Home / Companies / Fingerprint / Blog / January 2026

January 2026 Summaries

7 posts from Fingerprint

Filter
Month: Year:
Post Summaries Back to Blog
For nearly two decades, the prevailing strategy of web security teams has been to block bots due to the perceived risks of automation, such as scraping and fraud. However, as the internet evolves, AI agents are increasingly performing legitimate tasks, such as automating operations and assisting with purchasing decisions, challenging the notion that all automation is harmful. The core issue now is identifying whether automated traffic is legitimate rather than simply stopping it. Industries like e-commerce and fintech are particularly affected, as distinguishing between authorized and unauthorized automation directly impacts revenue and trust. The launch of Authorized AI Agent Detection allows businesses to identify and verify AI agents with certainty, enabling them to safely automate tasks, prevent fraud, and improve operational efficiency. This new capability, supported by cryptographic verification, establishes a standard for AI agent visibility and verification, marking a shift toward an agentic economy where trust and identity are pivotal. As organizations adapt to this change, they can better manage traffic by discerning intent rather than merely categorizing it as "bot" or "not bot," paving the way for a future where AI agents enhance user experiences, operational efficiency, and security.
Jan 30, 2026 777 words in the original blog post.
Fingerprint has launched API v4 to enhance its device intelligence capabilities, offering a more streamlined and consistent experience for developers. The update simplifies integrations by unifying data formats across core components like the Server API, Webhooks, Sealed Client Results, and JavaScript Agent, resulting in faster and more predictable implementations. Key improvements include fewer core endpoints, lighter payloads, modern authentication, and clearer error messages. The JavaScript Agent v4 also introduces features like Suspect Score access and built-in Visitor ID caching. The update aims to reduce long-term maintenance and facilitate future feature adoption, with a migration timeline in place and full support available for a year post-deprecation. The API v4 is currently live, with recommendations for early migration to maximize the benefits of new features and maintain accuracy.
Jan 27, 2026 637 words in the original blog post.
Fingerprint's new Rules Engine, demonstrated through its Cloudflare deployment, enables teams to make real-time decisions without altering their application code. This tool allows fraud and risk teams to create and update rules independently, shifting enforcement to the network edge. A live demonstration showcases the capability to block and unblock traffic using Smart Signals, helping protect signup pages and block risky behaviors such as browser tampering or automation without the need for pull requests, redeployments, or engineering delays. The system offers a streamlined process for updating rules instantly, encouraging users to try it with a free trial and create their own ruleset within the Fingerprint dashboard.
Jan 21, 2026 145 words in the original blog post.
Fingerprint has launched new no-code capabilities in beta to enhance fraud prevention by enabling fraud, risk, and product teams to quickly understand and act on device risks without needing extensive engineering efforts. The new features include a no-code setup method for deploying Fingerprint at the edge using Cloudflare, allowing for rapid configuration and deployment without custom code. Additionally, the no-code Rules Engine allows users to create customizable rules using real-time device and browser signals to block, challenge, or flag suspicious traffic. These tools aim to empower fraud analysts with ongoing autonomy to assess and respond to device risk profiles, with the ability to start in monitoring mode to understand baseline behaviors before enforcing rules. The capabilities are designed to reduce time-to-value by providing intuitive interfaces for quick deployment and iterative rule building, with the goal of making device intelligence accessible and actionable for teams managing fraud risk.
Jan 16, 2026 807 words in the original blog post.
The third annual company hackathon provided a dynamic platform for employees from various departments, including engineers, product managers, and designers, to collaborate on innovative and experimental projects outside their routine tasks. Participants formed small teams to explore bold ideas aligned with the company's mission, choosing any technologies they preferred, with minimal constraints. The event, which was fully remote, fostered a sense of shared experience through a live kickoff call, a food and drinks budget, and a "Best Meme" award, allowing for both creative project development and informal interaction. Over 48 hours, 14 teams presented their projects, which were evaluated for creativity and potential impact, with top projects and a meme competition winner receiving prizes. The hackathon not only encouraged cross-role collaboration and creativity but also resulted in several project ideas worthy of product incorporation, reinforcing the company's commitment to innovation in a remote work environment.
Jan 13, 2026 740 words in the original blog post.
Evaluating the accuracy of fingerprinting solutions involves complex challenges due to their reliance on probabilistic signals that can vary over time and environments, making marketing claims potentially unreliable in actual use. The inconsistency in defining accuracy metrics further complicates evaluations, often focusing on ideal scenarios rather than real-world behavior. To address this, a practical approach is recommended, involving concrete tests conducted under consistent conditions to reveal different strengths and trade-offs rather than relying on a single accuracy metric. Tests should focus on aspects such as stability, resilience, and business impact, with guiding principles emphasizing fair comparisons by testing solutions on the same traffic and surfaces and clearly defining ground truths for each test. It's important to distinguish between stability, evasion resistance, and business impact, evaluating them separately to avoid misleading results. Silent failures should be monitored closely, as they can undermine downstream decisions. The guide suggests starting with simple tests like environment change scenarios and then expanding to more complex evaluations, ensuring thorough analysis without overinterpreting limited data. Fingerprinting's effectiveness in fraud detection is also assessed by comparing fraud caught, false positives, and business impact, using simulated fraud actions to measure the contribution of fingerprinting to overall fraud prevention outcomes.
Jan 06, 2026 2,487 words in the original blog post.
Account takeover (ATO) fraud is a sophisticated attack method where criminals use stolen credentials to log into customer accounts, making detection challenging due to their ability to mimic legitimate users. Instead of exploiting system vulnerabilities, attackers utilize valid credentials obtained through phishing, malware, or dumps, blending in with regular user activities. The subtlety of these attacks is compounded by the distribution of risk indicators across various systems, and modern bots' ability to replicate human behavior further complicates detection. While multi-factor authentication (MFA) remains crucial, it is often insufficient on its own, as attackers can bypass it using advanced techniques. Effective ATO detection requires evaluating risk throughout the entire user session, not just at login, using tools that integrate device intelligence, behavioral analytics, and adaptive authentication. Several platforms offer solutions that blend these technologies to provide comprehensive protection against ATO, with the best strategies combining multiple layers of defense to ensure both login integrity and session security.
Jan 05, 2026 2,894 words in the original blog post.