By NHI Mgmt Group Editorial TeamBased on 1Kosmos: “Contact Center Fraud Prevention: Securing Authentication for Call Center Agents” (February 4, 2026)

TL;DR: Contact center fraud is rising fast, with nearly 29% of U.S. adults experiencing account takeover in 2024 and fraudulent calls reaching 12.5 billion in Q1 2025, according to 1Kosmos. The real issue is not just fraud volume but the weakness of identity proofing, agent workflow, and monitoring controls built for slower, less adaptive attackers.


At a glance

What this is: This is 1Kosmos' analysis of contact center fraud, showing that customer service channels are being abused because identity verification, agent training, and monitoring controls still leave exploitable gaps.

Why it matters: It matters because contact centers sit on customer accounts, transactions, and support privileges, so weak verification creates fraud, account takeover, and governance risk across customer IAM and operational identity controls.

By the numbers:

  • Nearly 29% of U.S. adults experienced account takeover in 2024, according to 1Kosmos.
  • Fraudulent calls reached 12.5 billion in Q1 2025, according to 1Kosmos.

Context

Contact center fraud is a governance problem as much as a fraud problem. It exploits customer service workflows to bypass identity verification, impersonate legitimate users, and move from conversation to account control.

The identity issue is that many contact centers still rely on security questions, caller ID checks, and human judgment under time pressure. Those controls were built for slower, less adaptive attackers and do not hold up well against social engineering, AI voice cloning, or deepfakes.

For IAM and customer identity teams, the question is no longer whether contact centers need stronger verification. It is how to stop high-volume, high-pressure interactions from turning identity proofing into an operational weak point.


Key questions

Q: What breaks when contact centers rely on security questions for identity verification?

A: Security questions fail because attackers can often source the answers from breaches, social media, or prior interactions. In a contact center, that means the control no longer proves the caller is genuine, it only proves the attacker can gather enough background information to sound legitimate. The result is a verification model that creates false confidence while leaving account recovery and high-risk changes exposed.

Q: Why do contact center fraud attacks succeed even when agents follow scripts?

A: Scripts help only if the attacker behaves predictably, but fraudsters use urgency, emotional pressure, spoofed numbers, and deepfake voices to push agents outside normal decision paths. The risk rises when operational targets reward speed, because the fraudster is effectively attacking both the agent and the workflow. That makes workflow design as important as fraud detection itself.

Q: What are the signs that call center identity verification is failing?

A: Common warning signs include rising high-risk calls, more spoofed caller activity, increased abuse of password reset and account change requests, and greater reliance on agent judgment instead of verified factors. If support teams still trust caller ID or secret questions for sensitive actions, the process is already misaligned with the current fraud environment and needs stronger step-up controls.

Q: Should contact centers use voice biometrics instead of password-based checks?

A: Voice biometrics are stronger than passwords or security questions, but they should not be treated as a single point of trust. The better model uses voice as one signal inside a layered verification flow that also considers device, session, and transaction risk. That reduces the chance that a convincing impersonation can trigger account control on its own.


Technical breakdown

Why knowledge-based verification fails in contact centers

Knowledge-based authentication and caller ID checks are weak because the data they rely on is often already exposed through breaches, phishing, or public sources. In a contact center, the attacker does not need to defeat a password manager or a device binding control. They only need to convince an agent that the caller sounds plausible and knows enough personal detail to pass a scripted check. That makes the control brittle under pressure, especially when service metrics reward speed over scrutiny. The result is not just a bad authentication method, but an authentication model that assumes private knowledge stays private after the first breach.

Practical implication: move away from static verification questions and treat call handling as an identity assurance workflow, not a customer service script.

How AI voice cloning and deepfakes change the fraud model

AI-generated voice cloning changes the economics of impersonation because the attacker can now reproduce a believable voice profile at scale. That undermines controls that depend on human intuition, speech familiarity, or confidence in vocal cues. Deepfakes also compress the time available for detection, because the fraud can be executed quickly and repeatedly before a suspicious pattern becomes obvious. In identity terms, the channel itself becomes part of the attack surface. The core weakness is not the audio quality alone, but the assumption that a human agent can reliably distinguish genuine from synthetic identity under real-world workload conditions.

Practical implication: combine voice analytics, fraud signals, and step-up verification instead of treating voice recognition as a standalone trust decision.

Why agent workflow and monitoring have to be part of identity verification

Contact center fraud succeeds when verification is treated as a front-door event and monitoring is treated as a separate back-office function. In practice, attackers often get through the first interaction and then use the live session to change credentials, update contact details, or pivot into account takeover. That means the control problem extends beyond entry authentication into session oversight, escalation handling, and suspicious-change detection. A mature design watches for repeated resets, rapid profile changes, unusual urgency patterns, and verification bypasses across channels. The technical issue is continuity: identity assurance must persist after the initial check, not end when the call is connected.

Practical implication: monitor the session, not just the login, and trigger escalation when high-risk changes occur during the interaction.


Threat narrative

Attacker objective: The attacker wants to obtain unauthorized control of customer accounts or sensitive information through the contact center interaction.

  1. Entry begins when the attacker uses social engineering, caller ID spoofing, or AI-generated voice impersonation to reach a contact center agent and appear legitimate.
  2. Credential access follows when the attacker convinces the agent to disclose account details, bypass verification, or approve a reset that exposes the customer account.
  3. Escalation occurs when the attacker uses the live session to change credentials, update recovery data, or take over the account before the legitimate user can intervene.
  4. Impact is account takeover, unauthorized transactions, customer data exposure, and downstream trust damage that can also trigger compliance and reputational loss.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Contact center fraud is an identity assurance failure, not only a fraud problem. The article shows that attackers are not simply stealing money, they are exploiting weak verification paths inside customer service operations. That places the issue squarely in customer IAM, not just in the fraud team. For practitioners, the control question is whether the contact center can prove identity under pressure without relying on assumptions that attackers already know how to bypass.

Knowledge-based checks are now structurally misaligned with modern impersonation. Security questions, caller ID, and static scripts assume that attackers cannot cheaply manufacture enough trust signals to pass as real customers. AI voice cloning and deepfakes break that assumption because they let fraudsters present believable identity cues at scale. The implication is that assurance has to shift from remembered facts to stronger, layered verification tied to the actual interaction context.

Identity verification in the contact center must be continuous, not episodic. The article makes clear that the threat does not end when a caller passes the first gate. Once an attacker is inside the session, credential resets, profile edits, and recovery changes can complete the takeover before monitoring reacts. That means the governing model has to treat verification, monitoring, and escalation as one control plane.

Contact centers expose a named gap we can call verification latency. This is the delay between an initial trust decision and the system noticing that the caller was fraudulent. The longer that latency, the more room attackers have to pivot from impersonation to account takeover. For teams, reducing that gap becomes a core design objective for customer identity governance.

The most dangerous failure mode is operational optimism under service pressure. When agents are measured primarily on speed and customer satisfaction, security steps become optional in practice even when they are mandatory on paper. That is how fraudsters exploit the human layer. Practitioners should treat KPI design as part of identity control, because the workflow will follow the incentive.

From our research library:

What this signals

Contact center identity governance is moving from point verification to session-level assurance. The practical lesson for IAM teams is that a caller who passes the front door can still be fraudulent inside the session. Controls need to detect suspicious state changes, not just authenticate the first request.

Verification latency is the gap fraudsters exploit. Once an attacker can keep a call alive long enough to reset credentials or alter recovery data, the contact center has already lost the identity decision. Teams should design for immediate escalation when high-risk account actions appear during a live interaction.


For practitioners

  • Replace static verification with layered identity proofing Use step-up authentication that combines mobile factors, biometric signals, and risk scoring for high-value or sensitive requests instead of relying on knowledge questions alone.
  • Instrument the live call for fraud signals Monitor for rapid credential changes, unusual urgency, repeated reset requests, and mismatches between call behavior and account history during the session.
  • Train agents on impersonation tactics and escalation Build recurring training for social engineering, spoofing, voice cloning, and deepfake indicators so agents know when to pause the workflow and escalate.
  • Align KPIs with verification quality Review performance targets that reward speed over assurance and remove incentives that encourage agents to skip required checks under queue pressure.
  • Protect sensitive account changes with stronger step-up controls Require additional verification before password resets, recovery updates, or high-risk account changes so a single successful impersonation cannot complete the takeover.

Key takeaways

  • Contact center fraud succeeds when verification is treated as a one-time checkpoint instead of a live identity decision.
  • The article links rising account takeover pressure to weak verification methods, AI impersonation, and agent workflow gaps.
  • The most effective response is layered identity proofing, session monitoring, and stronger controls around high-risk account changes.

Key terms

  • Contact Center Fraud: Fraud that targets customer service operations to trick agents, bypass verification, or gain unauthorized access to accounts and data. It blends social engineering with identity abuse, so the real failure is often in the trust checks and workflows that govern the interaction.
  • Account Takeover: Account takeover is unauthorized use of a legitimate account after an attacker obtains valid access through stolen credentials, tokens, or trusted integrations. The key security problem is that the resulting activity often looks normal to logs and controls, which makes containment and attribution harder than in a forced-entry breach.
  • Identity proofing: The process of verifying that a person is who they claim to be before granting or restoring access. In higher-risk recovery paths, proofing can include stronger evidence checks such as government ID validation or liveness-based facial verification so the assurance level matches the sensitivity of the request.
  • Deepfake-based impersonation: A fraud technique that uses synthetic audio, video, or both to make an attacker appear to be a trusted person during a live interaction. The tactic exploits human trust in familiar cues and often aims to trigger urgent actions such as payments, resets, or access changes before verification is challenged.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 23, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org