Fraud Article

Fraud doesn’t stand still. Neither should our response to it.

The problem with known fraud? New fraud doesn’t have to look familiar. Traditional rules and crosslinking are powerful tools, but they rely on patterns we already know. And that leaves a window for emerging attacks to get through.

Fraud prevention has always involved a race against change. Fraudsters find a way around a control. We identify the pattern, build a rule, and stop it. Then the cycle starts again.

That model remains important. But fraud is evolving faster, and I think it’s worth being honest about where the traditional approach runs into limits.

The problem with fighting known fraud

Rules-based systems and crosslinking are core components of our broader fraud prevention system. Rules help us identify patterns we’ve already learned to associate with fraudulent activity, for example, a combination of VPN use and a fraud-prone document type. Crosslinking connects activity across verifications, surfacing relationships that aren’t visible when looking at a single attempt in isolation.

But both capabilities share something in common: they depend on prior knowledge. A rule can only stop an attack that resembles something we’ve already documented. Crosslinking reveals a trail only after one has been left.

A new attack doesn’t have to look like the last one. Fraudsters can experiment with fresh techniques, combine existing methods in unexpected ways, or introduce characteristics that haven’t previously been associated with fraud. That creates a window between the first signs of an attack and the moment defenses adapt. A window that a determined fraudster can exploit.

When a new technique works, it gets tested again. If it keeps working, it gets refined and scaled. The window between discovery and adaptation is exactly where that scaling happens.

This is why I’ve come to think that the time-to-adapt, how quickly fraud prevention can respond when something new appears, is one of the most important dimensions of the problem. It’s not enough to ask whether we can eventually detect a new attack. We also need to ask how much time the attack has to scale before we can respond.

Adaptive Intelligence in Action

Read the Global Mobility Case Study

Discover how Veriff’s fraud detection helped a global food delivery platform cut fraud and streamline driver onboarding.

What signals can tell us

One way to make fraud prevention more adaptive is to look beyond the identity evidence itself.

Every verification takes place in a broader environment. The device being used, the network it connects through, and the technical characteristics of a session. As media injection and deepfake techniques become more sophisticated, this surrounding context becomes increasingly valuable.

A deepfake may be visually convincing. A coordinated fraud campaign may be hard to detect from any single verification. But the device and network signals associated with fraudulent sessions often exhibit patterns that are detectable at the aggregate level, even when individual attempts look unremarkable on their own.

No single signal tells you an attempt is fraudulent. But patterns across fraudulent activity can reveal characteristics associated with an emerging attack: characteristics that begin to appear before the attack is fully understood.

That creates an opportunity: to learn from what is happening now, rather than relying exclusively on patterns established in the past.

An adaptive layer built on recent signals

The approach I’ve been working on at Veriff is built around this idea. The system learns from recent device and network signals observed in fraudulent activity identified by other fraud prevention systems, and uses that intelligence to automatically adapt protection, without waiting for a human to manually identify the pattern and write a new rule.

The signals can extend beyond the device and network. For example, the system can identify when a document field, such as a date of issue, repeats unusually often across fraudulent attempts and flag new attempts using the same field value.

The goal is to give new attack vectors as little time as possible to scale. In practice, this means a new attack pattern can typically be neutralized within hours of its first appearance, and within 24 hours at most, before it has the opportunity to grow into a large-scale problem.

This isn’t meant to replace the existing layers of fraud prevention. Rules and crosslinking remain important. They handle known patterns effectively, and that work doesn’t stop. What this adds is a complementary capability that responds to emerging threats that haven’t yet been seen clearly enough to codify. Ultimately, the greatest value lies in this invisible, proactive defense: shutting down initial probes before attacks can scale, because stopping fraud before it happens is always more powerful than catching it after the fact.

 The chain looks something like this:

The value isn’t in any single signal. It’s in the ability to learn from recent fraudulent activity and use that intelligence to strengthen defenses against the next wave, while it’s still forming.

What this has meant in practice

The system has already been deployed across real traffic, demonstrating what adaptive detection can achieve when operating in the field:

  • Targeted impact: In a recent wave of attacks affecting a top mobility customer, the capability prevented thousands of fraudulent approvals that would have otherwise slipped through undetected.
  • Broad protection: Across our global traffic, the system identifies 10% of all declined verifications weekly and is the sole deciding factor in roughly 2-4% of declined verifications, rising sharply during active attacks.

Rather than offering fixed promises for every situation, these figures serve as a live illustration of what signal-based detection delivers. They prove that adapting to emerging fraud in near–real time drastically shortens the window in which an attack can scale.

To bring this capability directly into existing risk workflows, results from Adaptive Signal Intelligence have recently been integrated into our Fraud Risk Score, part of the broader Fraud Intelligence package.

Why this matters as fraud techniques evolve

As fraud techniques like deepfakes and media injection advance, single identity checks (such as our suite of document and biometric checks) are no longer sufficient on their own. Combining individual verifications with broader device and network context provides a more complete risk picture to spot coordinated or hidden attacks.

Ultimately, modern fraud prevention must pair traditional, backward-looking detection (“Have we seen this before?”) with real-time, adaptive intelligence (“What are we seeing right now?”). Systems like Veriff’s use both layers to stop known threats while continuously adapting to unfamiliar, emerging attack vectors.

Take the next step

  1. Stay ahead of fraud trends. Subscribe to our newsletter for the latest research, data, and industry insights.
  2. See Veriff in action. Try the Identity Verification live demo and experience exactly what your users see.
  3. Talk to our team. Book a personalized demo and get answers to your specific questions.

Subscribe for insights

CTA form illustration

Start building with Veriff for free

Your journey toward faster, more accurate identity verification starts here.