Skip to main content

Chase's New Passkey and Trusted Contact Features: A Small Business Security Guide

9 min readMike ThriftMike Thrift
Chase's New Passkey and Trusted Contact Features: A Small Business Security Guide

Three seconds of audio is all it takes to clone a voice convincingly enough to fool a bank teller, a bookkeeper, or a business owner's own spouse. That's not a hypothetical from a cybersecurity conference — it's the baseline capability of commercial speech models available today, and it's exactly the threat that pushed Chase to quietly rebuild how its customers log in and authorize money movement.

In early 2026, Chase began rolling out passkeys for signing in to chase.com and resetting passwords, alongside a separate feature called Trusted Contact Person that flags high-risk wire transfers to someone outside the transaction. Neither feature made huge headlines outside banking trade press, but together they represent the clearest signal yet that AI-driven fraud has forced banks to rethink account security from the ground up — and small business owners, who move real operating capital through these same login screens, have the most to gain from understanding what changed and why.

Why Your Bank Login Suddenly Looks Different

For twenty years, "secure enough" for online banking meant a password plus maybe a text-message code. That model is breaking down for a specific reason: AI has made the weakest link in that chain — the human being who can be fooled — much easier to fool.

According to Goran Loncaric, a managing director at JPMorganChase, passkeys close this gap because the private cryptographic key never leaves the customer's device. It "can't be guessed, reused or phished," which matters because phishing and credential-stuffing attacks depend on tricking someone into typing a password into a fake login page or reusing a leaked password from another breach. A passkey has nothing to type, so there's nothing to steal.

The Trusted Contact Person feature addresses a different attack entirely — one where the fraud doesn't target the login at all, but the phone call that comes after. Chase built it specifically in response to deepfake and voice-spoofing scams, where a fraudster calls a business owner impersonating a vendor, executive, or even a family member, and pressures them into authorizing an urgent wire. With a trusted contact designated, a high-risk transfer triggers an alert to that second person — who has no access to the account or its balance — giving someone a chance to say "wait, did you actually authorize this?" before the money is gone.

The Threat Behind the Feature

The numbers explain why banks are moving now rather than waiting.

Voice cloning no longer requires special access or expensive equipment. A free trial of a commercial speech model, roughly thirty seconds of audio pulled from a LinkedIn video or company podcast, and a phone are enough to produce a convincing clone of someone's voice. That low barrier shows up directly in the fraud statistics: deepfake-related fraud attempts increased by more than 2,000% over the past three years, and voice phishing (vishing) attacks specifically surged by several hundred percent in 2025 as AI tools became more accessible.

The financial exposure for small and mid-sized businesses is not abstract. Per-incident losses from deepfake-enabled fraud on the SMB side typically run $30,000 to $400,000 — often the result of a single convincing phone call or video that impersonates a CEO, vendor, or bank representative and requests an urgent wire transfer. Banks themselves aren't immune either: financial institutions report losing an average of roughly $600,000 per voice-deepfake incident, with nearly a quarter of those losing over $1 million.

This is the context in which "add a login step" and "designate a trusted contact" stop sounding like friction and start sounding like common sense.

What Passkeys Actually Change for You

If you've never set one up, a passkey can feel abstract compared to a password you've memorized for years. In practice, it's simpler, not more complicated:

  • No password to remember or type. You unlock a passkey with the same biometric or PIN you already use to unlock your phone or laptop — Face ID, a fingerprint, or a device passcode.
  • Nothing sits on a server to be stolen. Traditional passwords are stored (hashed, ideally) on the company's servers, which is exactly what gets exposed in a breach. A passkey's private half never leaves your device, so there's no password database for attackers to steal in the first place.
  • Phishing pages stop working. A fake "Chase login" page can capture a password you type into it. It cannot capture a passkey, because the passkey is cryptographically tied to the real chase.com domain and simply won't respond to an impostor site.
  • It's measurably more reliable, too. Independent adoption data from the FIDO Alliance puts passkey login success at roughly 93%, compared to 63% for passwords — a difference driven mostly by people forgetting or mistyping passwords in the first place.

None of this requires you to be technical. If your bank offers passkeys, turning one on is typically a two-minute settings change, and you can keep your password as a fallback while you get comfortable.

This Isn't Just a Chase Problem

Chase is the largest U.S. bank by assets, so its moves tend to set the pace for the rest of the industry — but it's not acting alone. Passkey adoption has crossed into the mainstream faster than almost any other security technology in recent memory: the FIDO Alliance reported roughly 5 billion passkeys in active use worldwide as of its 2026 World Passkey Day report, with 90% of people now aware of the technology and about half using it regularly when it's offered. On the enterprise side, 68% of organizations have deployed or are actively rolling out passkeys for employee logins.

That matters for small business owners because the accounts you touch every day — your bank, your payroll provider, your accounting software, your domain registrar — are increasingly likely to offer a passkey option even if they haven't announced it with a press release. The practical move is to check your account security settings periodically rather than waiting for an email announcement.

How to Recognize a Deepfake or Vishing Attempt

Technology alone won't catch everything, especially in the window before every vendor and bank rolls out stronger authentication. A few behavioral tells still separate most AI-assisted scams from legitimate requests:

  • The request creates artificial urgency. "This has to happen right now, before end of day" is a manipulation tactic, not a normal business constraint. Legitimate wires, vendor payments, and payroll changes almost never require bypassing your normal approval process.
  • The caller discourages verification. Scripts built around deepfake audio often include lines like "don't call me back on the office line, use this number instead" — precisely because a callback to a known, trusted number is what breaks the scam.
  • Audio or video quality has subtle artifacts. AI-generated voice can sound slightly flat in emotional range, or video can show unnatural blinking, lighting inconsistencies, or lip-sync drift. These cues are getting harder to spot as the technology improves, which is exactly why process-based defenses (a second approver, a callback policy) matter more than trying to detect fakes by ear.
  • The channel doesn't match the relationship. A vendor who has only ever emailed invoices suddenly calling to request an urgent wire change is a mismatch worth pausing on, even if the voice sounds right.

A Practical Security Checklist for Small Business Bank Accounts

Whether or not your bank has rolled out passkeys yet, the underlying lesson applies broadly. Here's what actually reduces your exposure:

  1. Turn on passkeys wherever they're offered, starting with your business bank account, payroll provider, and accounting software — the accounts that can move money.
  2. Designate a trusted second approver for wire transfers, even informally. If your bank doesn't have a formal "trusted contact" feature yet, set an internal rule: no wire above a set dollar threshold goes out without a second person confirming by a channel other than the one the request came in on (e.g., a phone call requesting an urgent wire gets confirmed by text or in person, not a callback to a number the caller provided).
  3. Treat urgency as a red flag, not a reason to skip verification. Deepfake and vishing scripts are built around manufactured time pressure — "the wire has to go out in the next ten minutes." Real vendors and real executives can wait for a callback on a known number.
  4. Retire SMS-only two-factor authentication where you can. Text-message codes are better than nothing, but they can be intercepted or socially engineered via SIM-swap attacks. Passkeys or authenticator apps are stronger.
  5. Keep a recovery plan for whoever holds admin access. If you set up hardware security keys or device-bound passkeys for your bookkeeper or accountant, register a backup method too — losing the only device with access to a business bank account is its own kind of costly downtime.

Where Bookkeeping Fits Into the Security Picture

Fraud prevention and financial recordkeeping aren't separate problems — they reinforce each other. A business that reconciles its accounts weekly, rather than monthly or quarterly, will catch a fraudulent wire transfer within days instead of discovering it a month later when the bank statement finally gets reviewed. Clear, current records are also what your bank, your insurer, or law enforcement will ask for first if you do need to dispute a transaction or file a fraud claim — the faster you can show exactly what was authorized and when, the faster a case moves.

This is one of the quieter benefits of keeping books in a transparent, auditable format rather than a black-box tool you only open at tax time: when something looks off, you can actually see it.

Keep Your Finances Organized and Auditable

As banks add new layers of login security, your own financial records deserve the same level of scrutiny and transparency. Beancount.io provides plain-text accounting that gives you complete, version-controlled visibility into every transaction — no black boxes, no vendor lock-in, and an audit trail that makes it easy to spot something that doesn't belong. Get started for free and see why developers and finance professionals are switching to plain-text accounting.

Share this article