TL;DR: Fraudsters can rotate email, IP, phone, and payment details in seconds, while 44% use developer tools to simulate device behavior and synthetic identity fraud rose 300% in the US in a single year, according to SumSub. Device intelligence matters because it helps fraud teams make earlier, more proportionate decisions without over-relying on signals that attackers can easily spoof.
At a glance
What this is: This is a guide to using device intelligence across the user lifecycle, with the central finding that device signals are harder for fraudsters to fake than email, IP, phone or payment details.
Why it matters: It matters because fraud teams need earlier, more proportionate decisions at signup, login, recovery and payout, and device intelligence can reduce over-reliance on easily spoofed signals.
By the numbers:
- In 2025, 44% of fraudsters used developer tools to simulate device behaviour.
- Synthetic identity fraud in the US rose 300% in a single year.
Context
Fraud teams increasingly face a control problem, not just a detection problem: identity attributes can be rotated quickly, but device behaviour tends to leave a more durable pattern. Device intelligence uses signals from the device environment to help distinguish legitimate users from automated or deceptive activity.
SumSub frames the issue across the full user lifecycle, from registration to refunds and investigations. The practical question is not whether device data exists, but how to combine it with identity, behavioural and payment signals so friction is applied only when the risk picture justifies it.
That makes device intelligence relevant to fraud operations that need to act earlier without blocking legitimate users. The article is best read as a decision framework for where device signals should influence approve, monitor, step up, review or block outcomes.
Key questions
Q: How should security teams use device intelligence in fraud prevention without overblocking users?
A: Use device intelligence as one input to risk-based decisions, not as a sole proof of identity. Correlate browser, network, proxy, and tampering signals with authentication context, then reserve blocking for combinations that show strong abuse patterns. That approach reduces false positives while still catching automation, infrastructure masking, and suspicious session behaviour.
Q: Why do device signals matter when fraudsters can rotate other identifiers quickly?
A: Device signals matter because email addresses, IPs, phone numbers, and payment details can change quickly, but device behaviour is harder to fake consistently across a full journey. That makes device intelligence a useful context signal for distinguishing a genuine user from a coordinated abuse pattern.
Q: What are the signs that device intelligence is failing in fraud decisioning?
A: Common signs include high false-positive rates, inconsistent outcomes across signup and login, and rules that trigger on isolated attributes without context. If fraudsters can change simple identifiers faster than controls adapt, the programme is relying on weak signals and not enough composite evidence.
Q: Should teams prioritise device intelligence over identity verification or payment checks?
A: No. Device intelligence works best as a complementary control because each signal answers a different question. Identity verification confirms who is likely behind the interaction, payment checks assess transaction risk, and device intelligence helps judge whether the environment itself is trustworthy.
Technical breakdown
Device intelligence versus device fingerprinting
Device fingerprinting and device intelligence are related but not identical. Fingerprinting usually focuses on collecting a set of device attributes to identify a browser or environment, while device intelligence interprets those attributes in context, looking for consistency, change and risk patterns over time. That distinction matters because isolated signals can be spoofed or reused, but the broader device story is harder to fake when combined with behavioural and identity evidence. For fraud operations, the value is not raw telemetry. It is the ability to interpret a device as part of a decision model rather than as a stand-alone identifier.
Practical implication: tune device analysis for contextual risk scoring, not simple device matching.
Why device signals survive where other fraud signals do not
Email addresses, IPs, phone numbers and even payment details can be rotated quickly by fraudsters, which makes them weak as sole decision inputs. Device data is different because it reflects software, configuration and interaction patterns that are more expensive to reproduce consistently at scale. The article notes that some fraudsters use developer tools to simulate device behaviour, which reinforces the point that attackers are already trying to close this gap. When signals are easily changed, they are useful only if the surrounding model can detect drift, replay, emulation or impossible combinations of attributes.
Practical implication: treat device signals as harder-to-spoof evidence, but validate them against other identity and payment signals.
Decisioning across signup, login, recovery and payout
The operational value of device intelligence changes by lifecycle stage. At signup, it can help suppress fake account creation and synthetic identity patterns. At login and recovery, it can surface account takeover risk or suspicious repeat access. At payout and investigation stages, it can help distinguish normal customer behaviour from coordinated abuse or mule-like activity. The important architectural point is that the same signal should not trigger the same action everywhere. Device intelligence works best when the decision logic is stage-aware and tied to the business risk of the moment.
Practical implication: align device rules to lifecycle stage so the same signal can approve, step up or block depending on context.
Threat narrative
Attacker objective: The attacker wants to get fraudulent activity accepted as legitimate long enough to open accounts, take over sessions, abuse payments or cash out.
- Entry begins when fraudsters rotate customer-facing identifiers such as email, IP address, phone number and payment details to create a fresh-looking session or account.
- Credential or device abuse follows when developer tools are used to simulate device behaviour and make the environment appear more legitimate than it is.
- Impact emerges when synthetic identities, fake accounts, account takeover, payment fraud or payout abuse pass through controls that relied on signals the attacker could easily change.
Breaches seen in the wild
- Firebase misconfiguration exposure 2024: Missing Firebase security rules on 916 websites exposed 125 million user records and 19.87 million plaintext passwords; a quarter were fixed.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Device intelligence is now a fraud governance problem, not just a detection feature. The article shows that fraudsters can rotate easy-to-change attributes faster than many rules can react, which means static decisioning loses value quickly. Device intelligence matters because it gives teams a more durable signal to use when the identity surface is intentionally fluid. The practitioner conclusion is that device data has to be governed as part of the fraud decision model, not treated as an optional telemetry feed.
Device intelligence works because it shifts the control point earlier in the lifecycle. Signup, recovery and payout all reward earlier discrimination, but only if the organisation can interpret the same signal differently by stage. That is a governance change as much as a technical one, because it forces teams to define where friction is acceptable and where it creates avoidable customer loss. The practitioner conclusion is that lifecycle-aware decisioning is the real operating model behind effective device intelligence.
Mixing device, identity, behavioural and payment signals is the only defensible way to reduce false positives. No single signal should carry the whole decision, especially when attackers can emulate one layer of evidence. The article points toward proportionate friction, which is the right objective for fraud operations that need both loss reduction and customer preservation. The practitioner conclusion is to design composite decision logic rather than let one weak signal dominate approval outcomes.
Fraud teams should read this through the lens of signal integrity and trust boundaries. The named concept here is device-signal resilience gap: the distance between what a team thinks a device signal proves and what a fraudster can still fake. The article shows that this gap narrows when device intelligence is contextual, but it never disappears. The practitioner conclusion is that teams should measure where device evidence is strong enough to change outcomes and where it only supports review.
From our research library:
- Nearly 60% of companies reported that fraud losses were still increasing in 2025.
What this signals
Device-signal resilience gap: fraud programmes increasingly need to measure the difference between a device signal that is observable and a device signal that is decision-grade. The article makes clear that fraudsters can rotate easier attributes quickly, so governance has to focus on where device evidence genuinely improves confidence.
For practitioners, the real shift is toward lifecycle-aware decisioning. A signal that supports allow at signup may only support review at payout, which means fraud policy, customer experience and case management now have to be designed together.
For practitioners
- Define stage-specific decision thresholds Map signup, login, recovery, payout and investigation to different approve, monitor, step up, review and block thresholds so device data is evaluated in context.
- Blend device data with identity and payment signals Use composite rules that combine device, behavioural and payment evidence so no single spoofable attribute drives the outcome on its own.
- Separate fingerprinting from decisioning Treat device fingerprinting as one input to an investigation model, not as a stand-alone proof of legitimacy or fraud.
- Tune friction to the fraud use case Apply stronger challenge steps for fake accounts and payout abuse than for lower-risk flows, where legitimate-user impact matters more.
- Test for emulation and rapid attribute change Look for repeated device patterns that appear alongside quickly changing email, IP, phone or payment details, especially where fraud tools may be simulating behaviour.
Key takeaways
- Device intelligence is valuable because it gives fraud teams a harder-to-spoof signal when other customer attributes are easy to rotate.
- The article ties device data to real fraud pressure, including 44% of fraudsters using developer tools and synthetic identity fraud rising 300% in the US.
- Teams get the most value when device signals are combined with identity, behavioural and payment data inside stage-aware decision rules.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP API Security Top 10 addresses the attack and risk surface, while NIST CSF 2.0, OWASP ASVS and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP API Security Top 10 | API2 — Broken Authentication | Fraud workflows rely on trust in sessions and account access, which attackers try to spoof. |
| Recommendation — Review authentication checkpoints so device intelligence feeds stronger decisions when session trust looks inconsistent. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Decisioning across the lifecycle depends on correctly authorising risky user actions. |
| Recommendation — Use PR.AA-05 to align device-based risk signals with step-up, review and block decisions. | ||
| OWASP ASVS | V8 — Authorization | The article is about deciding when to permit, challenge or block user actions. |
| Recommendation — Apply V8 to ensure fraud controls make authorization decisions from multiple corroborating signals. | ||
| CIS Controls v8 | CIS-5 — Account Management | Lifecycle decisions across signup, recovery and payout map to account governance. |
| Recommendation — Use CIS-5 to govern risky account lifecycle events and tie device risk to account actions. | ||
Key terms
- Device Intelligence: Device intelligence is the practice of interpreting signals from a device to assess whether a session or transaction is likely legitimate. It goes beyond fingerprinting by combining device context with behavioural, identity, and payment evidence to support a risk decision.
- Device fingerprint: A bundle of client signals used to recognise the same browser, app, or device across sessions. It often includes user agent, platform traits, and other stable characteristics. For impossible travel, fingerprinting helps separate a real attacker on a different device from a user switching networks.
- Synthetic Identity Document Fraud: Synthetic identity document fraud is the use of fabricated or AI-generated identity documents to impersonate a real or invented person. It targets verification workflows by presenting fake passports, driver’s licences, or IDs that can look credible enough to pass basic checks unless teams use stronger authenticity and anomaly detection controls.
- Proportionate Friction: Proportionate friction is the practice of adding more verification or challenge only when the risk justifies it. In fraud operations, it is the balance between stopping abuse and preserving legitimate conversion, recovery and payment completion, which requires stage-aware decisioning rather than blanket blocking.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org