Join our Newsletter — 33% off our NHI Course

Fraud lifecycle defence in 2026: are identity controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Fraud attacks rose 180% last year as organised networks, synthetic identities, and AI agents intensified pressure across onboarding, payments, payouts, and cash-out, according to SumSub. The real problem is that fraud now behaves like a connected lifecycle, so identity controls must track trust, risk, and escalation across the full user journey.

Editorial analysis by NHI Mgmt Group, based on content published by SumSub: “Fraud Prevention: Best Practices for 2026”.

Key questions

Q: What breaks when fraud controls only cover onboarding and not the rest of the user journey?

A: Stage-limited controls let fraudsters pass a clean entry point and then shift abuse into payments, payouts, or cash-out where governance is weaker.

Q: Why do synthetic identities make traditional fraud controls less effective?

A: Synthetic identities reduce the value of controls that rely on spotting obviously fake profiles at signup.

Q: How should teams decide when to step up fraud controls?

A: Use observed risk change as the trigger, not just the presence of a new session or transaction.

Practitioner guidance

  • Align fraud controls to the full lifecycle Map trust-building, onboarding, payment, payout, and cash-out to explicit control owners so each stage inherits prior risk decisions.
  • Correlate identity proofing with downstream risk Carry verification outcomes into transaction monitoring and payout approval so one clean onboarding event does not reset the risk posture.
  • Tune escalation for synthetic identity patterns Use device, velocity, and behaviour signals together so gradual fraud build-up is detected before cash-out.

Bottom line: Fraud is best understood as a staged lifecycle, which means controls at onboarding alone cannot protect the rest of the journey.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Fraud lifecycle defence is really identity lifecycle defence in disguise. Once fraud moves from a single event to a connected journey, the governance problem becomes trust continuity across identity proofing, transaction use, and payout. That is why identity teams cannot leave fraud entirely to downstream review functions. The practitioner conclusion is that fraud controls must be designed as lifecycle controls, not isolated checkpoints.

A few things that frame the scale:

  • 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to the Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which means many identity programmes still cannot see the accounts most likely to be abused.

A question worth separating out:

Q: What should organisations do when AI agents become part of the fraud problem?

A: Organisations should assume fraud can scale faster and with more variation when AI agents are involved. The response is to redesign reviews for machine-speed activity, use layered signals, and avoid relying on static thresholds that were built for human behaviour. The control model has to match the adversary's speed.

👉 Read our full editorial: Fraud lifecycle defence in 2026 needs stronger identity controls



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Fraud lifecycle defence is now an identity governance problem, not just a detection problem. The article’s core premise is that fraud travels across onboarding, payments, payouts, and cash-out as a connected sequence. That means the control plane has to preserve decision context across the full lifecycle, not only at the first verification step. Practitioners should treat fraud governance as a stateful identity problem, where the same subject can move from low-risk enrolment to high-risk monetisation.

A few things that frame the scale:

A question worth separating out:

Q: What should fraud teams do when AI-assisted fraud changes the speed of attacks?

A: Shorten decision loops, connect signals across channels, and predefine stage-based escalation so the team can respond before the attacker completes the next lifecycle step. Manual review remains useful, but only when it is reserved for cases that truly need human judgment and not for every anomaly.

👉 Read our full editorial: Fraud lifecycle defence in 2026 needs stronger identity controls


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.