A NewsGhana email interview with Faryam Asif, chief technology officer of Shufti
Account recovery is the weakest point in a bank’s defences against identity fraud, Faryam Asif, chief technology officer of verification firm Shufti, told NewsGhana in written answers.
Asif’s view matters because banking looks like the safest sector in Shufti’s own data. The company’s Identity Fraud Report 2026, published on 8 September, measured fraudulent attempts as a share of verification requests across 11 industries between January and June 2026. Banking had the lowest rate, at 4.24 per cent. Crypto platforms had the highest, at 22.49 per cent, followed by fintech at 18.36 per cent and forex at 17.18 per cent.
Banking was also the only sector where altered documents were not the main tool of fraud. Replayed images and screenshots came first, at 1.23 per cent of banking verification requests, ahead of altered documents at 0.77 per cent.
Asif cautioned against reading too much into that. The data shows a pattern, he said, not the reason behind it. His larger point is that a clean check when an account is opened says little about what happens later, when attackers target recovery, logins and large transfers.
Shufti sells identity verification and fraud detection services. The report itself notes that a sector’s rate reflects both the attacks attempted and the controls applied to them. Asif’s answers have been edited for length.
Does banking’s low rate mean stronger onboarding is pushing fraud elsewhere?
“It is a reasonable interpretation, but I would be careful about saying that the data proves it. Our data shows the pattern, not the reason behind it.”
He said banks generally have more established document checks, which can make forged documents harder to pass. Customer behaviour and differences in fraud patterns could also explain the figures. “What we can say is that when one route becomes harder, attackers tend to look for another.”
Why is a replayed image a different problem from a forged document?
“With a forged document, something has been changed. It could be a photo, a name, a date, or the document itself. A good document check is designed to spot those changes.”
“With a replayed image or screenshot, the document itself might be completely genuine. The face might also belong to a real person. The problem is that the image is not live.”
A system that only checks whether a document is real can therefore pass the attempt, he said. “The document may be real, but it is not being presented by the person it belongs to.”
How much should banks trust conventional know-your-customer checks?
Asif declined to say how fast criminals can build a fake identity, but said generative AI has made convincing synthetic content cheaper and easier to produce. Shufti’s data shows how quickly organised groups move. When the same operation appeared in a second country, it did so nine and a half minutes later on average, and in the fastest case 38 seconds later. He said that points to coordinated activity on shared infrastructure.
“Conventional KYC is still necessary, but it is no longer enough on its own,” he said. A 2019 Federal Reserve white paper cited an estimate that 85 to 95 per cent of applicants identified as potential synthetic identities were not flagged by traditional fraud models.
Where is fraud likely to go if onboarding gets harder?
He expects two shifts. The first is further along the customer journey: account recovery, logins, changes to beneficiaries and high-value transactions. The second is towards sectors with lighter identity controls.
The sectors are connected, he warned. “If a criminal carries out a SIM swap, they can gain control of the phone number used for banking or email security. So even a bank with strong onboarding can be affected by a weakness somewhere else in the chain.”
Which parts of the banking journey are most exposed after an account opens?
“If I had to pick one, account recovery is the biggest weak point by far.”
He said recovery is built for customers who cannot pass normal checks, so it is more forgiving by design, and SIM swaps let criminals receive the text-message codes it relies on. High-value transactions and beneficiary changes come next, followed by mobile banking, where a trusted device may face few further checks. “Recovery is where attackers can get in, and high-value transactions are where the money can leave.”
Should identity checks become continuous?
“Yes. Some fraud only becomes visible when you look at behaviour over time.”
In the first half of 2026, the largest connected cluster in Shufti’s data linked 70 identities across 13 devices, and one device appeared in 16 separate verification requests.
Is AI changing the economics of fraud?
“It could, and I think it already has.” Once a fake works, he said, it can be reused many times at little extra cost. Of the links Shufti found between separate fraudulent attempts, 65.68 per cent came from the same forged document being reused.
What is the biggest mistake banks make?
“Looking at every application in isolation and then treating the decision as permanent.”
His advice was to check, before approving an application, whether the same document, face, device or network has appeared elsewhere in the customer base. When banks buy fraud tools, he said, they should ask for detection rates by type of attack, false-positive rates and real examples of connected accounts being flagged for review.


