TL;DR: Fraud tactics from decades ago still work because scammers adapt the same social-engineering patterns to modern business workflows, according to Abnormal AI’s Vision 2023 webinar, while the FBI and more than 14,000 organisations have used Frank Abagnale’s insights as a prevention reference. The lesson is that trust, approval, and verification processes remain soft targets when attacker behaviour changes faster than controls.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Cybercrime, Identity Theft, and Scams: Tips for Staying One Step Ahead in 2023”.
Key questions
Q: How should security teams reduce fraud risk in identity-heavy workflows?
A: Focus on the points where identity trust is most vulnerable: enrolment, account recovery, profile changes, and payout or transfer approval.
Q: Why do old fraud tactics still work in modern enterprises?
A: Old fraud tactics still work because they target human decision-making, not just systems.
Practitioner guidance
- Harden account recovery paths Remove easy-to-abuse recovery shortcuts, add stronger step-up checks, and require independent verification for high-risk resets and changes.
- Review approval workflows for fraud exposure Identify business approvals that can be influenced by urgency, familiarity, or authority, then separate routine requests from high-risk exceptions.
- Test exception handling with social-engineering scenarios Use realistic fraud scenarios to see where staff will override policy, accept urgent requests, or skip validation under pressure.
Bottom line: Older fraud tactics remain effective because they still exploit trust in approval and verification workflows.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Fraud resilience fails when organisations treat familiarity as assurance. The article’s central warning is that older scams still work because people and processes still reward recognisable behaviour. That means identity programmes cannot rely on channel modernisation alone. Practitioners have to treat human approval steps as governable attack surfaces, not just business conveniences.
A question worth separating out:
Q: How do fraud controls differ from standard access controls?
A: Access controls decide whether an identity may enter a system, while fraud controls judge whether a request itself is trustworthy. That difference matters because attackers often target the process around the control, not the control mechanism alone. In practice, fraud controls must cover human behaviour, workflow integrity, and escalation paths.
👉 Read our full editorial: Why fraud tactics still work and what teams should expect next