Identity fraud rarely begins and ends with a single stolen document. It is usually a connected process in which criminals collect identity data, create convincing evidence, pass verification controls, gain account access, and convert that access into financial or operational value.
Understanding this fraud lifecycle helps digital platforms place controls at the right points. Face++ supports a layered identity security strategy by combining face comparison, liveness detection, biometric search, and risk signals across onboarding and account use.
1. Identity Data Is Collected
The first stage is obtaining personal information. Fraudsters may acquire names, dates of birth, addresses, document numbers, portraits, login credentials, and phone numbers through:
- Data breaches
- Phishing websites
- Social engineering
- Malware and credential theft
- Public social media profiles
- Stolen or leaked identity documents
- Illicit data marketplaces
A complete identity package is more valuable than an isolated credential because it can support account opening, password recovery, SIM replacement, or customer service impersonation.
Platforms should therefore avoid treating correct personal data as proof of identity. A fraudster may know every requested detail without being the legitimate person.
2. Stolen Data Is Turned into Fraudulent Evidence
After collecting identity data, attackers prepare evidence that can pass digital verification. Common techniques include:
- Editing names, dates, portraits, or document numbers
- Combining information from multiple identities
- Displaying document images on another screen
- Printing and recapturing stolen document images
- Generating synthetic identity documents
- Using face swaps or AI-generated portraits
- Creating deepfake video for biometric checks
Some fraudulent documents remain highly readable. OCR may accurately extract every field while the underlying document is still manipulated, synthetic, or presented by the wrong person.
This is why document extraction should be connected to authenticity analysis, consistency checks, face verification, and liveness detection.

3. Fraudsters Attempt to Pass Onboarding
The next objective is to open an account using stolen, manipulated, or synthetic identity evidence.
An attacker may submit a genuine document belonging to someone else and then attempt to defeat the facial check. Other attackers alter the document portrait to match their own face or inject manipulated video directly into the verification session.
A layered onboarding workflow should answer several separate questions:
- Is the submitted document readable?
- Are its fields internally consistent?
- Does the document show signs of manipulation or recapture?
- Does the current face match the document portrait?
- Is the biometric sample from a genuine live person?
- Are the device and session signals consistent with legitimate use?
Face++ face comparison can provide a 1:1 similarity assessment between the document portrait and the current user. Liveness detection adds genuine-presence analysis to help identify photos, replays, masks, deepfakes, and suspicious capture patterns.
4. Attackers May Target Existing Accounts Instead
Creating a new account is not always necessary. Criminals may compromise an existing account through leaked passwords, phishing, session theft, SIM swapping, malware, or recovery abuse.
Once inside, they may attempt to:
- Change the registered email or phone number
- Reset security credentials
- Add a new payment method or beneficiary
- Disable security notifications
- Withdraw money or transfer assets
- Access stored personal information
- Use the trusted account to defraud other users
A successful password login should not automatically establish that the legitimate account owner is present. Device changes, unusual behavior, account recovery attempts, and high-risk transactions can all justify additional identity verification.
Face++ face verification and liveness detection can serve as step-up controls when account risk changes.
5. Account Abuse Converts Identity Access into Value
Account access becomes profitable when attackers can extract money, services, data, or trust. Common forms of account abuse include fraudulent purchases, loan applications, unauthorized withdrawals, promotion abuse, money laundering, and impersonation scams.
Fraudsters may also maintain accounts for extended periods. Instead of immediately making a large transaction, they can build normal-looking activity, increase limits, and wait for a valuable opportunity.
This makes ongoing identity risk monitoring important. Digital platforms should reassess trust when meaningful events occur rather than relying permanently on the onboarding result.
6. Fraud Networks Reuse Identities, Faces, and Devices
Identity fraud is often coordinated. The same face, document template, device, network, or behavioral pattern may appear across multiple accounts.
Individual sessions can look acceptable when evaluated in isolation. Relationships between sessions may reveal:
- One face linked to multiple claimed identities
- Multiple accounts created from the same device environment
- Repeated use of manipulated document templates
- Shared network or session infrastructure
- Rapid changes between identity profiles
- Similar attack patterns across different accounts
Face++ face search can help identify whether a submitted face appears elsewhere in an enrolled database. Used with appropriate governance and thresholds, 1:N biometric search can support duplicate-account detection and fraud-network investigation.

7. A Layered Defense Across the Account Lifecycle
No single control can reliably stop every form of identity fraud. Effective protection combines evidence from multiple stages.
At onboarding, platforms can apply document checks, face comparison, liveness detection, and device analysis.
During account use, they can monitor login context, device changes, behavioral anomalies, profile updates, and transaction risk.
At high-risk events, platforms can trigger Face++ face verification and liveness detection to confirm that the current user matches the trusted identity and is genuinely present.
Across accounts, biometric and device relationships can help expose repeated or coordinated abuse.
The resulting decision should be risk-based. Low-risk users can continue with minimal friction, uncertain cases can receive a step-up check, and high-risk sessions can be reviewed or blocked.
8. Frequently Asked Questions
Q1. What is the difference between identity theft and identity fraud?
Identity theft is the unauthorized acquisition of personal information. Identity fraud occurs when that information is used to impersonate someone, open accounts, access services, or conduct unauthorized activity.
Q2. Can a genuine identity document still be used for fraud?
Yes. A genuine document may be stolen or submitted by someone other than its owner. Face comparison and liveness detection help establish whether the presenter matches the document portrait and is genuinely present.
Q3. How does Face++ help prevent identity fraud?
Face++ provides facial identity capabilities including 1:1 face comparison, liveness detection, and 1:N face search. These capabilities can support onboarding, identity reverification, account recovery, and high-risk transaction controls.
Q4. Is onboarding verification enough to prevent account abuse?
No. Risk can change after onboarding. Digital platforms should monitor important account events and trigger identity reverification when device, behavior, profile, or transaction signals indicate elevated risk.
9. From One-Time Verification to Continuous Identity Security
Identity fraud is a lifecycle problem. Stolen data becomes fraudulent evidence, fraudulent evidence enables account access, and account access becomes abuse.
Digital platforms need controls that connect document evidence, facial identity, genuine presence, device context, account behavior, and cross-account relationships. By integrating Face++ face comparison, liveness detection, and face search into risk-based workflows, businesses can strengthen identity assurance without applying maximum friction to every user.



