Agentic fraud brings AI-driven attacks to a new scale

Banks face the challenge of protecting real accounts as AI agents can test combinations and adapt attacks to bypass security controls.

 


Financial fraud is entering a stage in which artificial intelligence systems can generate fake identities, test attack methods and modify their strategies with minimal human intervention.


In Colombia, 997 data thefts, 63 cases of identity theft and 94 cyberattacks per second against banking institutions occur every day, according to the 2026 Financial Agenda.

These figures come as financial fraud enters a new phase in which artificial intelligence can autonomously execute processes, learn from each attempt and modify its strategy in response to security controls.

The phenomenon, known as agentic fraud, represents a third generation of identity fraud.

Artificial intelligence expands the scale of fraud.

First, criminals used photographs, screens or masks to impersonate a person. Then came deepfakes, synthetic faces and manipulated content injected into systems. Now, an artificial intelligence agent can create a fake identity, open an account, test different documents and adapt an attack when it encounters a blockage.

The scale of the challenge is particularly relevant in Colombia, where 96% of citizens have at least one financial product and 82% of transactions are already carried out through digital channels.

During 2024, 80% of fraud reported by users to banking institutions occurred online, and the amount claimed for digital fraud reached COP 679 billion.

In practice, agentic fraud transfers to artificial intelligence systems tasks that attackers previously performed manually, such as generating fake elements, testing different combinations and adjusting attempts in response to security controls.

The main difference between traditional fraud and agentic fraud lies in autonomy and scale. Previously, an attacker had to alter documents, create fake accounts and carry out each attempt manually.

Now, artificial intelligence agents can generate thousands of fake faces and documents, test different combinations and identify which ones are more likely to bypass controls.

They can also seek to take control of real accounts with balances, payroll deposits, credit limits or active products, rather than focusing solely on opening fake accounts.

Attacks incorporate synthetic identities and documents.

Incode’s 2026 Agentic Fraud Report analyzed 66 documented fraud incidents, 44 of them confirmed cases involving artificial intelligence. The findings show that this technology is already being used to create synthetic identities, forge documents, generate deepfakes and automate different stages of an attack.

This evolution marks the shift from isolated, manually executed fraud to operations capable of acting at scale, learning from each attempt and adjusting their strategy in response to security controls.

In 2024, Incode processed more than 4.1 billion identity verifications globally, allowing it to analyze patterns related to fake documents, impersonation, synthetic identities and automated attacks.

The study “Cybersecurity, an enabler of trust and competitiveness,” prepared by Endeavor Data Unit and Incode Technologies, found that Latin American organizations receive an average of 2,803 cyberattacks per week, compared with 1,984 globally.

Although 65% of Latin American organizations consider themselves well or very well prepared, only 17% formally assess their cybersecurity strategy on a monthly or continuous basis. The report also states that 68% identify phishing and social engineering as their main threats.

Íñigo Castillo, General Manager for Latin America at Incode: “Agentic fraud changes the rules because artificial intelligence can execute the entire attack, learn from blocks and try again at a scale that was not possible with manual processes. Banks need to verify in real time whether there is a real person behind each interaction and whether that person is truly who they claim to be.”

Banks face the challenge of protecting identity without increasing friction.

Faced with this new generation of fraud, indiscriminately adding more security steps can affect legitimate customers without necessarily stopping an automated system capable of making thousands of attempts.

Incode’s technology integrates document verification, facial recognition and biometrics, as well as liveness detection, to determine whether a real person is in front of the camera and whether they match the identification presented.

It can also detect deepfakes, injected videos, synthetic identities and documents created or manipulated with artificial intelligence.

These capabilities can be used when opening an account and at sensitive moments such as login, credential recovery, changes to personal information, loan applications or higher-risk transactions.

Against this backdrop, the financial sector will need to move from isolated verifications toward continuous identity protection.

In a predominantly digital banking environment, distinguishing a real person from an identity created or controlled by artificial intelligence will be essential to protect users’ funds and preserve trust in financial institutions.


Share:
Hosting Web
Most Read