Local

How banks use behavior to spot suspicious payments

Behavioral biometrics can add a quiet security check but privacy and false positives remain concerns

Close-up,View,Of,African,Man's,Hands,Holding,Plastic,Credit,Card 3 Tampa companies that can help lower your home's carbon footprint (Cast Of Thousands/Shutterstock / Cast Of Thousands)

Every online payment requires a bank to make a quick decision. It must determine whether the person making the purchase is the real account holder or someone using stolen information.

The cost of getting that decision wrong is high. Global payment card fraud losses reached $33.41 billion in 2024, according to the Nilson Report.

Banks already check passwords, card numbers, devices and one-time codes. Some are also examining how customers normally interact with an app or website.

This technology is known as behavioral biometrics.

Thrivikram Eskala has spent more than 20 years working on financial technology, cloud systems and security infrastructure. He is an engineering services architect and the author of “Always Verifying,” a book about identity and security in modern technology systems.

Eskala has worked on payment authentication systems designed to evaluate customers without interrupting every transaction.

What behavioral biometrics measure

Traditional authentication asks customers to provide something they know or possess. That might include a password, a security code or a phone receiving a notification.

Behavioral biometrics takes a different approach. It looks for patterns in how someone uses a device.

Those signals can include typing speed, touchscreen movements, mouse activity, the path a customer takes through an app and the angle at which a phone is held.

A system can compare those actions with the customer’s usual behavior. A familiar pattern may support approval of a transaction. A major change may lead the system to request another form of verification.

“You are not asking the customer to do anything new,” Eskala said. “The signal is already there in how they behave.”

The goal is not to replace every password or security code. It is to provide another source of information that can help a bank decide when a stronger check is needed.

Security that runs in the background

Eskala said a payment framework he worked on collected behavioral signals during an ordinary customer session and sent them to scoring tools.

When the activity matched an established pattern, the transaction could continue without another visible step. If the activity appeared unusual, the system could request additional verification.

The framework was also designed to connect with different behavioral biometric services. That gave financial institutions the ability to change vendors without rebuilding the entire payment system.

“Every extra step you add to catch a fraudster also punishes the honest customer standing right behind them,” Eskala said. “What I kept coming back to was authentication that costs the real person nothing.”

That balance is important for banks and retailers. Too little security can allow fraud. Too much friction can frustrate customers or cause them to abandon a purchase.

Where regulation fits

European payment rules generally require strong customer authentication for many electronic payments.

That process uses at least two independent elements. They can include something the customer knows, something the customer possesses or something connected to who the customer is.

European banking guidance says behavioral biometrics can qualify under the third category, known as inherence. However, simply collecting device or location data is not enough.

The method must identify the specific customer and have a very low chance of accepting an unauthorized person.

That means behavioral analysis is not automatically a replacement for a password or one-time code. Financial institutions must show that the system is reliable and that its different authentication factors remain independent.

The problem with false alerts

Behavioral systems can make mistakes in both directions.

A false positive may flag a legitimate customer as suspicious. A false negative may allow an attacker to continue using the account.

People also do not behave exactly the same way every day. A customer may switch phones, use an unfamiliar computer, injure a hand or make a payment while traveling.

New customers create another challenge because the system has little history to examine.

“The average case is easy,” Eskala said. “The system earns its keep on the exceptions.”

Banks must decide how much evidence is needed before blocking a transaction or asking for another security check. A behavioral score should inform that decision, not make it alone.

Privacy remains part of the trade-off

Behavioral data can be personal. A system may continuously observe how someone types, moves through an app or holds a device.

Financial institutions need clear limits on what they collect, how long they retain it and who can access it. Customers should also understand when this monitoring is taking place.

Poorly protected behavioral profiles could become another target for criminals. The systems therefore need encryption, access controls and a clear process for removing information that is no longer needed.

Eskala argues that the technology is most useful when it works quietly while still respecting the person being measured.

“The best authentication is the kind nobody remembers because nothing ever interrupted them,” he said.

Behavioral biometrics may help banks make better decisions without adding another step to every payment. Its value, however, depends on careful testing, strong privacy protections and recognizing that behavior is one security signal rather than absolute proof of identity.

Brody Wooddell

Brody Wooddell, WFTV.com

Brody Wooddell is a digital journalist and media leader with more than a decade of experience in content strategy, audience growth, and digital storytelling across television and online news platforms.

0