How Partners Can Strengthen Security, Reduce Risk and Protect Cloud Investments
At a glance:
- Three fraud vectors are converging: compromised accounts, exposed application programming interface (API) keys and credentials and fraudulent or synthetic business identities.
- Partners carry the financial risk: under reseller agreements, consumption charges resulting from compromised credentials or fraudulent onboarding may remain the partner’s responsibility.
- According to Palo Alto Networks, 90% of breaches involve identity and access control weaknesses: highlighting the importance of strong security fundamentals.
- Four foundational controls can help reduce risk: protect identities, secure credentials and API keys, monitor consumption and immediately investigate anomalies.
A single compromised credential can generate substantial cloud charges before unusual activity is detected. Cloud consumption fraud is evolving as quickly as the AI and cloud adoption it exploits. A few years ago, most incidents involved stolen credentials or compromised accounts. Today, attackers are also using synthetic business identities, AI-generated documentation and increasingly sophisticated social engineering to gain unauthorized access to cloud services. Once inside, they can rapidly provision compute resources and generate significant costs before suspicious activity is detected.
Prevention, in combination with detection, helps protect the bottom line.
The Threat Landscape is Expanding
1. Compromised Accounts
Phishing, stolen credentials or missing multi-factor authentication (MFA) can allow attackers to access legitimate cloud environments and provision compute resources using trusted identities.
2. Exposed API Keys and Credentials
Another common entry point is exposed credentials. According to the State of Secrets Sprawl Report 2025, 28.6 million API keys, access tokens and cloud credentials were publicly exposed in a single year—demonstrating how quickly an overlooked secret can become a costly incident.
3. Fraudulent or Impersonated Businesses
A growing fraud vector involves stolen or synthetic business identities that appear legitimate during onboarding. These organizations may rapidly provision AI workloads, graphics processing unit (GPU) resources and other cloud services before abandoning the account without payment. As generative AI makes fraudulent documents and identities more convincing, identity verification has become an increasingly important layer of fraud prevention.
Strong Fundamentals Still Stop Most Fraud
Although attackers continue to adapt, the most effective defenses remain consistent.
Partners can reduce risk by focusing on four foundational controls:
- Protect identities. Enable MFA, apply least-privilege access and regularly review user permissions.
- Secure credentials and API keys. Restrict API keys to approved services and IP addresses, avoid storing credentials in source code, rotate secrets regularly and use secure secret-management and scanning tools.
- Monitor cloud consumption. Configure budgets, usage alerts, anomaly detection and regular consumption reviews to identify unexpected activity before costs escalate.
- Investigate anomalies immediately. Prompt investigation can help reduce risk and limit potential financial losses.
Identity Verification Extends Beyond Technology
Technology can improve visibility into unusual activity, but it cannot verify business legitimacy. Strong onboarding and end-customer verification processes can help partners reduce the likelihood of fraudulent organizations gaining access to cloud resources.
Independent verification of identities, tax information and supporting documentation is especially important before provisioning cloud services, particularly for accelerated deployments, unusually large AI or GPU workloads or purchasing behavior that does not align with an end customer’s stated business profile.
Additional review is warranted when you observe:
- Recently registered domains.
- False, look-alike or spoofed email domains that appear similar to legitimate company domains.
- Inconsistent or difficult-to-verify business information.
- Requests to bypass verification procedures.
- Unusually rapid consumption growth.
- Purchasing behavior that does not align with an end customer’s stated business profile.
While these measures can improve visibility into unusual activity, they are not guaranteed to detect, prevent or mitigate fraud. Partners remain responsible for end-customer due diligence, credential protection, ongoing monitoring and risk management.
Resilience is Built Before It’s Needed
Resilience is built long before suspicious activity appears. As cloud environments become more interconnected and AI workloads continue to grow, fraud tactics will continue to evolve. The partners best positioned to manage cloud consumption fraud are those that embed identity protection, end-customer verification, credential management and operational discipline into routine business processes. Doing so can help reduce financial exposure, strengthen end-customer trust and build more resilient cloud businesses.
Continue Strengthening Your Fraud Prevention Strategy
For additional guidance, contact your local TD SYNNEX Cloud team. Partners may also seek confidential fraud screening support for potentially suspicious end customers, transactions or cloud consumption activity.
Partners can also contact the TD SYNNEX Global Fraud Prevention Team at Fraud@tdsynnex.com for confidential fraud screening and real-time guidance on potentially suspicious customers, transactions or activities.