TL;DR: A reported 180% rise in sophisticated multi-step attacks across 2024 to 2025 underscores how identity signals, device intelligence, and behaviour monitoring are converging in enterprise fraud controls, according to SumSub. Fraud governance is no longer separate from identity governance, because the same trust decisions now span user onboarding, transaction monitoring, and real-time risk response.
Editorial analysis by NHI Mgmt Group, based on content published by SumSub: “Sumsub Recognized as Leader in Chartis RiskTech Quadrant for Enterprise Fraud Solutions 2026”.
By the numbers:
- The share of sophisticated multi-step attacks increased by 180% over 2024-2025, according to SumSub.
Key questions
Q: Where do identity trust controls fail in practice?
A: They fail when separate controls validate different parts of the path but do not present a unified signal to the user.
Q: Why do identity signals matter in fraud prevention models?
A: Identity signals matter because fraud rarely appears as a single event.
Q: How should teams decide when to step up fraud controls?
A: Use observed risk change as the trigger, not just the presence of a new session or transaction.
Practitioner guidance
- Map trust decisions across the full user journey Document where onboarding, session monitoring, payment review, and case management each consume the same identity signals so governance gaps are visible.
- Separate signal quality from decision ownership Assign clear owners for identity data quality, device telemetry, behavioural indicators, and fraud decision thresholds so one weak input does not distort every downstream action.
- Test for multi-step attack progression Exercise scenarios where the same actor changes device, behaviour, or channel mid-journey to see whether controls still correlate the activity as one risk path.
Bottom line: Fraud controls now sit inside the identity governance problem because the same signals increasingly support onboarding, monitoring, and response.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Fraud identity controls are becoming the front line of identity governance. The article shows that enterprises are buying and benchmarking platforms on how well they combine identity signals, device intelligence, and behavioural monitoring. That is no longer just a fraud problem, because the same evidence increasingly governs who is trusted to complete a transaction, open an account, or progress through a workflow. Practitioners should treat fraud tooling as part of the identity control surface, not a separate security lane.
A few things that frame the scale:
- The share of sophisticated multi-step attacks increased by 180% over 2024 to 2025, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
A question worth separating out:
Q: How do you know if fraud controls are actually improving?
A: Fraud controls are improving when teams can correlate fewer false handoffs, faster escalation, and better detection of staged attacks across the full user journey. The best signal is not volume of alerts, but whether the organisation can connect identity, device, and behaviour evidence to a defensible decision. If investigations still rely on manual stitching, the model is not mature.
👉 Read our full editorial: Chartis recognition signals fraud identity controls are maturing
Fraud controls are becoming identity governance controls. The article shows that identity signals, device intelligence, and behavioural monitoring are now part of the same trust decision layer. That means fraud programmes are no longer separate from IAM or compliance in practice, even if the org charts still say otherwise. The practitioner implication is that control ownership must be shared across identity, fraud, and risk teams.
A few things that frame the scale:
- Nearly 60% of companies reported that fraud losses were still increasing in 2025.
A question worth separating out:
Q: What does convergence between fraud and identity governance mean for security teams?
A: It means the same evidence now supports verification, response, and compliance decisions, so separate operating models become inefficient and inconsistent. Teams need shared ownership of trust signals, escalation logic, and review outcomes, otherwise one function can undermine the controls another function depends on.
👉 Read our full editorial: Chartis recognition signals fraud identity controls are maturing