How In-App Fraud Can Happen After A Valid Login
A customer can pass every security check at login. They enter a password, one-time PIN or biometric, and the application grants access as expected. Minutes later, a beneficiary is added, account information is changed or a payment is approved. That is how in-app fraud can happen after a valid login: the login itself may be valid, but control of the session can change before a higher-risk action is completed.
Understanding how in-app fraud can happen after a valid login does not mean authentication has failed. Authentication performed its role when access was granted. The challenge is maintaining confidence in who is using the application as the session continues. The period between the initial identity check and a later higher-risk action is the transaction gap.
In South Africa, the scale of digital banking fraud makes this gap worth examining. Within SABRIC’s 2024 banking crime statistics, digital banking accounted for 65.3% of reported banking fraud incidents. Cases rose from 31,612 in 2023 to approximately 64,000 in 2024, while losses increased from R1 billion to more than R1.4 billion. Importantly, SABRIC attributed these incidents to social engineering that exploited human error, rather than technical compromises of banking platforms.
How control can change after login
A fraudulent transaction may be completed inside an application, but the route into that session often starts elsewhere.
Phishing messages and fraudulent support calls can capture login details or persuade a customer to disclose sensitive information. A SIM swap can redirect a one-time PIN. Stolen personal information can help a criminal answer security questions or build a convincing profile of the account holder.
A compromised device creates another route. SABRIC warns that Remote Access Trojan software can give a criminal control of a victim’s device. The attacker may be able to view the screen, capture credentials and perform transactions from the device the customer normally uses.
In each case, the application may still receive familiar signals. The correct credentials have been entered. The expected device is being used. The session has been authenticated. The application can be working as designed even though someone else may be directing what happens next.
What the transaction gap looks like
Consider a simplified banking scenario:
- A criminal obtains a customer’s credentials or gains remote access to the customer’s device.
- The expected authentication steps are completed and the application opens a valid session.
- Once inside, the criminal changes contact details, adds a beneficiary or increases a transaction limit.
- A payment is created and approved later in the same session.
- If no additional control identifies or interrupts the activity, the active session can be used to complete the transaction.
Banks may use transaction monitoring, behavioural analysis, payment limits, step-up authentication and other controls to detect unusual activity. The example does not suggest that these controls are absent or ineffective. It shows why a valid session and continued confidence in the user’s identity are not necessarily the same thing.
Not every case of post-login fraud is the same. A session may be taken over by another person. A criminal may operate an application remotely through a compromised device. In another case, the legitimate customer may be manipulated into making the payment. These scenarios can look similar once the transaction appears, but they do not have the same cause and cannot all be addressed in the same way.
Authentication remains essential
Existing authentication and fraud controls provide different and valuable checks:
- A password or PIN shows that the correct secret was entered.
- A one-time PIN shows access to the phone number or channel receiving it.
- Device recognition shows that the application is running on a known device.
- A biometric can help confirm the authorised person’s presence at the moment of verification.
- Transaction monitoring can identify activity that differs from an established pattern.
These controls should not be discarded or replaced. The practical question is whether an organisation also needs greater confidence in the user’s identity later in the session, particularly when a customer performs an action that is sensitive, financially significant or difficult to reverse.
Not every in-app action carries the same risk
Viewing an account balance does not carry the same consequence as releasing funds, changing a payout account or authorising another device. The level of identity assurance needed may therefore change as the customer moves through the application.
Financial-services organisations can begin by identifying actions such as:
- adding a new beneficiary;
- approving a high-value payment;
- increasing a transaction limit;
- linking an external wallet or changing a payout account;
- authorising another device; or
- replacing contact details and redirecting transaction alerts.
This gives fraud, risk and technology teams a practical way to decide where additional identity assurance could add value. Rather than adding another step to every interaction, organisations can focus on the moments where the consequences are greatest.
Extending identity assurance beyond login
Continuous Facial Recognition with Liveness is designed to strengthen existing authentication by extending identity assurance into the active digital session.
It helps organisations maintain greater confidence that the authorised user remains the person interacting with the application, including when higher-risk actions take place. This adds another layer of identity assurance without replacing the controls already used to manage login, devices and transactions.
The distinction is important. Continuous identity assurance focuses on who is interacting with the application. It does not decide whether a transaction is safe or whether the customer has been manipulated into making it.
One part of a broader fraud-prevention approach
No single security measure can address every form of in-app fraud. Organisations need different controls for different risks.
Authentication helps establish identity at the beginning of the journey. Device and security controls help identify other forms of compromise. Transaction monitoring helps assess whether an action is unusual or carries greater risk. Continuous identity assurance extends confidence in the user’s identity beyond login.
Customer education, payment controls and fraud investigation remain important when criminals manipulate legitimate customers into taking an action themselves.
Continuous Facial Recognition with Liveness should therefore be viewed as part of a broader fraud-prevention approach. Its role is to strengthen identity assurance while other controls address the device, transaction and circumstances surrounding the customer’s actions.
How Datanamix helps close the transaction gap
Datanamix provides Continuous Facial Recognition with Liveness as part of its identity and verification technology portfolio. The solution helps banks, fintechs and other financial-services organisations extend identity assurance beyond login while building on their existing authentication and fraud controls.
Book a demo with Datanamix to discuss where additional identity assurance could support higher-risk actions in your customer journeys.









