How identity fraud became the threat that never sleeps

1 hour ago 6

Before COVID-19, fraudsters largely operated in line with the standard workweek, active between 9 am – 5 pm and tapering off at the weekends. Then, during the pandemic, fraud started to spike at off-peak times, including late at night and on weekends.

This suggests that fraudsters started to intentionally target businesses when staff weren’t manning the systems, or that they started viewing it as more of an opportunistic or recreational activity.

Today, the pattern has been upended again. In the ever-increasing digital era, AI-assisted tools are not only automating processes for criminals, enabling them to scale operations quickly, but they are also making fraud cheaper and harder to detect. Fraud has now evolved into an ‘always-on’ threat that flows like water, seeking cracks to exploit.

Fraud Specialist Senior Manager at Entrust.

Yet, the latest AI attack vectors have also become somewhat of a distraction for businesses. Simpler, low-tech methods still persist but have become a blind spot in many companies’ security.

The focus on solving the high-tech issue has drawn attention away from the low-tech issue, creating a renewed vulnerability to rudimentary attacks. The key is learning to combat AI-powered identity-based attacks, while also tightening loopholes that are enabling rudimentary fraud attempts to slip through the cracks.

Ultimately, that means implementing a broad set of layers – combining identity verification, biometric authentication, liveness detection, and so on – to catch the different spectrums of attack.

The new face of fraud

Modern fraud is coordinated and intentionally mimics legitimate users and devices to evade detection.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Fraud rings now use automation and device emulation to run high-volume attacks. But rather than launching hundreds of fraudulent applications at once, attackers are submitting small batches over time, enabling them to disappear before issues are identified.

We’re also seeing slight spikes in fraudulent activity from 2-4 am. This suggests deliberate coordination, where attackers are exploiting times when both users and security teams are least likely to respond quickly. This creates a larger window to abuse compromised identities before detection and remediation occur.

Fraudsters are also increasingly exploiting human behavior. There’s been an upward trend in phishing, deepfake impersonations, and romance scams, with each tactic targeting a different vulnerability, whether that’s trust, emotional attachment, or even fatigue. Thames Valley Police has warned that romance fraudsters deliberately keep victims talking late into the night, using exhaustion to erode judgment.

However, businesses have been slow to adapt to the new face of fraud. Because modern users demand speed and simplicity, companies continue to drive UX changes that reduce friction during critical times, like onboarding.

But in many cases, this has become an Achilles heel. Too many organizations are optimized for minimizing user friction without balancing that with continuous protection. They set automated controls which alone are no match for fraudsters who are exploiting human behavior and deliberately operating below detection thresholds.

Two security changes are having a big impact in bolstering defenses against these attacks. First, more adaptive security approaches that detect social engineering signals through behavioral and contextual cues, for example. Second, inserting more varied and unpredictable identity checks that make it significantly harder for attackers to rely on automated or scripted tactics.

Proactive approaches, such as red teaming or fraud simulation exercises, can also help organizations identify weaknesses before they are exploited.

AI has made fraud cheaper, not just smarter

As far back as 2019, AI was used to mimic a CEO’s voice for financial exploitation. Deepfake AI technology has come a long way since then. Injection attacks, where manipulated or synthetic media is fed directly into systems to bypass the camera, surged by 40% in 2025 compared to 2024, and deepfakes now account for one in every five biometric fraud attempts.

That’s because AI has helped to commoditize fraud at a massive scale. AI-assisted tools have lowered the barrier to entry, making it available to anyone with access to a laptop and a credit card.

Fraud-as-a-service platforms sell ready-made kits, credential dumps, deepfakes, and stolen data online. This is one reason why digital forgeries, often created using open-source models, now make up 35% of all fraudulent document submissions.

As these techniques become standardized and widely available, static identity checks (like selfies) are no longer sufficient. An identity that appears legitimate at onboarding can be compromised later on, requiring organizations to continuously verify trust rather than treating identity as a one-time event.

Yet low-tech methods still find success

Despite the increased volume of AI-powered threats, the most common points of entry remain startlingly simple. Many fraudsters still rely on remarkably low-tech methods. For example, in selfie-based identity verification, 90% of attacks involve basic presentation methods, such as using someone else’s photo on a screen, an image of an ID, or showing a printed copy to the camera.

Organizations that focus exclusively on advanced techniques leave themselves exposed to the most basic ones.

By requiring users to move in a specific, unplanned way, systems can distinguish real individuals from 2D images, masks, injected media such as deepfakes, or simple spoofing attempts such as a video of a video or a photo. Partnered with behavioral analysis and real-time risk signals, these tactics provide a strong countermeasure.

As fraud becomes distributed and industrialized, the organizations best positioned to respond will be those that pursue an identity-centric security approach. We need to stop viewing identity checks as a one-and-done moment and start seeing it as an ongoing process throughout the customer journey.

The goal is to make identity security invisible to legitimate users and unavoidable for fraudsters. In a world where fraud no longer sleeps, security strategies can’t afford to either.

We've featured the best authenticator app.

This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit

Fraud Specialist Senior Manager at Entrust.

Read Entire Article