TL;DR: Identity fraud grew 180% year over year and multi-step attacks rose from 10% to 28% of all cases, according to Sumsub's Identity Fraud Report 2025-2026, showing that one-time verification is no longer enough across the customer lifecycle. Continuous, real-time identity controls now matter more than static checks when AI-powered fraud adapts mid-flow.
At a glance
What this is: This is Sumsub’s analysis of how identity fraud is becoming multi-step and AI-driven, with attacks now stretching across the customer lifecycle rather than stopping at onboarding.
Why it matters: IAM and fraud teams need controls that keep verifying identity after initial proofing, because static checks no longer hold up against adaptive, lifecycle-spanning attack flows.
Context
Identity fraud is no longer a single-point verification problem. When attackers can adapt in stages across onboarding, authentication, and account use, the control failure is not just weak proofing but a governance model that treats identity as settled after the first check.
Sumsub links this shift to AI-enabled fraud patterns that move faster than traditional review cycles. For identity programmes, that means the relevant question is not whether initial verification passed, but whether trust can be continuously re-established as behaviour changes during the session and over time.
Key questions
Q: Why do one-time identity checks fail against multi-step AI fraud?
A: One-time checks only validate identity at a single moment, while AI-driven fraud can change documents, device signals, and behaviour across later steps. That lets an attacker pass the gate and then evolve the attack after trust has already been granted. Continuous monitoring is needed because the fraud often appears after onboarding, not during it.
Q: How should security teams reduce identity fraud without blocking legitimate users?
A: Use layered decisioning instead of single-step checks. Combine document verification, behavioural signals, device intelligence, and recovery risk scoring so trust is assessed across the full journey. The goal is not to stop every suspicious event at the first gate, but to make fraud expensive enough that repeated abuse no longer scales.
Q: What signals show that identity security controls are not keeping up?
A: Look for broad roles granted for convenience, orphaned accounts after turnover, shared credentials in business workflows and repeated entitlement changes in critical systems without timely review. Those patterns show that access governance is lagging behind operational reality.
Q: How do continuous identity controls differ from static verification?
A: Static verification answers whether a user looked legitimate at one point in time. Continuous controls answer whether the identity still looks legitimate as context changes across sessions, devices, and transactions. That difference matters because AI-assisted fraud often succeeds by shifting after the first check, not by failing it.
Technical breakdown
Why multi-step identity fraud breaks static verification
Multi-step identity fraud chains together several actions, often beginning with synthetic or manipulated identity signals and ending in account abuse, transaction fraud, or mule activity. The problem is not only the initial fake document or deepfake. It is that each stage can look individually plausible while the overall sequence is fraudulent. Static checks capture a point in time, but AI-assisted attackers can alter inputs, timing, and artefacts between stages. That makes the real control issue sequence awareness: the ability to correlate risk across events instead of validating only the first touchpoint.
Practical implication: move verification logic from a single gate to lifecycle-wide event correlation.
How AI-powered fraud agents change the attack model
An AI fraud agent is a software system that can coordinate actions across a fraud chain with limited human direction. In practice, that means faster variation in documents, device signals, behavioural cues, and follow-on steps such as mule setup or account takeover. The governance challenge is not just volume, but adaptation. When the attack adjusts mid-flow, rules based on fixed patterns degrade quickly. Identity security teams therefore need to treat the fraud path as a dynamic sequence of identity assertions, each one needing re-evaluation against context, history, and anomaly signals.
Practical implication: tune detection to behavioural drift, not just known fraud signatures.
Why customer lifecycle monitoring matters more than onboarding checks
Identity trust has to survive after onboarding because fraud often emerges after the first successful verification. That includes authentication abuse, payment abuse, and account orchestration by networks rather than isolated users. Lifecycle monitoring links proofing, access, and usage into one control plane, which is why one-time identity checks are increasingly insufficient. The most resilient programmes watch for consistency between claimed identity, device context, and subsequent behaviour. Without that continuity, fraud teams are left reacting to damage after an account has already been accepted as legitimate.
Practical implication: align fraud controls with ongoing identity assurance, not just KYC entry checks.
NHI Mgmt Group analysis
Multi-step fraud has become a lifecycle governance problem, not a verification problem: the failure is no longer at the point of identity proofing alone. Fraud now advances by accumulating trust across stages, which means a programme that certifies identity once and then stops is governing yesterday’s attack model. Practitioners should treat identity assurance as a continuous state, not a completed event.
AI-driven fraud compresses the time between suspicion and exploitation: adaptive attackers can change documents, behaviour, and sequencing faster than manual review can keep up. That does not just increase false negatives. It collapses the usefulness of controls that assume a stable identity presentation over a review window. Identity teams need to recognise that review cadence itself can become the vulnerability.
Continuous identity monitoring is the new blast-radius control: when attackers span the full customer lifecycle, the important question becomes how far a fraudulent identity can move before the programme notices. That shifts the centre of gravity from entry assurance to ongoing trust validation, with fraud detection, authentication, and account risk scoring operating as one control surface.
Identity fraud and inclusion are now linked operationally: the same programme that blocks synthetic and AI-assisted fraud must also avoid excluding legitimate users in weak-document or high-friction markets. That creates a governance trade-off around assurance depth, step-up triggers, and reusable identity patterns that practitioners cannot solve with onboarding policy alone.
Reusable trust is the concept practitioners should watch: once identity evidence is accepted, many programmes reuse that trust too broadly across later sessions and services. AI-driven fraud exploits that reuse by turning an early approval into a long-lived assumption. The practical conclusion is that identity trust must be re-earned at the points where risk changes, not inherited indefinitely.
What this signals
Reusable trust is becoming the weak point in identity programmes: many teams still treat successful onboarding as durable proof, but AI-driven fraud now exploits the gap between first verification and later use. The governance question is no longer whether a user cleared a check, but whether the trust granted at that point should still be valid after behaviour changes.
Identity teams should expect fraud models to move from isolated decisioning toward sequence-based risk evaluation. That means stronger linkage between proofing, authentication, and ongoing monitoring, especially where account value rises after onboarding.
The practical shift is to design assurance for re-evaluation, not permanence. If identity trust cannot be refreshed when context changes, AI-enabled fraud will keep using the same accepted identity to travel farther into the customer journey.
For practitioners
- Extend monitoring beyond onboarding Correlate proofing, authentication, device, and session events so that a clean initial check does not mask later fraud signals.
- Introduce lifecycle-based risk scoring Re-evaluate identity trust at key user journey stages such as account creation, first payment, profile change, and high-value actions.
- Separate legitimate friction from fraud controls Use step-up triggers and verification paths that raise assurance without excluding users who lack strong documents or stable device histories.
- Test for AI-driven pattern shifts Review whether current fraud models can detect rapid changes in document style, behavioural cadence, and cross-session identity reuse.
Key takeaways
- Identity fraud is shifting from single-step deception to multi-step lifecycle abuse that can survive the first verification gate.
- Sumsub cites a 180% year-over-year increase in sophisticated fraud and a rise in multi-step attacks from 10% to 28% of all cases.
- The control response is continuous identity assurance across the customer journey, not reliance on a single onboarding decision.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | AI-driven fraud exploits weak or one-time identity validation across the lifecycle. |
| NHI-10 — Human Use of NHI | Fraud chains often reuse human-facing identity flows to mask non-human coordination. | |
| Recommendation — Use NHI-04 to require stronger authentication checks when identity trust changes across the journey. Apply NHI-10 controls to detect when legitimate-looking identity flows are being orchestrated fraudulently. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Identity assurance has to be revalidated as permissions and trust change over time. |
| Recommendation — Map lifecycle identity decisions to PR.AA-05 so permissions are rechecked when context shifts. | ||
| MITRE ATT&CK | TA0006;TA0040 — Credential Access; Impact | The article describes fraud chains that move from deceptive entry to later loss events. |
| Recommendation — Track fraudulent identity activity through TA0006 and TA0040 to improve detection of staged abuse. | ||
Key terms
- Multi-step identity fraud: An attack pattern where the adversary succeeds through a sequence of smaller actions rather than one obvious bypass. The first step may be identity proofing abuse, while later steps use the trusted account or session for takeover, mule activity, or transaction fraud.
- Continuous Identity Assessment: An approach that evaluates trust after onboarding, not only at account creation. It is especially relevant in marketplaces because risk shifts during recovery, payout changes, and high-value transactions, where a once-trusted identity may no longer deserve the same confidence.
- Synthetic Identity: A synthetic identity is a software-based actor that can authenticate, request access, and execute actions without being a human user. In practice, this includes AI agents, bots, service accounts, tokens, and other machine identities that need clear ownership, scope, and revocation.
- Identity lifecycle automation: The orchestration of joiner, mover, and leaver events so access is granted, adjusted, and removed without manual gaps. For mixed identity estates, it matters because revocation and review must keep pace with identities that do not follow human employment timelines.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org