THE BROAD VIEW

Why NRIC authentication is flawed – and what’s the alternative?

New security layers are essential when a single data breach can trigger a cascading impact across banks and providers of critical services

Summarise
    • With digital scams on a steep rise, organisations must enhance identity verification methods while ensuring privacy protection.
    • With digital scams on a steep rise, organisations must enhance identity verification methods while ensuring privacy protection. IMAGE: PIXABAY
    Published Sat, Feb 28, 2026 · 06:30 AM

    AS SCAMMERS become more brash, it is no exaggeration to say that Singapore’s digital economy faces a threat to its continuity and resilience.

    Although losses from scams decreased 24.8 per cent in 2025 compared with 2024, the Singapore Police Force revealed on Wednesday (Feb 25) that the figure still stood at an eye-watering S$913.1 million.

    Unsurprisingly, this has spurred action, with the Personal Data Protection Commission recently announcing the discontinuation of National Registration Identity Card (NRIC)-based authentication by end-2026.

    In its place, the private sector must transition to multi-factor authentication for verifying customer identities. This includes biometric fingerprint or facial verification, as well as specialised security tokens aligned with the Fast Identity Online standard.

    For businesses, navigating this shift requires close examination of the status quo – static authentication. Sectors handling sensitive identity data such as healthcare, telecommunications and financial institutions must be capable of verifying customer identities and continuously evaluating transaction risk.

    The thieves that don’t exist

    Fraudsters and scammers are inventing new ways to circumvent safeguards. Last November, the police uncovered a scheme utilising digitally altered Singapore identity cards to create payment services accounts for channelling illicit profits.

    Sophisticated synthetic identity fraud – also known as Frankenstein fraud – is also on the rise. In March 2025, there was a notable case where a Singaporean company lost S$499,000 when fraudsters conducted a sophisticated deepfake video call that duped its finance director into approving money transfers.

    Operations like this contributed to the S$23 million losses stemming from Frankenstein fraud, and Juniper Research estimates that could more than double by 2030.

    Frankenstein fraud is especially effective because it makes composite identities from a combination of stolen and fabricated information, artificial intelligence (AI)-generated imagery, and voice synthesis. Threat actors use these as building blocks for hyper-realistic digital personas capable of fooling the keenest eye.

    Synthetic identities are also used to execute the long con. Scammers use these digital personas to establish creditworthiness over months or years before securing a substantial loan, at which point they are discarded.

    Financial services are not alone in this: Telecoms operators face SIM swop fraud and account takeovers. Healthcare institutions face privacy breaches that can directly affect patient safety and trust. Banks face direct financial loss and fraud liability.

    As these sectors transition towards physiological biometrics (such as Singpass facial verification for higher-risk transactions), deepfakes can circumvent facial recognition software, particularly if the software lacks robust “liveness” detection.

    That is why organisations must remain constantly aware of emerging threats – and how their current defences measure up against the technologies being employed to target them and their customers.

    The flaws of NRIC authentication

    NRICs were never designed to be security credentials, even though they’ve historically been used across multiple services for identification and authentication.

    This reuse means that a single breach can trigger a cascading impact, resulting in impersonation across banks, telecoms operators, healthcare institutions and government-linked services.

    NRICs also facilitate impersonation and social engineering since they are frequently regarded as “proof of identity”. Once NRIC details are exposed through data breaches, phishing schemes or information leaks, they cannot be altered or cancelled, making them a high-risk credential that attackers can misuse unfettered.

    Cybercriminals can exploit stolen information to effectively mimic individuals, circumvent verification processes, or escalate privileges via call centres and online platforms.

    This can be observed through multiple major incidents that occurred over the past few years.

    Some examples include the SingHealth cyberattack that stole the personal details of 1.5 million patients, the IT system error at the Council of Estate Agencies that distributed the names and NRIC numbers of more than 3,000 individuals to 18 unintended recipients, and the Accounting and Corporate Regulatory Authority’s Bizfile portal leak that exposed the full NRIC numbers of business owners, company directors and stakeholders.

    What organisations can do

    Digital identity and robust identity access management (IAM) must serve as the new security layers safeguarding an organisation’s reputation and the trust of customers, patients and subscribers.

    Here’s a quick guide on the steps and processes that organisations can use to seamlessly integrate IAM into their operations:

    • Utilise flexible and adjustable authentication. Modern digital identity systems provide risk-based authentication that adjusts verification methods according to immediate threat indicators, ensuring robust security without adding friction to customer experience.
    • Implement continuous identity verification. Beyond the initial login, continuous identity verification maintains trust during onboarding, sensitive interactions and account recovery. This minimises complex fraud tactics that circumvent static verifications.
    • Incorporate sophisticated biometrics. Biometric techniques that embed privacy protection significantly reduce fraud risk. Zero-knowledge biometrics, for example, which do not retain accessible biometric information, enhance trust in identity verification and safeguard user privacy.
    • Tackle identity fraud issues head-on. Fraud causes both emotional and financial harm, but victims frequently perceive a lack of support from service providers. With surveys showing high concern among consumers about identity fraud and AI-related risks, this is a golden opportunity for organisations to enhance customer trust through robust digital identity safeguards and clear communication about how these strategies benefit customers.

    Trust must be built from the ground up

    In a threat landscape defined by AI-powered fraud, fabricated identities and deepfakes, fixed credentials are no longer sufficient. Shifting away from NRIC-based verification is not merely a compliance obligation, but also an essential progression towards more robust, flexible identity systems.

    The institutions that thrive in this new digital reality will be those that regard identity as a strategic cornerstone for security, innovation and enduring trust.

    The writer is director at Ping Identity