SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
SEON expands fraud signals to spot synthetic identities

SEON expands fraud signals to spot synthetic identities

Thu, 1st Oct 2026 (Today)
Mara Sugue
MARA SUGUE News Editor

SEON has expanded its Signal Intelligence platform to more than 1,100 proprietary data points, extending coverage in address intelligence, session behaviour, and phone and carrier data.

The additional signals are intended to help fraud and risk teams identify manufactured identities and links between accounts that may be part of wider fraud rings. They also add deeper digital footprint and device data to SEON's existing signal set.

The expansion comes as financial crime teams face a rise in synthetic and manipulated identities created with generative artificial intelligence tools. SEON cited findings from the Financial Action Task Force suggesting that convincing deepfakes can now be generated quickly with a smartphone.

For fraud investigators, the problem is often not a single red flag but how multiple data points fit together. An email address may validate correctly, a device may appear normal, and an address may pass basic checks, yet inconsistencies can emerge when those details are assessed against each other.

SEON's latest changes are aimed at improving that cross-checking process. The new data points fall into three broad areas: identity history, shared infrastructure, and live user behaviour.

History signals

One part of the rollout focuses on whether an identity appears to have an established record across online services. SEON's Digital Footprint and Phone Intelligence tools now track where an email address or phone number has appeared over time across areas including AI developer platforms, job boards, property listings, and dating apps.

Phone-based checks have also been expanded to include SIM-swap and number-porting history. Those records can help investigators assess whether a phone number has a consistent past or shows signs of recent changes that may indicate elevated risk.

Shared infrastructure

Another part of the expansion centres on reused infrastructure, which can reveal connections between accounts that seem unrelated on the surface. Address Intelligence now standardises address data across more than 240 countries, allowing teams to identify when different applications or accounts resolve to the same location despite differences in formatting or unit details.

Device Intelligence has also been extended. The system can now surface signs of AI-agent activity, compromised iOS devices, Android eSIM mismatches, and discrepancies between network and country data when visible IP information is obscured by a virtual private network.

These checks are intended to help expose patterns that fraud rings often rely on, such as repeated use of the same buildings, devices, or network arrangements across multiple accounts. In many cases, those connections only become visible when data from separate layers is combined.

Live behaviour

The third area focuses on behaviour during an active session. According to SEON, Session Monitoring follows actions from onboarding through login, account recovery, checkout, and payment.

The monitoring is designed to detect activity such as automation, remote access, off-screen behaviour, and active calls while a session is taking place. The goal is to enable intervention before suspicious activity develops into account takeover or payment fraud.

The additional signals are also being fed into SEON's AI Command Centre, where fraud teams use rules, alerts, reviews, and investigations. The same signal set can also be connected to external investigator AI tools through its Model Context Protocol server.

Tamas Kadar, Chief Executive Officer and Co-Founder of SEON, said the challenge for fraud teams is that fake identities have become easier to create at scale, while maintaining a credible and consistent history across many accounts remains harder.

"AI has made a believable identity cheap to produce. What fraudsters cannot easily do at scale is build a consistent history for every account without reusing infrastructure," said Kadar, Chief Executive Officer and Co-Founder of SEON.

"That is where our signal foundation makes the difference. The more dimensions a fraud team can check simultaneously, the harder it is to hide an identity that does not add up," Kadar said.

Alongside the product update, SEON has introduced a research series called Hidden Risk Files, which presents case studies from its fraud consultants on how specific signals can reveal broader criminal activity. The first case examines how one device attribute, a screen-brightness reading, was used to connect thousands of accounts in a fraud ring operating across Android devices.

SEON, which operates from Austin, London, Budapest, and Singapore, says it serves thousands of companies worldwide in fraud prevention and anti-money laundering compliance.