At A Glance
New account fraud is increasing as fraudsters equip malicious bots with stolen and synthetic identity data to open fraudulent accounts at scale.Finding a reliable, customer-friendly way to protect your business against new account fraud is vital to surviving in today’s digital-driven economy. Not only can ignoring the problem invite fraud losses and damage client goodwill, but implementing the wrong solutions can lead to onboarding issues that drive away potential customers.
Our recently released 2026 Identity and Fraud Report revealed that nearly 60 percent of U.S. businesses reported higher fraud losses in 2025, with many of these involving new account fraud. At the same time, problems with onboarding caused 52 percent of consumers to drop off and take their business elsewhere.
In other words, your customers want protection, but they aren’t willing to compromise their digital experience to get it. You need to find a way to meet both these needs when combating new account fraud.
What is new account fraud?
New account fraud occurs any time a bad actor creates an account using identity information that doesn’t belong to them. This process is referred to by different names, such as onboarding fraud, account creation fraud or account opening fraud.
Examples of some of the more common types of new account fraud include:
- Synthetic identity (ID) fraud: This occurs when a fraudster blends identity data from multiple people or combines stolen data with their own information. For example, they might use someone’s real Social Security number combined with a fake email. Typically, this is done to bypass identity-based checks while ensuring the fraudster still controls the email or other credentials associated with the account.
- Identity theft: In a traditional identity theft scheme, fraudsters use complete stolen identities to create new, fraudulent accounts. Stolen identity data can be harvested through scams or purchased in bulk on the dark web. Complete identities are most often used when targeting businesses with more robust KYC processes, like financial institutions or government agencies.
- Fake identity: Fraudsters create accounts with wholly fabricated personally identifiable information (PII). This occurs most commonly in industries with streamlined, lightweight onboarding processes, like social media and rewards/loyalty accounts.
New account fraud may manifest as individual account creations, but the repercussions spill over to impact entire organizations. In fact, many account opening attacks leverage malicious bots to steal information or create fake accounts en masse, meaning losses can cascade quickly if fraudsters aren’t stopped during the application process.
How does new account fraud work?
New account fraud begins with the harvesting of stolen or fabricated data. Common tactics include:
- Data breaches: Frequent breaches produce stolen data that is often resold on dark web marketplaces. A survey revealed that 61% of Americans have received at least one data breach notification in the past two years.
- Phishing scams: Fraudsters pose as legitimate organizations, contacting consumers with fake emails or cloned apps that are used to steal personal information.
- Bot scrapers: Automated bots scrape information posted publicly on social media or on websites.
Synthetic ID fraud: Through any of the above tactics, fraudsters garner partial identities and piece them together in a way that mimics a legitimate, identity. For example, if the fraudster has a real Social Security number but no other information, they might combine it with a fake name and birth date (or vice versa). The fake or stolen identity might first be used to open a new account, like a credit card or a demand deposit account. If the account isn’t shut down, it could turn into a longer-term scheme like bust-out fraud, where fraudsters establish credit history until it can be used for higher-value targets, like loans and bank withdrawals.
How are organizations handling new account fraud prevention and where do they fall short?
Most organizations have at least one solution in place to prevent new account fraud (in some industries certain processes are mandatory). Some traditional methods used in new account fraud prevention include:
- Completely Automated Public Turing Tests (CAPTCHAs): These tests help reduce bot attacks that lead to data breaches and ensure that individuals logging into your system are actual people.
- Multifactor authentication (MFA): MFA bolsters users’ password protection and helps guard against account takeover. If a scammer tries to take over an account, they won’t be able to complete the process.
- Password protection: Robust password managers can help ensure that one stolen password doesn’t lead to multiple breaches.
- Knowledge-based authentication: Knowledge-based authentication can be combined with MFA solutions, providing an additional layer of identity verification.
- Know-your-customer (KYC) solutions: Businesses may utilize KYC to verify customers via government IDs, background checks, ongoing monitoring, and the like.
- Additional protective measures may involve more robust identity verification behind the scenes. Examples include biometric verification, government ID authentication, public records analysis, and more.
Many of these methods are trusted among businesses and consumers alike. They’ve been on the market for a while — which means fraudsters have evolved to find ways to beat them. Moreover, they often add complexity to the account creation process, creating even more challenges for businesses, including:
- Next-generation bots: Malicious bots have evolved to replicate human behavior and cycle through device and network data, rendering traditional bot detection methods ineffective.
- Integration inefficiency: To close gaps in new account fraud detection, institutions often use multiple security solutions that aren’t built to work together, leading to data redundancies and excessive costs.
- Excessive friction: Manual verification methods slow down the account creation process, turning away potential new customers.
- False positives: Most fraud stacks aren’t designed to compensate for natural abnormalities, ultimately treating ;genuine customers as red flags. Examples include identity mismatches and, in use cases where AI agents are common, blockage of legitimate automated sessions.
How we can help
Our fraud management services provide a multi-layered approach that lets businesses customize solutions to their needs. Advanced machine learning analytics utilizes extensive, proprietary data to provide a unique experience that not only protects your company, but it also protects your customers’ experience.
- Behavioral analytics (NeuroID): Experian NeuroID combines device and network intelligence with behavioral analytics — typing patterns, copy/paste behavior, hesitation, and navigation — to separate genuine customers from fraudsters in real time. For genuine users, behavioral, device and network baselines established at onboarding can reveal account takeover attempts and fraudulent transactions later in the customer lifecycle.
- Customer Identification Program (CIP): Our KYC solutions provide stronger, friction-free identity verification at onboarding. The tools start with onboarding, but continue throughout the customer journey, including portfolio management. The tools also help your company comply with relevant KYC regulations.
- Cross-industry analysis of identity behavior: We created an identity graph that aggregates consumer information in a way that gives companies access to a cross-industry view of identity behavior as it changes over time. This means that when a new account is opened, your company can determine behind the scenes if any part of the identity is connected to instances of fraud or presents actions not normally associated with the customer’s identity.
- Multifactor authentication solutions: When additional information is needed, our MFA solutions utilize low-friction, consumer-trusted techniques like two-factor authentication, knowledge-based authentication, and unique one-time password authentication during remote transactions to guard against hacking.
- Synthetic ID fraud protection: Our fraud management solutions include robust protection against synthetic ID fraud. Our groundbreaking technology detects and predicts synthetic identities throughout the customer lifecycle, utilizing advanced analytics capabilities.
- Precise ID®: The Precise ID platform lets customers choose the combination of fraud analytics, identification verification, and workflows that best meet their business needs. This includes machine-learned fraud risk models, robust consumer data assets, one-time passwords (OTPs), knowledge-based authentication (KBAs), and powerful insights via the Identity Element Network®.
Protect your business from new account fraud with us
Our innovative fraud and identity solutions can strengthen your new account fraud prevention strategies while optimizing customer experiences for legitimate customers.
References
2. “Identity Theft.” USA.gov, December 6, 2023. https://www.usa.gov/identity-theft
3. Purcell, Michael. “Synthetic Identity Fraud: What is It and How to Combat It.” Thomson Reuters, April 28, 2023. https://legal.thomsonreuters.com/blog/synthetic-identity-fraud-what-is-it-and-how-to-combat-it/