Blog

When Identity Fraud Looks Real, No Single Signal Can Be Trusted

Published By sara.smith

Our CEO Lisa Bonalle recently sat down with Ryan Alexander, VP and Global Head of Identity and Fraud Product at Prove, and Charlie Custer, Head of Market Research and Content at SentiLink, for our latest webinar “When Identity Fraud Looks Real: Layered Signals for a Changing Threat Landscape.” The conversation kept coming back to one problem: the checks lenders have trusted for years are getting easier to fool.

Generative AI “is able to clone documents, clone faces, clone voices,” Alexander said. And the fraud rings using it know exactly what lenders look for, so they build identities designed to pass.

All three experts agreed that checking identity only at account opening is no longer enough. Lenders need to use multiple signals together and keep monitoring accounts after they open.

“Identity is the common thread across our digital customer relationships,” Alexander said. “This identity really needs to be known as a continuous thing.”

Fake identities get most of the attention, but they are not the whole story. SentiLink’s 2026 studies found that lenders carry five times more first-party fraud, committed by real people using their own identities, than identity theft and synthetic fraud combined. Much of it never gets called fraud at all; it gets written off as ordinary credit loss.

During the webinar, the panel discussed topics like AI-created identities, recycled phone numbers, and the costs of mislabeled fraud. Here are the top 10 takeaways, starting with the fraudsters’ tactics.

1. Fraudsters have learned which signals you check

The biggest change of the past year, Custer said, is the growing sophistication of organized fraud rings. “The sophisticated fraudsters know the signals that we’re looking at,” he said, “and increasingly we’re seeing them use those in combination.”

SentiLink has seen synthetic identity fraud rates dip slightly. Meanwhile, assumed identity abuse is rising. Fraudsters steal the identity of a former legal U.S. immigrant who has left the country. As Custer put it, “There’s no victim who’s going to report this crime.”

Fraudsters are now automating their attacks; in fact, in early 2026, SentiLink saw cases where they used residential proxies, “cycling through IPs until they find one that gets through.” Fraudsters are exploiting old phone numbers, email addresses and two-factor authentication are also being targeted.

2. AI is turning identity farming into an assembly line

AI also lets fraudsters figure out which identities succeed and which institutions are easiest to target, then repeat those attacks at scale. Bonalle described a learning loop that can “create more of these for me faster than any human could farm identities.”

Alexander explained that mule accounts are central to many scams. Scammers can open these accounts with stolen or fake identities, by recruiting real people, or by taking over existing accounts. Recruitment ads now appear on social media as job postings. Custer added that YouTube and TikTok videos promote check fraud and credit privacy number schemes as harmless “glitches” or credit repair.

Stay Ahead of Credit Risk Trends

Get practical insights on credit decisioning, fraud prevention, and lending automation delivered to your inbox.

3. The phone is a far deeper signal than most lenders use

Alexander walked through the phone threats Prove is tracking:

  • Recycled numbers. A surrendered number is reassigned to a new user, who may then target the previous owner’s accounts.
  • Text-only IoT numbers. Lines built for devices like parking meters are cheap to activate and can still pass SMS authentication.
  • MVNO lines. Virtual carriers rent towers from the major networks, which can help fraudsters mask their trails, though many good customers use them too.
  • SMS-enabled landlines. Decades-old numbers carry long tenure that fraudsters can borrow.

One of his preferred signals combines a one-time link with location data. When a customer clicks a link sent by text, the browser shows the phone’s real location. If a password reset is requested in one place but the link is clicked somewhere far away, it suggests social engineering. If many credit card applicants are all far from home, that’s a warning sign.

The depth of the data matters, he said. Consortium velocity data still has value, but the strongest signals come from carriers, telephony infrastructure and porting records. “You don’t want to be relying on any one source,” he said.

His practical advice is to rely on vendors. “They know their signals better than you do.”

4. Layering is about routing, not just detection

Flagging a risky application is a start, Custer said, but lenders also have to pick the right next step. “If your step-up is a phone OTP, but the fraudster controls that phone, you’re wasting your time and money, and the fraud is going to pass that step-up.”

He was direct about other common step-ups, too. Document verification and liveness checks, he said, “are just exploitable if you have a sophisticated enough fraudster at this point.” Understanding why an application is risky helps you choose a step-up that fraudsters cannot easily get past.

SentiLink provides over 300 different data attributes, but Custer warned that not all are equally useful, and the best ones vary by institution. They also change over time. “The fact that these are the most performant signals today doesn’t mean that they’re going to be tomorrow.”

5. Build the decision in layers, and keep testing

Bonalle described a sequence a lender can run cost-effectively at origination:

  1. Is this device legitimate, or is a reused or oddly located number too risky?
  2. Is this a real human, or a synthetic identity?
  3. If human, is the information really theirs, or is this identity theft?
  4. If the account opens, how likely is repayment?

Getting the order and cutoffs right, she said, “requires a good bit of test and learn,” through champion-challenger strategies that are continuously refined.

6. The front door is not enough

Some fraud is meant to stay hidden until it suddenly appears. “You can’t just focus on the guards at the gate,” Bonalle said. Lenders should regularly review their portfolios to find fraud rings targeting certain regions or products. “It has to be a both-and approach.”

7. Mislabeled fraud is quietly draining lenders

The sharpest numbers of the hour came from SentiLink’s 2026 retrospective studies, which tested its scores against institutions’ historical data:

  • 5x: institutions held five times more first-party fraud than identity theft and synthetic fraud combined.
  • 72%: on average, 72 percent of preventable fraud losses, in dollar terms, came from high-risk first-party fraud applications.

Bonalle explained that when fraud is recorded as credit loss, the costs add up. Accounts go through collections, statements continue, and write-off rules must be followed. Credit models trained on mislabeled losses may focus too much on behavior that is actually fraud. The institution can then become an easy target. “If you’re not doing that to an industry standard,” she said, “you’ll keep getting hit, and that’s a significant cost.”

Alexander added the reverse problem. Collections on a stolen identity can land on an innocent person’s credit report, turning a victim into an apparent perpetrator. “Everyone knows there’s fraud in the credit bucket,” he said. “You can’t solve a problem that you don’t quantify correctly.”

8. Stop trying to read minds on first-party fraud

First-party fraud is often defined by intent: a real person who never meant to repay. “But you can’t measure intent,” Custer said. He suggests letting go of that idea and focusing on the actual signals that predict risk.

Those signals are rarely found within just one institution. When SentiLink looked at 2026 first-party fraud cases, the early warning signs were “almost always at a different institution. Often it’s even in a different industry.”

The exposure varies sharply by sector. In SentiLink’s H1 2026 report, first-party fraud ran at roughly 1 percent or less in consumer lending and above 5 percent in auto lending. Telecom fraud rates are high across every category, he said, because “you need a phone to do almost any type of fraud.”

9. AI helps the defenders most behind the scenes

The panel did not believe in quick fixes. “Some people have this idea of like, let’s just slap ChatGPT on this,” Custer said. “I don’t think that’s the case, or at least we’re not there yet.”

Instead, AI is speeding up the work around the models. SentiLink used it to rapidly build a tool that extracts names from Department of Justice fraud indictments, creating a new risk data set. Prove is testing AI to automate fraud investigations, then pushing what it learns at one bank into its decision engine for every client.

Bonalle believes the biggest benefit is in optimization. Right now, people mostly review champion-challenger results. AI can analyze these results, suggest the next strategy, and help coordinate fraud and credit decisions. This, she said, “allows that learning loop to get faster and faster for the good guys.”

10. The next identity question: is that really your agent?

The session ended with a discussion about agentic AI. Panelists talked about AI agents that seem human and can open loans at scale. They also asked a difficult question: if a consumer’s agent gives wrong information on an application, who is responsible?

As AI agents become more involved in financial decisions, verifying the consumer may no longer be enough. Lenders will also need to determine whether an AI agent is legitimately acting on that person’s behalf or whether someone else is behind it.

Alexander noted that ChatGPT had just announced users could connect their credit report and score. Loan shopping inside a chatbot may not be far behind. “Identity is always at the heart of these questions,” he said, “and getting it right is critically important.”

The bottom line

No one on the panel promised a finish line. “It’s a cat-and-mouse game. It’s also kind of a race,” Custer said. “There’s no cure for fraud.”

The practical advice from the hour was clear. Combine different kinds of data, like Prove’s phone intelligence and SentiLink’s fraud-type scores. Make decisions on those signals in real time, using a decisioning platform like GDS Link that brings every signal together and learns from each outcome. Keep watching accounts after they open. And when a loss is fraud, call it fraud.

Fraudsters who seem real are not going away. Lenders who catch them will be those who do not rely on just one signal.

Missed the live session? Watch the full webinar recording, and contact GDS Link to see how layered decisioning can work for your portfolio.

Recent articles

One Hike, Twelve Different Forecasts: What the Fed’s Split Means for Credit Risk
Read article
Why Your Fraud Score Isn’t Catching Today’s Fake Applicants
Read article
Why Using Multiple Fraud Signals Beats Relying on a Single Model
Read article