That's exactly it. It's important to look at a whole bunch of factors. For example, fraudsters tend to go directly to the payments page, whereas good users will browse around the site before making a purchase. There are tons of little signals like that which allow you to distinguish legitimate users from the fraudsters.
We don't do things like two-factor auth -- in general, we believe in minimizing friction. It's a better user experience, and if you can prevent fraud without burdening the user, why not?
We have more information with some examples of signals our system uses here:
https://siftscience.com/large-scale-machine-learning