Article

Identity verification and fraud prevention: Why your customer’s identity is only part of the story

Verification confirms who a customer is but it doesn't confirm what they'll do next. Fraudsters are exploiting this gap, here’s what you can do about it.

August 2nd, 2026
 ·  5 minutes
Abstract digital illustration of interconnected 3D blocks and data points, representing data or payments

What if most of your fraud is coming from known, verified customers on recognised devices? According to our 2026 Fraud Report, this is a fast-growing issue for businesses who are struggling to keep up. 

That’s because identity verification and fraud prevention have traditionally been treated as the same problem. That approach makes sense when fraud comes from stolen or fake credentials. 

But, with this new type of fraud, it’s no longer enough to confirm who someone is. You need to understand what they intend to do with that identity over time.

In this article, we'll draw on our fraud report, based on a survey of 1,000 US-based enterprise merchant decision makers and platform transaction data, to unpack how fraud is changing. We’ll cover:

  • Why identity verification isn’t enough on its own any longer

  • The three most common forms of fraud hiding behind legitimate-looking identities

  • How your loyalty incentives are being exploited

  • How you can level up your fraud checks from a single one-time verification

Uncover more fraud trends in our latest fraud report or get in touch to chat to a fraud expert.

Why identity verification alone no longer works

When you verify your customer, you're confirming their identity in a one-off check against a set of credentials. In doing this, you can be sure they are who they say they are. However, to understand their intent, you need something else: recognition. 

As Jeff Hallenbeck, VP of Customer Advocacy at Adyen, noted that this kind of fraud "has become automated, iterative, and in many cases indistinguishable from legitimate customer activity until you look across time and context rather than at the transaction in front of you."

Recognition is built over time, based on whether a customer's ongoing behaviour continues to match a consistent pattern. A sudden change in behaviour would be missed by a one-time verification check but would be caught by a tool that monitors behaviour patterns.

Fraud & identity blog article Andrea Ferrari video thumbnail

Andrea Ferrari, Sr. Product Manager, explains how Adyen's approach to dynamic identification shifts the focus from who is transacting to what they're trying to do.

3 types of legitimate-looking abuse

This new type of fraud doesn't come from accounts that have been broken into. It comes from real accounts, being used differently than intended. Here's what each looks like in practice:

First-party fraud

First-party fraud is when a customer makes a legitimate purchase and then disputes the charge with their bank, falsely claiming non-receipt, defects, or unauthorised use. It's hard to catch because the original transaction was genuine. Nothing about it looks suspicious at the point of sale. According to our report, this type of fraud is the most common form of abuse in the US, accounting for 44% overall.

Note: First-party fraud is often used interchangeably with ‘friendly fraud’. The difference is that first-party fraud is always deliberate rather than someone genuinely forgetting a purchase or not recognising a charge.

Fake accounts and identity abuse

Fake accounts and identity abuse involve creating or manipulating accounts to access promotions and rewards. A new account might be linked to a real customer but created only to access a one-time promotion, for example, using a disposable email address to claim the same welcome discount several times Each account passes identity verification on its own and the abuse only becomes visible when accounts are viewed in relation to each other. According to our report, fake accounts and identity abuse account for 42% of reported fraud in the US.

Policy and promotion abuse

In this instance, the customer is exploiting your policies directly, through: 

  • Serial returns: Repeatedly buying and returning items well beyond normal shopping behaviour.

  • Wardrobing: Buying an item, using it for its intended purpose, then returning it for a full refund.

  • Free trial cycling: Repeatedly signing up for free trials, often using different emails or slightly altered personal details, like a middle name or shortened first name, to avoid detection while still being linked to the same person.

  • Loyalty point harvesting: Creating or manipulating multiple accounts to accumulate loyalty points or rewards.

  • Stacking discounts beyond their intended use: Combining multiple codes, promotions, or offers in ways the terms weren't designed to allow.

According to our report, policy and promotion abuse accounts for 40% of reported fraud. However, unlike the other two, policy and promotion abuse doesn't necessarily involve any deception. It’s all about intent. For example, one global software company saw a rise in free trial cycling with users signing up, often using invalid or low-quality payment credentials. The issue only became visible at the first billing cycle.

The incentive problem hiding in your policies

Every incentive you create in good faith to build loyalty is also an incentive someone can turn against you. A discount meant to reward sign-ups becomes a reason to sign up repeatedly. A generous returns policy meant to build trust becomes a low-cost way to borrow products for free. 

Online communities openly share tactics for maximising promotions or getting refunds approved. What might once have counted as fraud gets reframed as a loophole, a hack, or simply a smart way to get more value. Many people doing this don't see themselves as committing fraud at all, which makes the problem harder to define, let alone solve.

This is translating into real losses. Nearly 70% of businesses surveyed expect fraud and abuse to limit their ability to grow revenue, and 50% report a rise in false declines as they try to control it.

Shifting from one-time identity checks to ongoing monitoring

Catching this type of fraud means moving from point-in-time identity checks to continuous behavioural assessment across the customer lifecycle. In this way, you can see if their current behaviour still matches a recognized pattern.

To establish what counts as normal behaviour, it helps to have access to large volumes of data. This doesn't have to come from your business alone. It's even better if you can draw on data from other businesses where this customer is also showing up. Adyen, for example, processes transactions for enterprise businesses across the globe, which means we can see how a given identity behaves not just with one business, but across many. In practice, there's an 84% chance Adyen has already seen a given shopper before, even if they're new to you. That shopper recognition means a new customer isn't automatically a blank slate. They could have a long track record of policy and promotion abuse on our platform, and spotting that removes the need for manual rules, cutting fraud and operational cost while improving conversion.

None of this is about stronger verification; it's about treating identity as an ongoing signal that you can use to spot and stop abuse even before it happens.

Adyen’s dynamic approach to identification

A customer’s identity carries an ongoing footprint of purchase patterns and activity across online and in-person channels. Their behavior forms a picture that builds with every transaction. Because Adyen operates as a single global platform, we're able to connect that footprint across businesses rather than seeing it in fragments. Shifts in customer behaviour stand out against a pattern built from real transaction history. Our systems are designed to spot these changes, like when a customer suddenly starts cycling through promotions or spreading purchases across accounts.

That's the thinking behind Dynamic Identification. Rather than treating every customer as unknown until proven otherwise, Dynamic Identification draws on these behavioural signals to spot anomalies and prevent abuse. This is what powers Adyen Uplift, the decision engine behind our fraud and conversion tools, which has driven up to a 6% increase in conversion by reducing false declines without loosening fraud controls.

Fraud defence is a moving target, not a single checkpoint

Verification tells you who a customer is once. It doesn't tell you what they'll do in a week, a month, or a year later. That's exactly where this type of fraud lives, and it's exactly why defense has to go beyond verification. As Jeff Hallenbeck put it: "Instead of treating identity as something that is verified once and then assumed to remain static, we should view it as a continuous signal that evolves over time and requires ongoing interpretation."

Uncover more fraud trends in our latest fraud report or get in touch to chat to a fraud expert.

Identity verification and fraud prevention FAQs

First-party fraud is when a customer makes a legitimate purchase, then disputes the charge with their bank, falsely claiming non-receipt, defects, or unauthorised use, despite receiving exactly what they paid for.






Fresh insights, straight to your inbox

Subscribe to email alerts