Blog post

Fraudsters Are Picking Their Targets More Carefully, and Getting Better at Hiding

Charlie Custer

Published

September 1, 2026

One of the most consistent patterns from our 1H 2026 Fraud Report is that fraudsters — or at least the most dedicated fraudsters and scammers — are operating with increasing sophistication:

  • They're targeting specific financial instruments, including 401(k)s and HELOCs.
  • They're using legacy PII and hyper-local residential proxies to defeat anti-identity-theft fraud controls.
  • They're specifically targeting institutions that don't require 2FA at account opening, allowing them to use a victim's real contact information without having to control it

More careful targeting

Organized fraudsters and scammers are increasingly setting their sights on financial instruments like HELOCs and 401(k)s that offer major advantages over other targets:

  • High value: the median value of a 401(k) account for an American in their 40s, for example, is over $150,000.
  • Long detection window: people look at their bank and card accounts weekly or monthly, but may not even log into their 401(k) for years.

In the Fraud Report and in this blog post, we have detailed some of our observations related to the "Yahoo Boys," a coalition of fraudsters and scammers that have been around for years and are now actively sharing details in their channels about how to target and acquire 401(k) and HELOC access. We also observed an uptick in high-risk HELOC applications over the course of 2025, although we cannot be certain whether there is a causal relationship.

And it's not just specific financial instruments that fraudsters are targeting; identity thieves are also targeting institutions that don't require two-factor authentication (2FA) at account opening because it allows them to blend in with the pool of legitimate applicants more effectively.

Better camouflage

Traditionally, contact and connection details have been some of the most effective ways for fraud prevention tools to flag identity theft. If an application comes in with a person's name and then a phone or email address they've never been associated with before, that's a red flag. If that person lives in New York but their application was submitted from an IP address in California, that's a red flag.

Fraud fighters know this, but fraudsters know it too, and the most sophisticated among them are using a variety of tools to combat it, removing these red-flag signals so that their applications blend in:

  • Legacy PII: Fraudsters use phones or emails previously associated with the victim but now controlled by the fraudster.
  • Current PII: if 2FA is not a part of the application process, fraudsters can submit the application using the victim's real phone and email (often followed by a contact change request to swap in a contact they control).
  • Residential proxies: thanks in part to the AI boom, residential proxies have proliferated faster than tracking services can keep up, allowing fraudsters to submit applications appearing to come from IPs very close to the victim's real location and often associated with the victim's real ISP.

While the majority of identity theft applications still trip these red flags — not all fraudsters are sophisticated! — these applications are finding their way through the cracks because they make the applications look both historically and geographically plausible given the victim's identity. For fraud teams, the takeaways are clear:

  1. Ensure your fraud models are up to date. SentiLink's latest ID Theft Score model, for example, contains improvements to detect and flag the use of Legacy PII and residential proxies.
  2. Implement two-factor authentication at onboarding. This will likely reduce the incidence of these applications, as fraudsters shift to other institutions in search of softer targets.
  3. Monitor for post-approval contact change requests and consider using tools such as SentiLink's PII Risk Scores to assess the risk associated with the requested change.

These patterns are among the trends discussed in our 1H 2026 Fraud Report, which also benchmarks fraud rates in the US and across various industries. Get your free copy here.

Content

Share

Learn how we can help.

Schedule a demo with a fraud expert and evaluate our solutions.