Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Traditional Identity Fraud
Governance, Ownership & Risk

Traditional Identity Fraud

← Back to Glossary
By NHI Mgmt Group Updated September 26, 2026 Domain: Governance, Ownership & Risk

Traditional identity fraud is the use of someone’s personal information to commit financial crime without the victim necessarily being directly engaged in the interaction. It often appears in account opening, loan applications, or benefit claims. The core weakness is unauthorized use of identity data to pass controls meant for legitimate customers.

What Traditional Identity Fraud Means in Practice

Traditional identity fraud is not a mere paperwork error, it is the misuse of a real person’s identity data to satisfy onboarding or eligibility checks that should only pass for the legitimate customer. In practice, the fraudster is trying to look like the rightful owner of the identity long enough to open an account, obtain credit, or claim benefits.

The important distinction is that the victim may never be part of the transaction at all. That makes the crime different from ordinary unauthorised account use, because the attacker is exploiting identity proofing, record checks, and trust in submitted information rather than simply taking over an existing login.

Where It Commonly Appears

Traditional identity fraud shows up most often where an organisation creates a new relationship or approves value based on identity evidence. Account opening, loan applications, insurance enrolment, and government benefit claims are common examples because those processes often rely on identity data, document checks, and automated decisioning.

It can also arise when identity information is harvested from data breaches, phishing, social engineering, or stolen mail and then reused across multiple institutions. The same data set may be enough to bypass weaker checks in one environment even if another organisation would reject the same application.

For a broader view of how identity abuse fits into wider financial crime controls, FinCEN remains a useful authority on AML obligations and suspicious activity reporting in the US context.

Why the Fraud Succeeds

The fraud works when an organisation treats identity data as proof of legitimacy without enough corroboration. Static data points such as name, date of birth, address history, or national identifier fragments can be valuable signals, but they are often weak on their own because they can be stolen, guessed, or assembled from multiple sources.

This is why identity fraud frequently exploits gaps in identity proofing, document verification, fraud scoring, and cross-checks against prior history. A single control failure may be enough, but the more common pattern is a chain of small weaknesses that collectively allow a false identity to pass as genuine.

Where identity assurance and authentication are part of the control design, the underlying NIST SP 800-63 Digital Identity Guidelines are relevant because they frame assurance, proofing, and authenticator strength as distinct control problems, not a single yes-or-no check.

Business and Security Consequences

The immediate impact is usually financial loss, but the downstream effects are broader. Organisations may absorb charge-offs, fraud investigation costs, remediation work, regulatory scrutiny, and reputational damage, while the real person whose identity was misused can face collection notices, credit damage, or delays proving they were not the applicant.

There is also a control-risk dimension for the institution itself. If identity fraud patterns are not detected early, they can contaminate customer records, distort risk models, and create false confidence in onboarding controls that appear effective until losses accumulate.

For organisations that want a technology-specific framing of identity weaknesses, the OWASP Non-Human Identity Top 10 is not about this human fraud pattern directly, but it is useful as a contrasting control model for understanding how identity abuse becomes a security issue when trust, credentials, and access are not tightly governed.

Risk and Threat Considerations

Traditional identity fraud is attractive because it targets the point where organisations decide whether a person deserves access to money, services, or credit. The risk is not only stolen funds, but also false approvals that can persist until the account is used, the debt defaults, or the victim notices the misuse.

Failure mechanism: The attacker relies on weak or incomplete identity proofing, then presents stolen or assembled personal data that passes the organisation’s legitimacy checks without requiring the victim to participate.

Impact: The organisation may open fraudulent accounts or approve fraudulent claims, while the real identity holder absorbs remediation effort, potential credit harm, and prolonged dispute resolution.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP API Security Top 10 addresses the attack and risk surface, while NIST SP 800-63, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesDefines identity proofing and authenticator assurance relevant to fraud-resistant onboarding.
Recommendation — Apply stronger identity proofing and assurance decisions before approving high-risk customer actions.
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)Covers identity and authentication controls for customers and other external users.
IA-12 — Identity ProofingDirectly addresses proving an external user's identity before service enrollment or access.
Recommendation — Use IA-8 to authenticate external users before granting account access or approval. Apply IA-12 to strengthen proofing during onboarding and benefit or credit eligibility checks.
OWASP API Security Top 10API2 — Broken AuthenticationFraudulent onboarding often exploits weak authentication or verification in exposed digital flows.
Recommendation — Harden authentication and verification in exposed application and API onboarding flows.
CIS Controls v8CIS-5 — Account ManagementAccount creation and lifecycle controls help limit fraudulent account establishment.
Recommendation — Tighten account management checks for new, changed, or recovered customer identities.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org