TL;DR: VPN use is now routine, desktop sessions carry the densest fraud signal mix, and mobile integrity events remain rare but more decisive when they appear, according to Fingerprint's 2026 Device Intelligence Report, which analyses more than 23 billion identification events across over 7 billion browsers and devices.
NHIMG editorial — based on content published by Fingerprint: 2026 Device Intelligence Report on device and browser characteristics at decision points
By the numbers:
- The report analysed more than 23 billion identification events across over 7 billion browsers and devices worldwide.
- In 2025, roughly 1 in 5 identification events involved VPN usage, up from about 1 in 6 the year before.
- Fingerprint says 4.4% of desktop browser identifications showed tampering in 2025, up from 2.6% in 2024.
Questions worth separating out
Q: How should security teams handle VPN users without blocking legitimate access?
A: Security teams should use VPN detection as a contextual risk signal, not as an automatic deny rule.
Q: Why do desktop sessions produce more fraud signal noise than mobile sessions?
A: Desktop browsers allow more modification, virtualization, and automation tooling, so they generate more ambiguous signals.
Q: What do security teams get wrong about browser tampering and device signals?
A: They often treat each signal as a verdict instead of part of a pattern.
Practitioner guidance
- Recalibrate VPN treatment in decisioning rules Remove VPN presence as a standalone suspicion trigger in most flows, then use it as context alongside device integrity, velocity, and account history.
- Build separate scoring for desktop and mobile sessions Use different thresholds, evidence weights, and response paths for desktop and mobile because their baseline noise profiles are not comparable.
- Inventory approved automation and AI agent traffic Create explicit allowlists for QA jobs, internal bots, and AI-driven workflows, then bind them to named owners, scoped permissions, and revocation procedures.
What's in the full report
Fingerprint's full report covers the operational detail this post intentionally leaves for the source:
- Region, platform, and browser-runtime breakdowns that help teams tune fraud thresholds by environment
- Detailed segment analysis of browser tampering, virtual machine usage, and developer-tool patterns across desktop traffic
- Mobile integrity signal breakdowns, including rooted Android, jailbroken iOS, app cloning, and man-in-the-middle detection
- Benchmark data on suspect-score distributions that can support internal risk calibration and policy tuning
👉 Read Fingerprint's 2026 Device Intelligence Report for the full traffic baseline →
Desktop fraud signals and VPN normalisation: what teams should do?
Explore further
Desktop-heavy fraud is now a signal stacking problem, not a single-indicator problem. The report shows that the highest-risk activity clusters on desktop because desktop environments tolerate more modification, virtualization, and automation tooling. That means teams should stop asking whether a signal is suspicious in isolation and start asking whether several low-to-medium signals align into a coherent abuse pattern. The governance lesson is straightforward: risk scoring must reflect context density, not checkbox detection.
A question worth separating out:
Q: How should teams decide when to challenge or block an identification event?
A: Use channel-specific thresholds and response logic. On desktop, require multiple correlated signals before hard action. On mobile, even a small number of high-confidence integrity indicators may justify stronger controls. The decision should reflect expected user behaviour, business tolerance for friction, and the quality of evidence available at that point in the journey.
👉 Read our full editorial: Device intelligence shows fraud risk concentrates on desktop sessions