TL;DR: Fraud is shifting from convincing people to manipulating systems, with attackers using camera injection, emulator farms, AI-driven tactics, and reverse-engineered onboarding flows to evade layered defences, according to SumSub. Traditional controls are increasingly brittle when the adversary studies workflows, not just users.
At a glance
What this is: This is a SumSub analysis of how fraud now targets verification workflows and control logic rather than only people, using automation and system manipulation to bypass defences.
Why it matters: It matters to IAM practitioners because onboarding, identity proofing, and risk controls can fail when fraud is engineered to exploit process seams, not just impersonation cues.
Context
Fraud here means the deliberate manipulation of identity and verification systems so that malicious activity is accepted as legitimate. The article argues that the target has shifted from persuading a human reviewer to feeding a system the inputs it is designed to trust, which puts onboarding and risk decisioning at the centre of the problem.
That shift matters for human IAM because proofing, enrolment, and step-up controls are only as strong as the workflows they depend on. When attackers reverse engineer those workflows, controls that look layered on paper can become predictable paths through the identity journey.
Key questions
Q: How should teams handle onboarding flows that attackers can reverse engineer?
A: Treat the flow as a security control, not just a product journey. Map every branch, exception, and fallback so you can see where an attacker can steer the process toward a weaker decision. Then test whether each control still adds value when the attacker already knows the sequence.
Q: Why do layered fraud defences fail against machine-speed attacks?
A: Layered defences fail when the layers are predictable, correlated, or tuned too slowly for the attacker’s iteration rate. If an adversary can learn the logic behind liveness, device, and behaviour checks, each layer stops being independent and becomes another signal to evade.
Q: What are the first signs that fraud controls are too easy to manipulate?
A: Look for recovery requests, payment approvals, or exception decisions that are approved quickly, bypass normal review, or rely on a single person’s judgment. Repeated urgency, unusual familiarity, and a pattern of policy overrides are all indicators that the workflow is exposing the organisation to social engineering rather than absorbing it.
Q: Should identity teams treat fraud detection and IAM governance as separate programmes?
A: No. Fraud detection and IAM governance increasingly depend on the same onboarding, proofing, and trust decisions, so gaps in one programme can be exploited through the other. Shared signals, shared exception handling, and shared ownership reduce the chance that attackers can move through the identity journey unnoticed.
Technical breakdown
Camera injection and emulator farms in identity proofing
Camera injection attacks feed synthetic or replayed video into liveness and selfie checks, while emulator farms provide scale by simulating many devices and sessions. Both techniques are aimed at the control plane of identity proofing, not at a single account. The attacker is testing how the system scores authenticity, device behaviour, and session continuity, then adapting input until the workflow accepts it. This is why fraud operations increasingly resemble QA against the defender’s own onboarding pipeline.
Practical implication: review where proofing decisions depend on device trust and liveness signals that can be replayed or simulated.
Reverse-engineered onboarding flows and workflow abuse
Reverse engineering an onboarding flow means mapping the sequence of checks, thresholds, and fallback paths that a product uses to decide whether a user can proceed. Once that logic is understood, attackers can tune submissions to avoid triggers, delay detection, or route through weaker exceptions. This is a governance problem as much as a detection problem, because the workflow itself becomes the attack surface. Layered defences fail when their order and decision points are predictable.
Practical implication: treat onboarding logic as security-sensitive design, not just product UX, and test for bypass paths introduced by exception handling.
AI-driven fraud and machine-speed adaptation
AI-driven fraud increases the rate at which adversaries can test combinations of documents, device traits, prompts, and behavioural signals. The real change is not intelligence in the abstract, but iteration speed: attacks can be varied, replayed, and scaled faster than manual review or periodic rule tuning can absorb. That creates a gap between human-paced controls and machine-paced abuse. For IAM teams, the question is no longer whether a control works in isolation, but whether it can keep up with adversarial learning in real time.
Practical implication: move from static rule sets to continuous feedback loops that can retrain or retune controls as attack patterns change.
Threat narrative
Attacker objective: The attacker’s objective is to obtain trusted access to systems and transactions by making fraudulent identities and sessions pass identity controls at scale.
- Entry begins when attackers submit synthetic identity signals through camera injection, emulator farms, or other automated inputs designed to satisfy verification checks.
- Credential or trust access is gained when onboarding logic accepts the manipulated workflow and treats the session or identity proof as legitimate.
- Escalation follows as reverse-engineered paths and AI-driven variation are used to scale successful attempts across accounts, regions, or product flows.
- Impact is fraud at machine speed, where criminal operations exploit trusted identity systems for repeated abuse before layered defences can react.
Breaches seen in the wild
- tj-actions/changed-files compromise 2025: A stolen bot token let attackers poison tj-actions/changed-files so pipelines printed their CI/CD secrets to public logs (CVE-2025-30066).
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Fraud now behaves like a control-plane attack, not a persuasion attack. The article shows adversaries targeting onboarding, liveness, and workflow logic rather than human judgement alone. That changes the unit of governance from user screening to decision path integrity. Practitioners need to think in terms of how identity controls are consumed, not just how they are configured.
Reverse-engineered onboarding flow is the right concept for this threat. Once an attacker understands thresholds, fallbacks, and exception handling, the workflow itself becomes the bypass route. This is not a one-off bypass but a repeatable method for turning process knowledge into fraud yield. Identity teams should treat onboarding logic as a security-sensitive asset, not only a conversion funnel.
Machine-speed fraud exposes a cadence mismatch in human IAM controls. Traditional review, tuning, and manual investigation cycles were designed for fraud that changed more slowly. AI-assisted and automated abuse compresses attacker iteration into the gap between control updates. The implication is that detection must become continuous and feedback-driven, or the control stack will always be chasing last week’s attack pattern.
Layered defences only work when the layers are non-predictable and independently meaningful. If camera checks, device checks, and behavioural signals all feed from the same weak assumptions, an attacker can learn the whole stack at once. This article reinforces a broader identity security principle: layered controls are not resilient by default, they are resilient only when each layer adds distinct resistance to manipulation. Practitioners should measure whether their layers actually change attacker cost.
System manipulation fraud belongs in the same governance conversation as NHI and agentic abuse. The common thread is not the actor type, but the exploitation of machine-paced decisioning against controls built for slower, more observable abuse. As identity programmes converge, teams should evaluate how onboarding, fraud, and access governance share signals and failure modes. The practitioner takeaway is to stop treating fraud tooling as separate from identity architecture.
From our research library:
- U.S. fraud losses are projected to reach $40 billion by 2027.
What this signals
Workflow trust is becoming the new attack surface. Identity programmes that focus only on credential theft miss the more structural risk: attackers are learning how the verification engine itself makes decisions. That means resilience depends on whether the system can resist being fed the right-looking inputs, not just whether a user can be impersonated.
Fraud controls and identity controls are converging. Onboarding, proofing, and step-up logic now influence both account creation and abuse prevention, which means false separation between fraud operations and IAM governance creates blind spots. Practitioners should evaluate controls as one identity decision chain rather than as isolated checkpoints.
For practitioners
- Harden onboarding decision paths Map each verification step, fallback, and exception path to identify where manipulated inputs can be accepted as legitimate.
- Test for camera and emulator abuse Add abuse cases for camera injection, virtualised device environments, and repeated-session automation to your fraud testing.
- Separate signal dependencies Avoid letting liveness, device, and behavioural checks fail together on the same hidden assumption, because correlated signals are easier to game.
- Shorten detection feedback loops Review how quickly fraud patterns move from detection to rule updates, model retraining, or analyst escalation.
Key takeaways
- Fraud is increasingly aimed at the systems that verify identity, which makes workflow integrity as important as user authenticity.
- The article points to camera injection, emulator farms, AI-driven variation, and reverse-engineered onboarding as the core abuse patterns.
- Identity teams need faster detection feedback and stronger control-path testing if they want layered defences to hold up against adaptive fraud.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP API Security Top 10 addresses the attack surface, NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the technical controls, and SOC 2 (AICPA) defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP API Security Top 10 | API6 — Unrestricted Access to Sensitive Business Flows | Fraud manipulates onboarding and verification flows to reach trusted outcomes. |
| Recommendation — Map onboarding and proofing journeys to API6 and remove exploitable fallback paths. | ||
| NIST SP 800-63 | SP 800-63B — Authentication | The article centres on identity proofing and authentication signals being gamed. |
| Recommendation — Align proofing and authentication checks to SP 800-63B and test them against replay and automation abuse. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Fraud seeks trusted authorization outcomes by manipulating identity decisioning. |
| Recommendation — Review authorization decision points under PR.AA-05 for fraud-induced trust failures. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account creation and lifecycle abuse are central to the fraud patterns discussed. |
| Recommendation — Use CIS-5 to tighten account provisioning and remove weak exception handling. | ||
| SOC 2 (AICPA) | CC6.1 — Logical Access Security Software Infrastructure | The article concerns trust in logical access and onboarding controls in a service environment. |
| Recommendation — Assess logical access and onboarding controls against CC6.1 for fraud-resilience gaps. | ||
Key terms
- Identity proofing: The process of verifying that a person is who they claim to be before granting or restoring access. In higher-risk recovery paths, proofing can include stronger evidence checks such as government ID validation or liveness-based facial verification so the assurance level matches the sensitivity of the request.
- Active Liveness Check: An active liveness check requires the user to complete a prompt during verification, such as blinking, smiling, or turning the head. The system uses the response to confirm presence and detect replay or spoofing attempts. It is stronger against fraud, but it adds friction and depends on user participation.
- Workflow Manipulation: Workflow manipulation is the abuse of business logic, exception paths, or decision sequences to produce a trusted outcome. In identity systems, it turns process knowledge into an attack method and can defeat layered controls that are individually sound but collectively predictable.
- Fraud signal: A fraud signal is any observable clue that suggests suspicious behaviour, such as failed verification, unusual access, transaction anomalies, or mismatched identity attributes. Good programmes do not rely on one signal alone. They correlate multiple signals before escalating a case.
Deepen your knowledge
NHI governance, identity lifecycle, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org