As Fraudsters Evolve, CUs Must Too: Security Expert Says Static Defenses Are ‘Outmatched And Outdated’

ATLANTA— Credit unions can no longer rely on static defenses against fraud, and contextual authentication is proving to be the solution, Entersekt said, pointing to dramatic results achieved by one large credit union.

For decades the industry leaned on the same two tools to stop unauthorized access: usernames/passwords and one-time passcodes (OTPs) sent by text or email. Those defenses worked when attacks were rudimentary. They don’t now. Today’s fraudsters weaponize social engineering, device spoofing and cross-platform credential stuffing — and a growing chorus of analysts say credit unions must move from static checks to contextual authentication if they want to stay ahead.

iStock-hirun

That warning isn’t theoretical. According to Mzukisi Rusi, vice president of product development for authentication at Entersekt, the $3.1-billion Chartway FCU in Virginia Beach, Va., deployed contextual authentication and saw immediate, measurable wins: tens of thousands of malicious login attempts stopped and thousands of suspicious password-reset attempts flagged in a single month, unpaid operational workload slashed and six- and seven-figure fraud exposure reductions projected within a short period. Those outcomes, Rusi said, show the difference between reacting to fraud and preventing it.

Why The Old Model Fails

OTPs were introduced more than 20 years ago and remain the predominant step-up mechanism across many financial institutions. But Rusi — whose company has spent years building device-based and context-aware solutions — lays out why those methods are now a liability:

  • OTPs are trivial to social engineer. A fraudster pretending to be a bank rep can cajole a member into reading back a code sent by text or email.
  • Username/password pairs are routinely stolen and re-used across services.
  • Static rules (IP allowlists, simple velocity checks) catch some attacks but can’t read context: Is this device familiar? Is the behavior consistent with the member’s history? Is the channel trustworthy?

“Static defenses will not keep up,” Rusi says. “Fraud has evolved into context manipulation and emotional pressure. You can’t expect a one-size-fits-all control to stop it.”

What Contextual Authentication Actually Is

Contextual authentication adapts in real time. Instead of asking every user to perform the same step (enter an OTP), the system evaluates a set of signals and responds according to risk:

  • Device signals. Is the request coming from a previously bound, trusted device? Is there evidence of malware or risky apps on the device?
  • Channel context. Is the user in the mobile app, a desktop browser, the call center or a web checkout flow?
  • User history and preferences. Has this member logged in from this device before? Do they typically use Face ID or a password?
  • Transaction risk. Is this a low-value balance check or a high-value transfer/password reset?

Put together, these signals give the system a risk score. Low-risk actions proceed frictionlessly; high-risk ones trigger a targeted step-up (biometric scan, out-of-band confirmation, temporary block) or a human review. Crucially, contextual systems can also involve the member — e.g., push a notification that asks “Did you request this password reset?” so legitimate members can deny fraudulent attempts instantly.

Chartway’s Case: Outcomes That Demand Attention

Mzukisi Rusi

Chartway Credit Union’s fraud performance numbers with the solution are striking:

  • ~10,000 malicious login attempts blocked because they originated from untrusted or suspicious devices.
  • ~3,000 password-reset attempts in one month were surfaced and triaged; about 90% of reset attempts were shown to come from trusted devices (and thus were legitimate), while the remaining 10% were untrusted and either rejected by members or blocked by the system.
  • The credit union projected large fraud-savings from reduced unauthorized access and fewer manual member support calls — a measurable ROI in the six/low seven figures across the rollout period, according to vendor calculations.
  • Operational benefits included fewer call-center escalations and more empowered members who could see and reject suspicious activity themselves.

Those results aren’t small incremental gains; they’re operational and financial moves the industry takes seriously. Chartway’s experience shows contextual authentication can be both more secure and less frictional for legitimate members — the holy grail for digital banking, Rusi said.

The real takeaway for credit unions is practical: systems that silently build device trust, collect meaningful risk signals, and empower members to confirm or reject suspicious activity reduce both successful attacks and support costs, Rusi explained.

What Credit Unions Should Do Now

  1. Inventory your signals. Know what device, channel and behavioral signals current stack collects. If the CU only has passwords and OTPs, they’re starting from a deficit.
  2. Prioritize device binding and trust modeling. Establishing a persistent device identity (without intrusive UX) is a high-leverage control: it’s cheaper to trust a known device than to reauthenticate every time.
  3. Adopt adaptive, not binary, controls. Use risk scoring to tailor step-ups so low-risk users move fast while high-risk actions get stronger checks.
  4. Measure both security and member friction. Track blocked attacks and member experience metrics — adoption rises when security reduces friction for legitimate users.
  5. Plan for regulatory and operational gains. Contextual trails provide better evidence that actions were authorized, and can cut manual investigations and call-center burden.

The Bigger Picture

The fraud landscape is not static. Rusi argues the industry is at a turning point: attacks exploit context and emotion, not just stolen credentials. Credit unions that continue to rely on legacy OTPs and static rulebooks will face rising losses and member burnout. Those that embrace adaptive, layered authentication — and that view members as partners in fraud defense — can achieve both superior security and a better digital experience.

Section: Standard
Word Count: 1109
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/As-Fraudsters-Evolve-CUs-Must-Too-Security-Expert-Says-Static-Defenses-Are-Outmatched-And-Outdated