BioCatch Launches DeviceIQ to Combat AI-Driven Fraud and Device Spoofing

BioCatch Launches DeviceIQ to Combat AI-Driven Fraud and Device Spoofing

Financial institutions are strengthening device intelligence capabilities as fraud tactics become more sophisticated in the era of AI-driven attacks. BioCatch’s latest launch highlights how banks are moving beyond traditional authentication methods to assess device trustworthiness before a session even begins.

The battle against digital financial crime has entered a new phase with BioCatch, a leader in behavioural biometrics, officially releasing DeviceIQ. This advanced device identification and intelligence product is designed to redefine how financial institutions assess the trustworthiness of hardware used for mobile and online banking. As criminals adopt increasingly sophisticated evasion tactics, such as emulators, device spoofing, and data wiping, traditional security signals have become less reliable. The launch of this platform aims to bridge that gap by providing a deep analysis of device health before a user even attempts to log in.

The current fraud landscape is being rapidly reshaped by the emergence of artificial intelligence tools, including deepfakes and agentic browsers. These technologies allow bad actors to separate user actions from physical device signals, creating a significant challenge for legacy detection systems. Furthermore, banks must navigate these threats while adhering to strict global privacy laws. DeviceIQ addresses these pressures by assessing the risk level of each session, regardless of whether the device has been seen before, ensuring that only healthy and legitimate hardware can access sensitive financial data.

The platform introduces several innovative capabilities that differentiate it from standard security tools. One primary feature is persistent recognition, which maintains a device’s identity even after a user upgrades their phone or reinstalls a banking application. This reduces the friction of repeated validations for honest customers while simultaneously flagging attempts by criminals to mask their hardware identity. Additionally, the system leverages network effects, drawing on insights from the broader BioCatch ecosystem to identify devices previously linked to money mules or to account takeovers at other institutions.

Pre-authentication detection is another critical pillar of the new technology. Before a password is entered or a face is scanned, the system monitors for jailbroken operating systems, missing sensors, or unauthorized code designed to intercept banking data. This allows risk teams to block compromised devices entirely or flag the session as high risk before it officially begins. Early testing at a major American financial institution showed that devices flagged by the system were thirteen times more likely to have successfully bypassed previous security layers.

Privacy remains a central focus of the architecture. The tool does not collect personal identifiers such as names, addresses, or social security numbers. Instead, it uses pseudonymized data to ensure that all device identities meet international security and regulatory requirements. This information is integrated into a unified platform via a single software development kit, giving banks a holistic view of behavioural, transactional, and device risk in one location.

To prepare for a future driven by automation, the company also introduced an additional layer, DeviceIQai. This feature is specifically designed to distinguish between human users and AI agents. It can identify deepfake attempts by detecting the use of virtual cameras or pre-recorded audio during authentication. By distinguishing between a genuine user using an AI assistant and a criminal using a bot for account takeover, the platform enables banks to support modern automation while maintaining a secure perimeter.

What this means for the industry

• Device intelligence is becoming a critical layer in fraud prevention
Banks are moving beyond traditional authentication methods to assess the health and trustworthiness of devices before access is granted.

• AI-driven fraud is reshaping security strategies
The rise of deepfakes and automated attack tools is forcing institutions to adopt more advanced detection capabilities.

• Pre-authentication risk detection is gaining importance
Identifying threats before login attempts allows banks to block compromised sessions early and reduce potential losses.

• Balancing security with user experience remains key
Persistent device recognition helps reduce friction for legitimate users while maintaining strong protection against fraud.

• Distinguishing between human and AI activity will be essential
As automation increases, the ability to differentiate between genuine users and malicious bots will become a core requirement for financial security.

Notice an error or have additional information about this story? Contact the Finnoex newsroom: newsroom [at] finnoex [dot] com.

Discover more from Finnoex

Subscribe now to keep reading and get access to the full archive.

Continue reading