By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: FingerprintPublished May 18, 2026

TL;DR: Authentication gains have not stopped fraud because attackers now exploit enrollment, session, and device-trust gaps across the customer lifecycle, according to Fingerprint, while Juniper Research projects financial fraud losses will reach $58.3 billion globally by 2030. The real control boundary has shifted from credential verification to persistent device intelligence that can survive across sessions.


At a glance

What this is: This article argues that stronger authentication alone is no longer enough for banks, because fraud now bypasses the login moment by exploiting device trust, session control, and enrollment flows.

Why it matters: It matters to identity and fraud teams because account security now depends on seeing risk across sessions and channels, not just verifying a credential at a single point in time.

By the numbers:

👉 Read Fingerprint's analysis of device intelligence and banking fraud risk


Context

Banks have invested heavily in biometrics, MFA, passkeys, and behavioral scoring, but those controls were built to answer a narrower question: does this credential match the enrolled user right now? The article’s central point is that banking identity risk now extends beyond the login to the device, session, and enrollment lifecycle, which is where fraud teams need persistent context.

In practice, this is an identity-verification and fraud-governance problem as much as an authentication problem. When AI can spoof faces, clone voices, and amplify social engineering, the security boundary moves from first-factor verification to the trustworthiness of the device and session carrying that identity across time.

Persistent device intelligence becomes the connective layer between customer identity, session trust, and downstream transaction controls. That starting position is now typical of high-friction fraud environments, but still atypical in the way most Tier 1 banks operationalise control coverage.


Key questions

Q: What breaks when banks rely only on strong authentication for fraud prevention?

A: Strong authentication breaks down when attackers move after login, because the system can validate a credential without understanding whether the device, session, or enrolment path is trustworthy. That leaves room for session hijacking, SIM swap, remote access tools, and fraud that uses a legitimate customer session to move money. The fix is to pair authentication with persistent device and behavioural context.

Q: Why do trusted accounts create more fraud loss than obvious new attacks?

A: Trusted accounts already carry behavioural history, payment permissions, and user confidence, so malicious actions blend in more easily. That makes them better vehicles for monetisation than noisy attack attempts. The result is higher downstream loss even when overall fraud volume appears to be falling.

Q: How do security and fraud teams know whether device intelligence is working?

A: Look for three signals: fewer false positives, lower abandonment at login and checkout, and earlier detection of repeated abuse from the same persistent device. If fraud loss drops while good customers move through without extra friction, the device layer is doing its job. If challenges increase but loss does not fall, the controls are too blunt.

Q: Who is accountable when fraud happens after authentication succeeds?

A: Accountability sits with the teams that own the identity journey, API exposure and transaction controls together. If authentication, fraud monitoring and payment risk are split into separate silos, attackers exploit the gaps between them. Governance should define who can stop a session before value moves.


Technical breakdown

Why authentication no longer defines the trust boundary

Traditional authentication proves a user or device met a point-in-time check, but it does not prove that the same device remains trustworthy after the session begins. In banking, that distinction matters because attackers increasingly move after login, using session hijacking, remote access tools, SIM swaps, and post-enrolment abuse. Biometric and passkey controls reduce credential theft, but they do not expose cross-session reuse, shared device infrastructure, or coordinated fraud patterns. The architectural gap is visibility: the system sees a valid event, not the broader behavioural context around it.

Practical implication: treat authentication as an entry signal and add a persistent trust layer underneath it.

How device intelligence exposes enrollment and session abuse

Device intelligence builds continuity across interactions by correlating hardware, browser, environment, and behavioural signals over time. That makes it useful against attacks that exploit legitimate flows, such as registering a passkey on an attacker-controlled device after temporary account access, or using a RAT to control a live session alongside the victim. It also helps identify when the same device appears across unrelated accounts, which is a strong marker for mule networks and coordinated fraud. The value is not in replacing authentication, but in detecting when a valid login is happening on an untrusted endpoint.

Practical implication: correlate enrolment, login, and payment events against persistent device profiles before expanding trust.

Why established accounts are more exposed than new ones

Fraud teams often focus on new-account abuse, but established accounts usually carry the highest payout potential because they already possess trust, limits, and fewer friction points. Once a trusted account is compromised, the attacker inherits payment velocity, reduced review, and historical legitimacy that can suppress alerts. Scam-driven fraud extends the same pattern by manipulating legitimate customers into authorising harmful actions, which means the system must distinguish routine account ownership from abnormal device and payee behaviour. The control problem is no longer just who logged in, but how the account is being used across time.

Practical implication: move high-value account monitoring from single-event checks to lifecycle-based trust monitoring.


Threat narrative

Attacker objective: The attacker wants to convert a legitimate or semi-legitimate banking session into fast fund movement from a trusted account before risk controls detect the abuse.

  1. Entry typically begins with credential theft, SIM swap, social engineering, or attacker-controlled enrolment that lets the fraudster reach an authenticated banking session.
  2. Escalation occurs when the attacker binds a new device, hijacks the live session, or uses remote access tooling to operate under legitimate-looking controls.
  3. Impact follows when trusted-account privileges, payee trust, or payment rails are abused to move funds before the customer or bank can intervene.

NHI Mgmt Group analysis

Device trust is becoming the real identity perimeter in banking. Authentication still matters, but it now answers only part of the security question. Banks that stop at credential verification miss the harder problem of persistent device reputation across sessions, accounts, and channels. For identity and fraud teams, the practical conclusion is that device intelligence must sit alongside authentication as a governing control.

Passkeys reduce phishable secrets, but they also move risk into enrolment governance. The article correctly shows that a strong authenticator can still be captured if an attacker controls the device at the moment of binding. That creates a lifecycle problem, not a one-time login problem. Teams need to govern who can enrol, re-bind, or replace authenticators, because the trust decision now lives in the journey, not the password.

Persistent device intelligence is a named control concept worth sharpening: cross-session trust continuity. This is the capability to recognise whether the same device, environment, or behavioural pattern is reappearing across unrelated events. It is especially relevant where synthetic identity, mule networks, and scam-driven fraud blur the line between valid identity and malicious intent. Practitioners should treat this as a detection and policy layer, not just a fraud analytics feature.

Financial institutions are being pushed toward a broader identity model that includes the device as a governed entity. The article’s examples show that account takeover is no longer a single-factor failure. It is an ecosystem failure spanning customer identity, device reputation, session integrity, and payment authorisation. The implication for IAM and fraud programmes is clear: governance must extend beyond the credential to the runtime context that carries it.

What this signals

Identity programmes should expect fraud controls to move further from the login screen and closer to runtime trust scoring. That shift favours architectures that can retain context across sessions, devices, and enrolment events, because point-in-time verification alone cannot distinguish legitimate use from coordinated abuse.

Cross-session trust continuity: the next control battleground is not whether a customer can authenticate, but whether the same device and environment should keep inheriting trust after authentication. Teams that cannot answer that question will continue to over-trust high-value accounts and under-detect behavioural fraud.

For IAM and fraud leaders, this is a signal to tighten the handoff between customer identity, device reputation, and payment authorisation. The operational priority is not more friction everywhere, but better discrimination at the moments where trust is expanded.


For practitioners

  • Map fraud controls to the full customer lifecycle Trace where trust is granted, expanded, and reused across onboarding, enrolment, login, payee addition, and payment execution. Identify where the same device can move from low-risk to high-trust without additional scrutiny.
  • Add device continuity checks to enrolment flows Require device reputation and environment history before allowing passkey registration, authenticator replacement, or account recovery. This helps stop attacker-controlled device binding after temporary access.
  • Correlate sessions across accounts and channels Look for repeat device fingerprints, shared browser characteristics, abnormal input cadence, and repeated payee patterns across unrelated accounts. These are strong indicators of coordinated fraud, mule activity, or RAT use.
  • Tune high-value transaction controls for trusted-account abuse Apply stricter review or step-up logic when an established account behaves differently from its own history, even if the login was valid. Fraud often surfaces only after the account has already been granted trust.
  • Review replacement options for legacy device-intelligence tooling If your fraud stack relied on a now-retired platform, validate whether the replacement still supports persistent device identity, cross-session correlation, and lifecycle risk scoring rather than cookie-only recognition.

Key takeaways

  • Authentication is still necessary, but it no longer defines the full trust boundary for banking fraud.
  • Fraud now exploits device continuity, enrolment flows, and trusted-account privilege to bypass controls that only inspect a single login event.
  • Banks need persistent device intelligence and lifecycle-aware governance if they want to reduce account takeover without breaking legitimate customer journeys.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63BThe article centres on authenticators, passkeys, and phishing-resistant login flows.
NIST CSF 2.0PR.AC-1Identity proofing and access control are central to preventing trusted-account abuse.
NIST SP 800-53 Rev 5IA-5Authenticator management is directly relevant to passkeys, MFA, and re-binding risk.
GDPRArt.32Where device intelligence processes personal data, security of processing becomes relevant.

Use SP 800-63B to strengthen authenticator binding and step-up decisions around high-risk enrolment events.


Key terms

  • Persistent Device Intelligence: Persistent device intelligence is the ability to recognise and score a device or environment across multiple sessions, accounts, and channels. It uses hardware, browser, network, and behavioural signals to determine whether the same endpoint remains trustworthy after authentication. In fraud programmes, it closes the gap left by point-in-time login checks.
  • Passkey Enrolment Fraud: Passkey enrolment fraud happens when an attacker gains temporary access to an account and registers their own device or authenticator as trusted. After enrolment, the attacker can authenticate legitimately because the system believes the new binding is valid. The weakness is not the passkey itself, but the governance around who can bind it.
  • Trusted Account Abuse: The use of a legitimate, compromised identity to send malicious messages or perform unauthorized actions. Because the account already has reputation and context, defenders often miss it until the abuse spreads beyond the first target.

What's in the full article

Fingerprint's full article covers the operational fraud patterns this post intentionally leaves at a higher level:

  • Detailed walkthroughs of biometric bypass, passkey enrolment abuse, and session hijacking patterns in banking.
  • Practical explanations of how device intelligence is used to connect onboarding, login, and payment-stage signals.
  • Examples of the controls banks are adding around step-up, enrolment validation, and trusted-account monitoring.
  • Benchmark context on why legacy cookie-based tracking is not enough for modern fraud operations.

👉 Fingerprint's full article covers the device, session, and enrolment patterns behind modern account takeover

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, workload identity, secrets management, and access lifecycle control. It helps security and identity practitioners build the governance model needed for machine and service-account trust decisions.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org