Category: Fraud prevention

Social Engineering Tactics in Cybersecurity: The Enterprise Defense Playbook

Social Engineering Tactics in Cybersecurity: The Enterprise Defense Playbook

Identity weaknesses played a material role in almost 90% of the 750-plus incidents Palo Alto Networks’ Unit 42 investigated in 2025, with 65% of initial access driven by identity-based attacks. This was not solely because those organizations lacked multi-factor authentication (MFA) or security training. Rather, attackers…

Designing a Call Center Fraud Prevention Program: From Agent Training to Automated Controls

Designing a Call Center Fraud Prevention Program: From Agent Training to Automated Controls

Every enterprise call center fraud prevention program faces the same design tradeoff: how much of the identity verification burden should rest on agents, and how much should shift to automated controls? Most organizations still lean heavily toward the agent side. They invest in training, create verification scripts, and assume that…

How ID Dataweb Enables IAL2-Compliant Identity Proofing at Scale

How ID Dataweb Enables IAL2-Compliant Identity Proofing at Scale

In July 2025, the National Institute of Standards and Technology (NIST) released the final version of Special Publication (SP) 800-63, Revision 4. This update reflects nearly four years of research, two public draft cycles, and close to 6,000 public comments. The revision defines updated Digital Identity Guidelines designed to…

Risk Signal Strategy: Which Signals Matter for Each Identity Fraud Type

Risk Signal Strategy: Which Signals Matter for Each Identity Fraud Type

Most enterprises collect more authoritative identity data and risk signals than they act on. They also lack clearly defined relationships between specific risk signals and specific identity fraud types. A device fingerprint that is effective against credential stuffing may be irrelevant for synthetic identity fraud. A phone number check that…

When Out-of-Band Verification Becomes a Weak Link

When Out-of-Band Verification Becomes a Weak Link

For years, Short Message Service (SMS) one-time passwords (OTP) worked well enough. If you could receive a code at a phone number, you likely controlled the account. When porting required showing up at a carrier store with ID, that assumption generally held. It no longer does. The Cybersecurity and Infrastructure…

5 Signs Your Enterprise Is Vulnerable to Account Takeover Fraud

5 Signs Your Enterprise Is Vulnerable to Account Takeover Fraud

Many organizations do not miss account takeover attacks because they lack controls. They miss them because they interpret the wrong risk signals or reduce useful signals to a simple pass-or-fail outcome. The issue is not only whether a credential, device, phone number, or recovery factor can be validated. It is…

Reducing SMS Authentication Risk with Identity Threat Detection

Reducing SMS Authentication Risk with Identity Threat Detection

Most enterprise teams already understand the critiques of Short Message Service (SMS). Codes can be intercepted, phished, or redirected. Yet phone numbers remain embedded in too many critical flows. They are still a standard recovery channel and second-factor authenticator. The problem is that a phone number is not a stable…

Phishing-as-a-Service Is Fueling Identity Compromise. Identity Threat Detection Is the Response.  

Phishing-as-a-Service Is Fueling Identity Compromise. Identity Threat Detection Is the Response.  

Phishing-as-a-service has turned identity abuse into a supply chain. Attackers no longer need deep technical skills to run phishing infrastructure. For defenders, keeping pace is difficult without visibility across the entire identity ecosystem.

Document Fraud Detection: Strategies for Enterprise Security Teams 

Document Fraud Detection: Strategies for Enterprise Security Teams 

Effective document fraud detection requires layered defenses. Only through risk signal correlation can enterprises move beyond false confidence and achieve measurable fraud reduction.  

Credential Compromise is the Leading Attack Vector: Why Enterprise Security Must Shift to Identity Threat Detection 

Credential Compromise is the Leading Attack Vector: Why Enterprise Security Must Shift to Identity Threat Detection 

Some of the most disruptive breaches in recent years began with nothing more than a compromised credential. Organizations that continue to focus primarily on perimeter controls and point-in-time authentication are defending against an outdated threat model.