- Sponsored
Why phone fraud is rising as the new identity battleground for agencies
Government agencies are confronting a critical paradox in their digital transformation journeys. As they successfully fortify their online portals, they’re increasingly finding the humble telephone has become a primary target for sophisticated fraud.
Traditional methods for verifying constituents’ identities over the phone are proving increasingly easy for fraudsters to overcome, according to Greg Schlichter, Director of Research and Consulting at TransUnion. At the same time, the public has grown skeptical about who’s on the line when agencies attempt to respond to constituents, making it harder to serve citizens.
The result is a decline in trust and higher costs, says Schlichter in a new Scoop News Group executive video interview.
He maintains traditional identity management systems are failing because they rely on static data that rarely changes. Standard personal identifiable information (PII) is no longer a reliable tool for gatekeeping. Social Security numbers and dates of birth are widely available on the dark web.
Compounding the challenge, fraudsters are increasingly adept at impersonating and deceiving call center agents and identity-verification IVR (Interactive Voice Response) systems by using stolen PII and knowledge-based authentication (KBA). They’re no longer just reading from a script; they’re using AI to socially engineer agents in real time. This includes neutralizing accents to make overseas calls sound local or using deepfake technology in video-based support calls to mimic the appearance of a legitimate constituent.
What were once secure credentials have become a “persistent attack surface” fraudsters can exploit to manipulate call center personnel. “It gets particularly scary now when you start to factor in AI and what a motivated bad actor can do,” Schlichter warned. “You can also have real-time AI that, if you’re doing a video chat, can change your appearance and look very realistic.”
Data corroboration vs. static identity
To combat this, agencies must shift toward a model of real-time data corroboration, argues Schlichter. That includes turning increasingly to device intelligence.
“Every device, more or less, can be uniquely fingerprinted in a way that’s difficult for a bad actor to obfuscate,” he said. “Imagine the risk signal you’d get if…[AK1] you have a fraud signal that says some retailer previously reported this device as being used to facilitate credit card fraud. That’s a huge gamechanger.”
What’s needed is “real-time identity corroborating signals from authoritative data sources that… when combined, can create a very strong signal for identity verification purposes.” This approach leverages a network of authoritative providers to verify the “digital exhaust” surrounding a call — such as whether a phone number was recently reassigned or the carrier signal shows hallmarks of spoofing.
By sharing this data through a consortium of users, agencies can identify high-risk traffic before a call even reaches an agent.
At the same time, “You don’t want to make everyone go through the gauntlet. You need to find ways to segment high risk from low risk — and you need ways to further segment high risk,” he said.
Moving forward, government leaders should prioritize FedRAMP-ready tools that provide real-time verification, ensuring security is as invisible as possible to honest constituents while remaining an impassable barrier to hackers.
This executive video interview and summary article were produced by Scoop News Group for FedScoop and underwritten by TransUnion.
Learn more about how TransUnion helps public sector organizations verify identities for more secure communications.