TL;DR: Authentication gains have not stopped fraud because attackers now exploit enrollment, session, and device-trust gaps across the customer lifecycle, according to Fingerprint, while Juniper Research projects financial fraud losses will reach $58.3 billion globally by 2030. The real control boundary has shifted from credential verification to persistent device intelligence that can survive across sessions.
NHIMG editorial — based on content published by Fingerprint: device intelligence and the future of banking identity risk
By the numbers:
- Fraud losses are projected to cost financial institutions $58.3 billion globally by 2030, a 153% surge from 2025 levels.
- Losses from account takeover fraud in the U.S. totaled $15.6 billion in 2024, up from $12.7 billion the year prior.
- Every dollar lost to a fraudster costs North American financial institutions $4.41.
Questions worth separating out
Q: What breaks when banks rely only on strong authentication for fraud prevention?
A: Strong authentication breaks down when attackers move after login, because the system can validate a credential without understanding whether the device, session, or enrolment path is trustworthy.
Q: Why do trusted accounts create more fraud loss than obvious new attacks?
A: Trusted accounts already carry behavioural history, payment permissions, and user confidence, so malicious actions blend in more easily.
Q: How do security and fraud teams know whether device intelligence is working?
A: Look for three signals: fewer false positives, lower abandonment at login and checkout, and earlier detection of repeated abuse from the same persistent device.
Practitioner guidance
- Map fraud controls to the full customer lifecycle Trace where trust is granted, expanded, and reused across onboarding, enrolment, login, payee addition, and payment execution.
- Add device continuity checks to enrolment flows Require device reputation and environment history before allowing passkey registration, authenticator replacement, or account recovery.
- Correlate sessions across accounts and channels Look for repeat device fingerprints, shared browser characteristics, abnormal input cadence, and repeated payee patterns across unrelated accounts.
What's in the full article
Fingerprint's full article covers the operational fraud patterns this post intentionally leaves at a higher level:
- Detailed walkthroughs of biometric bypass, passkey enrolment abuse, and session hijacking patterns in banking.
- Practical explanations of how device intelligence is used to connect onboarding, login, and payment-stage signals.
- Examples of the controls banks are adding around step-up, enrolment validation, and trusted-account monitoring.
- Benchmark context on why legacy cookie-based tracking is not enough for modern fraud operations.
👉 Read Fingerprint's analysis of device intelligence and banking fraud risk →
Device intelligence for banking fraud: are your controls keeping up?
Explore further
Device trust is becoming the real identity perimeter in banking. Authentication still matters, but it now answers only part of the security question. Banks that stop at credential verification miss the harder problem of persistent device reputation across sessions, accounts, and channels. For identity and fraud teams, the practical conclusion is that device intelligence must sit alongside authentication as a governing control.
A question worth separating out:
Q: Who is accountable when fraud happens after authentication succeeds?
A: Accountability sits with the teams that own the identity journey, API exposure and transaction controls together. If authentication, fraud monitoring and payment risk are split into separate silos, attackers exploit the gaps between them. Governance should define who can stop a session before value moves.
👉 Read our full editorial: Persistent device intelligence is now core to banking identity risk