Table of contents
- Fraud is not one thing; the main types of fraud target identity, payments, accounts and businesses in distinct ways that call for different defences.
- Identity fraud, including synthetic identity fraud, uses stolen or fabricated identities to open accounts or obtain credit, and it is the root of much downstream fraud.
- Payment and card fraud exploit stolen card or account details to make unauthorised transactions.
- Account takeover fraud hijacks a legitimate user's existing account, often through phishing or stolen credentials.
- Authorised push payment fraud tricks victims into sending money themselves, which makes it especially hard to reverse.
- Business-targeted fraud, such as business email compromise and invoice fraud, exploits trust and process rather than technology, and strong verification is the common thread that limits most of these.
The types of fraud are the distinct categories of deception used to obtain money, assets or advantage dishonestly, spanning identity and synthetic identity fraud, payment and card fraud, account takeover, authorised push payment fraud, and business fraud. Each type exploits a different weakness, so understanding the categories is the starting point for defending against them.
TL;DR
Fraud comes in distinct types, each exploiting a different weakness. Identity fraud uses stolen identities, and synthetic identity fraud fabricates new ones, to open accounts or obtain credit. Payment and card fraud misuse stolen details for unauthorised transactions. Account takeover hijacks a real user's existing account. Authorised push payment fraud tricks victims into sending money themselves. Business fraud, such as business email compromise and invoice fraud, exploits trust and process. Because so many categories of fraud start with a fake or stolen identity, strong identity verification is the single most effective control, alongside monitoring and user education tailored to each category.
What are the main types of fraud?
The main types of fraud are the recognised categories of dishonest schemes used to obtain money, assets or advantage. Broadly, they fall into a few families: identity-based fraud, payment fraud, account-based fraud, social-engineering fraud, and fraud aimed at businesses. Each exploits a different vulnerability, which is why no single control stops all of them and why understanding the categories matters before choosing defences.
The categories also connect. A stolen or fabricated identity, the product of identity fraud, is frequently the raw material for the others, used to open the account that will commit payment fraud or receive the proceeds of a scam. That is why identity sits at the centre of most fraud prevention: get identity right and you remove the foundation many types of fraud are built on. The sections below define the most important categories and how each is detected, building on the verification standards described in our KYC software guide.
What is identity fraud?
Identity fraud is the use of someone else's personal information, without their consent, to impersonate them for financial gain, typically to open accounts, obtain credit, or access services in the victim's name. It relies on stolen identity data, names, dates of birth, identification numbers and documents, often obtained through data breaches, phishing or the purchase of stolen credentials on illicit markets.
Identity fraud is foundational because it enables so much else: an account opened with a stolen identity becomes a vehicle for payment fraud, laundering or scams. Defending against it is the core purpose of identity verification, confirming that the person presenting an identity genuinely is that person. Modern defences read the chip in identity documents rather than relying on an easily faked photo, and use liveness to confirm a real, live person, which is increasingly important as generative tools make fake images convincing, the subject of our guide to deepfake detection.
What is synthetic identity fraud?
Synthetic identity fraud is a distinct and fast-growing variant in which the fraudster does not steal a whole real identity but fabricates a new one, often by combining real and fake data, for example a real identification number with a fabricated name and history. The synthetic identity is then nurtured over time, building a credit and transaction footprint until it can be used to obtain significant credit and disappear.
What makes synthetic identity fraud so difficult is that there is often no real victim to report it, and the fabricated identity can look legitimate on paper for months or years. Traditional checks that simply confirm data points exist can be fooled, because the individual data may be real even though the person is not. Defeating it requires verification that ties the claimed identity to a real, live human being, through chip-based document checks and liveness, rather than merely confirming that a set of details matches a record somewhere. It is a clear example of why among the types of fraud, identity verification quality, not just data matching, is decisive.
What are the main types of payment fraud?
Payment fraud covers the types of fraud that misuse payment instruments or systems to move money without authorisation. The most familiar is card fraud, where stolen card details are used for unauthorised purchases, whether the physical card is present or, far more commonly now, in card-not-present online transactions. Related forms include the use of stolen bank account details for unauthorised transfers and direct debits.
Payment fraud is often the endpoint of another type of fraud: the card or account details are obtained through a data breach, phishing or account takeover, then monetised. Defences combine transaction monitoring that flags anomalous spending, authentication that confirms the legitimate customer is behind a transaction, and controls that limit the damage from stolen details. Because payment fraud so often depends on an account opened or taken over using a compromised identity, strong onboarding verification and account security are upstream controls that reduce it, alongside the payment-specific monitoring that catches it in the act.
What is account takeover fraud?
Account takeover fraud is the hijacking of a legitimate customer's existing account by an unauthorised party. Rather than opening a new fraudulent account, the fraudster gains access to a real one, typically through stolen credentials, phishing, credential-stuffing using passwords leaked in breaches, or social engineering, and then drains funds, makes unauthorised transactions, or exploits the account's standing.
Account takeover is particularly damaging because the account is genuine, so the activity can initially look legitimate and slip past controls tuned to spot fake accounts. Defences focus on authentication and behaviour: strong, phishing-resistant authentication to make credentials harder to misuse, and monitoring that detects when a real account suddenly behaves out of character, a new device, an unusual location, a change of contact details followed by a large transfer. Reducing the value of stolen credentials, and confirming the person behind a sensitive action is really the account holder, are the core defences against this type of fraud.
What is authorised push payment (APP) fraud?
Authorised push payment fraud, or APP fraud, is a social-engineering type of fraud in which the victim is tricked into authorising a payment themselves, sending money from their own account to an account controlled by the fraudster. Because the victim authorises the transaction, it can be far harder to detect and reverse than an unauthorised one. Common variants include impersonation scams, where the fraudster poses as a bank, a supplier, a government body or even a family member, and purchase scams for goods that never arrive.
APP fraud is especially challenging because the customer's own credentials and authentication are used legitimately, so the payment looks authorised because it is. Defences therefore lean on detecting the hallmarks of a scam in progress, unusual payees, out-of-pattern payments, and behavioural signals, and increasingly on verifying that the account being paid genuinely belongs to who the payer thinks, the role of account and identity verification in the payment chain. Because the fraudster still needs an account to receive the funds, strong verification of that receiving account is one of the more effective systemic controls.
What is business fraud?
Business fraud covers the types of fraud aimed at organisations rather than individuals. The most prominent is business email compromise, where a fraudster impersonates an executive, supplier or trusted party, often by compromising or spoofing an email account, to trick an employee into transferring funds or changing payment details. Invoice fraud, where a genuine-looking but fraudulent invoice or amended bank details divert a legitimate payment, is a closely related and very common variant.
These schemes exploit trust and process rather than technology, which is what makes them dangerous: they can bypass technical controls by manipulating a person with legitimate access. Related business-targeted fraud includes the use of fraudulent or misrepresented companies to obtain credit or services, which is where verifying the business itself, through KYB verification and resolving who really owns and controls a counterparty, becomes a defence. Strong verification of both the people and the businesses you deal with, combined with robust payment-change controls, is the common thread that limits most business fraud.
How do you prevent the main types of fraud?
No single control stops every type of fraud, but a few principles cover most of them. The most powerful is strong identity verification, because so many types of fraud, identity fraud, synthetic identity fraud, account opening for payment fraud, receiving accounts for scams, depend on a fake or stolen identity. Verifying identity against a real, live person, using chip-based document checks and liveness rather than easily faked photos, removes the foundation many schemes rely on.
Around that sit complementary defences: strong, phishing-resistant authentication to blunt account takeover; transaction monitoring to catch anomalous payments and layering; business verification to expose fraudulent or misrepresented companies; and user education to counter the social engineering behind APP fraud and business email compromise. The common thread is knowing who you are really dealing with, at onboarding and continuously, and holding that identity data safely so it does not itself become the breach that fuels the next wave of fraud, the logic behind decentralised, sharded identity infrastructure. Get identity right and hold it safely, and the majority of fraud becomes far harder to commit.
The bottom line
Fraud is a family of distinct schemes, identity and synthetic identity fraud, payment and card fraud, account takeover, authorised push payment fraud, and business fraud like email compromise and invoice fraud, each exploiting a different weakness. The unifying insight is that most of them start with a fake or stolen identity, or the abuse of a real one, which is why strong identity verification is the highest-leverage defence, backed by authentication, monitoring, business verification and user education matched to each category. Know who you are really dealing with, verify it against a real person, and hold that data safely, and the foundation the majority of fraud is built on simply is not there.
Related resources
- Deepfake detection in KYC
- KYC Software: 2026 Buyer's Guide
- KYB verification: how it works
- What is a KYC passport?
- Zyphe decentralised KYC