Join our Newsletter — 33% off our NHI Course

Fraud tactics in 2026: what IAM teams are missing

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Fraud tactics from decades ago still work because scammers adapt the same social-engineering patterns to modern business workflows, according to Abnormal AI’s Vision 2023 webinar, while the FBI and more than 14,000 organisations have used Frank Abagnale’s insights as a prevention reference. The lesson is that trust, approval, and verification processes remain soft targets when attacker behaviour changes faster than controls.

Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Cybercrime, Identity Theft, and Scams: Tips for Staying One Step Ahead in 2023”.

Key questions

Q: How should security teams reduce fraud risk in identity-heavy workflows?

A: Focus on the points where identity trust is most vulnerable: enrolment, account recovery, profile changes, and payout or transfer approval.

Q: Why do old fraud tactics still work in modern enterprises?

A: Old fraud tactics still work because they target human decision-making, not just systems.

Practitioner guidance

  • Harden account recovery paths Remove easy-to-abuse recovery shortcuts, add stronger step-up checks, and require independent verification for high-risk resets and changes.
  • Review approval workflows for fraud exposure Identify business approvals that can be influenced by urgency, familiarity, or authority, then separate routine requests from high-risk exceptions.
  • Test exception handling with social-engineering scenarios Use realistic fraud scenarios to see where staff will override policy, accept urgent requests, or skip validation under pressure.

Bottom line: Older fraud tactics remain effective because they still exploit trust in approval and verification workflows.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21474
 

Fraud resilience fails when organisations treat familiarity as assurance. The article’s central warning is that older scams still work because people and processes still reward recognisable behaviour. That means identity programmes cannot rely on channel modernisation alone. Practitioners have to treat human approval steps as governable attack surfaces, not just business conveniences.

A question worth separating out:

Q: How do fraud controls differ from standard access controls?

A: Access controls decide whether an identity may enter a system, while fraud controls judge whether a request itself is trustworthy. That difference matters because attackers often target the process around the control, not the control mechanism alone. In practice, fraud controls must cover human behaviour, workflow integrity, and escalation paths.

👉 Read our full editorial: Why fraud tactics still work and what teams should expect next


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.