools in the fight against fraud, and Thanh finds it promising that some countries have enacted or created legal frameworks for organisations to share data while preserving the privacy of individuals.









