Connect with us

Hi, what are you looking for?

Datanamix News

In-App Fraud Risk: Beyond Banking 

In-app fraud risk beyond banking

In-App Fraud Risk: Beyond Banking 

An authenticated account can do far more than grant access. It can change payout details, redeem stored value, authorise another user or redirect money. In-app fraud risk can emerge when these actions are performed by someone other than the authorised user. Looking at in-app fraud risk across different industries helps organisations identify the account actions with the greatest financial, privacy or operational consequences. 

Understanding in-app fraud risk starts with a simple distinction: login establishes access, while later actions determine what that access can be used to do. For organisations examining in-app fraud risk, the important question is not only whether the login was valid, but whether the authorised user is still behind the screen when a higher-risk action takes place. Mapping in-app fraud risk can show where added identity assurance may be most useful. 

Why in-app fraud risk depends on the action 

Most digital journeys include a mix of lower-risk and higher-risk activity. Viewing a statement, checking a booking or reading account information does not carry the same consequence as changing bank details, granting another user access or approving the movement of money. Assessing in-app fraud risk therefore means identifying actions that can: 

  • Move money or another form of value 
  • Change where a payment, refund or benefit will be sent 
  • Alter who can access or control an account 
  • Expose sensitive personal or business information 
  • Create a decision that may be difficult to reverse 

Although the specific actions differ across industries, in-app fraud risks raise the same underlying question: is the authorised user still the person performing the action? 

Where in-app fraud risk can appear 

The following examples show how in-app fraud risk can arise inside authenticated accounts across different industries. They do not represent claims about a particular organisation, platform or documented incident. 

Fintech, investments and digital assets 

A fintech customer may change the account receiving a loan payout, link an external wallet or draw down approved credit. An investment or digital-asset platform may also allow someone to add a new withdrawal destination and approve a transfer later in the same session. The in-app fraud risk appears when the person directing where the money or asset will go is no longer the authorised user. 

Healthcare, insurance and medical aid 

Healthcare, insurance and medical-aid accounts may allow users to change who can access information, receive money or benefit from a policy. Someone controlling an authenticated account could redirect a claim payment or member refund, replace a beneficiary, update account details or authorise another person to act on the member’s behalf. These in-app fraud risks make identity important at the point of change, although identity assurance cannot determine whether the underlying claim or request is legitimate. 

Retail and ecommerce 

Retail accounts can contain saved payment methods, delivery information, vouchers and loyalty points. If someone else gains control of the account, they could place an order using stored payment details, redirect a delivery or convert loyalty points into gift cards, airtime or another transferable form of value. The in-app fraud risk becomes more significant when an action moves value or changes where purchased goods will be delivered. 

Telecommunications 

A telecommunications application may allow a customer to update contact details, activate an eSIM or move a mobile number to another device. The in-app fraud risk can extend into other services because mobile numbers are often used to receive one-time PINs and account alerts. Maintaining confidence in the user’s identity during a sensitive change can add another layer of assurance without replacing existing customer checks or device controls. 

Ride-hailing and delivery platforms 

A driver or courier may complete work through an authenticated platform account. Before the earnings are released, the banking details linked to the profile could be changed. This creates an in-app fraud risk at the point where the platform decides where the driver’s or courier’s money will be paid. Additional identity assurance could help the platform maintain greater confidence that the authorised account holder is requesting the change. 

Property and hospitality 

Property and accommodation platforms combine listings, reservations, tenant or guest information, refunds and payout settings. An authenticated host, landlord or property administrator may be able to replace the account receiving rental or booking income, redirect a deposit or refund, or grant another user control of the profile. These in-app fraud risks arise after login, when a later action changes who controls the account or receives the money. 

Business applications 

Inside a business application, an authenticated finance user may change a supplier’s banking details, an administrator may grant another person access to sensitive systems or an employee may approve a payment after the session has been active for some time. Existing permissions and approval processes remain essential. In-app fraud risk arises if the person using those permissions is no longer the authorised employee. 

Education and public services 

Education and public-service applications can connect a named individual to records, applications and formal decisions. An authenticated user may be able to change personal details, access sensitive records, submit a request or nominate an account to receive funds. In-app fraud risks arise when these actions carry financial, privacy or administrative consequences and the organisation can no longer be certain who is interacting with the application. 

How to identify in-app fraud risk 

A practical review of in-app fraud risk begins by mapping the actions available after login and considering the consequences of each one. Organisations can ask: 

  • Can this action move or redirect money, benefits or stored value? 
  • Can it give another person access to the account or application? 
  • Can it change important identity, contact or payout information? 
  • Could it expose sensitive data? 
  • Would it be difficult to reverse once completed? 
  • Does the organisation need greater confidence in who is performing it? 

Mapping in-app fraud risks in this way allows organisations to focus additional controls on the actions carrying greater consequences without adding unnecessary friction to lower-risk interactions. 

How identity assurance can help address in-app fraud risk 

Continuous Facial Recognition with Liveness can help organisations address the identity component of in-app fraud risk by extending identity assurance into the active digital session. It is designed to help maintain greater confidence that the authorised user remains the person interacting with an application when a higher-risk action takes place. 

The role of the technology in addressing in-app fraud risks must be understood clearly. Continuous Facial Recognition with Liveness does not determine whether an action is financially sound, detect malware or establish whether an authorised user is being manipulated. It complements existing authentication, access controls, transaction monitoring and fraud-prevention measures rather than replacing them. 

A layered response to in-app fraud risk 

Addressing in-app fraud risk requires different controls for different parts of the problem. Authentication helps establish identity when a session begins. Access controls determine what the user is permitted to do. Transaction monitoring assesses the activity taking place, while device security and fraud investigations address other risks. Continuous identity assurance adds another layer by helping the organisation maintain confidence in who is using the application when higher-risk actions take place. 

Managing in-app fraud risks is not about replacing existing security investments or applying the same control to every interaction. It is about identifying the moments where an action carries greater consequences and deciding whether stronger identity assurance could add value. 

How Datanamix helps organisations address in-app fraud risk 

Datanamix provides Continuous Facial Recognition with Liveness as part of its identity and verification technology portfolio. The solution helps organisations address the identity component of in-app fraud risk while building on their existing authentication, access and fraud controls. 

Book a demo with Datanamix to discuss your in-app fraud risks and identify where additional identity assurance could support higher-risk actions in your digital journeys. 

You May Also Like

Datanamix News

How to improve right-party contact rates in debt collection in South Africa  Right-party contact is one of the most important performance indicators in debt...

Datanamix News

How to find updated debtor contact details in South Africa  One of the biggest operational challenges facing South African debt collectors today is outdated debtor...

Datanamix News

Is manual verification slowing your digital retail business down?  Manual verification is one of the biggest hidden risks in digital retail today. As digital...

Datanamix News

How can businesses prevent commercial fraud in South Africa?  Commercial fraud is no longer a distant risk. Commercial fraud is a daily reality for...

Datanamix News

Datanamix brings Continuous Facial Recognition with Liveness to South Africa through YEO Messaging Digital fraud is evolving. As organisations continue to expand digital onboarding,...

Datanamix News

The Digital Compliance Gap in Debt Review: Why Identity Assurance Matters More Than Ever  The debt review industry in South Africa has embraced digital...

Datanamix News

How can digital retailers verify customer identity online in South Africa?    Digital retail in South Africa has grown rapidly, jumping from R37.4 billion in 2018...

News Watch

Ghana’s National Identification Authority (NIA) says it plans to expand use cases of the national ID – the Ghana Card – in order to drive financial...

Datanamix News

How do you verify a business and its directors in South Africa?  Verifying a business in South Africa is no longer just about confirming registration details. It...

Datanamix News

How can you assess business credit risk without paying for a full credit report every time?  Every lender, supplier, insurer, and credit provider faces...

Copyright © 2026 - Datanamix
Disclaimer: The information in this BLOG is provided for general informational purposes only and is the opinion of the author only. No information contained in this blog should be construed as legal advice from Datanamix or the individual author, nor is it intended to be a substitute for legal counsel on any subject matter. No reader of this blog should act or refrain from acting on the basis of any information included in, or accessible through, this blog without seeking the appropriate legal or other professional advice on the particular facts and circumstances at issue.