
Most fraud conversations start and end at onboarding, right after the various checks have returned as verified. However, every account sitting in a bank or fintech's book today was verified under yesterday's controls. And in the modern era, new threats emerge by the minute.
Most troublingly, many accounts were onboarded two, three, even five years ago, when thresholds were looser, liveness models were weaker, and GenAI-assisted documents and deepfakes barely existed. These accounts were real, legitimate customers at the time. But "verified once" is not the same as "safe forever." Account takeover, not fraudulent onboarding, is quickly becoming the more dangerous side of KYC.
Incode data shows a marked increase in document and selfie fraud attempts, with most sessions involving the use of advanced AI.
Every one of those numbers describes fraud at the point of entry, but they also imply something risk teams don't talk about enough: if attackers are this much better at defeating verification today than they were two years ago, then every account that passed a weaker check two years ago is a live question mark.
An account isn't just a one-time pass/fail event. It is a standing credential that fraudsters can target long after onboarding through credential stuffing, SIM swaps, session hijacking, or increasingly, synthetic re-verification designed to survive a lighter-touch step-up check. The same forces driving up onboarding fraud (including cheap GenAI tooling, high-value single verification moments, and regulatory pressure without infrastructure parity) apply with equal force to account takeover.
Continuous trust is more relevant today than ever before, largely due to three converging trends:
That combination doesn't just make new account openings riskier. It makes previously onboarded accounts a growing liability. Why? Because the defenses that verified them were calibrated for a threat environment that no longer exists.
An institution doesn't need a high failure rate on old accounts to have a large absolute exposure; it just needs a large book of accounts that were never re-checked against current-generation defenses.
The core approach for new onboarding is multi-signal, adaptive defense: correlating biometrics, device integrity, and behavior instead of relying on any single check. That same logic should extend backward into the existing customer base:
The reality we all face is that the front door isn't the only door anymore. Every account onboarded under yesterday's controls carries exposures under today's threat model. Institutions that only look forward, strengthening new onboarding while leaving the existing accounts untouched, are defending only a small portion of risk.
Ready to see what continuous trust looks like with Incode? Request a demo today.