Blog post
The AI Boom Is Helping Identity Thieves Look Like Neighbors
Burt Helm
Published
August 13, 2026
- Two attacks on our partners this spring arrived from inside the victims’ own neighborhoods. These partners saw automated identity theft attacks in which applications came from IP addresses within a few miles of the victim’s home, often on the victim’s own internet provider.
- The mechanism is a residential proxy: web traffic routed through a stranger’s home internet connection, targetable down to the ZIP code and the internet provider.
- AI demand is why residential proxy supply exploded. Scraping the web at AI’s needed scale requires addresses that don’t look like data centers. That spending built infrastructure fraudsters now rent for cheap
- Detection is behind, and we tested it. We bought residential proxies on the open market ourselves; none were flagged by industry-standard tools.
- Legacy phone numbers finished the job. Many applications carried a number that had genuinely belonged to the victim years earlier.
- What we’re doing: Building model features purpose-built for residential proxy abuse, tested against real fraud attacks, and designed to catch more of the traffic that older anonymization logic could let throug
Every so often, a fraud attack stumps us (at first). Late this spring, two did: Within weeks of each other, two of our partners reported what looked like automated identity theft attacks: the kind where fraudsters take a batch of stolen identities and use software to try to open new accounts en masse. The weird part was the internet traffic. Every application looked like it was coming from the victim’s own home, or a few blocks from it, often on the same internet provider the victim actually used. Many of them used phone numbers that had belonged to the victims years earlier.
We dug in. What we found turns on a wonky phrase we knew all too well, one you may soon hear more often outside of cybersecurity circles: residential proxy. It isn’t a new idea — it just means routing your web traffic through another person’s device, so that whatever you do online appears to come from an IP address tied to their house, not yours. What’s new is that residential proxies are suddenly sprouting up everywhere, and getting harder to spot. The reason why is a story of supply and demand, bots and humans, and a confusing game of masks that’s causing havoc in the worlds of AI, cybersecurity, and fraud prevention.
The Original Proxy
To explain, we need to start with the most fundamental building block of the Internet: the Internet Protocol address. An IP address is a delivery address for machines. It tells the network where to send things back. That’s it.
The original sin driving this story — the approximation that launched whole industries devoted to identifying web traffic, redirecting it, and disguising it — is that an IP address tells you where a computer is, and therefore something about the person using it. For a long time that was safe enough. Addresses were handed out in blocks to providers operating in particular places. Traffic from an address belonging to a cable company in Ohio? Reasonable guess: a guy in Ohio.
Those reasonable guesses turned out to be worth money. Streaming services used IP addresses to enforce licensing deals, advertisers to target local audiences — and banks to flag a loan application filed thousands of miles from the customer’s address (hi, that’s us!). A routing detail evolved into an identity credential: a rough answer to where are you, and from there, a partial answer to are you who you say you are?
That spawned a mirror-image business. Once websites started behaving differently depending on which IP address you arrived from, there was money in being able to arrive from somewhere else. Retailers began tracking prices in other markets, researchers measured what’s blocked where. Others simply wanted anonymity, to mask their original IP.
All this created a third industry: telling the difference. Banks, retailers, ticket sellers (and fraud prevention companies like us) now pay specialist firms to map the internet’s masks — to flag traffic arriving through a VPN, a data center, or an address with a history of trouble. It’s an arms race: every advance in detection forces a new kind of mask, and every new mask forces advances in detection.
After AI, the flood
But here’s the thing: most of the Internet isn’t people anymore. Bots now generate more than half of traffic on the Internet, according to a 2026 report from Thales. Bots have jobs. Some are benign: search engines indexing pages, monitors checking that sites are up. Many aren’t: software scraping prices, testing stolen passwords against login pages, opening fake accounts. The unwelcome ones have to get past doors built to keep them out. Bots became the best customers of the industry that masks IP addresses as a result.
And then AI showed up to the party. AI needs bots, bots, and more bots — to read the entire internet for training, to fetch live pages for answers, to browse and book and buy on a customer’s behalf. And whether or not those web pages want to be crawled by AI bots (many don’t) AI bots find a way — by hook, by crook, or by proxy. AI companies and their kajillions of dollars have created a demand to mask traffic unlike anything that came before. Those resources are increasingly pouring into one very specific place: residential proxies.
Residential proxy is an umbrella term covering many different arrangements, some legal, some not. A guy running Honeygain, an app that pays a few dollars a month for your spare bandwidth, is a residential proxy. A malware-infected wifi router is a residential proxy. So is everything in between: a free game on your phone or a streaming app on your smart TV that resells your connection without telling you. This June, Spur found that proxy software is embedded in more than 42% of the apps in LG’s smart TV store.
Business is booming. Bright Data, one of the largest providers of residential proxy networks, advertises more than 400 million residential addresses. Last fall, Spur counted 250 million unique ones in a single ninety-day stretch, a number its co-founder called unheard of. Lumen’s threat researchers, who watch the criminal end of the market, see roughly 20 million distinct addresses a day and estimate that something approaching 60 million compromised devices are in circulation worldwide, about a quarter of them in the United States. All of it is for sale; access runs around a few dollars per gigabyte at volume. The dashboards are self-service and the targeting has gotten absurdly good: order traffic from a specific country, state, city, ZIP code, or internet provider, and hold the same address for as long as your session needs it.
Which brings us back to fraudsters, who built none of it but are benefiting from all of it. The same dashboard that sells a scraping operation for a million addresses in Ohio will sell a single address in a specific Ohio ZIP code to somebody holding a stolen identity from that ZIP code. This allows fraudsters to game risk scores that flag an application as risky when the applicant’s address is far from their IP’s location. Among a targeted sample of low-scoring fraud applications from our internal database assembled to study this phenomenon, every mile mattered: mean risk scores climbed steadily as the distance between address and IP grew, from under 200 for addresses within a kilometer of their IP to nearly 400 once that gap passed 100 kilometers.
The two attacks and what’s next
The two recent attacks on our partners used this tactic at scale across thousands of identities. An automated system paired each stolen identity with a proxy address as close to that person’s home as it could get. When an application didn’t clear, the same identity came back on another application from a different nearby IP address. SentiLink’s scores caught most of it — that’s how the partners noticed the attack in the first place, with the share of applications we flagged high-risk climbing from about a third to roughly 80% in a matter of days. But enough got through to concern us. Many of the applications also carried a phone number that had genuinely belonged to the victim years earlier, since abandoned, reissued, and captured by the fraud rings. Like proximity, an old number can read as continuity to fraud models. But in these cases, these numbers meant OTP verification codes went to the attackers further lowering traditional risk signals.
So why didn’t our proxy detection alone catch every application? Part of the answer is that lists of proxy providers flagged as risk are always lagging the market. Addresses enter these pools by the millions, and some look ordinary until they are used in an attack. In our own testing, some residential proxies available for purchase did not appear on common lists of risky proxies. But there’s another reason too: older models flagged only the riskiest providers and let several larger, mainstream providers pass, since a relatively small portion of their traffic is used for fraud. The latest models target all residential proxies, then combine other signals to separate risky from legitimate traffic within those large IP pools.
So we’re working on all fronts: widening the list of risky proxies, digging into traffic within each proxy, and pushing for IP information that keeps pace with the evolving threat landscape. It means new models with features devoted to solving this problem. Before long, it may also mean questioning the industry assumption that IP is a valid stand-in for identity.
Learn more: This is one of the trends we’re monitoring in our twice-yearly fraud report. Sign up to make sure you receive it.
Related Content
Blog article
August 13, 2026
The AI Boom Is Helping Identity Thieves Look Like Neighbors
Read article
Blog article
July 21, 2026
Fraud Markets Are Now Selling Trips to Consumers
Read article
Blog article
June 26, 2026