Last week one of my clients was victimized by a new form of artificial intelligence-powered cybertheft. The cybercrooks used new technology to exploit a common vulnerability.
It is easier now for cyberthieves to attack those having unclaimed digital identities at financial institutions. An unclaimed digital identity exists when someone has not activated online account access at a bank or brokerage that offers such access.
My clients are a husband and wife who opened several joint bank accounts at a local financial institution. The accounts have been open for over 20 years with no previous irregularities. Many years ago, the husband enrolled in online access to the bank accounts, but the wife never did.
The husband is cyber savvy and implemented controls including dual authentication, password manager software, etc. He was reasonably confident that the accounts were protected from cybertheft.
On Aug. 24, cyberthieves impersonated his wife and enrolled in online service access to the couple’s joint bank accounts. They simultaneously opened another account in her name at an out-of-state financial institution.
On Aug. 25, they used the wife’s online access to initiate several ACH transfers from the couple’s bank accounts to the new account created in the wife’s name at the other financial institution.
The theft was discovered early on the morning of Aug. 26 when the husband received an email from the bank advising him that the bank account balances fell below a certain threshold.
So how did this happen?
The cybercriminals did not attempt to hack the husband’s secure online account access. Instead, they exploited the wife’s unclaimed digital identity. They used generative AI to create a profile for the wife in the bank’s online access portal.
In order to accomplish this, the cybercrooks’ AI assimilated the wife’s personally identifiable information including her full name, date of birth, Social Security number, address and at least one of the bank account numbers. Much of this information is available in cyberspace, but it would take a lifetime for a human to retrieve this data. Generative AI can assimilate such data very quickly.
Once this information is obtained, the cybercrooks impersonated the wife and enrolled in online banking. Because the data matched the information the bank has on file, the cybercrooks easily passed the bank’s first line of defense.
The criminal’s next step was to overcome the bank’s security features to verify the identity of the person seeking online access.
Cybercriminals use a variety of techniques to do so, but an explanation of those methods is beyond the scope of this column. A Google search will result in a fairly detailed discussion of the various schemes undertaken by cybercriminals.
If you experience this type of fraud, it is critical that you report it immediately.
Generally, if you report the fraud within two business days of its occurrence, your loss is limited to $50. The bank must absorb the rest.
If you report the theft after two business days but within 60 days of receiving the bank statement showing the fraud, then your loss is limited to $500. If you report it after 60 days of receiving that bank statement, you are fully on the hook for the loss. Under certain circumstances your loss is fully covered.
When you report this type of fraud, the bank will generally require you to complete a form explaining what happened.
While the bank cannot require you to file a police report, some banks may delay processing a credit until you also file an Internet Crime Complaint Center complaint form with the FBI.
Generally, a bank must restore your funds within 10 days of reporting the theft. Under certain circumstances, it can take as long as 45 days.
Because the cyberthieves have all of the necessary information to open a bank account, they can also take out loans in the victim’s name.
Therefore, it is important that victims consider immediately freezing their credit with all three of the major credit bureaus.
What could have been done to prevent this cybertheft?
Clearly cyberthieves use AI to open new avenues to cybertheft. In this case, the victim was a person having an unclaimed digital identity.
Account holders having an unclaimed digital identity should consider enrolling in online access, even if they do not intend to use it. When they enroll, they should also consider establishing dual authentication as a prophylactic cybersecurity measure.
I have practiced public accounting for over a half century. Until recently, my clients rarely experienced online theft, mail theft and other fraudulent transactions. Over the past few years, these have become prevalent.
Unfortunately, AI will accelerate that trend.
Jim de Bree is a semi-retired CPA residing in Valencia.







