May 2026 Summaries
4 posts from Fingerprint
Filter
Month:
Year:
Post Summaries
Back to Blog
Smart Signals has introduced two new features: Rare Device Detection and iOS Simulator Detection, aimed at enhancing risk assessment by identifying potentially fraudulent device environments. Rare Device Detection evaluates device attributes such as operating system and browser version against Fingerprint's global traffic, identifying devices with uncommon configurations, which can indicate early-stage attacks. This feature is currently in beta and provides percentile data on how rare a device setup is. iOS Simulator Detection, available now, identifies visits from simulators rather than real devices, allowing for the detection of automated fraudulent activities that leverage simulators to mimic genuine device interactions. Both features are designed to complement existing fraud signals, providing additional context for decision-making processes like triggering authentication steps or blocking suspicious activities. By integrating these signals with others such as Suspect Score and VPN/proxy detection, organizations can improve their capability to detect and mitigate fraud before it becomes widespread.
May 21, 2026
587 words in the original blog post.
Global banking institutions have invested heavily in sophisticated authentication systems, yet fraud losses are rising, projected to reach $58.3 billion globally by 2030. Despite advancements like multi-factor authentication and passkeys, AI-powered fraud techniques such as deepfake attacks have exposed vulnerabilities in traditional authentication methods, making them less effective. Persistent, cross-session device intelligence is identified as a critical missing layer in account security, providing the ability to track and assess the trustworthiness of devices across customer interactions. The sunset of Microsoft's Dynamics 365 Fraud Protection platform has left significant gaps in fraud detection capabilities, with many institutions resorting to less effective cookie-based tracking methods. Device intelligence offers a more robust solution by evaluating consistent behavioral and environmental signals, reducing false positives, and enhancing machine learning models for fraud detection. By integrating device intelligence, financial institutions can better safeguard against modern threats while delivering a seamless and secure experience for legitimate customers.
May 18, 2026
3,205 words in the original blog post.
Phishing attacks involving fraudulent Android Package Kit (APK) downloads have become a significant threat, particularly in regions like the Asia-Pacific, where sideloading apps is common. These attacks typically involve social engineering tactics, such as fake bank calls, to trick individuals into installing malicious apps that can intercept one-time passcodes (OTPs) sent via SMS for authentication. Once installed, these apps silently forward OTPs to fraudsters, enabling unauthorized access to victims' bank accounts. Despite the apparent legitimacy of credentials and OTPs, this method bypasses traditional security measures. Regulators in affected regions are pushing for stronger authentication methods beyond SMS OTPs, such as device-bound solutions and biometrics. Device intelligence, which provides context about the device and its behavior, offers an additional layer of protection by detecting anomalies and preventing unauthorized access, even when credentials and OTPs appear valid.
May 13, 2026
2,027 words in the original blog post.
hCaptcha, once considered a privacy-friendly alternative to Google's reCAPTCHA, is facing challenges as bot threats become more sophisticated and user expectations evolve. Users often abandon forms due to difficult puzzles, and advanced AI can bypass these challenges, rendering them ineffective. Compliance issues arise from hCaptcha's cookie requirements and data transfer concerns, particularly for EU-based organizations with strict data residency needs. As a result, many teams seek alternatives that provide frictionless, passive bot detection without compromising user privacy. Solutions like device fingerprinting analyze browser and hardware attributes to detect bots without visible user interaction, while Cloudflare Turnstile offers invisible verification through background telemetry checks. Friendly Captcha employs cryptographic proof-of-work, offering strong privacy compliance but potentially impacting device performance. reCAPTCHA v3 eliminates visible challenges by using risk scores, though it presents privacy concerns due to data collection. Simple methods like honeypot fields and rate limiting can deter unsophisticated bots for low-risk forms. The future of bot detection is moving towards passive, continuous assessment to protect against threats without hindering genuine user experiences.
May 12, 2026
1,443 words in the original blog post.