The Contact Center Has Become Banking’s Identity Blind Spot
Learn how banks can modernize contact center authentication to prevent account takeover, reduce fraud and costs, and improve customer experience with stronger identity intelligence.


Key takeaways
- Legacy contact center authentication increases fraud risk and customer friction.
- AI is making impersonation and account takeover easier to scale.
- Authenticating customers before they reach an agent can reduce cost and friction.
- Strong authentication requires multiple identity and risk signals, not security questions alone.
- Contact centers should be part of a unified, continuous authentication strategy.
Banks have spent years making digital account opening, online banking, and payment authorization faster and easier, and for good reason. McKinsey found that successful customer-experience transformations can increase sales conversion rates by 15–20% while reducing service costs by 20–50%. Yet one of banking’s most consequential customer channels often still relies on an authentication model built for a different era. The consequences extend beyond fraud. Every minute spent authenticating a legitimate caller adds contact center cost, increases handle time, and creates friction for customers who simply want to access their accounts or get help. Banks are effectively paying agents to repeatedly establish identity, often using information that is increasingly easy for fraudsters to obtain.
In the contact center, a caller may be asked to provide a date of birth, address, Social Security number, recent transaction, or answer to a security question. A few years ago, it would be unlikely that that information would be known by anyone but the owner of that information. But today, much of this information is no longer secret. It can be purchased, stolen, researched, inferred, or elicited through social engineering.
That makes the contact center an attractive entry point for account takeover. Fraudsters do not always need to defeat a bank’s strongest digital controls. Sometimes, they only need to persuade an agent that they are someone else.

Contact center fraud is part of a much larger identity problem
The scale of impersonation fraud makes very clear what banks are up against. Consumers reported losing $3.5 billion to imposter scams in 2025, according to the Federal Trade Commission. Nearly one in three fraud reports involved impersonation, and bank impersonators generated the highest reported losses among business impersonation scams.
The FBI’s Internet Crime Complaint Center recorded 53,369 call center scam complaints and $1.9 billion in reported losses in 2024. Those figures cover scams perpetrated through criminal call centers, but they reveal how effectively fraudsters can use live conversations, urgency, and impersonation to manipulate victims and financial institutions.
Account takeover is also becoming more costly for companies. In 2025, TransUnion found that account takeover accounted for 31% of the fraud losses reported by surveyed U.S. businesses. Its data also showed that global digital account takeover volume increased 21% between the first half of 2024 and the first half of 2025.
These threats converge in the bank contact center. A fraudster may call to reset credentials, change contact information, add a payee, redirect a transfer, order a replacement card, or gain enough information to launch an attack elsewhere. But what appears to be a routine service request may actually be one step in a coordinated, cross-channel takeover.
AI is making a familiar problem faster and more convincing
Social engineering isn’t new, but generative AI is changing its economics and rapidly increasing the rate of innovation. Fraudsters can use AI to research targets, generate scripts, translate conversations, imitate communication styles, and create convincing synthetic audio or documents at massive scale.
FinCEN has reported an increase in suspicious activity reports describing the suspected use of deepfake media in fraud schemes targeting financial institutions and their customers. It has also warned that criminals are using generative AI to create or alter identity documents and circumvent identity verification and authentication controls.
In this environment, it’s easy to see how contact centers can be an unwitting but effective orchestrator of fraud tactics. First, there’s voice cloning. AI can help an attacker sound more credible, respond more naturally, and carry on a convincing pretext throughout a call. When that effort is combined with breached personal data, spoofed phone numbers, compromised devices, or manipulated one-time passcodes, even a well-trained agent will struggle to distinguish a legitimate customer from an impostor.
We’re far beyond ascertaining whether a voice sounds real or not. The more pressing matter is whether the bank has sufficient evidence that the person interacting with it is the legitimate account holder and is authorized to complete the requested action.
Weak authentication is also expensive authentication
The problem with knowledge-based authentication is not limited to security. It also consumes some of the bank’s most expensive customer-service resources while creating friction for the customers the bank most wants to serve well.
Every question takes time. Legitimate customers may not remember an old address, the exact amount of a recent transaction, or the answer they provided to a security question years ago. When answers do not match, agents may need to ask additional questions, introduce another authentication method, transfer the caller, or escalate the interaction. The result is longer handle times, higher operating costs, and a worse experience for legitimate customers.
Banks are then forced into a false tradeoff:
- Add more questions and friction to reduce fraud.
- Relax authentication to preserve the customer experience.
- Transfer more calls to specialized teams, increasing cost and delay.
None of these options addresses the underlying weakness: the bank is spending more time trying to establish identity through information rather than stronger evidence of identity.
The economics become significant at contact center scale. A live-agent interaction is one of the most expensive customer-service channels a bank operates, and authentication consumes agent time before the customer has even explained why they are calling. Verifying a caller through security questions can take anywhere from 60 seconds to several minutes, particularly when answers do not match or additional verification is required.
In a Forrester Total Economic Impact analysis, a composite financial services organization handling 12 million inbound calls annually modeled a five-minute average handle time at roughly $1 per minute. At just one minute of authentication per call, that would represent approximately 200,000 agent-hours and $12 million annually spent establishing identity.
And the cost is not only financial. Every minute spent proving that a legitimate customer is who they say they are is a minute the agent is not resolving the reason the customer called. At sufficient scale, unnecessary authentication contributes to longer calls, greater demand on agents, longer queues, and more customer frustration.
That is the fundamental problem with legacy contact center authentication: banks can spend more to create more friction without necessarily establishing more trust.
Voice alone should not carry the burden of trust
Voice biometrics can add useful intelligence, but no single signal can determine whether a high-risk banking action is allowed. Synthetic audio, replay attacks, background noise, changing voices, and enrollment limitations can all affect the reliability of voice-based decisions.
The stronger approach is to evaluate multiple signals in context. Before and during the interaction, a bank can consider whether:
- The phone number is actively connected and associated with the customer.
- The device and phone number have an established history.
- The number was recently ported, reassigned, or linked to suspicious activity.
- The caller’s identity attributes are consistent with trusted records.
- The current interaction differs from the customer’s normal behavior.
- The requested action warrants additional authentication.
This shifts the contact center from questioning the caller to recognizing the customer. For the bank, every authentication step completed before an agent becomes involved can reduce expensive agent handling time while allowing employees to spend more of the conversation actually serving the customer.
Authenticate earlier, then apply friction according to risk
For many banks, authentication does not begin until an agent answers the call. By that point, the institution is already consuming agent time, and the customer is already waiting.
A more effective model begins establishing trust before the conversation starts. Low-risk callers can be passively authenticated and routed efficiently. Higher-risk callers can receive a step-up challenge before an agent approves a sensitive request.
This creates a more proportionate experience:
- Trusted customers move through the interactive voice response (IVR) or reach an agent without repeating information the bank already knows.
- Uncertain interactions receive additional verification based on risk.
- High-risk activity can be blocked, escalated, or restricted before account changes or money movement occur.
Importantly, identity should not be evaluated only at a single moment. Phone numbers, devices, attributes, and risk conditions change over time. Continuous identity monitoring helps banks detect those changes and maintain a more accurate understanding of the customer throughout the relationship.
The contact center should be part of a unified authentication strategy
Fraudsters move effortlessly across channels. They may gather information through the IVR, reset a credential through an agent, intercept an OTP, and complete a transaction online. If each channel makes an isolated authentication decision, the bank will miss the pattern.
Contact center authentication therefore needs to connect to the same identity and risk framework used for digital banking. A trusted identity established in one channel should inform decisions in another, while suspicious changes should be visible across the customer journey.
This does not require banks to abandon every existing control at once. It means evolving from fragmented, challenge-heavy authentication toward a unified approach that combines persistent identity, real-time risk signals, and step-up verification.
The objective is not to challenge every caller more aggressively. It is to recognize legitimate customers more confidently and reserve friction for interactions that actually require it.
Bringing identity intelligence into Amazon Connect
Prove for Amazon Connect, available through AWS Marketplace, brings Prove’s identity verification, authentication, and fraud-prevention capabilities directly into Amazon Connect contact center journeys.
Banks can use the Prove solutions to authenticate callers before they reach an agent, assess phone and identity risk in real time, improve IVR containment, and introduce step-up verification for higher-risk activity.
The best authentication experience for a good customer may be no authentication experience at all. Instead of starting with “Can you verify your date of birth, address, and recent transactions?,” the conversation can start with: “How can we help you?”
The result is stronger protection against account takeover without forcing every legitimate customer through the same authentication gauntlet.
Identity is the foundation of contact center security
Modernizing contact center identity is therefore not only a fraud initiative. It is also a customer-experience and operating-efficiency initiative. Banks can spend less time proving that good customers are who they say they are, reserve additional friction for genuinely risky interactions, and allow agents to spend more of each conversation actually helping customers.
The contact center needs the same caliber of identity intelligence that banks increasingly apply to account opening, login, and transactions.
When identity can be established earlier and evaluated continuously, banks can prevent more account takeovers, reduce unnecessary authentication time, improve customer experience, and make high-risk actions harder for fraudsters to reach.
The future of contact center security is not more questions. It is better evidence.
Sources: Federal Trade Commission, 2025 imposter scam data; FBI, 2024 Internet Crime Report; FinCEN Alert on Deepfake Fraud; TransUnion H2 2025 Global Fraud Report.
The modern
way of proving identity
Trusted by 2,000+ leading companies to reduce fraud and improve consumer


Frequently Asked Questions
Many bank contact centers still rely on knowledge-based authentication and personal information that fraudsters can steal, research, or obtain through social engineering. This can make the contact center a target for account takeover.
Generative AI can help fraudsters research targets, create convincing scripts, clone voices, generate synthetic documents, and scale impersonation attacks.
Banks can authenticate customers earlier using multiple identity and risk signals, then apply additional verification when an interaction or requested action presents greater risk
Yes. Authenticating customers before they reach an agent can reduce authentication-related handle time and allow agents to spend more time resolving customer needs.
Prove for Amazon Connect enables banks to authenticate callers before they reach an agent, assess phone and identity risk in real time, improve IVR containment, and step up verification for higher-risk activity.

Keep reading
Read the article: How Public SMS Numbers Undermine OTP VerificationPublic SMS numbers can bypass basic OTP verification and expose onboarding flows to fraud. Learn why OTP alone isn’t enough and how layered identity and risk signals can help.
Read the article: Trust at Marketplace Speed: Why Authentication Is Becoming Persistent InfrastructureLearn why marketplace authentication must extend beyond login. Explore how persistent identity, cryptographic possession, and risk-based authentication can help marketplaces prevent account takeover, reduce friction, and maintain trust across the customer lifecycle.
Read the article: Beyond the OTP: What’s Driving the Next Generation of Authentication in Online GamingLearn why online gaming authentication is moving beyond passwords, SMS OTPs, and traditional MFA toward continuous, risk-based trust. Explore how persistent identity, cryptographic possession, device and network intelligence, and adaptive authentication can help gaming operators reduce fraud while creating a more seamless player experience.
