A fintech app scores every login attempt for account-takeover risk using device, location, and behavior signals. Require step-up authentication — a code, a biometric check — at a low risk threshold, and most takeover attempts get blocked before they succeed, but legitimate users also get stopped more often for an extra verification step.
The Fintech Fraud Lab models 8,000 login attempts. Lowering the step-up authentication threshold blocks more true account-takeover attempts, at the cost of inconveniencing more legitimate users with an extra authentication step.
The rarity of genuine takeover attempts is again the key constraint here: with true takeovers making up a tiny fraction of all logins, any threshold aggressive enough to catch most of them will also flag a meaningful number of entirely legitimate users, which is exactly the friction a fintech product has to manage carefully.
🧪 Try it yourself: the Fintech Fraud Lab simulation lets you move the step-up authentication threshold and watch the daily outcome update live.
🧪 Try it yourself: the Fintech Fraud Lab simulation lets you experiment with everything described above directly in your browser.