By NHI Mgmt Group Editorial TeamBased on Arkose Labs: “The Attack Runs Itself: What Agentic AI Fraud Actually Looks Like” (April 21, 2026)

TL;DR: Agentic AI fraud now operates as a 24-hour attack factory that generates synthetic identities, adapts across sessions, and uses legitimate or compromised access paths at the interaction layer, according to Arkose Labs, while the World Economic Forum reports 73% of respondents were personally affected by cyber-enabled fraud in 2025. Identity verification alone fails when behaviour changes mid-session and success depends on observing what the actor does, not just who it claims to be.


At a glance

What this is: This is an analysis of how agentic AI fraud now runs through account creation, login, payment, and MCP-connected interaction paths with adaptive, session-to-session behaviour that defeats identity-first checks.

Why it matters: IAM, fraud, and identity security teams need to treat interaction-layer behaviour as the control point because agent identity checks alone cannot distinguish autonomous abuse from legitimate users or authorised workloads.

By the numbers:

  • 73% of respondents were personally affected by cyber-enabled fraud in 2025, according to the World Economic Forum's Global Cybersecurity Outlook 2026 cited by Arkose Labs.

Context

Agentic AI fraud is fraud executed by software systems that can plan, adapt, and continue across sessions, not just script-like bots. The governance gap is that many controls still assume fraud can be understood from a login or device signal alone, when the decisive evidence sits in behaviour across the interaction layer.

Arkose Labs frames the problem around identity-first defenses that focus on who the actor claims to be rather than what it does. For IAM and fraud teams, that shifts the question from authentication confidence to behavioural trust under autonomous or semi-autonomous execution.

The article also distinguishes AI-assisted fraud from fully agentic campaigns, which matters because the control failure changes with the actor. AI-assisted operations still rely on human steering, while fully agentic fraud can probe, learn, and retry without human pacing, which is a different governance problem.


Key questions

Q: What breaks when agentic AI fraud is judged only by identity signals?

A: Identity-only fraud controls break when the actor can change tactics after sign-in. A verified account, credential, or agent provenance claim says little about whether the session is being used to probe, adapt, and complete fraud across onboarding, checkout, or account takeover flows. Teams need behavioural trust, not just identity trust.

Q: Why do agentic fraud campaigns make mid-session adaptation so dangerous?

A: Because the system can learn from each failure and change the next attempt without waiting for human guidance. That removes the pacing assumption most fraud models rely on, where failure on one session limits the next. The result is a campaign that gets better at bypassing controls as it runs.

Q: How can IAM teams tell whether fraud controls are actually working?

A: Look for fewer unverified high-risk requests, better challenge rates on abnormal approvals, and stronger separation between routine identity events and exceptional transactions. If users still complete sensitive actions based only on message urgency or apparent authority, the control is not working.

Q: What is the difference between agent identity and agent behaviour in fraud defence?

A: Agent identity describes who or what the system claims to be. Agent behaviour describes what it does over time, including retries, workflow choices, and escalation paths. In agentic fraud, identity can be legitimate while behaviour is abusive, so governance must evaluate both layers separately.


Technical breakdown

Synthetic identity generation at machine speed

Synthetic identity generation is the entry point for many agentic fraud campaigns. Instead of creating one fraudulent profile at a time, AI systems can assemble convincing identity packages in minutes, using generated text, images, and document flows to pass initial checks. The important shift is scale plus adaptability: the actor can tune inputs based on what survives validation, then reuse the learnings in the next run. That makes static onboarding controls easier to probe and less informative as stand-alone signals. Practical implication: treat sign-up integrity as an adaptive adversary problem, not just a form-validation problem.

Practical implication: move fraud controls upstream into the identity proofing and interaction sequence, where synthetic accounts are first assembled.

Autonomous navigation through the interaction layer

The interaction layer is where the campaign actually executes. Agentic systems fill forms, handle MFA, retry on rejection, submit documents, and continue across login, account creation, checkout, and API-driven flows. This is not network-layer anomaly in the classic sense, because the traffic can look normal while the behavioural sequence is not. The risk is especially acute when the system can learn which steps trigger friction and then adjust its path. For identity teams, that means the observable control surface is not just the credential event, but the task sequence around it. Practical implication: instrument behavioural checkpoints across critical journeys, not just at authentication.

Practical implication: add behaviour-aware controls to account creation, login, and payment flows where the fraud actually manifests.

Why agent identity checks miss agentic abuse

Agent identity verification answers a narrow question: who or what is this actor? It does not answer whether the actor is behaving within the expected bounds of the session or workflow. That gap matters because a verified or authorised actor can still be used maliciously, especially when the campaign is driven through compromised credentials, service account abuse, or identity spoofing. In other words, trust in declared identity does not equal trust in execution. Practical implication: separate identity confidence from behavioural authorisation and monitor for scope drift during the session.

Practical implication: govern the session outcome, not only the initial identity assertion.


Threat narrative

Attacker objective: The attacker wants to scale fraud operations across identity and transaction flows while keeping the behaviour convincing enough to pass ordinary verification and friction controls.

  1. Entry begins with synthetic identity generation, which creates fraudulent accounts or profiles at machine speed and gives the campaign a foothold in onboarding or sign-up flows.
  2. Credential or access abuse follows when the actor uses compromised credentials, service account abuse, or spoofed identity to move through login, verification, or account-takeover paths.
  3. Escalation occurs when the agent adapts to friction, handles MFA, retries failed attempts, and learns which interaction patterns bypass defences in later sessions.
  4. Impact is coordinated cashout or transaction abuse across multiple accounts, with persistent memory and self-improvement increasing throughput and reducing human effort.

NHI Mgmt Group analysis

Identity-first fraud defense collapses when the actor is allowed to adapt after the authentication event. The article shows that the core control assumption is no longer stable identity, but stable behaviour. When the session itself can change tactics, the governance boundary shifts from who the actor is to what the actor does inside the interaction layer. Practitioners should treat behavioural evidence as the primary trust signal, not a secondary one.

Agentic fraud turns account creation and account abuse into the same governance problem. Synthetic identity generation, form navigation, MFA handling, and cashout are not separate threats when the same runtime system can chain them together. That means fraud controls built as isolated checkpoints miss the continuity of the attack. The right programme question is how identity assurance, workflow telemetry, and transaction risk are joined across the full journey.

Interaction-layer visibility is now the decisive gap in fraud programs. The article is explicit that these campaigns do not present clearly at the network layer and can look legitimate unless teams observe behaviour at the point of use. That is a structural problem for programmes still anchored in perimeter signals or static credentials. The implication is that fraud governance must be rebuilt around journey-level observability.

Agent identity is a necessary attribute, but it is not a sufficient control model. Verifying declared origin or cryptographic identity tells you something about provenance, not about intent, delegation, or subsequent actions. The article’s central warning is that identity-first frameworks can certify the wrapper while missing the abuse path. Practitioners should separate actor attestation from policy enforcement at runtime.

Ephemeral trust is the named concept that now matters most in agentic fraud. A session that starts with legitimate credentials can become fraudulent through adaptive behaviour, retries, and memory carried across attempts. That means trust is not a property granted once at sign-in. It is continuously renegotiated through the interaction layer, and security programmes must be designed around that reality.

From our research library:

What this signals

Behavioural trust now outranks identity attestation for fraud control. Systems that can hold legitimate credentials, vary their path, and learn across attempts create a trust problem that sign-in controls cannot solve on their own. The control point has moved to what happens during the session, not just at the front door.

Agentic fraud forces identity programmes to converge with fraud operations. That convergence is already visible in the fact that 67% of organisations still rely heavily on static credentials despite the risks they pose to agentic AI deployments. The implication is that credential governance and behavioural fraud detection can no longer sit in separate programme silos.


For practitioners

  • Instrument critical journeys for behavioural trust Add telemetry to account creation, login, MFA, checkout, and API-driven flows so you can detect adaptive retries, scripted navigation, and session-to-session learning.
  • Separate identity proofing from runtime authorisation Treat an authenticated or verified identity as an input, not an endpoint, and require behavioural evidence before high-risk actions are allowed to complete.
  • Review controls that assume fixed scripts Map where your fraud programme still assumes a bot will repeat the same path, then identify checkpoints that can respond to adaptation inside a live session.
  • Harden onboarding against synthetic identity assembly Increase friction and validation depth where fake accounts are assembled, especially in flows that can be completed at machine speed with generated artefacts.
  • Monitor service-account and credential misuse in interaction flows Look for legitimate-looking access patterns that still produce abnormal transaction sequences, because identity spoofing can hide in authorised paths.

Key takeaways

  • Agentic AI fraud is not just faster bot activity. It combines synthetic identities, adaptive sessions, and legitimate-looking access paths to defeat controls that focus only on who the actor claims to be.
  • The article points to a 24-hour attack factory model in which one operator can coordinate many agents, while the World Economic Forum reports 73% of respondents were personally affected by cyber-enabled fraud in 2025.
  • Teams need to shift from identity-only verification to interaction-layer governance, with behavioural checkpoints, journey telemetry, and runtime trust decisions that can respond to adaptation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI02 — Tool MisuseThe article describes autonomous systems using workflows and interaction tools to commit fraud.
ASI03 — Identity & Privilege AbuseThe attack relies on compromised credentials, service accounts, and identity spoofing.
ASI10 — Rogue AgentsThe article discusses fully autonomous attack agents acting without human effort per account.
Recommendation — Map interaction-layer fraud paths to ASI02 and restrict which tools and workflows agents can invoke. Apply ASI03 to separate declared identity from runtime privilege and session behaviour. Use ASI10 to detect and contain autonomous agents operating outside authorised fraud workflows.
OWASP Non-Human Identity Top 10NHI-02 — Secret LeakageCompromised credentials are part of the article's abuse path through legitimate-looking access.
NHI-04 — Insecure AuthenticationThe article shows that identity checks can succeed while the session is still abusive.
NHI-10 — Human Use of NHIThe article describes human strategy executed through non-human systems and identities at scale.
Recommendation — Treat exposed credentials as an interaction-layer fraud risk and revoke them before they can be reused. Harden authentication steps so they feed behavioural controls instead of serving as the sole trust gate. Govern human-to-machine fraud paths as NHI abuse when people steer automated account and transaction activity.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article frames a governance gap between AI-enabled capability and control ownership.
Recommendation — Assign governance accountability for agentic fraud detection and response across fraud, IAM, and AI risk teams.

Key terms

  • Agentic Fraud: Fraud executed by systems that can plan, adapt, and complete tasks with limited or no human intervention during the session. The control problem is not only account creation, but whether the system can continue to behave within approved bounds after access is granted.
  • Interaction layer: The point where a user, agent, or automation interacts with the business flow, such as login, checkout, account creation, or API use. This layer matters because it exposes behaviour, not just network characteristics, and it is often where agentic misuse becomes visible before deeper compromise occurs.
  • Behavioural Trust: Behavioural trust is the practice of judging message legitimacy by observed patterns such as timing, conversation history, and action sequence rather than by domain reputation alone. It is especially important when attackers operate through real accounts and authentic platforms.
  • Synthetic Identity: A synthetic identity is a software-based actor that can authenticate, request access, and execute actions without being a human user. In practice, this includes AI agents, bots, service accounts, tokens, and other machine identities that need clear ownership, scope, and revocation.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org