<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Fingerprint Blog RSS Feed]]></title><description><![CDATA[The Fingerprint device intelligence platform works across web and mobile applications to identify all visitors with industry-leading accuracy — even if they’re anonymous.]]></description><link>https://fingerprint.com</link><generator>GatsbyJS</generator><lastBuildDate>Mon, 31 Aug 2026 20:13:42 GMT</lastBuildDate><item><title><![CDATA[6 bot detection tools to enhance online security]]></title><description><![CDATA[Elevate your cybersecurity with 6 essential bot detection tools. Learn how to shield your online presence from bots effectively.]]></description><link>/blog/bot-detection-tools/</link><guid isPermaLink="false">/blog/bot-detection-tools/</guid><pubDate>Fri, 28 Aug 2026 22:27:53 GMT</pubDate><enclosure url="https://fingerprint.com/static/7bf34984f8ced3c2f42592a6720a4208/blog-6-bot-detection-tools-to-enhance-online-security.png" length="0" type="image/png"/><content:encoded>&lt;p&gt;Not all bots are bad. At their core, bots are just programs designed to carry out automated tasks on behalf of humans, which can save businesses a ton of time and money.&lt;/p&gt;
&lt;p&gt;While some bots are useful, others are harmful. They may be programmed to probe security weaknesses, steal company data, overload your servers, or take over your users’ accounts.&lt;/p&gt;
&lt;p&gt;Bot detection is a vital tool in your fraud stack. It’s how teams can identify and block malicious bot-driven activity, so you can ensure your online security remains intact.&lt;/p&gt;
&lt;p&gt;Without proper &lt;a href=&quot;https://fingerprint.com/blog/bot-detection/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&quot;bad bot” detection&lt;/a&gt;, your company’s online systems are vulnerable to malicious actors. This is why detecting dangerous bots — and distinguishing between malicious bots and trusted automation — is essential for protecting your business from data breaches, downtime, financial loss, and reputational damage.&lt;/p&gt;
&lt;p&gt;Below, we’ll cover six leading bot detection tools, their key features, and pricing, so you can make an informed decision about which tool is best for you.&lt;/p&gt;
&lt;h2 id=&quot;features-to-look-for-in-a-bot-detection-tool&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#features-to-look-for-in-a-bot-detection-tool&quot; aria-label=&quot;features to look for in a bot detection tool permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Features to look for in a bot detection tool&lt;/h2&gt;
&lt;p&gt;Here’s what to be on the lookout for when choosing a bot detection tool for your business:&lt;/p&gt;
&lt;h3 id=&quot;device-fingerprinting&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#device-fingerprinting&quot; aria-label=&quot;device fingerprinting permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Device fingerprinting&lt;/h3&gt;
&lt;p&gt;&lt;a href=&quot;https://fraud.net/d/device-fingerprinting/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Device fingerprinting&lt;/a&gt; gathers data from user browsers, apps, and devices to create unique identifiers without cookies. This helps identify users across different sessions and prevents bots from mimicking legitimate users.&lt;/p&gt;
&lt;p&gt;It enhances security solutions by recognizing risk patterns that can indicate fraud, so it’s a core feature in bot detection software. By analyzing device attributes like browser type and hardware settings, device fingerprinting streamlines good bot vs. bad bot detection.&lt;/p&gt;
&lt;h3 id=&quot;real-time-fraud-detection&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#real-time-fraud-detection&quot; aria-label=&quot;real time fraud detection permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Real-time fraud detection&lt;/h3&gt;
&lt;p&gt;&lt;a href=&quot;https://fingerprint.com/blog/real-time-fraud-detection/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Real-time fraud detection&lt;/a&gt; is crucial for stopping dangerous bots before they cause harm. This feature uses algorithms to monitor and analyze traffic instantly, helping identify and block bad bots quickly.&lt;/p&gt;
&lt;p&gt;Additionally, by integrating with web application firewalls, real-time fraud detection helps provide instant protection against automated threats. It can also support the scalability of security systems by managing large volumes of data efficiently.&lt;/p&gt;
&lt;h3 id=&quot;machine-learning-and-ai&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#machine-learning-and-ai&quot; aria-label=&quot;machine learning and ai permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Machine learning and AI&lt;/h3&gt;
&lt;p&gt;Machine learning and AI technologies enable tools to learn from traffic patterns and normal user behavior. When fed high-quality data, it can help teams constantly adapt to new threats based on behavioral analysis. (Behavioral analysis involves studying user actions to spot anomalies, such as enabling AI to detect when bots are imitating humans.)&lt;/p&gt;
&lt;p&gt;ML and AI use behavior analysis and dynamic learning to continuously improve over time and can when bots are imitating humans. For example, bots might have unusually fast click patterns or consistent interaction intervals. While this may go unnoticed with manual detection, ML algorithms that have been refined using system or user feedback can quickly flag this as anomalous behavior.&lt;/p&gt;
&lt;p&gt;Because ML models evolve based on the data they’re trained on over time, these algorithms become more flexible and advanced at recognizing unusual patterns — even as bot tactics evolve.&lt;/p&gt;
&lt;h3 id=&quot;mobile-app-protection&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#mobile-app-protection&quot; aria-label=&quot;mobile app protection permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Mobile app protection&lt;/h3&gt;
&lt;p&gt;Due to the increasing use of mobile devices (among legitimate users and fraudsters), make sure your chosen tool supports comprehensive protection across web and mobile platforms. Bot detection tools for mobile apps need to account for unique, &lt;a href=&quot;https://startupnation.com/manage-your-business/protect-your-business/5-types-of-app-code-security-vulnerabilities-you-need-to-know/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;app-specific vulnerabilities&lt;/a&gt; like broken authentication or injection flaws.&lt;/p&gt;
&lt;p&gt;Mobile app protection features typically include analyzing mobile traffic patterns, detecting whether a device is rooted or jailbroken, and integrating with mobile security protocols. This ensures effective identification and mitigation of bots targeting mobile apps, safeguarding user data and app functionality.&lt;/p&gt;
&lt;h2 id=&quot;the-top-6-bot-detection-tools&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#the-top-6-bot-detection-tools&quot; aria-label=&quot;the top 6 bot detection tools permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;The top 6 bot detection tools&lt;/h2&gt;
&lt;p&gt;To help you zero in on the ideal bot detection tool for your organization, let’s break down six of the top tools known for their reliability, advanced features, and user-friendly interfaces.&lt;/p&gt;
&lt;h3 id=&quot;fingerprint&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#fingerprint&quot; aria-label=&quot;fingerprint permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Fingerprint&lt;/h3&gt;
&lt;p&gt;Fingerprint offers &lt;a href=&quot;https://fingerprint.com/products/smart-signals/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;browser and device intelligence&lt;/a&gt; for web and mobile applications. With Fingerprint, each app or web visitor gets a permanent identifier, so they’re identifiable across different browsers, operating systems, locations, and devices with industry-leading accuracy — even if they’re browsing anonymously. Fingerprint also provides &lt;a href=&quot;https://fingerprint.com/blog/vpn-detection-how-it-works/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;VPN detection&lt;/a&gt; and identifies rooted and jailbroken devices, application tampering, and cloned apps.&lt;/p&gt;
&lt;h4 id=&quot;key-features&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#key-features&quot; aria-label=&quot;key features permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Key features&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Device and browser fingerprinting: Fingerprint creates a unique visitor ID for all visitors, identifying them with industry-leading accuracy, ensuring reliable user recognition and robust security.&lt;/li&gt;
&lt;li&gt;Bot detection and fraud prevention: Fingerprint excels in detecting bots and fraudulent activities. By analyzing device and browser fingerprints, it distinguishes between fraudulent and legitimate users, safeguarding your systems.&lt;/li&gt;
&lt;li&gt;AI agent and assistant detection: Unlike its bot detection capabilities, Fingerprint also can detect and verify agentic traffic through a cryptographically-signed ecosystem as well as HTTP-level traffic from AI assistants.&lt;/li&gt;
&lt;li&gt;Seamless integration: The platform seamlessly integrates into your existing fraud prevention stack, making implementation straightforward. Whether your team is in engineering, product, fraud/risk, security, or beyond, Fingerprint adapts to your needs.&lt;/li&gt;
&lt;li&gt;Comprehensive visitor insights: Gain valuable insights into user behavior with detailed information about devices, browsers, and geolocation, and more, empowering data-driven decisions.&lt;/li&gt;
&lt;li&gt;Customizable policies: Tailor detection rules and policies to suit your specific use case. Whether you’re combating &lt;a href=&quot;https://fingerprint.com/blog/account-takeover-examples/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;account takeover attempts&lt;/a&gt; or &lt;a href=&quot;https://fingerprint.com/blog/what-is-a-bot-attack/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;preventing bot attacks&lt;/a&gt;, Fingerprint lets you fine-tune your settings for optimal protection.&lt;/li&gt;
&lt;li&gt;Real-time alerts: Fingerprint keeps you informed with real-time alerts when suspicious activity occurs, enabling you to quickly respond to potential threats.&lt;/li&gt;
&lt;li&gt;CAPTCHA-free mitigation: Enhances user experience and reduces frustration and friction.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&quot;pricing&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#pricing&quot; aria-label=&quot;pricing permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Pricing&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Pro Plus: $99/month for up to 20K API calls&lt;/li&gt;
&lt;li&gt;Enterprise: Custom quotes on request&lt;/li&gt;
&lt;/ul&gt;
&lt;link rel=&quot;stylesheet&quot; href=&quot;/plugins/customizable-cta/customizable-cta.css&quot;&gt;

          &lt;div class=&quot;ctaRoot brightTheme  withCodeExample&quot;&gt;
            &lt;div class=&quot;ctaContainer&quot;&gt;
              &lt;div&gt;
                &lt;h2&gt;Ready for better bot detection?&lt;/h2&gt;
&lt;p&gt;Install our &lt;strong&gt;JS agent&lt;/strong&gt; on your website to accurately identify visitors and stop harmful bot traffic before it impacts your business&lt;/p&gt;

              &lt;/div&gt;
              &lt;div class=&quot;buttonsContainer&quot;&gt;
                &lt;a href=&quot;https://dashboard.fingerprint.com/signup&quot; id=&quot;custom-cta-signup&quot; class=&quot;buttonSignUp&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Start Free Trial&lt;/a&gt;
                
                
              &lt;/div&gt;
            &lt;/div&gt;
            &lt;div class=&quot;demoContainer&quot;&gt;&lt;div class=&quot;codeExample&quot;&gt;&lt;/div&gt;&lt;/div&gt;
          &lt;/div&gt;
&lt;h3 id=&quot;datadome&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#datadome&quot; aria-label=&quot;datadome permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;DataDome&lt;/h3&gt;
&lt;p&gt;DataDome was founded in 2015 and its mission is to proactively defend businesses against bot-driven fraud and protect their online assets.&lt;/p&gt;
&lt;h4 id=&quot;key-features-1&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#key-features-1&quot; aria-label=&quot;key features 1 permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Key features&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Online fraud and bot detection: DataDome uses machine learning to analyze every incoming request. It blocks bad bots, account takeover attempts, credential stuffing, skewed analytics, and more.&lt;/li&gt;
&lt;li&gt;Real-time analysis: DataDome adapts to usage patterns and ensures high protection.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&quot;pricing-1&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#pricing-1&quot; aria-label=&quot;pricing 1 permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Pricing&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Business: $3,690 per month&lt;/li&gt;
&lt;li&gt;Corporate: $6,490 per month&lt;/li&gt;
&lt;li&gt;Enterprise: $8,590 per month&lt;/li&gt;
&lt;li&gt;Enterprise Plus: Custom quotes on request&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;cloudflare&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#cloudflare&quot; aria-label=&quot;cloudflare permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Cloudflare&lt;/h3&gt;
&lt;p&gt;Cloudflare Bot Management is a cloud-based solution designed to identify and mitigate malicious bot activity on websites and applications. It leverages data from millions of Internet properties to manage both good bots and bad bots in real time.&lt;/p&gt;
&lt;p&gt;By analyzing behavior and detecting anomalies in network traffic, Cloudflare Bot Management automatically blocks bad bots without disrupting legitimate user experiences.&lt;/p&gt;
&lt;h4 id=&quot;key-features-2&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#key-features-2&quot; aria-label=&quot;key features 2 permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Key features&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Bot attack prevention: Cloudflare blocks various malicious bot activities, including credential stuffing, content scraping, inventory hoarding, and DDoS attacks.&lt;/li&gt;
&lt;li&gt;Multiple detection methods: The system employs machine learning, behavioral analysis, and device fingerprinting to accurately classify bots.&lt;/li&gt;
&lt;li&gt;CAPTCHA support: Cloudflare identifies bots using &lt;a href=&quot;https://fingerprint.com/blog/captcha-alternatives/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;CAPTCHA alternatives&lt;/a&gt;, minimizing legitimate user frustration.&lt;/li&gt;
&lt;li&gt;Simple deployment: No complex configuration or maintenance required. Cloudflare Bot Management recommends rules right out of the box.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&quot;pricing-2&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#pricing-2&quot; aria-label=&quot;pricing 2 permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Pricing&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Free: $0/month&lt;/li&gt;
&lt;li&gt;Pro: $20/month&lt;/li&gt;
&lt;li&gt;Business: $200/month&lt;/li&gt;
&lt;li&gt;Enterprise: Custom quotes on request&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;arkose-labs&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#arkose-labs&quot; aria-label=&quot;arkose labs permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Arkose Labs&lt;/h3&gt;
&lt;p&gt;Arkose Labs aims to undermine fraud by empowering digital businesses to waste attackers’ time and resources. Arkose Labs offers a &lt;a href=&quot;https://fingerprint.com/blog/bot-management-solutions/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;bot management solution&lt;/a&gt; that detects and prevents malicious bot activities while allowing authorized bots (e.g., search engine crawlers) to access websites and applications.&lt;/p&gt;
&lt;h4 id=&quot;key-features-3&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#key-features-3&quot; aria-label=&quot;key features 3 permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Key features&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Proactive defense: Detect and mitigate attacks before they make an impact.&lt;/li&gt;
&lt;li&gt;Adaptive response: Dynamic interception traps bad bots without sacrificing customer experience.&lt;/li&gt;
&lt;li&gt;Actionable data: A multitude of signals drives precise, transparent decision-making.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&quot;pricing-3&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#pricing-3&quot; aria-label=&quot;pricing 3 permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Pricing&lt;/h4&gt;
&lt;p&gt;Interested businesses have to book a demo for pricing information.&lt;/p&gt;
&lt;h3 id=&quot;radware-bot-manager&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#radware-bot-manager&quot; aria-label=&quot;radware bot manager permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Radware Bot Manager&lt;/h3&gt;
&lt;p&gt;Radware Bot Manager provides specialized enterprise-grade defense against bots by using a three-layer approach:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Preemptive protection: Blocks unwanted IPs and identities before they cause damage.&lt;/li&gt;
&lt;li&gt;Behavioral-based detection: Uses AI to catch threats.&lt;/li&gt;
&lt;li&gt;Advanced mitigation: Offers a range of granular mitigation options.&lt;/li&gt;
&lt;/ol&gt;
&lt;h4 id=&quot;key-features-4&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#key-features-4&quot; aria-label=&quot;key features 4 permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Key features&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Intent-based behavioral analysis: Learns and evolves from feedback received.&lt;/li&gt;
&lt;li&gt;Device and browser fingerprinting: Identifies anomalies to distinguish between fraudsters and real users.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&quot;pricing-4&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#pricing-4&quot; aria-label=&quot;pricing 4 permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Pricing&lt;/h4&gt;
&lt;p&gt;Radware offers a 30-day free trial. For pricing information, you’ll need to contact their sales team.&lt;/p&gt;
&lt;h3 id=&quot;reblaze&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#reblaze&quot; aria-label=&quot;reblaze permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Reblaze&lt;/h3&gt;
&lt;p&gt;Reblaze uses machine learning to construct and maintain behavioral profiles of legitimate human visitors.&lt;/p&gt;
&lt;h4 id=&quot;key-features-5&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#key-features-5&quot; aria-label=&quot;key features 5 permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Key features&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Real-time traffic visibility: The Reblaze dashboard gives you a detailed overview of your traffic.&lt;/li&gt;
&lt;li&gt;API for programmatic operation: You can operate Reblaze completely programmatically.&lt;/li&gt;
&lt;li&gt;DNS and SSL management: The platform is maintained remotely by Reblaze experts so your security is always up-to-date and effective.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&quot;pricing-5&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#pricing-5&quot; aria-label=&quot;pricing 5 permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Pricing&lt;/h4&gt;
&lt;p&gt;Pricing isn’t immediately available on their site. Interested parties will need to contact their team directly for a price quote.&lt;/p&gt;
&lt;h2 id=&quot;accelerate-your-bot-management-efforts-with-fingerprint&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#accelerate-your-bot-management-efforts-with-fingerprint&quot; aria-label=&quot;accelerate your bot management efforts with fingerprint permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Accelerate your bot management efforts with Fingerprint&lt;/h2&gt;
&lt;p&gt;Fingerprint offers a comprehensive &lt;a href=&quot;https://fingerprint.com/products/bot-detection/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;bot detection solution&lt;/a&gt; that identifies all online visitors with industry-leading accuracy. Our browser Bot Detection Smart Signal detects automation tools, search bots, and other sophisticated threats in real time, and makes it simple to distinguish between legitimate users and bots.&lt;/p&gt;

          &lt;div class=&quot;ctaRoot brightTheme  withCodeExample&quot;&gt;
            &lt;div class=&quot;ctaContainer&quot;&gt;
              &lt;div&gt;
                &lt;h2&gt;Ready for better bot detection?&lt;/h2&gt;
&lt;p&gt;Install our &lt;strong&gt;JS agent&lt;/strong&gt; on your website to accurately identify visitors and stop harmful bot traffic before it impacts your business&lt;/p&gt;

              &lt;/div&gt;
              &lt;div class=&quot;buttonsContainer&quot;&gt;
                &lt;a href=&quot;https://dashboard.fingerprint.com/signup&quot; id=&quot;custom-cta-signup&quot; class=&quot;buttonSignUp&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Start Free Trial&lt;/a&gt;
                
                
              &lt;/div&gt;
            &lt;/div&gt;
            &lt;div class=&quot;demoContainer&quot;&gt;&lt;div class=&quot;codeExample&quot;&gt;&lt;/div&gt;&lt;/div&gt;
          &lt;/div&gt;</content:encoded><tags>bot attacks, use cases</tags></item><item><title><![CDATA[Automation Intelligence API for UCP: How to detect automated ecommerce checkout bots]]></title><description><![CDATA[Stop bots at checkout when there's no browser to fingerprint: Using the Automation Intelligence API with Google UCP.]]></description><link>/blog/how-to-detect-checkout-bots/</link><guid isPermaLink="false">/blog/how-to-detect-checkout-bots/</guid><pubDate>Tue, 25 Aug 2026 14:10:00 GMT</pubDate><enclosure url="https://fingerprint.com/static/c16d7f7cd6128166e541e9bec1a58436/technical-post-detecting-bots-at-checkout-when-there-s-no-browser-to-fingerprint_-automation-intelligence-api-ucp..png" length="0" type="image/png"/><content:encoded>&lt;p&gt;Agentic commerce changes what a &quot;checkout request&quot; looks like.&lt;/p&gt;
&lt;p&gt;In the &lt;a href=&quot;https://github.com/Universal-Commerce-Protocol&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Universal Commerce Protocol&lt;/a&gt; (UCP), the thing hitting your &lt;code&gt;complete_checkout&lt;/code&gt; endpoint is often not a browser at all. It’s a platform&apos;s backend or an AI agent calling your API directly via REST or MCP. There’s no page load, no JavaScript execution, nothing for a browser-based bot detection script to run in.&lt;/p&gt;
&lt;p&gt;This is the gap we built our &lt;a href=&quot;https://docs.fingerprint.com/reference/automation-intelligence-api&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Automation Intelligence API&lt;/a&gt; to fill: It detects automation from HTTP request metadata alone — headers, method, URL, IP — with no JavaScript agent required.&lt;/p&gt;
&lt;p&gt;In this post, we’ll walk through how to wire it into a UCP merchant integration, and — because UCP happens to give you two separate places to look — how to run it on both the &lt;strong&gt;caller&lt;/strong&gt; of your checkout API and, when the platform provides it, the &lt;strong&gt;buyer&lt;/strong&gt; behind the transaction.&lt;/p&gt;
&lt;h2 id=&quot;what-a-ucp-checkout-request-actually-looks-like&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#what-a-ucp-checkout-request-actually-looks-like&quot; aria-label=&quot;what a ucp checkout request actually looks like permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;What a UCP checkout request actually looks like&lt;/h2&gt;
&lt;p&gt;UCP&apos;s spec and reference implementations live in the &lt;a href=&quot;https://github.com/Universal-Commerce-Protocol&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Universal-Commerce-Protocol GitHub org&lt;/a&gt;: The protocol itself in &lt;code&gt;ucp&lt;/code&gt;, and runnable reference merchant servers (Python/FastAPI and Node.js/Hono) in &lt;code&gt;samples&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&quot;https://ucp.dev/specification/checkout/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Checkout capability&lt;/a&gt; is what you&apos;ll integrate against.&lt;/p&gt;
&lt;p&gt;Its REST binding defines five operations, all under &lt;code&gt;/checkout-sessions&lt;/code&gt;:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Operation&lt;/th&gt;
&lt;th&gt;Method&lt;/th&gt;
&lt;th&gt;Endpoint&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Create Checkout&lt;/td&gt;
&lt;td&gt;&lt;code&gt;POST&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;/checkout-sessions&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Get Checkout&lt;/td&gt;
&lt;td&gt;&lt;code&gt;GET&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;/checkout-sessions/{id}&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Update Checkout&lt;/td&gt;
&lt;td&gt;&lt;code&gt;PUT&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;/checkout-sessions/{id}&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Complete Checkout&lt;/td&gt;
&lt;td&gt;&lt;code&gt;POST&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;/checkout-sessions/{id}/complete&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cancel Checkout&lt;/td&gt;
&lt;td&gt;&lt;code&gt;POST&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;/checkout-sessions/{id}/cancel&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;em&gt;(Source: &lt;a href=&quot;https://ucp.dev/specification/checkout-rest/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Checkout — REST Binding&lt;/a&gt;)&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Every request, regardless of operation, must carry a &lt;code&gt;UCP-Agent&lt;/code&gt; header identifying the calling platform&apos;s profile, plus required &lt;code&gt;Idempotency-Key&lt;/code&gt; and &lt;code&gt;Request-Id&lt;/code&gt; headers.&lt;/p&gt;
&lt;p&gt;Platforms may additionally authenticate using RFC 9421 HTTP Message Signatures via &lt;code&gt;Signature&lt;/code&gt;/&lt;code&gt;Signature-Input&lt;/code&gt; headers.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;MCP is a separate binding.&lt;/strong&gt; The same five operations exist, but they arrive as &lt;code&gt;tools/call&lt;/code&gt; requests to a single MCP endpoint, with the operation name in &lt;code&gt;params.name&lt;/code&gt; and the payload in &lt;code&gt;params.arguments&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;The checkout session ID moves out of the URL path and into the arguments, &lt;code&gt;Request-Id&lt;/code&gt; isn&apos;t part of the binding, and the platform profile travels in &lt;code&gt;meta[&quot;ucp-agent&quot;]&lt;/code&gt; inside the body.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The detection call is the same either way.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The Automation Intelligence API works from headers, method, URL, and IP, none of which change shape between a REST payload and a JSON-RPC envelope. In our documentation, the &lt;a href=&quot;https://docs.fingerprint.com/docs/bot-detection/overview&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Bot Detection overview&lt;/a&gt; lists &quot;AI agents or assistants calling your API directly, MCP servers, or any backend-to-backend traffic&quot; as the traffic the Automation Intelligence API targets, because none of it requires a browser.&lt;/p&gt;
&lt;h2 id=&quot;two-different-things-to-point-automation-intelligence-at&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#two-different-things-to-point-automation-intelligence-at&quot; aria-label=&quot;two different things to point automation intelligence at permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Two different things to point Automation Intelligence at&lt;/h2&gt;
&lt;p&gt;UCP integration gives you signal about two distinct actors, and they deserve two distinct checks.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;The caller&lt;/th&gt;
&lt;th&gt;The buyer&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;What it is&lt;/td&gt;
&lt;td&gt;Whatever opened the HTTP connection to your &lt;code&gt;checkout-sessions&lt;/code&gt; (or &lt;code&gt;/mcp&lt;/code&gt;) endpoint&lt;/td&gt;
&lt;td&gt;The human the platform says is completing the purchase&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Where it comes from&lt;/td&gt;
&lt;td&gt;The raw HTTP request itself — headers, method, URL, client IP&lt;/td&gt;
&lt;td&gt;&lt;code&gt;signals[&quot;dev.ucp.buyer_ip&quot;]&lt;/code&gt; / &lt;code&gt;signals[&quot;dev.ucp.user_agent&quot;]&lt;/code&gt; in the UCP request body, when the platform includes them&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Availability&lt;/td&gt;
&lt;td&gt;Always present&lt;/td&gt;
&lt;td&gt;Optional&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;The &lt;code&gt;signals&lt;/code&gt; object is documented in the &lt;a href=&quot;https://ucp.dev/specification/overview/#signals&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;protocol specification&apos;s Signals section&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;One check tells you about the thing that&apos;s actually talking to your server. The other tells you what the platform says it observed about the buyer&apos;s connection, on a surface you never talked to. Both are useful, but not interchangeable.&lt;/p&gt;
&lt;h2 id=&quot;detecting-the-caller-rest-or-mcp&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#detecting-the-caller-rest-or-mcp&quot; aria-label=&quot;detecting the caller rest or mcp permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Detecting the caller (REST or MCP)&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://docs.fingerprint.com/reference/automation-intelligence-api&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Automation Intelligence API&lt;/a&gt; has a single endpoint, &lt;code&gt;POST /edge&lt;/code&gt; (also called the &lt;a href=&quot;https://docs.fingerprint.com/reference/server-api-edge&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Collect Intelligence endpoint&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Its request body (&lt;code&gt;EdgeRequest&lt;/code&gt;) requires:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;headers&lt;/code&gt; — an ordered array of &lt;code&gt;{name, value}&lt;/code&gt; pairs&lt;/li&gt;
&lt;li&gt;&lt;code&gt;method&lt;/code&gt; — the HTTP method&lt;/li&gt;
&lt;li&gt;&lt;code&gt;url&lt;/code&gt; — the absolute URL that was requested&lt;/li&gt;
&lt;li&gt;at least one of &lt;code&gt;ipv4_address&lt;/code&gt; / &lt;code&gt;ipv6_address&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;rest-example&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#rest-example&quot; aria-label=&quot;rest example permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;REST example&lt;/h3&gt;
&lt;p&gt;Say a platform sends this to your &lt;code&gt;complete_checkout&lt;/code&gt; endpoint:&lt;/p&gt;
&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;jsx&quot;&gt;&lt;pre class=&quot;language-jsx&quot;&gt;&lt;code class=&quot;language-jsx&quot;&gt;&lt;span class=&quot;token constant&quot;&gt;POST&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;checkout&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sessions&lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;chk_9f2a&lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;complete &lt;span class=&quot;token constant&quot;&gt;HTTP&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;1.1&lt;/span&gt;
&lt;span class=&quot;token literal-property property&quot;&gt;Host&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; merchant&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;example&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;com
&lt;span class=&quot;token constant&quot;&gt;UCP&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Agent&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; profile&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&quot;https://platform.example/.well-known/ucp&quot;&lt;/span&gt;
User&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Agent&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; platform&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;client&lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;1.0&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;.0&lt;/span&gt;
Idempotency&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Key&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;550e8400&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;e29b&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;41d4&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;a716&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;446655440000&lt;/span&gt;
Request&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Id&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; req_abc123
&lt;span class=&quot;token literal-property property&quot;&gt;Authorization&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; Bearer sk&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;live&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;abc123
Content&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Type&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; application&lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;json

&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;payment&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;instruments&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;handler_id&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;gpay_1234&quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;h3 id=&quot;mcp-example&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#mcp-example&quot; aria-label=&quot;mcp example permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;MCP example&lt;/h3&gt;
&lt;p&gt;Over MCP, the same operation arrives as a &lt;code&gt;tools/call&lt;/code&gt; to your MCP endpoint instead:&lt;/p&gt;
&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;jsx&quot;&gt;&lt;pre class=&quot;language-jsx&quot;&gt;&lt;code class=&quot;language-jsx&quot;&gt;&lt;span class=&quot;token constant&quot;&gt;POST&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;mcp &lt;span class=&quot;token constant&quot;&gt;HTTP&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;1.1&lt;/span&gt;
&lt;span class=&quot;token literal-property property&quot;&gt;Host&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; merchant&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;example&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;com
Content&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Type&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; application&lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;json
&lt;span class=&quot;token constant&quot;&gt;UCP&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Agent&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; profile&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&quot;https://platform.example/.well-known/ucp&quot;&lt;/span&gt;
Idempotency&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Key&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;550e8400&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;e29b&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;41d4&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;a716&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;446655440000&lt;/span&gt;
Content&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Digest&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; sha&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;256&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token constant&quot;&gt;RK&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;0qy18MlBSVnWgjwz6lZEWjP&lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;lF5HF9bvEF8FabDg&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt;
Signature&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Input&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; sig1&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&quot;@method&quot;&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;@authority&quot;&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;@path&quot;&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;content-digest&quot;&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;content-type&quot;&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;ucp-agent&quot;&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;idempotency-key&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;keyid&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&quot;platform-2026&quot;&lt;/span&gt;
&lt;span class=&quot;token literal-property property&quot;&gt;Signature&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; sig1&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt;MEUCIQDXyK9N3p5Rt&lt;span class=&quot;token operator&quot;&gt;...&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt;

&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;jsonrpc&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;2.0&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;id&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;method&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;tools/call&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;params&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;token string-property property&quot;&gt;&quot;name&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;complete_checkout&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token string-property property&quot;&gt;&quot;arguments&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
      &lt;span class=&quot;token string-property property&quot;&gt;&quot;meta&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
        &lt;span class=&quot;token string-property property&quot;&gt;&quot;ucp-agent&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;profile&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;https://platform.example/.well-known/ucp&quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
        &lt;span class=&quot;token string-property property&quot;&gt;&quot;idempotency-key&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;550e8400-e29b-41d4-a716-446655440000&quot;&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
      &lt;span class=&quot;token string-property property&quot;&gt;&quot;id&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;chk_9f2a&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
      &lt;span class=&quot;token string-property property&quot;&gt;&quot;checkout&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
        &lt;span class=&quot;token string-property property&quot;&gt;&quot;payment&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;instruments&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;handler_id&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;gpay_1234&quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Either way you forward that request — minus the secret values — to &lt;code&gt;/edge&lt;/code&gt;:&lt;/p&gt;
&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;jsx&quot;&gt;&lt;pre class=&quot;language-jsx&quot;&gt;&lt;code class=&quot;language-jsx&quot;&gt;&lt;span class=&quot;token constant&quot;&gt;POST&lt;/span&gt; &lt;span class=&quot;token literal-property property&quot;&gt;https&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;api&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;fpjs&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;io&lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;v4&lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;edge
&lt;span class=&quot;token literal-property property&quot;&gt;Authorization&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; Bearer &lt;span class=&quot;token constant&quot;&gt;FPJS_SECRET_API_KEY&lt;/span&gt;

&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;headers&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;name&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;Host&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;value&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;merchant.example.com&quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;name&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;UCP-Agent&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;value&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;profile=\&quot;https://platform.example/.well-known/ucp\&quot;&quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;name&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;User-Agent&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;value&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;platform-client/1.0.0&quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;name&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;Idempotency-Key&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;value&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;550e8400-e29b-41d4-a716-446655440000&quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;name&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;Request-Id&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;value&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;req_abc123&quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;name&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;Authorization&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;value&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;&quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;name&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;Content-Type&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;value&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;application/json&quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;method&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;POST&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;url&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;https://merchant.example.com/checkout-sessions/chk_9f2a/complete&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;ipv4_address&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;34.162.244.71&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token comment&quot;&gt;// custom correlation value&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;linked_id&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;chk_9f2a&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token comment&quot;&gt;// arbitrary metadata&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;tags&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;source&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;ucp_transport&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;user_agent&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;platform-client/1.0.0&quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;&lt;code&gt;ipv4_address&lt;/code&gt; here is the actual peer connecting to your server, not anything from the UCP payload.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;linked_id&lt;/code&gt; set to the checkout session ID lets you pull every Automation Intelligence event for a given checkout later via &lt;code&gt;GET /v4/events?source=edge&lt;/code&gt; or a single event via &lt;code&gt;GET /v4/events/{event_id}&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;The endpoint shown is the global region. Use &lt;strong&gt;eu.api.fpjs.io&lt;/strong&gt; or &lt;strong&gt;ap.api.fpjs.io&lt;/strong&gt; if your workspace is in the EU or Asia.&lt;/p&gt;
&lt;h3 id=&quot;web-bot-auth-is-also-supported&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#web-bot-auth-is-also-supported&quot; aria-label=&quot;web bot auth is also supported permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Web Bot Auth is also supported&lt;/h3&gt;
&lt;p&gt;If the calling agent signs its requests per Web Bot Auth, the request carries &lt;code&gt;Signature-Agent&lt;/code&gt;, &lt;code&gt;Signature-Input&lt;/code&gt; (with &lt;code&gt;tag=&quot;web-bot-auth&quot;&lt;/code&gt;), and &lt;code&gt;Signature&lt;/code&gt; headers, separate from — and possibly alongside — any UCP-level RFC 9421 signature.&lt;/p&gt;
&lt;p&gt;Forward those three headers through in your &lt;code&gt;headers[]&lt;/code&gt; array exactly like any other header (the values intact, unlike &lt;code&gt;Authorization&lt;/code&gt;), and Fingerprint verifies the signature server-side against the published key directory, returning a response where &lt;code&gt;bot_info.identity&lt;/code&gt; is &lt;code&gt;&quot;signed&quot;&lt;/code&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;Visit our &lt;a href=&quot;https://fingerprint.com/web-bot-auth/test/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Web Bot Auth testing page&lt;/a&gt; for a free, public endpoint where you can send a signed request and get clear feedback on whether your signature validates correctly.&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;reading-the-response&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#reading-the-response&quot; aria-label=&quot;reading the response permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Reading the response&lt;/h3&gt;
&lt;p&gt;&lt;code&gt;bot_info&lt;/code&gt; is only present in the response when a bot is detected — no &lt;code&gt;bot_info&lt;/code&gt; means no automation signal, not a confirmed human. When present, per &lt;a href=&quot;https://docs.fingerprint.com/docs/ai-agents&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;AI agent detection&lt;/a&gt;, &lt;code&gt;bot_info.identity&lt;/code&gt; is the field to act on:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;code&gt;verified&lt;/code&gt;&lt;/strong&gt; — identity confirmed by Fingerprint.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;code&gt;signed&lt;/code&gt;&lt;/strong&gt; — the WBA signature checked out against the agent&apos;s published key directory.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;code&gt;unknown&lt;/code&gt;&lt;/strong&gt; — recognized as automation, but it didn&apos;t present a verifiable identity.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;code&gt;spoofed&lt;/code&gt;&lt;/strong&gt; — it claimed an identity that couldn’t be verified.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;detecting-the-buyer-when-ucp-has-the-signals&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#detecting-the-buyer-when-ucp-has-the-signals&quot; aria-label=&quot;detecting the buyer when ucp has the signals permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Detecting the buyer, when UCP has the signals&lt;/h2&gt;
&lt;p&gt;Now the second, complementary check. When a platform includes &lt;code&gt;signals&lt;/code&gt; on a &lt;code&gt;complete_checkout&lt;/code&gt; request:&lt;/p&gt;
&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;jsx&quot;&gt;&lt;pre class=&quot;language-jsx&quot;&gt;&lt;code class=&quot;language-jsx&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;payment&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;instruments&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt; &lt;span class=&quot;token comment&quot;&gt;/* ... */&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;signals&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;token string-property property&quot;&gt;&quot;dev.ucp.buyer_ip&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;203.0.113.42&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token string-property property&quot;&gt;&quot;dev.ucp.user_agent&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;Mozilla/5.0 (Windows NT 10.0; Win64; x64) ...&quot;&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;That&apos;s a second, independent thing worth running through the Automation Intelligence API. This is the human the transaction is for, and their IP and browser are worth the same bot or IP intelligence (proxy, VPN, datacenter, geolocation) checks you&apos;d apply to a caller you connected to directly. Signals aren&apos;t limited to completion, so you can run this earlier in the flow as well.&lt;/p&gt;
&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;jsx&quot;&gt;&lt;pre class=&quot;language-jsx&quot;&gt;&lt;code class=&quot;language-jsx&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;headers&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;name&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;User-Agent&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;value&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;Mozilla/5.0 (Windows NT 10.0; Win64; x64) ...&quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;method&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;POST&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;url&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;https://merchant.example.com/checkout-sessions/chk_9f2a/complete&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;ipv4_address&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;203.0.113.42&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;linked_id&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;chk_9f2a&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token string-property property&quot;&gt;&quot;tags&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;source&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;ucp_signal&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;user_agent&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;Mozilla/5.0 (Windows NT 10.0; Win64; x64) ...&quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;A single &lt;code&gt;User-Agent&lt;/code&gt; string, with no accompanying header set, is a weaker input than a real captured request — you&apos;re mainly getting IP intelligence on the buyer&apos;s IP, plus whatever automation signal Fingerprint can infer from the UA string. That&apos;s still useful — a &lt;code&gt;buyer_ip&lt;/code&gt; that resolves to a datacenter or a known VPN exit node is worth knowing about.&lt;/p&gt;
&lt;h2 id=&quot;putting-both-checks-together&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#putting-both-checks-together&quot; aria-label=&quot;putting both checks together permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Putting both checks together&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Caller &lt;code&gt;identity&lt;/code&gt; is &lt;code&gt;signed&lt;/code&gt;/&lt;code&gt;verified&lt;/code&gt;, no buyer signal present.&lt;/strong&gt; Nothing further to review from this pair.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Caller &lt;code&gt;identity&lt;/code&gt; is &lt;code&gt;spoofed&lt;/code&gt;&lt;/strong&gt; . Worth reviewing regardless of what the buyer signal says; a caller failing its own claimed identity check is a stronger signal than anything derived from a buyer IP you didn&apos;t observe yourself.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Caller looks clean, buyer IP resolves to a datacenter or known proxy/VPN.&lt;/strong&gt; Doesn&apos;t necessarily mean fraud (plenty of legitimate users route through VPNs), but it&apos;s a reasonable input into a broader risk model alongside order value, shipping/billing mismatch, and history.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No buyer signal at all.&lt;/strong&gt; UCP doesn&apos;t require platforms to send it, and many won&apos;t in agent-initiated purchases.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Store both events (or at least both &lt;code&gt;event_id&lt;/code&gt;s) against the checkout, and let your fraud/risk logic decide what to do with the combination.&lt;/p&gt;
&lt;h2 id=&quot;where-this-stands-today&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#where-this-stands-today&quot; aria-label=&quot;where this stands today permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Where this stands today&lt;/h2&gt;
&lt;p&gt;Two things worth flagging before you build on this.&lt;/p&gt;
&lt;p&gt;The first is that &lt;a href=&quot;https://docs.fingerprint.com/reference/automation-intelligence-api&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Automation Intelligence API&lt;/a&gt; is currently in Public Preview, so the response schema is subject to change.&lt;/p&gt;
&lt;p&gt;The second is that UCP is an actively developed spec, too. The &lt;code&gt;ucp&lt;/code&gt; &lt;a href=&quot;https://github.com/Universal-Commerce-Protocol/ucp&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;repository&lt;/a&gt; has an open issue tracker and regular pull requests, and the protocol uses &lt;a href=&quot;https://ucp.dev/specification/overview/#versioning&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;dated versioning&lt;/a&gt; (this post reflects the &lt;code&gt;2026-04-08&lt;/code&gt; release) specifically because backward-incompatible changes are expected to keep shipping as the spec matures.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;further-reading&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#further-reading&quot; aria-label=&quot;further reading permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Further reading&lt;/h2&gt;
&lt;p&gt;GitHub:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/Universal-Commerce-Protocol&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Universal Commerce Protocol&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/Universal-Commerce-Protocol/ucp&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;UCP specification &amp;#x26; docs source&lt;/a&gt; (&lt;code&gt;ucp&lt;/code&gt; repo)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/Universal-Commerce-Protocol/samples&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;UCP sample merchant servers&lt;/a&gt; (&lt;code&gt;samples&lt;/code&gt; repo)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;UCP.dev:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://ucp.dev/specification/overview/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;UCP Protocol Overview&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://ucp.dev/specification/checkout-rest/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;UCP Checkout — REST Binding&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://ucp.dev/specification/checkout-mcp/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;UCP Checkout — MCP Binding&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Fingerprint docs:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.fingerprint.com/docs/bot-detection/overview&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Bot detection overview&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.fingerprint.com/reference/automation-intelligence-api&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Automation Intelligence API &lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.fingerprint.com/reference/server-api-edge&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Collect Intelligence endpoint&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.fingerprint.com/docs/ai-agents&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;AI agent detection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.fingerprint.com/docs/bot-detection/web-bot-auth-implementation&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Web Bot Auth implementation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><tags>ai agents, bot attacks, integrations, implementation guides, ecommerce fraud, automation intelligence</tags></item><item><title><![CDATA[New Smart Signal: Active Call Detection for iOS and Android]]></title><description><![CDATA[Fingerprint's new Active Call Detection Smart Signal shows when a user is on a call during sensitive actions, giving fraud teams real-time context on vishing.]]></description><link>/blog/product-update-active-call-detection/</link><guid isPermaLink="false">/blog/product-update-active-call-detection/</guid><pubDate>Fri, 21 Aug 2026 13:47:00 GMT</pubDate><enclosure url="https://fingerprint.com/static/5c1bfeb25ed3094c0ab032f82f10d95a/blog-active-call-smart-signal-launch.png" length="0" type="image/png"/><content:encoded>&lt;p&gt;Our newest mobile Smart Signal, Active Call Detection, is now available for both iOS and Android.&lt;/p&gt;
&lt;p&gt;Active Call Detection returns exactly one thing: whether someone is on a phone call while they use your mobile app:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;&quot;active_call&quot;: true&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;That is the whole response. &lt;code&gt;true&lt;/code&gt; when there is an active cellular or internet (VoIP) call happening, &lt;code&gt;false&lt;/code&gt; when there isn&apos;t.&lt;/p&gt;
&lt;p&gt;A phone call happening at the same moment as a password reset or a wire transfer is one of the few clues you can get to indicate social engineering, and it requires no new permissions or personal data to access it.&lt;/p&gt;
&lt;h2 id=&quot;why-we-built-active-call-detection&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#why-we-built-active-call-detection&quot; aria-label=&quot;why we built active call detection permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Why we built Active Call Detection&lt;/h2&gt;
&lt;p&gt;A lot of fraud detection works by finding something wrong. A device that has been tampered with, a login from an unrecognized browser, or a payment that doesn&apos;t match anything the account has done before. But with social engineering, you don’t get any of that.&lt;/p&gt;
&lt;p&gt;In a vishing (voice phishing) attack, the fraudster never touches your app. They call the victim, maybe pose as their bank or technical support, and talk them through steps to exfiltrate money, steal their account, and more.&lt;/p&gt;
&lt;p&gt;The victim resets the password. The victim reads the one-time passcode out loud. The victim approves the transfer. Every action comes from the real person, on their real device, using their real credentials, from their usual location.&lt;/p&gt;
&lt;p&gt;So the session looks perfectly fine because the only thing that has gone wrong is happening out loud, on a phone call, somewhere your fraud stack doesn’t see or hear.&lt;/p&gt;
&lt;p&gt;We added this new signal to close this gap, especially for our customers in banking and fintech, where vishing scams are prevalent and disastrous.&lt;/p&gt;
&lt;h2 id=&quot;how-active-call-detection-works&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#how-active-call-detection-works&quot; aria-label=&quot;how active call detection works permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;How Active Call Detection works&lt;/h2&gt;
&lt;p&gt;Active Call Detection works on iOS and Android, starting with SDK version v2.16.0, and requires no additional permissions in your app on either platform.&lt;/p&gt;
&lt;p&gt;It collects nothing about the call itself, such as the phone number, duration, or who is on the other end. The signal knows a call is happening, and that is all. The signal will show as &lt;code&gt;true&lt;/code&gt; for both cellular and VoIP calls.&lt;/p&gt;
&lt;p&gt;The signal reflects the call state at the moment of the identification event, and you&apos;ll find the result alongside the other Smart Signals in the Server API response, webhooks, and Sealed Client Results.&lt;/p&gt;
&lt;h2 id=&quot;when-to-check-if-a-user-is-on-a-phone-call&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#when-to-check-if-a-user-is-on-a-phone-call&quot; aria-label=&quot;when to check if a user is on a phone call permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;When to check if a user is on a phone call&lt;/h2&gt;
&lt;p&gt;An active call on its own tells you very little. What makes the signal useful is checking it at moments when a call could be suspicious or indicate social engineering, not just at app launch. For example:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;One-time passcode entry.&lt;/strong&gt; Your user is reading a code off their own device, which takes a few seconds and requires no help from anyone. A call in progress during that step suggests the code is being read to someone rather than into your app.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Payments, transfers, and beneficiary changes.&lt;/strong&gt; Moving money is the goal of most vishing attacks, and the fraudster usually stays on the line to walk the victim through it. A call at the moment of confirmation means someone may be pressuring them to do it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Login and account recovery.&lt;/strong&gt; Password resets and recovery flows are how account takeover starts. A call during either one can mean a fraudster is guiding a victim step by step into handing over access.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;High-risk settings changes.&lt;/strong&gt; Updating a phone number, adding a linked device, or raising a withdrawal limit are all changes that can lead to a bigger loss later.&lt;/p&gt;
&lt;h2 id=&quot;what-to-do-when-you-detect-a-call&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#what-to-do-when-you-detect-a-call&quot; aria-label=&quot;what to do when you detect a call permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;What to do when you detect a call&lt;/h2&gt;
&lt;p&gt;Plenty of people are on legitimate calls while they use your app, and blocking every one of them would be a great way to frustrate your customers without stopping much fraud. The useful question isn&apos;t whether to block, it&apos;s what a call in progress changes about how you handle the rest of the session.&lt;/p&gt;
&lt;p&gt;One simple example response would be to show an indicator on the screen when someone opens your app while on a call, letting them know your company is not the one calling. It&apos;s a small UI element that prompts the victim to pause and question what they&apos;ve been told. For a legitimate caller, it’s just a banner they can ignore.&lt;/p&gt;
&lt;p&gt;Beyond a warning, there are a few other options depending on the flow:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Require step-up authentication before a transfer or settings change goes through&lt;/li&gt;
&lt;li&gt;Add a short confirmation delay to high-value transactions, which gives the user time to think without the scammer&apos;s voice driving the pace&lt;/li&gt;
&lt;li&gt;Route the session to manual review rather than blocking it outright&lt;/li&gt;
&lt;li&gt;Log the result and look for patterns, like accounts where every large transfer happens during a call&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;And because a call by itself isn&apos;t suspicious, this signal becomes much stronger when paired with other &lt;a href=&quot;https://fingerprint.com/products/smart-signals/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Smart Signals&lt;/a&gt;, such as cloned app or developer tools detection.&lt;/p&gt;
&lt;h2 id=&quot;getting-started-with-active-call-detection&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#getting-started-with-active-call-detection&quot; aria-label=&quot;getting started with active call detection permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Getting started with Active Call Detection&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.fingerprint.com/docs/smart-signals-introduction#availability&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Active Call Detection is available now&lt;/a&gt; on Pro Plus and Enterprise plans for iOS, and Free, Pro Plus, Enterprise plans for Android.&lt;/p&gt;
&lt;p&gt;To start receiving it, update your app to iOS SDK v2.16.0 or Android SDK v2.16.0 or higher, and the &lt;code&gt;active_call&lt;/code&gt; field will appear alongside the other Smart Signals.&lt;/p&gt;
&lt;p&gt;From there, the main thing to sort out is placement. Pick the moments in your app where a phone call is genuinely out of place, whether that&apos;s OTP entry, transaction confirmation, or account recovery, and make sure you&apos;re requesting identification at those steps.&lt;/p&gt;
&lt;p&gt;If you want to dig into the details, our &lt;a href=&quot;https://docs.fingerprint.com/docs/smart-signals-reference#active-call-detection&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Smart Signals reference page&lt;/a&gt; has the full documentation.&lt;/p&gt;
&lt;p&gt;And if you&apos;re not using Fingerprint yet, you can &lt;a href=&quot;https://dashboard.fingerprint.com/signup&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;start with our free plan&lt;/a&gt; or &lt;a href=&quot;https://fingerprint.com/contact-sales/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;reach out to our team&lt;/a&gt; to talk through how this would fit into your fraud stack.&lt;/p&gt;</content:encoded><tags>product-updates, smart-signals, android, ios, fintech</tags></item><item><title><![CDATA[The best fraud prevention and risk conferences [late 2026 - early 2027]]]></title><description><![CDATA[Explore the top fraud prevention and risk conferences for late 2026–early 2027, organized by industry: e-commerce, marketplaces, fintech, identity, trust & safety, igaming, and financial crime.]]></description><link>/blog/best-fraud-prevention-conferences/</link><guid isPermaLink="false">/blog/best-fraud-prevention-conferences/</guid><pubDate>Fri, 14 Aug 2026 11:11:00 GMT</pubDate><enclosure url="https://fingerprint.com/static/69ce8d172602d025c2358b2cc3682fd8/best-fraud-prevention-conferences-list.jpg" length="0" type="image/jpeg"/><content:encoded>&lt;p&gt;There is a lot of variation among the types of &quot;fraud and risk conferences&quot; that exist around the world.&lt;/p&gt;
&lt;p&gt;Do you want strategies for &lt;a href=&quot;https://fingerprint.com/blog/e-commerce-payment-fraud-detection-prevention/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;protecting revenue in e-commerce platforms&lt;/a&gt;? Or learn new techniques for &lt;a href=&quot;https://fingerprint.com/blog/bot-detection/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;stopping bot attacks&lt;/a&gt; in banking and fintech? Hear executive-level perspectives and roundtables with fraud industry leaders? Or learn bleeding-edge engineering tactics to help your team prevent multi-accounting, promo abuse, and account takeover?&lt;/p&gt;
&lt;p&gt;No matter your role or industry, if you&apos;re looking for events that can give you the best insights for detecting and deterring fraud in the digital realm, we&apos;ve got you covered.&lt;/p&gt;
&lt;p&gt;Here&apos;s our rundown of the best fraud prevention and risk conferences coming up in late 2026 and early 2027, broken out by industry focus. We hope these events give you new learnings to help you stay ahead of the emerging threats and challenges in modern fraud defense.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;📍 Visit &lt;a href=&quot;https://fingerprint.com/events&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;fingerprint.com/events&lt;/a&gt; for an up-to-date view of where you can find us in person, along with upcoming and on-demand webinars.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;h2 id=&quot;e-commerce-and-merchant-fraud&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#e-commerce-and-merchant-fraud&quot; aria-label=&quot;e commerce and merchant fraud permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;E-commerce and merchant fraud&lt;/h2&gt;
&lt;p&gt;These conferences delve into the most pressing fraud and risk challenges facing merchants, retailers, ecommerce platforms, financial institutions, and payment processing providers. Topics covered may include payment fraud, chargebacks and dispute management, policy and returns abuse, promo and coupon stacking, account takeovers, login and checkout security, and the growing question of how to handle agentic traffic while protecting real users and accounts.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pricing:&lt;/strong&gt; MRC tiers by membership status and company type, with merchants paying substantially less than solution providers. Merchant Fraud Alliance pricing varies depending how early you book. MPE offers free merchant passes.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Event&lt;/th&gt;
&lt;th&gt;Dates&lt;/th&gt;
&lt;th&gt;Location&lt;/th&gt;
&lt;th&gt;Link&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;MRC San Diego (members only)&lt;/td&gt;
&lt;td&gt;Sept 14–16, 2026&lt;/td&gt;
&lt;td&gt;Hyatt Regency Mission Bay, San Diego, CA&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://merchantriskcouncil.org&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;merchantriskcouncil.org&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Merchant Fraud Alliance&lt;/td&gt;
&lt;td&gt;Oct 6–7, 2026&lt;/td&gt;
&lt;td&gt;Convene Willis Tower, Chicago, IL&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://merchantfraudalliance.com&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;merchantfraudalliance.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;MRC Dublin (members only)&lt;/td&gt;
&lt;td&gt;Nov 2–4, 2026&lt;/td&gt;
&lt;td&gt;Clayton Hotel Burlington Road, Dublin, Ireland&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://merchantriskcouncil.org&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;merchantriskcouncil.org&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Merchant Payments Ecosystem (MPE)&lt;/td&gt;
&lt;td&gt;Mar 9–11, 2027&lt;/td&gt;
&lt;td&gt;InterContinental Berlin, Germany&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://merchantpaymentsecosystem.com&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;merchantpaymentsecosystem.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;MRC Vegas&lt;/td&gt;
&lt;td&gt;Mar 15–18, 2027&lt;/td&gt;
&lt;td&gt;ARIA Resort &amp;#x26; Casino, Las Vegas, NV&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://merchantriskcouncil.org&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;merchantriskcouncil.org&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;MRC London&lt;/td&gt;
&lt;td&gt;Apr 26–28, 2027&lt;/td&gt;
&lt;td&gt;InterContinental London – The O2, UK&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://merchantriskcouncil.org&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;merchantriskcouncil.org&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id=&quot;marketplaces-and-platform-risk&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#marketplaces-and-platform-risk&quot; aria-label=&quot;marketplaces and platform risk permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Marketplaces and platform risk&lt;/h2&gt;
&lt;p&gt;Multi-sided platforms have a distinct threat model, and Marketplace Risk is the only conference series built entirely around it. The recurring themes are fake and duplicate account creation, seller onboarding and KYB, listing and inventory fraud, buyer-seller collusion, off-platform disintermediation, review manipulation, and the trust-and-safety policy work that sits alongside all of it. Sessions are short and workshop-shaped rather than keynote-driven, and the attendee mix leans toward trust and safety leads, risk and compliance managers, and platform operations people at marketplaces, gig platforms, sharing-economy companies, and social commerce apps. Legal and policy titles are unusually well represented compared to the merchant events.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pricing:&lt;/strong&gt; Marketplace Risk uses tiers for pricing, with variation depending on the industry, sponsorship status, and role. They offer coupons and scholarship rates, as well.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Event&lt;/th&gt;
&lt;th&gt;Dates&lt;/th&gt;
&lt;th&gt;Location&lt;/th&gt;
&lt;th&gt;Link&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Marketplace Risk New York&lt;/td&gt;
&lt;td&gt;Sept 14–16, 2026&lt;/td&gt;
&lt;td&gt;Jay Conference Bryant Park, New York, NY&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://marketplacerisk.com/new-york-conference&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;marketplacerisk.com/new-york-conference&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Digital Risk Summit São Paulo&lt;/td&gt;
&lt;td&gt;Oct 13–15, 2026&lt;/td&gt;
&lt;td&gt;Grand Mercure Vila Olímpia, São Paulo, Brazil&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://marketplacerisk.com/sao-summit&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;marketplacerisk.com/sao-summit&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Marketplace Risk Global Summit&lt;/td&gt;
&lt;td&gt;Nov 2–3, 2026&lt;/td&gt;
&lt;td&gt;The Aon Centre, London, UK&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://marketplacerisk.com/global-summit&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;marketplacerisk.com/global-summit&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Marketplace Risk Management Conference&lt;/td&gt;
&lt;td&gt;May 11–13, 2027&lt;/td&gt;
&lt;td&gt;Convene, 40 O&apos;Farrell St, San Francisco, CA&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://marketplacerisk.com/conference&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;marketplacerisk.com/conference&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id=&quot;fintech-and-payments&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#fintech-and-payments&quot; aria-label=&quot;fintech and payments permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Fintech and payments&lt;/h2&gt;
&lt;p&gt;Fraud, identity, and increasingly agentic-AI risk are among the biggest agenda tracks at fintech and payments conferences like Money20/20. The Money20/20 Americas event expects over 11,000 attendees, with 1 out of 3 from the C-suite, demonstrating both an executive-level attendee profile as well as a large number of partnership opportunities and insights across industries like banks, payments, tech, retail, startups, and more.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pricing:&lt;/strong&gt; Nearly all of them offer heavily discounted or free passes for qualifying banks, credit unions, retailers, and early-stage startups — Money20/20 has a free hosted-buyer program for banks and retailers.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Event&lt;/th&gt;
&lt;th&gt;Dates&lt;/th&gt;
&lt;th&gt;Location&lt;/th&gt;
&lt;th&gt;Link&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Money20/20 USA&lt;/td&gt;
&lt;td&gt;Oct 18–21, 2026&lt;/td&gt;
&lt;td&gt;The Venetian Expo, Las Vegas, NV&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://us.money2020.com&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;us.money2020.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Money20/20 Asia&lt;/td&gt;
&lt;td&gt;Apr 27–29, 2027&lt;/td&gt;
&lt;td&gt;Queen Sirikit National Convention Center, Bangkok, Thailand&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://asia.money2020.com&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;asia.money2020.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Money20/20 Europe&lt;/td&gt;
&lt;td&gt;Jun 8–10, 2027&lt;/td&gt;
&lt;td&gt;RAI Amsterdam, Netherlands&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://europe.money2020.com&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;europe.money2020.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id=&quot;identity-and-authentication&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#identity-and-authentication&quot; aria-label=&quot;identity and authentication permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Identity and authentication&lt;/h2&gt;
&lt;p&gt;These events are focused on the core themes of bot detection and fake-account prevention through the lens of identity verification, digital credentials, and continuous authentication. Topics and talks may focus on passkeys and phishing-resistant logins, deepfake prevention, verifiable credentials and digital wallets, eIDAS 2.0 in Europe, and non-human and agentic identity, meaning how you authenticate and authorize an AI agent acting on a user&apos;s behalf. The audience is more technical, with tracks that appeal to roles like identity architects, product managers, security strategists, IAM practitioners, CISOs, and engineers.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pricing:&lt;/strong&gt; Gartner summits are the priciest, although they do offer one free pass per three paid. Authenticate and Identiverse gate pricing behind registration, and Identiverse offers 10–20% team discounts at three, five, and ten attendees plus up to 20 CPE credits.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Event&lt;/th&gt;
&lt;th&gt;Dates&lt;/th&gt;
&lt;th&gt;Location&lt;/th&gt;
&lt;th&gt;Link&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Authenticate U.S. (FIDO Alliance)&lt;/td&gt;
&lt;td&gt;Oct 19–21, 2026&lt;/td&gt;
&lt;td&gt;Omni La Costa Resort &amp;#x26; Spa, Carlsbad, CA&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://authenticatecon.com&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;authenticatecon.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Gartner Identity &amp;#x26; Access Management Summit&lt;/td&gt;
&lt;td&gt;Dec 7–9, 2026&lt;/td&gt;
&lt;td&gt;Caesars Forum, Las Vegas, NV&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://www.gartner.com/en/conferences/calendar&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;gartner.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Gartner IAM Summit EMEA&lt;/td&gt;
&lt;td&gt;Mar 8–9, 2027&lt;/td&gt;
&lt;td&gt;InterContinental London – The O2, UK&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://www.gartner.com/en/conferences/calendar&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;gartner.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Identiverse&lt;/td&gt;
&lt;td&gt;Jun 28–Jul 1, 2027&lt;/td&gt;
&lt;td&gt;Mandalay Bay Resort, Las Vegas, NV&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://identiverse.com&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;identiverse.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id=&quot;trust-and-safety-research-and-cybercrime&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#trust-and-safety-research-and-cybercrime&quot; aria-label=&quot;trust and safety research and cybercrime permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Trust and safety, research, and cybercrime&lt;/h2&gt;
&lt;p&gt;These are more academic and research-oriented events, often where the content is peer-reviewed or policy-driven rather than vendor-led. Stanford&apos;s Trust &amp;#x26; Safety Research Conference draws academics, policy staff, and the more research-minded practitioners from large platforms who want to join sessions on platform accountability, AI-driven abuse, coordinated inauthentic behavior, and online-harms research. The 2026 program at the APWG eCrime Symposium includes a track on AI as a cybercrime catalyst and autonomous fraud operations.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pricing:&lt;/strong&gt; TSRC runs $200–$350 for academic, civil society, and government attendees and $650–$800 for industry, with registration closing September 20, 2026. APWG eCrime is a flat $350.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Event&lt;/th&gt;
&lt;th&gt;Dates&lt;/th&gt;
&lt;th&gt;Location&lt;/th&gt;
&lt;th&gt;Link&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Trust &amp;#x26; Safety Research Conference (TSRC)&lt;/td&gt;
&lt;td&gt;Oct 1–2, 2026&lt;/td&gt;
&lt;td&gt;Stanford University Alumni Center, Stanford, CA&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://tip.fsi.stanford.edu&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;tip.fsi.stanford.edu&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;APWG eCrime Symposium&lt;/td&gt;
&lt;td&gt;Nov 2–6, 2026&lt;/td&gt;
&lt;td&gt;InterContinental Lisbon, Portugal&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://apwg.org&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;apwg.org&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;em&gt;Note: The largest dedicated trust and safety event, TrustCon 2026, took place in July in San Francisco. Their 2027 event date has not yet been announced.&lt;/em&gt;&lt;/p&gt;
&lt;h2 id=&quot;affiliate-igaming-and-gambling&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#affiliate-igaming-and-gambling&quot; aria-label=&quot;affiliate igaming and gambling permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Affiliate, igaming, and gambling&lt;/h2&gt;
&lt;p&gt;These are large-scale conferences with a wide range of attendee profiles — from practitioner sessions with technical specifics to C-suite and executive-level perspectives. Topics and areas of focus for igaming and gambling include multi-accounting, bonus and promo abuse, sign-up offer farming, ban evasion, arbitrage and matched-betting rings, affiliate traffic fraud, KYC and age verification, and responsible-gaming compliance and regulatory risks. For affiliate-themed events, invalid traffic, click fraud, cookie stuffing, incentivized-traffic misrepresentation, and attribution manipulation are all core conference talk tracks and discussion themes.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pricing:&lt;/strong&gt; There is a wide range of pricing across these conferences. SBC does offer a free expo pass and complimentary passes for operators, affiliates, and regulators, with paid conference tiers, as well. The affiliate events range based on registration date, membership status, and standard and premium tiers.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Event&lt;/th&gt;
&lt;th&gt;Dates&lt;/th&gt;
&lt;th&gt;Location&lt;/th&gt;
&lt;th&gt;Link&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;SBC Summit&lt;/td&gt;
&lt;td&gt;Sept 29 – Oct 1, 2026&lt;/td&gt;
&lt;td&gt;Feira Internacional de Lisboa &amp;#x26; MEO Arena, Lisbon, Portugal&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://sbcevents.com/sbc-summit&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;sbcevents.com/sbc-summit&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;IAB Annual Leadership Meeting&lt;/td&gt;
&lt;td&gt;Feb 1–3, 2027&lt;/td&gt;
&lt;td&gt;JW Marriott Hill Country, San Antonio, TX&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://iab.com&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;iab.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;SBC Summit Rio&lt;/td&gt;
&lt;td&gt;Mar 2–4, 2027&lt;/td&gt;
&lt;td&gt;Riocentro, Rio de Janeiro, Brazil&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://sbcevents.com/sbc-summit-rio&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;sbcevents.com/sbc-summit-rio&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;SBC Summit Europe&lt;/td&gt;
&lt;td&gt;Apr 19–21, 2027&lt;/td&gt;
&lt;td&gt;RAI Amsterdam, Netherlands&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://sbcevents.com/sbc-summit-europe&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;sbcevents.com/sbc-summit-europe&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;i-Con (Island Conference)&lt;/td&gt;
&lt;td&gt;May 27–28, 2027&lt;/td&gt;
&lt;td&gt;Limassol, Cyprus&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://island-conference.com&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;island-conference.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;SBC Summit Canada&lt;/td&gt;
&lt;td&gt;Jun 15–17, 2027&lt;/td&gt;
&lt;td&gt;Metro Toronto Convention Centre, Canada&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://sbcevents.com/sbc-summit-canada&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;sbcevents.com/sbc-summit-canada&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;em&gt;Note: SBC Summit Americas is confirmed to return to Fort Lauderdale in 2027 but dates are still listed as TBA.&lt;/em&gt;&lt;/p&gt;
&lt;h2 id=&quot;financial-crime-aml-and-scam-prevention&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#financial-crime-aml-and-scam-prevention&quot; aria-label=&quot;financial crime aml and scam prevention permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Financial crime, AML, and scam prevention&lt;/h2&gt;
&lt;p&gt;These events are aimed at fraud defense in traditional regulated financial institutions and compliance functions in banking and finance. Topics covered include synthetic identity, account takeover, authorized push payment (APP) scams, mule account detection, and AI-generated fraud. For engineers and fraud analysts who are working at a bank, a neobank, a lender, or a payments company, this section will feel more relevant than the merchant or marketplace tracks.&lt;/p&gt;
&lt;p&gt;These types of events can vary widely in format and feel. ISMG&apos;s Fraud Prevention Summit and the Datos Insights Financial Crime &amp;#x26; Cybersecurity Forum are curated, practitioner-gated events where vendors can only attend by sponsoring. Millennium Alliance&apos;s GRC Assembly is invitation-only and C-suite-restricted, aimed at global chief risk and compliance officers. Intellect&apos;s Fraud FS Summit is a single-day, single-plenary, press-closed session for heads of fraud and financial crime at UK banks.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pricing:&lt;/strong&gt; Millennium Alliance is fully hosted for delegates (members). The credentialing conferences charge varying rates, depending on membership, pass type, and sector.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Event&lt;/th&gt;
&lt;th&gt;Dates&lt;/th&gt;
&lt;th&gt;Location&lt;/th&gt;
&lt;th&gt;Link&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Financial Crime &amp;#x26; Cybersecurity Forum (Datos Insights)&lt;/td&gt;
&lt;td&gt;Sept 15–16, 2026&lt;/td&gt;
&lt;td&gt;The Westin, Charlotte, NC&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://datos-insights.com&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;datos-insights.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Fraud FS Summit (Intellect)&lt;/td&gt;
&lt;td&gt;Oct 15, 2026&lt;/td&gt;
&lt;td&gt;London, UK&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://intellectfs.com&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;intellectfs.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ACFE Fraud Conference Canada&lt;/td&gt;
&lt;td&gt;Nov 15–17, 2026&lt;/td&gt;
&lt;td&gt;Montreal, Canada and Virtual&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://fraudconference.com&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;fraudconference.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Enterprise GRC Assembly (Millennium Alliance)&lt;/td&gt;
&lt;td&gt;Feb 9–10, 2027&lt;/td&gt;
&lt;td&gt;Location TBC&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://mill-all.com&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;mill-all.com&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;em&gt;Dates, locations, and pricing were verified against organizer websites in August 2026. Conferences shift details often, especially pricing tiers and 2027 dates that haven&apos;t been announced yet, so always confirm on the organizer&apos;s site.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;———&lt;/p&gt;
&lt;h2 id=&quot;where-youll-find-us-on-the-road&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#where-youll-find-us-on-the-road&quot; aria-label=&quot;where youll find us on the road permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Where you&apos;ll find us on the road&lt;/h2&gt;
&lt;p&gt;Our team will be at many of the listed events above. You can stop by our booth for demos and deep-dives on our later product updates, attend executive roundtables and presentations, and catch breakout talks from our engineers and technical experts.&lt;/p&gt;
&lt;p&gt;We can&apos;t wait to see you out there!&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;📍 Visit &lt;a href=&quot;&quot;&gt;fingerprint.com/events&lt;/a&gt; for an up-to-date view of where you can find us in person, along with upcoming and on-demand webinars.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><tags>events</tags></item><item><title><![CDATA[How to detect which AI tools call your MCP server]]></title><description><![CDATA[See which AI tools are calling your MCP server. Use Fingerprint's Automation Intelligence API to identify clients from request metadata alone, no JavaScript agent needed.]]></description><link>/blog/how-to-detect-ai-tools-mcp-server/</link><guid isPermaLink="false">/blog/how-to-detect-ai-tools-mcp-server/</guid><pubDate>Wed, 12 Aug 2026 15:35:00 GMT</pubDate><enclosure url="https://fingerprint.com/static/d74d3b37f314f75575379c7f6ec1cd38/blog_how_to_detect_which_ai_tools_call_your_mcp_server.png" length="0" type="image/png"/><content:encoded>&lt;p&gt;You shipped an MCP server. Tool calls are coming in. Now, you want to answer a simple question: Which AI tools are actually calling it?&lt;/p&gt;
&lt;p&gt;For most teams, the honest answer is &quot;we&apos;re not sure.&quot; You can see request volume, tool names, and latency. What you can&apos;t see is whether that traffic is Claude Code running on a developer&apos;s laptop, a Cursor session, a cloud-hosted agent runner, or something impersonating one of them.&lt;/p&gt;
&lt;p&gt;That knowledge gap matters more than it looks.&lt;/p&gt;
&lt;p&gt;You may be looking to answer product questions like:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Which clients to prioritize&lt;/li&gt;
&lt;li&gt;Which tool schemas to optimize&lt;/li&gt;
&lt;li&gt;Whether a spike is adoption or a runaway loop&lt;/li&gt;
&lt;li&gt;Whether &quot;agentic&quot; usage is real&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MCP&apos;s design makes these questions unusually hard to answer.&lt;/p&gt;
&lt;p&gt;This post covers how to close that gap using Fingerprint&apos;s &lt;a href=&quot;https://docs.fingerprint.com/reference/automation-intelligence-api&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Automation Intelligence API&lt;/a&gt; (currently in a free public preview), how to set up the integration, and what we learned from adding it to our own MCP server.&lt;/p&gt;
&lt;h2 id=&quot;why-mcp-analytics-are-harder-than-web-analytics&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#why-mcp-analytics-are-harder-than-web-analytics&quot; aria-label=&quot;why mcp analytics are harder than web analytics permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Why MCP analytics are harder than web analytics&lt;/h2&gt;
&lt;p&gt;Standard product analytics assume a browser or a logged-in user. MCP gives you neither in a useful form. It&apos;s JSON-RPC over HTTP, called by a program on behalf of a person you never see.&lt;/p&gt;
&lt;p&gt;This has two consequences.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First, there&apos;s no JavaScript agent to run.&lt;/strong&gt; Most sophisticated bot detection works by collecting signals from a real browser. There is no browser here. Any client-side approach is structurally unavailable to an MCP server.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Second, everyone falls back to &lt;code&gt;User-Agent&lt;/code&gt; parsing.&lt;/strong&gt; It&apos;s the obvious move, and it&apos;s weak in three specific ways:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Coverage&lt;/strong&gt;. Many MCP clients send a generic HTTP library UA, or nothing meaningful at all.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Trust&lt;/strong&gt;. &lt;code&gt;User-Agent&lt;/code&gt; is self-reported. Any script can claim to be a well-known coding tool, and nothing in your stack disagrees.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Depth&lt;/strong&gt;. Even an honest UA doesn&apos;t tell you whether the request came from a laptop or a datacenter, which is often the more interesting question.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;You end up with a chart of strings you can&apos;t fully trust and can&apos;t fully interpret.&lt;/p&gt;
&lt;h2 id=&quot;how-fingerprints-automation-intelligence-api-detects-ai-tools-calling-your-mcp-server&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#how-fingerprints-automation-intelligence-api-detects-ai-tools-calling-your-mcp-server&quot; aria-label=&quot;how fingerprints automation intelligence api detects ai tools calling your mcp server permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;How Fingerprint&apos;s Automation Intelligence API detects AI tools calling your MCP server&lt;/h2&gt;
&lt;p&gt;Our Automation Intelligence API works entirely from HTTP request metadata — the headers, method, URL, and client IP that already reach your server. No JavaScript agent, no client SDK, no changes for the people calling your MCP endpoint.&lt;/p&gt;
&lt;p&gt;You POST that metadata to the Collect Intelligence endpoint and get back a structured verdict: what kind of automation this is, who operates it, whether its claimed identity holds up, and where it&apos;s connecting from. Average response times are under 30ms, and it&apos;s designed to run in edge, pre-origin, or middleware contexts, so it fits naturally in an MCP request path.&lt;/p&gt;
&lt;p&gt;It&apos;s available in the Global (&lt;code&gt;api.fpjs.io&lt;/code&gt;), EU (&lt;code&gt;eu.api.fpjs.io&lt;/code&gt;), and Asia (&lt;code&gt;ap.api.fpjs.io&lt;/code&gt;) regions and is authenticated with a secret API key.&lt;/p&gt;
&lt;h2 id=&quot;the-integration-in-three-steps&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#the-integration-in-three-steps&quot; aria-label=&quot;the integration in three steps permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;The integration, in three steps&lt;/h2&gt;
&lt;h3 id=&quot;1-capture-the-request-metadata&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#1-capture-the-request-metadata&quot; aria-label=&quot;1 capture the request metadata permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;1. Capture the request metadata&lt;/h3&gt;
&lt;p&gt;Forward all the original headers, preserving order and capitalization — detection accuracy depends on seeing the request as the client actually sent it. Headers carrying credentials (&lt;code&gt;Authorization&lt;/code&gt;, &lt;code&gt;Cookie&lt;/code&gt;, &lt;code&gt;Set-Cookie&lt;/code&gt;) must still be present but blanked, never dropped: removing them changes the shape of the request.&lt;/p&gt;
&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;tsx&quot;&gt;&lt;pre class=&quot;language-tsx&quot;&gt;&lt;code class=&quot;language-tsx&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;const&lt;/span&gt; &lt;span class=&quot;token constant&quot;&gt;BLANK&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token keyword&quot;&gt;new&lt;/span&gt; &lt;span class=&quot;token class-name&quot;&gt;Set&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&quot;authorization&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;cookie&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;set-cookie&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;proxy-authorization&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;

&lt;span class=&quot;token comment&quot;&gt;// Node&apos;s rawHeaders preserves the original order and casing.&lt;/span&gt;
&lt;span class=&quot;token keyword&quot;&gt;function&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;headerEntries&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;req&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token keyword&quot;&gt;const&lt;/span&gt; out &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
  &lt;span class=&quot;token keyword&quot;&gt;for&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token keyword&quot;&gt;let&lt;/span&gt; i &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt; i &lt;span class=&quot;token operator&quot;&gt;&amp;lt;&lt;/span&gt; req&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;rawHeaders&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;length&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt; i &lt;span class=&quot;token operator&quot;&gt;+=&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;2&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;token keyword&quot;&gt;const&lt;/span&gt; name &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; req&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;rawHeaders&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;i&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
    &lt;span class=&quot;token keyword&quot;&gt;const&lt;/span&gt; value &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; req&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;rawHeaders&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;i &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
    out&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;push&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; name&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; value&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token constant&quot;&gt;BLANK&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;has&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;name&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;toLowerCase&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;?&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;&quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; value &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  &lt;span class=&quot;token keyword&quot;&gt;return&lt;/span&gt; out&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;h3 id=&quot;2-send-it-for-analysis&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#2-send-it-for-analysis&quot; aria-label=&quot;2 send it for analysis permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;2. Send it for analysis&lt;/h3&gt;
&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;tsx&quot;&gt;&lt;pre class=&quot;language-tsx&quot;&gt;&lt;code class=&quot;language-tsx&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;const&lt;/span&gt; res &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token keyword&quot;&gt;await&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;fetch&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&quot;https://api.fpjs.io/v4/edge&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  method&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;POST&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  headers&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    Authorization&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token template-string&quot;&gt;&lt;span class=&quot;token template-punctuation string&quot;&gt;`&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;Bearer &lt;/span&gt;&lt;span class=&quot;token interpolation&quot;&gt;&lt;span class=&quot;token interpolation-punctuation punctuation&quot;&gt;${&lt;/span&gt;process&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;env&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token constant&quot;&gt;FINGERPRINT_SECRET_API_KEY&lt;/span&gt;&lt;span class=&quot;token interpolation-punctuation punctuation&quot;&gt;}&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;token template-punctuation string&quot;&gt;`&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token string-property property&quot;&gt;&quot;Content-Type&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;application/json&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  body&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token constant&quot;&gt;JSON&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;stringify&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    headers&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;headerEntries&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;req&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    method&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; req&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;method&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    url&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token template-string&quot;&gt;&lt;span class=&quot;token template-punctuation string&quot;&gt;`&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;https://mcp.example.com&lt;/span&gt;&lt;span class=&quot;token interpolation&quot;&gt;&lt;span class=&quot;token interpolation-punctuation punctuation&quot;&gt;${&lt;/span&gt;req&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;url&lt;span class=&quot;token interpolation-punctuation punctuation&quot;&gt;}&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;token template-punctuation string&quot;&gt;`&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    ipv4_address&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; clientIp&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    tags&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token string-property property&quot;&gt;&quot;user-agent&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; req&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;headers&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&quot;user-agent&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;That optional &lt;code&gt;tags&lt;/code&gt; object is free-form and gets stored on the event — handy for slicing later. We tag the raw &lt;code&gt;User-Agent&lt;/code&gt;, which turns the unreliable-on-its-own string into a useful secondary dimension once it sits next to a verified identity.&lt;/p&gt;
&lt;h3 id=&quot;3-record-the-result&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#3-record-the-result&quot; aria-label=&quot;3 record the result permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;3. Record the result&lt;/h3&gt;
&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;tsx&quot;&gt;&lt;pre class=&quot;language-tsx&quot;&gt;&lt;code class=&quot;language-tsx&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;const&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; bot_info&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; ip_info &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token keyword&quot;&gt;await&lt;/span&gt; res&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;json&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;

analytics&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;track&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&quot;mcp_request&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  tool&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; bot_info&lt;span class=&quot;token operator&quot;&gt;?.&lt;/span&gt;name&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;                          &lt;span class=&quot;token comment&quot;&gt;// &quot;ChatGPT Agent&quot;&lt;/span&gt;
  category&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; bot_info&lt;span class=&quot;token operator&quot;&gt;?.&lt;/span&gt;category&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;                  &lt;span class=&quot;token comment&quot;&gt;// &quot;ai_agent&quot;&lt;/span&gt;
  provider&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; bot_info&lt;span class=&quot;token operator&quot;&gt;?.&lt;/span&gt;provider&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;                  &lt;span class=&quot;token comment&quot;&gt;// &quot;OpenAI&quot;&lt;/span&gt;
  identity&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; bot_info&lt;span class=&quot;token operator&quot;&gt;?.&lt;/span&gt;identity&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;                  &lt;span class=&quot;token comment&quot;&gt;// &quot;signed&quot; | &quot;verified&quot; | &quot;spoofed&quot;&lt;/span&gt;
  confidence&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; bot_info&lt;span class=&quot;token operator&quot;&gt;?.&lt;/span&gt;confidence&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;              &lt;span class=&quot;token comment&quot;&gt;// &quot;high&quot;&lt;/span&gt;
  datacenter&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; ip_info&lt;span class=&quot;token operator&quot;&gt;?.&lt;/span&gt;v4&lt;span class=&quot;token operator&quot;&gt;?.&lt;/span&gt;datacenter_name&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;      &lt;span class=&quot;token comment&quot;&gt;// &quot;Amazon AWS&quot;&lt;/span&gt;
  country&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; ip_info&lt;span class=&quot;token operator&quot;&gt;?.&lt;/span&gt;v4&lt;span class=&quot;token operator&quot;&gt;?.&lt;/span&gt;geolocation&lt;span class=&quot;token operator&quot;&gt;?.&lt;/span&gt;country_code&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;That&apos;s the whole integration. A trimmed response looks like this:&lt;/p&gt;
&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;json&quot;&gt;&lt;pre class=&quot;language-json&quot;&gt;&lt;code class=&quot;language-json&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;&quot;event_id&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;1758130560902.8tRtrH&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;&quot;bot_info&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;token property&quot;&gt;&quot;category&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;ai_agent&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token property&quot;&gt;&quot;provider&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;OpenAI&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token property&quot;&gt;&quot;name&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;ChatGPT Agent&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token property&quot;&gt;&quot;identity&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;signed&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token property&quot;&gt;&quot;confidence&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;high&quot;&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;&quot;ip_info&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;token property&quot;&gt;&quot;v4&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token property&quot;&gt;&quot;asn_name&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;Google LLC&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token property&quot;&gt;&quot;asn_type&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;hosting&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
            &lt;span class=&quot;token property&quot;&gt;&quot;datacenter_result&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token property&quot;&gt;&quot;datacenter_name&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;Google Cloud&quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;&quot;vpn&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean&quot;&gt;false&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;&quot;proxy&quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean&quot;&gt;false&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;h2 id=&quot;what-you-actually-learn-about-your-mcp-server-traffic&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#what-you-actually-learn-about-your-mcp-server-traffic&quot; aria-label=&quot;what you actually learn about your mcp server traffic permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;What you actually learn about your MCP server traffic&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Automation Intelligence can help you understand and analyze your MCP server traffic in several useful ways. It gives you:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1. A real category taxonomy.&lt;/strong&gt; Instead of a UA string, you get a classification: &lt;code&gt;ai_agent&lt;/code&gt;, &lt;code&gt;ai_assistant&lt;/code&gt;, &lt;code&gt;ai_browser&lt;/code&gt;, &lt;code&gt;ai_crawler&lt;/code&gt;, &lt;code&gt;ai_search&lt;/code&gt;, &lt;code&gt;browser_automation&lt;/code&gt;, &lt;code&gt;scraping&lt;/code&gt;, &lt;code&gt;monitoring_and_analytics&lt;/code&gt;, &lt;code&gt;search_engine_crawler&lt;/code&gt;, and more.&lt;/p&gt;
&lt;p&gt;&quot;40% of our MCP traffic is &lt;code&gt;ai_agent&lt;/code&gt;, 55% &lt;code&gt;ai_assistant&lt;/code&gt;&quot; is a sentence you can put in a roadmap review. Slice, dice, analyze, and report on your traffic in any number of ways, with greater depth and accuracy.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. Identity you can trust — the part UA parsing can never give you.&lt;/strong&gt; Every detection carries an &lt;code&gt;identity&lt;/code&gt; value:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Identity&lt;/th&gt;
&lt;th&gt;Meaning&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;verified&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Well-known bot with a publicly verifiable identity, operated by the provider&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;signed&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Cryptographically signs its requests via &lt;a href=&quot;https://docs.fingerprint.com/docs/bot-detection/web-bot-auth-implementation&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Web Bot Auth&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;spoofed&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Claims a public identity but fails verification&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;unknown&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Doesn&apos;t publish a verifiable identity&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;code&gt;signed&lt;/code&gt; is the interesting one. Web Bot Auth lets an agent cryptographically prove which platform it&apos;s running on, so &lt;code&gt;signed&lt;/code&gt; isn&apos;t an inference — it&apos;s confirmed. And &lt;code&gt;spoofed&lt;/code&gt; is the value that has no equivalent in UA-based analytics at all: something claimed to be a well-known tool and the claim didn&apos;t hold. In UA parsing, that request would have been silently counted as the real thing.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. Where the traffic physically comes from.&lt;/strong&gt; The &lt;code&gt;ip_info&lt;/code&gt; block returns ASN, ASN type (&lt;code&gt;hosting&lt;/code&gt;, &lt;code&gt;isp&lt;/code&gt;, &lt;code&gt;business&lt;/code&gt;), datacenter detection and name, plus geolocation — alongside separate VPN and proxy detection with confidence levels. For MCP, this maps cleanly onto a question you care about: &lt;code&gt;asn_type: &quot;isp&quot;&lt;/code&gt; usually means a developer&apos;s machine; &lt;code&gt;datacenter_result: true&lt;/code&gt; with &lt;code&gt;datacenter_name: &quot;Amazon AWS&quot;&lt;/code&gt; means a hosted agent. Local IDE usage versus automated cloud workloads is a real product distinction that drives very different capacity and pricing conversations.&lt;/p&gt;
&lt;h2 id=&quot;dogfooding-our-own-mcp-server-at-fingerprint&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#dogfooding-our-own-mcp-server-at-fingerprint&quot; aria-label=&quot;dogfooding our own mcp server at fingerprint permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Dogfooding: our own MCP server at Fingerprint&lt;/h2&gt;
&lt;p&gt;We run a managed MCP server at &lt;code&gt;mcp.fpjs.io&lt;/code&gt; (&lt;a href=&quot;https://fingerprint.com/blog/introducing-fingerprint-mcp-server/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;announcement here&lt;/a&gt;), with an &lt;a href=&quot;https://github.com/fingerprintjs/fingerprint-mcp-server&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;open-source version&lt;/a&gt; you can self-host. It connects AI assistants to &lt;a href=&quot;https://fingerprint.com/products/fingerprint-pro/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Fingerprint device intelligence&lt;/a&gt; — so having no visibility into which AI tools were calling &lt;em&gt;it&lt;/em&gt; was a slightly embarrassing blind spot.&lt;/p&gt;
&lt;p&gt;We added Automation Intelligence to it. Every HTTP request to the MCP endpoint gets its metadata forwarded for analysis, and the result is recorded alongside our existing telemetry. On the open-source server, this hangs off a small request-inspection hook, which keeps the analytics code out of the protocol layer.&lt;/p&gt;
&lt;p&gt;The MCP client ecosystem we see connecting spans a wide range of coding tools and assistants:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Claude Code&lt;/strong&gt;, &lt;strong&gt;Claude Desktop&lt;/strong&gt;, and Claude on the web&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cursor&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;OpenAI Codex&lt;/strong&gt; and ChatGPT connectors&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;VS Code&lt;/strong&gt; with GitHub Copilot&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Zed&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Windsurf&lt;/strong&gt;, &lt;strong&gt;Cline&lt;/strong&gt;, and &lt;strong&gt;Continue&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;JetBrains&lt;/strong&gt; AI Assistant&lt;/li&gt;
&lt;li&gt;Custom in-house agents built directly on MCP SDKs&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Seeing that distribution — with verified identity and datacenter context attached, rather than inferred from strings — changed how we think about which surfaces to test against before a release.&lt;/p&gt;
&lt;h2 id=&quot;production-notes&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#production-notes&quot; aria-label=&quot;production notes permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Production notes&lt;/h2&gt;
&lt;p&gt;Three things worth getting right, all of which we hit:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Fail open, always.&lt;/strong&gt; This is analytics, not authorization. If the API is slow, rate-limited, or unreachable, your MCP server must still serve the request. Log the failure and move on — never let an analytics call decide whether a tool call succeeds.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Handle 429 gracefully.&lt;/strong&gt; Exceeding your rate limit returns &lt;code&gt;429&lt;/code&gt; with a &lt;code&gt;too_many_requests&lt;/code&gt; error code, sometimes with a &lt;code&gt;Retry-After&lt;/code&gt; header. Treat it as an expected condition: log it at the info level, drop that event, and keep serving traffic.&lt;/p&gt;
&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;tsx&quot;&gt;&lt;pre class=&quot;language-tsx&quot;&gt;&lt;code class=&quot;language-tsx&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;try&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token keyword&quot;&gt;const&lt;/span&gt; res &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token keyword&quot;&gt;await&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;analyze&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;req&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
  &lt;span class=&quot;token keyword&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;res&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;status &lt;span class=&quot;token operator&quot;&gt;===&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;429&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; log&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&quot;rate limited, skipping event&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
  &lt;span class=&quot;token keyword&quot;&gt;else&lt;/span&gt; &lt;span class=&quot;token keyword&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;res&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;ok&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;record&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token keyword&quot;&gt;await&lt;/span&gt; res&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;json&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token keyword&quot;&gt;catch&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;err&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  log&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;error&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&quot;automation intelligence failed&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; err&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;token comment&quot;&gt;// never rethrow&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Do the call off the request path.&lt;/strong&gt; Push the payload onto a bounded queue and let a background worker deliver it. A bounded queue that drops under pressure is much better than one that adds latency to every tool call.&lt;/p&gt;
&lt;p&gt;Every event is also retrievable afterward through the Events API by &lt;code&gt;event_id&lt;/code&gt;, or in bulk via &lt;code&gt;/v4/events?source=edge&lt;/code&gt; — so your data warehouse job doesn&apos;t have to depend on your MCP server having captured everything perfectly in real time.&lt;/p&gt;
&lt;h2 id=&quot;how-to-get-started&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#how-to-get-started&quot; aria-label=&quot;how to get started permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;How to get started&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Create a secret API key in your &lt;a href=&quot;https://dashboard.fingerprint.com/api-keys&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Fingerprint dashboard&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;POST your request metadata to &lt;code&gt;https://api.fpjs.io/v4/edge&lt;/code&gt; (or the endpoint for your region).&lt;/li&gt;
&lt;li&gt;Record &lt;code&gt;bot_info&lt;/code&gt; and &lt;code&gt;ip_info&lt;/code&gt; next to your existing MCP telemetry.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The &lt;a href=&quot;https://docs.fingerprint.com/reference/automation-intelligence-api&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Automation Intelligence API&lt;/a&gt; is free during the public preview, and the &lt;a href=&quot;https://docs.fingerprint.com/reference/server-api-edge&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Collect Intelligence endpoint reference&lt;/a&gt; has the full request and response schema. If you want to check coverage for a specific agent, the &lt;a href=&quot;https://docs.fingerprint.com/docs/bot-detection/bot-directory&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Bot Directory&lt;/a&gt; is the place to look.&lt;/p&gt;
&lt;p&gt;MCP made it easy for AI tools to call your services. This makes it easy to know which ones did.&lt;/p&gt;</content:encoded><tags>ai agents, implementation guides</tags></item><item><title><![CDATA[Top 12 device intelligence platforms: 2026 list]]></title><description><![CDATA[This guide lists 2026’s leading device intelligence tools with insights on accuracy, coverage, privacy compliance, and pricing so you can choose the right fit.]]></description><link>/blog/best-device-intelligence-platforms/</link><guid isPermaLink="false">/blog/best-device-intelligence-platforms/</guid><pubDate>Thu, 06 Aug 2026 13:36:00 GMT</pubDate><enclosure url="https://fingerprint.com/static/c5263532271fc5b1b03f8237ae449483/top-device-intelligence-platforms.jpg" length="0" type="image/jpeg"/><content:encoded>&lt;h2 id=&quot;what-is-a-device-intelligence-platform&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#what-is-a-device-intelligence-platform&quot; aria-label=&quot;what is a device intelligence platform permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;What is a device intelligence platform?&lt;/h2&gt;
&lt;p&gt;A device intelligence platform is a SaaS solution that assigns stable visitor IDs across web and mobile devices and analyzes fingerprinting, behavioral, and network signals in real time to detect fraud, bots, VPN use, browser tampering, and other suspicious activity.&lt;/p&gt;
&lt;p&gt;Device intelligence platforms are used by technical teams including engineering, fraud, trust, risk, security, and UX—working at digital businesses who want to detect and prevent fraudulent activity across their web and mobile devices.&lt;/p&gt;
&lt;p&gt;This guide explains what device intelligence is, why static fraud identity check systems, where device fingerprinting stops and broader device intelligence starts, which signals actually help stop modern attacks, how to evaluate platforms, and how twelve leading providers compare so you can choose the right solution for your stack and fraud model.&lt;/p&gt;
&lt;h2 id=&quot;device-intelligence-vs-device-fingerprinting-what-actually-matters&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#device-intelligence-vs-device-fingerprinting-what-actually-matters&quot; aria-label=&quot;device intelligence vs device fingerprinting what actually matters permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Device intelligence vs. device fingerprinting: What actually matters&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://fingerprint.com/blog/device-fingerprinting/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Device fingerprinting&lt;/a&gt; creates a unique device ID by hashing browser or operating system details, such as user-agent strings, installed fonts, and hardware settings. That&apos;s how companies using this technology know whether they&apos;ve seen a certain device before and associate it with one or several accounts.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://fingerprint.com/blog/device-intelligence/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Device intelligence&lt;/a&gt; goes further. On top of the device ID, it layers in behavioral and network signals that highlight network anomalies, emulator usage, automation frameworks, and other potentially risky signals to fraud and risk teams. By layering device intelligence on top of device fingerprinting, businesses get deeper risk analysis, fewer false positives, and the ability to spot sophisticated attack vectors in real time. Some services even can distinguish between good bots and AI agents (like search engine crawlers) and bad ones.&lt;/p&gt;
&lt;h2 id=&quot;the-problem-device-intelligence-solves-post-kyc-fraud-and-why-static-identity-checks-fail&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#the-problem-device-intelligence-solves-post-kyc-fraud-and-why-static-identity-checks-fail&quot; aria-label=&quot;the problem device intelligence solves post kyc fraud and why static identity checks fail permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;The problem device intelligence solves: Post-KYC fraud and why static identity checks fail&lt;/h2&gt;
&lt;p&gt;In 2025, consumers reported more than $16 billion in fraud losses overall, &lt;a href=&quot;https://www.ftc.gov/news-events/news/press-releases/2026/06/ftc-data-show-people-reported-losing-3-point-5-billion-imposter-scams-2025&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;according to the FTC&lt;/a&gt;, with the real loss probably several times higher than this figure. Many of these schemes exploit accounts after signup and authorization checks, with &lt;a href=&quot;https://fingerprint.com/blog/identity-verification-fraud-prevention/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;82% of fraud happening post–identity verification&lt;/a&gt;, making device intelligence increasingly important for fintech, e-commerce, gaming, SaaS, media, marketplace, and other digital businesses that need to reduce risk without adding user friction.&lt;/p&gt;
&lt;p&gt;Single-point-in-time onboarding checks — like &lt;a href=&quot;https://fingerprint.com/blog/kyc-know-your-customer-financial-fraud/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Know-Your-Customer (KYC) verification&lt;/a&gt; and ID document scans — aren&apos;t effective in preventing future fraud attempts. In fact, fraudsters make a point of breaking into verified accounts, either through phishing or buying data on the dark web. Once they&apos;re in, they use emulators, app cloners, and bots to hijack accounts, drain funds, and milk promotions.&lt;/p&gt;
&lt;p&gt;Fraudsters may also focus on methods designed to bypass weak device identification capabilities, such as &lt;a href=&quot;https://fingerprint.com/blog/sim-swap-attack/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;SIM swapping&lt;/a&gt;, &lt;a href=&quot;https://fingerprint.com/blog/vpn-detection-how-it-works/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;VPN and proxy use&lt;/a&gt;, and IP changes. Device intelligence changes the game by spotting these anomalies in real time.&lt;/p&gt;
&lt;p&gt;Device intelligence picks up where static fraud controls like KYC checks leave off: monitoring every session and transaction in real time, and flagging suspicious behavior as soon as it pops up.&lt;/p&gt;
&lt;p&gt;Persistent device identification can translate to fewer chargebacks, less promo abuse, and measurable bottom-line gains.&lt;/p&gt;
&lt;h2 id=&quot;the-signals-that-actually-stop-modern-attacks&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#the-signals-that-actually-stop-modern-attacks&quot; aria-label=&quot;the signals that actually stop modern attacks permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;The signals that actually stop modern attacks&lt;/h2&gt;
&lt;p&gt;Strong device intelligence platforms don&apos;t just look for obvious red flags. They combine hundreds of technical signals, and some use machine learning to identify unusual device behavior, to expose fraud patterns, without collecting personally identifiable information (PII). Here are some of the essential signals a good solution should provide:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Browser entropy values:&lt;/strong&gt; Helps detect spoofed environments or cloned browsers trying to blend in.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Time-zone/IP mismatch:&lt;/strong&gt; Flags when a device&apos;s system time doesn&apos;t match its IP location or related IP addresses, a classic sign of fraudsters trying to cloak their true location through virtual private networks (VPNs) or proxies; some vendors also analyze over 65,000 parameters for VPN detection.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Emulator or virtual machine artifacts:&lt;/strong&gt; Spots devices running in virtual environments, as opposed to normal phones or computers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Sensor spoofing (GPS, gyro):&lt;/strong&gt; Uncovers fake or manipulated sensor data, often used to fake location or device movement.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Automation frameworks (Selenium, Puppeteer):&lt;/strong&gt; Reveals scripted bot flows attempting to automate fraud at scale.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Behavioral biometrics:&lt;/strong&gt; Measures user interactions to identify behavioral patterns that can reveal suspicious activity.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;All of these signals rely on technical device metrics only, which have nothing to do with the user&apos;s identity, so privacy is preserved while fraudsters are exposed.&lt;/p&gt;
&lt;p&gt;Note: Some device intelligence providers do link personal info with unique devices, a technique that leads to higher confidence in identification accuracy but also introduces regulatory issues &lt;a href=&quot;https://docs.fingerprint.com/docs/privacy-and-compliance&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;around privacy&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;important-considerations-when-evaluating-device-intelligence-platforms&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#important-considerations-when-evaluating-device-intelligence-platforms&quot; aria-label=&quot;important considerations when evaluating device intelligence platforms permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Important considerations when evaluating device intelligence platforms&lt;/h2&gt;
&lt;h3 id=&quot;accuracy-and-false-positive-rates&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#accuracy-and-false-positive-rates&quot; aria-label=&quot;accuracy and false positive rates permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Accuracy and false-positive rates&lt;/h3&gt;
&lt;p&gt;Top performers deliver high accuracy with low false-positive rates, helping reduce mistaken blocks for legitimate users. That means real-time risk scoring can reduce friction for low-risk sessions, which translates to smoother onboarding and less lost revenue. Platforms with higher false positives risk turning away legitimate customers, which hurts conversion and trust. That said, true accuracy is notoriously difficult to calculate, so be skeptical of precise claims.&lt;/p&gt;
&lt;h3 id=&quot;integration-time-and-developer-effort&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#integration-time-and-developer-effort&quot; aria-label=&quot;integration time and developer effort permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Integration time and developer effort&lt;/h3&gt;
&lt;p&gt;Integration times vary by platform and implementation scope. Lightweight SDKs can enable quick initial rollouts, while production deployments may offer deeper integration at the cost of bulkier implementation and maintenance. The best solutions support seamless integration through both client- and server-side techniques for more secure risk analysis.&lt;/p&gt;
&lt;h3 id=&quot;privacy-compliance-and-data-handling&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#privacy-compliance-and-data-handling&quot; aria-label=&quot;privacy compliance and data handling permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Privacy compliance and data handling&lt;/h3&gt;
&lt;p&gt;All vendors listed claim GDPR and CCPA compliance, though it&apos;s up to the customer to use device intelligence in a compliant way. Some platforms, like Fingerprint and JuicyScore, offer in-region data storage. If a vendor relies on third-party data enrichment or links to PII, double-check compliance, especially in sensitive markets.&lt;/p&gt;
&lt;h2 id=&quot;the-top-device-intelligence-platforms-for-fraud-prevention&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#the-top-device-intelligence-platforms-for-fraud-prevention&quot; aria-label=&quot;the top device intelligence platforms for fraud prevention permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;The top device intelligence platforms for fraud prevention&lt;/h2&gt;
&lt;h3 id=&quot;fingerprint&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#fingerprint&quot; aria-label=&quot;fingerprint permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Fingerprint&lt;/h3&gt;
&lt;p&gt;Fingerprint offers highly accurate browser and device identification to provide a stable device identifier. It uses 100+ signals, including hardware attributes such as screen resolution and hardware configuration, to assign each visitor a unique, persistent visitor ID. The platform also provides &lt;a href=&quot;https://fingerprint.com/products/smart-signals/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;20+ Smart Signals&lt;/a&gt;, including Bot Detection, VPN Detection, Incognito Detection for private browsing modes, Emulator and Virtual Machine Detection, Developer Tools Detection, Geolocation Spoofing Detection, and more.&lt;/p&gt;
&lt;p&gt;Fingerprint&apos;s lightweight SDK can be integrated quickly, delivers low-latency results, and supports server-side analysis and identification retrieval for enhanced security.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Strengths:&lt;/strong&gt; Fast deployment, industry-leading accuracy and highly persistent visitor ID, broad signals coverage, flexible and rapid integration&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Industries:&lt;/strong&gt; Fintech, banking and financial services, online marketplaces, gaming and gambling, e-commerce, SaaS&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;If you want to see how Fingerprint performs in your environment, &lt;a href=&quot;https://dashboard.fingerprint.com/signup&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;you can try it free and start seeing data in minutes&lt;/a&gt;. You can also &lt;a href=&quot;https://fingerprint.com/contact-sales/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;reach out to our team&lt;/a&gt; for a personalized demo.&lt;/em&gt;&lt;/p&gt;
&lt;h3 id=&quot;sumsub&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#sumsub&quot; aria-label=&quot;sumsub permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Sumsub&lt;/h3&gt;
&lt;p&gt;Sumsub is an integrated fraud stack that supports the entire customer journey, from sign up and KYC/KYB onboarding ID verification to ongoing monitoring, including transaction monitoring and device intelligence powered by the Fingerprint platform.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Strengths:&lt;/strong&gt; Verification throughout the account lifecycle, device behavioral analysis&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Industries:&lt;/strong&gt; Fintech, payment, trading, crypto, igaming, mobility, marketplaces, neobanks&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;seon&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#seon&quot; aria-label=&quot;seon permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;SEON&lt;/h3&gt;
&lt;p&gt;SEON is a compliance platform that incorporates AML screening, case management, and regulatory reporting. It uses a rules engine that combines device fingerprints with other risk signals in its decisioning.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Strengths:&lt;/strong&gt; Aggregated digital risk signals, transparent decisioning&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Industries:&lt;/strong&gt; Fintech, financial services, payments, iGaming, retail&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;shield&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#shield&quot; aria-label=&quot;shield permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;SHIELD&lt;/h3&gt;
&lt;p&gt;SHIELD uses device IDs, device signals, and behavioral signals to detect fraud on mobile devices, analyzing user behaviors and usage patterns to surface suspicious activity. Their clientele is mostly in Asia.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Strengths:&lt;/strong&gt; Behavioral modeling, focus on mobile devices&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Industries:&lt;/strong&gt; Ride hailing, superapps, online delivery, social media, streaming, e-wallets, digital and neobanking, online casinos&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;datavisor&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#datavisor&quot; aria-label=&quot;datavisor permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;DataVisor&lt;/h3&gt;
&lt;p&gt;DataVisor uses unsupervised anomaly detection for fraud detection, applying machine learning-based network analysis to detect anomalies across accounts and devices rather than reviewing a single device in isolation; this helps identify fraud rings, synthetic identities, and the same device appearing across multiple accounts.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Strengths:&lt;/strong&gt; ML clustering, flexible orchestration, responsive support&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Industries:&lt;/strong&gt; Banks, credit unions, fintech, digital payments&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;experian-fraudnet&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#experian-fraudnet&quot; aria-label=&quot;experian fraudnet permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Experian FraudNet&lt;/h3&gt;
&lt;p&gt;FraudNet is a risk engine that turns device intelligence into device risk scoring. It uses real time signals and real time data to trigger step-up authentication for high risk devices.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Strengths:&lt;/strong&gt; Third-party data enrichment, KYC integration, edit rules within UI&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Industries:&lt;/strong&gt; Advertising &amp;#x26; media, automotive, energy &amp;#x26; utilities, financial services, healthcare, insurance, mortgage, public sector, rental property solutions, telecommunications&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;juicyscore&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#juicyscore&quot; aria-label=&quot;juicyscore permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;JuicyScore&lt;/h3&gt;
&lt;p&gt;JuicyScore focuses on privacy-centric, adaptive scoring that uses device data and behavior signals to tailor risk decisions and reduce false positives, especially in markets with lighter regulatory regimes.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Strengths:&lt;/strong&gt; Emerging market coverage, privacy-first design, device-based account risk profiling&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Industries:&lt;/strong&gt; Financial institutions, e-commerce, insurance, travel&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;kount&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#kount&quot; aria-label=&quot;kount permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Kount&lt;/h3&gt;
&lt;p&gt;Kount is a trust and safety solution focused on payment fraud that uses device intelligence as one input into fraud detection and risk scoring, with those signals also helping inform multi-factor authentication decisions for riskier sessions.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Strengths:&lt;/strong&gt; AI scoring, chargeback defense, direct link to Equifax&apos;s credit and identity data&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Industries:&lt;/strong&gt; Retail, marketplaces, digital goods, financial services&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;ibm-trusteer&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#ibm-trusteer&quot; aria-label=&quot;ibm trusteer permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;IBM Trusteer&lt;/h3&gt;
&lt;p&gt;IBM Trusteer protects banks from many forms of attacks with a cross-institution reputation network that strengthens digital identity analysis and helps stop fraud through shared signals, while evaluating one device within a broader reputation network and supporting multiple endpoint deployment options.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Strengths:&lt;/strong&gt; Behavioral biometrics based on user interactions and transaction history, malware checks, emphasis on persistence&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Industries:&lt;/strong&gt; Financial institutions&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;sardine&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#sardine&quot; aria-label=&quot;sardine permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Sardine&lt;/h3&gt;
&lt;p&gt;Primarily serving fintechs, Sardine is designed to stop fraud with device intelligence as one input, and its key benefits include broader fraud insights, with device intelligence use cases spanning banking and payments workflows.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Strengths:&lt;/strong&gt; Responsive support, tight focus on banking/payments, AI-based risk process automation&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Industries:&lt;/strong&gt; Crypto, fintech, neobanks, retail&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;arkose-labs&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#arkose-labs&quot; aria-label=&quot;arkose labs permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Arkose Labs&lt;/h3&gt;
&lt;p&gt;Oriented toward defending large companies, especially digital platforms, from scaled fraud, automated abuse, account creation attacks, and sign-up abuse, with a proprietary CAPTCHA-like challenge that helps identify virtual machines used in automated attacks&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Strengths:&lt;/strong&gt; Bot detection, anti-scraping protections for platform content, Security Operations Center for 24/7 coordination&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Industries:&lt;/strong&gt; Gaming, fintech, marketplaces&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;incognia&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#incognia&quot; aria-label=&quot;incognia permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Incognia&lt;/h3&gt;
&lt;p&gt;Focused on user identity challenges specific to gig economy and peer-to-peer apps, and Incognia builds a persistent device identity from device behavior over time.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Strengths:&lt;/strong&gt; Persistent device ID, assured identity tied to individual user, a unique device identifier for individual devices, and resilience across factory resets&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Industries:&lt;/strong&gt; Food delivery, P2P marketplaces, ride sharing&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Disclaimer: This article is based on publicly available information from official company websites and reputable third-party sources as of the time of writing. Product features, pricing models, and capabilities may change over time. Readers should verify details directly with each vendor before making business decisions.&lt;/em&gt;&lt;/p&gt;
&lt;h2 id=&quot;choosing-the-right-device-intelligence-solution&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#choosing-the-right-device-intelligence-solution&quot; aria-label=&quot;choosing the right device intelligence solution permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Choosing the right device intelligence solution&lt;/h2&gt;
&lt;h3 id=&quot;match-features-to-your-industry&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#match-features-to-your-industry&quot; aria-label=&quot;match features to your industry permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Match features to your industry&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Fintech:&lt;/strong&gt; Look for account takeover prevention, proxy/VPN identification, and bot detection&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;E-commerce:&lt;/strong&gt; Prioritize distinguishing good and bad bots, long-lasting device IDs, and velocity detection&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;iGaming:&lt;/strong&gt; Must-haves are multi-accounting detection, deep geolocation identification, and emulator detection&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;B2B SaaS:&lt;/strong&gt; Focus on account sharing prevention and device trust indicators&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Different device types can require different controls, and a single device appearing across accounts may indicate coordinated abuse.&lt;/p&gt;
&lt;h2 id=&quot;ready-to-strengthen-your-fraud-defenses&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#ready-to-strengthen-your-fraud-defenses&quot; aria-label=&quot;ready to strengthen your fraud defenses permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Ready to strengthen your fraud defenses?&lt;/h2&gt;
&lt;p&gt;Weigh the strengths and trade-offs for your business, then plan a proof-of-concept to see which device intelligence solution best fits your risk profile and user experience goals.&lt;/p&gt;
&lt;p&gt;Curious how Fingerprint stacks up in your environment? You can &lt;a href=&quot;https://fingerprint.com/contact-sales/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;reach out to our team&lt;/a&gt; or &lt;a href=&quot;https://dashboard.fingerprint.com/signup&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;start a free trial&lt;/a&gt; to experience highly accurate device intelligence and a frictionless user experience.&lt;/p&gt;
&lt;link rel=&quot;stylesheet&quot; href=&quot;/plugins/customizable-cta/customizable-cta.css&quot;&gt;

          &lt;div class=&quot;ctaRoot defaultTheme  withCodeExample&quot;&gt;
            &lt;div class=&quot;ctaContainer&quot;&gt;
              &lt;div&gt;
                &lt;h2&gt;Ready to &lt;strong&gt;solve&lt;/strong&gt; your biggest fraud challenges?&lt;/h2&gt;
&lt;p&gt;Install our &lt;strong&gt;JS agent&lt;/strong&gt; on your website to uniquely identify the browsers that visit it.&lt;/p&gt;

              &lt;/div&gt;
              &lt;div class=&quot;buttonsContainer&quot;&gt;
                &lt;a href=&quot;https://dashboard.fingerprint.com/signup&quot; id=&quot;custom-cta-signup&quot; class=&quot;buttonSignUp&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Start Free Trial&lt;/a&gt;
                
                
              &lt;/div&gt;
            &lt;/div&gt;
            &lt;div class=&quot;demoContainer&quot;&gt;&lt;div class=&quot;codeExample&quot;&gt;&lt;/div&gt;&lt;/div&gt;
          &lt;/div&gt;</content:encoded><tags>anti-fraud technology, fingerprinting</tags></item><item><title><![CDATA[A safer destination: Building stronger fraud controls at ridesharing platforms]]></title><description><![CDATA[Ban evasion, tenant drivers, and referral farming cost ridesharing platforms millions. Learn how device intelligence closes the re-entry gap identity checks miss.]]></description><link>/blog/ride-sharing-fraud/</link><guid isPermaLink="false">/blog/ride-sharing-fraud/</guid><pubDate>Mon, 03 Aug 2026 14:59:00 GMT</pubDate><enclosure url="https://fingerprint.com/static/b1d8a5f5df2191cc0f3b7085757e8d0b/ridesharing-fraud-report-cover.jpg" length="0" type="image/jpeg"/><content:encoded>&lt;p&gt;&lt;em&gt;Fraud, trust, and engineering teams at ridesharing companies have to fight fraud in a way that is structurally different from any other business. You need a unique, two-sided control architecture to prevent threats from two distinct areas: the rider side and the driver side.&lt;/em&gt; &lt;em&gt;Yet the fraud controls in place today may be missing a critical layer...&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;———&lt;/p&gt;
&lt;h2 id=&quot;introduction-two-sided-marketplace-two-sided-fraud&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#introduction-two-sided-marketplace-two-sided-fraud&quot; aria-label=&quot;introduction two sided marketplace two sided fraud permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Introduction: Two-sided marketplace, two-sided fraud&lt;/h2&gt;
&lt;p&gt;Most companies manage fraud from one direction: the customer.&lt;/p&gt;
&lt;p&gt;Ridesharing platforms have to manage it from two: the driver and the rider.&lt;/p&gt;
&lt;p&gt;Each presents distinct challenges, distinct economic incentives for bad actors to exploit, and distinct failure points and impacts to the business when controls don&apos;t work.&lt;/p&gt;
&lt;p&gt;What makes these challenges especially acute is that the two sides are interdependent.&lt;/p&gt;
&lt;p&gt;A fraudulent driver can put riders at risk, harm the platform&apos;s reputation, and impact regulatory standing. A fraudulent rider can reduce driver earnings, distort growth metrics, and bleed revenue from the business.&lt;/p&gt;
&lt;p&gt;Neither side can be addressed in isolation. Both can undermine the company&apos;s ability to gain a foothold and grow in the markets where they want to.&lt;/p&gt;
&lt;p&gt;In this report, we&apos;ll uncover the twin sides of fraud that ridesharing platforms are fighting today, the structural gaps in many current identity architectures, and why device intelligence is the missing layer for teams who want to build a stronger fraud stack at scale.&lt;/p&gt;
&lt;h2 id=&quot;trust-behind-the-wheel-the-three-most-common-types-of-driver-side-fraud&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#trust-behind-the-wheel-the-three-most-common-types-of-driver-side-fraud&quot; aria-label=&quot;trust behind the wheel the three most common types of driver side fraud permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Trust behind the wheel: The three most common types of driver-side fraud&lt;/h2&gt;
&lt;p&gt;The fraud vectors that cause the most operational damage on the driver side break down into three overlapping categories.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Account sharing and tenant drivers&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;In emerging markets with high demand and high growth—like across Eastern Europe, Sub-Saharan Africa, and parts of the Middle East—a verified driver account is itself an asset with monetary value. An individual who has passed onboarding, built up a rating, and achieved preferred status may sell or rent that account to another driver who either could not pass verification or has already been deactivated. This creates &quot;tenant drivers&quot;: individuals operating anonymously behind borrowed credentials. From the platform&apos;s perspective, the account looks legitimate. The behavior looks legitimate. The problem is that the actual person behind the wheel is completely untracked. Their real identity is unknown, their history is invisible, and if something goes wrong, the account holder can claim no knowledge.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Profile rental&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;More damaging still is the use of rented profiles by previously deactivated drivers. Say a driver is removed from the platform for poor ratings, safety violations, or fraudulent activity. This account-level ban is the only control in place. That deactivated driver can then pay another verified account holder to use their profile, re-enter the platform, and continue operating under that assumed profile. The &lt;a href=&quot;https://fingerprint.com/blog/how-to-detect-ban-evasion/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;ban for the individual is meaningless&lt;/a&gt; because it was applied to an account, not a device.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Fake cancellations&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Riders may submit false service complaints, or cancel trips in ways designed to extract credits or refunds, in order to exploit platform dispute mechanisms. Drivers are the ones who the bear the economic and rating consequences, through no fault of their own. In markets where resolutions lean toward the rider by default, this can contribute to a negative driver experience: loss of earnings, frustration, and churn.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;the-re-entry-gap-what-identity-verification-checks-dont-see&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#the-re-entry-gap-what-identity-verification-checks-dont-see&quot; aria-label=&quot;the re entry gap what identity verification checks dont see permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;The re-entry gap: What identity verification checks don&apos;t see&lt;/h2&gt;
&lt;p&gt;Driver-side fraud in ridesharing is not just a problem of verifying identity. It&apos;s a problem of persistence over time.&lt;/p&gt;
&lt;p&gt;Most ridesharing platforms have invested in a strong set of document and identity verification tools, like selfie checks, liveness detection, and document verification.&lt;/p&gt;
&lt;p&gt;The problem with these methods is that they operate at a single point in time.&lt;/p&gt;
&lt;p&gt;Identity verification answers one question: &lt;em&gt;Is this the real person behind this account, right now, at onboarding?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;It does not answer the questions that matter after that moment:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Is the same person operating the account today as the one who passed verification six months ago?&lt;/li&gt;
&lt;li&gt;Has this device been used by a previously banned driver?&lt;/li&gt;
&lt;li&gt;Is the device presenting this new account linked to a pattern of deactivated accounts?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The re-entry cost for a banned driver in a high-fraud market is trivially low. A new SIM card costs less than a dollar in most emerging markets. A fresh email address takes thirty seconds. An app reinstall wipes the local footprint.&lt;/p&gt;
&lt;p&gt;Identity verification was designed to confirm who someone is. It was not designed to tell if someone is acting like someone else.&lt;/p&gt;
&lt;p&gt;&lt;span
      class=&quot;gatsby-resp-image-wrapper&quot;
      style=&quot;position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 766px; max-height: 650px;&quot;
    &gt;
      &lt;span
    class=&quot;gatsby-resp-image-background-image&quot;
    style=&quot;padding-bottom: 51.5%; position: relative; bottom: 0; left: 0; display: block;&quot;
  &gt;&lt;/span&gt;
  &lt;img
        class=&quot;gatsby-resp-image-image&quot;
        alt=&quot;Visual representation of the structural gap highlighting the identity layer&amp;#39;s inability to close the re-entry gap.&quot;
        title=&quot;The structural gap in identity verification&quot;
        src=&quot;/static/45577c01243504dbee61ed5933fcea1a/f7616/rideshare-fraud-the-structural-gap.png&quot;
        srcset=&quot;/static/45577c01243504dbee61ed5933fcea1a/e17e5/rideshare-fraud-the-structural-gap.png 400w,
/static/45577c01243504dbee61ed5933fcea1a/0a47e/rideshare-fraud-the-structural-gap.png 600w,
/static/45577c01243504dbee61ed5933fcea1a/f7616/rideshare-fraud-the-structural-gap.png 766w,
/static/45577c01243504dbee61ed5933fcea1a/c1b63/rideshare-fraud-the-structural-gap.png 1200w&quot;
        sizes=&quot;(max-width: 766px) 100vw, 766px&quot;
        style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;&quot;
        loading=&quot;lazy&quot;
        decoding=&quot;async&quot;
      /&gt;
    &lt;/span&gt;&lt;/p&gt;
&lt;h2 id=&quot;rider-side-fraud-the-referral-and-multi-account-problem&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#rider-side-fraud-the-referral-and-multi-account-problem&quot; aria-label=&quot;rider side fraud the referral and multi account problem permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Rider-side fraud: The referral and multi-account problem&lt;/h2&gt;
&lt;p&gt;If driver-side fraud is about persistent identity evasion, rider-side fraud is about account proliferation. The economic model that powers ridesharing growth—first-trip credits, referral bonuses, promotional discounts for new users—creates a structural incentive for &lt;a href=&quot;https://fingerprint.com/blog/how-to-prevent-multiaccounting-fraud/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;multi-accounting&lt;/a&gt; that email verification alone cannot address.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;How referral fraud works in ridesharing&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Ridesharing referral programs are designed to turn existing riders into growth channels: refer a friend, both parties get credit. The mechanics are straightforward. The fraud is equally straightforward.&lt;/p&gt;
&lt;p&gt;A single fraudster, or a coordinated group, may create dozens of &quot;new&quot; rider accounts using freshly registered email addresses, new phone numbers, and, if necessary, cheap prepaid SIMs.&lt;/p&gt;
&lt;p&gt;Each account receives first-trip credits. Each account can generate a referral payout back to the original account. The fraudster extracts platform credits, real trip value, and referral bonuses. The platform records a spike in &quot;new user&quot; signups and growth metrics that look healthy until the unit economics are examined.&lt;/p&gt;
&lt;p&gt;This is &lt;a href=&quot;https://fingerprint.com/blog/what-is-referral-fraud-prevention-tips/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;referral farming&lt;/a&gt; at scale. It&apos;s the ridesharing equivalent of account cycling, and it&apos;s operationally damaging in ways that go beyond the direct cost of credits paid out.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Why standard controls fail here&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The standard fraud control playbook with email verification, phone number validation, and credit card checks doesn&apos;t work against device-level multi-accounting for a simple reason: A determined fraudster doesn&apos;t reuse those signals.&lt;/p&gt;
&lt;p&gt;What they almost always reuse, because it&apos;s expensive or difficult to change, is the device.&lt;/p&gt;
&lt;p&gt;The same phone running six different email addresses with six different SIM cards will still have the same hardware fingerprint, the same app install history, and the same behavioral patterns across sessions.&lt;/p&gt;
&lt;p&gt;Device intelligence that persists over time can identify this linkage and stop referral farming at the root. Email verification cannot.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The false-positive problem&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Aggressive controls against multi-accounting create a problem that&apos;s the mirror image of the fraud problem: Legitimate new users in the same high-fraud markets get caught in broad-brush rule-based filters.&lt;/p&gt;
&lt;p&gt;A genuine first-time rider in Nairobi or Lagos, signing up on a shared device or from an IP associated with previous fraud attempts, gets blocked. The platform loses a real customer while the fraudster continues operating.&lt;/p&gt;
&lt;p&gt;Precision matters. The goal is not to make account creation harder for everyone. It&apos;s about identifying a specific set of device-level signals that can distinguish a genuine new user from an account cycling operation.&lt;/p&gt;
&lt;p&gt;This level of precision is something that static, IP-based, or email-based checks cannot provide. Device intelligence can.&lt;/p&gt;
&lt;h2 id=&quot;the-compliance-side-doing-your-due-diligence-with-device-intelligence&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#the-compliance-side-doing-your-due-diligence-with-device-intelligence&quot; aria-label=&quot;the compliance side doing your due diligence with device intelligence permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;The compliance side: Doing your due diligence with device intelligence&lt;/h2&gt;
&lt;p&gt;The financial cost of driver fraud is clear (and significant). It can be seen in lost fares, operational overhead, and inflated customer service load.&lt;/p&gt;
&lt;p&gt;But the compliance dimension is where exposure to driver fraud can compound and become existential. Especially for any platform operating across dozens of regulatory jurisdictions.&lt;/p&gt;
&lt;p&gt;In markets with weaker regulatory oversight, ridesharing platforms have become vectors for informal economic activity that regulators classify as money laundering.&lt;/p&gt;
&lt;p&gt;When an operator can use a rented profile to run thousands of dollars in fares through a verified account without that account holder&apos;s knowledge, the platform has inadvertently facilitated a financial crime.&lt;/p&gt;
&lt;p&gt;The account holder is nominally responsible. The platform is operationally responsible.&lt;/p&gt;
&lt;p&gt;In what could be an early signal of a broader regulatory trend across many countries and regions, &lt;a href=&quot;&quot;&gt;Tunisia recently investigated ridesharing activity&lt;/a&gt; to see if unverified operators were using ridesharing platforms to move funds outside formal banking systems.&lt;/p&gt;
&lt;p&gt;As ridesharing matures, regulators in developing markets are beginning to treat platforms as financial infrastructure, not just transportation services.&lt;/p&gt;
&lt;p&gt;The compliance argument for persistent device-level visibility is not that it eliminates fraud. It&apos;s that it constitutes demonstrable due diligence.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The key takeaway:&lt;/strong&gt; A platform that can show it links identities to device-level data—and that it actively detects when a device associated with a banned user attempts re-onboarding—is in a fundamentally different regulatory position than one that relies only on single-point-in-time document checks at onboarding.&lt;/p&gt;
&lt;h2 id=&quot;the-missing-layer-what-device-intelligence-does&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#the-missing-layer-what-device-intelligence-does&quot; aria-label=&quot;the missing layer what device intelligence does permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;The missing layer: What device intelligence does&lt;/h2&gt;
&lt;p&gt;Most fraud controls at ridesharing platforms today operate at the identity layer or the behavior layer. They do not operate at the device layer in a persistent, cross-session way.&lt;/p&gt;
&lt;p&gt;This is exactly the gap that device intelligence fills.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://fingerprint.com/blog/device-intelligence/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Device intelligence&lt;/a&gt; generates a highly accurate identifier that can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Persist across app reinstalls, cache clears, and new account creation&lt;/li&gt;
&lt;li&gt;Survive SIM card changes and email address rotation&lt;/li&gt;
&lt;li&gt;Link new account creation attempts back to a device history (including known suspicious patterns and banned users)&lt;/li&gt;
&lt;li&gt;Be connected to a specific and verified identity, account, or record&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Device intelligence makes it possible to recognize if someone is using a device to emulate or impersonate another identity. The fraudulent linkage is immediately visible.&lt;/p&gt;
&lt;p&gt;For driver-side fraud, this means a deactivated driver&apos;s device can be flagged when it attempts to complete onboarding under a new account—even if everything at the identity layer looks legitimate. The ban follows the device, not just the name.&lt;/p&gt;
&lt;p&gt;For rider-side fraud, this means a device that has already collected first-trip credits or a referral bonus can thwarted when it attempts to do so again under a fresh account. The farming operation is visible before the payout is made, not after.&lt;/p&gt;
&lt;p&gt;The operational value of device-level identification is that it can operate invisibly to legitimate users. There is no additional step in the onboarding flow. There is no extra friction for a genuine new driver or rider. The signal is collected passively, processed server-side, and only surfaced to fraud and product teams as part of their fraud engines and risk scoring models.&lt;/p&gt;
&lt;p&gt;This is the key operational difference from identity verification controls, which are an added step to the onboarding process.&lt;/p&gt;
&lt;p&gt;Device intelligence adds zero friction to the user experience. It adds zero cost to the growth funnel. It inserts a persistent, cross-session layer of detection &lt;em&gt;underneath&lt;/em&gt; the existing identity stack without any UX impact.&lt;/p&gt;
&lt;h2 id=&quot;what-good-looks-like-where-device-intelligence-works-in-practice&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#what-good-looks-like-where-device-intelligence-works-in-practice&quot; aria-label=&quot;what good looks like where device intelligence works in practice permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;What &quot;good&quot; looks like: Where device intelligence works in practice&lt;/h2&gt;
&lt;p&gt;The ridesharing platforms that are ahead of this problem aren&apos;t replacing their identity verification stack. They&apos;re adding a critical layer that connects the dots across the full lifecycle of both drivers and riders.&lt;/p&gt;
&lt;p&gt;Here are a few areas where the architecture looks like in practice:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;At driver onboarding&lt;/strong&gt; &lt;br&gt;
A &lt;a href=&quot;https://fingerprint.com/blog/device-fingerprinting&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;device fingerprint&lt;/a&gt; is captured and linked to the verified identity. If the device has a history on the platform—previous accounts, prior deactivations, fraud flags from other sessions—that context is surfaced immediately. Onboarding continues normally for clean devices. High-risk devices are routed for additional review.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;During active driver sessions&lt;/strong&gt; &lt;br&gt;
Session-level device signals can detect behavioral anomalies. For example, if a driver account starts operating from a device that doesn&apos;t match the registered fingerprint, this could be a signal of account sharing or profile rental. A security challenge, like a re-verification prompt, can be served to ensure the legitimacy of the driver.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;At rider account creation&lt;/strong&gt; &lt;br&gt;
New account creation is compared against the device&apos;s history. A device that has been associated with multiple accounts, previous credit collection, or referral payouts is flagged for review. Genuine new users with clean device histories proceed without any additional friction.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;For referral program integrity&lt;/strong&gt; &lt;br&gt;
Referral payouts can be gated against device-level uniqueness checks, not just account-level uniqueness. The same device generating multiple referral events is detectable even when the accounts involved are all &quot;new&quot; by every identity signal.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;the-business-case-cleaner-metrics-faster-growth&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#the-business-case-cleaner-metrics-faster-growth&quot; aria-label=&quot;the business case cleaner metrics faster growth permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;The business case: Cleaner metrics, faster growth&lt;/h2&gt;
&lt;p&gt;There is a common assumption in fraud and product discussions that tightening fraud controls necessarily means slowing growth. This assumption is wrong.&lt;/p&gt;
&lt;p&gt;The platforms that have added device intelligence to their fraud stack report three outcomes consistently:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Cleaner growth metrics.&lt;/strong&gt; When multi-accounting and referral farming are suppressed, new user numbers may look smaller—but they reflect &lt;em&gt;actual&lt;/em&gt; new users. Customer Acquisition Costs (CAC) becomes more accurate. Cohort retention data becomes meaningful. Marketing attribution works. The growth data is cleaner and clearer.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Higher promotional ROI.&lt;/strong&gt; When first-trip credits and referral bonuses go to real new users, they generate real long-term riders. When they&apos;re being farmed, they generate nothing but wasted cash outflows. Device-level controls ensure the promotional budget is doing what it was designed to do.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reduced driver churn.&lt;/strong&gt; Fake cancellations, dispute manipulation, and rating fraud all contribute to driver dissatisfaction and churn. Suppressing those behaviors through device-level detection improves driver economics, which improves supply reliability, which improves the rider experience. The effects compound.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;the-bottom-line-for-fraud-product-and-engineering-leaders&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#the-bottom-line-for-fraud-product-and-engineering-leaders&quot; aria-label=&quot;the bottom line for fraud product and engineering leaders permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;The bottom line for fraud, product, and engineering leaders&lt;/h2&gt;
&lt;p&gt;The fraud challenge facing ridesharing platforms in 2026 is not a problem of insufficient identity verification. Most platforms have adequate controls at the identity layer.&lt;/p&gt;
&lt;p&gt;The gap is below that layer, at the device level. This is where the re-entry risk vectors exist, where multi-accounting lives, where referral abuse happens.&lt;/p&gt;
&lt;p&gt;Device intelligence doesn&apos;t replace the controls you have in place today. It augments them.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://fingerprint.com/products/fingerprint-pro/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Fingerprint&lt;/a&gt; can close the re-entry gap that account-level bans leave open, and bring visibility to the cross-account risk patterns that identity-layer controls are structurally blind to.&lt;/p&gt;
&lt;p&gt;For ridesharing companies, device intelligence data can strengthen your compliance posture, improve business metrics, and reduce risk exposure for both the driver and rider side of the business.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;If you’d like to see how Fingerprint can strengthen your fraud controls, &lt;a href=&quot;https://fingerprint.com/contact-sales/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;contact our sales team for a personalized demo&lt;/a&gt;.&lt;a href=&quot;https://fingerprint.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related reading:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://fingerprint.com/blog/tutorial-stop-referral-fraud-device-intelligence/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;How to protect your business from referral fraud&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://fingerprint.com/blog/overcoming-fraud-challenges-online-marketplaces/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Overcoming fraud challenges in online marketplaces&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://fingerprint.com/blog/account-creation-fraud/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Account creation fraud: detection and prevention&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><tags>account sharing, new account fraud</tags></item><item><title><![CDATA[Friend or fraud? How social platforms can stop bot-driven attacks without slowing growth]]></title><description><![CDATA[Protect platform integrity and meet regulatory requirements by moving beyond traditional controls to durable, device-level intelligence.]]></description><link>/blog/device-intelligence-for-social-platforms/</link><guid isPermaLink="false">/blog/device-intelligence-for-social-platforms/</guid><pubDate>Mon, 27 Jul 2026 14:38:00 GMT</pubDate><enclosure url="https://fingerprint.com/static/a51c0ed25fb828a1d1836370dbfe19f9/custom-report-how-social-platforms-can-stop-new-account-fraud-without-slowing-growth.png" length="0" type="image/png"/><content:encoded>&lt;p&gt;&lt;strong&gt;&lt;em&gt;Growing social account fraud. The alarming rise in bad bots. Ever-tightening regulations. Here’s what you can do to stay ahead.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&quot;introduction-the-tipping-point&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#introduction-the-tipping-point&quot; aria-label=&quot;introduction the tipping point permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Introduction: The tipping point&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;It’s a good time to be a bot.&lt;/p&gt;
&lt;p&gt;In late May 2026, the internet reached a new, ominous milestone. This event went largely unnoticed by most internet users, but its impact is being felt across the world.&lt;/p&gt;
&lt;p&gt;That&apos;s when internet traffic crossed a symbolic threshold: The share of HTML requests &lt;a href=&quot;https://www.nbcnews.com/tech/tech-news/bot-web-traffic-overtaken-human-web-traffic-data-shows-rcna348522&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;tipped over&lt;/a&gt; from being &lt;em&gt;mostly of human origin&lt;/em&gt; to &lt;em&gt;mostly of bot origin&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;This landmark confirms what we already know: Bot traffic is increasing, and it’s an acute threat to social platforms everywhere.&lt;/p&gt;
&lt;p&gt;Not all bots are bad, though. Yet a significant number are out to steal, disrupt, and destroy. And if you&apos;re on a technical team wrangling this new world of bots, you already know this.&lt;/p&gt;
&lt;p&gt;The real pressing questions today for those teams are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;How can you ensure you&apos;re as prepared as you can be to face malicious bots and their cybercriminal commanders?&lt;/li&gt;
&lt;li&gt;How can you deliver trustworthy experiences for legitimate users, ensure your revenue streams are strong, and build products that comply with ever-more-complex online safety regulations?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;It’s a tall order.&lt;/p&gt;
&lt;p&gt;&lt;span
      class=&quot;gatsby-resp-image-wrapper&quot;
      style=&quot;position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 766px; max-height: 650px;&quot;
    &gt;
      &lt;span
    class=&quot;gatsby-resp-image-background-image&quot;
    style=&quot;padding-bottom: 96.75000000000001%; position: relative; bottom: 0; left: 0; display: block;&quot;
  &gt;&lt;/span&gt;
  &lt;img
        class=&quot;gatsby-resp-image-image&quot;
        alt=&quot;A table displaying various types of bots, including their features and functionalities for comparison.&quot;
        title=&quot;How bots make life difficult for social platforms&quot;
        src=&quot;/static/9c7625158590411c8fc55f35b4e218f5/f7616/snap-report-graphic.png&quot;
        srcset=&quot;/static/9c7625158590411c8fc55f35b4e218f5/e17e5/snap-report-graphic.png 400w,
/static/9c7625158590411c8fc55f35b4e218f5/0a47e/snap-report-graphic.png 600w,
/static/9c7625158590411c8fc55f35b4e218f5/f7616/snap-report-graphic.png 766w,
/static/9c7625158590411c8fc55f35b4e218f5/c1b63/snap-report-graphic.png 1200w&quot;
        sizes=&quot;(max-width: 766px) 100vw, 766px&quot;
        style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;&quot;
        loading=&quot;lazy&quot;
        decoding=&quot;async&quot;
      /&gt;
    &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;This report explores this new reality technical teams at social platforms are facing.&lt;/p&gt;
&lt;p&gt;We&apos;ll cover why new account fraud has evolved into such a tricky challenge in the era of AI. We&apos;ll look at why traditional controls are becoming less effective against organized bot operations.&lt;/p&gt;
&lt;p&gt;And we&apos;ll share some specific ways that persistent device intelligence can help social platforms stop abuse while maintaining the smooth, low-friction experiences that legitimate users expect.&lt;/p&gt;
&lt;h2 id=&quot;the-bot-industrial-complex-is-thriving&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#the-bot-industrial-complex-is-thriving&quot; aria-label=&quot;the bot industrial complex is thriving permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;The bot-industrial complex is thriving&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;There was a time when fake accounts were relatively unsophisticated.&lt;/p&gt;
&lt;p&gt;A single attacker might manually create a handful of profiles using disposable email addresses before eventually being detected and removed.&lt;/p&gt;
&lt;p&gt;That model is long gone.&lt;/p&gt;
&lt;p&gt;Modern fraud operations increasingly resemble professional software businesses. Instead of an individual creating a few fake accounts (&lt;a href=&quot;https://fingerprint.com/blog/how-to-prevent-multiaccounting-fraud/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;multi-accounting&lt;/a&gt;), organized groups build automated pipelines capable of producing thousands of identities across multiple platforms simultaneously. These operations invest in infrastructure designed specifically to imitate legitimate users while avoiding traditional detection techniques.&lt;/p&gt;
&lt;p&gt;A fraudster can generate a new email address in seconds, purchase fresh residential IP addresses, clear browser storage, or create a new browser profile with little effort. It can cost as little as&lt;a href=&quot;https://www.cam.ac.uk/stories/price-bot-army-global-index&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt; $0.10 to obtain SMS verification&lt;/a&gt; for a fake UK social account.&lt;/p&gt;
&lt;p&gt;There are numerous techniques fraudsters can use.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://fingerprint.com/blog/product-update-understand-visitor-behavior-march-2025/#improved-virtual-machine-vm-detection&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Virtual machines&lt;/a&gt;&lt;/strong&gt; allow attackers to operate hundreds of isolated browser environments from a single physical system.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://fingerprint.com/blog/product-update-anti-detect-browser-detection/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Anti-detect browsers&lt;/a&gt;&lt;/strong&gt; deliberately randomize browser characteristics to make each session appear unique.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://fingerprint.com/blog/residential-proxies-explained/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Residential proxy networks&lt;/a&gt;&lt;/strong&gt; rotate connections through millions of consumer IP addresses, making simple IP-based blocking far less effective than it once was.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The results from employing any (or all) of these tactics can be swift and difficult to manage: The fraudsters are running an industrial process for manufacturing identities at scale. Like a game of whack-a-mole, if one account is suspended, another takes its place almost immediately.&lt;/p&gt;
&lt;p&gt;This fundamentally changes the economics of platform abuse. Rather than protecting long-lived accounts, attackers work at massive scale and volume. They expect bot-built accounts to be detected and replaced continuously. And they simply move onto the next.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The bot armies have tooled up and scaled out. And fraud fighters need a new toolset to bolster their defenses.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;For technical teams, the challenge looks very different to what it once was: It&apos;s no longer about identifying a single suspicious account.&lt;/p&gt;
&lt;p&gt;Instead, it&apos;s about recognizing when the thousands of apparently unrelated accounts could &lt;em&gt;originate from the same underlying infrastructure&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;We’re not talking about a few laptops here. Attackers can rapidly generate new bot-based identities at an unprecedented scale—an effort that not long ago was significantly more expensive and operationally complex.&lt;/p&gt;
&lt;p&gt;For platforms balancing growth with safety, this represents an important shift in thinking. And this is where device intelligence becomes increasingly important.&lt;/p&gt;
&lt;p&gt;The goal is to identify the &lt;em&gt;infrastructure&lt;/em&gt; that creates those fraudulent identities.&lt;/p&gt;
&lt;h2 id=&quot;banning-accounts-without-banning-devices-creates-a-revolving-door&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#banning-accounts-without-banning-devices-creates-a-revolving-door&quot; aria-label=&quot;banning accounts without banning devices creates a revolving door permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Banning accounts without banning devices creates a revolving door&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Removing an abusive account isn’t the end of the problem. It may only be the beginning of the next cycle.&lt;/p&gt;
&lt;p&gt;Factory resets, app reinstalls, and changes to browser or device settings can generate new identifiers, giving fraudsters the cover they need to evade detection.&lt;/p&gt;
&lt;p&gt;If a social platform bans an account, it may take seconds for another fake account to appear. This is known as &lt;strong&gt;recidivism&lt;/strong&gt;— the repeated return of previously banned users under new identities.&lt;/p&gt;
&lt;p&gt;Regulators and regulatory frameworks, like the &lt;a href=&quot;https://www.gov.uk/government/publications/online-safety-act-explainer/online-safety-act-explainer&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;UK’s Online Safety Act&lt;/a&gt;, want safeguards that are effective at preventing repeat abuse. These regulators explicitly recognize &lt;strong&gt;device bans&lt;/strong&gt; as a necessary enforcement mechanism.&lt;/p&gt;
&lt;p&gt;In the UK, for example, &lt;a href=&quot;https://www.ofcom.org.uk/online-safety&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Ofcom’s Trust &amp;#x26; Safety&lt;/a&gt; model recommends permanent enforcement measures, including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Account bans&lt;/li&gt;
&lt;li&gt;IP bans&lt;/li&gt;
&lt;li&gt;Device bans&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;But how do you ensure that banned or age-restricted users don’t simply return under a new, false identity?&lt;/p&gt;
&lt;p&gt;Answering this question requires moving device bans to a durable layer of device-level signals that remain effective—even as cookies are reset, settings change, or other evasion techniques are used.&lt;/p&gt;
&lt;p&gt;This is device-level identification. And it is account security taken to a whole new level of sophistication.&lt;/p&gt;
&lt;h2 id=&quot;from-ad-spend-to-attribution-how-bot-traffic-distorts-metrics-and-destroys-growth&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#from-ad-spend-to-attribution-how-bot-traffic-distorts-metrics-and-destroys-growth&quot; aria-label=&quot;from ad spend to attribution how bot traffic distorts metrics and destroys growth permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;From ad spend to attribution: How bot traffic distorts metrics and destroys growth&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The primary victims of bots and fake accounts are user safety and trust. But there are second-order harms.&lt;/p&gt;
&lt;p&gt;As social platforms increasingly rely on advertising revenue, user identity has become just as important for commercial performance as it is for abuse prevention.&lt;/p&gt;
&lt;p&gt;Since the introduction of stricter mobile privacy controls, including Apple’s App Tracking Transparency (IDFA) framework, advertisers have become more dependent on the attribution signals reported by the platforms themselves.&lt;/p&gt;
&lt;p&gt;Campaign performance, return on ad spend (ROAS) and bidding decisions all rely on the assumption that impressions, clicks and conversions reflect genuine human behavior. That assumption becomes harder to defend when legitimate user activity is diluted by bots.&lt;/p&gt;
&lt;p&gt;Non-human sessions can distort engagement metrics and reduce the accuracy of attribution models. Over time, this weakens confidence in campaign reporting and makes it more difficult for advertisers to justify premium CPMs (cost per mille, or thousand clicks) or continued investment. In this scenario, bot activity transforms from a cost and a nuisance to an obstacle to business growth.&lt;/p&gt;
&lt;p&gt;The problem is particularly acute in browser and desktop environments.&lt;/p&gt;
&lt;p&gt;As platforms expand web experiences, they also lose many of the persistent signals available in native mobile apps. Short-lived browser sessions and frequently reset identifiers create blind spots between ad exposure and conversion, making it harder to understand whether a campaign reached a real person or an automated session.&lt;/p&gt;
&lt;p&gt;In our &lt;a href=&quot;https://fingerprint.com/blog/device-intelligence-report-2026/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;2026 Device Intelligence Report&lt;/a&gt;, we found that &lt;strong&gt;96% of detected desktop automation is associated with abuse&lt;/strong&gt;, highlighting how much of today’s threats originate in environments where traditional trust signals are weakest.&lt;/p&gt;
&lt;p&gt;The revenue-driving importance of these underlying signals is clear to see. In their year-end fiscal report for 2025, Snap reported 89% year-over-year growth in revenue from In-App Optimizations. This demonstrates how increasingly sophisticated advertising products depend on accurate user identification and trustworthy behavioral data.&lt;/p&gt;
&lt;p&gt;The fact is: Poor identity signals affect the experience (and ROI) these platforms can unlock for their legitimate users.&lt;/p&gt;
&lt;p&gt;When platforms cannot confidently distinguish trusted users from abusive ones, enforcement becomes a wild guess. False positives can lock genuine users out of their accounts, interrupt access to paid services, and create unnecessary friction. And false negatives allow automated abuse to continue unchecked.&lt;/p&gt;
&lt;p&gt;If a platform can’t reliably distinguish a human session from an automated one, it cannot provide the quality of measurement, attribution, or user experience that advertisers and legitimate users want and need.&lt;/p&gt;
&lt;h2 id=&quot;existing-device-protections-dont-always-stop-determined-ban-evasion&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#existing-device-protections-dont-always-stop-determined-ban-evasion&quot; aria-label=&quot;existing device protections dont always stop determined ban evasion permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Existing device protections don’t always stop determined ban evasion&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Most Trust &amp;#x26; Safety stacks already include a mature set of fraud controls.&lt;/p&gt;
&lt;p&gt;Behavioral analytics, CAPTCHA, multi-factor authentication (MFA), credential validation, IP reputation, VPN detection, and device-based protections all play an important role in reducing abuse.&lt;/p&gt;
&lt;p&gt;If you’re expecting to hear us say these are outdated and ineffective, you won&apos;t. They do work. It&apos;s just that they were designed to solve different problems than the most pressing ones today.&lt;/p&gt;
&lt;p&gt;And determined attackers continue to find ways around them.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The big difference is not detection, but persistence.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Modern social platforms already use device signals to help detect abuse and enforce device-level actions. But determined attackers can break that link by resetting devices, spoofing identifiers, clearing local data, rotating networks, or combining multiple evasion techniques.&lt;/p&gt;
&lt;p&gt;This means that even modern device-level protections have big holes in their effectiveness. A device that has previously been associated with abuse may later appear to be new, allowing operators to return with fresh accounts.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://fingerprint.com/products/fingerprint-pro/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Persistent device intelligence&lt;/a&gt; addresses this blind spot by adding an identity layer beneath accounts, sessions, and network attributes. It doesn’t replace existing Trust &amp;#x26; Safety controls—it layers up on top, strengthening them by recognizing returning devices even when:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Cookies have been cleared&lt;/li&gt;
&lt;li&gt;Credentials have changed&lt;/li&gt;
&lt;li&gt;Network characteristics have rotated&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The outcome is that platforms can connect activities that would otherwise appear unrelated and identify repeat abuse before it becomes another cycle of account creation.&lt;/p&gt;
&lt;h2 id=&quot;persistent-device-intelligence-how-fingerprint-takes-protection-to-the-next-level&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#persistent-device-intelligence-how-fingerprint-takes-protection-to-the-next-level&quot; aria-label=&quot;persistent device intelligence how fingerprint takes protection to the next level permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Persistent device intelligence: How Fingerprint takes protection to the next level&lt;/h2&gt;
&lt;p&gt;The fact is no single control can stop every form of account abuse. The success of Trust &amp;#x26; Safety programs rests on layered defenses, with each control addressing a different stage of the attack lifecycle.&lt;/p&gt;
&lt;p&gt;Yes, email and phone verification help raise the cost of mass account creation. And, yes, CAPTCHA can deter basic types of bot activity and automated abuse. Rate limiting, behavioral analytics, and IP intelligence all add valuable signals that help identify suspicious activity.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;But determined attackers have adapted to these controls.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Disposable email addresses, residential proxies, anti-detect browsers, and automated account creation pipelines allow fraudulent activity to bypass many traditional account- and network-level defenses.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;This is where persistent device intelligence provides an additional layer of protection.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Fingerprint identifies the device behind an interaction, creating an identity signal that keeps working even as attackers rotate emails, clear cookies, or change network connections. Used alongside existing fraud controls, Fingerprint enables platforms to recognize returning devices and identify repeat offenders before abuse can expand.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Fingerprint also extends protection beyond exact device matching through &lt;a href=&quot;https://fingerprint.com/blog/product-update-proximity-detection/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;proximity detection&lt;/a&gt;.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Instead of looking only for an identical device, it can recognize hardware that is highly similar to devices previously associated with abuse.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Proximity detection&lt;/li&gt;
&lt;li&gt;Persistent visitor/device identification&lt;/li&gt;
&lt;li&gt;Smart Signals (VPN, VM, tampering, bot detection, etc.)&lt;/li&gt;
&lt;li&gt;Device reputation over time&lt;/li&gt;
&lt;li&gt;Continuous risk assessment&lt;/li&gt;
&lt;li&gt;Stable identity across sessions&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This closes an important gap that account-based controls cannot address, allowing platforms to link related activity that would otherwise appear unrelated.&lt;/p&gt;
&lt;p&gt;&lt;span
      class=&quot;gatsby-resp-image-wrapper&quot;
      style=&quot;position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 766px; max-height: 650px;&quot;
    &gt;
      &lt;span
    class=&quot;gatsby-resp-image-background-image&quot;
    style=&quot;padding-bottom: 58.75%; position: relative; bottom: 0; left: 0; display: block;&quot;
  &gt;&lt;/span&gt;
  &lt;img
        class=&quot;gatsby-resp-image-image&quot;
        alt=&quot;A diagram illustrating the differences in device intelligence for fraud prevention as compared to standard and legacy approaches.&quot;
        title=&quot;The persistent device intelligence difference&quot;
        src=&quot;/static/7846cecc4e3b8e83a33f01bac188f3d8/f7616/snap-report-graphic-2.png&quot;
        srcset=&quot;/static/7846cecc4e3b8e83a33f01bac188f3d8/e17e5/snap-report-graphic-2.png 400w,
/static/7846cecc4e3b8e83a33f01bac188f3d8/0a47e/snap-report-graphic-2.png 600w,
/static/7846cecc4e3b8e83a33f01bac188f3d8/f7616/snap-report-graphic-2.png 766w,
/static/7846cecc4e3b8e83a33f01bac188f3d8/42b11/snap-report-graphic-2.png 2364w&quot;
        sizes=&quot;(max-width: 766px) 100vw, 766px&quot;
        style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;&quot;
        loading=&quot;lazy&quot;
        decoding=&quot;async&quot;
      /&gt;
    &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;What you get is a stronger foundation for your Trust &amp;#x26; Safety program.&lt;/p&gt;
&lt;p&gt;By adding a persistent device layer beneath existing controls, platforms can reduce recidivism, improve the quality of enforcement decisions, strengthen advertiser confidence, and provide a safer experience for legitimate users. And this happens all while making industrialized account abuse significantly more difficult and expensive to sustain for attackers.&lt;/p&gt;
&lt;p&gt;It’s a win for your users and your compliance team. And it’s a big win in the fight against malicious bots.&lt;/p&gt;
&lt;p&gt;——&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;Want a closer look at device intelligence in action?&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Fingerprint can help strengthen your existing Trust &amp;#x26; Safety stack by detecting sophisticated bot activity and stopping repeat offenders before abuse can scale.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;a href=&quot;https://fingerprint.com/contact-sales/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Book a tailored demo&lt;/a&gt; and see how we can help your team.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;</content:encoded><tags>fingerprinting, bot attacks</tags></item><item><title><![CDATA[Frictionless by design, fragmented by default: The hidden costs of siloed identity in fintech]]></title><description><![CDATA[Explore the structural challenges multi-product fintech platforms face due to fragmented identity. See how device intelligence can unify identity, reduce fraud losses, and streamline compliance without adding friction to the user journey.]]></description><link>/blog/device-intelligence-for-fintech/</link><guid isPermaLink="false">/blog/device-intelligence-for-fintech/</guid><pubDate>Fri, 17 Jul 2026 11:33:00 GMT</pubDate><enclosure url="https://fingerprint.com/static/c370676634e6f92875924b0faca97cc6/block-report.png" length="0" type="image/png"/><content:encoded>&lt;h2 id=&quot;introduction&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#introduction&quot; aria-label=&quot;introduction permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Introduction&lt;/h2&gt;
&lt;p&gt;The draw for consumers to banking services at modern fintech companies is clear: Open an account quickly, get approved at checkout in seconds, and move money instantly. All digital. &lt;/p&gt;
&lt;p&gt;And the shift in consumer behavior exemplifies that this draw is working: Digital-first platforms and financial technology companies &lt;a href=&quot;https://www.forbes.com/sites/ronshevlin/2025/01/06/why-fintechs-are-beating-the-banks-in-new-checking-accounts/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;secured approximately 44% of new account openings in 2024&lt;/a&gt;. In comparison, the combined market share of traditional megabanks and regional institutions &lt;a href=&quot;https://www.forbes.com/sites/ronshevlin/2025/01/06/why-fintechs-are-beating-the-banks-in-new-checking-accounts/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;barely reached 43%&lt;/a&gt;.&lt;a href=&quot;https://www.forbes.com/sites/ronshevlin/2025/01/06/why-fintechs-are-beating-the-banks-in-new-checking-accounts/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;However, as these fintech disruptors continue to build for speed and scale—and continue to integrate more customer-first products under their umbrella—there is a structural problem occurring. &lt;/p&gt;
&lt;p&gt;The problem is fragmented identity. And for multi-product fintechs, this problem is costing real dollars. &lt;/p&gt;
&lt;p&gt;&lt;span
      class=&quot;gatsby-resp-image-wrapper&quot;
      style=&quot;position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 766px; max-height: 650px;&quot;
    &gt;
      &lt;span
    class=&quot;gatsby-resp-image-background-image&quot;
    style=&quot;padding-bottom: 50.24999999999999%; position: relative; bottom: 0; left: 0; display: block;&quot;
  &gt;&lt;/span&gt;
  &lt;img
        class=&quot;gatsby-resp-image-image&quot;
        alt=&quot;Bar graph illustrating the percentage of new checking accounts opened by various types of financial institutions.&quot;
        title=&quot;New checking accounts opened by institution&quot;
        src=&quot;/static/364d5c3914bd6d592f6f7d4457af0faa/f7616/report.png&quot;
        srcset=&quot;/static/364d5c3914bd6d592f6f7d4457af0faa/e17e5/report.png 400w,
/static/364d5c3914bd6d592f6f7d4457af0faa/0a47e/report.png 600w,
/static/364d5c3914bd6d592f6f7d4457af0faa/f7616/report.png 766w,
/static/364d5c3914bd6d592f6f7d4457af0faa/c1b63/report.png 1200w&quot;
        sizes=&quot;(max-width: 766px) 100vw, 766px&quot;
        style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;&quot;
        loading=&quot;lazy&quot;
        decoding=&quot;async&quot;
      /&gt;
    &lt;/span&gt;&lt;/p&gt;
&lt;h2 id=&quot;the-fintech-paradox-more-products-less-visibility&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#the-fintech-paradox-more-products-less-visibility&quot; aria-label=&quot;the fintech paradox more products less visibility permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;The fintech paradox: More products, less visibility&lt;/h2&gt;
&lt;p&gt;Fintech platforms process billions of transactions across multiple financial functions, including activities like payments, Buy Now Pay Later (BNPL), and stock trading. Yet they often cannot answer a simple question about visitors across their products: “Is this the same person?”&lt;/p&gt;
&lt;p&gt;Every product team evaluates visitors, customers, and risk on its own terms—with little to no shared data across the other products on their platform. &lt;/p&gt;
&lt;p&gt;The result is a clear paradox. The more products a platform adds to enhance the customer experience, the wider the gap grows between what they know about their customers across the entire platform.&lt;/p&gt;
&lt;p&gt;A customer trusted across years of payment history becomes unrecognizable the moment they move to another financial product, hindering that returning user experience and making it easier for fraudsters to exploit. &lt;/p&gt;
&lt;p&gt;For example, someone who’s been making P2P payments in one product, or on-time installment payments in a BNPL product, moves to a different financial service under the same umbrella company because they want to take out a SMB loan. They are treated as a fully new customer and have to restart.&lt;/p&gt;
&lt;p&gt;Unfortunately, this is not a data quality or KYC (Know Your Customer) problem. It is a problem that happens when trust is evaluated independently per product with no continuity among them. &lt;/p&gt;
&lt;p&gt;The forces that created this problem were actually acting entirely rational. Acquisitions brought incompatible identity stacks. Product teams were measured on vertical metrics with no horizontal ownership across the entire infrastructure. And as AI reshapes workflows and how teams manage their fraud defense, the problem is compounded.&lt;/p&gt;
&lt;p&gt;More static rules are added to compensate in an attempt to boost detections—but these only create more friction for users and increase false positives, further deepening fragmentation rather than resolving it.&lt;/p&gt;
&lt;h2 id=&quot;trust-does-not-travel&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#trust-does-not-travel&quot; aria-label=&quot;trust does not travel permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Trust does not travel&lt;/h2&gt;
&lt;p&gt;When a customer applies for a loan on a fintech platform, where they have been a deposits customer for years, the lending product asks, “Does this applicant qualify right now?”&lt;/p&gt;
&lt;p&gt;They pull a credit file, run a verification check, and evaluate the application in isolation. The customer’s years of history from the deposits product do not enter any trust decisions for the loan. They live in a different silo and are evaluated by a different team. &lt;/p&gt;
&lt;p&gt;While this form of fragmented identity hurts legitimate customers, the checks in place are not the problem. The problem is that their fundamental design only evaluates at a point-in-time, not the person the platform already knows. &lt;/p&gt;
&lt;p&gt;The hidden costs of this negative user experience start to compound. Customer churn, lost cross-sell opportunities, and unnecessary step-up challenges are all a result of the fragmented identity architecture in place. &lt;/p&gt;
&lt;p&gt;Instead of asking, “Does this applicant qualify right now,” the individual products &lt;em&gt;should&lt;/em&gt; be asking, “What do we already know about this applicant?”&lt;/p&gt;
&lt;p&gt;A continuous device intelligence layer enables this. It operates entirely behind the scenes, invisible to the customer, generating a stable identifier that can persist across sessions, across products—even through spoofing and evasion attempts, privacy changes, and evolving fraud tactics.&lt;/p&gt;
&lt;h2 id=&quot;continuous-device-intelligence-as-the-missing-layer&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#continuous-device-intelligence-as-the-missing-layer&quot; aria-label=&quot;continuous device intelligence as the missing layer permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Continuous device intelligence as the missing layer&lt;/h2&gt;
&lt;p&gt;Though legitimate trust does not travel, fragmented identity visibility lets fraud do exactly that. Fraud does not stay in one place. It moves. An account that looked clean at approval could be a mule account moving money or defaulting on BNPL loans by day thirty. &lt;/p&gt;
&lt;p&gt;This is why device intelligence signals are so valuable to fintechs right at onboarding. They are one of the few tools that can catch fraud before it moves. Device spoofing, emulator farms, and fraud rings that pass automated ID verification are all detectable at the device layer without adding a single step to the customer journey. &lt;/p&gt;
&lt;p&gt;For a legitimate customer, the result is frictionless onboarding. For fintechs, the same layer can reveal whether seven new accounts opened in one day all came from the same device, stopping fraud before it moves downstream. &lt;/p&gt;
&lt;p&gt;Here is what it can look like in practice for a legitimate customer: A trustworthy user attempts to open a new loan account. Device intelligence returns various signals: No association with previously flagged IPs, no overlap with fraud infrastructure or tampering present, and minimal activity. As a result, the risk score stays low, additional checks and manual review do not fire, and the customer moves through the onboarding journey without friction.&lt;/p&gt;
&lt;p&gt;Now look at a bad actor moving through a BNPL flow without device intelligence in place: Take a fraudster who finds a real Social Security number with no credit history. They attach a fabricated name and address, build up payment history over time, and construct a credit file. Now they have a record. They apply for multiple BNPL installment loans (which all happens at every checkout in seconds)—the data matches, the check passes, they get approved and secure (fraudulent) funds. &lt;/p&gt;
&lt;p&gt;Without device intelligence, the fraudster has been able to seamlessly complete all transactions with nothing connecting the malicious activity. With device intelligence, the same visitor identifier would have linked all the installment loans across all the checkouts and could have stopped the transactions before they completed.&lt;/p&gt;
&lt;p&gt;The increasing use of generative AI and automation is only amplifying the problem by making exploitation scalable. Synthetic identities get deployed across multiple account types, AI-generated documents pass systems and get re-used, and emulator farms simulate thousands of &quot;unique&quot; users to open new accounts with signup bonuses again and again.&lt;/p&gt;
&lt;p&gt;For all points in the customer journey—account origination, transactions, payments, and investing—a persistent device intelligence layer is the link that connects not only trustworthy behavior, but also suspicious, high-risk behavior.&lt;/p&gt;
&lt;p&gt;&lt;span
      class=&quot;gatsby-resp-image-wrapper&quot;
      style=&quot;position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 766px; max-height: 650px;&quot;
    &gt;
      &lt;span
    class=&quot;gatsby-resp-image-background-image&quot;
    style=&quot;padding-bottom: 38.5%; position: relative; bottom: 0; left: 0; display: block;&quot;
  &gt;&lt;/span&gt;
  &lt;img
        class=&quot;gatsby-resp-image-image&quot;
        alt=&quot;Diagram illustrating the steps of fraud throughout the customer journey, highlighting key stages and vulnerability points..&quot;
        title=&quot;Fraud across the full customer journey&quot;
        src=&quot;/static/e158c3ad93775925ca30d90c471056c1/f7616/fraud-across-customer-journey.png&quot;
        srcset=&quot;/static/e158c3ad93775925ca30d90c471056c1/e17e5/fraud-across-customer-journey.png 400w,
/static/e158c3ad93775925ca30d90c471056c1/0a47e/fraud-across-customer-journey.png 600w,
/static/e158c3ad93775925ca30d90c471056c1/f7616/fraud-across-customer-journey.png 766w,
/static/e158c3ad93775925ca30d90c471056c1/c1b63/fraud-across-customer-journey.png 1200w&quot;
        sizes=&quot;(max-width: 766px) 100vw, 766px&quot;
        style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;&quot;
        loading=&quot;lazy&quot;
        decoding=&quot;async&quot;
      /&gt;
    &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;For lean fraud and risk teams, this link lowers manual review needs and dispute-resolution cases downstream.&lt;/p&gt;
&lt;p&gt;For compliance teams, signal data can improve operational efficiency, as well. A layer that provides multiple, discrete signals on a session—or several sessions over time—gives them more in-depth information for analysis, as opposed to one opaque score or a single moment-in-time view.&lt;/p&gt;
&lt;p&gt;This is more valuable evidence, and can provide a clearer audit trail, to directly protect fintechs against large regulatory fees and attrition.&lt;/p&gt;
&lt;h2 id=&quot;the-four-key-benefits-of-unifying-identity-through-device-intelligence&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#the-four-key-benefits-of-unifying-identity-through-device-intelligence&quot; aria-label=&quot;the four key benefits of unifying identity through device intelligence permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;The four key benefits of unifying identity through device intelligence&lt;/h2&gt;
&lt;p&gt;Multi-product fintechs have spent years optimizing individual products to deliver the speed, simplicity, and convenience customers prefer. But optimizing for individual products leaves a big gap at the platform level: identity. Device intelligence is the layer that can connect identity across products, letting trust compound across the entire customer relationship rather than reset at every product boundary.&lt;/p&gt;
&lt;p&gt;Unifying identity through device intelligence can deliver four key benefits: &lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Reduced fraud losses  &lt;/li&gt;
&lt;li&gt;Increased cross-sell conversion&lt;/li&gt;
&lt;li&gt;Lowered compliance overhead&lt;/li&gt;
&lt;li&gt;Reduced operational burden &lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Scaling fintechs with a variety of financial products operating under their umbrella will also benefit with greater visibility of both return customers and fraudulent activity, turning identity fragmentation into an advantage instead of a liability. The ability to catch fraud patterns earlier and link fraudulent activity across accounts and products can continue to add value to the business over time.&lt;/p&gt;
&lt;p&gt;For the product and fraud teams who are already being asked to do more with less, these benefits translate into meaningful returns on their investment in a device intelligence layer. &lt;/p&gt;
&lt;h2 id=&quot;device-intelligence-for-stronger-fraud-defense-in-fintech&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#device-intelligence-for-stronger-fraud-defense-in-fintech&quot; aria-label=&quot;device intelligence for stronger fraud defense in fintech permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Device intelligence for stronger fraud defense in fintech&lt;/h2&gt;
&lt;p&gt;If you’d like to see how Fingerprint can strengthen your fraud defense, &lt;a href=&quot;https://fingerprint.com/contact-sales/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;contact our sales&lt;/a&gt; team for a personalized demo. We can discuss your specific use case and business needs, including the ways device intelligence can help prevent account takeover, origination/onboarding fraud, payments fraud, and loan fraud—without impacting your returning customer experience.&lt;/p&gt;
&lt;p&gt;To dive deeper into topics like fragmented trust, evasive fraud patterns that beat detection, the friction dilemma, and what top-tier fintechs and digital banks are doing to navigate these issues today, watch our on-demand webinar &lt;a href=&quot;https://fingerprint.com/webinar/building-trust-in-digital-finance/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Building Trust in Digital Finance&lt;/a&gt;.&lt;/p&gt;</content:encoded><tags>fintech, buy now pay later</tags></item><item><title><![CDATA[How cross-site tracking actually works (and how to protect yourself)]]></title><description><![CDATA[Cookies, fingerprinting, bounce tracking, and more: how the web follows you across sites, and the realistic steps to protect your privacy.]]></description><link>/blog/cross-site-tracking/</link><guid isPermaLink="false">/blog/cross-site-tracking/</guid><pubDate>Thu, 02 Jul 2026 14:05:00 GMT</pubDate><enclosure url="https://fingerprint.com/static/f594e77198ff8ee07e524eeaaeb13a65/blog_cross-site-tracking.jpg" length="0" type="image/jpeg"/><content:encoded>&lt;h2 id=&quot;what-is-cross-site-tracking&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#what-is-cross-site-tracking&quot; aria-label=&quot;what is cross site tracking permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;What is cross-site tracking?&lt;/h2&gt;
&lt;p&gt;Cross-site tracking is the practice of recognizing the same device across multiple, otherwise unrelated websites by using a shared identifier — turning separate visits into one continuous, linkable trail of behavior.&lt;/p&gt;
&lt;p&gt;Every time you move around the internet, a profile of you is being created. Not by one site, but by dozens of companies you&apos;ve probably never even heard of.&lt;/p&gt;
&lt;p&gt;They&apos;re stitching together a picture of where you&apos;ve been, what you looked at, how long you lingered, and what you almost bought but didn&apos;t. You&apos;ll never interact with most of them directly. You just unknowingly carry their observers around from page to page, like lint on a sweater.&lt;/p&gt;
&lt;p&gt;It&apos;s easy to wave this off. So what if some ad network knows I looked at running shoes? But the data doesn&apos;t stay in the world of advertising, and it doesn&apos;t stay anonymous. It gets bought, sold, merged, and breached.&lt;/p&gt;
&lt;p&gt;The same infrastructure built to target ads has been used to de-anonymize people, &lt;a href=&quot;https://www.lexology.com/library/detail.aspx?g=046c0a3c-ae60-4026-841b-0a32ed8f140f&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;set different prices based on who a retailer thinks you are&lt;/a&gt;, and &lt;a href=&quot;https://www.eff.org/deeplinks/2026/03/targeted-advertising-gives-your-location-government-just-ask-cbp&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;feed government surveillance&lt;/a&gt;. The profile being built as you browse is more durable, more detailed, and more widely shared than the &quot;targeted ads&quot; framing suggests.&lt;/p&gt;
&lt;p&gt;In this post, we&apos;ll dig into the raw materials behind cross-site tracking, the handful of things about you and your device that make persistent identification possible in the first place. Then we&apos;ll get into how those raw materials get assembled into the machinery that follows you around. And then, share some tips and techniques you can use to make yourself harder to follow.&lt;/p&gt;
&lt;p&gt;While total invisibility online is an art form, most of the tools to fight cross-site tracking are within your reach.&lt;/p&gt;
&lt;h2 id=&quot;the-three-building-blocks-of-persistent-identification&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#the-three-building-blocks-of-persistent-identification&quot; aria-label=&quot;the three building blocks of persistent identification permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;The three building blocks of persistent identification&lt;/h2&gt;
&lt;p&gt;Before anyone can follow you around the internet, they need a way to recognize you when you show up. At first, this is just &quot;you,&quot; as in the same browser or device that visited a site, not necessarily your name or any personal information. But that recognition is the foothold. Once a tracker can reliably identify you, it can start attaching everything else it learns to that identifier.&lt;/p&gt;
&lt;p&gt;There are really only three places to find the raw material to recognize you in the first place, and almost every tracking technique boils down to using one or more of them.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Storage.&lt;/strong&gt; A site asks your browser to hold onto a little piece of data, and your browser, being agreeable, does. The next time you show up, that data is still there, and now you&apos;re recognized. Cookies are the famous example, but the same idea shows up in localStorage, &lt;a href=&quot;https://fingerprint.com/blog/firefox-tor-indexeddb-privacy-vulnerability/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;IndexedDB&lt;/a&gt;, and a handful of other browser storage mechanisms. The issue, at least from a tracker&apos;s perspective, is that browser storage is fragile. You can clear it, block it, or browse in a mode that throws it away when you&apos;re done. Storage-based identification only lasts as long as the storage does.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Network.&lt;/strong&gt; Every request your device makes carries your IP address, because the response has to get back to you somehow. That IP is a halfway-decent identifier on its own. It often points to a specific household or, on mobile, follows you around for a while before it changes. It&apos;s not precise, plenty of people can share one, and it shifts over time, but it&apos;s always there, and you can&apos;t simply turn it off the way you can refuse a cookie. To make it stop identifying you, you have to actively route around it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Browser and device attributes.&lt;/strong&gt; To render pages correctly, your browser volunteers a steady stream of details about your setup: which browser and version you&apos;re running, your operating system, screen resolution, time zone, language, installed fonts, and how your specific hardware renders graphics, among many other things. Any one of these is unremarkable and shared by millions of browsers or devices. But stack enough of them together, and the combination starts to get more and more rare, rare enough to pick one browser out of millions. Collecting these attributes and turning them into an identifier is called &lt;a href=&quot;https://fingerprint.com/blog/browser-fingerprinting-techniques/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;browser fingerprinting&lt;/a&gt;, and unlike storage, there&apos;s nothing sitting on your device to delete. The fingerprint is just based on what your browser looks like.&lt;/p&gt;
&lt;p&gt;The thing to know is that these three rarely work alone. Storage, network, and browser attributes each have weak spots, but used together, they cover for each other. Clear your cookies, and a tracker might still recognize your IP. Change your IP, and the fingerprint is still there. Stack all three, and you get something far more durable than any one of them on its own.&lt;/p&gt;
&lt;p&gt;On its own, being recognized as &quot;the same browser that visited last Tuesday&quot; is pretty harmless. Recognition is just a building block, and it has plenty of uses unrelated to surveillance. What can turn it into a privacy nightmare is what gets built on top of it: a profile, assembled from everything attached to you over time, fed by an identifier that doesn&apos;t stay put on one site.&lt;/p&gt;
&lt;p&gt;The same handful of companies have their hooks in thousands of sites at once, which means the &quot;you&quot; they recognize in a news article can be matched to the &quot;you&quot; on a shopping site, a travel booking, or a symptom checker. All while quietly picking up your real name and personal information to go with it.&lt;/p&gt;
&lt;p&gt;So how does information actually get passed from one site to another to build that file? That&apos;s where the real machinery comes in.&lt;/p&gt;
&lt;p&gt;&lt;span
      class=&quot;gatsby-resp-image-wrapper&quot;
      style=&quot;position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 766px; max-height: 650px;&quot;
    &gt;
      &lt;span
    class=&quot;gatsby-resp-image-background-image&quot;
    style=&quot;padding-bottom: 62.75000000000001%; position: relative; bottom: 0; left: 0; display: block;&quot;
  &gt;&lt;/span&gt;
  &lt;img
        class=&quot;gatsby-resp-image-image&quot;
        alt=&quot;Common cross-site tracking techniques&quot;
        title=&quot;Common cross-site tracking techniques&quot;
        src=&quot;/static/b7b2eb0851232154fafb3476be984d72/f7616/common-cross-site-tracking-techniques.png&quot;
        srcset=&quot;/static/b7b2eb0851232154fafb3476be984d72/e17e5/common-cross-site-tracking-techniques.png 400w,
/static/b7b2eb0851232154fafb3476be984d72/0a47e/common-cross-site-tracking-techniques.png 600w,
/static/b7b2eb0851232154fafb3476be984d72/f7616/common-cross-site-tracking-techniques.png 766w,
/static/b7b2eb0851232154fafb3476be984d72/97a96/common-cross-site-tracking-techniques.png 2400w&quot;
        sizes=&quot;(max-width: 766px) 100vw, 766px&quot;
        style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;&quot;
        loading=&quot;lazy&quot;
        decoding=&quot;async&quot;
      /&gt;
    &lt;/span&gt;&lt;/p&gt;
&lt;h2 id=&quot;how-cross-site-tracking-gets-built&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#how-cross-site-tracking-gets-built&quot; aria-label=&quot;how cross site tracking gets built permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;How cross-site tracking gets built&lt;/h2&gt;
&lt;p&gt;Recognition gives you an identifier. Cross-site tracking is what happens when a bunch of sites quietly agree to use the same one. Here&apos;s how that actually gets pulled off.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;IP address.&lt;/strong&gt; The original cross-site identifier, and the crudest. For a long time, your IP was a decent way to recognize you, since it often stuck to your household or followed your phone around for a while, and any site you visited could see it without doing anything clever. The trouble for trackers is that it was never precise. Whole households and offices could share one, mobile IPs shift around, and a VPN can easily change it. As IPv4 addresses ran low and providers started cramming more and more users onto each shared address, it has only gotten more opaque. It still works as an input signal that sharpens everything else, and when paired with the techniques below, the picture becomes much clearer.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Third-party cookies.&lt;/strong&gt; This is the technique that built the ad industry. Most cookies are first-party, set by the site you&apos;re actually visiting, and they do helpful things like keep you logged in or remember what&apos;s in your cart. A third-party cookie is different: A site you visit loads something from another domain — an ad, a &quot;like&quot; button, an invisible pixel — and that other domain gets to set its own cookie in your browser. Now imagine that same other domain has a presence on thousands of other sites. Every time you land on one of them, your browser helpfully hands back the cookie it set earlier, and the tracker knows it&apos;s you again. As you hop from a recipe blog to a news site to an online store, the tracker sees a single continuous trail with the same ID stamped on every step. The cookie was set by a third party, hence the name, and that third party is the same across all of those sites, which is the whole trick.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tracking pixels.&lt;/strong&gt; A tracking pixel is the delivery mechanism for a lot of this. It&apos;s usually a 1x1 transparent image, or just a snippet of code, embedded on a page for the sole purpose of phoning home. The most widely deployed example is the Meta Pixel, which sits on a huge chunk of the web. When you load a page that has it, your browser quietly reports back to Meta: This browser viewed this page, added this to the cart, started this checkout, and has these cookies and this network data. Meta Pixel &lt;a href=&quot;https://arxiv.org/html/2603.09380v1&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;tracks user activity through about 20 default and standard events such as PageView, Purchase, and AddToCart&lt;/a&gt;. One study found its automatic event tracking, which collects things like button clicks and page metadata, &lt;a href=&quot;https://arxiv.org/html/2603.09380v1&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;was adopted by up to 98.4% of the websites&lt;/a&gt; running it, mostly because it&apos;s on by default. The host site gets web analytics. Meta gets to connect your behavior in a random store to the account where it already knows your name.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Cookie syncing.&lt;/strong&gt; Here&apos;s a problem trackers have: Each one sets its own cookie with its own ID, and those IDs don&apos;t necessarily match. The ad network that knows you as &lt;code&gt;ABC123&lt;/code&gt; and the data broker that knows you as &lt;code&gt;XYZ789&lt;/code&gt; are looking at the same person without realizing it. Cookie syncing is the backroom handshake that fixes this. When you load a page, the trackers on it quietly ping each other and swap notes, &quot;my ABC123 is your XYZ789,&quot; so they can merge what they each know about you. It&apos;s the mechanism that turns a bunch of separate watchers into a shared surveillance network, and it happens in milliseconds, invisibly, while the page is still loading.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Cookie respawning.&lt;/strong&gt; This is the one that explains why just clearing your cookies often doesn&apos;t do what you&apos;d hope. The classic version of cookie respawning stashes a backup copy of your ID somewhere that &quot;clear cookies&quot; tends to miss, like localStorage or IndexedDB, and when you delete the main cookie, a script notices it&apos;s gone and quietly regenerates it from the backup with the same old ID. The deleted cookie comes back from the dead, which is why these are sometimes called evercookies. The most notorious hiding spots, like Flash storage, are gone now. Browsers have gotten better at clearing these places along with cookies, but the version that still works reliably doesn&apos;t store a backup at all. A tracker can recognize your browser by its attributes, that third building block from earlier, and look the ID right back up. &lt;a href=&quot;https://arxiv.org/pdf/2409.15656&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Research from 2025&lt;/a&gt; showed this directly: When researchers altered a browser&apos;s fingerprint, the cookies that returned changed too, indicating the fingerprint was really the one doing the identifying.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Link decoration and click IDs.&lt;/strong&gt; Ever notice a URL stuffed with a bunch of stuff after the question mark? Something like &lt;code&gt;?fbclid=&lt;/code&gt; or &lt;code&gt;?gclid=&lt;/code&gt; followed by a long string of gibberish? That string is a click identifier used for tracking. When you click an ad or a link, the destination gets your identifier baked right into the address, so the new site knows exactly who sent you and can tie this visit to your existing profile. As browsers clamp down on third-party cookies, link decoration is becoming a stronger identifier. A cookie rides along automatically, but when that&apos;s blocked, the ID has to travel some other way. So they pass it hand to hand through the links you click.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Bounce tracking.&lt;/strong&gt; A sneakier cousin of link decoration. Instead of just tacking an ID onto the link, the link quietly routes you &lt;em&gt;through&lt;/em&gt; the tracker&apos;s own domain before sending you on to where you meant to go. You click what looks like a normal link, your browser makes a pit stop at the tracker&apos;s site for a few milliseconds, and then lands on your destination. You never notice the detour, but the tracker&apos;s domain puts itself in a first-party position that lets it set and read first-party cookies, the kind browsers are far less likely to block. It&apos;s a way to get third-party tracking done while wearing a first-party hat.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CNAME cloaking.&lt;/strong&gt; This one is less about a new identifier and more about dodging the defenses browsers have built. Browsers have grown aggressive about blocking third-party cookies, so some trackers have found a way to be first-party instead. The site sets up a subdomain, something like &lt;code&gt;metrics.example.com&lt;/code&gt;, that appears to belong to the site you&apos;re visiting. But this subdomain, via a DNS record, actually points to a tracking company&apos;s servers. Your browser sees a first-party subdomain and extends first-party trust, and the tracker uses that to collect cookies and quietly forward identifying data off to its own servers, the kind it would have been blocked from setting if it had asked directly. Routing through a subdomain isn&apos;t inherently shady; plenty of sites do it for their own analytics or to keep their own tools from being blocked. The problem is when a third party uses it to build a profile on you and link your activity on this site to everywhere else they&apos;ve seen you.&lt;/p&gt;
&lt;p&gt;All of these techniques get you recognized, but recognized as a string of characters, not a name. Two things turn the identifier into an actual identity.&lt;/p&gt;
&lt;p&gt;The first is when you simply hand it over: You log in, type your email at checkout, enter your phone number, and now the profile has a verified, real-world person attached to it. Your email is especially useful here, since many people use the same one almost everywhere, which makes it a stable key that ties your activity together across sites that could never share a cookie.&lt;/p&gt;
&lt;p&gt;The second is probabilistic inference. If a laptop and a phone keep showing up on the same home IP every evening with similar browsing habits, a tracker&apos;s models will bet they belong to the same person and merge the two, no login required. Ad companies build what are called identity or cross-device graphs, linking your phone, laptop, and tablet into a single profile, so the &quot;you&quot; on your laptop and the &quot;you&quot; on your phone get recognized as the same person.&lt;/p&gt;
&lt;p&gt;The main theme across all of these identification methods is that each one is a way to carry a single identifier from one site or device to the next, linking your separate visits into one continuous trail. And they&apos;re increasingly built to survive the protections meant to stop them.&lt;/p&gt;
&lt;p&gt;But here&apos;s the good news: Those protections, the ones trackers are working so hard to dodge, are real. And you have more of them at your disposal than you might think.&lt;/p&gt;
&lt;h2 id=&quot;how-to-protect-yourself-from-cross-site-tracking&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#how-to-protect-yourself-from-cross-site-tracking&quot; aria-label=&quot;how to protect yourself from cross site tracking permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;How to protect yourself from cross-site tracking&lt;/h2&gt;
&lt;p&gt;It&apos;s quite hard to become truly invisible online and avoid cross-site tracking completely. But you can go from trivially easy to identify to genuinely hard to recognize with just a few key changes.&lt;/p&gt;
&lt;p&gt;Almost every defense is chasing the same goal: Making sure you can&apos;t be reliably recognized as the same person from one site to the next.&lt;/p&gt;
&lt;p&gt;One way to do this is to blend in: Look so much like everyone else that there&apos;s nothing distinctive to lock onto. The other is to stay in motion: Change what you present often enough that no stable identifier ever forms. Clear your storage so cookies don&apos;t persist, route around your IP so it can&apos;t anchor you, and present a browser that either matches the crowd or shifts over time.&lt;/p&gt;
&lt;p&gt;The real sweet spot is doing both at once. A common browser configuration, paired with rotating network paths and non-persistent storage, blends you into the crowd while leaving nothing stable enough to anchor to.&lt;/p&gt;
&lt;p&gt;Here&apos;s the trap, though. Doing this yourself, by hand, tends to backfire. Pile on enough rare extensions, obscure settings, and a niche operating system in the name of privacy, and you don&apos;t disappear into the crowd; you become the most distinctive person in it. A browser loaded with 15 privacy add-ons running on an unusual setup is often easier to spot, not harder. The approaches that actually work are the ones where the blending or the shifting is engineered for you and shared across a large group of people, so you&apos;re one of many rather than a snowflake.&lt;/p&gt;
&lt;p&gt;With that in mind, here are some options, roughly from least to most effort. Some are a complete setup on their own, while others are layers you can add on top.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;iOS Safari with iCloud Private Relay, in Private Browsing&lt;/strong&gt;. For most people, this is the strongest privacy-to-effort ratio available. It covers all three building blocks at once, with some extra defenses on top. Private Browsing wipes cookies and storage when you close it, and Intelligent Tracking Prevention blocks third-party cookies outright and shuts down bounce tracking, so there&apos;s nothing for a tracker to plant or reuse across the web. &lt;a href=&quot;https://support.apple.com/en-us/102602&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;iCloud Private Relay&lt;/a&gt; routes your traffic through two separate relays so that no single party, not the sites you visit, not your network provider, not even Apple, can see both who you are and what you&apos;re looking at, and the IP you present is shared by a pile of other Apple users. And Safari actively fights fingerprinting: It scrambles some of the signals trackers read, like canvas, audio, and WebGL output, with injected noise, and flattens others, like your screen size, to generic values. Both make it harder to pin a stable identifier on you.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Firefox and Brave.&lt;/strong&gt; If you&apos;re not in Apple&apos;s world, these are the strong mainstream picks, and both block a lot of this out of the box. Firefox&apos;s Total Cookie Protection, on by default, gives each website you visit its own separate cookie jar, so a tracker embedded on two different sites can&apos;t connect the cookie it sets on one to the cookie it sets on the other. Recent versions have also added fingerprinting defenses that Mozilla says &lt;a href=&quot;https://blog.mozilla.org/en/firefox/fingerprinting-protections/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;cut the number of trackable users in half&lt;/a&gt;. Brave blocks trackers and third-party cookies aggressively by default and fights fingerprinting by randomizing the signals trackers read, so your fingerprint changes from one session to the next. Turn either one to its stricter setting and you also get protections against bounce tracking and click-ID-laden URLs.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;One good content blocker.&lt;/strong&gt; Whatever browser you land on, a single reputable content blocker is the highest-leverage add-on you can run, because it stops trackers, pixels, and ad scripts from loading in the first place. No script, no fingerprint, no pixel phoning home. uBlock Origin is the consensus pick on Firefox, and uBlock Origin Lite is the version that works within Chrome&apos;s newer extension rules. Brave and Safari already have strong built-in blocking, so you mostly don&apos;t need to add anything there, but AdBlock Pro for Safari makes it more robust. The key word here is &lt;em&gt;one&lt;/em&gt; content blocker. This is the place to remember the entropy trap: A single well-maintained blocker makes you safer, but a tower of overlapping privacy extensions just makes you more distinctive and more easily identifiable.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Keep your logged-in life separate.&lt;/strong&gt; Of everything here, this is the one that might matter most, because a login is the only identifier you hand over voluntarily, and it&apos;s a perfect, verified match. No amount of tracking defense helps if you&apos;re signed into Google or Facebook on the same browser or device you use for everything else. The fix is to use private/incognito modes or to use separate browser profiles, the feature most browsers have for running fully independent setups, each with its own cookies and logins. Keep one profile signed into the accounts you actually use, Google, your email, your bank, and do your general browsing in a separate profile where you stay logged out. Because the logged-in identity is what staples a real name to everything else, walling it off keeps your casual browsing from getting tied back to the real you so easily. Firefox offers Multi-Account Containers that do a lighter version of this inside a single window, letting you quarantine a logged-in account, your Google session, say, to its own color-coded tabs so the rest of your browsing stays separate from it. It won&apos;t stop tracking on its own, but it breaks one of the easiest links trackers rely on.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;VPNs, with a caveat.&lt;/strong&gt; A VPN masks your IP address by routing your traffic through its servers, which genuinely helps with the network building block, especially on public Wi-Fi. But it&apos;s worth being clear about what a VPN does not do: it doesn&apos;t touch your cookies, and it doesn&apos;t change your browser fingerprint. The site you visit still sees the same browser attributes it always did. A VPN swaps one of the three building blocks and leaves the other two untouched, so on its own it&apos;s a partial measure, not a force field. The marketing tends to oversell this. It&apos;s a useful layer, but not a solution by itself.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Mullvad Browser and Tor.&lt;/strong&gt; If you need more protection than a mainstream browser offers, this is the next step up. The Tor Browser routes your traffic through multiple relays and, just as importantly, ships a browser deliberately engineered so that every Tor user looks alike, which is uniformity taken to its logical extreme. Mullvad Browser is an interesting middle option: It&apos;s the Tor Browser&apos;s anti-fingerprinting approach without the Tor network, so you get that same &quot;look like everybody else&quot; benefit on the regular internet, typically paired with a VPN. There is a real tradeoff, though. Tor is slower, and plenty of sites treat its traffic with suspicion or block it outright. Even here, you&apos;re raising the difficulty of tracking, but not dropping to zero. A determined script may still get a partial, lower-confidence read even against a hardened setup.&lt;/p&gt;
&lt;p&gt;There&apos;s an even-more hardcore tier beyond this, from LibreWolf&apos;s hardened-by-default setup to aggressive script blocking with NoScript or a full arkenfox configuration, all the way to isolating browsing activity in separate virtual machines. But each of these cause real friction, and past a point, the unusual setup starts working against you.&lt;/p&gt;
&lt;p&gt;None of these makes you invisible, and stacking all of them quickly becomes impractical. Most people don&apos;t need to fully disappear online, and honestly, the Safari setup or a privacy-focused browser gets most people most of the way there.&lt;/p&gt;
&lt;p&gt;If you want to see where you actually stand, EFF&apos;s &lt;a href=&quot;https://coveryourtracks.eff.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Cover Your Tracks&lt;/a&gt; and &lt;a href=&quot;https://privacytests.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;PrivacyTests.org&lt;/a&gt; both let you test your browser in a single click. You can see how unique your browser is and whether your blockers are working.&lt;/p&gt;
&lt;h2 id=&quot;so-what-about-fingerprint&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#so-what-about-fingerprint&quot; aria-label=&quot;so what about fingerprint permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;So what about Fingerprint?&lt;/h2&gt;
&lt;p&gt;You might be thinking, what is a company literally named Fingerprint doing writing a post like this? The answer is that we believe it is critical to understand these technologies, their differences and nuances, and how they are used.&lt;/p&gt;
&lt;p&gt;The same fingerprinting that lets an ad network track you across sites also lets a bank stop an &lt;a href=&quot;https://fingerprint.com/blog/account-takeover-fraud/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;account takeover&lt;/a&gt; before it drains your life savings, or a social platform keep a &lt;a href=&quot;https://fingerprint.com/blog/how-to-detect-ban-evasion/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;banned abuser&lt;/a&gt; from coming back under a new account. What matters is what you do with the identifier.&lt;/p&gt;
&lt;p&gt;Cross-site tracking needs an identifier that&apos;s shared across many sites: The third-party cookie that&apos;s the same everywhere it sits. Fingerprint&apos;s visitor ID is more narrow: It is scoped to a single customer&apos;s environment, so if two customers identify the same browser or device, they get two completely different IDs.&lt;/p&gt;
&lt;p&gt;We also don&apos;t collect your name, email address, or any other personal information. Our data isn&apos;t sold, and we aren’t an advertising product. The value our customers get comes from signals that point to risk — like signs that a browser has been tampered with or is automated — which flag potential fraud without needing to know who you are or if you recently were shopping for sweaters.&lt;/p&gt;
&lt;h2 id=&quot;protect-yourself-out-there&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#protect-yourself-out-there&quot; aria-label=&quot;protect yourself out there permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Protect yourself out there&lt;/h2&gt;
&lt;p&gt;You can&apos;t make yourself invisible online, and chasing that is a good way to drive yourself a little crazy. The realistic goal is smaller and more achievable: Make it so the tracking machinery that&apos;s out there simply can&apos;t get a stable read on you.&lt;/p&gt;
&lt;p&gt;The good news is that the highest-impact moves are the low-effort ones. Pick a browser that fights for you instead of against you, run one good content blocker, keep your logged-in life walled off from everything else, and every so often, test where you actually stand.&lt;/p&gt;
&lt;p&gt;You don&apos;t have to do all of it, and you definitely don&apos;t need 15 extensions and a custom-made setup that makes you stand out more than you blend in. A couple of solid choices cover most of the distance.&lt;/p&gt;</content:encoded><tags>fingerprinting, privacy, web browser security</tags></item><item><title><![CDATA[What is eIDAS 2.0? How device intelligence strengthens EUDI Wallet compliance]]></title><description><![CDATA[eIDAS 2.0 is reshaping digital identity in the EU. Learn what it is, how EUDI Wallets work, and how device intelligence can strengthen EUDI Wallet compliance.]]></description><link>/blog/eidas-2-0/</link><guid isPermaLink="false">/blog/eidas-2-0/</guid><pubDate>Wed, 17 Jun 2026 13:44:00 GMT</pubDate><enclosure url="https://fingerprint.com/static/45e5a3016905958d2ddc14272f4e9abb/eidas-2-0.jpg" length="0" type="image/jpeg"/><content:encoded>&lt;p&gt;The deadline is closer than most businesses realize. By December 2026, every EU member state must make a certified European Digital Identity (EUDI) Wallet available to all its citizens and residents.&lt;/p&gt;
&lt;p&gt;eIDAS 2.0 — formally &lt;a href=&quot;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1183&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Regulation (EU) 2024/1183&lt;/a&gt; — is the law behind EUDI Wallets, and it is the EU&apos;s most significant overhaul of digital identity legislation in a decade. This is an updated framework for how individuals and businesses prove who they are online across borders.&lt;/p&gt;
&lt;p&gt;For the technical teams across industries who are operating in the EU or serving European customers, the clock is now running to transform applications and services in order to ensure compliance with the new regulation.&lt;/p&gt;
&lt;p&gt;This guide covers what eIDAS 2.0 is, what the EUDI Wallet does, its technical implications, and how &lt;a href=&quot;https://fingerprint.com/blog/device-intelligence/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;device intelligence&lt;/a&gt; can strengthen your EUDI Wallet implementation.&lt;/p&gt;
&lt;h2 id=&quot;what-is-eidas-20&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#what-is-eidas-20&quot; aria-label=&quot;what is eidas 20 permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;What is eIDAS 2.0?&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;eIDAS stands for &lt;strong&gt;Electronic Identification, Authentication and Trust Services&lt;/strong&gt;. The original eIDAS Regulation (No 910/2014) was adopted in 2014 and created the EU&apos;s first unified framework for electronic identification and trust services. It covered things like digital signatures, electronic seals, and timestamping. Its goal was to give individuals and businesses a secure, legally recognized way to interact digitally across EU member states.&lt;/p&gt;
&lt;p&gt;eIDAS 2.0 is the &lt;a href=&quot;https://community.infineon.com/t5/Blogs/The-Evolution-of-eIDAS-Past-Present-and-Future/ba-p/997573&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;revised and updated version of the original eIDAS 1.0 regulation&lt;/a&gt;. This updated regulation&apos;s core ambition is straightforward.&lt;/p&gt;
&lt;p&gt;By 2030, the EU aims for at least 80% of citizens to be using a digital identity solution. The goal is to reduce reliance on fragmented national ID systems, minimize personal data disclosure, and enable more seamless cross-border digital interactions.&lt;/p&gt;
&lt;h2 id=&quot;the-eudi-wallet-the-core-of-eidas-20&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#the-eudi-wallet-the-core-of-eidas-20&quot; aria-label=&quot;the eudi wallet the core of eidas 20 permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;The EUDI Wallet: The core of eIDAS 2.0&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The European Digital Identity (EUDI) Wallet is the centrepiece of eIDAS 2.0, and it will have the most direct impact on how businesses verify customers and conduct digital transactions.&lt;/p&gt;
&lt;h3 id=&quot;what-is-the-eudi-wallet&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#what-is-the-eudi-wallet&quot; aria-label=&quot;what is the eudi wallet permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;What is the EUDI Wallet?&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;The EUDI Wallet is a certified wallet provided or recognized by a member state, and through which EU citizens and businesses can store, manage, and share verified digital credentials. Think of it as a digital counterpart to a physical wallet, except every document it contains is cryptographically verified, legally valid across the EU, and under the full control of the holder.&lt;/p&gt;
&lt;p&gt;Citizens can store and present credentials in the EUDI Wallet, including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;National identity documents&lt;/li&gt;
&lt;li&gt;Driving licenses&lt;/li&gt;
&lt;li&gt;Professional qualifications and certifications&lt;/li&gt;
&lt;li&gt;Educational diplomas&lt;/li&gt;
&lt;li&gt;Business licenses and authorizations&lt;/li&gt;
&lt;li&gt;And others, depending on the region&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The EUDI Wallet is built on a privacy-by-design principle. Data is stored locally on the user&apos;s device, so there is less centralized data concentration and breach risk. A built-in privacy dashboard gives users complete transparency over what they&apos;ve shared, with whom, and when.&lt;/p&gt;
&lt;h3 id=&quot;selective-disclosure-sharing-only-whats-needed&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#selective-disclosure-sharing-only-whats-needed&quot; aria-label=&quot;selective disclosure sharing only whats needed permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Selective disclosure: Sharing only what&apos;s needed&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;One of the wallet&apos;s most consequential features is selective disclosure. Rather than sharing an entire identity document, a user can present only the specific attributes a service requires. Proving you&apos;re over 18 doesn&apos;t require revealing your date of birth. Proving your professional license doesn&apos;t require sharing your home address.&lt;/p&gt;
&lt;p&gt;Under GDPR, this substantially reduces compliance exposure and risk aspects for businesses that adopt the EUDI Wallet for identity verification.&lt;/p&gt;
&lt;h3 id=&quot;credential-types-for-eudi-wallet-architecture&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#credential-types-for-eudi-wallet-architecture&quot; aria-label=&quot;credential types for eudi wallet architecture permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Credential types for EUDI Wallet architecture&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;There are several credential types that can be used within the EUDI Wallet ecosystem:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;PID (Person Identification Data)&lt;/strong&gt;.The core identity credential issued by a member state.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;PuB-EAAs (Public Body Electronic Attestations of Attributes)&lt;/strong&gt;. Attributes issued by public authorities, such as residence or civil-status information.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;EAAs (Electronic Attestations of Attributes).&lt;/strong&gt; Digital credentials issued by a wide range of organizations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;QEAAs (Qualified Electronic Attestations of Attributes)&lt;/strong&gt;. Electronic attestations issued under the eIDAS trust framework by Qualified Trust Service Providers (QTSPs).&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;For engineers and identity teams implementing EUDI Wallets, the distinction between credential types is important because they play different roles within the architecture and trust framework.&lt;/p&gt;
&lt;h2 id=&quot;who-does-eidas-20-apply-to&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#who-does-eidas-20-apply-to&quot; aria-label=&quot;who does eidas 20 apply to permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Who does eIDAS 2.0 apply to?&lt;/strong&gt;&lt;/h2&gt;
&lt;h3 id=&quot;eu-member-states&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#eu-member-states&quot; aria-label=&quot;eu member states permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;EU Member States&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Every member state must provide at least one EUDI Wallet solution to citizens and legal entities by the end of 2026. They must also accept wallets issued by other member states — a key interoperability requirement that underpins the single digital market vision.&lt;/p&gt;
&lt;h3 id=&quot;regulated-private-sector-organizations&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#regulated-private-sector-organizations&quot; aria-label=&quot;regulated private sector organizations permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Regulated private-sector organizations&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;This is where eIDAS 2.0 has the broadest business impact. Many sectors face mandatory EUDI Wallet acceptance requirements, which vary in timeline and depend on specific situations where digital identification or authentication is required, for example, strong customer authentication (SCA). The regulation may impact KYC and AML workflows as well by introducing a standardized, wallet-based identity mechanism that many regulated organizations will need to support.&lt;/p&gt;
&lt;h3 id=&quot;qualified-trust-service-providers-qtsps&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#qualified-trust-service-providers-qtsps&quot; aria-label=&quot;qualified trust service providers qtsps permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Qualified Trust Service Providers (QTSPs)&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Organizations that issue qualified electronic signatures, seals, timestamps, or other trust services are subject to specific technical and operational requirements under eIDAS 2.0, including accepting wallet-based authentication for the issuance of qualified certificates.&lt;/p&gt;
&lt;h3 id=&quot;individual-citizens&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#individual-citizens&quot; aria-label=&quot;individual citizens permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Individual citizens&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Wallet use remains entirely voluntary for individuals. The regulation explicitly requires that no one is discriminated against for choosing not to use a wallet. Businesses must continue to support alternative authentication and verification methods for users who prefer them.&lt;/p&gt;
&lt;h3 id=&quot;non-eu-businesses&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#non-eu-businesses&quot; aria-label=&quot;non eu businesses permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Non-EU businesses&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;eIDAS 2.0 applies to any organization that participates in regulated trust services, relies on EUDI Wallets, or falling into a covered relying-party category, regardless of where it is headquartered. If you have EU customers and operate in a regulated sector, this regulation and acceptance-obligation deadlines may apply to you.&lt;/p&gt;
&lt;h2 id=&quot;technical-impact-of-eidas-20-focus-areas-for-development-and-fraud-teams&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#technical-impact-of-eidas-20-focus-areas-for-development-and-fraud-teams&quot; aria-label=&quot;technical impact of eidas 20 focus areas for development and fraud teams permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Technical impact of eIDAS 2.0: Focus areas for development and fraud teams&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;There are several areas where eIDAS 2.0 will be an important consideration and impact project work for development and engineering teams. Those teams will need to focus efforts in these areas to ensure compliance.&lt;/p&gt;
&lt;h3 id=&quot;idv-kyc-and-customer-onboarding&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#idv-kyc-and-customer-onboarding&quot; aria-label=&quot;idv kyc and customer onboarding permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;IDV, KYC, and customer onboarding&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;The EUDI Wallet will significantly impact customer onboarding and user experiences for credential verification. Today, &lt;a href=&quot;https://fingerprint.com/blog/identity-verification-fraud-prevention/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;identity verification&lt;/a&gt; for financial services typically requires document submission, manual review, and processing windows that can take hours or days.&lt;/p&gt;
&lt;p&gt;Wallet-based verification can be completed in seconds: a customer presents government-verified credentials, the relying party checks the cryptographic proof, and the interaction is complete.&lt;/p&gt;
&lt;p&gt;For high-volume businesses in banking, insurance, or fintech, this is a fundamental re-engineering of the onboarding funnel.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;For more on how new account fraud intersects with identity verification, &lt;a href=&quot;https://fingerprint.com/blog/new-account-fraud/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;see our guide&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;h3 id=&quot;strong-customer-authentication-sca&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#strong-customer-authentication-sca&quot; aria-label=&quot;strong customer authentication sca permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Strong customer authentication (SCA)&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Under PSD2, SCA requirements have strengthened transaction security but also introduced friction: one-time codes, app confirmations, and additional verification steps that increase checkout abandonment.&lt;/p&gt;
&lt;p&gt;The EUDI Wallet may offer a clean path through this, with the ultimate goal and outcome a single, wallet-based authentication step that can satisfy SCA requirements while reducing friction for the end user.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;For a full breakdown of how payment authentication works alongside these regulations, &lt;a href=&quot;https://fingerprint.com/blog/payment-authentication/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;see our guide&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;h2 id=&quot;the-gap-eidas-20-doesnt-close-what-happens-after-verification&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#the-gap-eidas-20-doesnt-close-what-happens-after-verification&quot; aria-label=&quot;the gap eidas 20 doesnt close what happens after verification permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;The gap eIDAS 2.0 doesn&apos;t close: What happens after verification&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;eIDAS 2.0 is built around a &quot;verify once, reuse often&quot; model. A citizen verifies their identity, stores credentials in the EUDI Wallet, and reuses those credentials across services without repeating the full verification process.&lt;/p&gt;
&lt;p&gt;For users, that&apos;s a significantly better experience. For businesses, it introduces a risk that the regulation itself doesn&apos;t address.&lt;/p&gt;
&lt;p&gt;A EUDI Wallet credential establishes that a presented identity was valid at the moment of issuance. It has no view of what happens to the account after that moment.&lt;/p&gt;
&lt;p&gt;That one credential can&apos;t tell you whether the same person from the first session is accessing the account on the 47th session. It can&apos;t detect when a verified account changes hands, is used by automation, or is accessed from an environment that has changed materially since onboarding.&lt;/p&gt;
&lt;p&gt;While the credential check is a critical security step, it is just one moment in time.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;For more on the gaps in identity verification flows and how to extend visibility further than a single document check, &lt;a href=&quot;https://fingerprint.com/blog/identity-verification-fraud-prevention&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;read our full report&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;h2 id=&quot;how-device-intelligence-strengthens-the-credential-layer&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#how-device-intelligence-strengthens-the-credential-layer&quot; aria-label=&quot;how device intelligence strengthens the credential layer permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;How device intelligence strengthens the credential layer&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The identity check at onboarding is a moment in time. It has no bearing on what happens to the account months later. This is the structural gap that device intelligence fills.&lt;/p&gt;
&lt;p&gt;A persistent device identifier, applied at the moment of verification and maintained across subsequent sessions, creates continuity that the credential layer alone cannot provide. Trusted users returning on a recognized device move forward without friction.&lt;/p&gt;
&lt;p&gt;Sessions where the device environment has changed materially — for example, when a returning visitor shows a different hardware profile, new browser configuration, or unfamiliar network pattern — can be flagged for step-up controls proportionate to the actual risk they represent, rather than applied universally to all returning users.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://fingerprint.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Fingerprint&lt;/a&gt; provides exactly this layer. Our device intelligence platform produces stable visitor identifiers that persist for weeks and months, even through cookie clearing, incognito sessions, and browser updates. Adding &lt;a href=&quot;https://fingerprint.com/products/smart-signals/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Smart Signals&lt;/a&gt; can surface even richer context at the session level, before any application-layer check runs. Things like &lt;a href=&quot;https://fingerprint.com/blog/bot-detection/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;bot activity&lt;/a&gt;, VM or VPN use, &lt;a href=&quot;https://fingerprint.com/blog/location-spoofing-detection/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;location anomalies&lt;/a&gt;, and browser tampering all become visible before a user reaches an authentication or transaction flow.&lt;/p&gt;
&lt;p&gt;For organizations building compliant verification checks for EUDI Wallets, device intelligence can augment the credential layer by handling the session layer. Together, they can provide an added layer of trust that holds up across the full account lifecycle, not just at the moment of onboarding.&lt;/p&gt;
&lt;h2 id=&quot;how-to-prepare-a-step-by-step-framework-for-eidas-20-compliance&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#how-to-prepare-a-step-by-step-framework-for-eidas-20-compliance&quot; aria-label=&quot;how to prepare a step by step framework for eidas 20 compliance permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;How to prepare: A step-by-step framework for eIDAS 2.0 compliance&lt;/strong&gt; &lt;/h2&gt;
&lt;p&gt;Compliance with eIDAS 2.0 is a program of work. The following steps provide a practical framework to help development and engineering teams get organized and get started.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1. Audit your current identity workflows.&lt;/strong&gt; Map your existing onboarding,&lt;a href=&quot;https://fingerprint.com/blog/kyc-know-your-customer-financial-fraud/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt; KYC&lt;/a&gt;, and authentication processes against eIDAS 2.0 requirements. Identify where wallet-based verification would replace or supplement current flows, and where gaps exist between your current data collection practices and the selective-disclosure model the regulation requires.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. Register as a relying party.&lt;/strong&gt; Depending on the jurisdiction, businesses that wish to accept EUDI Wallet credentials may need to register with their national eIDAS 2.0 authority as a relying party. This is a prerequisite for wallet integration: Begin this process early, as national implementation timelines vary.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. Evaluate your technical stack.&lt;/strong&gt; Assess compatibility with ISO/IEC 18013-5 (the mDL standard used for wallet credentials), W3C Verifiable Credentials, and the EUDI Architecture Reference Framework. For many organizations, this could mean integrating through a platform that already handles these standards rather than building compliance infrastructure from scratch.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4. Shift your data collection model.&lt;/strong&gt; eIDAS 2.0 is built around attribute-based, selective disclosure. If your current onboarding flow collects full identity documents by default, you will need to re-engineer it to request only the specific attributes each transaction requires. This is both a technical change and an operational one that touches your privacy policies and consent flows.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;5. Choose a Qualified Trust Service Provider (QTSP).&lt;/strong&gt; QTSPs are the accredited entities that issue qualified signatures, seals, and attestations under eIDAS 2.0. Unless you are becoming a QTSP yourself, partnering with one is the most efficient route to compliance for most organizations.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;6. Add a device intelligence layer.&lt;/strong&gt; The EUDI Wallet handles credential verification at onboarding. It does not handle session-level risk across the account lifecycle. Device intelligence signals can complement your existing fraud and verification controls, by expanding visibility from beyond the single moment of approval and extending to subsequent visits and sessions. This is what enables low-friction return experiences for legitimate users and targeted step-up controls for sessions where risk context has changed. See how&lt;a href=&quot;https://fingerprint.com/blog/improving-identity-verification-registration-device-intelligence/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt; device intelligence strengthens identity verification&lt;/a&gt; for a practical walkthrough.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;7. Participate in pilot programmes.&lt;/strong&gt; The European Commission and several member states have run large-scale pilots to test real-world EUDI Wallet implementation. Where available, participating in these programmes provides practical integration experience before mandatory deadlines — and positions your organization ahead of the compliance curve.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;8. Train your teams.&lt;/strong&gt; Take stock of your internal policies and employees. Legal, compliance, product, and customer service teams all need to understand the new identity model, what wallet-based authentication means for user interactions, and how the credential types map to your existing verification requirements.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;9. Test and validate.&lt;/strong&gt; Before mandatory acceptance dates, your wallet integration should be thoroughly tested across all customer-facing platforms and internal systems. Understanding cross-border interoperability — for example, ensuring that a wallet issued in Germany works correctly with servers in another member state — deserves particular attention.&lt;/p&gt;
&lt;h2 id=&quot;building-stronger-verification-for-the-new-eidas-20-standard&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#building-stronger-verification-for-the-new-eidas-20-standard&quot; aria-label=&quot;building stronger verification for the new eidas 20 standard permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Building stronger verification for the new eIDAS 2.0 standard&lt;/strong&gt; &lt;/h2&gt;
&lt;p&gt;eIDAS 2.0 represents the most significant overhaul of identity verification in a decade. For businesses in regulated sectors, the EUDI Wallet rollout is a pressing operational and compliance undertaking.&lt;/p&gt;
&lt;p&gt;The organizations that will emerge from this transition in the strongest position are those who are already actively working on the transition. By auditing identity workflows, evaluating technical infrastructure, and building relationships with qualified trust service providers now, those organizations can ensure compliance and acceptance of EUDI Wallets by 2027.&lt;/p&gt;
&lt;p&gt;Adding a &lt;a href=&quot;https://fingerprint.com/products/fingerprint-pro/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;/a&gt;&lt;a href=&quot;https://fingerprint.com/products/fingerprint-pro/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;device intelligence layer&lt;/a&gt; to identity infrastructure can be a forward-thinking way for businesses to strengthen verification. Device intelligence extends visibility beyond a single moment-in-time check, so you can ensure trust and security hold up across sessions, as eIDAS 2.0 becomes the new identity standard in the EU.&lt;/p&gt;</content:encoded><tags>compliance</tags></item><item><title><![CDATA[Fraud analytics: 4 most common techniques ]]></title><description><![CDATA[Explore key fraud analytics techniques, real-world use cases, and practical implementation tips to protect your business.]]></description><link>/blog/fraud-analytics/</link><guid isPermaLink="false">/blog/fraud-analytics/</guid><pubDate>Mon, 15 Jun 2026 12:05:00 GMT</pubDate><enclosure url="https://fingerprint.com/static/cb19f2ef4ef836fb7ff524b53010ae53/fraud-analytics.jpg" length="0" type="image/jpeg"/><content:encoded>&lt;p&gt;Fraud is an increasing threat to businesses across industries, and the &lt;a href=&quot;https://fingerprint.com/blog/definitive-guide-real-cost-online-fraud/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;real cost of online fraud&lt;/a&gt; extends well beyond direct financial loss to include reputational damage, regulatory exposure, and customer churn. Fraud analytics gives security and engineering teams the tools to detect suspicious patterns at scale, often in real time and before damage occurs.&lt;/p&gt;
&lt;p&gt;This guide covers how fraud analytics works, what to look for in a solution, and how to build it into your existing stack.&lt;/p&gt;
&lt;h2 id=&quot;what-is-fraud-analytics&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#what-is-fraud-analytics&quot; aria-label=&quot;what is fraud analytics permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;What is fraud analytics?&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Fraud analytics is the use of data science, machine learning, and AI to detect and prevent fraudulent transactions and behaviors in real time.&lt;/p&gt;
&lt;p&gt;With the global fraud detection and prevention market expected to &lt;a href=&quot;https://www.marketsandmarkets.com/Market-Reports/fraud-detection-prevention-market-1312.html&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;grow to $66.6 billion&lt;/a&gt; (USD) by 2028, fraud analytics is becoming an increasingly critical investment for businesses across industries.&lt;/p&gt;
&lt;p&gt;The process begins with the collection and analysis of vast amounts of transaction and behavioral data. Machine learning models process this data to surface anomalies, identify suspicious patterns, and assign risk scores to events as they happen. Unlike rule-based systems that flag only what you&apos;ve explicitly defined, ML-driven fraud analytics can detect novel attack patterns and adapt as fraudster behavior evolves.&lt;/p&gt;
&lt;p&gt;By combining historical pattern analysis with real-time signals, fraud analytics lets security and engineering teams anticipate fraudulent behavior before it causes damage, rather than simply reacting after the fact.&lt;/p&gt;
&lt;h2 id=&quot;benefits-of-using-fraud-analytics&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#benefits-of-using-fraud-analytics&quot; aria-label=&quot;benefits of using fraud analytics permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Benefits of using fraud analytics&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Fraud analytics equips you with advanced tools to better protect your financial interests. Below, we&apos;ll outline a number of benefits you&apos;ll gain from using these tools.&lt;/p&gt;
&lt;h3 id=&quot;reduced-financial-losses-from-fraudulent-transactions&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#reduced-financial-losses-from-fraudulent-transactions&quot; aria-label=&quot;reduced financial losses from fraudulent transactions permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Reduced financial losses from fraudulent transactions&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Financial institutions that deploy advanced fraud detection systems can intercept and prevent fraudulent transactions. In turn, they protect their revenues.&lt;/p&gt;
&lt;p&gt;This approach not only safeguards assets but also ensures you maintain customer trust in your business. Your ability to detect and respond to fraudulent activity sooner rather than later can reduce financial damage and preserve your reputation.&lt;/p&gt;
&lt;h3 id=&quot;improved-operational-efficiency-and-faster-investigations&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#improved-operational-efficiency-and-faster-investigations&quot; aria-label=&quot;improved operational efficiency and faster investigations permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Improved operational efficiency and faster investigations&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Fraud analytics streamline the identification and investigation of suspicious activities, improving your operational efficiency. Fraud and security teams can quickly pinpoint and scrutinize irregularities, ensuring prompt action.&lt;/p&gt;
&lt;p&gt;Fast action reduces the time and resources spent on fraud investigations. Teams can then focus their time on other critical areas of your operation. Integrating automated fraud detection tools can further accelerate response times, minimizing the window of opportunity for fraudsters to exploit.&lt;/p&gt;
&lt;h3 id=&quot;identifying-new-patterns-and-trends&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#identifying-new-patterns-and-trends&quot; aria-label=&quot;identifying new patterns and trends permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Identifying new patterns and trends&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;With access to a breadth of data and predictive models, organizations develop stronger pattern recognition and trends in fraud. These insights enable you to stay ahead of the continuous evolution of fraudulent strategies.&lt;/p&gt;
&lt;p&gt;As fraudsters keep adapting their tactics, having a system in place that evolves with these trends helps you stay ahead. You&apos;ll be prepared to thwart current fraudulent schemes and you&apos;ll be ready for future threats.&lt;/p&gt;
&lt;h3 id=&quot;proactive-risk-management-and-informed-decision-making&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#proactive-risk-management-and-informed-decision-making&quot; aria-label=&quot;proactive risk management and informed decision making permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Proactive risk management and informed decision-making&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Effective fraud risk management is proactive, not reactive. By using data analytics techniques, you can conduct a thorough risk assessment, anticipate potential threats, and make informed decisions to reinforce your defenses against fraud loss.&lt;/p&gt;
&lt;p&gt;This proactive stance means implementing strategic defenses before fraud can occur, rather than just responding to incidents after they happen.&lt;/p&gt;
&lt;p&gt;The integration of predictive analytics and machine learning models can enhance your ability to foresee and mitigate risks.&lt;/p&gt;
&lt;h2 id=&quot;techniques-used-in-fraud-analytics&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#techniques-used-in-fraud-analytics&quot; aria-label=&quot;techniques used in fraud analytics permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Techniques used in fraud analytics&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Fraud analytics uses various techniques to interpret data and detect anomalies. Each approach below can be used to give you a comprehensive assessment of fraud risk.&lt;/p&gt;
&lt;h3 id=&quot;1-descriptive-analytics&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#1-descriptive-analytics&quot; aria-label=&quot;1 descriptive analytics permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;1. Descriptive analytics&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Descriptive analytics involves summarizing historical data to identify patterns within transaction data and user behavior. For teams reviewing reports or dashboards, this is the initial layer of analytics.&lt;/p&gt;
&lt;p&gt;Descriptive analytics relies on basic statistical techniques to curate data sets and ensure data quality is maintained. Common outputs include the calculation of averages, frequencies, and variations within your fraud data.&lt;/p&gt;
&lt;h3 id=&quot;2-diagnostic-analytics&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#2-diagnostic-analytics&quot; aria-label=&quot;2 diagnostic analytics permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;2. Diagnostic analytics&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Once patterns are established, teams dive deeper into the data sets with diagnostic analytics to discover the reasons behind specific events.&lt;/p&gt;
&lt;p&gt;More complex analytics are involved, such as mining data for specific fraud indicators that can reveal fraudulent behaviors. The methodology might include examining cause and effect by using algorithms that dissect the relationships within the data.&lt;/p&gt;
&lt;h3 id=&quot;3-predictive-analytics&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#3-predictive-analytics&quot; aria-label=&quot;3 predictive analytics permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;3. Predictive analytics&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Predictive analytics harnesses machine learning techniques and predictive models to forecast the likelihood of future fraud based on historical data.&lt;/p&gt;
&lt;p&gt;By analyzing trends and patterns, teams can identify potential risks before they turn into actual fraud. Machine learning algorithms are used to sift through massive volumes of data and detect subtle, complex fraud schemes.&lt;/p&gt;
&lt;h3 id=&quot;4-prescriptive-analytics&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#4-prescriptive-analytics&quot; aria-label=&quot;4 prescriptive analytics permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;4. Prescriptive analytics&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Prescriptive analytics focuses on finding the best course of action for any given situation. This might involve machine learning algorithms that not only predict potential fraud but also suggest ways to prevent it.&lt;/p&gt;
&lt;p&gt;By analyzing past incidents and outcomes, teams can curate response strategies and establish proactive defenses against future fraud attempts.&lt;/p&gt;
&lt;h2 id=&quot;how-device-intelligence-enhances-fraud-analytics&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#how-device-intelligence-enhances-fraud-analytics&quot; aria-label=&quot;how device intelligence enhances fraud analytics permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;How device intelligence enhances fraud analytics&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://fingerprint.com/blog/device-intelligence-explainer/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Device intelligence&lt;/a&gt; adds a powerful layer to fraud analytics by providing real-time insights into the devices accessing your platform.&lt;/p&gt;
&lt;p&gt;Here&apos;s how Fingerprint&apos;s device intelligence capabilities support fraud detection:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Bot Detection:&lt;/strong&gt; Flags automated activity from tools like Selenium or Puppeteer, helping you block credential stuffing attacks, fake account creation, and other bot-driven fraud.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Persistent Visitor ID:&lt;/strong&gt; Assigns a stable identifier to each device that remains consistent across sessions—even when users clear cookies, use incognito mode, or attempt to hide their identity. This enables the recognition of repeat offenders and the linking of suspicious behavior over time.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Smart Signals:&lt;/strong&gt; Provides actionable insights such as VPN detection, browser tampering, incognito mode usage, and proxy detection to help you understand the full context of each visitor.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Suspect Score:&lt;/strong&gt; Aggregates multiple Smart Signals into a single weighted risk value, making it easy to quickly identify suspicious devices without analyzing each signal individually. The higher the score, the more suspicious the device.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The quality of a fraud model depends heavily on the quality of its input data, and device signals are among the hardest for fraudsters to spoof.&lt;/p&gt;
&lt;p&gt;Beyond individual signals, Fingerprint provides over 100 device data points that can be piped directly into your existing ML models and fraud analytics tools. By enriching your analytics pipeline with persistent, accurate device intelligence, you give your models the context they need to make faster and more confident risk decisions.&lt;/p&gt;
&lt;h2 id=&quot;how-fraud-analytics-are-used-to-safeguard-transactions-and-reduce-losses&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#how-fraud-analytics-are-used-to-safeguard-transactions-and-reduce-losses&quot; aria-label=&quot;how fraud analytics are used to safeguard transactions and reduce losses permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;How fraud analytics are used to safeguard transactions and reduce losses&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Fraud analytics tools blend security measures and fraud detection techniques to protect payment activity and minimize loss from fraud.&lt;/p&gt;
&lt;h3 id=&quot;protecting-online-transactions&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#protecting-online-transactions&quot; aria-label=&quot;protecting online transactions permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Protecting online transactions&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Real-time fraud analytics reduce the risk of fraudulent activity by continuously monitoring transaction patterns, device signals, and behavioral data. When something falls outside established norms, the system flags it and assigns a risk score, allowing fraud teams to respond immediately rather than after damage has occurred. Machine learning refines this process over time, improving detection accuracy and reducing false positives that would otherwise block legitimate transactions.&lt;/p&gt;
&lt;h3 id=&quot;preventing-chargebacks&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#preventing-chargebacks&quot; aria-label=&quot;preventing chargebacks permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Preventing chargebacks&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Chargebacks often signal credit card fraud or disputed transactions that could have been caught earlier in the flow. Fraud analytics helps by monitoring transaction behavior for inconsistencies and setting thresholds for acceptable activity. Combining behavioral analysis with identity verification frameworks like&lt;a href=&quot;https://fingerprint.com/blog/kyc-know-your-customer-financial-fraud/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt; Know Your Customer (KYC)&lt;/a&gt; reduces wrongful declines while maintaining a strong defense against fraudulent transactions. A well-tuned&lt;a href=&quot;https://fingerprint.com/blog/fraud-prevention-strategies/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt; fraud detection strategy&lt;/a&gt; finds the balance between security and minimizing friction for legitimate customers.&lt;/p&gt;
&lt;h3 id=&quot;combating-account-takeover&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#combating-account-takeover&quot; aria-label=&quot;combating account takeover permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Combating account takeover&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;a href=&quot;https://fingerprint.com/blog/account-takeover-solutions/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;ATO prevention&lt;/a&gt; systems analyze login behavior, device consistency, and access patterns to detect unauthorized access attempts early. Combining behavioral analytics with device intelligence and MFA creates a layered defense that is significantly harder to bypass than any single control. Detecting anomalies at the device level, such as a known bad actor returning on a new session or a single device cycling through multiple accounts, gives teams earlier intervention points before accounts are compromised.&lt;/p&gt;
&lt;h2 id=&quot;harness-the-power-of-fraud-analytics-with-fingerprint&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#harness-the-power-of-fraud-analytics-with-fingerprint&quot; aria-label=&quot;harness the power of fraud analytics with fingerprint permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;strong&gt;Harness the power of fraud analytics with Fingerprint&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Fraud analytics is only as good as the data feeding it.&lt;/p&gt;
&lt;p&gt;Fingerprint gives fraud and engineering teams access to over 100 device intelligence signals, including bot detection, VPN and proxy detection, browser tampering. Our persistent visitor ID survives cookie clears and session resets, strengthening your models with accurate, hard-to-spoof input data that can help you make faster and more confident risk decisions.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://dashboard.fingerprint.com/login&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Create a free account&lt;/a&gt; or&lt;a href=&quot;https://fingerprint.com/contact-sales/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt; get in touch&lt;/a&gt; to see how Fingerprint fits into your fraud analytics stack.&lt;/p&gt;</content:encoded><tags>fraud-glossary</tags></item><item><title><![CDATA[6 most effective techniques to prevent credential stuffing]]></title><description><![CDATA[Credential stuffing attacks are growing in scale and cost. Discover the 6 most effective prevention techniques to stop automated login abuse and protect your users' accounts.]]></description><link>/blog/credential-stuffing-prevention-checklist/</link><guid isPermaLink="false">/blog/credential-stuffing-prevention-checklist/</guid><pubDate>Fri, 12 Jun 2026 10:20:00 GMT</pubDate><enclosure url="https://fingerprint.com/static/6126336034482958f92d5d99f7f5f2db/credential-stuffing-prevention-v1.png" length="0" type="image/png"/><content:encoded>&lt;p&gt;Credential stuffing is an automated cyberattack where hackers use stolen username-password pairs to gain unauthorized access to user accounts across multiple websites. Credential stuffing prevention is one of the most effective cybersecurity defenses a website or organization can implement today. Securing and protecting your users&apos; data with&lt;a href=&quot;https://fingerprint.com/blog/account-takeover-prevention/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt; account takeover prevention&lt;/a&gt; methods can go a long way toward stopping costly and damaging breaches.&lt;/p&gt;
&lt;p&gt;Credential stuffing attacks are among the most common causes of data breaches. This technique is made possible because around &lt;a href=&quot;https://cybernews.com/security/password-leak-study-unveils-2025-trends-reused-and-lazy/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;94% of people reuse passwords on multiple accounts&lt;/a&gt; rather than using a password manager to generate unique passwords, meaning that once attackers have that information, reusing it across other sites is trivial. Data breaches, many of which originate from credential stuffing, &lt;a href=&quot;https://www.ibm.com/reports/data-breach&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;cost U.S. organizations an average of $9.48M&lt;/a&gt; according to IBM&apos;s 2024 Cost of a Data Breach Report.&lt;/p&gt;
&lt;p&gt;The scale of credential stuffing attacks is only increasing globally. Billions of credentials are exposed in data breaches each year, with attackers using automated tools to test these stolen credentials across thousands of websites simultaneously. The success rate may be low (&lt;a href=&quot;https://hbr.org/2017/12/you-cant-secure-100-of-your-data-100-of-the-time&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;around 0.1-0.2%&lt;/a&gt;), but the sheer volume of attempts makes credential stuffing highly profitable for attackers.&lt;/p&gt;
&lt;h3 id=&quot;what-is-credential-stuffing&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#what-is-credential-stuffing&quot; aria-label=&quot;what is credential stuffing permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;What is credential stuffing?&lt;/h3&gt;
&lt;p&gt;Credential stuffing is the automated use of usernames and passwords obtained through data breaches, phishing campaigns, or purchases on dark web marketplaces. These hacks can be coordinated by the party carrying out the credential stuffing attack, or cybercriminals can purchase pre-obtained logins from the dark web.&lt;/p&gt;
&lt;p&gt;Automation bots rapidly enter stolen login details across many websites simultaneously. While they&apos;re rare, a successful login can expose personal information, saved payment methods, or other sensitive account data.&lt;/p&gt;
&lt;p&gt;Credential stuffing attacks are popular because they can sweep a wide range of sites much faster than entering the information manually. Not only that, but bots can distribute their requests from different IP addresses, making simple IP-based blocking ineffective.&lt;/p&gt;
&lt;h3 id=&quot;what-is-the-difference-between-credential-stuffing-and-brute-force-attacks&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#what-is-the-difference-between-credential-stuffing-and-brute-force-attacks&quot; aria-label=&quot;what is the difference between credential stuffing and brute force attacks permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;What is the difference between credential stuffing and brute force attacks?&lt;/h3&gt;
&lt;p&gt;Credential stuffing, password spraying, and brute force attacks are all automated login attacks used to gain access, but they work differently. Credential stuffing uses known username-password pairs stolen from previous data breaches, while brute force attacks systematically guess passwords using random combinations or dictionary words. Password spraying takes the opposite approach, trying a small number of commonly used passwords against many different accounts to avoid lockout thresholds. Credential stuffing is typically more effective because it exploits password reuse across multiple sites.&lt;/p&gt;
&lt;h3 id=&quot;famous-credential-stuffing-attacks&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#famous-credential-stuffing-attacks&quot; aria-label=&quot;famous credential stuffing attacks permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Famous credential stuffing attacks&lt;/h3&gt;
&lt;p&gt;Even if you haven&apos;t heard the term credential stuffing attack before, there&apos;s a good chance you may have heard of one being carried out:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;In 2020, around 500,000 usernames and passwords were&lt;a href=&quot;https://www.forbes.com/sites/daveywinder/2020/04/28/zoom-gets-stuffed-heres-how-hackers-got-hold-of-500000-passwords/?sh=6a5438ba5cdc&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt; stolen from Zoom&lt;/a&gt;, published on the dark web, and made available for purchase.&lt;/li&gt;
&lt;li&gt;The North Face has fallen victim to  credential stuffing attacks four times in the past few years including an&lt;a href=&quot;https://www.cpomagazine.com/cyber-security/the-north-face-credential-stuffing-attack-compromises-200000-accounts/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt; information leak of nearly 200,000 users in 2022&lt;/a&gt; and &lt;a href=&quot;https://www.malwarebytes.com/blog/news/2025/06/the-north-face-warns-customers-about-potentially-stolen-data&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;another recent incident in 2025&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;In 2025, &lt;a href=&quot;https://www.securityweek.com/draftkings-warns-users-of-credential-stuffing-attacks/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;DraftKings warned users of an attack&lt;/a&gt; after hackers accessed user accounts and compromised names, addresses, phone numbers, email addresses, and other information.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The list goes on. While the information in a single North Face account may seem insignificant, when the same password is used for an online bank account, it can become a much larger (and more expensive) problem.&lt;/p&gt;
&lt;h3 id=&quot;checklist-for-credential-stuffing-prevention&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#checklist-for-credential-stuffing-prevention&quot; aria-label=&quot;checklist for credential stuffing prevention permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Checklist for credential stuffing prevention&lt;/h3&gt;
&lt;p&gt;So what can you do to protect your users’ accounts against credential stuffing, beyond simply requiring strong passwords? It may require extra effort, but the payoff can be protecting your users’ personal data, personal information, and widespread access to other accounts.&lt;/p&gt;
&lt;p&gt;Here are the most effective techniques to protect yourself from credential stuffing attacks:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Multi-factor authentication (MFA):&lt;/strong&gt; A security method requiring users to verify their identity through a secondary device, biometric scan, or authenticator app before accessing their account. MFA can be integrated via a separate app such as Duo or JumpCloud. When a user logs in, the MFA provider pushes a notification to their registered device to confirm the attempt. MFA is easy to set up, and many platforms are now incorporating it as a standard part of the login process.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;IP blocking:&lt;/strong&gt; A security measure that denies connections from specific IP addresses or regions identified as suspicious. You can block access at the server or WAF level based on region or flagged IP ranges. Blocking IP addresses is particularly effective when you can identify suspect IP addresses repeatedly attempting login attempts against your system. However, it loses effectiveness when those IP addresses are randomized or rotated, which is common in credential stuffing operations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Device fingerprinting:&lt;/strong&gt; A technique that uses browser and device attributes to create a stable and unique identifier for each visitor. Also known as &lt;a href=&quot;https://fingerprint.com/blog/browser-fingerprinting-techniques/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;browser fingerprinting&lt;/a&gt;, it&apos;s based on your browser and device settings, such as screen resolution, GPU capabilities, language, and operating system. Fingerprint&apos;s device identification generates a persistent visitor ID that can detect when the same device attempts logins across multiple accounts or when a known bad actor returns — even after clearing cookies or changing IPs. This allows you to recognize and block repeat attackers regardless of the account they target.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Bot detection:&lt;/strong&gt; Technology that identifies and blocks automated scripts, headless browsers, and other automation tools attempting login abuse. Fingerprint&apos;s Bot Detection Smart Signal can block credential stuffing bots by analyzing visitors and returning &lt;code&gt;notDetected&lt;/code&gt; when no bot activity is found, &lt;code&gt;good&lt;/code&gt; for known legitimate bots like search engines or verified AI agents, and &lt;code&gt;bad&lt;/code&gt; for automation tools and headless browsers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Rate limiting:&lt;/strong&gt; A defense mechanism that restricts the number of login attempts allowed from a given user, device, or IP address within a defined time window. When a threshold is exceeded, subsequent attempts can be blocked, delayed, or challenged with step-up authentication. Rate limiting is one of the most straightforward controls to implement and is effective against low-sophistication attacks. It becomes less effective against distributed credential stuffing operations where requests are spread across many IP addresses and timed to stay under detection thresholds, making it most effective when combined with device fingerprinting or bot detection.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Breach credential checking:&lt;/strong&gt; At login or account creation, you can check submitted passwords against known breach datasets using a service like the&lt;a href=&quot;https://haveibeenpwned.com/API/v3&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt; Have I Been Pwned API&lt;/a&gt;. If a credential pair appears in a known breach, you can prompt the user to reset their password before granting access. Not essential, but a low-effort integration that adds a meaningful layer of protection for users who reuse passwords across sites.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id=&quot;protect-your-users-from-credential-stuffing-before-attackers-find-the-gaps&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#protect-your-users-from-credential-stuffing-before-attackers-find-the-gaps&quot; aria-label=&quot;protect your users from credential stuffing before attackers find the gaps permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Protect your users from credential stuffing before attackers find the gaps&lt;/h3&gt;
&lt;p&gt;Credential stuffing attacks are increasing in scale and sophistication, and the cost of a breach, financial, legal, and reputational, can be significant and long-lasting. A proactive approach to&lt;a href=&quot;https://fingerprint.com/blog/stop-credential-stuffing/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt; credential stuffing prevention&lt;/a&gt; means building the right controls into your authentication layer before attackers find the gaps: rate limiting to slow automated attempts, bot detection and device fingerprinting to catch distributed attacks that evade IP-based defenses, and MFA to ensure compromised credentials alone aren&apos;t enough to gain access.&lt;/p&gt;
&lt;p&gt;Fingerprint gives you the device intelligence to make smarter authentication decisions at every login.&lt;a href=&quot;https://fingerprint.com/contact-sales/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt; Talk to our team&lt;/a&gt; to see how it fits into your stack, or &lt;a href=&quot;https://dashboard.fingerprint.com/signup&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;create a free account&lt;/a&gt; and get started.&lt;/p&gt;</content:encoded><tags>use cases</tags></item><item><title><![CDATA[Retail account fraud: Make it stop with device intelligence]]></title><description><![CDATA[Account takeovers, payment fraud, and chargebacks cost retailers billions. Discover how device intelligence closes the gaps legacy fraud controls leave behind.]]></description><link>/blog/device-intelligence-for-retail/</link><guid isPermaLink="false">/blog/device-intelligence-for-retail/</guid><pubDate>Tue, 09 Jun 2026 12:42:00 GMT</pubDate><enclosure url="https://fingerprint.com/static/60228e0cb8bd539a67e7e3161cd66250/retail-report-cover.png" length="0" type="image/png"/><content:encoded>&lt;h2 id=&quot;introduction-were-not-trying-to-scare-you-but&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#introduction-were-not-trying-to-scare-you-but&quot; aria-label=&quot;introduction were not trying to scare you but permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Introduction: We’re not trying to scare you, but…&lt;/h2&gt;
&lt;p&gt;For decades, fraud prevention for retailers online was essentially a login problem. Secure the account, verify the credential, and the transaction that followed was presumed legitimate.&lt;/p&gt;
&lt;p&gt;That model no longer holds.&lt;/p&gt;
&lt;p&gt;Despite a decade of structural transformation, many industry-standard fraud controls — passwords, one-time codes, CAPTCHAs — are becoming outdated and increasingly ineffective against emerging threats, especially AI-driven ones.&lt;/p&gt;
&lt;p&gt;Fraud teams in retail need to embrace a new mindset and evolve past those conventional fraud controls. Because today’s omnichannel shopping environment has a larger attack surface than ever before.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Loyalty programs&lt;/strong&gt; concentrate stored payment methods, reward balances, and purchase patterns into a single, high-value account target.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Buy online, pick up in store&lt;/strong&gt; (BOPIS) introduces a blended risk area, where fraudsters can exploit the online experience and make off with physical goods.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Account security&lt;/strong&gt; — along with account takeovers, payment fraud, and chargebacks — can no longer be treated as a single-point-of-defense problem.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;It’s no longer just about securing at a single interaction, or using a single risk indicator.&lt;/p&gt;
&lt;p&gt;&lt;span
      class=&quot;gatsby-resp-image-wrapper&quot;
      style=&quot;position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 766px; max-height: 650px;&quot;
    &gt;
      &lt;span
    class=&quot;gatsby-resp-image-background-image&quot;
    style=&quot;padding-bottom: 47.5%; position: relative; bottom: 0; left: 0; display: block;&quot;
  &gt;&lt;/span&gt;
  &lt;img
        class=&quot;gatsby-resp-image-image&quot;
        alt=&quot;Bar chart shows global e-commerce fraud losses projected to rise from $138 billion in 2025 to $226 billion in 2029, a 63.8% increase.&quot;
        title=&quot;Global ecommerce losses: Projected growth&quot;
        src=&quot;/static/637fb8a12b9e5b6a866e8cf26e3e1098/f7616/global-ecommerce-fraud-losses.png&quot;
        srcset=&quot;/static/637fb8a12b9e5b6a866e8cf26e3e1098/e17e5/global-ecommerce-fraud-losses.png 400w,
/static/637fb8a12b9e5b6a866e8cf26e3e1098/0a47e/global-ecommerce-fraud-losses.png 600w,
/static/637fb8a12b9e5b6a866e8cf26e3e1098/f7616/global-ecommerce-fraud-losses.png 766w,
/static/637fb8a12b9e5b6a866e8cf26e3e1098/c1b63/global-ecommerce-fraud-losses.png 1200w&quot;
        sizes=&quot;(max-width: 766px) 100vw, 766px&quot;
        style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;&quot;
        loading=&quot;lazy&quot;
        decoding=&quot;async&quot;
      /&gt;
    &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://capitaloneshopping.com/research/ecommerce-fraud-statistics/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Global ecommerce fraud losses exceeded $138 billion in 2025&lt;/a&gt;. And it’s projected to nearly double by 2029. Online payment fraud on its own cost merchants $53 billion in 2025.&lt;/p&gt;
&lt;p&gt;These stats demonstrate how much fraudsters have already adapted to traditional fraud defense methods. And how they are continuing to impact the bottom line for retailers.&lt;/p&gt;
&lt;p&gt;&lt;span
      class=&quot;gatsby-resp-image-wrapper&quot;
      style=&quot;position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 600px; max-height: 650px;&quot;
    &gt;
      &lt;span
    class=&quot;gatsby-resp-image-background-image&quot;
    style=&quot;padding-bottom: 28.500000000000004%; position: relative; bottom: 0; left: 0; display: block;&quot;
  &gt;&lt;/span&gt;
  &lt;img
        class=&quot;gatsby-resp-image-image&quot;
        alt=&quot;$53 billion projected merchant losses from online payment fraud in 2025. Large orange dollar sign, smaller gray dollar sign. Source: Capital One Shopping, 2025.&quot;
        title=&quot;Merchant losses to online payment fraud&quot;
        src=&quot;/static/d60eb94969dbb16d55915a0a6847cdd4/0a47e/merchant-losses.png&quot;
        srcset=&quot;/static/d60eb94969dbb16d55915a0a6847cdd4/e17e5/merchant-losses.png 400w,
/static/d60eb94969dbb16d55915a0a6847cdd4/0a47e/merchant-losses.png 600w&quot;
        sizes=&quot;(max-width: 600px) 100vw, 600px&quot;
        style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;&quot;
        loading=&quot;lazy&quot;
        decoding=&quot;async&quot;
      /&gt;
    &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Consumer behavior in the digital-first, always-on market means there’s a vast and complex area of exposure. Precise, accurate detection is vital across the entire environment — from initial visit to account login to guest checkout to order fulfillment.&lt;/p&gt;
&lt;p&gt;Simply adding new challenges and authentication layers puts fraud teams in a bind: You may take away any meaningful security gains by negatively impacting UX. Any added friction points can harm retention and revenue. Loyal customers get frustrated. New customers don’t convert.&lt;/p&gt;
&lt;p&gt;The reality for fraud defense in online retail is this: Teams need to have broad and deep visibility for threat detection at scale, delivered in a way that won’t impact the core user experience.&lt;/p&gt;
&lt;p&gt;In this report, we’ll examine how account fraud in retail has evolved, take a closer look at the risk elements across different attack surfaces, and cover how device-level intelligence is an essential layer that can strengthen controls and reduce risk for retailers.&lt;/p&gt;
&lt;p&gt;&lt;span
      class=&quot;gatsby-resp-image-wrapper&quot;
      style=&quot;position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 600px; max-height: 650px;&quot;
    &gt;
      &lt;span
    class=&quot;gatsby-resp-image-background-image&quot;
    style=&quot;padding-bottom: 28.500000000000004%; position: relative; bottom: 0; left: 0; display: block;&quot;
  &gt;&lt;/span&gt;
  &lt;img
        class=&quot;gatsby-resp-image-image&quot;
        alt=&quot;Infographic showing &amp;#39;55% of retailers experienced organized retail crime in 2025&amp;#39; with orange and gray store icons. Source: The Impact of Retail Theft &amp;amp; Violence, 2025.&quot;
        title=&quot;Organized retail crime in 2025&quot;
        src=&quot;/static/6527e59c6b6f719460cef7cf4fcf299e/0a47e/organized-retail-crime.png&quot;
        srcset=&quot;/static/6527e59c6b6f719460cef7cf4fcf299e/e17e5/organized-retail-crime.png 400w,
/static/6527e59c6b6f719460cef7cf4fcf299e/0a47e/organized-retail-crime.png 600w&quot;
        sizes=&quot;(max-width: 600px) 100vw, 600px&quot;
        style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;&quot;
        loading=&quot;lazy&quot;
        decoding=&quot;async&quot;
      /&gt;
    &lt;/span&gt;&lt;/p&gt;
&lt;h2 id=&quot;bopis-the-bridge-between-digital-fraud-and-physical-product-loss&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#bopis-the-bridge-between-digital-fraud-and-physical-product-loss&quot; aria-label=&quot;bopis the bridge between digital fraud and physical product loss permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;BOPIS: The bridge between digital fraud and physical product loss&lt;/h2&gt;
&lt;p&gt;Buy online, pick up in store (BOPIS) has become a primary channel for organized retail crime (ORC). One study by the National Retail Federation found that more than half of all retailers had fraud incidents conducted by ORC groups in 2025.&lt;/p&gt;
&lt;p&gt;The BOPIS model removes the friction that once slowed fraud: A fraudster who obtains valid account credentials can place an order for high-value merchandise and collect it in person, often before the legitimate account holder is even aware of the breach.&lt;/p&gt;
&lt;p&gt;This happened in March 2026 at the home improvement retailer Lowe&apos;s. &lt;a href=&quot;https://www.attorneygeneral.gov/taking-action/attorney-general-sunday-announces-arrests-of-trio-for-takeovers-of-lowes-customers-accounts-in-5-counties/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Legitimate customer account credentials were stolen&lt;/a&gt; and used to place online orders, and a number of high-value construction materials were then picked up at locations across several counties in Pennsylvania. The scheme resulted in nearly $50,000 in losses before the criminals were apprehended.&lt;/p&gt;
&lt;p&gt;&lt;span
      class=&quot;gatsby-resp-image-wrapper&quot;
      style=&quot;position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 600px; max-height: 650px;&quot;
    &gt;
      &lt;span
    class=&quot;gatsby-resp-image-background-image&quot;
    style=&quot;padding-bottom: 25.25%; position: relative; bottom: 0; left: 0; display: block;&quot;
  &gt;&lt;/span&gt;
  &lt;img
        class=&quot;gatsby-resp-image-image&quot;
        alt=&quot;Infographic stating $112 billion in collective annual losses due to retail crime. Includes dollar symbols and source: Retail Theft &amp;amp; Violence, 2025.&quot;
        title=&quot;Collective annual losses to retail crime&quot;
        src=&quot;/static/ff5627cf6979d298d3099493f3659e0d/0a47e/annual-retail-losses.png&quot;
        srcset=&quot;/static/ff5627cf6979d298d3099493f3659e0d/e17e5/annual-retail-losses.png 400w,
/static/ff5627cf6979d298d3099493f3659e0d/0a47e/annual-retail-losses.png 600w&quot;
        sizes=&quot;(max-width: 600px) 100vw, 600px&quot;
        style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;&quot;
        loading=&quot;lazy&quot;
        decoding=&quot;async&quot;
      /&gt;
    &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;What makes the Lowe&apos;s case instructive is its structure: Because the credential layer was seen as authentic, the transactions and fulfillments that followed both assumed a completed digital order meant a legitimate customer.&lt;/p&gt;
&lt;p&gt;This is just one example of many. The National Retail Federation calculated that retail crime collectively &lt;a href=&quot;https://nrf.com/research/the-impact-of-retail-theft-violence-2025&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;costs retailers over $112 billion annually&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&quot;chargebacks-and-disputes-the-hidden-cost-of-operational-strain&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#chargebacks-and-disputes-the-hidden-cost-of-operational-strain&quot; aria-label=&quot;chargebacks and disputes the hidden cost of operational strain permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Chargebacks and disputes: The hidden cost of operational strain&lt;/h2&gt;
&lt;p&gt;Another exposure area for retailers is user account security and account takeovers (ATO).&lt;/p&gt;
&lt;p&gt;When you add chargebacks and dispute workflows, the true financial weight of retail ATO can be an invisible cost center that compounds the direct fraud loss by a factor of two to four times before the case is closed.&lt;/p&gt;
&lt;p&gt;&lt;span
      class=&quot;gatsby-resp-image-wrapper&quot;
      style=&quot;position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 600px; max-height: 650px;&quot;
    &gt;
      &lt;span
    class=&quot;gatsby-resp-image-background-image&quot;
    style=&quot;padding-bottom: 97.50000000000001%; position: relative; bottom: 0; left: 0; display: block;&quot;
  &gt;&lt;/span&gt;
  &lt;img
        class=&quot;gatsby-resp-image-image&quot;
        alt=&quot;Flowchart showing stages of account fraud: a purchase by a fraudster, shipment, dispute by the cardholder, bank chargeback, retailer notified.&quot;
        title=&quot;When an account is compromised&quot;
        src=&quot;/static/166639edcfed157f3b95ff4d6b4f32ab/0a47e/when-an-account-is-compromised.png&quot;
        srcset=&quot;/static/166639edcfed157f3b95ff4d6b4f32ab/e17e5/when-an-account-is-compromised.png 400w,
/static/166639edcfed157f3b95ff4d6b4f32ab/0a47e/when-an-account-is-compromised.png 600w&quot;
        sizes=&quot;(max-width: 600px) 100vw, 600px&quot;
        style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;&quot;
        loading=&quot;lazy&quot;
        decoding=&quot;async&quot;
      /&gt;
    &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;The mechanics of ATO are straightforward. A fraudster places an order using a compromised account&apos;s stored payment method. The order ships or is picked up. The legitimate cardholder notices the charge, contacts their bank, and files a dispute. The bank initiates a chargeback.&lt;/p&gt;
&lt;p&gt;When the retailer receives the chargeback notice, they faces a choice: Contest the dispute with evidence, or absorb the loss.&lt;/p&gt;
&lt;p&gt;Either path is expensive.&lt;/p&gt;
&lt;p&gt;Contesting a chargeback requires labor. A human has to analyze transaction records, account activity, and authentication logs, then assemble and report on the event within a tight response window.&lt;/p&gt;
&lt;p&gt;For retailers without clean and accurate device-level data, the dispute process can have little return on the effort expended. The customer&apos;s bank will often rule in favor of the cardholder, and the retailer eats the loss plus the chargeback fee, which typically runs $20 to $100 per transaction on top of the disputed amount.&lt;/p&gt;
&lt;p&gt;And the expense doesn&apos;t stop at this chargeback fee, either.&lt;/p&gt;
&lt;p&gt;High chargeback rates can trigger escalating consequences from payment processors. For omnichannel retailers who may process thousands or millions of transactions monthly, a fraud spike that pushes the chargeback ratio above a certain threshold can negatively impact the relationship with their payment platforms, and result in even more fees.&lt;/p&gt;
&lt;p&gt;Dispute work can also take time and attention from fraud teams that could otherwise be spent on proactive detection. Analysts pulled into chargeback responses are not building detection models, reviewing suspicious activity, or improving the accuracy of risk scoring.&lt;/p&gt;
&lt;p&gt;The overall operational strain is a compounding tax on the fraud team&apos;s effectiveness.&lt;/p&gt;
&lt;p&gt;&lt;span
      class=&quot;gatsby-resp-image-wrapper&quot;
      style=&quot;position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 766px; max-height: 650px;&quot;
    &gt;
      &lt;span
    class=&quot;gatsby-resp-image-background-image&quot;
    style=&quot;padding-bottom: 44.25%; position: relative; bottom: 0; left: 0; display: block;&quot;
  &gt;&lt;/span&gt;
  &lt;img
        class=&quot;gatsby-resp-image-image&quot;
        alt=&quot;Bar chart showing the increasing cost to retailers per dollar lost to fraud from $3.13 in 2019 to a projected $6.03 in 2029. Source: Statista.&quot;
        title=&quot;Cost to retailers per dollar lost to fraud (2019-2019)&quot;
        src=&quot;/static/296536d6b5ce5ebc4375afe9a71a296d/f7616/cost-to-retailers.png&quot;
        srcset=&quot;/static/296536d6b5ce5ebc4375afe9a71a296d/e17e5/cost-to-retailers.png 400w,
/static/296536d6b5ce5ebc4375afe9a71a296d/0a47e/cost-to-retailers.png 600w,
/static/296536d6b5ce5ebc4375afe9a71a296d/f7616/cost-to-retailers.png 766w,
/static/296536d6b5ce5ebc4375afe9a71a296d/c1b63/cost-to-retailers.png 1200w&quot;
        sizes=&quot;(max-width: 766px) 100vw, 766px&quot;
        style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;&quot;
        loading=&quot;lazy&quot;
        decoding=&quot;async&quot;
      /&gt;
    &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Research from the payments industry estimates that for every $1 in direct fraud loss, retailers incur over $4 in associated costs: chargeback fees, processing penalties, dispute labor, and customer service contacts. And this expense is only growing.&lt;/p&gt;
&lt;p&gt;The most effective place to break this chain is upstream of the transaction. A risky session that is flagged early — or even blocked before order placement — generates no chargeback, no dispute labor, no processing fee, and no customer remediation cost.&lt;/p&gt;
&lt;p&gt;Device-level signals can give this level of insight and eliminate the entire fraudulent cascade.&lt;/p&gt;
&lt;h2 id=&quot;trad-auth-isnt-enough&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#trad-auth-isnt-enough&quot; aria-label=&quot;trad auth isnt enough permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Trad-auth isn’t enough&lt;/h2&gt;
&lt;p&gt;The default playbook for retail account security — passwords, multi-factor authentication (MFA), and CAPTCHA challenges — was implemented for a simpler attack environment. It assumed that verifying what someone knows (a password) or owns (a phone for MFA) would reliably distinguish customers from fraudsters.&lt;/p&gt;
&lt;p&gt;That playbook is now outdated.&lt;/p&gt;
&lt;p&gt;Stolen credentials are cheap, widely available, and industrially harvested. Data breaches, phishing campaigns, and AI-powered social engineering methods produce billions of fresh username/password combinations. These flow into criminal marketplaces and become the raw material for credential stuffing attacks against retail login endpoints.&lt;/p&gt;
&lt;p&gt;AI has only accelerated this dynamic.&lt;/p&gt;
&lt;p&gt;Fraudsters now use AI to craft convincing phishing pages and emails that capture consumer credentials at scale. The same technology is used to write scripts that can defeat CAPTCHA challenges. Deepfakes are increasingly able to pass verification checks. MFA can also be bypassed via SIM-swapping, real-time phishing relays, and social engineering that tricks consumers into approving fraudulent authentication requests.&lt;/p&gt;
&lt;p&gt;The result: The credentials that once safely cleared a retailer&apos;s standard authentication stack are no longer a reliable signal of a legitimate customer.&lt;/p&gt;
&lt;p&gt;Those credentials can confirm that someone possesses correct login information. They say nothing about the device, the behavioral context, or the legitimacy of the session behind it.&lt;/p&gt;
&lt;h2 id=&quot;friction-vs-conversion-abandonment-happens&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#friction-vs-conversion-abandonment-happens&quot; aria-label=&quot;friction vs conversion abandonment happens permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Friction vs conversion: Abandonment happens&lt;/h2&gt;
&lt;p&gt;Adding more authentication steps is an often-intuitive way to try and strengthen credential flows and account security. But this carries real, measurable tradeoffs.&lt;/p&gt;
&lt;p&gt;Namely, the impact on conversion rates.&lt;a href=&quot;&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span
      class=&quot;gatsby-resp-image-wrapper&quot;
      style=&quot;position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 600px; max-height: 650px;&quot;
    &gt;
      &lt;span
    class=&quot;gatsby-resp-image-background-image&quot;
    style=&quot;padding-bottom: 23.75%; position: relative; bottom: 0; left: 0; display: block;&quot;
  &gt;&lt;/span&gt;
  &lt;img
        class=&quot;gatsby-resp-image-image&quot;
        alt=&quot;A statistic reads, &amp;quot;58% of shoppers abandon their transaction when encountering difficulties at login or verification.&amp;quot; Two shopping bag icons are displayed.&quot;
        title=&quot;Shopper cart abandonment: Impact stat #1&quot;
        src=&quot;/static/64e8d7bedbd4971887677457698157bb/0a47e/consumers-abandon-1.png&quot;
        srcset=&quot;/static/64e8d7bedbd4971887677457698157bb/e17e5/consumers-abandon-1.png 400w,
/static/64e8d7bedbd4971887677457698157bb/0a47e/consumers-abandon-1.png 600w&quot;
        sizes=&quot;(max-width: 600px) 100vw, 600px&quot;
        style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;&quot;
        loading=&quot;lazy&quot;
        decoding=&quot;async&quot;
      /&gt;
    &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span
      class=&quot;gatsby-resp-image-wrapper&quot;
      style=&quot;position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 600px; max-height: 650px;&quot;
    &gt;
      &lt;span
    class=&quot;gatsby-resp-image-background-image&quot;
    style=&quot;padding-bottom: 30.75%; position: relative; bottom: 0; left: 0; display: block;&quot;
  &gt;&lt;/span&gt;
  &lt;img
        class=&quot;gatsby-resp-image-image&quot;
        alt=&quot;A statistic reads, &amp;quot;1 in 4 consumers abandon a $100 cart when required to reset their password at checkout.&amp;quot;&quot;
        title=&quot;Shopping cart abandonment: Impact stat #2&quot;
        src=&quot;/static/227db005c0f0f4e51331ae0b9843035b/0a47e/consumers-abandon-3.png&quot;
        srcset=&quot;/static/227db005c0f0f4e51331ae0b9843035b/e17e5/consumers-abandon-3.png 400w,
/static/227db005c0f0f4e51331ae0b9843035b/0a47e/consumers-abandon-3.png 600w&quot;
        sizes=&quot;(max-width: 600px) 100vw, 600px&quot;
        style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;&quot;
        loading=&quot;lazy&quot;
        decoding=&quot;async&quot;
      /&gt;
    &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://baymard.com/blog/current-state-of-checkout-ux&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span
      class=&quot;gatsby-resp-image-wrapper&quot;
      style=&quot;position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 600px; max-height: 650px;&quot;
    &gt;
      &lt;span
    class=&quot;gatsby-resp-image-background-image&quot;
    style=&quot;padding-bottom: 30.75%; position: relative; bottom: 0; left: 0; display: block;&quot;
  &gt;&lt;/span&gt;
  &lt;img
        class=&quot;gatsby-resp-image-image&quot;
        alt=&quot;A statistic reads, &amp;quot;1 in 5 consumers abandon checkout when asked to verify or reset their password at checkout&amp;quot;&quot;
        title=&quot;Shopping cart abandonment: Impact stat #3&quot;
        src=&quot;/static/9be576a7410ba1786b7c37f2f2e95d1c/0a47e/consumers-abandon-2.png&quot;
        srcset=&quot;/static/9be576a7410ba1786b7c37f2f2e95d1c/e17e5/consumers-abandon-2.png 400w,
/static/9be576a7410ba1786b7c37f2f2e95d1c/0a47e/consumers-abandon-2.png 600w&quot;
        sizes=&quot;(max-width: 600px) 100vw, 600px&quot;
        style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;&quot;
        loading=&quot;lazy&quot;
        decoding=&quot;async&quot;
      /&gt;
    &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Every added friction point can cause shoppers to not follow through on their purchase.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://fidoalliance.org/research-findings-consumer-trends-and-attitudes-towards-authentication-methods/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;58% of shoppers abandon their transaction&lt;/a&gt; when they encounter difficulties at the login or verification step. &lt;a href=&quot;https://www.beyondidentity.com/resource/are-password-resets-costing-your-company-survey&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;1 in 4 consumers abandon a $100 cart&lt;/a&gt; when required to reset their password. &lt;a href=&quot;https://baymard.com/blog/current-state-of-checkout-ux&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;1 in 5 consumers abandon checkout&lt;/a&gt; when asked to verify or reset their password.&lt;a href=&quot;&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;For omnichannel retailers whose most valuable customers are loyalty members, adding friction can frustrate those customers. Every unnecessary challenge step is an invitation to abandon the cart, seek an alternative, or disengage from the loyalty program entirely.&lt;/p&gt;
&lt;p&gt;It is a tax on retention, reputation, and lifetime value.&lt;/p&gt;
&lt;h2 id=&quot;false-positives-and-the-grey-space-of-outdated-risk-indicators&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#false-positives-and-the-grey-space-of-outdated-risk-indicators&quot; aria-label=&quot;false positives and the grey space of outdated risk indicators permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;False positives and the grey space of outdated risk indicators&lt;/h2&gt;
&lt;p&gt;Static and rule-based fraud detection systems that evaluate traffic against fixed risk thresholds can generate high false positive rates. Every false positive represents a declined transaction, an unnecessary step-up challenge, or a blocked account that incurs customer service costs and retention damage. And every one is a challenge to analyze, and an added strain on fraud teams.&lt;/p&gt;
&lt;p&gt;Traditional visitor recognition methods compound this problem. Cookie-based identification fails when users switch browsers, clear their cache, reset settings, or use incognito mode.&lt;/p&gt;
&lt;p&gt;The widespread use of VPNs, which may have been seen as an indicator of risk before, no longer holds the same weight — as privacy-conscious legitimate users now may trigger the same VPN usage signal.&lt;/p&gt;
&lt;p&gt;&lt;span
      class=&quot;gatsby-resp-image-wrapper&quot;
      style=&quot;position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 766px; max-height: 650px;&quot;
    &gt;
      &lt;span
    class=&quot;gatsby-resp-image-background-image&quot;
    style=&quot;padding-bottom: 35%; position: relative; bottom: 0; left: 0; display: block;&quot;
  &gt;&lt;/span&gt;
  &lt;img
        class=&quot;gatsby-resp-image-image&quot;
        alt=&quot;Bar graph showing the growth of VPN usage between 2024 and 2025 with three line items for desktop browser, other browser, and mobile (browser or app)&quot;
        title=&quot;Device intelligence data from 2025: VPN usage detections&quot;
        src=&quot;/static/3dc7d3cb6d78700a17a627a13fcfc768/f7616/FDIR2026_VPN.png&quot;
        srcset=&quot;/static/3dc7d3cb6d78700a17a627a13fcfc768/e17e5/FDIR2026_VPN.png 400w,
/static/3dc7d3cb6d78700a17a627a13fcfc768/0a47e/FDIR2026_VPN.png 600w,
/static/3dc7d3cb6d78700a17a627a13fcfc768/f7616/FDIR2026_VPN.png 766w,
/static/3dc7d3cb6d78700a17a627a13fcfc768/c65fa/FDIR2026_VPN.png 1434w&quot;
        sizes=&quot;(max-width: 766px) 100vw, 766px&quot;
        style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;&quot;
        loading=&quot;lazy&quot;
        decoding=&quot;async&quot;
      /&gt;
    &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;In our &lt;a href=&quot;https://fingerprint.com/try/device-intelligence-report-2026/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;2026 Device Intelligence Report&lt;/a&gt;, data from across 23 billion device identification events in 2025 showed &lt;a href=&quot;https://fingerprint.com/blog/device-intelligence-report-2026/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;roughly 1 in 5 involved VPN usage&lt;/a&gt;. For Chromium-based desktop browsers, that climbs to 1 in 3. Even on mobile, 13% of identification events involve VPN routing. All of these are up from the prior year, demonstrating how VPNs are becoming a routine part of internet traffic.&lt;/p&gt;
&lt;p&gt;Using VPN routing as a static risk indicator could spike false positive rates unnecessarily.&lt;/p&gt;
&lt;p&gt;Said another way: A fraud detection layer that is focused on any one indicator in isolation may throw off positive risk alerts for legitimate customers. Any detection system that is simultaneously too permissive for real threats and too aggressive toward real customers is a grey space that fraud teams don’t want to occupy.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://fingerprint.com/blog/suspect-score-ai-recommendations/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Dynamic risk scoring&lt;/a&gt; that can be weighted and tuned to specific traffic patterns and business needs can be a huge difference maker for companies trying to strengthen account security — without impacting conversion rates.&lt;/p&gt;
&lt;h2 id=&quot;loyalty-accounts-as-targets-part-1-fraudsters-behind-a-tree-rubbing-their-hands-together&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#loyalty-accounts-as-targets-part-1-fraudsters-behind-a-tree-rubbing-their-hands-together&quot; aria-label=&quot;loyalty accounts as targets part 1 fraudsters behind a tree rubbing their hands together permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Loyalty accounts as targets, part 1: Fraudsters behind a tree, rubbing their hands together  &lt;/h2&gt;
&lt;p&gt;Retail loyalty programs are designed around a simple premise: Concentrate relationship value into a single account, and the customer who holds that account will spend more, return more often, and cost less to serve.&lt;/p&gt;
&lt;p&gt;For large-format retailers like Lowe&apos;s who serve both everyday consumers and professionals, their loyalty accounts are a key commercial relationship, as well.&lt;/p&gt;
&lt;p&gt;This concentration of value is precisely what makes loyalty accounts the primary target layer for retail account fraud, and it’s why &lt;strong&gt;l&lt;/strong&gt;oyalty program fraud has emerged as one of the fastest-growing fraud categories in retail.&lt;/p&gt;
&lt;p&gt;The economic logic is straightforward.&lt;/p&gt;
&lt;p&gt;Loyalty accounts hold stored payment methods, redeemable points balances, gift card credits, and purchase history that can be monetized — either through direct redemption or by reselling access to this valuable account information.&lt;/p&gt;
&lt;h2 id=&quot;loyalty-accounts-as-targets-part-2-its-like-the-opposite-of-a-flywheel&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#loyalty-accounts-as-targets-part-2-its-like-the-opposite-of-a-flywheel&quot; aria-label=&quot;loyalty accounts as targets part 2 its like the opposite of a flywheel permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Loyalty accounts as targets, part 2: It’s like the opposite of a flywheel&lt;/h2&gt;
&lt;p&gt;When a loyalty account is compromised, the financial damage compounds quickly. Beyond what may be a single fraudulent transaction, the impact can include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Direct fraud loss&lt;/strong&gt; on orders placed with stored payment methods&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Chargeback processing fees&lt;/strong&gt; and dispute costs&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Customer service volume&lt;/strong&gt; for account recovery&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Potential regulatory exposure&lt;/strong&gt; for the data breach&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Customer relationship damage&lt;/strong&gt; from the experience itself&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Customers who experience fraud on a platform are significantly more likely to churn, reduce purchase frequency, and disengage from loyalty programs regardless of how well the retailer handles the recovery. The true cost of a compromised loyalty account is not a single transaction — it is the customer lifetime value (CLV) of the person who is walking away.&lt;/p&gt;
&lt;p&gt;This is the core reason account fraud in retail is not a fraud team problem in isolation.&lt;/p&gt;
&lt;p&gt;It is a growth problem.&lt;/p&gt;
&lt;h2 id=&quot;loyalty-accounts-as-targets-part-3-okay-spill-the-loyal-tea&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#loyalty-accounts-as-targets-part-3-okay-spill-the-loyal-tea&quot; aria-label=&quot;loyalty accounts as targets part 3 okay spill the loyal tea permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Loyalty accounts as targets, part 3: Okay, spill the loyal-tea&lt;/h2&gt;
&lt;p&gt;Loyalty programs are some of the highest value accounts in retail. &lt;a href=&quot;https://www.rivo.io/blog/loyalty-program-statistics&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Members may outspend non-members by a factor of two to five times&lt;/a&gt;, depending on the program tier, with greater frequency, higher average order values, and lower acquisition cost per purchase.&lt;/p&gt;
&lt;p&gt;It&apos;s why CLV is a crucial metric for many retailers. It&apos;s also what makes these accounts attractive as fraud targets, and it is exactly where the friction-fraud tension becomes a strategic problem, not just an operational one.&lt;/p&gt;
&lt;p&gt;The conventional response to account takeover risk is to add more authentication requirements: password resets, OTP verification before reward redemption, step-up challenges. Each of these controls is individually defensible. Collectively, they create a user experience that repeatedly asks the most valued customers to prove they are who they say they are.&lt;/p&gt;
&lt;p&gt;Which, in turn, frustrates those highest-value members.&lt;/p&gt;
&lt;p&gt;If they are a member with a high balance and stored payment methods, numerous forced authentication steps during redemption is not a minor inconvenience — it starts to send them a message that their member relationship is more adversarial than built on trust. Those frequent visits, habitual purchases, and positive brand impressions may start to erode.&lt;/p&gt;
&lt;p&gt;Instead of becoming the highest contributors to the CLV metric, frustrated loyalty members may abandon transactions, even abandon the loyalty program entirely.&lt;/p&gt;
&lt;p&gt;Yet the flip side can be equally acute: Fraud events that impact loyalty members can be highly damaging to that relationship, too.&lt;/p&gt;
&lt;p&gt;&lt;span
      class=&quot;gatsby-resp-image-wrapper&quot;
      style=&quot;position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 600px; max-height: 650px;&quot;
    &gt;
      &lt;span
    class=&quot;gatsby-resp-image-background-image&quot;
    style=&quot;padding-bottom: 30.75%; position: relative; bottom: 0; left: 0; display: block;&quot;
  &gt;&lt;/span&gt;
  &lt;img
        class=&quot;gatsby-resp-image-image&quot;
        alt=&quot;Illustration of four user icons, one in orange with an &amp;#39;x&amp;#39;, highlighting &amp;quot;1 in 4&amp;quot; loyalty members cancel after a single account compromise.&quot;
        title=&quot;Loyalty members will cancel after a single account compromise&quot;
        src=&quot;/static/61e50d8f3b8c28f789e1db6a915eb19a/0a47e/loyalty-cancel.png&quot;
        srcset=&quot;/static/61e50d8f3b8c28f789e1db6a915eb19a/e17e5/loyalty-cancel.png 400w,
/static/61e50d8f3b8c28f789e1db6a915eb19a/0a47e/loyalty-cancel.png 600w&quot;
        sizes=&quot;(max-width: 600px) 100vw, 600px&quot;
        style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;&quot;
        loading=&quot;lazy&quot;
        decoding=&quot;async&quot;
      /&gt;
    &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Members affected by fraud will experience a breach of trust with the brand that stored and presumably protected their data, payment methods, and rewards history.&lt;/p&gt;
&lt;p&gt;Even when done well, remediation processes take time and require multiple customer service engagements — and still generate frustration. &lt;a href=&quot;https://www.rivo.io/blog/fraud-detection-loyalty-programs-statistics&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;A quarter of loyalty members will cancel their memberships following a single account compromise&lt;/a&gt; after experiencing fraud, regardless of how effectively the brand responds.&lt;/p&gt;
&lt;p&gt;This puts fraud defense for loyalty programs in a bind. Aggressive fraud controls erode CLV through friction and abandonment. Meanwhile, insufficient controls damage CLV from the other side, through fraud events and the trust collapse that follows.&lt;/p&gt;
&lt;p&gt;The path out of this bind is not more frequent password resets or CAPTCHAs. It is a &lt;a href=&quot;https://fingerprint.com/products/fingerprint-pro/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;device-level intelligence layer&lt;/a&gt; that is accurate enough to identify risky activity without triggering friction for legitimate and loyal customers.&lt;/p&gt;
&lt;p&gt;The member is invisibly recognized and served a seamless site experience. The fraudster is flagged as high risk and can be dealt with in a separate path.&lt;/p&gt;
&lt;h2 id=&quot;what-device-intelligence-does-persistent-accurate-risk-signals-for-stopping-retail-account-fraud&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#what-device-intelligence-does-persistent-accurate-risk-signals-for-stopping-retail-account-fraud&quot; aria-label=&quot;what device intelligence does persistent accurate risk signals for stopping retail account fraud permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;What device intelligence does: Persistent, accurate risk signals for stopping retail account fraud&lt;/h2&gt;
&lt;p&gt;The best solution for fraud detection across retail accounts is improving the quality of the risk signal at the device level.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://fingerprint.com/products/fingerprint-pro/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Device intelligence&lt;/a&gt; processes 100+ browser, network, and device attributes — things like hardware configuration, installed fonts, browser behavior, network characteristics, and timing patterns — to generate a persistent, highly accurate identifier for every visitor.&lt;/p&gt;
&lt;p&gt;Unlike cookie-based tracking, this visitor ID (also known as device fingerprint) cannot be cleared or blocked. It persists over time and across sessions, even survives cookie deletion, browser resets, and incognito mode.&lt;/p&gt;
&lt;p&gt;This persistent ID empowers a new approach to fraud defense, one that can&apos;t be evaded in a single point in time. Initial visits, logins, transactions, and fulfillment can be tied to known devices and give retail more security across the entire chain.&lt;/p&gt;
&lt;p&gt;If a new device accesses a trusted loyalty account, the action can flagged and analyzed for risk. A known fraudster with stolen credentials can be spotted earlier, even if it&apos;s their first visit, by correlating device activity to known risk patterns.&lt;/p&gt;
&lt;p&gt;When fraud teams add a more advanced set of &lt;a href=&quot;https://fingerprint.com/products/smart-signals/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Smart Signals&lt;/a&gt; — such as browser tampering, bot activity, timezone mismatches, and behavioral anomalies — they get even more detailed risk assessment insights for their fraud engines. Device-level data can give greater depth and clarity for dispute defense.&lt;/p&gt;
&lt;p&gt;Smart Signal data can also be dynamically calibrated and weighted, rather than applied as a uniform rule. High-risk sessions trigger step-up challenges or blocking. Normal sessions pass through without friction.&lt;/p&gt;
&lt;h2 id=&quot;apply-device-intelligence-liberally-in-these-four-places&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#apply-device-intelligence-liberally-in-these-four-places&quot; aria-label=&quot;apply device intelligence liberally in these four places permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Apply device intelligence liberally in these four places&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Account login.&lt;/strong&gt; Flag first-time device access to high-value accounts — those with stored payment methods, high loyalty balances, or Pro tier status — for step-up authentication, while allowing recognized devices to log in without interruption. This approach concentrates friction where the risk is highest, not across the entire customer population.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;BOPIS order placement.&lt;/strong&gt; Perform device-level verification at the point of digital order confirmation, not at store pickup. This closes the execution gap that ORC rings exploit, where a confirmed digital order has already allocated inventory and charged a payment method before any in-store check occurs. Fraud stopped at order placement stops the entire downstream impact.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Guest checkout.&lt;/strong&gt; Persistent device identification links checkout sessions across attempts from the same device, enabling the detection of repeat fraud attempts. A guest checkout that appears on a device with a history of chargebacks or suspicious activity can be flagged for review. First-time buyers with no historical activity can be served seamless checkouts.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;As an accurate signal input to ML models.&lt;/strong&gt; Device data improves the accuracy of machine learning fraud models by providing highly accurate session-level context. The combination of device history, behavioral signals, and Smart Signals enables models to reduce false-positive rates while learning, adapting, and improving detection of novel attack patterns. More accurate models mean less friction for legitimate customers and fewer fraudulent sessions that slip through.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;retailers-ready-to-reduce-risk-️-device-intelligence&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#retailers-ready-to-reduce-risk-%EF%B8%8F-device-intelligence&quot; aria-label=&quot;retailers ready to reduce risk ️ device intelligence permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Retailers ready to reduce risk ♥️ device intelligence  &lt;/h2&gt;
&lt;p&gt;As loyalty programs scale and omnichannel fulfillment expands, the account fraud problem in retail will only become more acute. Traditional auth controls will continue to be defeated by novel and sophisticated attacks. Rule-based systems will continue to produce the false positives that damage conversion and retention. And BOPIS and loyalty programs will continue to be susceptible avenues of attack.&lt;/p&gt;
&lt;p&gt;The retailers who strengthen their defenses won’t do so by adding more friction for all customers. They will do it by getting the device signal right, so they can recognize and distinguish legitimate customers from the fraudulent actors trying to stay hidden.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The &lt;a href=&quot;https://fingerprint.com/products/fingerprint-pro/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Fingerprint device intelligence platform&lt;/a&gt; is purpose-built to solve the accuracy and friction challenge at the core of retail fraud prevention.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;It is not a replacement for existing fraud tools and authentication flows. It is an added layer of signal data that makes every other layer in your fraud engine more accurate.&lt;/p&gt;
&lt;p&gt;We give fraud teams unparalleled breadth and depth of signals in a single API response, in milliseconds. By analyzing 100+ device and browser signals, Fingerprint generates a unique visitor identifier that persists across sessions, and lasts for months, not days.&lt;/p&gt;
&lt;p&gt;For retail fraud and product teams, Fingerprint device intelligence can reduce risk for the business, reduce friction for loyal customers, and reduce the losses and operational strain that come from fraud.&lt;/p&gt;</content:encoded><tags>account takeover, ecommerce fraud</tags></item><item><title><![CDATA[What we've been building: AI detection, new Smart Signals, and more]]></title><description><![CDATA[A roundup of recent Fingerprint releases covering AI Agent and AI Assistant Detection, Rare Device Detection, iOS Simulator Detection, Suspect Score AI recommendations, and the new MCP Server.]]></description><link>/blog/product-roundup-ai-detection-smart-signals/</link><guid isPermaLink="false">/blog/product-roundup-ai-detection-smart-signals/</guid><pubDate>Thu, 04 Jun 2026 11:50:00 GMT</pubDate><enclosure url="https://fingerprint.com/static/9aeab1202ef054fc358952e6e97bea51/q1-product-roundup.png" length="0" type="image/png"/><content:encoded>&lt;p&gt;You know this by now: Automated traffic is no longer just bots trying to break things. AI agents are booking flights. AI assistants are crawling your content. AI is doing all sorts of things across mobile and web traffic. And your fraud stack needs to tell the difference between threats and normal activity.&lt;/p&gt;
&lt;p&gt;Here&apos;s a look at what we&apos;ve shipped recently to help you stay ahead.&lt;/p&gt;
&lt;h2 id=&quot;ai-agent-detection-and-ai-assistant-detection&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#ai-agent-detection-and-ai-assistant-detection&quot; aria-label=&quot;ai agent detection and ai assistant detection permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;AI Agent Detection and AI Assistant Detection&lt;/h2&gt;
&lt;p&gt;We launched two new detection capabilities that give you a clear picture of the AI traffic hitting your application.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://fingerprint.com/blog/product-update-ai-agent-detection/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;AI Agent Detection&lt;/a&gt; tells you when an AI model is driving a real browser session on behalf of a user, verified with 100% certainty via cryptographic signing from providers such as OpenAI, AWS AgentCore, and Browserbase.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://fingerprint.com/blog/product-update-ai-assistant-detection/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;AI Assistant Detection&lt;/a&gt; (now in beta) works at the HTTP layer, verifying whether requests from ChatGPT, Gemini, or Claude are legitimate or spoofed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;new-smart-signals-rare-device-detection-and-ios-simulator-detection&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#new-smart-signals-rare-device-detection-and-ios-simulator-detection&quot; aria-label=&quot;new smart signals rare device detection and ios simulator detection permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;New Smart Signals: Rare Device Detection and iOS Simulator Detection&lt;/h2&gt;
&lt;p&gt;We added two brand-new Smart Signals that give you sharper risk context to make better decisions.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://fingerprint.com/blog/product-update-rare-device-detection-ios-simulator-detection/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Rare Device Detection&lt;/a&gt; evaluates device attribute combinations against Fingerprint&apos;s global traffic and tells you not just whether a device is rare, but how rare — including setups never-before-seen in our 14-day reference window.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://fingerprint.com/blog/product-update-rare-device-detection-ios-simulator-detection/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;iOS Simulator Detection&lt;/a&gt; flags visits from simulated environments rather than real devices, giving you a reliable non-genuine device signal you can feed directly into your risk engine.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We also expanded developer tools detection to mobile, bringing a previously web-only signal to your native app coverage.&lt;/p&gt;
&lt;h2 id=&quot;suspect-score-ai-recommendations&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#suspect-score-ai-recommendations&quot; aria-label=&quot;suspect score ai recommendations permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Suspect Score AI recommendations&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://fingerprint.com/blog/suspect-score-ai-recommendations/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Suspect Score&lt;/a&gt; now learns from your own labeled fraud data. Upload your data to the dashboard and get AI-recommended, optimized signal weightings tailored to your specific traffic mix, without manual tuning or guesswork. You keep full visibility into how scores are constructed and full control over whether to apply the recommendations.&lt;/p&gt;
&lt;h2 id=&quot;fingerprint-mcp-server&quot; style=&quot;position:relative;&quot;&gt;&lt;a href=&quot;#fingerprint-mcp-server&quot; aria-label=&quot;fingerprint mcp server permalink&quot; class=&quot;anchor before&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; focusable=&quot;false&quot; height=&quot;16&quot; version=&quot;1.1&quot; viewBox=&quot;0 0 16 16&quot; width=&quot;16&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;Fingerprint MCP Server&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://fingerprint.com/blog/introducing-fingerprint-mcp-server/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Fingerprint MCP Server&lt;/a&gt; turns your device intelligence data into a layer that you can query directly. Fraud analysts can ask natural language questions — &quot;Are these accounts related?&quot; &quot;Why did suspicious transactions spike on checkout?&quot; — and get answers in seconds instead of hours of manual investigation. Developers can connect AI coding environments, such as Claude Code or Cursor, directly to Fingerprint to build and ship fraud-prevention features faster.&lt;/p&gt;
&lt;p&gt;See it in action:&lt;/p&gt;
&lt;iframe style=&quot;aspect-ratio: 16 / 9; border-radius: 8px; width: 100%;&quot; src=&quot;https://www.youtube.com/embed/93mWU8O_cbo?si=ni2_0tUrHEUFuyA8&quot; title=&quot;YouTube video player&quot; frameborder=&quot;0&quot; allow=&quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&quot; referrerpolicy=&quot;strict-origin-when-cross-origin&quot; allowfullscreen&gt;&lt;/iframe&gt;
&lt;p&gt;Have questions about any of these? &lt;a href=&quot;https://fingerprint.com/support/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Reach out to us&lt;/a&gt; for answers, demos, and early access where applicable&lt;/p&gt;</content:encoded><tags>product-updates, ai agents, smart-signals</tags></item></channel></rss>