Technological developments make it difficult to identify impostors.

After identity theft cases, Israel regulator demands sweeping review of financial firms’ ID checks

The regulator’s move follows a recent rise in cases involving Israeli homeowners living abroad who claim impostors used stolen identification documents to take out loans against their properties 

The Capital Market Authority is stepping up its efforts to tackle identity theft and financial fraud, requiring regulated financial service providers to conduct a comprehensive review of their identification and authentication systems, including a retrospective review of customer accounts opened over the past two years. The move comes against what the authority describes as a growing risk of fraud, embezzlement and identity theft across the financial system.
The instructions come shortly after Calcalist reported on two cases in which owners of apartments in Netanya who live abroad claimed that impostors used stolen identification documents to place liens on their properties. In one case, a couple living in Moscow claimed that a NIS 1.2 million mortgage was registered against their apartment without their knowledge, after their home was burglarized and identification documents were stolen.
1 View gallery
מאגר ביומטרי זיהוי ביומטרי
מאגר ביומטרי זיהוי ביומטרי
Technological developments make it difficult to identify impostors.
(Shutterstock)
In another case, a brother and sister living in Germany claimed that impostors obtained a NIS 2 million loan and used their apartment as collateral. In both cases, the mortgages were registered in favor of non-bank lender Magen Afikim. The claims are currently the subject of legal proceedings and have not been adjudicated.
In a letter issued by the authority this week to regulated financial service providers, it said that fraud and impersonation risks are carried out through a variety of methods, both through digital interfaces and in face-to-face interactions. Among other methods, the authority cited the use of forged identification documents, identity theft, social engineering and advanced technologies. It warned that technological developments are making it harder to identify impostors and increasing the risk of fraudulent activity.
Accordingly, regulated entities are required to reassess the effectiveness of their identification and authentication measures, both through remote channels and during face-to-face interactions, and to examine their control systems and identification procedures. As part of the review, they must also examine the use of technological tools for detecting forged documents, as well as conducting liveness checks and technological verification of customers. The updated policy must be presented to the board of directors for discussion and approval by mid-October.
In addition, the authority is requiring companies to conduct a scan and review of customer accounts opened over the past 24 months, with particular emphasis on accounts opened through remote identification. The review is intended to assess compliance with identification and authentication requirements and identify suspicious signs of fraud, impersonation or the use of synthetic identities. Companies will be required to submit the findings of the review, including any corrective and control measures taken, to the authority by November 4. The authority is also requiring reports on material fraud incidents and details of the steps taken in response.