Category: Fraud prevention

Understanding and Detecting Synthetic Identity Fraud

Understanding and Detecting Synthetic Identity Fraud

When identity verification checks only confirm narrow facts, synthetic identity fraud can still succeed. Consider several risk signals commonly used in identity workflows today. An active phone number shows that a line is in service. A returned one-time passcode shows control of that number during an interaction. Document validation indicates…

Identity Lifecycle Management: Why Onboarding and Account Recovery Are the Most Important to Secure

Identity Lifecycle Management: Why Onboarding and Account Recovery Are the Most Important to Secure

Phishing-resistant authenticators offer stronger security, but they can still protect the wrong person. When a threat actor defeats identity verification during onboarding, an otherwise strong access management workflow can still grant unauthorized access. If a threat actor bypasses authentication by exploiting account recovery, the system may bind a replacement factor…

Securing Account Recovery from Identity Attacks

Securing Account Recovery from Identity Attacks

Account recovery workflows decide which person and which device an organization will re-trust. That makes recovery a privileged identity lifecycle event. For the most part, account recovery processes are designed to restore access conveniently. That emphasis on convenience can allow attackers to bypass the controls meant to keep them out.

Vishing vs. Smishing: How Enterprises Can Defend Their Shared Attack Chain

Vishing vs. Smishing: How Enterprises Can Defend Their Shared Attack Chain

An employee receives a text message warning about unusual activity on a company account. They reply that they don’t recognize it. Minutes later, someone claiming to work in IT calls, references the alert, and guides the employee through an account security process. Was the attack smishing or vishing? It was…

Passing Know Your Business (KYB) Checks Isn’t the Same as Stopping Business Fraud

Passing Know Your Business (KYB) Checks Isn’t the Same as Stopping Business Fraud

The contractor you just onboarded to work inside your environment could be a fraudster operating under a stolen identity, even though the vendor they claim to represent is a legitimate, registered company. Registration simply proves that a business entity filed paperwork with a state. It says nothing about who controls…

Loyalty Program Fraud Prevention in Travel is an Identity Problem

Loyalty Program Fraud Prevention in Travel is an Identity Problem

When a rewards balance disappears, the loss becomes visible at redemption. Miles may be transferred to a partner program, points converted into gift cards, or award travel booked without the account owner’s knowledge. By the time that happens, however, the loyalty program fraud has already succeeded. The real questions arise…

Understanding and Defending Against Vishing Attacks in 2026

Understanding and Defending Against Vishing Attacks in 2026

Most vishing defenses assume the attacker is after a password. The campaigns causing the most damage in 2026 rarely ask for one. Instead, they persuade a help desk representative to enroll a new phone number or convince a user to approve a connected application. The login that follows appears legitimate…

Governing Agentic AI Agents: What Your Identity Team Needs to Plan for Now

Governing Agentic AI Agents: What Your Identity Team Needs to Plan for Now

When an agentic AI agent acts on a user’s behalf, most current deployments run it with that user’s privileges and record its activity under the user’s identity. The agentic AI agent itself disappears into the session. That design choice creates the core challenge of governing agentic AI. Two distinct principals,…

AI-Powered Cyber Fraud Detection: What’s Real, What’s Hype, and What Truly Matters for Enterprises

AI-Powered Cyber Fraud Detection: What’s Real, What’s Hype, and What Truly Matters for Enterprises

The Federal Bureau’s (FBI’s) 2025 Internet Crime Complaint Center (IC3) Report logged $20.9 billion in cybercrime losses across more than one million complaints. For the first time in the report’s 25-year history, the FBI identified AI as a distinct crime category: 22,364 complaints and $893 million…

Designing a Healthcare CIAM Strategy That Balances Patient Access and Identity Security

Designing a Healthcare CIAM Strategy That Balances Patient Access and Identity Security

The Office of the National Coordinator for Health Information Technology (ONC) reports that in 2025, 65% of individuals accessed their health records online, 57% used app-based access, and 51% used proxy or caregiver access. Those numbers mean patient identity infrastructure now serves a population that varies…