TL;DR: Fraudsters are increasingly mimicking legitimate traveller behaviour, with flight fraud risk up 32% in May 2026 and billing-name matches becoming more risky than they were earlier in the year, according to Riskified travel analysis. For identity and fraud teams, the lesson is that static trust signals and legacy review rules are losing predictive value as attackers learn to blend in.
At a glance
What this is: Riskified’s travel fraud analysis shows fraud rings are adapting their behaviour to resemble legitimate customers, making traditional signals less reliable across flights, hotels, and travel platforms.
Why it matters: This matters because identity verification, account security, and fraud controls in travel now have to distinguish genuine customer behaviour from adversarial imitation without slowing conversion for legitimate users.
By the numbers:
- Flight fraud risk increased by 32% in May 2026 compared with May 2025.
- Billing-name-to-passenger-name mismatches remained 2.5x riskier in 2025.
- Riskified’s travel network includes more than 60 travel merchants.
- Riskified has processed $828 billion in cumulative travel transactions as of June 2026.
👉 Read Riskified's travel fraud analysis on shifting booking scams and traveller behaviour
Context
Travel fraud is no longer just a problem of stolen cards or obvious mismatches. The security gap is that fraud rings are now studying the same behavioural cues merchants use for trust decisions and then reproducing them at scale. In travel, that directly affects identity verification, account recovery, loyalty abuse, and transaction authorisation.
For IAM and fraud teams, the important shift is that a legitimate-looking identity signal can no longer be treated as a reliable proxy for intent. The article is really about governance of risk signals, where account state, device context, booking timing, and historical behaviour must be evaluated together rather than in isolation.
Key questions
Q: How should travel merchants adapt fraud controls when attackers mimic legitimate customer behaviour?
A: They should move from single-signal rules to contextual scoring that combines booking timing, device continuity, loyalty behaviour, account age, and identity history. The goal is to detect patterns that are still abnormal in combination, even when each individual signal looks plausible on its own. That approach reduces false confidence and makes adversarial mimicry harder to exploit.
Q: When do identity signals become too weak to rely on for travel fraud detection?
A: They become too weak when attackers can learn and reproduce the same indicators the merchant uses for trust decisions, such as name matching, account history, or routine booking patterns. At that point, the signal is describing resemblance, not legitimacy. Teams should treat any high-value workflow that depends on one or two identity cues as a governance gap.
Q: What do security teams get wrong about loyal customer accounts and fraud risk?
A: They often assume a verified or long-standing account is inherently trustworthy. In travel, compromised accounts can be more dangerous than new ones because they already contain reservation data, loyalty value, and trusted relationships. Security teams should monitor abnormal usage of verified accounts as aggressively as they inspect new-account abuse.
Q: How can fraud and IAM teams work together to reduce travel account abuse?
A: They should connect authentication policy, account recovery, device intelligence, and fraud case handling into one operating model. IAM teams provide identity assurance and recovery controls, while fraud teams detect monetisation behaviour and transaction abuse. When those functions share signals, compromised identities are easier to contain before loyalty theft or fraudulent booking completion.
Technical breakdown
Why legacy travel fraud signals are degrading
Travel fraud detection often relies on patterns that once separated genuine customers from attackers, such as name matches, booking timing, device reputation, and account history. The problem is that those signals are not intrinsic proof of legitimacy, only indicators that become weaker once fraud rings learn the scoring logic. When attackers can mimic timing, reuse trusted accounts, or align identity fields, the model’s precision drops. This is a classic adversarial adaptation problem: the defender’s features become the attacker’s playbook.
Practical implication: treat historical fraud rules as adaptive hypotheses, not fixed controls.
How compromised accounts change the trust model in travel
Travel platforms are attractive because loyalty balances, reservation details, and stored customer data create direct monetisation paths. Once an account is compromised, the attacker no longer needs to pass as a new customer. They can operate inside an existing trust relationship, which reduces friction in payment, booking, and support workflows. That changes the security model from blocking first-time abuse to detecting misuse of already-verified identities, including consumer and provider accounts.
Practical implication: add behavioural monitoring to verified-account workflows, not just onboarding checks.
Why timing and context now matter more than single signals
The article shows that last-minute bookings and billing-name alignment can both correlate with fraud, but neither is sufficient alone. In practice, a merchant needs to combine event timing, device continuity, account age, loyalty activity, and historical transaction shape to build a stronger risk picture. This is the same logic behind layered identity governance: one control rarely proves legitimacy, but multiple weak signals can establish a pattern worth actioning.
Practical implication: move fraud scoring toward multi-signal context rather than isolated rule triggers.
Threat narrative
Attacker objective: The attacker aims to monetise trusted travel identities by turning account access, loyalty value, and booking pathways into fraudulent revenue.
- Entry begins when fraudsters obtain compromised customer or travel-provider accounts, often through phishing, credential theft, or breached identities.
- Escalation occurs as the attacker leverages trusted account state, loyalty balances, or saved traveller data to pass through conventional screening with less friction.
- Impact follows when the fraud ring monetises bookings, points, or reservation access while blending into legitimate customer behaviour and avoiding detection.
NHI Mgmt Group analysis
Travel fraud is now an identity governance problem, not just a payment problem. The article shows fraudsters are exploiting trusted customer behaviour rather than only obvious payment anomalies. That matters because account recovery, loyalty systems, and reservation workflows all depend on identity assumptions that can be learned and impersonated. Practitioners should treat fraud detection as a trust-governance discipline, not a single-score exercise.
Behavioural mimicry is the named risk concept here: attackers are optimising for looking legitimate. Once fraud rings can imitate timing, name alignment, and account usage patterns, static rules lose discrimination value. That weakens any programme that assumes legitimate behaviour is stable enough to serve as a durable control boundary. Practitioners should expect adversarial adaptation, not just volume growth.
The most important control gap is overreliance on isolated identity signals. Name matches, booking windows, and account age all have value, but the article shows each can be gamed or reweighted by attacker learning. This aligns with broader identity governance lessons in NIST CSF and identity verification programmes: decisions should be contextual, not binary. Practitioners should re-evaluate how many of their trust decisions still depend on single-point indicators.
Travel merchants need closer convergence between fraud operations and IAM governance. The article touches compromised consumer and provider accounts, which means fraud is crossing into identity lifecycle, authentication, and access-recovery territory. That intersection is where policy, verification, and step-up controls either hold or fail. Practitioners should align fraud signals with identity controls instead of treating them as separate programmes.
Fraud resistance now depends on faster signal refresh than attacker learning cycles. Riskified’s findings point to a category-wide race between model drift and fraud-ring adaptation. Where merchants cannot refresh rules, device intelligence, and trust scoring fast enough, conversion-focused systems will keep absorbing loss. Practitioners should review whether their fraud governance is tuned for seasonal patterns or continuous adversarial change.
What this signals
Travel fraud programmes are converging with identity governance because the control question is no longer whether an account exists, but whether the current behaviour still matches the trust assumptions attached to it. That is why merchants need stronger linkage between fraud scoring, account recovery, and step-up verification. Behavioural mimicry: once attackers can copy legitimate usage patterns, the programme must detect context drift instead of isolated anomalies.
The operational signal to watch is not just chargeback volume, but the point at which verified identities start to behave like disposable ones. That is where loyalty systems, booking flows, and provider accounts become access surfaces rather than customer conveniences. Teams that can correlate device, identity, and transaction telemetry will spot this earlier than teams still separating fraud and IAM.
For practitioners
- Rebuild trust scoring around multi-signal context Combine booking timing, device continuity, account age, loyalty activity, payment history, and identity consistency into one decision layer instead of relying on a single pass or fail signal.
- Harden verified-account workflows Apply step-up checks to consumer and provider accounts when loyalty redemptions, reservation edits, or guest communications diverge from established behaviour, because those are the workflows fraudsters monetize.
- Separate high-risk travel behaviour from ordinary peak demand Model last-minute bookings, luxury-property reservations, and rapid loyalty usage as distinct risk clusters so fraud teams do not confuse seasonal traffic with adversarial activity.
- Align fraud operations with identity governance Link account recovery, authentication policy, and fraud case management so compromised identities are handled as an access problem as well as a transaction problem.
Key takeaways
- Travel fraud is increasingly an identity and trust-governance problem because attackers are learning to imitate legitimate behaviour rather than trigger obvious anomalies.
- Riskified’s data shows that traditional signals are losing discrimination value, with flight risk up 32% in May 2026 and billing-name matches becoming more dangerous over time.
- Practitioners should replace isolated fraud rules with contextual, multi-signal decisioning that links identity assurance, account recovery, and transaction monitoring.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-1 | Identity assertion and fraud screening are central to travel trust decisions. |
| NIST SP 800-63 | SP 800-63B | The article hinges on authentication and account assurance in verified travel accounts. |
| NIST SP 800-53 Rev 5 | IA-2 | Strong authentication is needed where compromised accounts drive travel fraud. |
| GDPR | Art.32 | Travel fraud controls process personal data and must protect it appropriately. |
Use IA-2 to require stronger authentication for account recovery and sensitive booking changes.
Key terms
- Behavioural Mimicry: The deliberate imitation of normal customer actions to reduce suspicion and improve approval odds. In fraud operations, behavioural mimicry can include cart composition, login patterns, timing, and shipping choices that look like established customer behaviour even when the underlying intent is malicious.
- Trust Signal Drift: The gap between a communication that still appears valid to email controls and the reality that its sender identity or intent has changed. In practice, it describes when static delivery checks no longer reflect the true risk of a message, especially in cloud-connected workflows.
- Valid Account Abuse: Valid account abuse occurs when attackers use legitimate credentials or tokens to enter systems and blend in with normal traffic. It is a preferred tactic because it sidesteps many exploit-based controls and inherits existing privilege. In NHI programmes, service accounts and API keys are common abuse paths when scope and rotation are weak.
What's in the full report
Riskified's full analysis covers the operational detail this post intentionally leaves for the source:
- Breakdowns of how fraud risk shifts across flights, hotels, and land transportation during different booking windows
- Methodology notes on the travel network sample, transaction coverage, and risk-level benchmarking used in the analysis
- Category-specific patterns for luxury hotels, loyalty abuse, and provider-account compromise that inform operational tuning
- Behavioural examples that show how fraud rings adapt faster than static trust signals can be refreshed
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, secrets management, IAM, and workload identity. It helps security and identity practitioners connect trust decisions to the controls that govern access, rotation, and accountability.
Published by the NHIMG editorial team on August 17, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org