惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
有赞技术团队
有赞技术团队
WordPress大学
WordPress大学
月光博客
月光博客
T
Tailwind CSS Blog
阮一峰的网络日志
阮一峰的网络日志
小众软件
小众软件
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Last Week in AI
Last Week in AI
大猫的无限游戏
大猫的无限游戏
S
SegmentFault 最新的问题
罗磊的独立博客
Jina AI
Jina AI
酷 壳 – CoolShell
酷 壳 – CoolShell
宝玉的分享
宝玉的分享
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 三生石上(FineUI控件)
量子位
雷峰网
雷峰网
Apple Machine Learning Research
Apple Machine Learning Research
美团技术团队
博客园 - 聂微东
V
V2EX

PYMNTS.com

Treasury Calls for Programmable Financial Enforcement Across Crypto DeepSeek Seeks $20 Billion Valuation as Tech Giants Weigh Investment Google Accelerates Agentic AI Shift With New Enterprise Platform OpenAI Begins Briefing Governments on Cybersecurity Capabilities DeFi Security Suffers New Blow With $3 Million Volo Exploit Uninvited Users Access Anthropic’s Mythos AI Model Block and Uber Expand Partnership Across Several Global Markets OpenAI Pledges $1.5 Billion to PE Enterprise AI Project Podcast: Inside the $9 Billion DeFi Hack That’s Shaking Crypto’s Foundations Synchrony CFO Flags Momentum in Spending and Credit Banks Risk Slowing the Emerging Middle Market Firms Driving Growth Paysafe Expands Digital Wallet Availability Across 18 European Markets Bad Data Can Break Good AI in Payments 50% More Digital Shopping Days Put Parents at the Center of Retail’s Shift 65% Call Insurance Essential. Why Most Spending Isn’t So Clear-Cut Amazon Recasts Marketplace Fraud as a Broader Trust Problem Capital One’s Q1 Shifts Attention From Spending to Strategy Lawmakers Question JetBlue About Surveillance Pricing Allegations Small Businesses Stop Chasing Amazon on Delivery Speed Google Embeds AI Into Chrome for 3.5 Billion Users Adobe Plans Outcome-Based Pricing for New AI Product Suite UnitedHealth Spends $1.5 Billion on AI and Wants Double Back MiCA Forces Crypto Firms to Get Licensed or Get Out Prediction Market Kalshi Targets Crypto Perpetuals New York Sues Coinbase and Gemini Over Prediction Markets Amazon and Anthropic Deepen Ties With Investment and Hardware Pact Agentic B2B Is Here. Are Your Contracts and Invoices Ready? Apple Hardware Leader John Ternus to Succeed CEO Tim Cook The Web Is Gaslighting AI Agents and Nobody Can Tell OCC Enters the Interchange Fight and Raises the Stakes
Fraudsters Hack the Signals Behind Identity Trust
PYMNTS · 2026-04-23 · via PYMNTS.com

The cybersecurity arms race, true to its name, is turning into a sprint.

Malware evolves by the hour, ransomware syndicates operate like multinational firms, and state-backed actors are continually probing and even intruding across the edges of critical infrastructure.

As a result, the front line for financial institutions is shifting. Attackers today are not breaking the identity systems powering financial services outright. Instead, they are working within them, manipulating the signals those systems rely on to establish trust.

“We’re seeing a clear move in fraud from artifact manipulation to now signal manipulation, and most worrying, it’s now going to system manipulation,” Henry Patishman, executive VP, Identity Verification Solutions at Regula, told PYMNTS.

Simply put, fraud is shifting from faking inputs to shaping outcomes. Attackers combine valid-looking identity signals — from IDs, biometrics, device and behavioral data across onboarding and authentication — and exploit how systems make decisions. The result: identities that look legitimate, but don’t actually correspond to a real person.

Advertisement: Scroll to Continue

That emerging threat, one that industry insiders are beginning to call “identity signal manipulation,” is forcing a rethink of how digital identity is verified across payments, banking and online platforms.

“In a world where everything can look real, trust will depend on how well you understand the integrity of identity signals, not just their appearance,” Patishman said.

The question is no longer whether a user was verified at a moment in time, but whether their identity remains consistent and trustworthy across sessions, devices and behaviors.

Fraudsters Move From Spoofing to Orchestration

What distinguishes this new threat from earlier forms of fraud is not just sophistication, but orchestration. Attackers are no longer spoofing a single attribute; they are coordinating multiple signals simultaneously to construct a convincing digital identity.

A recent case in the Netherlands cited by Patishman can help to illustrate the shift. A single attacker successfully opened nearly 50 bank accounts using real stolen passports, a live participant in front of a camera, and subtly altered biometric inputs. Each individual component appeared legitimate and collectively they were able to tell a false story that banking fraud systems failed to detect.

“The interesting part was that real documents, real selfies, and a real human were all part of the process, but manipulated just enough to pass the controls,” Patishman said.

And that is the emerging essence of signal manipulation: not falsifying identity outright, but bending reality just enough to slip through fragmented defenses.

What makes these attacks particularly effective is how identity verification systems are structured. Many still treat verification as a one-time event, like a checkpoint at onboarding or login. But in practice, identity is expressed across a sequence of interactions — from onboarding to login to transactions — each generating its own signals.

“One of the biggest shifts is that identity verification is no longer a single decision,” Patishman said. “It’s a chain of signals over time.”

Fraudsters have adapted accordingly. Rather than attempting a single high-risk breach, they probe for weak links across that chain, such as by injecting synthetic video into a camera feed, replaying biometric sessions, or subtly altering device data. Each signal may pass independently. The deception now lies in how they fit together.

Trust at the Source, Not the Outcome

The fraud realities facing financial institutions is also driving a deeper conceptual change in identity verification, one that is moving away from validating outcomes and toward validating origins.

The emerging model emphasizes what might be called “signal provenance”: understanding where data comes from, how it was captured, and whether it has been altered along the way. It’s an approach that borrows from legal frameworks, where evidence must be supported by a clear chain of custody.

“Trust can’t be inferred from outcomes anymore. It has to be proven at the point of capture,” Patishman said. “A biometric match proves similarity, not authenticity.”

Traditional systems often focus on results such as a document or face match. But attackers increasingly manipulate inputs before those checks even occur, producing outputs that appear valid but are fundamentally compromised.

“Biometrics don’t fail,” Patishman said. “But the systems around them can fail to verify their authenticity.”

In practice, systems may correctly match biometric data — but still fail to detect that the input itself has been manipulated or synthetically generated. The result is a valid match built on compromised data.

At the same time, while many organizations have invested in strong individual tools, those tools often operate in isolation.

“Fraud doesn’t happen in one signal, it happens in gaps between them,” Patishman said. “The next generation of identity verification isn’t a better check with a better tool. It’s a coordinated system that understands how signals relate to each other.”

This means a document, a biometric check, and device or behavioral data may each appear valid on their own, but still not belong to the same identity. When these signals are verified separately, those inconsistencies can go unnoticed.

Closing those gaps requires orchestration: systems that correlate signals across sources and over time, identify inconsistencies, and adapt dynamically to risk. Rather than a series of independent checks, identity verification becomes an evidence-based process.

Ultimately, as Patishman said, “security is now much more reliant on system and process design, not just tool accuracy.”