Article

Identity verification and fraud prevention: The hidden risk behind verified customers

Verification tells you a customer is who they say they are. It says nothing about what they'll do with that identity next.

September 1st, 2026
 ·  5 minutes
Shopping online at home on laptop

According to our 2026 Fraud Report, the fastest-growing fraud today doesn't come from unknown actors. It comes from known, verified customers on recognized devices, and most businesses aren't set up to catch it.

For years, identity verification and fraud prevention have been treated as the same problem: Confirm someone's identity, and the risk is largely contained.

That logic holds when fraud comes from stolen or fake credentials. But it doesn't account for fraud that comes from real, verified people behaving differently than expected. In this article, we'll draw on our fraud report, based on a survey of 1,000 US-based enterprise merchant decision makers and platform transaction data, to break down:

  • Why verification alone can't catch this type of fraud

  • The three most common forms of fraud hiding behind legitimate-looking identities

  • How everyday loyalty and promotion incentives are being turned against you

  • What it takes to move fraud detection beyond a single, one-time check

Verification catches identity but misses intent

When you verify a customer, you're confirming their identity against a set of credentials in a single check. That tells you they are who they claim to be. It tells you nothing about what they intend to do with that identity from that point on.

As Jeff Hallenbeck, VP of Customer Advocacy at Adyen, noted, this kind of fraud "has become automated, iterative, and in many cases indistinguishable from legitimate customer activity until you look across time and context rather than at the transaction in front of you."

That's where recognition comes in. Recognition is built over time, based on whether a customer's ongoing behavior continues to match a consistent pattern. A sudden shift, promotions being cycled repeatedly, the same payment details showing up across multiple accounts, would slip past a one-time verification check entirely. A system built to monitor behavior over time would catch it.

Fraud & identity blog article Andrea Ferrari video thumbnail

3 types of fraud hiding in plain sight

This kind of fraud doesn't come from accounts that have been broken into. It comes from real accounts, being used differently than intended. Here's what that looks like in practice.

1. First-party fraud

A customer makes a legitimate purchase, then disputes the charge with their bank, falsely claiming non-receipt, defects, or unauthorized use. It's difficult to catch because the original transaction was genuine. Nothing about it looks suspicious at the point of sale. According to our report, first-party fraud is the most common form of abuse reported, accounting for 44% overall.

Note: First-party fraud is often used interchangeably with "friendly fraud." The distinction is that first-party fraud is always deliberate, unlike a genuine mistake such as forgetting a purchase or not recognizing a charge.

2. Fake accounts and identity abuse

This involves creating or manipulating accounts to access promotions and rewards. A new account might be linked to a real customer but created solely to access a one-time promotion, for example, using a disposable email address to claim the same welcome discount multiple times. Each account can pass identity verification on its own. The abuse only becomes visible once accounts are viewed in relation to each other. Our report puts this at 42% of reported fraud.

3. Policy and promotion abuse

Here, customers exploit merchant policies directly, through:

  • Serial returns:

    Repeatedly buying and returning items well beyond normal shopping behavior

  • Wardrobing:

    Buying an item, using it for its intended purpose, then returning it for a full refund

  • Free trial cycling:

    Repeatedly signing up for free trials, often using different emails or slightly altered personal details, like a middle name or shortened first name, to avoid detection while still being linked to the same person

  • Loyalty point harvesting:

    Creating or manipulating multiple accounts to accumulate loyalty points or rewards

  • Stacking discounts beyond their intended use:

    Combining multiple codes, promotions, or offers in ways the terms weren't designed to allow

This accounts for 40% of reported fraud. Unlike the other two categories, policy and promotion abuse doesn't necessarily involve any deception about identity. It's entirely about intent. One global software company saw a rise in free trial cycling specifically, users signing up with invalid or low-quality payment credentials and no intention of converting. The pattern only became visible at the first billing cycle.

Why your own sales incentives are working against you

Every incentive you create in good faith to build loyalty is also an incentive someone can turn against you. A discount meant to reward sign-ups becomes a reason to sign up repeatedly. A generous returns policy meant to build trust becomes a low-cost way to borrow products for free.

Online communities openly share tactics for maximizing promotions or getting refunds approved. What might once have counted as fraud gets reframed as a loophole, a hack, or simply a smart way to get more value. Many people doing this don't see themselves as committing fraud at all, which makes the problem harder to define, let alone solve.

The cost is real. Nearly 70% of businesses surveyed expect fraud and abuse to limit their ability to grow revenue, and 50% report a rise in false declines as they try to control it.

From one-time checks to continuous fraud monitoring

Catching this type of fraud means moving from point-in-time identity checks to continuous behavioral assessment across the customer lifecycle. Instead of asking whether someone passed verification once, you're asking whether their current behavior still matches what's already known to be trustworthy.

Establishing what counts as normal behavior takes access to large volumes of data, and that data doesn't have to come from your business alone. It's even more useful when you can draw on data from other businesses where the same customer shows up. Adyen processes transactions for enterprise businesses across the globe, which means we can see how a given identity behaves not just with one business, but across many. In practice, there's an 84% chance Adyen has already seen a given shopper before, even if they're new to you.

That kind of shopper recognition means a new customer isn't automatically a blank slate. They could have a long track record of policy and promotion abuse on our platform, and catching that removes the need for manual rules, cutting fraud and operational cost while improving conversion.

None of this is about stronger verification. It's about treating identity as an ongoing signal you can use to spot and stop abuse before it happens.

How Adyen builds a continuous view of identity

A customer's identity carries an ongoing footprint of purchase patterns and activity across online and in-person channels. That footprint builds with every transaction. Because Adyen operates as a single global platform, we're able to connect that footprint across businesses rather than seeing it in fragments.

Shifts in behavior stand out clearly against a pattern built from real transaction history. Our systems are designed to catch those shifts, whether that's a customer suddenly cycling through promotions or spreading purchases across accounts.

That's the thinking behind Dynamic Identification. Rather than treating every customer as unknown until proven otherwise, Dynamic Identification draws on these behavioral signals to spot anomalies and prevent abuse. This is what powers Adyen Uplift, the decision engine behind our fraud and conversion tools, which has driven up to a 6% increase in conversion by reducing false declines without loosening fraud controls.

Fraud defense is a moving target, not a single checkpoint

Verification tells you who a customer is once. It doesn't tell you what they'll do in a week, a month, or a year later. That's exactly where this type of fraud lives, and it's exactly why defense has to go beyond verification.

As Jeff Hallenbeck put it: "Instead of treating identity as something that is verified once and then assumed to remain static, we should view it as a continuous signal that evolves over time and requires ongoing interpretation."

Uncover more fraud trends in our latest fraud report or get in touch to talk to a fraud expert.

Adyen Fraud report 2026 cover image

Read our 2026 fraud report

Download now

Fresh insights, straight to your inbox