- Oct 07, 2026
- 10 min read
New Account Fraud vs. Fraud Beyond Onboarding
New account fraud and fraud beyond onboarding differ in timing, signals, and risk. See how AI-powered detection tackles both fraud types.

Fraudsters can exploit accounts they open themselves or take over accounts that have been in use for years. Either way, the accounts end up fueling crime. The latest figures show that new account fraud affected 5.4 million US consumers in 2025, up 31% from 2024, while account takeover victims rose 18%. New account fraud was the only category of identity fraud whose losses rose, reaching $7 billion. Yet account takeover losses still exceeded $15 billion – more than twice as much – despite falling slightly from 2024.
New account fraud and account takeover fraud do require different signals, but they should not be managed in silos. At onboarding, the question is “should we establish trust with this applicant?” After onboarding, it becomes “does the person, device, or behavior exercising that trust still match our expectations?”
This guide explains how the two fraud stages overlap, why identity verification alone leaves gaps, and how digital-footprint analysis, device intelligence, behavioral monitoring, and AI can help protect accounts across the whole customer lifecycle.
What is new account fraud?
New account fraud is opening an account under false pretenses, either by using fake, stolen, or misleading information, or by hiding a plan to abuse the service or its promotions against the rules.
New account fraud mostly affects banks, lenders, crypto exchanges, iGaming operators, marketplaces, telecoms, and other digital services.
These accounts can be used for credit fraud, loan bust-outs, bonus or chargeback abuse, money muling, money laundering, scams, or to gain access to restricted services.
How new account fraud happens
Meet Alex – he doesn't exist. A fraudster buys an ID number, leaked in a data breach, on a dark web marketplace. It belongs to a real person who has no idea. He adds a made-up name, a fake address, and a new email. Then he uses an AI tool to generate a face, a matching ID document, and a selfie video that can fool a basic check.
Alex applies for an account at an online bank – approved. He repeats the process with slight tweaks at a crypto exchange, a payments app, and a lender. A few get rejected, so he changes a detail and tries again. Within days, Alex has several accounts. For months, he behaves like a model customer, building trust and raising credit limits. Then he maxes everything out, moves the money, and disappears. There's no real Alex to chase, and the person whose ID number was used finds the mess later.
Suggested read: AI Fake IDs and the New KYC Risk
A fraudster may impersonate a real person, use generative AI to fabricate a persona, recruit someone to open an account with genuine documents, or deploy bots, emulators, virtualized devices, and other tools to create and control accounts at scale. In synthetic identity fraud, the applicant combines real data, such as an identification number, with invented details.
Criminals can obtain personal data through breaches, phishing, malware, social engineering, public records, or dark web markets. They may alter documents, pair stolen details with a deepfake, or create a synthetic profile with plausible data points.
AI-driven synthetic identity fraud tools make it easy to generate photographs, supporting documents, backstories, or deepfakes, while automation repeatedly submits applications to exploit vulnerabilities across a large number of applications.
When one combination fails, attackers can generate another and resubmit it across businesses, products, or jurisdictions.

Suggested challenge: Can you outsmart The Beast? Put your memory to the test in this 50-second game!
Not every fraudulent applicant uses fake documents. A money mule may submit their authentic document and selfie, pass a liveness check, and then move the proceeds of crime through their account. Others apply under their real identity but lie about specific details, such as their source of income, or never intend to repay a loan.
Accounts can also be coordinated to exploit bonuses or evade restrictions. Shared devices, IP ranges, or addresses can help identify connections, but do not establish fraud on their own.
Why new account fraud is hard to catch at onboarding
Identity verification, face matching, and liveness are essential for establishing who is applying. But new account fraud often becomes visible only when you look beyond the identity itself and assess the context around the application.
Digital-footprint checks, for example, assess email age and history, deliverability, phone validity and history, and ownership signals where available. Network checks assess IP reputation, location inconsistencies, and potential proxy use. Device intelligence can detect emulators, tampered environments, automation, and repeated use of the same device. Velocity checks may expose implausibly rapid or numerous applications, while fraud-network detection can connect applicants through shared attributes. AI and machine learning can bring these signals together to identify patterns and assess risk in real time.
These checks involve processing personal data and may access information on users’ devices, so businesses need an appropriate lawful basis, clear privacy information, and any consent required for device access under applicable law.
Together, these signals support a risk-based response. Low-risk applicants can proceed with minimal friction once all legally required customer due diligence is complete, uncertain cases can undergo additional checks, and high-risk applications can be investigated.
Suggested read: What Is Device Fingerprinting?
What is fraud beyond onboarding?
Fraud beyond onboarding happens, or is detected, after a customer's account has already been opened and verified. It includes account takeover, as well as cases where customers are recruited as money mules, sell access to their accounts, collude with fraudsters, or commit fraud themselves.
Technically, some of these cases count as new account fraud, since the malicious intent was there from the start. However, the account's risk profile often changes or only becomes apparent after onboarding.
How fraud beyond onboarding happens
Meet Maria – her account stopped being hers. Maria gets a text that looks like it's from her bank: "Suspicious login detected. Verify your account here." She taps the link and enters her username and password on a page that looks exactly like the real one. Minutes later, a "bank agent" calls to "secure her account" and asks her to read out the one-time code she just received. She does.
The fraudster now has everything. He logs in, changes Maria's email and phone number so the alerts go to him, adds a new payee, and drains her savings. To a standard login check, nothing looks wrong: correct password, correct code, an account with years of good history.
This is account takeover fraud: a criminal gains unauthorized control of an existing account through methods like phishing, credential stuffing, malware, SIM swapping, session theft, social engineering, or a combination of these. The attacker may change contact details, add a payee, withdraw funds, obtain credit, or exploit the account’s established trust.
In other schemes, the genuine account holder stays in control. Customers may be recruited to receive the proceeds of crime, rent out their accounts, or transfer funds. Coordinated groups may abuse bonuses or manipulate reviews and peer-to-peer trades.
Both forms of abuse can pass conventional authentication checks for different reasons. An account thief may possess the correct credentials or intercept a one-time code, while a mule is the verified account holder. This is where behavioral analytics for online fraud prevention can add another signal. It compares how the user types, taps, swipes, navigates, or holds a device with their established patterns.
Why fraud beyond onboarding is hard to catch
Customers frequently travel, replace phones, forget passwords, and send money to new recipients. Any one anomaly may be innocent, so rigid rules can easily generate false positives and lead to frustration and inefficiency.
Identifying fraud after onboarding can be difficult because fraudulent activity may initially resemble ordinary account use. An attacker can study the account, delay fraudulent transactions, remain below detection thresholds, or operate through a stolen session that the platform already recognizes.
Where a money mule remains in control and uses their usual device and credentials, identity and login checks may show no change. Transaction and AML monitoring can identify red flags such as unexplained incoming payments, rapid onward transfers, and links to known mule accounts.
Effective post-onboarding fraud detection depends on more than isolated events. A new device alone may be harmless, but a new device followed by a password reset, contact-detail change, new payee, and rapid withdrawal is more concerning. Events should be assessed in context: against the customer’s previous behavior, the sequence and velocity of recent activity, known fraud patterns, and connections to other accounts or entities.
Suggested read: What Is Device Intelligence and How Does It Stop Fraud?
New account fraud vs. fraud beyond onboarding: Key differences
New account fraud involves creating an account through deception or with concealed abusive intent.
Fraud beyond onboarding concerns what happens after approval, with account takeover fraud as one major form.
Because an account can be fraudulent at creation and exploited later, the categories can overlap. Money mule activity is a money laundering concern, while fraud syndicates coordinate fraudulent activity and may use mule accounts to move the proceeds.
| Area | New account fraud | Fraud beyond onboarding |
| Main stage | Registration, application, and initial verification | Login, account changes or recovery, transactions, or other ongoing activity |
| Typical scenarios | Stolen or synthetic identity, genuine applicant with fraudulent intent, coordinated, or automated account creation | Account takeover, mule activity, account selling or renting, collusion, first-party abuse, or scam-related activity |
| Core question | Should this applicant or account be trusted at onboarding? | Are the current user and activity still trustworthy? |
| Strong signals | Identity, liveness, digital footprint, device, velocity, and network links | Behavioral, device, authentication, transaction, and network signals |
| Common harm | Credit loss, bonus abuse, mule activity, money laundering, fake profiles, and platform access abuse | Account theft, unauthorized payments, money laundering, scams, chargeback abuse, and customer losses |
| Typical response | Approve, reject, step up, restrict, investigate, or report where required | Monitor, authenticate, limit, block, investigate, or report where required |
Timing across the customer lifecycle
The signals available to businesses change throughout the customer lifecycle. At onboarding, businesses have little or no customer history to rely on, so risk decisions depend more on identity, device, network, and application or registration data.
Once an account is active, every login, device change, transaction, and interaction adds context. This makes it possible to spot deviations from established patterns and identify risk that may only emerge over time.
Detection signals and data sources
Fraud detection during KYC onboarding draws on applicant-provided information, verification results, and records from internal systems or external providers. These sources can vary in coverage, freshness, and reliability. A missing record shouldn't automatically be treated as a sign of fraud, but conflicting information may call for further checks.
After onboarding, data from authentication systems, payment platforms, and account records needs to be linked to the right customer and assessed without losing track of where it came from. Behavioral biometrics adds another layer to online fraud prevention, though its value depends on the quality of the data it's compared against.
Business impact and risk ownership
The business impact also changes across the customer lifecycle. New account fraud can increase credit losses, promotional abuse, mule activity, and investigation costs before a customer relationship is fully established.
Fraud beyond onboarding puts existing accounts, transactions, and customer trust at risk, leading to unauthorized payments, reimbursements, operational losses, complaints, and further investigation.
For regulated firms, both stages can also create regulatory exposure, including suspicious activity reporting obligations and, in some jurisdictions, liability to reimburse affected customers. In the UK, for example, new refund rules have applied since October 7, 2024. Payment service providers that offer Faster Payments must refund victims of authorized push payment (APP) fraud, up to £85,000 per claim. This includes most UK banks, building societies, and e-money firms. The cost is shared: the sending firm can recover 50% of the refund from the firm that received the money. This means the firm that onboarded the mule account pays for half of the loss. In the first full year, UK payment firms reimbursed £173 million ($228 million) to APP fraud victims. Control failures may also lead to regulatory enforcement.
Fraud prevention rarely sits with one team. Identity, fraud, AML, payments, cybersecurity, product, and support may all see different parts of the same risk. Shared signals, case history, decisioning, and feedback loops help those teams carry context across the customer lifecycle, rather than treat each event in isolation.
For firms subject to AML requirements, senior management remains accountable for effective AML systems and controls. The MLRO, or an equivalent designated officer, oversees day-to-day AML compliance. They review internal reports of suspicious activity and decide whether to file a suspicious activity report with the national financial intelligence unit. Shared systems and AI do not transfer these responsibilities.
Suggested read: What Is KYC? A Complete Guide to Know Your Customer Verification
How AI helps detect both fraud types
Defensive AI fraud detection helps businesses respond faster and at scale to AI fraud.
AI can help extract patterns from large volumes of identity, device, behavioral, transaction, and network data, allowing risk models to evaluate combinations of signals rather than relying on one indicator at a time. Using AI for fraud detection also allows for more sophisticated risk assessments, so suspicious activity can be challenged before it results in a loss.
However, AI is not a complete solution on its own. Models require representative data, regular testing, privacy safeguards, explainable decisions, and human oversight, particularly when a decision could prevent a legitimate customer from accessing an account or service.
AI at onboarding: Finding patterns without an account history
At onboarding, there is little or no customer history to compare with the application. AI instead has to assess risk from the evidence available in the application itself and the surrounding context.
Machine learning models can analyze patterns across identity data, documents, biometrics, devices, contact details, network information, application behavior, and relationships with other applicants. The value comes not only from checking each signal independently, but from identifying combinations that would be difficult to capture with a fixed set of rules.
AI after onboarding: Detecting changes over time
After onboarding, AI models can use previous logins, devices, sessions, transactions, account changes, recipients, and behavioral patterns to establish what normal activity looks like for each account. New activity can then be judged against what came before it.
Models can also detect slower changes that simple thresholds may miss, such as shifts in transaction patterns, growing connections to risky accounts, or behavior that gradually moves away from the customer's established baseline.
AI agents for continuous fraud investigation
Detection systems may identify suspicious activity, but an investigator still needs to establish what happened and how the case relates to other users or events. A fraud detection AI agent can help retrieve relevant identity, device, session, transaction, and network information, assemble a timeline, identify connected cases, and summarize the evidence for an analyst.
Unlike a model that produces a risk score for a single event, an AI agent can support a multi-step investigation. For example, with authorized access to relevant data sources and tools, an agent examining a suspicious transfer could check the recipient against recent applications, identify shared devices or IP addresses, find related alerts, and prepare the case for human review.
Building a unified fraud prevention strategy
Using AI at onboarding and after approval isn't enough if the two systems don't share information. Many businesses separate identity verification, transaction monitoring, cybersecurity, and fraud operations, leaving useful signals in different systems and case records. When those signals remain disconnected, businesses can miss relationships across different stages of the customer lifecycle. An account that appeared legitimate at sign-up may later become part of a money mule network. A device associated with an account takeover may subsequently be used to submit new applications.
Sumsub’s internal data indicates that 76% of fraud attempts occur after onboarding. A unified strategy lets new account fraud prevention and post-onboarding controls reinforce each other. With connected data, AI for fraud detection can assess activity in the context of the customer’s full history.
Connecting onboarding and post-onboarding signals
Connecting the two fraud stages works both ways. Onboarding data helps after approval, and new fraud findings should also update what the business knows about identities, devices, accounts, and relationships it has already seen.
A device, for example, may carry little risk when it first appears. If it is later linked to several confirmed fraud cases, that association changes its significance. The same decisions can then inform other active accounts and future applications connected to it.
This creates a feedback loop: each confirmed fraud case becomes new risk intelligence that can improve decisions at every stage.
Choosing AI-powered detection tools
When evaluating an AI fraud detection platform, businesses should ask whether it can:
- connect signals across the customer lifecycle, combining identity, digital-footprint, device, behavioral, transaction, and network data
- identify links between seemingly separate accounts, devices, payment instruments, and counterparties
- turn risk signals into action with configurable rules, thresholds, step-up checks, and risk-based workflows
- detect and respond to risk quickly, including in real time or near real time for high-risk events such as logins, account changes, or payments
- show why a case was flagged and preserve an audit trail
- integrate with existing fraud and compliance systems, including KYC, authentication, payment, AML, and case-management systems
- feed confirmed fraud cases back into future decisions, so new findings can improve detection elsewhere in the customer lifecycle
- support human control where it matters, allowing investigators to review, override, escalate, and provide feedback on automated decisions
Vendors should explain how their systems are tested against emerging attack methods and be transparent about their limitations.
Businesses should also assess each vendor’s privacy, security, resilience, geographic coverage, and fit with their regulatory requirements.
Sumsub brings these functions together through identity and liveness verification, digital-footprint screening, Device Intelligence, Fraud Network Detection, behavioral and transaction monitoring, account takeover prevention, automated workflows, and case management. This lets businesses use onboarding signals to detect suspicious activity later and apply intelligence from confirmed post-onboarding fraud to future applicants.
FAQ: New account fraud vs. fraud beyond onboarding
-
What is new account fraud?
New account fraud is creating an account using false, stolen, synthetic, or misleading information, or with a concealed intention to abuse the service or its promotional offers in breach of its terms and conditions. It affects banks, lenders, crypto exchanges, iGaming operators, marketplaces, telecoms, and other digital services. Fraudsters can use these accounts to take out credit or loans they never intend to repay, abuse bonuses or chargebacks, move or launder illicit money, run scams, or access services they'd otherwise be blocked from.
-
What is account takeover fraud?
Account takeover fraud occurs when an unauthorized person gains control of an existing user’s account through methods such as phishing, credential stuffing, malware, SIM swapping, or social engineering. The attacker then exploits the account’s funds, data, features, or established trust.
-
How to prevent account takeover fraud?
Individuals can protect themselves by using strong, unique passwords and multi-factor authentication, especially for their email. A compromised mailbox is often the key to everything else, because it lets fraudsters reset passwords for other accounts.
Businesses should make it hard for attackers to get in, and easy to spot them if they do. That means requiring multi-factor authentication, making account recovery secure so it can't be used as a backdoor, and adding extra verification for risky actions like changing contact details, adding a new device, or making a large withdrawal. Device and behavioral signals help flag logins that don't match the real user's usual patterns, while real-time transaction monitoring and network analysis can catch suspicious activity and links between accounts controlled by the same fraudster. Ongoing monitoring also works best when it's connected to the customer's original KYC data, so unusual changes can be judged against who the customer really is. -
How does AI detect fraud?
AI can help detect fraud by comparing identity, device, behavioral, network, and transaction data with historical baselines and known suspicious patterns. It can score risk in real time, link related entities, prioritize alerts, and help investigators assemble evidence, subject to governance and human oversight.
Relevant articles
- Article
- Yesterday
- < 1 min read

- Article
- Aug 28, 2026
- 13 min read
Insider fraud costs companies millions each year. Learn how internal fraud happens, why IAM alone can’t prevent it, and which controls can help close…

What is Sumsub anyway?
Not everyone loves compliance—but we do. Sumsub helps businesses verify users, prevent fraud, and meet regulatory requirements anywhere in the world, without compromises. From neobanks to mobility apps, we make sure honest users get in, and bad actors stay out.


