TL;DR: UK businesses lost over £1.2 billion to fraud in 2024 as attackers used device manipulation, synthetic identities, behavioural mimicry, and social engineering to bypass static controls, according to Sift. Fraud detection now depends on layered monitoring across the customer journey, because legacy rule sets cannot keep pace with identity-led attack patterns.
NHIMG editorial — based on content published by Sift: How Fraud Detection Works: Best Practices for UK Businesses in 2025
By the numbers:
- In 2024, financial fraud cost UK businesses over £1.2 billion.
Questions worth separating out
Q: How should organisations layer fraud controls across the customer journey?
A: They should combine identity proofing, device intelligence, behavioural analytics, velocity checks, and ongoing monitoring instead of relying on onboarding alone.
Q: Why do synthetic identities create such persistent fraud risk?
A: Synthetic identities can pass early checks because they are built to look consistent enough for first-line verification.
Q: What signals show that fraud controls are missing real abuse patterns?
A: Look for repeated logins, rapid profile edits, unusual transaction bursts, device reuse across many accounts, and users who appear new but behave with scripted consistency.
Practitioner guidance
- Implement layered fraud signals across the journey Combine device fingerprinting, behavioural analytics, IP reputation, and velocity checks at onboarding, login, profile change, and payment stages so a single bypass does not clear the full journey.
- Tie fraud scores to access decisions Use risk evidence to drive step-up authentication, transaction holds, or recovery friction instead of treating fraud detection as a reporting-only function.
- Monitor dormant accounts and low-activity users Review accounts that appear clean but have little recent activity, because synthetic identities often age quietly before monetisation or account takeover.
What's in the full article
Sift's full post covers the operational detail this post intentionally leaves for the source:
- A practical breakdown of the fraud detection stack, including where device fingerprinting, behavioural analytics, and velocity checks fit in production workflows.
- Examples of emerging fraud tactics such as device emulation, deepfake IDs, mobile app fraud, proxy obfuscation, and fraud-as-a-service operations.
- A feature-by-feature explanation of how to balance false positives, abandonment rates, and real-time risk decisions without overblocking legitimate users.
- Implementation guidance on linking fraud evidence to Strong Customer Authentication and reporting suspicious activity.
👉 Read Sift's guide to fraud detection best practices for UK businesses →
Fraud detection and identity signals: what UK teams need now?
Explore further
Fraud detection is now an identity governance problem, not just a scoring problem. The article shows that account trust is being shaped by device, behaviour, and proofing signals across the journey. That pushes fraud teams closer to IAM, because the real decision is how much identity confidence to grant at each step. Practitioners should treat fraud telemetry as part of access governance, not a separate after-the-fact control.
A question worth separating out:
Q: How should fraud teams and IAM teams share responsibility for step-up decisions?
A: Fraud teams should own the risk evidence and IAM teams should own the policy action, with both sides agreeing on when a user is challenged, blocked, or routed for review. Shared ownership prevents gaps where suspicious behaviour is detected but no access control changes follow. This is especially important for account recovery and payment workflows.
👉 Read our full editorial: Fraud detection for UK businesses is shifting to identity signals