July 28, 2026
I
4 min

Frictionless Security: Striking the Right Balance Between User Experience and Fraud Prevention

Every additional security step a company introduces to protect its users can also increase the likelihood of losing them. Lengthy forms, multiple authentication factors, and repeated verification requests create friction that may cause users to abandon the registration or login process. Yet in an environment where digital fraud is becoming increasingly sophisticated, reducing security controls is not an option.

The threat continues to grow. A study conducted across 36 financial institutions in Latin America found that social engineering fraud increased by 155% across the region in 2025. At the same time, a new generation of AI-powered attacks is emerging. Another report revealed that cybercriminals are increasingly using artificial intelligence to create far more convincing scams, driving a 201% increase in deepfake attacks across Latin America.

Against this backdrop, the limitations of traditional authentication methods are prompting organizations to adopt new approaches that strengthen security without creating friction—that is, without compromising the user experience (UX).

Frictionless Authentication

For years, authentication relied on users actively proving their identity through a password, an SMS verification code, or biometric authentication. Today, that model is being complemented by a new approach: authentication based on risk signals that are collected transparently, without requiring any additional action from the user.

Rather than replacing biometrics or other authentication methods, this approach enhances them with intelligent controls that analyze contextual information in the background to determine the risk level of each transaction.

These verification methods can leverage technologies such as behavioral biometrics and Mobile ID APIs to detect anomalous behavior and generate alerts when potential fraud is identified.

Secure Onboarding and Login

Mobile identity APIs add an extra layer of trust by leveraging data from the telecommunications network itself. They enable organizations to validate multiple attributes of a mobile line using carrier-provided information, rather than relying solely on credentials entered by the user.

With this approach, organizations can verify phone number ownership, detect recent SIM card changes, and use additional network signals to assess the risk level of a transaction. All of this happens transparently, reducing friction during onboarding, login, and transaction authorization.

The result is a smarter and more secure authentication model that incorporates information unavailable to applications on their own. It also enables organizations to verify a user's identity by comparing the information provided to the digital service with data previously validated by the mobile network operator (MNO), strengthening fraud prevention without introducing unnecessary steps for legitimate users.

The adoption of this model is being accelerated by Open Gateway, the GSMA initiative designed to standardize network APIs and provide businesses and developers with consistent access to mobile network capabilities.

Today, 86 operator groups—representing more than 300 mobile networks and nearly 80% of the world's mobile connections—have aligned with this framework.

Telecommunications Network-Based Authentication

(Source: Fierce Networks / Nokia)

Security and User Experience (UX)

The evolution of mobile identity APIs demonstrates that organizations no longer have to choose between delivering a seamless user experience and strengthening security. By leveraging signals from the mobile network, businesses can introduce new trust mechanisms that operate transparently, reduce friction, and enhance fraud prevention.

At Plusmo, we offer a portfolio of Mobile ID APIs that enable organizations to integrate these capabilities into digital onboarding, authentication, and transaction authorization processes. As a result, businesses can better protect themselves against threats such as account takeover, SIM swap fraud, and identity manipulation while delivering a simpler, faster, and more secure experience for their customers.

Download PDF
Go Back