Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› Why does identity fraud often get worse during…
Threats, Abuse & Incident Response

Why does identity fraud often get worse during major online behaviour shifts?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Threats, Abuse & Incident Response

Identity fraud rises when people move more activity online because attackers exploit new habits, rushed service rollouts, and account sprawl. During periods like the pandemic, scammers used fake grants, fake news updates, and exposed personal data from earlier breaches to target victims. Reused passwords and weak account protections make those attacks easier to scale across multiple services.

Why identity fraud accelerates when people suddenly move more of life online

When daily activity shifts online quickly, identity checks, account creation, and service access all happen at higher volume and lower friction. That creates more openings for fraud, because attackers do not need to defeat one system once, they can test weak onboarding, reuse stolen data, and abuse rushed digital processes across many services at scale.

Behaviour shifts also change the fraud mix. New users, stressed customers, and organisations under rollout pressure tend to accept weaker verification, lighter support checks, and more self-service recovery, which gives criminals more ways to impersonate legitimate people or create synthetic ones.

How attackers turn sudden digital adoption into scalable fraud

Fraud increases when stolen or leaked personal data becomes easier to combine with new account requests, password resets, and payment flows. If someone can answer a few checks from old breach data, a reused password, or a recovered email inbox, they can often move from data theft to account takeover with very little resistance.

This is why identity fraud often scales fastest when attackers can reuse the same playbook across many services. Reused credentials, weak recovery paths, and inconsistent identity proofing make it easier to push one successful intrusion into multiple accounts, especially when users have not yet updated their habits or protections.

Broad fraud controls work best when they reduce reusable trust. That includes stronger identity proofing for high-value actions, better device and session signals, and limits on how far a single compromise can spread. Practical guidance on Identity Fraud Prevention Guide shows why account takeover, synthetic identity, and fraud signals need to be treated as a connected problem rather than isolated incidents.

Why major events create more opportunity for fake requests, fake updates, and social engineering

Large behaviour shifts also create a believable story for social engineering. During a crisis or major public change, people expect grants, policy updates, delivery notices, benefits changes, and urgent account messages, so fraud messages fit the moment and feel less suspicious.

That timing matters because fraud is not only technical, it is behavioural. Attackers can use public attention, confusion, and urgency to get people to click, disclose, or approve actions they would normally question. Once a victim has been conditioned to expect rapid online movement, the attacker’s message does not need to be perfect, only plausible enough to get a response.

Identity assurance becomes more important when the environment is shifting, because the attacker advantage comes from weak certainty, not just weak passwords. A focused treatment of Identity Proofing and KYC Guide helps explain why onboarding and proofing quality matter when new digital demand spikes.

Risk and Threat Considerations

When behaviour changes quickly, organisations often relax controls to avoid blocking legitimate users, and that creates a fraud gap. The main risk is not only more attempted fraud, but more successful fraud through account takeover, synthetic identity creation, and abuse of recovery processes that were designed for convenience first.

Failure mechanism: Attackers combine breached personal data, reused passwords, weak verification, and urgent social engineering to pass as legitimate users or to exploit account recovery paths. As services move faster, defenders often have less time to tune thresholds, investigate anomalies, or detect coordinated abuse across multiple platforms.

Impact: The result can be fraudulent onboarding, financial loss, unauthorised access, customer trust damage, and persistent reuse of compromised identity data across later attacks. In a high-change period, one weak process can become a repeatable path for many victims.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, OWASP ASVS, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCredential reuse and weak recovery make authenticator lifecycle control central to fraud risk.
IA-2 — Identification and Authentication (Organizational Users)Identity fraud often succeeds when authentication is too weak for account access and recovery.
Recommendation — Enforce authenticator rotation, expiration, and reuse limits for high-risk identity journeys. Require stronger authentication for sensitive account access and recovery actions.
OWASP ASVSV6 — AuthenticationThe question concerns account access abuse, weak verification, and takeover paths.
Recommendation — Strengthen authentication assurance for sign-up, login, and recovery flows.
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication and Access ControlThe issue is scalable misuse of identity checks and access paths during rapid online shifts.
Recommendation — Harden identity proofing and access controls for the most abuse-prone journeys.
CIS Controls v8CIS-5 — Account ManagementAccount sprawl, reuse, and weak recovery are direct drivers of fraud escalation.
Recommendation — Reduce account sprawl and remove dormant or weakly governed access paths.

Practitioner Guidance

What to verify: Check whether the highest-risk journeys, especially onboarding, password reset, and payout or benefits changes, are still using the same trust assumptions after the behaviour shift. If a process now accepts more self-service, it should usually demand stronger step-up checks, not just faster handling.

What to prioritise: Focus first on controls that reduce cross-service reuse, because that is what makes fraud scale. Reused credentials, stale recovery methods, and weak identity proofing are the easiest places for a fraud campaign to expand from one account into many.

Common mistake: Treating the increase as a temporary spike and adding only manual review. Manual review helps, but it does not stop abuse patterns that are already repeatable across channels, especially when attackers are working from the same breach data and the same social engineering script.

Practitioner takeaway: The key issue is not simply that more people are online, it is that rapid behavioural change makes old trust rules obsolete faster than defenders can update them.

FinCEN

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org