#93 - The two things fraudsters can't hide

I've been in fraud for almost 17 years across Fintechs, eCom merchants, issuers, acquirers, BNPL players, you name it. I've seen fraud in every shape it takes.

But in every fraud case I've ever seen, no matter how sophisticated, I always spotted the same two things. And it’s those two things that I use to catch fraudsters.

Every time.

The two fingerprints of fraud

The first thing I’ll mention is intent.

Fraud doesn't happen by accident. It's always premeditated, and that premeditation shapes behavior in ways that ultimately separate it from how legitimate users behave.

That's the whole game.

You cannot fake intent, and you cannot hide intent. Not really. 

You infer it from what someone does when they think no one's checking too closely, and from the small decisions that only make sense if you're trying to avoid getting caught.

The second thing I’ll mention is infrastructure.

Fraudsters work with whatever tools they have access to - devices, IP networks, stolen or fabricated identities, or the generated emails they have.

Whatever their infrastructure is made of, it’s not random. It was acquired and developed to commit a specific fraud attack.

A ring built around stolen identities looks nothing like a ring built around synthetic ones. 

But each one repeats itself internally because building fresh infrastructure for every single account doesn't scale, even for fraudsters.

Every fraud ring leaves its own fingerprint in how it's built, and that fingerprint is what you're actually hunting for when no obvious fraud signals are there.

And guess what - once you find that fingerprint, that hidden connection between seemingly unrelated users, what does it tell you? That they all share the same intent.

Fraud is hard to spot, until it’s not

Here's a story that shows both principles at work. It's a fraud ring we caught at Sardine during a POC a few months back.

A client was seeing elevated fraud pressure, but every account looked good on its own - US-based, clean devices, emails that matched the account holder's name.

Nothing to flag if you're reviewing accounts one at a time. And most teams are reviewing accounts one at a time, because that's how most case queues are built.

Our IP penetration feature - which traces a session back to its real originating location instead of the one it presents - showed the sessions were actually originating from Germany and the UAE.

Why mask your location when signing up for a new financial product? That's a signal about intent before you've even looked at a transaction.

Fine, but what if you don't have IP penetration tech, or access to the user’s IP address at all? You could still catch this one.

Reviewed together, not one at a time, the same email-generation pattern jumps out:

first_name.first_letter_of_last_name@gmail.com (e.g., chen.z@gmail.com)

Second, all accounts shared the same IP city, even though they used different IPs. And it wasn’t just a city, it was London.

London, WI that is. It's a town so small even Wikipedia doesn't have their population figure.

That's the ring's infrastructure: a specific network to hide behind, plus a repeatable pattern in how the emails got generated.

No sophisticated tooling required for either fingerprint - you could spot all of that in an Excel sheet, if you know what to look for and you're looking at the right resolution.

Fighting sophisticated fraud with basic tools

I won't pretend this is the fix, because there isn't one fix for a problem this broad, but given the story above, here's one thing I’ve seen teams apply successfully.

And the beauty of it is you need little-to-no skills, budget, or fancy technology.

You simply need a good monitoring dashboard.

Because here’s the thing: a spike large enough to cause real losses can still register as a non-event if you're only watching aggregate volume. You're big enough that it gets lost in the noise.

So you shouldn’t assume spikes would be visible. Instead, you should hunt for them in specific, bounded segments - region or state, amount band, product type, whatever makes sense to your business.

Layer these segments and monitor the narrow, niche buckets instead of only the top-line numbers.

When you notice a micro-spike in one of them, rule out it’s a marketing campaign or a new product launch. Given that, the odds that this is unwanted behavior are quite high.

Do that, and you’ll be on to fraud much earlier than before. You won’t need chargeback files to let you know something’s up. It’ll be clear as day.

And that’s half the job.

Noticing fraud early enough is one of the biggest bottlenecks in what I call the Reaction Cycle. 

Is it the only thing you need to do? No. Is it the first thing you need to do? Likely not. But given its ROI, it’s damn near close.

Bottom line

Every fraud case leaves two fingerprints: intent and infrastructure.

Neither requires sophisticated tooling to catch, but they require you to fine-tune the resolution in which you look for fraud.

On one hand, zoom-out from individual events so you could spot patterns. On the other hand, watch for it in sub-segments rather than in general.

It’s easy and cheap to set up, and it works.

What's the narrowest segment you're currently monitoring for spikes?

In the meantime, that’s all for this week.

See you next Saturday.


P.S. If you feel like you're running out of time and need some expert advice with getting your fraud strategy on track, here's how I can help you:

Free Discovery Call - Unsure where to start or have a specific need? Schedule a 15-min call with me to assess if and how I can be of value.
​Schedule a Discovery Call Now »

Consultation Call - Need expert advice on fraud? Meet with me for a 1-hour consultation call to gain the clarity you need. Guaranteed.
​Book a Consultation Call Now »

Fraud Strategy Action Plan - Is your Fintech struggling with balancing fraud prevention and growth? Are you thinking about adding new fraud vendors or even offering your own fraud product? Sign up for this 2-week program to get your tailored, high-ROI fraud strategy action plan so that you know exactly what to do next.
Sign-up Now »

 

Enjoyed this and want to read more? Sign up to my newsletter to get fresh, practical insights weekly!

<
Next
Next

#92 - AI fraud is here. So where's the loss?