By NHI Mgmt Group Editorial TeamBased on SumSub: “Fraud Prevention: Best Practices for 2026” (June 8, 2026)

TL;DR: Fraud attacks rose 180% last year as organised networks, synthetic identities, and AI agents intensified pressure across onboarding, payments, payouts, and cash-out, according to SumSub. The real problem is that fraud now behaves like a connected lifecycle, so identity controls must track trust, risk, and escalation across the full user journey.


At a glance

What this is: This guide frames fraud as a connected lifecycle and argues that identity controls must track risk across onboarding, payments, payouts, and cash-out.

Why it matters: Identity, fraud, and IAM teams need to govern trust decisions across the full journey because isolated controls create blind spots that fraud networks exploit.


Context

Fraud prevention is no longer a single checkpoint problem. The article treats fraud as a lifecycle that stretches from trust-building and onboarding through payments, payouts, and cash-out, which is why controls that only look at one stage miss the attack path.

The identity connection is direct: fraud actors exploit how trust is established, how risk is escalated, and how responses are sequenced across the user journey. That makes this relevant to human identity governance, customer onboarding, and fraud operations rather than to a narrow detection-only model.


Key questions

Q: What breaks when fraud controls only cover onboarding and not the rest of the user journey?

A: Stage-limited controls let fraudsters pass a clean entry point and then shift abuse into payments, payouts, or cash-out where governance is weaker. The result is a false sense of safety at onboarding and a late, expensive response later in the lifecycle. Teams need controls that carry identity risk forward, not reset it after approval.

Q: Why do synthetic identities make traditional fraud controls less effective?

A: Synthetic identities reduce the value of controls that rely on spotting obviously fake profiles at signup. AI can create convincing identities quickly, so the stronger control is whether the downstream behaviour remains plausible, consistent, and bounded across sessions, devices, and payment activity.

Q: How should teams decide when to step up fraud controls?

A: Use observed risk change as the trigger, not just the presence of a new session or transaction. Step-up controls work best when they respond to anomalies in device continuity, behavioural sequence, or transaction context, because those changes often reveal that the same actor is progressing through a fraud chain.

Q: What should fraud teams do when AI-assisted fraud changes the speed of attacks?

A: Shorten decision loops, connect signals across channels, and predefine stage-based escalation so the team can respond before the attacker completes the next lifecycle step. Manual review remains useful, but only when it is reserved for cases that truly need human judgment and not for every anomaly.


Technical breakdown

Why lifecycle-based fraud outpaces point controls

Fraud lifecycle defence assumes that risk accumulates across multiple decisions, not just at account creation or transaction approval. When onboarding, payment, and payout controls are managed separately, attackers can shift between stages until one decision point is weaker than the rest. Synthetic identities and organised fraud networks thrive in that gap because each stage appears individually plausible. The technical problem is not only verification quality but state continuity: the system must carry trust, suspicion, and verification outcomes forward. Without that continuity, fraud teams end up detecting fragments rather than a coordinated campaign.

Practical implication: Map fraud controls to the full user journey, not to isolated checkpoints.

How synthetic identities change fraud decisioning

Synthetic identity fraud combines real and fabricated attributes to pass superficial checks and then build credibility over time. That makes static rules brittle, because the identity can look legitimate during onboarding while becoming risky only after behavioural accumulation or transaction history develops. In practice, the defender needs to correlate profile consistency, device signals, payment behaviour, and velocity patterns across sessions. This is where fraud prevention and identity governance overlap: if identity proofing, account risk, and payout access are not linked, the fraudster can progress from low-friction enrolment to high-value extraction.

Practical implication: Tie identity proofing outcomes to downstream risk controls and step-up decisions.

Why AI agents and organised networks complicate response

The article’s reference to AI agents points to faster, more adaptive fraud operations, but the central issue is orchestration rather than novelty. Organised fraud networks can combine humans, automation, and synthetic accounts to probe controls, adapt to friction, and route around blocking logic. That creates a moving target for response timelines: slow reviews give the network room to escalate, while heavy-handed friction can harm legitimate users. The technical challenge is to tune signals, thresholds, and escalation paths so that one weak signal at one stage does not determine the entire decision.

Practical implication: Design fraud response to adapt at runtime across onboarding, transaction, and payout signals.


Threat narrative

Attacker objective: The attacker aims to monetise a staged fraud campaign by moving from credible enrolment to payment abuse and cash-out.

  1. Entry occurs when fraud actors use trust-building, onboarding, or synthetic identities to get inside the customer lifecycle without triggering strong suspicion.
  2. Escalation follows as organised networks probe payment, payout, and cash-out controls, using the weakest stage to convert low-risk access into higher-value abuse.
  3. Impact is realised when fraudulent transactions, chargebacks, or payout theft scale across the lifecycle and damage revenue, operations, and reputation.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Fraud lifecycle defence is now an identity governance problem, not just a detection problem. The article’s core premise is that fraud travels across onboarding, payments, payouts, and cash-out as a connected sequence. That means the control plane has to preserve decision context across the full lifecycle, not only at the first verification step. Practitioners should treat fraud governance as a stateful identity problem, where the same subject can move from low-risk enrolment to high-risk monetisation.

Organised fraud networks succeed when organisations manage signals in silos. When trust decisions, transaction controls, and payout approvals are owned separately, attackers exploit handoff gaps between teams and tools. The named concept here is the lifecycle handoff gap: the interval where one team has accepted an identity and another has not yet inherited the risk posture. Fraud operations should align ownership so that one identity story follows the user end to end.

Synthetic identity fraud exposes the weakness of static trust assumptions. Fraud programmes often assume that a verified identity remains stable and reviewable in predictable stages. That assumption fails when a crafted identity can mature over time, accumulate benign-looking behaviour, and only become monetisable after trust has been built. Practitioners need to recognise that risk can emerge after approval, not before it.

AI-assisted fraud raises the tempo of escalation, which changes what counts as timely control. The article’s mention of AI agents is important because it signals faster probing, faster adaptation, and shorter windows for manual review to be effective. Identity teams should respond by tightening decision latency, improving cross-signal correlation, and defining stage-specific escalation triggers that do not rely on a single point-in-time check.

Fraud prevention and identity governance are converging around lifecycle accountability. The more an enterprise lets onboarding, payments, and payouts drift apart operationally, the more room fraud has to exploit policy inconsistencies. This pushes practitioners to define who owns the trust decision at each stage, what evidence must travel with the identity, and when a negative signal should persist into later stages.

From our research library:

What this signals

Lifecycle thinking changes fraud governance from a checkpoint model into a continuity model. The practical shift is that identity evidence must travel with the customer journey, including onboarding decisions, payment anomalies, and payout risk. When teams keep those signals separate, they create a governance seam that fraud networks can exploit.

Fraud lifecycle defence also changes how practitioners think about friction. The right question is not whether to add more friction everywhere, but where a signal is strong enough to justify escalation without breaking legitimate user flows. That is a programme design problem, not a rule-writing exercise.


For practitioners

  • Align fraud controls to the full lifecycle Map trust-building, onboarding, payment, payout, and cash-out to explicit control owners so each stage inherits prior risk decisions.
  • Correlate identity proofing with downstream risk Carry verification outcomes into transaction monitoring and payout approval so one clean onboarding event does not reset the risk posture.
  • Tune escalation for synthetic identity patterns Use device, velocity, and behaviour signals together so gradual fraud build-up is detected before cash-out.
  • Set stage-specific response thresholds Define when to step up, pause, or review based on the fraud stage rather than applying a single rule to the whole journey.

Key takeaways

  • Fraud is best understood as a staged lifecycle, which means controls at onboarding alone cannot protect the rest of the journey.
  • The article points to rising attack sophistication, including organised networks, synthetic identities, and AI-assisted tactics.
  • Effective defence depends on carrying trust and risk forward across the customer journey, with escalation tied to changing signals.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsFraud lifecycle controls depend on stage-aware authorisation decisions across onboarding and payout flows.
Recommendation — Apply PR.AA-05 to keep entitlement decisions aligned with lifecycle risk, not just initial verification.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementIdentity proofing and step-up decisions depend on managing authenticators across the fraud journey.
IA-8 — Identification and Authentication (Non-Organizational Users)The article is about customer identity and fraud across non-organisational users.
Recommendation — Use IA-5 to govern how authenticators and assurance state carry into later fraud decisions. Apply IA-8 to strengthen authentication and assurance for external users across the lifecycle.
CIS Controls v8CIS-5 — Account ManagementFraud lifecycle defence requires disciplined account state management and escalation handling.
Recommendation — Use CIS-5 to manage account transitions and remove stale access paths that fraud can exploit.
GDPRArt.32 — Security of processingCustomer identity and fraud controls must preserve the security of personal data used in decisions.
Recommendation — Align fraud monitoring and identity controls with Art.32 security of processing requirements.

Key terms

  • Fraud lifecycle: The fraud lifecycle is the sequence of stages an attacker or abusive user moves through, from identity or account creation to access, transaction activity, and investigation. Teams use the lifecycle to connect signals across functions instead of treating each alert as an isolated event.
  • Synthetic Identity: A synthetic identity is a software-based actor that can authenticate, request access, and execute actions without being a human user. In practice, this includes AI agents, bots, service accounts, tokens, and other machine identities that need clear ownership, scope, and revocation.
  • Step-up Control: A control that increases friction or verification when risk rises during a session or lifecycle stage. For fraud programmes, step-up works only when tied to combined signals such as device, behaviour, velocity, and destination changes, not to one isolated anomaly.
  • Identity proofing: The process of verifying that a person is who they claim to be before granting or restoring access. In higher-risk recovery paths, proofing can include stronger evidence checks such as government ID validation or liveness-based facial verification so the assurance level matches the sensitivity of the request.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org