# Fraud Got Cheaper to Fake, Thanks to AI. Checking for It Didn’t

> Source: <https://industrycontents.com/ai-fraud-detection-verification/>
> Published: 2026-08-02 23:49:07+00:00

19 min read

## Table of Contents

## TL;DR — tap to expand the short version

- Small merchants’ fraud tools (Shopify, Stripe Radar, WooCommerce plugins) verify the card, not the person, leaving a gap that AI-generated fraud attempts are built to slip through
- The cost of attempting fraud has fallen by an order of magnitude while the cost of checking for it has fallen only in the single digits, breaking the assumption that both scale together
- Synthetic identities can pass every check for 22 months by design, Equifax’s own case data shows a fraud ring building credit for nearly two years before a $723,721 bust-out
- Most AI fraud detection today still runs as one uniform check rather than a tiered, risk-based system, and even tiering doesn’t solve fraud built specifically to generate no detectable signal at all
- Agentic AI adds a new question underneath the old one: it’s no longer just “is this person real,” it’s “is the agent acting on their behalf authorized”

A Shopify seller posting under the username *slugbutter* on Reddit recognised a pattern that started a few weeks earlier. He was getting orders for a single one-dollar item, nothing else in the cart, from buyers with names that looked like random strings of characters, most shipping to addresses in and around Charleston, South Carolina, USA.

The seller’s normal catalog runs closer to $50 an item. Whoever was placing these orders was paying $8 in flat-rate shipping for a one dollar product, sometimes two or three times a day, sometimes not for several days, and buying nothing else. The seller knew it looked like a scam but it wasn’t obvious why anyone would bother scamming for a dollar.

They wouldn’t, not for *the dollar*. The purchase is the *tell* of something else. A stolen card being tested to see if it still works, on an item cheap enough that a merchant is unlikely to fight the chargeback if it turns out to be fraud. Once a batch of cards clears that test, the same numbers get used for larger purchases elsewhere, on sites the original merchant doesn’t see.

Mastercard’s [explainer on card testing fraud](https://www.mastercard.com/us/en/news-and-trends/Insights/2024/card-testing-fraud-explained-how-merchants-can-respond.html) describes this as an automated script parsing through stolen numbers to find which ones still work. It’s also a pattern built to slip past the common fraud tools small merchants use. Shopify, like most ecommerce platforms, scores every card order automatically using signals covered in its [own payments fraud analysis documentation](https://help.shopify.com/en/manual/payments/shopify-payments/configuring-shopify-payments), address verification (AVS), CVV matching, IP location, and behavioral patterns, then surfaces a risk level in the merchant’s dashboard. But those checks verify something about the *card*, not the *person* using it.

AVS matches the billing address with what the card issuer has on file. CVV confirms whoever is checking out has the card number in hand. But neither confirms identity, and a card that hasn’t been reported stolen yet will often clear both checks cleanly. The same reason *slugbutter’s* orders weren’t flagged before they became obviously strange. AVS itself was built for mail and phone orders decades ago and wasn’t designed as a complete solution for online transactions.

Yet the deeper bottleneck is more structural than a gap Shopify or any single platform failed to address. When these systems flag an order, they produce a recommendation rather than an automated decision, which means a person still has to review it, and manual review scales the way payroll does: linearly, with diminishing returns and rising error rates as volume grows.

That was manageable when fraud volume grew roughly in step with legitimate order volume. It stops being manageable once one side of that ratio is being generated by AI at a pace no review queue was built to absorb. Three-quarters of merchants surveyed in Veriff’s [2026 Fraud Industry Pulse report](https://www.veriff.com/resources/ebooks/fraud-industry-pulse-report-2026) said fraud hurt their revenue, and three in four specifically pointed to AI-driven attacks as the cause.

A rule-based check built to catch known patterns, mismatched address, blacklisted IP, unusual velocity, is reactive by design. Generative tooling is the cherry on top of a problem already boosted by automation and data availability.

## Three Platforms, Three Different Blind Spots

Put three of the biggest platforms side by side and the issue isn’t *overlap*.

| Platform | What it checks natively | What it explicitly cannot do |
|---|---|---|
| Shopify | AVS, CVV, IP location, device fingerprinting, velocity limits, network-wide known-scammer signals | Confirms card data, not identity; flags require human review, doesn’t auto-decide |
| WooCommerce | No native fraud scoring; relies on whichever payment gateway and plugins a merchant installs | Core platform provides no built-in transaction-level scoring; protection quality depends on gateway and plugin configuration, which varies widely by store |
| Stripe (Radar) | Network-wide machine learning across hundreds of signals, including device fingerprinting, behavioral patterns, and a fraud signal shared across businesses on Stripe | Its own guidance for cases where velocity or card-number patterns suggest a synthetic identity is to require ID verification or block outright |

Shopify and Stripe both score transactions well. Neither claims to confirm *who’s* behind the transaction. WooCommerce’s core platform doesn’t provide native transaction-level fraud scoring; protection depends heavily on the payment gateway and additional plugins a merchant installs, which means fraud protection for a huge share of WooCommerce stores is only as good as the gateway configuration someone remembered to turn on.

Even Stripe’s own [Radar documentation](https://docs.stripe.com/radar), widely regarded as the most sophisticated of the three, directs merchants toward identity verification rather than claiming Radar can settle the question itself. Identity and transaction risk are different problems, solved by different tools. No amount of refinement at the payment layer closes that gap on its own.

It’s a *silent* failure underneath a much louder story about AI and fraud. The headlines are about deepfakes and synthetic identities, but underneath them is a simpler problem of miscalculated accounting. The cost of attempting fraud has fallen much faster than the cost of stopping it, and a lot of verification infrastructure, including the common checkout-level tools merchants rely on, assumes those two costs move together.

For most of the last two decades, identity verification at scale meant picking a threshold and applying it uniformly. A bank, a lender, or a marketplace would decide on a level of friction, a document scan here, a selfie there, and run every new customer through the same gate.

The logic made sense when it was built. Fraud attempts were expensive enough for the attacker that volume stayed roughly proportional to the size of the legitimate customer base. A criminal ring manually sourcing stolen identities, formatting fake documents, and running the con by hand could only scale so far. Uniform verification was a reasonable match for a threat that scaled at roughly the same rate as the business did.

That assumption is what’s *broken*.

## Two Cost Curves Moving at Different Speeds

On the attack side, generative tools collapsed the labor cost of producing a convincing fraud attempt. Fake documents, synthetic faces, cloned voices, and scripted bot traffic that mimics real user behavior are now something a non-technical operator can rent.

Pindrop, a voice-security provider, [reported in its detection data](https://www.pindrop.com/article/ai-fraud-trends-and-risks/) a 1,210% rise in synthetic, replayed, and modulated voice fraud in 2025, against a 195% rise in traditional fraud over the same period. That figure describes one channel, voice and virtual-meeting fraud, inside its proprietary numbers, and it’s not an independent measure of AI fraud across payments and identity broadly.

But the direction matches everything else perfectly. LexisNexis’s [2026 Cybercrime Report](https://risk.lexisnexis.com/global/en/about-us/press-room/press-release/20260326-ccr-global-fraud) found synthetic identity fraud rose eight-fold globally in the same year, now accounting for more than one in ten reported frauds worldwide.

On the verification side, costs have moved, but nowhere near as fast. Juniper Research’s [analysis of digital identity verification costs](https://www.juniperresearch.com/resources/infographics/cost-per-digital-identity-verification-checks-to-drop-15-globally/) found that the average check cost around $0.20 in 2025, projecting a decline to $0.17 by 2029, a 15% drop stretched across four years. Fuller verification flows, the kind that combine document checks with liveness detection and biometric matching, run higher: standard market pricing across major providers in 2025 and 2026 lands between $1.00 and $3.00 per verification, with database-only checks running $0.50 to $1.50 and the addition of document and liveness layers pushing costs toward $4.00.

If you put those two curves next to each other, the cost of attempting fraud fell by an order of magnitude. The cost of checking for it fell by single digits, and checking thoroughly still costs real money per transaction. A company running one verification tier across its entire user base is effectively paying the same $1 to $3 fee to screen a legitimate repeat customer as it does to screen an account that a fraud ring is testing for the twentieth time that day.

Businesses are feeling this asymmetry directly. Nearly 60% of companies reported that fraud losses increased from 2024 to 2025, and 72% of business leaders now name AI-enabled fraud as a top operational challenge.

Consumers are absorbing a different shade of the same problem. The Federal Trade Commission’s [March 2025 data release on fraud losses](https://www.ftc.gov/news-events/news/press-releases/2025/03/new-ftc-data-show-big-jump-reported-losses-fraud-125-billion-2024) found consumers lost more than $12.5 billion to fraud in 2024, with losses climbing 25% even as the total number of fraud reports held roughly steady, meaning each successful attempt is, on average, doing more damage than it used to. The FTC’s preliminary 2025 figures put that number even higher, near $15.9 billion, suggesting the trend hasn’t slowed.

## Inside a Two-Year Nurture Period

Most synthetic identity coverage describes the mechanism in the abstract: fraudsters combine real and fabricated data, build a credit history, then cash out. Equifax’s [2019 whitepaper on synthetic identity fraud](https://assets.equifax.com/assets/usis/synthetic_identity_fraud_look_behind_mask_wp.pdf) walks through a named-but-fictitious example. A fraudster fabricates a Social Security number and pairs it with an invented name, “Helen Day,” and a date of birth. Helen Day applies for credit and gets denied. But the application itself is enough: the inquiry generates a credit file at the reporting agency, and Helen Day now exists on paper.

The fraudster pays a real cardholder with good credit to add Helen Day as an authorized user. Within two months, Helen Day has opened five accounts at five institutions. Eight months in, the same cardholder has four synthetic identities riding on his account, and together they’ve opened 28 accounts at 13 institutions. None have gone delinquent *yet*.

The bust-out doesn’t come until month 22. In Equifax’s example, one compromised cardholder account ends up legitimizing eight synthetic identities that open 66 fraudulent accounts and generate $723,721 in losses across 26 creditors.

The tell was behavioral rather than documentary. Helen Day checked her credit score roughly five times more often than an average consumer in the run-up to the bust-out. Real accounts change addresses about once every 70 months. The synthetic ones in this example changed every 10.

The Federal Reserve’s [2019 white paper on detecting synthetic identity fraud](https://fedpaymentsimprovement.org/wp-content/uploads/frs-synthetic-identity-payments-fraud-white-paper-october-2019.pdf) found something similar at scale. According to a study by ID Analytics, fraud models built to catch traditional identity theft failed to flag 85% to 95% of potential synthetic identity applicants, because synthetic accounts are built specifically to behave like normal ones while they’re being nurtured. TransUnion’s [research on synthetic identity behavior](https://www.transunion.com/blog/are-your-customers-real-synthetic-identities-driving-fraud) has found that the average charge-off rate for likely synthetic identities within a lending portfolio runs under 30%, meaning most suspected synthetic accounts are, for most of their life, making payments on time and looking exactly like a real customer building credit.

## Pricing Risk Instead of Flattening It

The industry’s answer has been to stop treating verification as a single gate and start treating it as a series of graduated checks, cheap and fast for low-risk signals, expensive and slow only where the signal warrants it. This is what’s generally described as risk-based or tiered verification. A database check for a returning customer with a clean history, a fuller document-and-liveness flow for a new account showing unusual signals, and manual review reserved for the smallest slice of cases that clear neither bar.

The economic logic becomes simple once the cost curves are laid out. If a full verification flow costs multiple dollars and a database-only check costs under a dollar, applying the expensive flow to every transaction only makes sense if the fraud rate across the whole population is high enough to justify it. As attack volume concentrates in specific patterns, new accounts from unusual geographies, sign-ups clustering around known abuse vectors, transaction sequences that match bot behavior, spending the expensive check everywhere becomes wasteful in exactly the way that spending nothing everywhere is reckless.

The opposite failure is also expensive. A system that becomes too aggressive blocks legitimate customers who happen to look unusual. Cherry Servers, a Lithuania-based cloud hosting provider, offers a concrete case. According to identity verification provider [Denfy’s Cherry Servers case study](https://idenfy.com/use-cases/cherry-servers-idenfy-study/), switching from a largely manual process to automated, risk-weighted checks cut new-client verification time by 65%. That figure maps onto the broader pattern of a company facing fraud losses in specific channels, in Cherry Servers’ case, payments from countries where 3D Secure protection wasn’t available, moved toward calibrated rather than uniform checks and reported a meaningful efficiency gain.

Mastercard’s [research on AI and fraud prevention](https://www.mastercard.com/global/en/news-and-trends/Insights/2026/ai-is-helping-banks-save-millions-by-transforming-payment-fraud-prevention.html) points to a similar effect at larger scale. 83% of industry leaders surveyed said AI-driven fraud tools have reduced false positives and customer churn, based on a Mastercard and Financial Times Longitude survey of 300 payments executives. That’s the other side of the tiering argument. The goal isn’t only catching more fraud; it’s not declining or slowing down legitimate customers who don’t need the expensive check in the first place.

A uniform, high-friction check applied to everyone doesn’t just cost the company money per transaction; it costs them customers who abandon a slow signup flow. Tiering is as much a response to that abandonment problem as it is a response to fraud losses.

Credit bureaus are making a similar bet at a larger scale. Equifax’s [press release announcing Synthetic Identity Risk](https://investor.equifax.com/news-events/press-releases/detail/1387/equifax-introduces-enhanced-synthetic-identity-fraud), launched in January 2026 and followed in April with a companion tool, Credit Abuse Risk, makes the argument that confirming someone’s creditworthiness and confirming that the applicant is a real person require different tools and data sets, since a strong credit score doesn’t prove the person behind it is genuine. That’s a structural admission from inside the credit industry that a single check, however good, can’t do both jobs at once, the same logic driving tiered verification at the transaction level, applied one layer up.

## Where AI Fraud Detection Tiering Runs Out

Tiering assumes risk shows up as a signal, the system can read such as unusual velocity, a mismatched device fingerprint, a geography flagged as high-risk. That assumption holds for a meaningful share of fraud. It doesn’t hold for fraud built specifically to generate no signal at all, no single victim to report it, no stolen person watching their credit report for signs of compromise, which is a growing share of the losses that matter most.

The numbers on synthetic identity are larger than the headline TransUnion figure suggests. TransUnion’s H1 2025 report put total U.S. credit exposure to suspected synthetic identities at $3.3 billion, a 3% increase since the end of 2023, and that’s likely an undercount. Much of this stays hidden in public statistics because losses from synthetic identities are frequently booked internally as credit losses rather than fraud losses, since the accounts look, on paper, like normal customers who simply stopped paying.

Fraud teams increasingly rely on a lookback window of 12 to 18 months and graph analytics that map relationships across accounts sharing identifiers like phone numbers or device IDs to catch this pattern, a fundamentally different kind of check than anything that happens at signup. A risk-tiered gate evaluates a moment. Synthetic identity fraud is built to survive any single moment and only becomes visible over time.

Agentic AI traffic complicates the picture differently. Automated systems capable of independently completing logins and payments, distinct from simple scripted bots, saw traffic surge 450% in 2025, according to LexisNexis, and some share of that traffic is legitimate: AI shopping agents acting on behalf of real customers, not fraud rings.

A verification system tuned to flag automated-looking behavior now has to separate a shopping agent buying groceries for its owner from a bot testing stolen card numbers, using signals that can look nearly identical from the outside, no mouse movement, uniform timing between actions, a browsing pattern that doesn’t match typical human hesitation.

Andras Cser, a Forrester vice president and principal analyst covering fraud management, has pointed in his [analysis of generative AI in fraud management](https://www.forrester.com/blogs/the-benefits-generative-ai-brings-to-fraud-management) to behavioral biometrics, reading mouse movements, typing rhythm, touchscreen pressure, device sensor data, as one of the more durable signals against this kind of automated traffic, precisely because it’s harder for a script to fake a full behavioral profile than to fake a single data point.

The problem is that the definition of what needs verifying is also shifting. Diane Deng, a Forrester senior consultant, put it plainly in her [Money20/20 Amsterdam takeaways](https://www.forrester.com/blogs/my-takeaway-from-money-20-20-for-your-gtm-team/) from mid-2026: an agent acting on a customer’s behalf now has to be verified *itself*, not treated as a proxy for a verified human. Attackers are already working both sides of that shift, she noted, using agents to industrialize deepfakes and synthetic identities while fraud teams begin deploying their own detection agents in response. The question isn’t only whether the person behind an account is real anymore. It’s whether the agent transacting on their behalf is *authorized*, a layer most checkout-level fraud tooling was never built to ask.

Synthetic identities and agentic traffic share a thread that should temper any confidence in tiering as a full solution. Neither is an evasion of a specific rule. Both are constructed to be unremarkable by the rule’s own standards.

## Trust Stops Being a One-Time Question

What’s changing *isn’t just* fraud tactics. It’s the nature of what “verified” means. A one-time gate, pass or fail at signup, made sense when identity was something to be confirmed once and trusted afterward.

Continuous, probabilistic risk-scoring assumes the opposite: that trust has to be re-evaluated at every meaningful interaction, because the account that looked clean at signup can be a synthetic identity accumulating credit for eighteen months before it defaults, or a real account taken over three transactions ago by a script no one at the company has looked at yet.

That shift carries its own costs, mostly around privacy and false positives, that the industry hasn’t fully reckoned with. Continuous scoring means continuous data collection. It also means a company’s fraud model is making judgment calls about legitimate customers’ behavior on an ongoing basis, not just at the door.

Helen Day passed every check anyone ran on her for 22 months. Nobody caught a lie, because there *wasn’t* one to catch in the way fraud detection looks for one, a mismatched address, a flagged card, a document that doesn’t scan right. The system did its job and still missed her. She’d spent two years making the answer *true*.

That’s the harder problem underneath all the tiering and scoring and graph analytics being built right now. None of it is *wrong*. It’s just built to answer a question that assumes the answer *holds still* once you’ve asked it.

## FAQ

A small transaction acts as a low-cost method to confirm that a stolen card is active and functional before attempting larger, more significant purchases. Because merchants are less likely to dispute a minor charge, this method allows thieves to verify card details while avoiding immediate detection.

No, these platforms primarily use signals like AVS, CVV, and device fingerprinting to validate card information rather than confirming the actual identity of the user. While these tools provide fraud scoring, they do not inherently verify that the person making the purchase is the card’s legitimate owner.

Synthetic identities can go undetected for extended periods, sometimes spanning nearly two years, by mimicking the behavior of real customers building credit. During this time, fraudsters may open numerous accounts and pass standard security checks before eventually cashing out.

Tiered verification optimizes resources by applying basic checks to low-risk transactions while reserving more expensive document or liveness verification for suspicious accounts. This approach prevents the unnecessary costs associated with performing high-level security checks on every single customer.

Tiered verification is often insufficient because synthetic identities and AI agents are specifically designed to appear unremarkable to standard risk signals. To counter these threats, fraud teams must utilize deeper strategies like graph analytics and longer lookback windows to identify hidden relationships between accounts.

## Recommended Reading

[Merchants Spent a Year Building Agentic Checkout Nobody Uses Yet](https://industrycontents.com/agentic-checkout-adoption-gap/), on why the agent-verification problem this piece raises is still mostly theoretical at the checkout stage[AI Agents Are Confirming Orders That Were Never Placed](https://industrycontents.com/ai-agent-journey-hallucinations/), a related failure mode where the trust gap sits downstream of purchase rather than at verification[Amazon Seized 15M Fakes With AI. The Counterfeiters Are Using the Same AI](https://industrycontents.com/brand-protection-stack-scaling-sellers/), the same cost asymmetry playing out in counterfeit goods instead of stolen identities[Claude vs ChatGPT: Which AI Security Incident Was Worse](https://industrycontents.com/claude-vs-chatgpt-ai-security-incident-worse/), on containment failures in systems built for a threat model that had already moved on[A 4.7 Product Rating Doesn’t Move AI the Way You’d Expect](https://industrycontents.com/ai-shopping-agents-ignore-star-ratings/), on how trust signals built for humans stop working once the buyer is an agent
