Back to Webinars

Fake People, Real Logins: The Identity Illusion

Date Aired: November 6, 2025

What You’ll Learn

Account takeover prevention fails when the system treats a valid credential as proof of a valid person. This webinar examines how credential stuffing, phishing, SIM swapping, stolen sessions, synthetic identity fraud, and weak recovery flows exploit that assumption. It then shows how risk-based authentication and continuous signal evaluation can catch what the login screen misses.

Key Takeaways:

  • A successful login can still be a security failure. Credential stuffing attacks use real email and password combinations from previous breaches, so the authentication system accepts exactly what it was designed to accept. The problem is not whether the credential works but who is using it.
  • Credential stuffing prevention requires more than checking passwords against a user database. Breach exposure, device history, proxy use, location, login timing, and account behavior can reveal when a technically valid login does not fit the person or session behind it.
  • MFA does not eliminate account takeover. Phishing can capture a password and the second factor in the same session. SIM swapping can redirect SMS codes. Stolen cookies can bypass the login flow entirely. Stronger authentication helps, but attackers increasingly work around it rather than through it.
  • Account recovery is often a second authentication system with weaker controls. Fraudsters exploit support processes, compromised email accounts, stolen phones, and carrier-porting events to reset credentials and take control without defeating the original login flow.
  • Synthetic identity fraud develops slowly by design. Attackers combine real and fabricated information, create accounts that appear harmless, and allow those accounts to build credibility before applying for loans, moving money, or performing another valuable action.
  • Fraudulent account creation can often be detected before registration is complete. Newly created email addresses, recently activated phone numbers, repeated identifiers, automated sign-up patterns, and mismatched identity details can expose coordinated abuse before a fake account becomes an operational problem.
  • Risk-based authentication works by evaluating combinations of signals rather than relying on one suspicious event. A new device may be legitimate. A proxy may be legitimate. A login from another country may be legitimate. All three appearing together deserve more scrutiny than any one signal alone.
  • Step-up verification should follow evidence. Low-risk users can continue without unnecessary friction, while suspicious sessions can trigger another factor, a different verification path, or a temporary pause. Treating every login as equally risky creates friction without creating equal protection.
  • Progressive registration creates multiple points for risk evaluation. An application can assess an email address first, then compare it with a phone number, device, document, or identity record. That makes it possible to change the journey as risk emerges instead of collecting everything upfront and evaluating it once.
  • Account takeover prevention must continue after login. Attackers who gain access often add a phone number, replace an email address, change a name, update recovery details, or prepare the account for later abuse. Post-authentication activity deserves the same scrutiny as the login itself.
  • Fraud controls should be placed where the business actually absorbs risk. Some companies need to stop fraudulent account creation immediately. Others can tolerate dormant fake accounts but must intervene before lending, withdrawals, purchases, or sensitive profile changes.
  • Authentication, identity verification, and fraud detection answer different questions. Authentication determines whether a credential is acceptable. Verification checks whether identity claims appear credible. Fraud detection evaluates whether the current behavior fits what is known about the person, device, network, and account.
  • AI makes familiar attacks easier to scale and harder to recognize. It can help fraudsters construct synthetic identities, personalize phishing messages, mimic executive communication, and generate instructions for building accounts that look plausible enough to survive basic checks.
  • Continuous risk evaluation reduces more than direct losses. Account investigations, refunds, customer notifications, support escalations, compliance documentation, and emergency engineering work all follow a weak identity decision. Fraud prevention is partly a security control and partly a way to stop one bad login from becoming the problem of five different departments.
View Transcript

Who Should Watch This Webinar?

  • CTOs
  • CIOs
  • CISOs
  • Security architects
  • Identity architects
  • Platform engineers
  • Application developers
  • Fraud teams

Topics Discussed:

  • Account takeover prevention
  • Credential stuffing prevention
  • Synthetic identity fraud
  • Fraudulent account creation
  • Risk-based authentication
  • AI-assisted phishing
  • SIM swapping
  • Session cookie theft
  • Account recovery fraud
  • Breached credential exposure
  • Device and network signals
  • Email and phone intelligence
  • Impossible travel
  • Progressive registration
  • Step-up verification
  • Continuous session monitoring
  • Post-login account changes
  • Authentication and fraud detection

Speakers:

Ken Michie Photo
Ken Michie
CTO, Engineering & Product, Fideo
Ken Michie has spent his career building the infrastructure that identity systems depend on, including distributed architectures, large-scale data pipelines, and the engineering foundations that make reliable identity resolution possible at scale. He holds five US patents, a master's degree in computer science, and dual bachelor's degrees in computer engineering and computer science. Ken has led global engineering teams across multiple continents, tackling the kinds of problems where "millions of records" is a starting point, not a ceiling. He's equally comfortable debating architecture trade-offs as he is building things himself.
Brad McCarty Photo
Brad McCarty
Sr. Product Marketer, FusionAuth
Brad McCarty has a theory about identity marketing: most of it fails because it's written for everyone, which means it's useful to no one. His own work takes the opposite approach: Migration case studies documenting why organizations leave legacy providers like Auth0 and AWS Cognito, infrastructure guides on building scalable CIAM with modern cloud platforms, and market analyses like the G2 Winter 2026 Grid Breakdown, tracking real shifts in how developers are choosing identity infrastructure. He presented the FusionAuth or Keycloak Decision Framework webinar to help engineering teams work through total cost of ownership trade-offs, and led the live reveal of the 2026 State of AI & Identity Report. He's been doing this long enough to know that the gap between what a product does and what a sales team can explain is where deals are won or lost.
Featured TechPaper
How to Avoid Breached Passwords
get tech paper
FusionAuth graphic titled "Breached Password Detection for Your Organization" with a warning icon.
Share this post
Watch  On-Demand
Subscribe to The FusionAuth Newsletter
Get updates on techniques, technical guides, and the latest product innovations coming from FusionAuth.