Third-Party Fraud: When Strangers Become Customers

Updated July 29, 2026
Every day, businesses onboard customers who are not who they claim to be. The credentials look real. The documents pass a surface check. The transaction completes. Then the real account holder calls to report fraud they never authorized.
That is third-party fraud: an external actor using someone else's identity, credentials, or personal information to illegally obtain funds, goods, or services. It is the most common category of identity fraud, and it targets the moment businesses are most vulnerable: when a stranger is trying to become a customer.
Understanding third-party fraud is the first step toward stopping it. This guide explains what it is, how it differs from other fraud types, what schemes to watch for, and how to build detection and prevention controls that actually work.
Key takeaways
- Third-party fraud occurs when an unauthorized external actor uses another person's identity or personal information to commit fraud, without the victim's knowledge or consent.
- The most common third-party fraud schemes include account takeover, new account fraud, synthetic identity fraud, and phishing-enabled identity theft.
- Every $1 of fraud loss costs U.S. financial firms $4 in revenue, making detection and prevention a direct business performance issue.
- Effective defense requires layered controls across the entire customer lifecycle: at onboarding, during ongoing transactions, and at high-risk authorization moments.
What is the difference between first-party and third-party fraud?
The most important distinction in fraud classification is who the perpetrator is.
First-party fraud occurs when an individual uses their own identity to deceive a business or financial institution for personal gain. The fraudster is the legitimate account holder or applicant. Common examples include:
- Falsifying income on a loan application
- Intentionally defaulting on credit after maxing out accounts (bust-out fraud)
- Disputing legitimate charges to obtain refunds (friendly fraud)
- Applying for credit with manipulated personal information
Third-party fraud involves an external actor who steals or fabricates someone else's identity. The perpetrator has no legitimate relationship with the business. Common examples include:
- Opening new credit accounts using stolen Social Security numbers
- Taking over existing accounts by hacking credentials
- Creating synthetic identities from a mix of real and fabricated information
- Using phishing to obtain a victim's login credentials and then draining their accounts
The detection challenge differs significantly between the two. First-party fraud is difficult to catch because the perpetrator uses real identity information, just with manipulated details. Third-party fraud is difficult to catch because the fraudster is impersonating a real person, and the stolen credentials may appear entirely legitimate.
Common third-party fraud schemes
Third-party fraud takes many forms. These are the schemes that fraud and risk teams encounter most frequently:
- Account takeover: A fraudster gains unauthorized access to a victim's existing account, typically by stealing login credentials through phishing, credential stuffing, or social engineering. Once inside, they change account details, initiate unauthorized transactions, or use the account to enable further fraud. ATO fraud affects banking accounts, email accounts, investment accounts, and any platform where a compromised login provides financial or data access. Account takeovers result in an average loss of $12,000 per incident, and ATO represents 27% of global reported fraud. One in nine password reset attempts in 2024 was a fraud attack, rising to one in four for resets initiated on desktop computers.
- New accounts: New account fraud occurs when a fraudster uses stolen or fabricated credentials to open accounts in someone else's name. They apply for credit cards, loans, or utility services using a victim's Social Security number, address, and other PII. They then max out the credit and disappear, leaving the victim with damaged credit and the business with unrecoverable losses.
- Synthetic identities: Synthetic identity fraud combines real and fabricated information to create a new, fake identity. A fraudster might use a real Social Security number (often stolen from a child or deceased person) paired with a fictitious name and date of birth. This synthetic identity is used to open accounts, build a credit history over time, and eventually commit large-scale fraud. Synthetic fraud is particularly difficult to detect because it does not rely entirely on stolen identities. The victim (the person whose SSN was used) may not discover the fraud for years. In 2022, synthetic fraud saw a 45% year-over-year increase.
- Phishing and social engineering: Phishing attacks use deceptive emails, text messages (smishing), or phone calls (vishing) to trick victims into revealing their PII or login credentials. Fraudsters impersonate banks, government agencies, or trusted companies. Once they have the credentials, they use them to commit account takeover or new account fraud. Social engineering is the human-layer attack that feeds most third-party fraud schemes. It exploits trust rather than technical vulnerabilities, making it effective even against users with strong passwords and multi-factor authentication (MFA).
- Loan stacking: In loan stacking, a fraudster applies for multiple loans simultaneously across different lenders using a stolen or synthetic identity. Because lenders do not always share real-time data, each application may appear legitimate. The fraudster collects the loan proceeds and defaults, leaving multiple institutions with losses.
How third-party fraud is orchestrated
Third-party fraud is rarely opportunistic. Sophisticated attacks follow a deliberate, multi-stage process.
- Reconnaissance. Fraudsters identify targets by researching business relationships, transaction flows, and weak security links. Social media and dark web marketplaces provide PII and credentials.
- Credential acquisition. Through phishing, data breaches, or dark web purchases, fraudsters obtain the identity information they need to impersonate a legitimate customer.
- Entry. Using stolen credentials, fraudsters access existing accounts or apply for new ones. They may plant malware, use forged documents, or exploit weak authentication controls to establish a foothold.
- Exploitation. Once inside, fraudsters redirect payments, submit fraudulent applications, or extract sensitive data. They operate in ways that mimic legitimate customer behavior to avoid triggering alerts.
- Extraction. Funds, data, or account access are converted to value as quickly as possible, often through wire transfers, cryptocurrency, or resale on the dark web.
- Cover. Fraudsters delete logs, use proxies, and create false trails to obstruct investigation and delay detection.
Many instances of third-party fraud are connected to organized crime rings. These groups invest in better technology and more sophisticated tactics as their fraud operations scale. Generative AI has made impersonation cheaper and more convincing, enabling fraudsters to produce synthetic documents, deepfake video, and AI-generated scripts for targeted social engineering attacks.
How businesses are responding
Defending against third-party fraud requires layered protection. Companies are investing in stronger identity verification, device intelligence, and behavioral analytics to separate legitimate customers from impostors. Real-time monitoring can detect unusual patterns, while shared intelligence networks help organizations stay ahead of emerging threats.
Customer awareness also matters. Many successful attacks begin with phishing or social engineering. By educating users about these risks, businesses can reduce the chances of compromise before a fraudster even attempts to transact.
The strongest programs combine prevention with recovery. They not only block unauthorized activity but also provide clear paths for legitimate customers to regain access when their accounts are compromised. This balance is essential for maintaining trust.
Why it matters now
Third-party fraud may be the oldest trick in the fraud playbook, but it is far from obsolete. As digital transactions multiply, the attack surface only grows. Criminals are faster, more organized, and better equipped than ever. For businesses, the stakes are clear: blocking fraudsters, not legitimate customers.
Identity verification, fraud intelligence, and strong recovery practices are no longer optional. They are the foundation of digital trust and the competitive edge for companies that get them right.






























.jpg)





























































.jpg)













































