Product
Platform
Platform
Platform
Developers
Quickstarts
Resources
Explore
Pricing
Download
get a demoLogin

Account takeover prevention fails when the system treats a valid credential as proof of a valid person. This webinar examines how credential stuffing, phishing, SIM swapping, stolen sessions, synthetic identity fraud, and weak recovery flows exploit that assumption. It then shows how risk-based authentication and continuous signal evaluation can catch what the login screen misses.


.png)
Hey, folks. We'll give people just a couple more minutes to filter in here, and then we will get started with our webinar.
Okay. Hi. Welcome. I'm Brad McCarty. I lead product marketing here for FusionAuth, and I'm pretty thrilled today to be joined by Ken Michie, CTO at Fideo Intelligence. We're gonna talk about tackling the critical challenge of AI-powered fraud.
Ken leads the technical team at Fideo Intelligence. They're a platform that processes billions of daily signals across 3,000,000,000 identities — kind of a scale that you need to combat automated attacks where fraudsters use AI to mimic user behavior and weaponize breach credentials.
So, Ken, welcome.
Yeah, thanks, Brad. Big thanks to FusionAuth for having me on stage today. You guys have a great product.
There's a lot going on in this space around authentication and fraud prevention, and that's what I want to talk to you about today. Having an authentication solution is not always exactly what you need to prevent fraud.
Authentication is great at confirming that the right credential is being used to allow somebody access to a system or sign up for an account. But obviously, it's not the only way to confirm that the person behind the credential is legitimate, and fraudsters are starting to exploit that gap.
Fraud itself has become a lot more scalable and harder to spot. Attackers are using automation and data from past breaches to target companies in bulk. They're also using all the new generative tools that sound and appear to be human. This means that social engineering messages are well written, personalized, and believable. It's not as obvious as it used to be to detect them. There used to be obvious tells — a misplaced comma or grammatical error — that we could all detect. But now it's becoming harder and harder to tell. And in these cases, it's not that authentication is the failing point. People are actually able to log in. It's just that attackers are now learning how to get around authentication and using other techniques to gain access to someone's account or create a fake sign up.
So just to look at a few examples — there are a lot of ways these attackers work, but here are maybe five I wanted to focus on.
The first one is credential stuffing. You may notice that hundreds of customers are complaining about new profiles appearing in their accounts — people are logging in who actually didn't log in. Attackers are using breached email and password pairs to log in to other people's accounts. Sometimes there's actually a person behind it; other times they're just fanning them out to bots. In this case, the credentials were correct, but the authentication system still allowed these people — who may not even be real people — to log in. That's credential stuffing.
As I alluded to above, with phishing and social engineering, a user gets an email that looks like it's from their bank. It says a charge failed and asks them to reenter their password. In that moment, the attacker collects the password and then uses the phone to get the two-factor authentication code — all before the actual person realizes what's happened. In the same way, fraudsters are also targeting employees. They're impersonating executives, cloning voices, and using realistic chat messages. All of this is hard to detect without behavioral or network-based signals.
The third one is SIM swapping, or porting attacks. If someone uses a phone as part of their identity or sign-up process, that can be an attack vector. What it might look like is someone suddenly losing service on their phone. The attacker has convinced the carrier that they're the actual account owner, ported it to a different carrier and account, and then once they control the phone, they can use the reset password capability to receive all SMS codes and take over the account. Again, authentication is working — there's just another layer missing to detect the real person.
The next one is synthetic identities. Synthetic identities are a mix of real information with fake information, or even information from multiple people combined. That's why they call it a synthetic identity. These are a really big problem in the financial sector — people trying to gain access to money, like getting a loan or opening a bank account. What they do is create these accounts and just sit on them. Over time they don't do anything suspicious, but they're slowly building credit and credibility. Then finally the bank says, hey, why don't we offer this person a loan? They've been a good, loyal customer for a year or two. And the person controlling the account — who isn't a real person — takes the loan and disappears. Again, these are valid sign-up methods, but you don't have enough information to prevent it.
And lastly, account recovery fraud: you need to recover your account, you forgot your password. Attackers exploit the weak links in that recovery process, similar to SIM swapping. They contact support, pose as the account owner, request a reset, and once they get in, they can take over the account and potentially drain a bank account.
So why isn't authentication enough? It doesn't ask if the account has been exposed in a breach. We're not asking if the device is trustworthy. We're not really knowing if the session they're coming in from is from an unusual place. And even cookies — once you've signed in, even your cookies can be leaked through malware. I've actually seen cases where you're able to capture someone's cookies, ship them over to another browser, install them on the site, and log in just as that person had. It's kind of scary.
All these blind spots are leading to an increase in account takeovers, and they're really having an impact on customers. They're creating a lot of operational strain and ultimately costing money. Teams are spending time investigating, refunding, and communicating incidents instead of improving products or managing growth. Support teams are spending hours trying to reconcile compromised accounts. Compliance teams have to get involved with their own documentation and incident management, and all of this causes engineering to slow down as well. It's not just a security issue — it's an efficiency and customer trust issue. If people are getting into your accounts, that affects your brand.
The industry has historically been fragmented into different buckets: authentication, identity verification, and fraud prevention. FusionAuth is amazing at the authentication side, and over at Fideo Intelligence, we're getting pretty good — if not amazing — on the fraud detection side. Bringing authentication, verification, and fraud detection together allows for a really coordinated defense. They're complementary. We're both seeing the same information coming in. One dimension is asking: is this person provisioned, is this person real in my account, do I trust what they put in? The other is asking: is the information they provided trustworthy? We're looking at the same problem from two different lenses.
Let's see.
Just to mention this too, because I covered a wide gamut of where fraud can occur — it's not always in the same spot. So there's a lot to look at across the typical customer journey.
There's a lot you can learn before the account is even created. You can look at whether the email being provided is brand new, whether the credential has appeared in breached data, or whether this looks like an automated account sign-up flow. But then as you get through the first few stages, you start looking at what's going on during the process. This is where you can look for signs of synthetic identities — combining that with document checks, device and carrier data, and looking at repeated patterns happening across all those identifiers. Maybe someone is creating fake accounts, fanning them out across a lot of bots, and trying to sign up on a lot of different sites. In our case, we see this with banks and loan platforms where the same email — just created — is being used to sign up for a bunch of different bank accounts or trying to get access to loans. That's a real problem.
Then you get to the login and authentication phase. Okay, they've created an account — now let's link the authentication outcome with that device and look at the behavior. If a valid login has happened from a new device behind a proxy, we can flag it for what we call step-up verification. You can look at the details and see if they make sense with respect to what was established when the account was created. More specifically, looking at the IP or even the time of day — if someone is always in the United States and then suddenly needs to log in from a different country in Europe, maybe it's legit, but it's also something you could flag, especially if it happens in quick succession. We call that impossible time travel.
After authentication, you can also look at what's happening within that login session. Always continue to evaluate activity and look for changes in the account — someone trying to add another email, add another phone number, or change the name. All those things could be totally valid, but they're also things to pay attention to. And again, you want to look at what's being provided in conjunction with everything else you already know.
The last thing I'll touch on is account recovery. Using cases where someone has stolen the email or the phone, or used a porting event — porting the phone number to a different carrier — those are all things you can pay attention to. Really, you just want to treat all unusual recovery attempts as higher risk. It's always ongoing. Just because you let them in the first time doesn't mean they're going to be good forever.
Before I wrap up, here's a quick real-world example. Information breached from someone's identity ends up on the dark web. Hackers pay attention, and they can buy these datasets for pennies on the dollar — it's pretty amazing how cheap a lot of our own information is. It might include emails, names, addresses, even social security numbers. Knowing if someone's identity has been breached — which most of ours has — and knowing which elements have been breached is actually really important. Paying attention to all of that when people are signing up, changing their account, or trying to prevent account takeover is critical.
In closing: fraud prevention complements authentication by providing ongoing context and coverage across the entire customer lifecycle. Three main points — fraud methods are continuing to evolve, it's no longer just static authentication, and we need to be able to adapt. Authentication is essential, but it's only one layer. There are multiple layers to this stack. And continuous, multi-signal risk detection reduces fraud losses and operational strain. That's actually why we created our product called Verify — because it looks at all of those things in conjunction. We know a lot about emails, we know a lot about phones. We know how long an email's been in use, how long a phone's been tied to a person. All of that combined can help generate a risk score to say: this operation, where someone is trying to change or add an email, is now pointing to a different identity. That's kind of weird — maybe we should slow down and verify whether it's actually legit.
That's all I've got for you. You can try us out with 100 free identity checks and kick the tires yourself.
Awesome. Ken, thanks so much. A couple of questions that rolled in as you were talking. We were talking about signals — what kinds of signals tend to be the most predictive of fraud risk today?
Yeah. There's a lot of information that gets provided on account sign-up or as part of changing an account. But typically it involves your phone or your email. The IP address is still relevant — I know IPs are changing and being masked more and more, but when they're not masked and you can attribute a location, or you know they're using a VPN or a data proxy, those can all be important signals. Specific to email: just knowing if it's deliverable — if you send an email to that address, is it even valid? Is it going to be responded to? The phone is kind of similar — you get the SMS codes. And really, it's just looking at the whole picture together.
Right. One of the things we talk about a lot here is that the more secure your authentication becomes, the more friction you can introduce for users. So how do you balance adding fraud checks without creating additional friction?
Yeah, it's like finding that magical balance point for sure. What we've found is that the more you can break it up — have an orchestration process where, say, you put in the email — I think you may call this a progressive sign-up or registration flow — if you put the email in, you can call a system like ours and say, this is a low-risk email address, so move them on to the next step. And then the next stage says, okay, give me your name and phone. You provide that, and then maybe in that moment we're like, wait — this email and this phone look legit, but I don't think they belong together. So you can offer a different verification path at that point. Really, it's an orchestration flow where you can customize the journey based on what you see, without saying: give me all your information upfront and then I'll decide. Maybe the phone is good, you make them do the SMS code, they come back with the right code, and you're like, okay, that checked out. But you didn't abort right away. So it's that balance of orchestration and a step-by-step approach that we've found to be most successful.
Yeah, and I think that speaks to having open platforms where you can connect API to API and integrate those calls directly with your existing systems. You talked about the journey — where in that customer journey do you really see fraud prevention adding the most value?
Yeah, it applies to all stages, but if you can head it off at the beginning, that can save you a lot of pain downstream. Having those prechecks upfront can be really impactful. Ironically, in other cases, some of the customers we've worked with are actually less concerned about that upfront prescreen and more concerned about the back-end activity that happens after they have the account. They may have a bunch of fake accounts in their banking platform, and that's not great — but it's only a problem when those fake accounts start trying to sign up for loans later. At that point, they can start looking at the activity happening after the sign-up flow. So it kind of depends on your industry and what your product is.
So how are fraudsters using AI and automation to get past traditional defenses? Are we looking at new versions of something like a DDoS attack, just flooding the zone — or what's the answer there?
Yeah, it depends on the sign-up flow you're encountering. But AI makes it a lot easier to identify what type of synthetic identity to create. You may not have to be as creative upfront — the AI will say, you should go create a Google Voice number, create this email over there, and you can get instructions on where to maybe find information you shouldn't be able to find. So there's the generative side, just coming up with creative ideas. But there's also the social engineering attacks happening with phishing campaigns where someone sends an email to you, Brad, but you didn't actually send it — someone crafted it in your tone and made it look just like you. That can then have a lot of downstream effects — maybe the person on the other end offers up too much or does click on that link, and that can kick off a whole different type of security incident.
Interesting. It's fascinating stuff. I love the parallels between what you guys are doing at Fideo Intelligence and what we do here at FusionAuth. Thanks for your time today, Ken, and for your expertise bringing this new world of identity and fraud verification into our world as well. I appreciate it.
Absolutely. I appreciate the opportunity. Thank you all for attending.
Thanks, everyone, for showing up today.