Articles

The Fraudster in the Mirror: Why Your Biggest Threat Might Be Your Own Customer

A major new cybercrime report confirms what fraud teams have quietly suspected for years and adds a fresh warning about AI-powered imposters that are getting uncomfortably good at being human.

The Fraudster in the Mirror: Why Your Biggest Threat Might Be Your Own Customer

LexisNexis Risk Solutions released its annual Cybercrime Report this week, drawing on analysis of more than 116 billion online transactions processed through its Digital Identity Network in 2025. The headline figure is an 8% rise in global fraud attacks. The more interesting story is in the details and some of them are distinctly uncomfortable.

Start with the finding that tends to get buried in conversations dominated by hacking and synthetic fraud: the single largest category of fraud, globally, is customers defrauding the organisations they do business with. First-party fraud — customers falsely disputing charges, exploiting refund policies, or misrepresenting their identities to secure credit — accounted for 38.3% of all reported fraud in 2025, making it the leading fraud type for the second consecutive year. In the UK and broader EMEA region, that figure climbs above 51%. More than half of reported fraud, in other words, isn’t an external attacker. It’s the person on the other side of the checkout.

That finding sits awkwardly alongside the industry’s instinct to frame fraud as something that happens to businesses and consumers, not by them. The cost-of-living context is hard to ignore. When household finances are stretched, the moral calculus around disputing a legitimate transaction or overstating a claim shifts for some people in ways that don’t register as crime in their own minds — even when they technically are.

The Identity That Never Existed

If first-party fraud is the familiar enemy hiding in plain sight, synthetic identity fraud is the one keeping risk teams up at night. One in ten frauds now involves a synthetic identity — a fake person assembled from fragments of real stolen data, representing an eightfold increase year on year and making it the fastest-growing fraud type globally.

The economics explain the enthusiasm. A synthetic identity has no real victim to raise an alarm. It can be carefully cultivated over months, building a plausible credit history and transaction record before being “busted out” in a single high-value strike. The payoff potential is significantly higher than opportunistic fraud, and the detection window is narrow. In Latin America, where digital financial services are expanding rapidly, synthetic identities already account for nearly half (48.3%) of all fraud — a preview of what more mature markets may be heading toward.

Bots That Behave Like People

The third strand of the report is perhaps the most technically significant. Automated bot attacks rose 59% in EMEA last year, but the volume increase is almost secondary to the capability shift underneath it. Bots are now mimicking human behaviour, e.g. cursor movements, typing rhythms, navigation patterns, with sufficient accuracy to fool behavioural fraud detection tools that were considered state-of-the-art not long ago.

The arms race dynamic here is stark. Every new fraud detection technique creates an incentive for attackers to replicate the behaviour that technique looks for. The result is a progressive narrowing of the gap between a genuine human interaction and a synthetic one.

Adding a further layer of complexity, the report flags a 450% surge in agentic AI traffic between January and December 2025 — AI agents conducting transactions on behalf of users, primarily at gaming sites and in card payment flows. LexisNexis is careful to note there’s no evidence of malicious intent in most of this traffic. But the detection challenge it creates is real: fraud systems now need to distinguish not between humans and bots, but between humans, bots, and legitimate AI agents — three categories with increasingly overlapping behavioural signatures.

“Cybercriminals are experimenting with the same technologies that are transforming digital commerce,” noted Stephen Topliss, vice president of fraud and identity at LexisNexis Risk Solutions. “Organisations must prepare for a future where both legitimate users and malicious actors rely on automated agents to interact online.”

A Sector-by-Sector Reckoning

The sectoral data adds texture. E-commerce saw its fraud attack rate jump 64% year on year, with login-stage attacks, where fraudsters attempt account takeovers rather than transactional fraud, surging 216%. Gaming and gambling platforms fared no better, recording a 76% rise in global attack rates. EMEA’s overall attack rate climbed 27%, its sharpest increase in several years, driven largely by account takeover attempts exploiting authentication gaps.

The through-line across all of these findings is speed. Fraud operations are industrialising faster than defences can respond, with automated tools allowing criminal networks to probe for weaknesses, test new techniques, and scale successful attacks in timeframes that manual detection simply cannot match.

The 2026 LexisNexis Cybercrime Report doesn’t offer easy solutions because there aren’t any. What it does make clear is that the fraud problem is no longer separable from the AI problem, and organisations still treating them as distinct workstreams are already behind.

Pay Space

Pay Space

2286 Posts

https://payspacemagazine.com/author/payspacemagazineauthor/

Our editorial team delivers daily news and insights on the global payment industry, covering fintech innovations, worldwide payment methods, and modern payment options.