TL;DR: Payment fraud bypass rose to 2.8%, account takeover attempts fell to 0.88%, and chargebacks increased 19% to 0.31%, indicating attackers are targeting fewer, higher-value accounts while losses increase, according to Sift’s Q2 2026 benchmarking. The practical lesson is that block rate alone is no longer a reliable success metric; teams need cost-per-attack and dispute-lag visibility.
At a glance
What this is: Q2 2026 fraud benchmarks show lower attack volume but higher downstream loss, with chargebacks climbing even as account takeover attempts decline.
Why it matters: Fraud, IAM, and identity verification teams need to recalibrate detection, authentication, and review thresholds because selective attacks on trusted accounts can bypass controls built for noisy, high-volume abuse.
By the numbers:
- Payment fraud bypass rate held steady at 2.8% in Q2 2026, essentially flat quarter over quarter and down 14% year over year from Q2 2025.
- Manual review rate declined 13.5% to 2.1% from 2.4% in Q1.
- Account takeover attempts declined to 0.88% in Q2 from 0.95% in Q1, a 7% quarterly improvement.
- Fraudulent chargebacks climbed 75.6% to 0.18% in Q2 from 0.10% in Q1, up 80% year over year.
👉 Read Sift's Q2 2026 fraud benchmarking analysis on chargebacks and ATO
Context
Fraud programmes often optimise for block rates and review throughput, but those measures can miss the real loss pattern when attackers shift to trusted, higher-value accounts. In this case, the primary issue is not more fraud traffic, but more effective fraud that blends into normal behaviour and settles before the dispute appears. That is why identity verification and account protection need to be evaluated together, not as separate control planes.
The article’s Q2 2026 data points to a classic governance gap in digital identity and fraud operations: teams may see fewer alerts while the cost of each successful compromise rises. In identity programmes, that usually means authentication, behavioural signals, and step-up logic are lagging the attacker’s targeting strategy. This is typical of mature fraud adaptation, not an isolated anomaly.
Key questions
Q: How should fraud teams respond when attack volume falls but chargebacks rise?
A: They should stop treating block rate as the primary success metric and start measuring cost per successful attack, dispute lag, and account-value concentration. Lower volume can mask more efficient abuse, especially when attackers target trusted accounts that look legitimate at transaction time. The right response is to re-tune risk scoring around downstream loss, not just front-end rejection.
Q: Why do trusted accounts create more fraud loss than obvious new attacks?
A: Trusted accounts already carry behavioural history, payment permissions, and user confidence, so malicious actions blend in more easily. That makes them better vehicles for monetisation than noisy attack attempts. The result is higher downstream loss even when overall fraud volume appears to be falling.
Q: What do security teams get wrong about manual review efficiency?
A: They often assume a lower manual review rate means better fraud prevention. In practice, it can also mean more ambiguous transactions are being approved because the review queue is thinner or the thresholds were relaxed. Teams need to compare review efficiency against later chargeback outcomes to know whether automation is genuinely reducing risk or just deferring it.
Q: Which accountability model should organisations use when identity compromise drives fraud losses?
A: Accountability should be shared across fraud, IAM, and customer risk teams because the loss originates in identity trust but surfaces in payment and finance. If each team owns only its own metric, the compromise path falls between functions. A shared control model, with one view of authentication, session risk, and dispute outcomes, is the only practical answer.
Technical breakdown
Why trusted-account fraud bypasses standard detection
Fraud on established accounts is harder to catch because the transaction inherits trust from prior behaviour. If the customer, device pattern, payment method, and account age all look normal, rules tuned to spot novelty or velocity may not trigger. That makes selective fraud more effective than card testing or bulk abuse, especially in environments with stored credentials and recurring billing. The control problem is not simply detection sensitivity. It is the inability of static signals to distinguish legitimate continuity from attacker mimicry when the account itself has already been compromised.
Practical implication: teams need risk models that weight trust decay, not just transaction anomalies.
How chargeback lag distorts fraud performance metrics
Chargebacks are a delayed signal. The transaction may complete successfully, the account holder may notice days or weeks later, and only then does the loss surface in reporting. That delay makes short-term fraud dashboards look healthier than the actual risk posture. If manual review volume falls at the same time, teams can end up approving more ambiguous transactions simply because the feedback loop is too slow. In other words, operational efficiency can look like improved defence while actually deferring losses into the dispute window.
Practical implication: measurement needs both real-time block rates and later-stage dispute outcomes.
Why account takeover and payment fraud now need the same control logic
Account takeover is not just an identity problem and payment fraud is not just a transaction problem when attackers use the first to enable the second. Once a trusted account is compromised, the attacker can reuse stored payment methods, purchase history, and behavioural consistency to reduce friction. That means identity assurance, session protection, and payment risk scoring should share signals and thresholds. Fragmented controls create blind spots where one team thinks the account is normal and another sees only a clean transaction.
Practical implication: integrate identity, session, and payment telemetry into one fraud decisioning workflow.
Threat narrative
Attacker objective: The attacker’s objective is to monetise trusted accounts with minimal detection by converting normal-looking sessions into approved transactions.
- Entry occurs through compromise of a trusted account rather than broad-volume card testing, which lets the attacker operate inside normal behavioural patterns.
- Escalation happens when the attacker reuses stored payment methods and historical trust to make transactions appear routine to automated checks.
- Impact appears later as fraudulent chargebacks and customer churn, after settlement has already completed and the loss is harder to reverse.
NHI Mgmt Group analysis
Selective fraud is now a governance problem, not just a detection problem. When attackers focus on high-value accounts, the issue becomes how trust is granted and maintained across the account lifecycle. Fraud teams that only measure block rates miss the downstream loss pattern, especially where disputes surface after settlement. That makes identity assurance, authentication strength, and behavioural context part of the same governance conversation.
Fraud controls tuned for volume are becoming structurally misaligned with attacker behaviour. The article’s data shows fewer attempts but higher chargeback cost, which is exactly what happens when adversaries optimise for conversion instead of scale. That shift exposes a named gap we can call trust compression risk: a small number of highly trusted sessions generate disproportionate loss when safeguards assume all low-volume traffic is low-risk. Practitioners should treat trust compression as a control design issue.
Identity verification and IAM must be connected to fraud decisioning in high-value environments. In payment and subscription models, the difference between a normal transaction and an attacker’s transaction often sits in the identity layer, not the payment layer. Behavioural signals, step-up authentication, and account history need to feed the same decision logic. The practitioner takeaway is straightforward: if identity telemetry does not influence fraud scoring, the control stack is blind to the attack path.
Rising disputes are a lifecycle signal, not just a finance metric. Chargeback growth often means the organisation learned about compromise too late to prevent settlement. That turns customer trust, identity assurance, and dispute handling into one continuous risk chain. Teams should interpret the rising dispute curve as evidence that their current account protections are failing to contain compromise before monetisation.
What this signals
Trust compression risk: when attackers concentrate on a small number of high-value accounts, identity and fraud teams need to measure how much loss can be generated from one trusted session, not just how many attempts were blocked. That shift pushes programmes toward tighter identity signals, faster dispute feedback, and stronger lifecycle controls on high-value accounts. For teams handling credentials and account access, the operational question is whether trust is being renewed too easily. For broader context on leaked secrets and exposure windows, compare this pattern with The State of Secrets in AppSec.
Fraud, IAM, and identity verification will increasingly converge around the same risk signal set because the attacker path is becoming more selective and less noisy. Programmes that keep transaction review separate from identity assurance will miss the point where compromise turns into monetised abuse. The governance signal is clear: a clean approval is not proof of a safe identity. Teams should align fraud telemetry with account lifecycle and authentication events before the next wave of selective attacks.
For practitioners
- Reweight fraud scoring toward trusted-account compromise Tune decisioning to penalise improbable activity on established accounts even when device, payment method, and customer history look normal. Use trust decay signals, session anomalies, and behavioural drift together rather than treating each in isolation.
- Link identity assurance to payment controls Feed authentication strength, step-up events, and recent credential changes into payment risk decisions so a clean transaction cannot override a compromised identity context.
- Track chargebacks as a delayed control signal Build a reporting view that compares real-time block rates with later dispute outcomes by cohort, vertical, and account age so you can see where fast approvals are hiding losses.
- Prioritise high-value verticals for tighter review thresholds Focus subscription, gaming, and other high-yield segments on stricter review logic because selective attackers are concentrating where one compromise produces repeated monetisation.
Key takeaways
- Fraud losses can rise even when attack volume falls, because attackers are shifting toward trusted, high-value accounts that blend into normal behaviour.
- Chargeback growth is a delayed control signal, which means block rates and manual review efficiency can look healthy while monetised abuse is already accumulating.
- The right defence is shared identity and fraud decisioning, with trust decay, authentication strength, and dispute outcomes feeding one control model.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63 and NIST CSF 2.0 set the technical controls, while GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B | The article hinges on authentication strength and account trust, both central to digital identity assurance. |
| NIST CSF 2.0 | PR.AA-1 | Account authentication and identity proofing are directly implicated in selective fraud patterns. |
| GDPR | Art.32 | Where identity data and account behaviour are processed, security of personal data becomes relevant. |
Ensure account-risk data and identity signals are protected with security measures proportionate to processing risk.
Key terms
- Account Takeover: Account takeover is unauthorized use of a legitimate account after an attacker obtains valid access through stolen credentials, tokens, or trusted integrations. The key security problem is that the resulting activity often looks normal to logs and controls, which makes containment and attribution harder than in a forced-entry breach.
- Chargeback Lag: Chargeback lag is the delay between a fraudulent transaction and the moment the dispute is recorded. That delay matters because it weakens real-time feedback loops, makes dashboards look healthier than they are, and allows attackers to keep exploiting the same weaknesses before the organisation understands the true loss pattern.
- Trust Decay: The idea that trust becomes less reliable over time unless systems keep re-checking the conditions behind it. In identity governance, this explains why static login decisions age badly and why continuous verification matters across human, NHI, and autonomous access models.
What's in the full report
Sift's full article covers the operational detail this post intentionally leaves for the source:
- Vertical-by-vertical benchmark data showing where fraud pressure is concentrating across Internet and Software, Online Gambling, Digital Commerce, and Finance.
- Breakdowns of payment fraud, account takeover, manual review, and chargeback trends that support internal benchmarking and board reporting.
- The article's interpretation of how better automation can still coincide with rising disputes when thresholds are tuned to the wrong signal mix.
- Context on how 2FA adoption and stored credential behaviour influence fraud outcomes in different business models.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle, and secrets management. It helps security and identity practitioners align access controls with the risks that arise when trust, credentials, and automation interact.
Published by the NHIMG editorial team on July 22, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org