Criminals are increasingly aware of the signals banks use to identify “good customers”—and they are using that knowledge to evade detection.
At the same time, legitimate customers are adopting behaviors that were once considered tried-and-true risk signals. Data breaches and privacy concerns, for example, have spurred many consumers to use VPNs, a behavior that was once viewed as a reliable fraud red flag.
The result is a growing inversion of traditional fraud signals: legitimate customers can look suspicious, while sophisticated criminals can appear trustworthy.
In a recent PaymentsJournal podcast, Diarmuid Thoma, Head of Fraud and Data Strategy at AtData, Jose Pallares, Senior Director of Product Management at Experian, and Jennifer Pitt, Senior Fraud Management Analyst at Javelin Strategy & Research, discussed the convergence of these patterns and how they are reshaping the fraud landscape.
This ambiguity has created an environment in which bad actors are thriving and consumers are losing confidence in financial institutions. To combat this threat, financial institutions must adopt methods that are both broader and more granular to accurately identify fraud.
The Rise of Manufactured Trust
Technology has accelerated this shift, but the underlying challenge is familiar. Whenever fraud systems learn to identify certain behaviors, criminals adapt to avoid them.
“Back when I was doing fraud review 20 years ago, if somebody was on a mobile device or a mobile number, that was slightly riskier because landlines were safer statistically,” Thoma said. “Whereas now if you gave a landline, that’s kind of a weird thing. There’s a natural part to that, and people have to keep that in mind, there are these shifts and profiles evolve.”
In the past, the prevailing fraud prevention philosophy was to build models capable of detecting abnormalities and inconsistencies. However, criminals are all too aware of this strategy, and it has instead become a blueprint for avoiding detection.
Artificial intelligence has also allowed bad actors to deploy these tactics at scale. With a few prompts, even technologically unsophisticated criminals can generate multiple synthetic profiles and manage them at scale.
They are also becoming more patient and strategic in how they carry out illicit activities.
“Once they had an account, they used to run up the account quickly, do a bust-out, and then run away,” Pitt said. “They don’t do that as much anymore. What they do is they make the account look legitimate over time. To skirt the detection on the forefront, they’re building up that identity with non-financial accounts. They might open up an email account, and once that identity becomes legitimized and verified at one organization, other organizations see it as more legitimate. It’s building that credit profile.”
These capabilities have allowed bad actors to manufacture trust at a time when it is more difficult than ever to discern an individual’s intentions. This is partly because consumers have also rapidly adopted technologies like AI and social media, especially among younger and more digitally native generations.
“The behavior profile of a good consumer is completely different than it was even five years ago,” Pallares said. “Fraudsters now think or look like good consumers, and consumers—from a fraud systems angle—look completely messy and risky. So how do we level up our existing fraud systems to catch and look at those things differently?”
The Compounding Effects of Misclassification
Beyond potential fraud losses, gaps in fraud infrastructure often cause legitimate customer activity to be misclassified as fraudulent. As a result, the customer experience suffers.
These errors often occur at a time when organizations’ relationships with customers are most tenuous.
“There are a lot who from early account set up are coming in and they’re spending a lot,” Thoma said. “They’re doing exactly what you’d be worried about from a commercial point of view, somebody comes in and spends a lot very fast and that’s concerning.”
This exemplifies one of the main drivers of false positives: verification often hinges on a single transaction, point in time, or identity element.
This short-sighted view can create significant issues for all customers, particularly high-value users. Their behaviors may raise numerous flags, as they may travel frequently, use multiple devices, and leverage a variety of payment methods.
“I’ve seen from a bank perspective that good customers were off-boarded because there were signals that they thought were fraud, and it was essentially a false positive where identity elements were flagged as fraud that really weren’t,” Pitt said. “And I’ve seen bad customers get on-boarded because of the same thing. Basically, the decision was wrong, and I’ve seen that a lot.”
Left unaddressed, these issues can lead to friction, abandonment, and reduced lifetime value, creating a compounding effect on operations and, ultimately, revenue.
This revenue drain can go unnoticed by financial institutions. While many institutions have processes in place to measure fraud, there is often no ready gauge for fraud misclassification.
“I think it’s probably a lot bigger than what we think because we just can’t measure it with any degree of accuracy,” Pallares said. “To compound the problem, there are fraud models that are being fed data, and these edge cases that result in false positives don’t make it into the fraud models for behavior. What you’re being measured on doesn’t allow for these edge cases to reduce the risk on those types of consumers.”
Trust Is Not Binary
The answer is not to abandon fraud signals, but to put them in context. A single transaction, device, or identity element can raise a question, but it shouldn’t determine whether a customer is trustworthy.
Financial institutions should take a longitudinal approach to fraud identification, looking at how a customer’s behavior develops over time. Consistent identity markers, such as a longtime email address, established device, or history of legitimate activity can provide valuable context that an isolated anomaly can’t.
This also requires fraud models that can adapt as consumer behavior changes. A behavior that once indicated risk may become commonplace, while new patterns may emerge as technology and consumer habits evolve.
“Trust is not binary, it’s built,” Pallares said. “You have to look across your different consumer touchpoints and what a consumer is doing, instead of saying, ‘I verify them at account opening, go wild.’ And trust can be revoked. Anytime something looks out of the ordinary and it’s not verified, there’s certain lightweight controls that people can put in place to make sure that once-verified is not always-verified.”
That broader view can’t always be found with a single institution. Fraud, payments, and customers experience teams need to share data and intelligence so that decisions are based on a more complete understanding of the customer. Extending that approach across institutions can provide an even stronger defense, particularly as fraudsters move between organizations and manufacture identities across multiple accounts.
“When we talk about siloes, it’s within organizations, but it’s also across organizations and across different industries that we need to be sharing,” Pitt said. “Have they been flagged before at another organization? Wouldn’t that help your organization to know if it’s been flagged before, because you wouldn’t onboard that identity? Right now, the exact same synthetic might be used at 100 different banks because fraudsters know that banks aren’t talking.”
The challenge is determining which signals represent legitimate complexity and which indicate coordinated fraud. A consumer with little financial history may simple be new to the system, while someone who rapidly establishes connections across multiple organizations may warrant greater scrutiny.
The goal, then, is not to find customers who look perfect on paper. It’s to identify customers whose identities and behaviors have been earned over time.
Trust Has to Be Earned
In a fraud environment where appearances can be manufactured, history becomes one of the most valuable indicators of trust. Financial institutions need the technology, data, and partners to uncover that history and distinguish between customers who look trustworthy and those whose identities and behaviors have earned that trust over time.
“When you’re selecting them, it has to be an uncorruptible history because now AI can create history in certain fields,” Thoma said. “In your vendor selection, you look for stuff that can give you the history that is isolated from that, that cannot be replicated, that cannot be created within a week or two and generated. It’s earned history, and that’s really important.”







