TL;DR: Credential theft appears in 39% of breaches and accounts for 52% of data compromised in basic web attacks, according to Verizon's 2026 DBIR, which is why Descope argues that fraud detection must move to authentication rather than waiting for transaction-time review. The governance issue is not just fraud volume, but whether identity teams can make login an enforceable risk decision instead of a pass-or-fail checkpoint.
NHIMG editorial — based on content published by Descope: Fraud Detection in Authentication: Using Identity Signals to Stop Fraud at Login
By the numbers:
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes, according to Entro Security research.
Questions worth separating out
Q: How should security teams reduce login friction without weakening identity security?
A: Security teams should replace high-friction, low-assurance controls with phishing-resistant authentication and context-aware access policies.
Q: Why do traditional IAM controls miss modern account takeover?
A: Traditional IAM often assumes the decisive security event is authentication at the IdP.
Q: What breaks when organisations rely on a single fraud signal at login?
A: A single signal creates blind spots.
Practitioner guidance
- Orchestrate login risk as a policy decision Combine behavioural, credential, device, and third-party fraud signals in one authentication flow so that each attempt can be allowed, challenged, or blocked consistently.
- Default to phishing-resistant login methods Use passkeys or other phishing-resistant methods for routine authentication, then reserve step-up authentication for higher-risk devices, locations, or actions.
- Separate login fraud from transaction fraud workflows Give identity teams and fraud teams a shared view of login risk, but keep the decision boundary at authentication so compromise is interrupted before payment or account abuse.
What's in the full article
Descope's full article covers the operational detail this post intentionally leaves for the source:
- Connector-level examples for breached-credential checks, device intelligence, and third-party fraud feeds in login flows
- Step-by-step examples of how conditional logic changes authentication outcomes for risky versus low-risk users
- Detailed guidance on when to challenge, block, or let users through based on multiple identity signals
- Practical examples of phishing-resistant login methods used alongside fraud detection in real journeys
👉 Read Descope's analysis of fraud detection in authentication and login risk →
Login fraud at authentication: are your identity signals keeping up?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Authentication is now a fraud control, not just an access control. Once attackers can reliably enter through exposed credentials, the login step becomes the earliest enforceable boundary for identity teams. That shifts ownership across IAM, fraud, and security operations, because post-login detection is already late. The implication is that programmes still treating authentication as a static gate are leaving the most actionable control point underused.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to Ultimate Guide to NHIs.
A question worth separating out:
Q: Who should own fraud-related identity risk decisions?
A: Ownership should be shared across IAM, fraud, compliance, and operations, with clear escalation rules. No single team sees the full picture, because identity assurance failures and abuse patterns emerge across onboarding, access, and transaction workflows. Joint ownership reduces blind spots and avoids delayed containment.
👉 Read our full editorial: Fraud detection at login is shifting identity risk to the front door