Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should organisations reduce account takeover and other…
Identity Beyond IAM

How should organisations reduce account takeover and other online fraud risks across customer journeys?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 27, 2026 Domain: Identity Beyond IAM

Organisations should combine identity verification, behavioural analytics, device intelligence, and risk-based step-up controls to detect suspicious patterns before a transaction completes. The goal is to score risk continuously, then apply friction only when signals justify it. Teams also need tuning, because fraudsters adapt quickly and often mimic legitimate behaviour to bypass static controls.

Why This Matters for Security Teams

account takeover and online fraud rarely begin with a dramatic breach. They usually start with small signals that look legitimate on their own: a reused password, a new device, a scripted login burst, or a session that shifts behaviour mid-journey. Security teams are under pressure to stop fraud without breaking conversion, which means static rules and one-time checks are too blunt for modern customer flows.

The risk is not only credential theft. Fraudsters increasingly chain identity proofing, device spoofing, session hijacking, and social engineering across signup, login, password reset, payout, and checkout. That makes NIST Cybersecurity Framework 2.0 useful as a governance baseline, but journey-level fraud control needs more than a control catalogue. NHIMG research shows 79% of organisations have experienced secrets leaks, with 77% resulting in tangible damage, which is a reminder that identity abuse often travels through overlooked paths, not only through the front door. The problem is visible in cases like the Meta AI Instagram Account Takeover, where abuse emerges from interaction paths that were not designed as classic authentication events.

In practice, many security teams discover the fraud pattern only after the customer reports a takeover or a chargeback has already been filed, rather than through intentional pre-transaction detection.

How It Works in Practice

Reducing fraud across customer journeys means treating identity as a continuous risk signal, not a single checkpoint. Organisations should combine identity verification, behavioural analytics, device intelligence, and transaction context so the system can score risk at each step and decide whether to allow, challenge, or block. Current guidance suggests that the strongest programs do not rely on one control; they layer controls so one weak signal does not become an easy bypass.

A practical design starts with low-friction baseline access and then adds step-up controls only when the journey changes in ways that matter: a new device, an impossible location shift, a password reset followed by payout changes, or a session that begins to automate. Behavioural analytics can flag abnormal typing cadence, navigation patterns, and request timing. Device intelligence can detect emulators, spoofing, tampering, or repeated use of high-risk fingerprints. Identity proofing should be reserved for the points where assurance matters most, especially high-value transactions and account recovery.

For mature teams, policy should be evaluated in real time rather than locked into fixed rules. That aligns with NIST SP 800-53 Rev. 5 Security and Privacy Controls for adaptive access oversight, and it also fits NHIMG guidance in the Ultimate Guide to NHIs — Key Challenges and Risks, which emphasizes visibility, rotation, and governance for identities that operate outside human workflows. Teams should tune thresholds continuously, because fraudsters will test the edge cases that sit just below blocking levels. The approach works best when it is instrumented across login, recovery, checkout, and support flows, not only at authentication, and it becomes unreliable when event telemetry is sparse or fragmented across vendors, legacy apps, and disconnected fraud tools.

  • Use step-up only when the cumulative signal justifies it, not on every suspicious event.
  • Correlate device, identity, session, and transaction data before making a decision.
  • Reassess trust after recovery flows, because those are common takeover entry points.
  • Log and review challenge outcomes so rules improve instead of stagnating.

Common Variations and Edge Cases

Tighter fraud controls often increase customer friction and operational overhead, so organisations must balance prevention against abandonment and support cost. That tradeoff is especially visible in low-risk consumer journeys, where too many prompts can drive users away, and in high-value journeys, where under-challenging can be expensive.

There is no universal standard for this yet, but current guidance suggests different journeys deserve different assurance levels. A password reset is not the same as a funds transfer, and a new-device login is not the same as a known-device checkout. Some environments need stronger verification for regulated actions, while others can tolerate a higher false-positive rate if the transaction value or abuse potential is high. The key is to define assurance tiers and make the risk engine sensitive to context, not just raw anomaly scores.

Edge cases include shared devices, legitimate travel, accessibility tools that alter behaviour patterns, and family accounts where normal usage looks irregular. These situations are where static models break down. Teams should also watch for fraud rings that distribute activity across many low-risk accounts, because individually normal-looking events can still form a coordinated attack. NHIMG’s Top 10 NHI Issues is a useful reminder that identity abuse often succeeds through scale, repetition, and weak lifecycle controls rather than one obvious exploit.

In practice, the controls fail when the organisation optimises only for conversion or only for loss reduction, because fraud adapts fastest in the gaps between those two goals.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AAJourney-based fraud controls depend on continuous identity assertion and authentication.
NIST SP 800-63IAL/AALIdentity proofing and authenticator assurance determine how much trust to place in a customer session.
NIST Zero Trust (SP 800-207)Continuous VerificationZero Trust supports re-evaluating trust during the session, not only at sign-in.
OWASP Non-Human Identity Top 10NHI-05Fraud often exploits weak identity lifecycle and secret handling behind customer-facing systems.
NIST AI RMFRisk scoring and automated challenge decisions need accountable AI governance and monitoring.

Set proofing and authenticator assurance by transaction risk, not by one-size-fits-all login policy.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org