Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Artificial intelligence is making it easier to create fake identities and harder for agencies to tell who’s real

Дата публикации: 18-09-2026 20:33:24

"We're really in fraud 4.0, that is an AI era where AI is underpinning a lot of the fraudulent based attacks that are happening today," said Jordan Burris.

Основное содержимое страницы с новостью.

Terry Gerton We are hearing AI headlines, I want to say almost hourly, including AI agents that are going beyond their guardrails. You’ve recently argued that AI is changing the fraud landscape. What’s a fraud scheme that’s common today that might have been much harder to pull off a few years ago without AI?

Jordan Burris You know, Terry, it’s interesting. Today, we’re in, we’re entering the era of like fraud 4.0. And if you think about the earlier instances or iterations of fraud, right? We started with what was happening with paper-based and very basic elements of fraud. Then you had the early internet era where folks were stealing usernames and passwords and PINs. And then as we got more digitally connected and socially integrated, this is where you start to see more manipulation of schemes. We talk about, we’re really in fraud 4.0 that is an AI era where AI is underpinning a lot of the fraudulent based attacks that are happening today. This is everything from, you know, leading towards the generation and manipulation of what would be our presence online. So think of like copying our faces so that way we can pretend to be individuals that we are not. This could be automated attacks that are being launched where At scale, you are having bots, think of it, that what used to be a very targeted attack that would perhaps take an hour to run can be done in seconds, can scale to tens of thousands and can be ongoing all day, right? I think a funny anecdote that one of my colleagues shared with me is that we used to actually watch the bell curve where it would be fraudsters would start their attack like work hours. They would start it early in the morning and then end at night and there’d be like a lunch break and you could see what was happening. But now, where we are today, it’s running 24/7.

Terry Gerton When I talk to people like you about this, I realize I have a failure of my personal imagination. I just can’t conceive of how some of these things happen. So when agencies get fooled today, what’s fooling them?

Jordan Burris It is, in some cases, a lot of it is it goes down to the processes by which they’ve been built on. So there is a lot inherent trust that is placed within public service, and really the digital services that have been constructed to date. We, those who worked in the public sector ecosystem for a long period of time, have operated under a mandate that for whatever the benefit is, whatever the service is, we have to get it to the right person. There is no wrong door. The challenge is that when we’re dealing with an error that is built around AI driven fraud, some of those doors are more fraught with risk than others. And so where we’ll see exploits take place today is that we will have AI driven bots that will call into call centers. Many call centers that exist across the government today still rely on asking knowledge based, authentication based questions. So what car do you drive? Who owns your mortgage? Please know that all that is available online. And now if you’re doing it and I can create a voice clone, especially for folks, because we decided to put our likenesses on social media, if I can a create a Voice Clone that sounds like me, that is now going through the prompt, answering all the questions, engaging with a live human, like this creates more of an more interesting dynamic where effectively the channels that we had relied on the trust that we placed in certain things are susceptible for exploit.

Terry Gerton You make a really important point there because fraud prevention and public access or ease of access often pull in different directions. So is there an example of a control that might reduce fraud but also make life harder for legitimate users.

Jordan Burris So I’ve seen many instances in my tenure, my career looking at, especially even going back to when I was in the White House and how we would try, people would try to put controls in place for the purpose of stopping fraud, but the effect of it is that we would make, it create more friction, we’d make it harder for individuals to engage within the ecosystem. What I believe today is that if done correctly, you actually can assess people accurately and you can do so in a frictionless manner and experience to which they become accustomed to in any digital service that they’re using online. Types of controls that can be evaluated. These are all everything from the way that biometrics may be used for helping people who potentially have locked themselves out of an account to reestablish their identity. So for an example, if you’ve gone through a rigorous upfront enrollment process that may exist today as part of creating a service for accessing an account, let’s say that you forgot your username and password, or you are that person who got locked out in the call center. You know, we’re all very used to potentially using our biometrics for like face ID, or if you’re like me who likes TSA pre-check, and I’m going through and letting them take my picture to go through, you could use your same biometric to basically unlock your account. Like that’s one type of control. Now there’s been arguments as to whether or not that is too friction-filled, or whether or that creates the right type of access for individuals. And so as an alternative, there are other controls that exist out there where you can use what are more advanced, I would say, fraud intelligence or analytics, where you’re then looking at what is happening with an identity as it is being presented in a digital form, meaning that the PII that you’re submitting, the device that you are using, the behavior of how quickly you’re filling out a form, all of these can be assessed in under a second to help paint a picture of risk. And to make this crystal clear for everyone, is that for me as a human, today, I cannot type quickly. My kids make fun of me for, despite the fact I work in tech, that when it comes to the amount of typos I put into things, or how much I have to go back and forth and reread things in a form, that I do not fill out a form pretty quickly. But if all of a sudden you have a Jordan that is showing up online, that is filling out a form in under a second, and he’s going through multiple pages, and then oh, by the way, he’s using an iPhone, where I historically have only used an Android device. I’m claiming that I’m doing this from my home in the D.C. area, but in reality my IP address is coming from a country in Africa. These are all signs that basically would pinpoint it’s probably not Jordan at the end of the day, right? And so using those types, that type of intelligence is how organizations can make more informed decisions.

Terry Gerton Jordan Burris is the head of public sector at Socure. Jordan, as you’re describing that, I’m thinking all of us are understanding more and more about that kind of scenario and what the possibilities are. But the government’s not anywhere close, at least, to the outside observer of being able to implement that. What has to happen or what has to change in government programs to move them to this more continuous risk-based verification?

Jordan Burris Yeah, absolutely. So I think there’s a few things that have to be done, right? One, there has to be, you know, very recently, it was a few months ago, I testified before Congress and highlighted a series of recommendations. I will not bore the audience by going through every single recommendation and every single talking point that came out as part of that. But look, one of the first ones that I highlighted was shifting from really looking at things around point in time compliance and driving more towards outcomes. It was very big on outcomes when I worked for the government and now that I’m outside of government, I’ve continued to be resolved that outcomes are really how we drive better improvement. And what that means is that when we’re looking at whether or not you’re able to stop fraud, whether or you’re not able to have a person move through the process seamlessly, you can measure all of those outcomes. And in doing so, you can determine whether or the controls, the layers of security or whatever that you’re putting in place. Are actually serving the purpose of the mission intended. And so you’re operating really at mission speed. I think the first thing for any agency is thinking about what does it mean to move beyond a compliance regime where you’re looking at what the latest NIST standard is, which in many cases, even to my friends at NIST, and they know I lovingly say this, it was written for a time that no longer exists. It was, you know, it is basically outdated at this moment in time. So NIST is not necessarily the ceiling, it is the floor. And the point being is, Instead we should move towards understanding outcomes. How are we driving better performance? The other piece is that fraud doesn’t stop. At first instance, there has been this argument that happens with agencies that, hey, if I stop fraud at the front door, the first time that someone goes is to engage with a digital service or any type of service that I can stop them permanently. The reality here is that’s just not the case, right? China, Russia, North Korea, it doesn’t matter what kind of nation-state you’re talking about. Their goal is to look across the life cycle of how digital services are rendered and find the path of least resistance in order to get access to those services and really to disrupt where funding is going. And then just generally, if we start to think about intelligence sharing broadly, there’s fraud signals that exist within every agency today based on the work that they’re doing. It would become more powerful if they were able to share that intelligence with each other so you can then identify what is happening dynamically with attacks that are evolving across the ecosystem. And this is not a new concept and premise. Within cyber security, every time there is a new cyber attack launched, they release what are the techniques, tactics, and procedures, or the TTPs, share them all across the country, not just within government, but across agencies, organizations, other countries in particular. We have to do the exact same thing when it comes to fraud and fraud intelligence and making sure that everyone has the best tools in front of them to defend for tomorrow.

Terry Gerton Jordan, as we’re thinking about this looking forward, is this an agency-by-agency solution given that many of these programs are managed by agencies, or is it a government integrated solution? Because I’m thinking about the complexity of deployment and the number of programs that have to be scanned. Which way should we think about going?

Jordan Burris There’s many models that can be deployed and I’ve been on both sides, many sides of the debate and every permutation that there is. Here’s what I would say is that I do believe that there should be shared infrastructure. There should be shared services that are being leveraged by the government in order to better help them defend and have kind of a unified view, unified visibility into what is happening with fraud intelligence. These services have to be adaptable. These services that be flexible and they have to be transparent to the agencies themselves so that way understand where they’re actually taking on risk overall. The White House, for an example, released a memo related to pushing and mandating login.gov. for digital-facing services. Login.gov, as part of its components or as part the services it provides, offers what would be identity verification technologies and fraud prevention technologies. That may be a good first step for agencies who are just getting started to thinking about what could be done as to leveraging a government-wide service to be able to help protect things of the front door. But then also may not be enough and the OMB did rightfully recognize that there may be other iterations of how different fraud prevention tools could be layered in with whatever you’re doing with these types of services to make sure that you’re actually stopping fraud across the entire life cycle and so you know it’s going to be kind of an evolution in maturity for every single organization that is engaging here and I for one am encouraged that at least we’re having the dialog to say it’s time to move forward in this regard.

Terry Gerton Let’s go back to your congressional testimony for a minute, because Congress really is a player in this. Many of the rules that agencies operate under are established in statute by Congress to support their oversight functions. So when you’re thinking about compliance versus outcomes, how are you seeing Congress rethink their role in terms of oversight, in terms of funding, and in terms of compliance.

Jordan Burris It so it’s interesting I think right now for where we are within Congress rightfully and there’s been, you know, I applaud the members of Congress that have engaged in the rich dialog to understand what is actually is happening in identity or what is happening and fraud and how do we potentially move forward. The reality here is that Congress is responsible for the funding that is provided to agencies for them to make changes. They’re responsible for their rules that sometimes agencies are having to abide by. For an example, there’s many instances where government payments are rendered to people because of a time frame by which they have to be submitted and if the agency identifies they’re potentially risky, they still have to pay them. And then the ideas that they’ll claw back later, classic pay and chase mentality, Congress very easily could change that rule, right? Change those requirements, change that mandate in particular. So I view Congress as being kind of a necessary partner to this conversation because they set up and put in place a lot of the framework that has to be by the agencies have to abide by as they’re continuing to execute and really providing the resourcing that’s necessary to make the changes that are required.

Copyright © 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1AI ‘is changing the game’ in fraud threats and prevention efforts, SSA OIG official says05.0216-09-2026
2From fulfilment to finance: How AI is reshaping everyday fraud for businesses08.9524-11-2025
3AI Without Guardrails Is Driving a New Era of Cybercrime014.0124-07-2026
4Как мошенники обманывают россиян с помощью искусственного интеллекта08.1825-08-2026
5A.I. Is Making Scams Hard to Spot. Here’s How to Protect Yourself.07.8428-05-2026
6AI Sends Global Crime Syndicates Into Fraud Nirvana018.4705-08-2026
7صعوبة تمييز الوجوه المولدة بالذكاء الاصطناعي تزيد مخاطر الاحتيال06.0502-08-2026
8AI hasn’t gone rogue. It’s worse than that01018-08-2026
9How AI Is Changing The Scam Landscape And What You Can Do To Stay Safe With Coinbase0724-06-2026
10AI is giving hackers an edge. Here’s how to protect yourself from online scams013.3310-08-2026

Классификация: Наука. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 9.88. Источник: federalnewsnetwork.com.