How to prevent fintech fraud: the device layer across the fraud types

Last updated on July 16, 2026 · 10 min read
Fintech turned account opening and lending into a few taps, and fraud followed the money into every one of those taps. A neobank signup, a buy now pay later approval, a first deposit, a login, each is a moment where a business has to decide in seconds whether the person on the other end is a real new customer or an operation wearing one. Fintech fraud is the whole family of ways that decision goes wrong, and it is not one attack but several that share a root.
This guide maps that terrain. It covers what fintech fraud is, the main types from new-account and synthetic-identity fraud to account takeover, payment and BNPL abuse, and mule or bust-out accounts, and where one specific layer fits across all of them: the device and anonymity signal behind each session, which links a fraud ring running many identities at once and flags the masked connections it hides behind. Identity verification, KYC, and credit-bureau checks stay in your own regulated stack; the device layer sits alongside them and answers a different question.
Key takeaways
- Fintech fraud is a family, not a single attack: new-account and synthetic-identity fraud, account takeover, payment and BNPL abuse, and mule or bust-out accounts each hit a different point in the customer lifecycle.
- The thread under most of them is one operation running many "separate" identities from a limited set of devices and connections, which is what makes the family catchable at one layer.
- The device and anonymity layer links those accounts back together and flags VPN, proxy, and anti-detect-browser sessions, so a ring stops hiding as unrelated customers.
- It is a positive division of labor: identity verification, KYC, and credit checks judge each identity in your regulated stack, while the device layer exposes the operation minting them at scale.
- You read the device behind each session, score it, and your own rules and risk engine decide what to approve, review, or decline, so a genuine new customer onboards untouched.
What is fintech fraud?
Fintech fraud is the set of fraudulent activities that target digital-first financial products, from neobanks and digital wallets to lending, buy now pay later, and payment apps. It spans the whole customer lifecycle: fabricated or stolen identities used to open accounts, existing accounts hijacked at login, payment and credit lines abused, and accounts opened to move other people's money. What ties these together in a fintech context is speed and distance. Onboarding is remote and near-instant, the counterparty is a browser or an app rather than a person at a branch, and the same convenience that wins customers lets one operation present as many. That is why fintech fraud is best understood as a family of related types rather than a single problem with a single fix.
The main types of fintech fraud
The fraud hitting a fintech is not one thing, but the list is short and the types repeat across neobanks, lenders, and wallets. Naming them in one place helps, because several share a root and a signal even though they hit different moments in the lifecycle. Each type has its own deeper guide; this is the map.
| Fintech fraud type | What it is | Covered in depth |
|---|---|---|
| New-account fraud | fake or throwaway accounts opened at signup to farm a sign-up bonus, take a promo, or slip back after a ban | new-account fraud |
| Synthetic-identity fraud | a fabricated "person" built from real and fake details, nurtured into a credit line, then busted out | synthetic identity fraud |
| Account takeover | an existing, trusted account hijacked at login with stolen credentials and drained or used to move funds | account takeover |
| Payment and BNPL abuse | thin-check pay-later approvals exploited through loan stacking, first-payment default, and stolen-card checkout | BNPL fraud |
| Mule and bust-out accounts | accounts opened or rented to receive and forward other people's money, or drawn to the limit and abandoned | multi-accounting |
| Business-account fraud | fake or shell business profiles opened to reach the higher limits that business products carry | multi-accounting |
Read down the middle column and two shapes appear. Most of these are an operation opening many accounts that each look like a legitimate new customer: new-account fraud, synthetic-identity farms, mule networks, and fake-business rings all run the same play at different scales. Account takeover is the exception, aimed at accounts that already exist rather than new ones, and it is worth naming separately because a fintech has to watch both the front door and the returning login. A pay-later or wallet product tends to feel several of these at once, since a single stolen or fabricated identity can open an account, stack credit, and cash out through it.
The scale is real. The 2026 Javelin Identity Fraud Study put traditional identity-fraud losses at $27.3 billion in 2025, affecting 18 million victims. The Federal Reserve has treated synthetic identity fraud as a strategic priority since 2018, and the Boston Fed has called it anything but victimless, costing billions and standing among the fastest-growing financial crimes in the country. New-account and mule activity rarely earn a single headline number, because each instance is small, but they leak margin from the same place: accounts a fintech treats as new, trusted, or legitimate that are none of those things. Mule networks in particular draw regulator attention, with the Financial Crimes Enforcement Network warning that criminals recruit and open accounts specifically to move illicit funds.
The one thread: one operation, many identities
Strip the product away and most of the list above is the same move: a single operation produces a stream of accounts that each look like a first-time customer, an established one, or a legitimate business. A synthetic-identity farm cultivates hundreds of "people" in parallel; a mule network opens or buys dozens of receiving accounts; a bonus operation re-claims a welcome offer under fresh registrations again and again. Whatever the payout, the machinery underneath is shared.
What ties those accounts back together is what the operation cannot cheaply reissue per account. The identity documents can be bought, the Social Security number can be borrowed, the email is disposable and the IP is rentable, but the device behind each session and the network it rides tend to stay the same from one "separate" account to the next. So a fintech does not have to solve six problems independently; it can also answer one question at the moment an account acts: how many other accounts trace back to this same machine, and is the connection working to look like a crowd. That linkage is the multi-accounting pattern, many accounts on one device, and it is the signature of an operation even when every identity on top is different.
Where the device layer fits, and where KYC stays
Fintech fraud detection works best as layers, each answering a question the others cannot. Drawing the line between those layers is the single most useful thing a fintech team can do, because it stops any one control from being asked to do a job it was never built for.
The identity layer judges the person
Identity verification, KYC, and credit-bureau checks validate who is applying: they cross-check a name, date of birth, and government identifier against authoritative sources, confirm documents, and read a credit file. This layer lives in your regulated stack, where it belongs, and it is what catches an identity whose details do not line up. It judges each application on its own merits, one person at a time.
The device layer judges the operation
The device and anonymity layer answers a different question: not "is this person real" but "how many of these applications are the same setup, and is it hiding." A synthetic identity engineered to pass verification still has to be created from a machine, and at scale an operation reuses a limited set of devices and connections across all of it. A persistent device identifier links those applications back together, and the anonymity signals flag the VPN, proxy, and anti-detect-browser sessions an operation leans on to make one setup look like many separate people. No identity check on a single application would reveal that, because nothing about that one identity is wrong.
The two layers are complementary, and neither replaces the other. Identity verification and KYC stay in your regulated stack and judge each identity, while the device layer links the operation running many identities at once and flags the masked sessions behind them. A synthetic identity that beats verification can still be caught as one of forty applications on a shared device, and a real customer who simply uses a VPN scores as exactly that rather than a fraud. Run both and the picture is complete from either side.
Reading the device without taxing real customers
The reflex when fraud climbs is to add friction to everyone: raise income requirements, add verification steps, cap what new accounts can move, and delay transactions for review. Some of that is prudent, but a fintech pays for it directly. In Signicat's Battle to Onboard research, the length of the process was behind 39 percent of abandoned bank-account applications, so friction at onboarding is measured in lost, legitimate customers. Reading the device first lets you aim the friction instead of spreading it.
Read the device, then decide
A JavaScript snippet identifies the visitor on your signup, login, or approval page, and your system reads a risk score for that session before it commits. A device already seen behind a dozen applications, or arriving over an anti-detect browser, scores high; a genuine first-time applicant on a normal connection scores clean and onboards with nothing added. Because the score is separate from the action, your own rules and your risk engine decide what a risky session gets: approve it, route it to a manual review or a step-up check, or decline it, while the real customer never feels a thing. The lending, approval, and onboarding decision stays in your system, informed by a clearer read of the session behind each request. That separation, read quietly and decide explicitly, is what lets a fintech cut fraud without turning onboarding into an obstacle course, because it reads the device and browser behind each session rather than hooking into your ledger.
Preventing fintech fraud with ShieldLabs
ShieldLabs adds the device and anonymity signal layer across your fintech's fraud surface, working alongside the identity verification, KYC, and credit checks that live in your regulated stack. You add one JavaScript snippet to your signup, login, or approval flow, and each visit returns persistent identification that survives cleared cookies and a rotated IP, so a cluster of "separate" applicants that all trace to one machine stays linked. Across accounts, the pre-built patterns surface which ones share a device, so a synthetic-identity farm or a mule ring reads as a linked group in the dashboard rather than a pile of unrelated signups.
We measured how a mule or synthetic-identity ring reuses its infrastructure: dozens of applications built from different names, borrowed identifiers, and disposable emails, each of which clears an identity check on its own, still converged on a shared device and a reused connection once we read the session behind them. It is the same operation regulators describe from the other side, with FinCEN warning in 2020 that criminals open accounts specifically to move illicit funds.
Alongside the linkage, each visit returns a risk score from 0 to 100 with the named anonymity signals behind it, the VPN, proxy, Tor, and anti-detect-browser use an operation relies on to make one setup look like a crowd. ShieldLabs scores the session and names the evidence; your identity and credit checks judge the person, and your own rules decide what to approve, review, or decline. You read the pattern and the score through the API and webhooks, so the decision stays in your stack, and the same device layer carries across the fraud types, from new-account fraud and synthetic identity at onboarding to account takeover at login and BNPL abuse at approval. It complements your regulated stack rather than standing in for it.
Sources
- Federal Reserve (FedPayments Improvement): Synthetic Identity Fraud
- Federal Reserve Bank of Boston: Synthetic identity fraud is not a victimless crime (2022)
- Financial Crimes Enforcement Network (FinCEN): Advisory on money mule schemes (2020)
- Wikipedia: Synthetic identity theft
- Javelin Strategy & Research: 2026 Identity Fraud Study: The Illusion of Progress (2026)
Frequently asked questions
- What is fintech fraud?
- Fintech fraud is the family of fraudulent activities that target digital-first financial products such as neobanks, digital wallets, lending, buy now pay later, and payment apps. It spans the customer lifecycle: fabricated or stolen identities used to open accounts, existing accounts hijacked at login, payment and credit lines abused, and accounts opened to move other people's money. It is best understood as a set of related types rather than one attack, because remote, near-instant onboarding lets a single operation present as many customers at once.
- What are the main types of fintech fraud?
- The main types are new-account fraud, where fake or throwaway accounts are opened to farm bonuses or offers; synthetic-identity fraud, where a fabricated identity is nurtured into a credit line and busted out; account takeover, where a trusted existing account is hijacked at login; payment and BNPL abuse, where thin-check pay-later approvals are exploited through loan stacking and default; and mule or bust-out accounts opened to receive and forward funds. Most share one root, an operation running many accounts from a limited set of devices, while account takeover targets accounts that already exist.
- How is fintech fraud detected?
- It is detected in layers, because no single check catches every type. Identity verification, KYC, and credit-bureau checks validate each applicant against authoritative sources and catch identities whose details do not line up. Device and network signals add a second layer that links supposedly separate accounts sharing one device or connection and flags VPN, proxy, and anti-detect-browser sessions. The identity layer judges the person, and the device layer judges the operation creating many identities at scale, so strong programs run both.
- Does ShieldLabs replace KYC or identity verification for fintech?
- ShieldLabs works alongside them. Identity verification, KYC, and credit checks stay in your regulated stack and validate who is applying. ShieldLabs adds the device and anonymity layer that links applications back to the machines they come from and flags masked connections, exposing an operation running many identities that pass verification individually. It returns a risk score with named signals through the API and webhooks, and your own rules and risk engine decide what to approve, review, or decline.
- How do you stop fintech fraud without adding friction for real customers?
- You read the device and network behind each signup, login, or approval instead of taxing everyone with extra verification, then score how risky the session is and act only on the high-risk ones. A genuine first-time customer on a normal connection scores clean and onboards with no extra step, while a device already behind a dozen applications, or one arriving over an anti-detect browser, stands out. Because the score is separate from the decision, your rules route only the risky sessions to a step-up or a manual review, so friction lands on the operation and not the customer.
Related articles

How to prevent refund and return abuse
How to prevent refund and return abuse: the multi-account refund-ring slice you can detect, how it differs from wardrobing and chargebacks, and how to read it.

How to prevent online travel fraud: the types and the actor behind them
What online travel fraud is, the main types from stolen-card bookings to miles theft and fake listings, and how the device behind a booking ties them together.

How to prevent coupon abuse (and tell it from coupon fraud)
How to prevent coupon abuse: what separates it from coupon fraud and everyday couponing, and how merchants catch one shopper using many accounts.