Inside Entrust's Push to Stop AI-Driven Account Takeovers — Fintech360hub
Fraud & ID Verification

Inside Entrust's Push to Stop AI-Driven Account Takeovers

A new biometric authentication system aims to replace passwords and OTPs with identity checks built for a world where deepfakes are getting harder to spot.

The Brief

Identity security firm Entrust has rolled out a Biometric Authentication solution built to counter account takeover attacks supercharged by AI. It swaps passwords, one-time passcodes and security questions for layered biometric checks — passkeys, face verification and motion authentication — designed to catch presentation, injection and deepfake attempts. The launch lands as account takeover overtakes other fraud types as the costliest threat facing US businesses, and as regulators warn that AI is widening the gap between organisations that can keep pace with attackers and those that can't.

Passwords and one-time codes were built for a threat landscape that no longer exists. As generative AI makes it cheaper and easier to fake a voice, a face or a login attempt, security vendors are racing to replace those decades-old defences with something harder to fool: proof of the actual person behind the interaction.

Entrust, the US-based digital security and identity management firm, has introduced a new tool aimed squarely at that problem — a response to what regulators and fraud data increasingly describe as an escalating, AI-accelerated wave of account takeover attempts.

Identity assurance through biometrics

Entrust positions the new system as an identity assurance layer that pairs biometric verification with authentication that adjusts to risk in real time.

The company says the tool is built to catch presentation attacks, injection attempts and deepfake-based fraud by demanding stronger proof of identity at the moments that matter most. Three verification methods sit behind it, each suited to a different risk level: a biometric passkey for high-risk situations that ties authentication directly to a verified individual, face verification that stands in for one-time passcodes, and motion-based checks that add a further layer of identity confirmation.

31%of all reported US business fraud losses now come from account takeover
9.8%average share of revenue US business leaders lost to fraud in 2025
35%of survey respondents rank biometrics as their most trusted authentication method

The growing AI threat landscape

The UK's National Cyber Security Centre has warned that AI is almost certain to keep making cyber intrusion tactics faster and more effective, likely driving both the volume and severity of attacks higher.

The agency also expects a widening split to emerge between organisations equipped to keep pace with AI-enabled threats and those left exposed — a gap it believes will make cybersecurity at scale increasingly non-negotiable through 2027 and beyond. Against that backdrop, account takeover has become one of the most costly categories of cybercrime. TransUnion data published in August 2025 found it now accounts for the largest share of reported fraud losses among US businesses, ahead of every other fraud type.

Preventing account takeover now means confirming the person behind every interaction, not just the credentials they type in. — Mike Baxter, Chief Technology & Product Officer, Entrust

Targeting critical moments

Fraudsters have shifted their focus away from the login screen and toward the moments that follow it.

Attackers are increasingly zeroing in on high-risk touchpoints such as account recovery flows, large transactions and changes to registered devices — moments Entrust argues most authentication systems still aren't built to scrutinise closely enough. That shift is part of why both consumers and businesses are warming to biometrics over legacy security methods: in Entrust's own survey data, biometric authentication came out as the most trusted option by a clear margin over usernames, passwords and one-time passcodes.

Key takeaways

  1. Account takeover is now the costliest fraud type. It accounts for nearly a third of all reported US business fraud losses.
  2. AI is raising the stakes on both sides. Regulators expect it to keep making cyberattacks faster and more effective through 2027 and beyond.
  3. Biometrics are replacing static credentials. Passkeys, face verification and motion checks are designed to close gaps that passwords and OTPs can't.
  4. Attackers now target moments, not just logins. Account recovery, large transactions and device changes are the new high-risk flashpoints.
  5. Trust is shifting toward biometrics. More than a third of people already rank them above passwords and one-time codes.