By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: DescopePublished August 18, 2026

TL;DR: Credential theft appears in 39% of breaches and accounts for 52% of data compromised in basic web attacks, according to Verizon's 2026 DBIR, which is why Descope argues that fraud detection must move to authentication rather than waiting for transaction-time review. The governance issue is not just fraud volume, but whether identity teams can make login an enforceable risk decision instead of a pass-or-fail checkpoint.


At a glance

What this is: This article argues that fraud detection should happen at login, using layered identity signals to stop account takeover, bot abuse, and risky authentication attempts before they become downstream fraud.

Why it matters: It matters because identity, fraud, and security teams need a shared control point at authentication, where credential abuse, device risk, and behavioural anomalies can be assessed before access is granted.

By the numbers:

👉 Read Descope's analysis of fraud detection in authentication and login risk


Context

Fraud detection at login is the practice of evaluating risk at the moment of authentication instead of waiting until after an account is abused or a transaction is completed. For IAM teams, the important shift is that the login event becomes an active control point, not just an access gate.

The article reflects a broader identity governance problem: credential abuse, bot activity, device anomalies, and third-party fraud signals now converge at the authentication layer. That makes login a shared concern for identity, fraud, and security programmes rather than a narrow product feature.


Key questions

Q: How should security teams reduce login friction without weakening identity security?

A: Security teams should replace high-friction, low-assurance controls with phishing-resistant authentication and context-aware access policies. The goal is to make the secure path easier than the workaround. That means strong enrollment, reliable recovery, and step-up checks only when risk signals such as device health or location warrant them.

Q: Why do traditional IAM controls miss modern account takeover?

A: Traditional IAM often assumes the decisive security event is authentication at the IdP. In practice, attackers may steal credentials, hijack sessions, or abuse OAuth flows after the initial login. If the browser is where access is actually established and reused, controls that stop at configuration data will miss the real attack path.

Q: What breaks when organisations rely on a single fraud signal at login?

A: A single signal creates blind spots. Behavioural checks miss legitimate travel, device fingerprinting misses clean but compromised devices, and bot detection misses human-led abuse. Without multiple signals feeding one policy, attackers only need to evade the weakest layer. Real resilience comes from combining signals and enforcing a consistent decision.

Q: Who should own fraud-related identity risk decisions?

A: Ownership should be shared across IAM, fraud, compliance, and operations, with clear escalation rules. No single team sees the full picture, because identity assurance failures and abuse patterns emerge across onboarding, access, and transaction workflows. Joint ownership reduces blind spots and avoids delayed containment.


Technical breakdown

Why login fraud needs layered identity signals

Login fraud is rarely visible through a single signal. Behavioural anomalies, breached credentials, device fingerprinting, bot indicators, and third-party risk feeds each catch a different part of the attack surface. Behaviour alone can indicate travel or VPN use, while a breached password may be harmless until combined with a new device or a high-risk IP. A layered design matters because authentication risk is contextual, not binary, and because attackers adapt quickly when one signal becomes noisy or easy to evade.

Practical implication: treat login as a decision engine that combines multiple signals before access is granted.

How phishing-resistant authentication changes fraud outcomes

Phishing-resistant authentication methods remove the reusable secret that most login fraud depends on. Passkeys and similar methods use cryptographic proof tied to the originating site, so they cannot be replayed on a fake login page the way passwords or SMS codes can. That does not eliminate every fraud path, but it removes the most common credential theft and phishing pattern at the authentication boundary. In practice, that changes the control objective from defending stolen secrets to defending device and session trust.

Practical implication: use phishing-resistant methods as the default path, then add step-up controls for risky actions.

Why third-party fraud signals matter in identity journeys

Identity platforms rarely see the whole fraud picture on their own. External providers can surface signals such as bot behaviour, synthetic identities, risky IPs, and known abuse patterns that are invisible in native authentication telemetry. The architectural point is that these signals should feed the same decision logic as internal identity checks, rather than living in a separate fraud stack with no influence on login policy. That creates a single governance layer for risk-based access decisions.

Practical implication: connect external fraud intelligence to the same authentication workflow that makes the access decision.


Threat narrative

Attacker objective: The attacker aims to gain trusted access at login so they can use the account for takeover, fraud, or further abuse.

  1. Entry begins at the authentication layer, where attackers use stolen credentials, bot-driven signup activity, or risky login patterns to target the account before any transaction occurs.
  2. Escalation happens when the attempt bypasses weak or single-factor checks, allowing the attacker to obtain a live session or reach sensitive post-login actions.
  3. Impact follows when the compromised session is used for account takeover, fraudulent transfers, fake account creation, or other downstream abuse.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Authentication is now a fraud control, not just an access control. Once attackers can reliably enter through exposed credentials, the login step becomes the earliest enforceable boundary for identity teams. That shifts ownership across IAM, fraud, and security operations, because post-login detection is already late. The implication is that programmes still treating authentication as a static gate are leaving the most actionable control point underused.

Credential reuse is the governance fault line that makes login fraud scalable. Public breach data and credential stuffing economics mean attackers do not need to break passwords in the traditional sense. They only need one exposed secret to work across multiple services, which turns weak credential hygiene into repeated account takeover risk. That means identity governance has to account for credential provenance, not just credential validity.

Login decisions need signal orchestration, not signal accumulation. The problem is not whether teams have behavioural data, device intelligence, or bot detection. The issue is whether those signals are combined into policy that can block, challenge, or step up access in real time. Without orchestration, organisations get telemetry without enforcement, which is a reporting problem rather than a control.

Fraud and identity teams should stop separating authentication risk from downstream abuse. A login that looks legitimate but originates from exposed credentials, a new device, or a bot cluster is already a governance event. The same risk logic that protects checkout, transfer, or account recovery should begin before access is established. Practitioners should treat login policy as the front line of fraud containment, not an afterthought.

From our research:

  • 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
  • 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to Ultimate Guide to NHIs.
  • For a wider governance baseline, Top 10 NHI Issues helps teams prioritise where identity risk becomes operational exposure.

What this signals

Credential abuse is no longer a downstream incident response problem. Once login becomes the first exploitable control point, security teams need authentication policies that can act on context in real time. That means building a governance model where identity signals, fraud feeds, and step-up rules operate as one policy surface, not separate tools.

Identity teams should expect login telemetry to become a board-level signal. The practical question is no longer whether fraud can be detected, but whether the organisation can prove it intervened before access was granted. For teams maturing their IAM programme, that makes auditability at the login boundary as important as the detection content itself.


For practitioners

  • Orchestrate login risk as a policy decision Combine behavioural, credential, device, and third-party fraud signals in one authentication flow so that each attempt can be allowed, challenged, or blocked consistently.
  • Default to phishing-resistant login methods Use passkeys or other phishing-resistant methods for routine authentication, then reserve step-up authentication for higher-risk devices, locations, or actions.
  • Separate login fraud from transaction fraud workflows Give identity teams and fraud teams a shared view of login risk, but keep the decision boundary at authentication so compromise is interrupted before payment or account abuse.
  • Tune bot detection to the login journey Use hidden field traps, risk scoring, and connector-based intelligence to identify automated login attempts before they reach password validation or account creation.

Key takeaways

  • Login fraud is best treated as an identity governance problem because the attack begins before a transaction ever occurs.
  • Layered identity signals outperform any single fraud check because attackers exploit gaps between behaviour, device, credentials, and bot controls.
  • Phishing-resistant authentication and real-time policy orchestration are now the most practical ways to reduce account takeover at scale.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-7Risk-based authentication and session trust fit the article's login decision model.
NIST SP 800-63SP 800-63BThe article centres on authentication strength and phishing-resistant login methods.
NIST Zero Trust (SP 800-207)Risk-based access decisions at login align with continuous verification concepts.
NIST SP 800-53 Rev 5IA-2Authentication control selection is central to the login fraud problem.

Apply zero trust principles by evaluating trust at each authentication attempt, not only at sign-in.


Key terms

  • Fraud Detection: Fraud detection is the process of identifying suspicious or deceptive activity before it causes loss. In identity-heavy environments, it relies on behavioural signals, transaction context, and assurance quality to decide whether an action is legitimate or likely to be manipulated.
  • Credential Stuffing: Credential stuffing is an attack that uses stolen username and password pairs from previous breaches to try logging into other services. It works because many people reuse credentials, and because the login attempt uses valid information, it can look ordinary until the surrounding behavior gives it away.
  • Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
  • Device fingerprint: A bundle of client signals used to recognise the same browser, app, or device across sessions. It often includes user agent, platform traits, and other stable characteristics. For impossible travel, fingerprinting helps separate a real attacker on a different device from a user switching networks.

What's in the full article

Descope's full article covers the operational detail this post intentionally leaves for the source:

  • Connector-level examples for breached-credential checks, device intelligence, and third-party fraud feeds in login flows
  • Step-by-step examples of how conditional logic changes authentication outcomes for risky versus low-risk users
  • Detailed guidance on when to challenge, block, or let users through based on multiple identity signals
  • Practical examples of phishing-resistant login methods used alongside fraud detection in real journeys

👉 The full Descope article shows how identity signals, bot checks, and step-up logic combine in practice.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org