As home to some of the world’s fastest-growing digital banking populations, paired with aggressive real-time payment rails, Asia Pacific has become fertile ground for increasingly sophisticated fraud rings. The same conditions that make its banking sector a global benchmark for convenience also make it an attractive target.
The reality of attackers using deepfakes to exploit the environment is only becoming more pronounced. The Arup attack in Hong Kong in 2024 and more recently, the Singapore scam involving deepfakes of the prime minister demonstrate that these incidents are already happening.
Synthetic media attacks are no longer a novelty confined to isolated cases but a scaled, repeatable tactic that institutions across the region must now plan around as a matter of course.
According to Interpol, more than half of the markets surveyed in the region now report that cybercrime accounts for more than 30% of all nationally recorded crime, with financial services among the sectors most exposed to the resulting wave of ransomware and cyber-enabled fraud.
Deepfakes: from novelty to operational threat
The Arup case and the Singapore impersonation incident show what that growth looks like in practice. The attacks are now convincing enough to bypass the human judgment that financial institutions have long relied on as a final control. When a voice, a face, and a familiar meeting format are all fabricated convincingly, basic intuitive checks like “does this look and sound right” are no longer dependable safeguards.
What confounds security teams is how quickly the threat has moved from theoretical to operational. A few years ago, deepfake fraud was a slide in a conference presentation about future risks. Today, it’s a line item in incident response plans.
Industrialized fraud amid a fragmented regulatory landscape
Generative AI now lets bad actors automate phishing, credential stuffing, and bot attacks at a volume that legacy fraud systems across the region simply weren’t built to absorb. What once required a skilled human operator working one target at a time can now run continuously, cheaply, and at scale. Furthermore, the tooling to do it is increasingly accessible to attackers with limited technical skill of their own.
Regulators are responding, but at markedly different speeds. Hong Kong’s HKMA and Singapore’s MAS are pushing operational resilience and AI risk guidance; India’s Aadhaar-linked verification ecosystem offers a different model again; and Australia’s digital ID framework continues to evolve. The result is no single regional standard—which creates real compliance complexity for institutions operating across borders, but also a genuine opportunity for those that get ahead of it rather than waiting for harmonization that may be years away. The institutions that treat this fragmentation as a forcing function for better identity practices, rather than a compliance headache to be managed market by market, end up with more resilient systems regardless of which regulation lands where.

From checkbox verification to continuous signals
The shift financial institutions need to make is from one-time, “checkbox” identity verification to continuous, layered signals. This includes liveness detection, behavioral biometrics, device fingerprinting, paired with adaptive multi-factor authentication that flexes based on real-time risk. This matters particularly in APAC, given how high customer expectations for frictionless digital banking have become across the region’s most digitally mature markets. The challenge for institutions is building fraud defenses that hold up against AI-generated attacks without reintroducing the friction customers have come to expect banks to have eliminated. In other words, verification needs to become something that happens continuously in the background rather than a single gate at login.
“Proof of Human” for AI agents
As banks deploy AI agents for tasks like loan processing and account servicing, a new problem emerges: how do you maintain an audit trail when the agent initiating an action isn’t a person? The industry needs “Proof of Human,” which is essentially a way to cryptographically tie every AI-initiated action back to a verified human, so institutions can prevent malicious agents from exploiting automated systems while still meeting audit and accountability requirements. As agentic AI moves from pilot projects into production banking workflows, this will become the baseline expectation of regulators and customers alike.
The institutions must get ahead of this shift by treating identity as a continuous, adaptive layer rather than a one-time hurdle. As AI agents continue to weave themselves into the fabric of our business operations, identity-first security will determine who maintains trust, who stays compliant, and who successfully keeps pace with a threat landscape that isn’t slowing down.
The views and opinions expressed in this article are those of the author and do not necessarily reflect those of CDOTrends. Image credit: iStockphoto/Jackie Niam
Click Here For The Original Source.
