Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Fraud across telcos, payments and identity: where should teams intervene?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19785
Topic starter  

TL;DR: Fraud crosses social media, telecoms, digital identity and payments systems, according to Verisec International’s Forum to Finish Fraud initiative, so prevention now depends on coordinated intervention across organisations rather than isolated control points. The governance lesson is that fraud programmes need shared visibility, cross-sector accountability and earlier intervention in the fraud chain, not just stronger checks at the point of transaction.

NHIMG editorial — based on content published by Verisec International: Forum to Finish Fraud and its cross-sector approach to digital fraud prevention

By the numbers:

  • When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes, and as quickly as 9 minutes in some cases.

Questions worth separating out

Q: What breaks when fraud controls are managed only inside individual business silos?

A: Fraud controls fail when each application team sees only part of the transaction trail.

Q: Why do cross-channel fraud attacks often bypass traditional identity checks?

A: Because identity checks are usually designed for one moment in one system, while fraud abuse often unfolds across several systems that inherit trust from each other.

Q: How should fraud teams and IAM teams share responsibility for step-up decisions?

A: Fraud teams should own the risk evidence and IAM teams should own the policy action, with both sides agreeing on when a user is challenged, blocked, or routed for review.

Practitioner guidance

  • Map the fraud chain across trust domains Document where identity proofing, telecom trust, transaction authorisation and customer communication hand off between teams, then identify where the same user or event is trusted twice without new verification.
  • Define shared escalation triggers Create joint triggers for fraud escalation across IAM, fraud, payments and customer support so that suspicious activity in one channel can block action in another channel before the transaction completes.
  • Add re-verification at high-risk trust boundaries Require fresh validation when a request moves from one trust domain to another, especially where authentication, account recovery or payment redirection crosses organisational boundaries.

What's in the full article

Verisec International's full article covers the operational detail this post intentionally leaves for the source:

  • A fuller explanation of Forum to Finish Fraud's community model and how the initiative is being structured across LATAM.
  • Details from the 4 June 2026 hybrid event, including the speaker lineup and the fraud themes discussed.
  • Examples of the broader fraud scenarios the forum wants to examine through its Fraud Kill Chain concept.
  • Context on how the initiative is thinking about user confidence in digital services across Mexico and LATAM.

👉 Read Verisec International's Forum to Finish Fraud article on cross-sector fraud prevention →

Fraud across telcos, payments and identity: where should teams intervene?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19376
 

Fraud governance is now a cross-domain identity problem, not just a finance problem. The article shows why fraud prevention cannot live only in payments or only in customer onboarding. Digital fraud now spans identity proofing, communications trust and transaction control, so any single team sees only part of the attack chain. For IAM and identity verification leaders, the lesson is that fraud controls must be designed around shared signals and shared ownership, not isolated review queues.

A question worth separating out:

Q: What should organisations do when fraud moves across telcos and digital identity channels?

A: Treat the cross-channel path as the control surface. That means adding re-verification at channel boundaries, sharing escalation triggers with partners and defining who can halt a transaction when one channel sees risk that another does not. Without that coordination, fraud will keep outrunning single-team defences.

👉 Read our full editorial: Digital fraud needs ecosystem defence, not isolated controls



   
ReplyQuote
Share: