Fraud is not winning because detection tools are underfunded. It is winning because the tools most businesses rely on were built to catch a different kind of fraud than the kind they are facing right now.
Modern fraud does not break your systems. It passes through them cleanly. It shows up with a real-looking name, a plausible email, an address that exists, and behavior that looks indistinguishable from a legitimate customer. Every individual check passes. The transaction moves forward. The loss happens quietly, and by the time it surfaces it has already compounded.
The problem is not the budget. It is what the architecture is actually designed to see.
The shift that changed everything.
Sumsub’s Identity Fraud Report 2025–2026, which analyzed more than four million fraud attempts, identified what they call the Sophistication Shift. The share of multi-step attacks, coordinated fraud operations that combine several advanced techniques within a single attempt, rose from 10 percent of all identity fraud in 2024 to 28 percent in 2025. That is a 180 percent increase in one year. Seventy-five percent of fraud and risk professionals surveyed expect the trend to accelerate further.
What this looks like in practice is a fraudster who does not try to break your defenses. They study them. They test against your controls. They engineer each submission to pass every check you run, because they know your checks are evaluated one at a time. A real-looking name clears name validation. A plausible email clears email screening. An existing address clears address validation. What none of those checks catch is that the zip code does not match the city, the IP address belongs to a hosting provider, and the same customer profile appeared in a flagged submission two months ago. Each signal looks clean. The pattern beneath them does not.
Each signal looks clean. The pattern beneath them does not.
This is why three of the most damaging fraud types in e-commerce right now share the same structural weakness in how they are detected.
Account takeover.
Account takeover now represents nearly one third of all reported U.S. business fraud losses, according to TransUnion, with digital account takeover volume growing 21 percent from the first half of 2024 to the first half of 2025 alone. A fraudster accesses a customer account using stolen credentials, drains stored payment methods and loyalty value, and is gone before a flag is raised. At the moment of login, the password matches, the device is recognized, and the session looks normal. The problem only becomes visible when signals are evaluated across time rather than checked once at the door.
Synthetic identity fraud.
Synthetic identity fraud now appears in 1 in 5 detected first-party fraud cases, according to Sumsub, and synthetic identity document fraud surged over 300 percent in the U.S. in Q1 2025 alone. Generative AI has made it trivially easy to produce fake driver’s licenses, passports, and biometric data convincing enough to clear standard verification checks. These identities are not primarily used to commit fraud at the moment of purchase. They are used to build history, accumulate trust, exploit promotions, and move through checkout looking like a loyal customer. By the time the pattern becomes visible the damage is done.
Coordinated multi-signal fraud.
The most expensive pattern is also the most deliberate. A single operation combines AI-generated identity documents, deepfake submissions to defeat liveness checks, and human-like behavioral mimicry timed to avoid triggering velocity rules. Juniper Research projects global e-commerce fraud losses will reach $107 billion by 2029, up from $44.3 billion in 2024. That trajectory is not driven by a lack of tools. It is driven by tools that were never designed to see how signals interact with each other.
What a different architecture looks like.
At Thanawalla Digital, we build systems that observe your data across every behavioral, identity, and transactional signal simultaneously, determine the next best action based on how those signals converge, and execute a scored, explainable response your team can act on immediately. That is the agentic approach we apply across every client engagement, and it is the architecture we built Fortza on.
Fortza applies 13 neuroscience-backed AI and non-AI layers to evaluate every transaction in context rather than in isolation. Your team controls which layers to activate based on your highest-risk signals and assigns the weight each layer carries in the final assessment.
What comes back is not an alert that requires manual interpretation. It is a clear risk determination with a plain-language explanation of exactly which signals raised concern, why they raised it, and what the combination means for that specific transaction. Your team gets the clarity they need to act confidently, not a queue of flags waiting on someone to figure out what the system actually saw.
The Fortza platform connects directly to your existing CRM or point-of-sale environment and is operational in five minutes with no replacement of existing tools required.
Start the conversation
If you want to see what Fortza surfaces on your own transaction data, we are happy to start that conversation with you. Book a demo and receive a scored, explainable risk determination on a live transaction set.
Book a demoSources
TransUnion. H2 2025 Top Fraud Trends Report. transunion.com
Sumsub. Identity Fraud Report 2025–2026. sumsub.com
Sumsub. Synthetic Identity Document Fraud Surges 300% in the U.S., Q1 2025. sumsub.com
Juniper Research. Global Merchant Fraud Prevention Market 2024–2029. juniperresearch.com