Mirela Ciobanu
06 Oct 2026 / 8 Min Read
Generative AI is changing fraud economics. Fake identities, forged documents, face swaps, and other attacks can be produced and scaled faster than before. At the same time, fraud teams face another challenge: a rapidly expanding market of technologies promising AI-powered detection, real-time intelligence, and protection against the latest threats.
So how can fraud leaders separate genuinely useful technology from the noise?
In a recent Leadership Insight Talk, The Paypers spoke with Hartley Thompson, CEO of Microblink, about how fraud is evolving, where current defences fall short, and what organisations should measure when evaluating fraud prevention technology.
Hartley points to three patterns that stand out today: synthetic identities that can behave like legitimate customers for months before committing fraud; employment fraud, where organised rings use fake candidates to gain access to corporate systems and sensitive data; and AI-assisted document attacks.
According to Microblink's fraud-lab observations, AI-generated ID attempts increased by around 23% last year, while face-swap document fraud rose by around 200%. Hartley also stresses that fraud looks different across markets: in Finland, for example, screen presentation attacks account for a large share of observed fraud failures, while portrait forgery is a leading document-fraud vector in the US.
The bigger change, however, is economic. The interviewee describes fraud as moving from isolated events to a continuous system that can generate identities, test them, and learn around the clock. And increasingly, he argues, the critical battleground is the point where evidence is first captured.
One of Hartley's central arguments is that many fraud-prevention stacks are looking too far downstream. When a document or biometric image reaches a server, it may already have been compressed, meaning evidence visible at the moment of capture can be lost. A server may also struggle to determine whether an image came from a genuine camera or was injected through a virtual camera or emulator.
That matters because attackers are adapting. Rather than creating entirely fake documents, they can edit genuine ones while retaining security features. Other attacks increasingly involve injection.
The implication is that downstream authentication and transaction monitoring inherit whatever errors occurred at the point of capture. ‘Monitoring only sees a payment, not a person,' Hartley argues.
For Hartley, the answer is a continuous view of the customer or actor. A suspicious transaction is often the end of a much longer chain: the actor has already been onboarded, authenticated, and trusted. Looking only at the transaction can therefore become a game of reacting to individual events rather than understanding the network behind them.
The stronger signals, he argues, are relational. The same face appearing across multiple applications, a device associated with different identities, or a document template recurring with small modifications may reveal connections that are invisible when each transaction is examined in isolation.
That also helps distinguish intent. A confused legitimate customer and a professional fraud ring might trigger similar rules, but they require very different responses. One may need assistance; the other needs to be stopped and traced.
Hartley is direct about one uncomfortable reality: fraud will get through. That means organisations should design not only for prevention, but also for rapid detection and intervention. This becomes particularly important with real-time payments and stablecoins, where settlement can be effectively final, and there may be little opportunity to recover funds afterwards.
His approach includes re-verifying an actor at higher-risk moments - such as adding a new payee, making a first large transfer, or changing a wallet or device. Organisations should also link identities, devices and documents to uncover the wider network behind a detected account.
And the feedback loop matters. Lessons from an incident should reach onboarding and prevention policies quickly, rather than remaining inside the fraud team for months.
Fraud losses alone can create a misleading picture of performance. As he points out, losses can be reduced simply by rejecting more customers. Instead, he advocates measuring the ‘total cost of trust’: fraud losses, false rejects, abandonment, review costs, and time to decision. Those measures should also be examined by relevant segments, regions and devices rather than hidden inside blended averages.
When evaluating new technology, his advice is equally practical: test it on your own traffic. Use shadow mode or a challenger approach, measure both false acceptance and false rejection rates, and look for independent testing.
And don't separate fraud performance from conversion. If fraud and growth teams operate against disconnected metrics, one objective can quietly lose to the other.
Hartley's advice to fraud leaders ultimately comes down to three principles.
Start at the edge. The most sophisticated AI model cannot compensate for evidence that was never captured reliably in the first place. Effective systems need multiple signals - document, biometric, device, and behavioural - working together throughout the customer lifecycle.
Demand evidence on your own traffic. Vendor benchmarks and demonstrations are not enough. Organisations should test technologies against their own customers, devices, channels, and real-world conditions.
Buy for explainability and adaptability. Fraud tactics change constantly, so organisations need to understand why a decision was made and how quickly a system can adapt when attackers change their methods.
As Hartley puts it, ‘AI that can't show its work’ risks becoming an expensive guess wrapped in AI.
The fraud landscape will continue to evolve, particularly as AI agents increasingly act on behalf of humans. For fraud leaders, the challenge is therefore not simply to deploy more AI, but to understand who or what is acting, what evidence supports that decision, and whether the technology is actually improving both security and the customer experience.
Watch the full conversation with Hartley Thompson and let us know what you think. What are you seeing in your own fraud environment, and which measures are proving most useful? We’d love to hear your feedback.
About author

Hartley Thompson is Chief Executive Officer of Microblink. At Microblink, Hartley is focused on the next evolution of identity: a world in which organisations must understand not only who a customer is at onboarding, but who or what is acting throughout the relationship. Before joining Microblink, he served as President of B-Line Medical, a healthcare technology company focused on improving clinical education and patient care. B-Line Medical was acquired in 2019.
About Microblink
Microblink is an Identity Intelligence platform that helps organisations verify identities, prevent fraud, and establish trust across the entire customer lifecycle. By combining document verification, biometrics, payment intelligence, and real-time risk signals, Microblink enables businesses to make faster, more accurate decisions from onboarding through authentication and ongoing account monitoring.
In 2025, Microblink processed 2.9 billion identity transactions across more than 195 countries and territories. Its proprietary Fraud Lab generates over 100,000 images monthly to train and test fraud detection models, helping organisations stay ahead of emerging threats, including deepfakes, synthetic identities, and AI-generated document fraud.
The Paypers is a global hub for market insights, real-time news, expert interviews, and in-depth analyses and resources across payments, fintech, and the digital economy. We deliver reports, webinars, and commentary on key topics, including regulation, real-time payments, cross-border payments and ecommerce, digital identity, payment innovation and infrastructure, Open Banking, Embedded Finance, crypto, fraud and financial crime prevention, and more – all developed in collaboration with industry experts and leaders.
Current themes
No part of this site can be reproduced without explicit permission of The Paypers (v2.7).
Privacy Policy / Cookie Statement
Copyright