JPMorgan Chase has implemented enhanced security protocols for its mobile banking platform to combat emerging threats from Face ID spoofing and AI-generated deepfakes, following a broader trend of increasing AI-driven fraud attempts in the financial sector. The new measures are part of industry-wide efforts to strengthen biometric authentication security as financial institutions face sophisticated cyber threats.
The bank has introduced an additional authentication step for users logging in via Face ID, making it more difficult for attackers to bypass biometric security using spoofed facial images or deepfake technology. Chase filed a patent earlier in 2025 for this security feature, which builds upon existing liveness detection protocols similar to those implemented by other financial institutions to prevent account takeover attempts.
Alongside these changes, Chase is deploying passkeys, a passwordless authentication system using cryptographic key pairs. The system stores a private key on the user’s device while the bank maintains the public key. Users authenticate using biometrics or a PIN, eliminating traditional password vulnerabilities. The move follows growing enterprise adoption of passkey technology, which uses the FIDO Alliance’s WebAuthn standard.
The bank is also developing defensive capabilities against AI-powered fraud, including systems to detect synthetic voices on incoming calls. “We are monitoring what’s happening with AI — deepfakes, voice fakes, and so on,” said a Chase representative. “The features we’re building extend that thinking into how we defend against, for example, fake voices on incoming calls.” The initiative responds to recent FBI warnings about AI-powered voice impersonation scams.
A new “Trusted Contact Person” feature allows customers to designate an individual who receives alerts about high-risk wire transfers, without granting account access or balance visibility. The security measure follows similar initiatives by other technology companies, such as Google’s Recovery Contacts system.
The security enhancements arrive as the financial industry confronts an increase in sophisticated fraud attempts, including synthetic identity theft and AI-powered phishing schemes. Financial institutions are responding by implementing advanced biometric matching, AI-powered facial recognition, and real-time fraud detection systems, part of a broader shift in banking security measures throughout 2025.
“Passkeys are more secure than passwords because hackers can’t steal them from a company’s servers,” explained a Chase official. “The private key stays on the customer’s device and can’t be guessed, reused or phished.”
Sources: American Banker, Financial & Retailers Protection Association