When Fraud Found Another Way
There is an old story about a castle that spent centuries making its walls stronger.
Taller gates, deeper moats, guards trained to spot a threat from a mile away. And it worked. Nobody could get through.
The people inside believed they had built something impossible to breach. What they didn’t see coming was the person who walked up to the gate one afternoon, knocked politely, and asked to be let in.
Where It Began
For most of the last decade, the financial industry was building exactly that kind of wall.
Every bank, every lending platform, and every digital payment service was trying to solve the same problem: Fake Identities. People were opening accounts using stolen names, fabricated documents, and stitched-together profiles that looked real enough to pass a basic check.
The industry’s response was predictable:
· Stricter KYC,
· Biometric verification,
· Two-factor authentication, and
· Machine learning models that screened everyone trying to enter.
For a while, the strategy worked. Creating fraudulent accounts became significantly harder, and it looked like the industry had gained the upper hand.
What nobody fully accounted for was what would happen next.
The Real Picture
A recent TransUnion report on digital fraud in India has one number that deserves far more attention than it has received.
India’s suspected digital fraud rate in 2025 was 7.1%, nearly double the global average of 3.8%. That’s the headline most outlets picked up. But buried inside the report is a finding that changes how you read that number:
- Globally, account creation is the riskiest stage, with 8.3% of attempts flagged as suspected fraud.
- In India, the riskiest stage is account login, at 3.9%, compared with 3.1% for account creation.
In other words, the higher risk in India lies in accounts that are already active, rather than in creating new ones.
Why Fraudsters Prefer Real Accounts?
Consider what it takes to create a fraudulent identity from scratch.
You need
- Convincing documents,
- A believable profile, and
- Enough patience to let the account age into something the system will trust.
Meanwhile, the systems you’re trying to fool are getting better at spotting exactly those patterns. It’s expensive, slow, and increasingly likely to fail.
Now look at the alternative!
Millions of accounts have already done all that work.
· They’ve passed KYC,
· Built a transaction history, and
· Established patterns the system recognizes.
And for fraudsters, getting access to one of those accounts is far easier than building one from scratch.
The TransUnion report also points in the same direction.
In the second half of 2025, 59% of Indian consumers reported being targeted by digital fraud, with phishing being the most commonly cited method. Instead of creating fake identities, phishing aims to gain access to accounts that are already trusted.
Where Risk Moved?
Stronger onboarding tightened the door on fake accounts and shifted attacker behaviour. With fewer successful synthetic identities, fraudsters turned to existing accounts that already carry trust and transaction history. The industry response follows that shift: solutions now focus on how users behave after login, using behavioural analytics, continuous authentication, and session-level monitoring to spot unusual activity.
The key question has moved from who enters the system to what happens inside it once access is in place.
The castle story reflects this shift: the structure held against obvious attacks, while risk moved to a quieter point of failure.
Fraud today relies on access to real accounts that passed initial checks and built trusted histories. Strong onboarding raised the bar at signup and lowered entry-stage fraud, while the main risk migrated into active accounts.
The next phase of defence requires detecting and stopping suspicious actions after login, with tools and processes that observe behaviour, verify ongoing legitimacy, and respond quickly when patterns change.
P.S: What topic do you think we should explore next? Let us know in the comments.
