A document declined as forged at one institution is not spent. It returns under another name, on another device, and is submitted again elsewhere, shifting exposure to repetition rather than any single submission. Matches between separate fraudulent attempts break down as reused fraudulent documents at 65.68%, shared controlled IP addresses at 17.67%, and shared devices at 16.64%. Document reuse is the strongest matching signal, because people legitimately share networks and devices. The largest connected cluster observed linked 70 identities across 13 devices, with a single device anchoring 16 verification events. Altered documents led the detection rate by attack instrument in nine of the eleven industries measured. Banking recorded a fraud rate of 4.24%, where replay and screenshot attacks remained the leading attack vectors.
Source: markets.businessinsider.com