New Account Fraud Across Industries: What It Is and How to Prevent It


Most fraud controls are built to protect accounts that already exist. New account fraud slips past them because there is nothing yet to protect: no history, no baseline, no prior behaviour to compare against. The account is fraudulent from the first second it exists, and by the time it does something visibly wrong, the fraudster has usually already extracted whatever they came for.
Recent data confirms that the scale of this issue is growing. In Javelin's 2026 Identity Fraud Study, new account fraud saw the sharpest rise in victims of any identity-fraud category – a 31% jump, from 4.2 million in 2024 to 5.4 million in 2025.
This type of fraud sits at the riskiest point in the customer journey. Account creation is where a business knows the least about the person in front of it and is under the most pressure to let them through quickly. In fact, industry analysis found that 8.3% of all digital account-creation attempts globally in 2025 – roughly 1 in 12 – were suspected fraud, making it the single highest-risk stage across the customer lifecycle. Marketing wants sign-ups, product wants activation, and risk teams are asked to keep fraud out without adding friction that costs conversions. New account fraud lives inside that tension, and it shows up across every major affected industry – digital lending, banking, BNPL, marketplaces, e-commerce and gaming.
This article covers what new account fraud is, how it operates, why registration-time checks alone keep missing it, and which signals actually catch it early – across industries, and in markets where traditional data is thin.
New account fraud is the creation of an account using stolen, synthetic or fabricated information, with the intent to extract value rather than to become a genuine customer. It is also called account creation fraud, account opening fraud or new account fraud (NAF), and it is distinct from account takeover, where a fraudster targets an account that already belongs to a real user.
The defining trait is that these accounts are "born-bad”. They were never attached to a real, trusted person, so there is no legitimate history hiding underneath. What they become depends on the platform: a fraudulent loan application, a mule account for moving illicit funds, a fake seller on a marketplace, a stack of duplicate profiles farming a sign-up promotion, or a synthetic identity slowly building credibility before a bust-out.
Fraudsters rarely open one account at a time. Account creation fraud is an industrial process, run with automation and infrastructure designed to bypass standard sign-up controls at volume. The identity feeding each account usually comes from one of three sources:
On the technical side, bots complete registration forms in milliseconds, rotating email addresses, device fingerprints and IP ranges to stay under velocity thresholds. Emulators and virtual machines imitate real devices. Disposable email services and SIM farms supply the throwaway contact details that one-time verification depends on. The result is that a single operation can push thousands of applications through an onboarding flow, probing for the combinations that get through.
Most onboarding defences concentrate on the moment of registration: CAPTCHA, email confirmation, phone verification, document checks. These raise the cost of fraud, and they are worth having. But each has a known bypass, and fraudsters have industrialised every one of them:
Anything the applicant simply hands over can be bought, faked or borrowed. The deeper problem is that these checks validate what is submitted rather than who is submitting it. A stolen identity produces a clean document. A synthetic identity produces a plausible one. And the one control built specifically to close that gap – identity verification itself – now needs to be augmented by additional controls.
For years the identity check anchored onboarding: confirm the document, confirm the person, and the rest of the decision could lean on it. Generative AI fraud has removed that anchor. Fabricated documents, synthetic profiles and AI-assisted application data are now cheap and convincing enough that the identity layer has become the layer fraudsters are very well equipped to defeat.
This is not hypothetical. In one documented investigation, security researchers recorded more than 8,000 attempts to bypass a single institution's liveness checks during digital KYC for loan applications in just eight months of 2025 – roughly thirty a day. The attackers were not stealing faces at the camera; they injected AI-generated deepfakes through virtual-camera software, so the system received a synthetic feed it read as a live, present human.
And the economics keep it coming: a ready-to-use synthetic identity sells for around $15, a deepfake image service for anywhere in between $10 and $50. When defeating the identity layer costs the price of a lunch, it stops being a barrier and becomes a formality. A liveness check confirms the content looks real; an injection attack controls what content is delivered – and most systems were built to solve only the first.
That gap is not confined to deepfake liveness attacks; it recurs on the applicant side in every market and through many doors: synthetic identities in the US and India, stolen or recycled identities across Africa and Southeast Asia, mule-driven applications in instant-payment economies. The surface details differ; the structure is constant – a submission that is internally consistent, satisfies every control it was designed to satisfy, and answers to no genuine intent behind it. None of this is a case for spending less on identity verification, which stays necessary and, in regulated markets, legally required. It is a case for stopping treating it as the last word.
With that gap in view, let’s take a look at the measures risk and anti-fraud teams can use to close it and to prevent new account fraud.
There is no single control that stops new account fraud. Every individual check has a bypass, which is why effective defence is layered – several independent methods that each raise the cost of fraud and, taken together, close the gaps any one of them leaves open. The layers below are complementary, not alternatives, and most mature onboarding stacks run some combination of all of them.
The first line is confirming that the submitted identity is real and belongs to the applicant. Document verification, biometric or liveness checks, and validation against authoritative data sources all raise the bar, and in regulated sectors KYC obligations make them mandatory. Their limitation is that they scrutinise what the applicant provides: a stolen identity yields a genuine document, and deepfake tooling has made fabricated documents and liveness spoofs harder to dismiss. Strong identity verification is necessary, but it is a floor rather than a complete answer.
A surprising amount of signal sits in the contact details themselves. Disposable or newly registered email domains, the age and reputation of an address relative to its first appearance, phone numbers tied to VoIP or SIM-farm ranges, and mismatches between the name and the data associated with it are all cheap, fast indicators. None is conclusive alone, but they filter a large share of low-effort fraud before heavier checks are needed.
The device reveals what the form conceals. Emulators and virtual machines carry technical fingerprints that differ measurably from ordinary consumer hardware, and reuse is a strong tell – the same device configuration appearing across many registrations in a short window points to a coordinated operation, even when every other detail has been varied to look distinct. Because fraudsters running at scale reuse infrastructure, device signals often expose rings that submitted details hide.
Real people fill out forms with natural variation in typing rhythm, field order, hesitation and correction. Automated sign-ups are fast, uniform and machine-smooth, and even when fraudsters add artificial delays to imitate a human, the pattern rarely holds. Copy-paste into sensitive fields, near-instant completion and the absence of any organic browsing beforehand all raise the risk profile.
VPNs, proxies and data-centre IPs that mask true location, geolocation that contradicts the stated address, a connection never seen before, or a cluster of sign-ups sharing one IP range each point to infrastructure legitimate users do not share. Velocity rules add the time dimension: a sudden spike of registrations from one device, IP range or geography, or a run of verification failures followed by slight-variation retries, is one of the clearest signs of an automated campaign.
CAPTCHA, invisible bot detection and sign-up rate limits by IP and device stop a meaningful share of automated attacks before they generate any useful data about the rest of the stack. They are routinely bypassed by solving farms and sophisticated bots, so they work best as an outer filter that thins the volume rather than as a primary defence.
Fraud is rarely confined to one platform. Shared or consortium intelligence means a device, email or pattern already flagged for fraud elsewhere arrives pre-elevated in risk, rather than looking clean because it is new to you. Cross-platform data turns isolated bad sign-ups into visible rings and gives smaller operators reach they could not build from their own traffic alone.
Rather than a binary pass-or-fail at sign-up, a risk score lets you route. Low-risk registrations proceed cleanly, medium-risk ones step up to further verification such as an additional document or an out-of-band check, and high-risk ones are held or declined. Multi-factor and step-up verification are most effective applied selectively, driven by the score, not imposed on everyone – the same adaptive-authentication logic that underpins effective account takeover prevention, where friction is reserved for the sessions that warrant it.
Some accounts pass every entry check and only reveal themselves later – immediately adding several payment methods, initiating a high-value transfer with no warm-up, or racing to a referral programme. Treating new account fraud as a lifecycle problem rather than a registration event closes the gap between onboarding controls and the first fraudulent action. Account age at the time of the first fraud event is one of the most useful operational signals a team can track. When that first action is a payment, payment screening – evaluating the transaction against fraud signals before it settles – becomes the natural continuation of the same defence.
No single check proves fraud, and treating any one as the whole answer is where most defences fail. A new device is not suspicious – plenty of people buy new phones. An unusual sign-up hour is not suspicious – people travel. What changes the picture is correlation: several weak signals lining up in a way that legitimate behaviour almost never produces. This is where device, behavioural and connection signals earn their place in the stack, because they read the live session and add separation that submitted details and one-off checks cannot.
The mechanics are shared, but the payoff a fraudster is chasing – and therefore the shape of the defence – changes by sector.
Here the new account is the credit decision. A fraudulent application is not just a fake profile; it is a loan that will never be repaid, often a first-payment default. Synthetic identities are patient in this vertical, building a thin but clean history before drawing down credit and disappearing. Because so much of the risk concentrates at the point of application, device and behavioural signals act as an additive layer on top of the credit model – separating genuine thin-file borrowers, who deserve access, from fabricated ones designed to look identical on paper. A born-bad account here rarely stays contained to one loan; it often becomes the launch point for downstream payment fraud, which is why stopping it at creation pays off twice.
For banks, new account fraud opens the door to mule networks and downstream money movement. An account created to receive and forward illicit funds may behave normally for a short window, which is why signals gathered at creation matter more than waiting for the first suspicious transfer. Onboarding is the cheapest place to stop the account, and the only place where the fraudster has not yet had time to blend in. Mule accounts, synthetic identities and first-party fraud all converge at this stage – we cover how they interact in our guide to bank account fraud, and the wider institutional picture in our banking fraud detection guide.
On marketplaces, fraudulent accounts become fake sellers, bogus listings and manipulated reviews that erode the trust the platform runs on. In e-commerce, they cluster around promotion abuse and inventory exploitation – dozens of accounts farming a new-customer discount or bypassing purchase limits to resell scarce stock. The financial hit is real, but the reputational one, as buyers lose confidence, often costs more.
In gaming, online gambling and other high-volume consumer platforms, multi-accounting drives bonus abuse, ban evasion and coordinated manipulation. iGaming is a particular target: sign-up offers, deposit bonuses and free bets are all built to reward new accounts, which is exactly what makes fabricating them profitable. Volumes are enormous and identity verification is often light, so device and behavioural correlation carries most of the detection load – recognising when many "different" players are in fact one operation running at scale.
Most published guidance on account opening fraud assumes rich underlying data: deep credit files, stable addresses, established digital footprints. In many of the fastest-growing digital markets – across India and South Asia, Latin America, Africa and Southeast Asia – that assumption does not hold. Credit bureaus have uneven coverage, onboarding is mobile-first, and a large share of legitimate applicants are genuinely thin-file, with little conventional history to check against.
That combination makes new account fraud both harder to catch and more damaging, because the usual verification anchors are missing precisely where fraud volumes are high. It also makes the signal layer more valuable, not less.
Device intelligence and behavioural analytics do not depend on a pre-existing credit record or a stored identity; they read the session in front of them. For a thin-file applicant with no bureau history, the device and its behaviour may be the strongest honest evidence available – which is why an approach that works without leaning on direct identifiers travels well across these markets.
Having the layers is one thing; orchestrating them without smothering legitimate sign-ups is another. The aim is not to stop every risky registration at the door but to make fraud expensive enough that it moves elsewhere, while genuine users pass through cleanly. That balance comes from applying friction in proportion to risk rather than uniformly – the difference between a control stack that protects conversion and one that quietly costs it.
In practice this means letting the risk score drive the routing. A clean sign-up from a trusted device with a consistent identity should meet no added friction at all, while the checks that carry a cost to the user – document upload, extra verification steps, manual review – are reserved for the registrations where the combined signal actually warrants them. Layered defence works only when the layers are sequenced by cost and risk, not stacked indiscriminately on everyone.
Done well, this reframes the growth-versus-fraud tension that risk leaders live with. The goal is not to reject more applicants but to reject the right ones – tightening exactly where the evidence warrants it, and clearing the path for the genuine customers, including thin-file ones, who would otherwise be caught by blunt precautionary rules. For a closer look at how the session-level layer feeds that decision, our article on device intelligence covers the mechanics in more detail.
JuicyScore analyses device, behavioural and connection signals in real time at the point of account creation – identifying new account fraud across lending, banking, marketplaces and e-commerce without relying on direct user identifiers. If you want to see how the signal layer fits on top of your existing onboarding and risk flow, book a demo with us and our team will walk you through the solution with your own use case in mind.
New account fraud is the creation of an account using stolen, synthetic or fabricated identity information to extract value rather than to become a genuine customer. It differs from account takeover, which targets accounts that already belong to real users. Because the account is fraudulent from the moment it exists, it has no legitimate history to expose it, making early signal-based detection essential.
New account fraud creates a fresh fraudulent account, while account takeover hijacks an existing legitimate one, usually through stolen credentials. Each type of fraud needs a different defence: account takeover detection watches for changes against a known baseline; new account fraud detection has no baseline and must read device, behavioural and connection signals from the registration session itself.
New account fraud is detected by layering several independent controls: identity and document verification, email and phone intelligence, device intelligence, behavioural analytics, network and velocity checks, bot defences, consortium data, and risk scoring that routes to step-up verification. Each has a bypass alone, so detection comes from correlating them in real time rather than relying on any single check.
Yes. Risk-based onboarding applies friction in proportion to risk instead of uniformly. Low-risk sign-ups from trusted devices and consistent profiles pass without extra steps, while higher-risk registrations are routed to step-up verification or declined. This concentrates friction where the signal warrants it and preserves a clean experience for the majority of legitimate applicants.
New account fraud affects digital lending, banking, BNPL, microfinance, marketplaces, e-commerce, and gaming. In lending it drives first-payment default and synthetic-identity credit loss; in banking it feeds mule networks; on marketplaces and in e-commerce it enables fake sellers and promotion abuse; and in gaming it powers multi-accounting and bonus abuse. The mechanics are shared even where the payoff differs.
If you found this useful, our newsletter shares how fraud and risk teams are handling new account fraud, device intelligence and digital risk across markets. It is occasional and practical, with no filler. You can subscribe here.

Discover what account takeover (ATO) fraud is, why it threatens digital finance, and how to prevent it effectively. Learn proven strategies to secure your business and protect your customers.

Explore how device intelligence improves fraud detection, credit scoring, and onboarding – with real-time analysis and privacy-first design.

Explore five common types of bank account fraud – from synthetic identities to mule networks – and how behavioral and device-based insights enable earlier, privacy-safe detection.
Get a live session with our specialist who will show how your business can detect fraud attempts in real time.
Learn how unique device fingerprints help you link returning users and separate real customers from fraudsters.
Get insights into the main fraud tactics targeting your market — and see how to block them.
Phone:+971 50 371 9151
Email:sales@juicyscore.ai
Our dedicated experts will reach out to you promptly