Blog post
What We Heard at Datos: 3 Takeaways
Cam Dufty
Published
September 24, 2026
The fraud and financial crime teams we talked with at Datos Financial Crime and Cybersecurity Forum 2026 focused mostly on the same three themes:
- They aren’t really fighting new fraud. It’s more about familiar MOs arriving with better infrastructure behind them and more sophisticated tactics, and how the controls that previously worked are now struggling to keep pace with fraudster scale and speed.
- No single signal holds up alone. Every point-in-time check that answers solely is a person who they claim to be is being battered by AI advancements that can reproduce a person convincingly. Layering cross-institutional views and history is playing a bigger part in fraud detection than ever before.
- First-party fraud is hard to measure, and harder to detect, partly because losses are misclassified as credit risk rather than fraud, which means no investigation and a vulnerability that stays open for the next attempt (in 2026 retrostudies, we found institutions carrying roughly five times more first-party fraud on their books than identity theft and synthetic fraud combined).
We’ve put together more detailed takeaways, and where we’re seeing these patterns across our own data, in the blog post below.
Takeaway 1: Speed is the best defense
Fraudsters are finding vulnerabilities and adapting their tactics faster than many defenses can keep up.
This isn’t news to anyone in the fraud space: moving faster than bad actors is always the goal. But the depth and sophistication of today’s evolving MOs is redefining what that looks like.
For example, in two large identity theft attacks on SentiLink partners in the first half of 2026, fraudulent applications appeared to come from the victims' own neighborhoods, over ordinary home internet connections.
The attackers were using residential proxies. For years, institutions largely kept pace with this threat through commercial detection services that map VPN and proxy IP ranges. But when our researchers purchased residential proxies and checked the IP addresses they received against the commercial proxy-intelligence data used in SentiLink's own screening, these industry-standard detection lists didn't identify them as proxies.
Detection tools, rules, and models all depend on knowing what an attack looks like. But the attacks are now changing faster than many models are prepared for (this is one reason that we emphasize for our partners the importance of upgrading to new model releases as soon as possible, to stay ahead of emerging threats).
Takeaway 2: One signal isn’t enough
Synthetic fraud rates across SentiLink partners have stayed relatively flat over the first half of 2026, even as identity theft hit the highest level we've recorded. The suspected reasons for this are unglamorous: broader recognition of the MO, and tools like eCBSV that let an institution check an SSN against an authoritative source. Synthetic identity fraud is simply harder to get away with than it was three years ago.
The MOs filling that synthetic fraud space aren't new. But they are ones that a single signal can’t catch.
The biggest example is first-party fraud. In 2026 retrostudies, we found roughly five times as much first-party fraud sitting on institutions' books as identity theft and synthetic fraud combined. In first-party fraud attacks, the name, DOB, and SSN are accurate, so there's no PII inconsistency to catch, no victim to file a report, and no eCBSV equivalent to check against.
Another is simply more sophisticated identity theft. Residential proxies, legacy PII, and assumed identity abuse all work by making a stolen identity look like a real customer on exactly the dimensions a verification check measures. The most common pattern we see at scale is automation stacking these together.
Underneath both is a classification problem. First-party fraud is especially prone to under-classification, so it gets written off as credit losses instead of investigated and tagged as fraud. And when a case does get reclassified later, the original record usually doesn't get corrected.
A loss classified as credit risk generates no investigation, which means the vulnerability that produced it stays open. And when fraudsters’ recognize an institution's weak points they distribute that information widely, to the point where there is public "how-to tutorials" naming specific institutions.
The answer to first-party fraud is to look at the record an identity leaves beyond a single application. Does the history make sense? Do the behaviors match? Are there records and relationships that support the identity? Risk indicated in cross-partner activity data ranks among the top most reliable fraud signals in every industry we cover.
AI can produce a convincing representation of a person, but it can't produce the cross-institutional history, and it can't rewrite an identity’s fraud markers. Layering applicants’ history, device and network intelligence, and document checks means a fraudster has to beat all of them at once — a much harder task.
Takeaway 3: The whole lifecycle is an opportunity
Questions that came up at our roundtable highlighted the importance of looking at fraud across the entire customer lifecycle.
Risk can emerge at account opening, during transactions, when money moves, at cash-out, and at dispute — some of the schemes we’ve tracked never even involve a fraudulent application at all.
For example, the "formats" that SentiLink's Fraud Intelligence Team found for sale in a Yahoo Boys Telegram channel are scripts for talking a victim into liquidating their own retirement account. Buyers are advised to control victim accounts through remote desktop sessions on compromised computers in the victim's own region, so logins appear local. Nothing suspicious is ever submitted and the account was opened years earlier by the real customer.
Fraud that isn't caught at the point of application is expensive. Across 1.6M+ applications from 2022 to 2026 that SentiLink retroactively scored, the average charge-off on a high-risk application was $6,149, rising to $9,276 for synthetic fraud and $8,745 for first-party fraud. In credit cards, charge-offs tied to high-risk applications ran 68 times the average across all credit card charge-offs (for more on all these numbers, download our 1H 2026 Fraud Report)
Watching the full lifecycle gives you more chances to catch the same fraud, and more ways to respond that don't add friction for a good customer. This is why it's a good idea to institute checks for account changes, such as contact change requests, and phone, email, and device risk scores that reach beyond initial onboarding.
What are your Datos takeaways?
We’d love to hear if this resonated with your biggest learning from Datos. You can contact our team here. Or, download SentiLink's latest Fraud Report for more insights into the evolving fraud landscape.