By NHI Mgmt Group Editorial TeamPublished 2026-06-25Domain: AnnouncementsSource: Arkose Labs

TL;DR: 64% of organisations report decreased customer acquisition due to cyberattacks, while 78% are concerned about AI-powered threats to critical business apps and 44% are focused on ATO and credential stuffing, according to Arkose Labs. The practical shift is that customer trust, bot pressure, and account abuse now have to be governed together, not as separate problems.


At a glance

What this is: Arkose Labs argues that AI-powered fraud, bot activity, and account takeover are directly affecting streaming and media businesses, with customer acquisition, revenue protection, and account security converging into one operational problem.

Why it matters: For IAM, IGA, PAM, and fraud teams, this matters because identity controls now have to cover customer access, bot behaviour, and abuse patterns at the same time rather than treating them as separate domains.

By the numbers:

👉 Read Arkose Labs' analysis of AI-powered fraud risks in streaming and media


Context

The core issue is no longer just fraud prevention. Media and streaming businesses are dealing with identity abuse, automated account creation, credential stuffing, and subscription abuse in the same customer journey, which means access control and abuse detection now overlap.

Arkose Labs frames the problem as protecting revenue while preserving seamless access for genuine users. That is the right governance question for IAM and fraud teams alike, because customer identity, bot resistance, and transaction trust are now coupled operational controls rather than isolated security tasks.


Key questions

Q: How should security teams reduce account takeover risk in customer-facing applications?

A: Security teams should combine behavioural detection, device intelligence, and adaptive challenges around login, recovery, and payment flows. The goal is not to block every suspicious request. It is to raise attacker cost while preserving a smooth path for legitimate users. That approach works best when fraud, IAM, and customer experience teams use the same risk signals.

Q: Why do bots and credential stuffing matter to IAM programmes?

A: Bots and credential stuffing matter because they turn identity controls into a business-risk problem. When automated abuse reaches accounts at scale, it affects access trust, customer acquisition, support workload, and revenue. IAM teams need to care because authentication outcomes alone do not show whether the programme is actually resisting abuse.

Q: What breaks when adaptive challenges are too blunt?

A: When challenges are too blunt, legitimate users encounter unnecessary friction while attackers adapt around static controls. That usually leads to higher abandonment, more support tickets, and weaker fraud outcomes. The failure is not just operational. It also hides risk because teams confuse friction with effectiveness.

Q: Who should own account abuse governance in streaming and media?

A: Account abuse governance should be shared by IAM, fraud operations, and product security, with clear decision ownership for challenge policy, recovery flows, and customer friction thresholds. If those responsibilities are split without coordination, attackers exploit the gaps between teams and users experience inconsistent protection.


How it works in practice

How bot detection works in customer identity flows

Modern bot mitigation does not rely on a single signal. It combines behavioural telemetry, device fingerprints, session patterns, network indicators, and interaction anomalies to identify automated traffic that looks superficially legitimate. In customer-facing services, that matters because credential stuffing and fake onboarding often use human-like timing and distributed infrastructure to evade simple rate limits. A useful model is adaptive decisioning, where the system raises friction only when risk crosses a threshold. That preserves conversion for genuine users while constraining abuse paths that erode trust and revenue.

Practical implication: map your highest-value customer journeys and add layered risk scoring before the abuse reaches account creation or login completion.

Why adaptive challenges matter for ATO and fake onboarding

Adaptive challenges work by increasing verification friction as confidence in legitimate user intent drops. Instead of applying the same control to every request, the system changes challenge strength based on risk signals such as velocity, device reputation, session consistency, and cross-account behaviour. This is particularly relevant for account takeover and fake onboarding, where fraudsters optimise for scale and low cost. The technical value is not just blocking attacks. It is forcing attackers into a higher-cost path that reduces ROI, which is often what changes their behaviour faster than static controls do.

Practical implication: tune challenge escalation rules so you protect sign-up and login without creating unnecessary friction for legitimate customers.

How decisioning intelligence supports anti-fraud governance

Decisioning intelligence turns observed abuse into reusable policy. By aggregating signals across tenants, industries, and attack patterns, teams can identify shared fraud infrastructure, repeated actor behaviour, and emerging evasion methods. That matters because many account abuse campaigns are not unique to one platform. They are repeatable, industrialised patterns. The architecture only becomes useful when risk data feeds both prevention and investigation. In other words, detection without decisioning leaves you with visibility but no control, while decisioning without good signal quality creates false positives and customer friction.

Practical implication: connect abuse telemetry to your fraud rules engine and review which signals actually reduce loss versus merely increasing alerts.


NHI Mgmt Group analysis

Identity and fraud have converged into one governance problem: media and streaming platforms can no longer treat customer authentication, bot mitigation, and revenue protection as separate controls. The article shows that attack pressure now runs through the full customer journey, from fake onboarding to account takeover and subscription abuse. For practitioners, the implication is that identity governance must be measured by abuse resistance as much as by login success.

Adaptive friction is now a core control surface, not a user-experience add-on: static authentication rules are too blunt for fraud systems that blend automation, stolen credentials, and human-like behaviour. The presence of 225-plus signals in the vendor description reflects the shift toward decisioning based on context, not just identity proofing. The practitioner conclusion is that customer friction should be risk-calibrated, not uniformly applied.

Revenue loss is becoming an identity metric: when cyberattacks reduce customer acquisition, the business impact is no longer confined to security operations. That changes how IAM leaders should talk about account abuse, because control failures now show up in acquisition funnels, churn, and support burden. The field implication is that identity programmes need fraud-linked KPIs, not just access-event metrics.

Bot activity is the structural precursor to account abuse at scale: credential stuffing, fake sign-ups, and automated probing create the conditions for downstream takeover and monetisation. This is where NHI-style thinking becomes relevant even in customer identity, because the threat is industrialised, repeatable, and machine-mediated. Practitioners should treat automated abuse as a governance signal, not a nuisance metric.

Cross-industry risk intelligence creates the biggest leverage when it feeds policy: sharing signals without enforcement only improves visibility. The real value is in turning shared abuse patterns into decision rules that can slow attackers before they reach accounts, payment paths, or subscription flows. For security teams, the conclusion is simple: intelligence must be operationalised or it remains descriptive.

From our research:

  • 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to AI Agents: The New Attack Surface report.
  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
  • That shift is why the OWASP Agentic AI Top 10 is becoming relevant to identity teams, not just AI builders.

What this signals

Identity teams should expect fraud controls and customer access controls to merge operationally. The old split between authentication and abuse prevention is breaking down because attackers now chain automation, stolen credentials, and revenue abuse in the same flow. That means policy owners need one view of customer trust, not two separate teams arguing over where the boundary sits.

AI-driven abuse is broadening the identity perimeter beyond human login events. With 80% of organisations reporting AI agents acting beyond intended scope in our research, the governance problem is no longer limited to customer fraud. It now includes machine-mediated abuse patterns that require coordinated controls across identity, telemetry, and decisioning.

Streaming and media teams should watch for the point where conversion protection becomes identity governance. The more your business depends on seamless access, the more your security model has to distinguish genuine user intent from industrialised abuse. That is where resources like the Top 10 NHI Issues become useful as a governance lens for machine-mediated threat pressure.


For practitioners

  • Instrument customer journeys for abuse, not just authentication Map signup, login, password reset, and payment flows for credential stuffing, fake account creation, and scripted abuse. Prioritise the paths where a small amount of friction will stop the largest amount of loss.
  • Calibrate challenge strength by risk tier Use adaptive challenges so low-risk users move through quickly while high-risk sessions face stronger verification. Reassess thresholds after each fraud campaign to avoid freezing your controls at yesterday’s attack pattern.
  • Tie fraud telemetry to identity and revenue metrics Track takeover rates, fake onboarding volume, and subscription abuse alongside conversion and churn so leadership sees the business cost of abuse. Use those metrics to justify policy changes and investment decisions.
  • Share abuse intelligence with decision owners Feed recurring signal patterns into the teams that own challenge policy, account recovery, and access rules. Intelligence only changes outcomes when it changes enforcement.

Key takeaways

  • AI-powered fraud is no longer a side issue for streaming and media platforms, because it directly affects acquisition, account trust, and revenue protection.
  • The most effective controls are adaptive and signal-driven, because static friction either misses abuse or punishes legitimate customers.
  • IAM, fraud, and product teams need shared metrics and shared decision ownership, or attackers will keep exploiting the gaps between them.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-1Identity proofing and access validation are central to stopping ATO and fake onboarding.
NIST Zero Trust (SP 800-207)DE.CM-1Continuous monitoring is needed to spot automated abuse and credential stuffing.
OWASP Non-Human Identity Top 10Machine-mediated abuse patterns overlap with non-human identity governance concerns.

Tie customer access controls to PR.AA-1 and validate identity signals before granting session trust.


Key terms

  • Account Takeover: Account takeover is the unauthorised use of a legitimate account after an attacker gains access through stolen credentials, phishing, or automated guessing. In customer environments, it often leads to fraud, abuse, support overhead, and trust erosion rather than immediate infrastructure compromise.
  • Adaptive Challenge: An adaptive challenge is a risk-based verification step that changes difficulty depending on how suspicious a session appears. It can include extra authentication, proof-of-presence checks, or step-up verification, and it is most effective when tuned to preserve low-friction access for legitimate users.
  • Credential Stuffing: Credential stuffing is the automated testing of stolen username and password pairs against online services. Attackers rely on password reuse and scale, so the control problem is not only authentication strength but also detection of machine-driven abuse and unusual login patterns.

What's in the full announcement

Arkose Labs' full article covers the operational detail this post intentionally leaves for the source:

  • Specific platform messaging around streaming revenue protection and customer transaction risk
  • Product-oriented explanation of how 225-plus signals are combined into real-time decisioning
  • Use-case examples for account takeover, fake onboarding, and SMS toll fraud
  • The vendor's own framing of adaptive challenges and intelligence sharing

👉 Arkose Labs' full article covers the platform messaging, signal model, and revenue-protection use cases.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on 2026-06-25.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org