Skip to main content
Glossary

Fraud & identity data dictionary

Plain-language definitions of the identity, fraud and risk terms used across Pipl Trust, Search and Elements.

A

Account Sharing / Account Farming

Account farming is the practice of creating large numbers of accounts, often using automated tools and lightly varied identity details, specifically to be sold, rented, or used for coordinated abuse rather than genuine individual use.

Example

An operation creates thousands of accounts using automated signup scripts and slightly varied name/email combinations, then sells verified, aged accounts in bulk to be used for bonus abuse or bot fraud elsewhere.

Why it matters

Farmed accounts often pass individual verification checks — each one may look plausible in isolation — which is why detecting account farming typically requires identifying the coordinated pattern across many accounts rather than any single account.

How it's detected

Network/link analysis identifying clusters of accounts sharing subtle infrastructure (device, creation timing patterns, IP ranges) is the primary detection method, since individual-account signals alone are often insufficient.

Account Takeover (ATO)

Account takeover is when a fraudster gains unauthorized access to a legitimate user's existing account — typically through stolen credentials, phishing, or credential stuffing — and uses it to commit fraud, such as making purchases or draining stored value.

Example

A fraudster obtains a customer's email and password from a data breach on an unrelated site, then uses those same credentials to log into the customer's account elsewhere, since many people reuse passwords across services.

Why it matters

ATO is especially damaging because it exploits an account with an established, trusted history — bypassing checks designed for new-account fraud, and often going unnoticed until the legitimate owner reports unauthorized activity.

How it's detected

Behavioral and device signals — a login from an unfamiliar device or location, a sudden change in typical usage patterns — can flag a session as likely compromised even when the correct credentials were used.

Anti-Money Laundering (AML)

Anti-Money Laundering refers to the laws, regulations, and business processes designed to prevent criminals from disguising illegally obtained funds as legitimate income by moving them through the financial system.

Example

A bank monitors transaction patterns for signs of layering — moving funds through multiple accounts in ways designed to obscure their origin — as part of its AML program.

Why it matters

AML compliance is a legal requirement for financial institutions and many other regulated businesses; failures can result in severe regulatory penalties, and AML obligations exist independently of whether a specific transaction is also fraudulent.

How it's implemented

AML programs combine KYC/KYB onboarding checks, ongoing transaction monitoring for suspicious patterns, sanctions and PEP screening, and mandatory reporting of suspicious activity to regulators.

Approval Rate

Approval rate is the percentage of transactions or account applications that a risk system approves, out of the total submitted.

Example

If a business processes 10,000 account applications and approves 9,200, its approval rate is 92%.

Why it matters

Approval rate is in direct tension with fraud loss rate — a system tuned to approve almost everything will have a high approval rate but likely also higher fraud losses, while an overly conservative system will have low fraud losses but reject legitimate customers (false declines), suppressing growth.

How it's optimized

The goal generally isn't maximizing approval rate in isolation, but maximizing approvals of genuinely legitimate customers specifically — which requires distinguishing false declines from correctly declined fraud within the rejected population.

B

Behavioral Biometrics

Behavioral biometrics analyze patterns in how a person physically interacts with a device — typing rhythm, mouse movement, touchscreen pressure and swipe patterns — to help distinguish genuine users from automated bots or a different person using stolen credentials.

Example

A returning customer's typical typing cadence and navigation pattern differs noticeably from the session pattern observed after their credentials were used following a data breach, flagging the session as potentially compromised.

Why it matters

Behavioral biometrics can detect account takeover even when the correct password and device were used, since they evaluate how the account is being used rather than only what credentials were presented.

How it's used

These signals are typically evaluated continuously during a session, rather than only at login, allowing detection of a takeover that occurs mid-session.

Bonus Abuse / Promo Abuse

Bonus abuse (or promo abuse) is when a person creates multiple identities, or exploits a single identity repeatedly, to claim sign-up bonuses, referral rewards, or promotional offers beyond what's intended for a single genuine customer.

Example

A person creates several accounts using slightly varied name spellings, different email aliases of the same inbox, and rotating devices to claim a "new customer" sign-up bonus multiple times.

Why it matters

Promotional programs are priced assuming a bounded number of genuine new customers claim them; abuse at scale directly inflates marketing costs without acquiring genuine new customers, and can make an otherwise profitable promotion loss-making.

How it's detected

Cross-account signal matching — shared devices, email aliasing patterns, overlapping addresses or payment methods — identifies clusters of accounts that are likely the same person or an organized abuse ring, even when individual account details differ.

Bot Fraud (Scalping)

Bot fraud, in a scalping context, is the use of automated scripts to rapidly purchase limited-availability inventory — concert tickets, limited product releases — at a speed and volume no human user could match, typically for resale at a markup.

Example

Within seconds of tickets going on sale, automated bots purchase a large share of available inventory across many simulated accounts, leaving few or none available to genuine buyers at the original price.

Why it matters

Beyond direct revenue impact, bot-driven scalping damages customer trust and experience — genuine fans or customers are systematically outcompeted by automation, not other genuine buyers.

How it's detected

Behavioral and velocity signals — inhuman click/purchase speed, patterns across many accounts sharing underlying device or network characteristics — distinguish bot traffic from genuine high-demand human traffic.

Bust-Out Fraud

Bust-out fraud is a scheme, often using a synthetic or stolen identity, where a fraudster builds a credit account's trustworthy history over time — making on-time payments, gradually increasing credit usage — before maxing out available credit and disappearing without repaying.

Example

A synthetic identity opens a credit card, makes small purchases and on-time payments for a year to build a positive history and earn credit limit increases, then rapidly charges the account to its limit and stops paying entirely.

Why it matters

Bust-out fraud is specifically designed to defeat standard credit risk monitoring, since the account looks genuinely low-risk right up until the moment it doesn't — the entire scheme depends on a patient, deliberate build-up phase.

How it's detected

Sudden, sharp deviations from an account's established usage pattern — a jump in spend velocity or credit utilization inconsistent with prior behavior — are a key signal, even against an account with an otherwise clean history.

C

Card Testing Fraud

Card testing fraud is when a fraudist uses a merchant's checkout process to verify whether stolen card numbers are still valid and active, typically via small or repeated low-value transactions, before using the validated cards for larger fraudulent purchases elsewhere.

Example

A fraudster runs a script that attempts many small transactions using a list of stolen card numbers against a merchant's checkout page, identifying which cards are still active and unflagged.

Why it matters

Card testing itself may not directly cost the merchant much (small transaction amounts), but it degrades checkout performance, increases processing costs, and the merchant's site becomes a tool for validating cards subsequently used for fraud elsewhere.

How it's detected

High-velocity, low-value transaction attempts using different card numbers but shared device or session characteristics are a strong card-testing signal.

Case Management (Fraud Investigations)

Case management, in a fraud context, refers to the tools and workflows used by fraud analysts to investigate flagged accounts or transactions — consolidating relevant signals, prior history, and related accounts into a single view to support an investigation and decision.

Example

An analyst investigating a flagged account uses a case management tool to view the account's full signal history, related accounts sharing device or network connections, and prior similar cases, rather than piecing that information together manually from separate systems.

Why it matters

Investigation quality and speed depend heavily on how much relevant context an analyst has readily available — scattered or incomplete information leads to slower investigations and less consistent decisions across analysts.

How it's structured

Effective case management tools surface not just the flagged item itself but its connections within the broader identity graph, prior related cases, and clear reason codes explaining why it was flagged in the first place.

Chargeback Fraud

Chargeback fraud occurs when a customer makes a legitimate purchase, then disputes the charge with their card issuer claiming it was unauthorized or the goods weren't received, despite having received them. It's a form of first-party fraud.

Example

A customer buys a product, receives it, then files a chargeback claiming non-delivery — keeping both the product and the refunded money.

Why it matters

Chargebacks carry direct financial cost (the refunded amount plus processing fees) and, at scale, can push a merchant's chargeback ratio above thresholds set by card networks, risking additional penalties or loss of payment processing privileges.

How it's detected

Because the transaction itself often looks legitimate at time of purchase, detection relies more on behavioral patterns — repeat disputers, mismatched claim details, delivery confirmation data — than on point-of-sale risk signals alone.

Chargeback Ratio

Chargeback ratio is the number of chargebacks a merchant receives divided by their total transaction volume over a given period, typically expressed as a percentage.

Example

A merchant processing 100,000 transactions in a month who receives 150 chargebacks has a chargeback ratio of 0.15%.

Why it matters

Card networks (Visa, Mastercard) set chargeback ratio thresholds, and merchants exceeding them can be enrolled in monitoring programs with additional fees, or in severe cases lose payment processing privileges entirely.

How it's managed

Reducing chargeback ratio requires addressing both fraud-driven chargebacks (via better transaction risk decisioning) and friendly-fraud-driven chargebacks (via clearer billing practices and dispute response processes).

Credential Stuffing

Credential stuffing is an automated attack where fraudists use large lists of stolen username-password pairs — typically obtained from data breaches on unrelated sites — and systematically attempt them against another service, exploiting the fact that many people reuse passwords.

Example

A list of email-password combinations leaked from a breached retailer is automatically tested against a bank's login page; the small percentage of reused passwords succeed and grant access to those accounts.

Why it matters

Credential stuffing doesn't require breaking any specific service's security — it exploits password reuse, meaning even a service with strong security of its own can be affected if its users reused a password compromised elsewhere.

How it's detected

High-volume, automated login attempt patterns — many attempts in rapid succession, often from a distributed set of IP addresses — are a strong signal for credential stuffing, distinct from normal human login behavior.

D

Data Breach

A data breach is an incident in which sensitive information — such as usernames, passwords, or personal identifying information — is accessed or exposed without authorization, often subsequently sold or shared in ways that enable further fraud.

Example

An unauthorized party gains access to a company's customer database and extracts email addresses and hashed passwords, which are later sold on illicit marketplaces and used in credential stuffing attacks against other services.

Why it matters

Data breaches at one company create downstream fraud risk for other, unrelated companies, since exposed credentials and personal data are frequently reused across services — a breach's impact isn't contained to the breached organization.

How it's addressed (downstream)

Businesses can monitor for their users' credentials appearing in known breach datasets and proactively prompt password resets, rather than waiting for fraudulent activity to occur.

Deepfake Fraud

Deepfake fraud uses AI-generated synthetic images, video, or audio that convincingly mimics a real or fabricated person to deceive identity verification systems or human reviewers.

Example

A fraudster uses an AI-generated video of a person's face, synced to a live camera feed in real time, to attempt to pass a facial liveness check during account verification.

Why it matters

As generative AI tools have become more accessible, the technical barrier to producing convincing deepfakes has dropped significantly, making this a growing category of verification risk rather than a rare edge case.

How it's detected

Detection techniques look for artifacts inconsistent with genuine video capture — unnatural blinking patterns, lighting inconsistencies, or signs of real-time video injection rather than a genuine camera feed — alongside standard liveness checks.

Device Fingerprinting

Device fingerprinting is the practice of identifying and tracking a specific device across sessions using a combination of technical attributes — browser configuration, screen resolution, installed fonts, hardware characteristics — rather than relying on a single identifier like an IP address, which can change or be shared.

Example

Two account creation attempts using different emails and IP addresses, but the same underlying device fingerprint, can be linked as likely originating from the same source.

Why it matters

IP addresses alone are unreliable for tracking, since they're frequently shared (public wifi, corporate networks) or masked (VPNs); device fingerprinting provides a more persistent signal for connecting activity across sessions.

How it's used

Device fingerprints feed into an identity graph as one signal type among several, helping establish whether multiple accounts or sessions are connected.

Digital Footprint

A digital footprint is the accumulated trail of online activity and data associated with an identity over time — accounts created, devices used, addresses associated, and behavioral patterns observed across digital interactions.

Example

A person's digital footprint might include an email address first seen years ago, a consistent device history, and a stable pattern of account activity across multiple merchants over time.

Why it matters

A longer, more consistent digital footprint is generally correlated with lower fraud risk, since fabricated identities are harder to backfill with a plausible multi-year history than to fabricate for a single point-in-time check.

How it's used

Risk models incorporate footprint depth and consistency as one input among several — not as a standalone pass/fail signal, since legitimate thin-file identities also have limited footprints.

Document Forgery

Document forgery is the creation or alteration of an identity document — a passport, driver's license, or utility bill — to misrepresent identity information, either by fabricating a document entirely or modifying elements of a genuine one.

Example

A fraudster alters the date of birth on a scanned driver's license image to misrepresent their age during an age-gated verification process.

Why it matters

As document capture and verification have moved online, forgery techniques have adapted accordingly — including digitally edited images and, increasingly, AI-generated fraudulent documents that can be difficult to distinguish from genuine ones on casual inspection.

How it's detected

Detection combines analysis of document security features, consistency checks against known document templates by issuing authority, and cross-referencing extracted document data against other identity signals.

E

Email Reputation

Email reputation is an assessment of an email address's trustworthiness based on observable signals — how long it's existed, how it's been used across other services, whether it's associated with prior fraud or abuse.

Example

An email address that's been in consistent use for several years across multiple legitimate services generally carries a stronger reputation signal than one created minutes before a transaction.

Why it matters

Email age and usage history are among the more difficult signals for a fraudster to fabricate convincingly at scale, since building genuine-looking history takes real time.

How it's used

Email reputation is typically one input among several in a broader risk model, not a standalone decision factor, since legitimate customers also sometimes use newly created emails.

Emulator Detection

Emulator detection identifies when a mobile app session is running on a software-simulated device (an emulator) rather than genuine physical hardware — a technique commonly used to automate fraud at scale without needing physical devices.

Example

A fraud ring runs hundreds of simulated Android device instances on a single server to create and operate fraudulent accounts at a scale impossible with physical devices.

Why it matters

Emulators allow fraud to be automated and scaled far beyond what physical device fraud would permit, and can be used to spoof device characteristics that would otherwise serve as a trust signal.

How it's detected

Emulators often have subtle but detectable technical inconsistencies compared to genuine hardware — sensor data that's absent or unnaturally uniform, performance characteristics inconsistent with claimed hardware — that detection tools check for.

F

False Decline

A false decline occurs when a legitimate customer is incorrectly flagged as fraudulent and blocked from completing a transaction or opening an account. It's the inverse error to letting fraud through: a real customer is rejected, not a fraudster accepted.

Example

A returning customer travels abroad and makes a purchase from an unfamiliar location on a new device. A rules-based system flags the mismatch and declines the transaction, even though the purchase was legitimate.

Why it matters

False declines carry a direct, measurable revenue cost, and repeated declines often push a customer to a competitor rather than trying again. Because false declines don't show up as "fraud losses" on a balance sheet, they're frequently under-tracked relative to their actual business impact.

How it's prevented

Systems that weigh multiple corroborating signals — rather than declining on a single mismatched attribute — reduce false declines by distinguishing genuine behavioral anomalies (a customer traveling) from actual fraud patterns.

False Negative

A false negative is when a risk system fails to flag an identity, transaction, or account that is actually fraudulent, allowing it through as if it were legitimate.

Example

A synthetic identity with a convincingly fabricated but internally consistent set of attributes passes a verification check and is approved, only to be used for fraud months later.

Why it matters

False negatives are the direct source of realized fraud losses; unlike false positives, which are visible immediately as customer friction, false negatives are often only discovered after the fact, when a loss has already occurred.

How it's reduced

Continuous model retraining against confirmed fraud outcomes helps a system adapt to fraud patterns it previously missed, though a false-negative rate of zero isn't a realistic target — the goal is minimizing it relative to false-positive tradeoffs.

False Positive

A false positive is when a risk system incorrectly flags a legitimate identity, transaction, or account as fraudulent or high-risk.

Example

A long-standing customer's transaction is flagged as suspicious because they made a purchase from a new country while traveling, despite the transaction being entirely legitimate.

Why it matters

A high false-positive rate creates unnecessary friction and manual review workload, and — when a false positive results in a declined transaction — becomes a false decline with direct revenue impact.

How it's reduced

Evaluating multiple corroborating signals rather than triggering on a single anomalous attribute reduces false positives by distinguishing plausible explanations (travel, a new device) from genuine fraud indicators.

First-Party Fraud

First-party fraud is fraud committed by a genuine account holder against the business they hold an account with — as opposed to a fraudster impersonating or stealing from someone else — such as disputing a legitimate charge or defaulting on credit with no intent to repay.

Example

A customer applies for a loan under their real identity with no intention of repaying it, or disputes a legitimate purchase as unauthorized to get a refund while keeping the goods.

Why it matters

First-party fraud is harder to detect with identity-verification tools alone, since the identity involved is genuine — detection instead relies on behavioral and intent signals rather than identity mismatch signals.

How it's detected

Patterns like repeat disputing behavior, applications with unusually optimistic risk profiles, or early default patterns inconsistent with genuine financial hardship can indicate first-party fraud.

Fraud Loss Rate

Fraud loss rate is the total value lost to confirmed fraud, typically expressed as a percentage of total transaction volume or revenue over a given period.

Example

A business processing $50M in transactions that experiences $250,000 in confirmed fraud losses has a fraud loss rate of 0.5%.

Why it matters

Fraud loss rate is one of the primary metrics used to evaluate a risk program's effectiveness, but it should be read alongside approval rate and false decline rate — a very low fraud loss rate achieved by declining large numbers of legitimate customers isn't actually a well-performing program.

How it's tracked

Accurate fraud loss rate tracking requires reliable downstream outcome data (confirmed chargebacks, confirmed fraud reports) fed back into the risk system, not just point-in-time transaction data.

Friendly Fraud

Friendly fraud is a chargeback filed by a genuine cardholder for a transaction they actually made, whether from a misunderstanding (not recognizing a charge description), a household dispute (a family member made the purchase), or intentional abuse of the dispute process.

Example

A cardholder doesn't recognize an unfamiliar billing descriptor on their statement and disputes the charge as fraudulent, even though they made the purchase.

Why it matters

Friendly fraud is often conflated with chargeback fraud generally, but the intent (or lack of it) matters for how a business responds — a confusing billing descriptor is a fixable process issue, while repeat intentional disputers are a fraud pattern.

How it's addressed

Clear billing descriptors and proactive receipt/confirmation communication reduce the misunderstanding-driven share of friendly fraud; behavioral tracking of repeat disputers addresses the intentional share.

I

IP Reputation

IP reputation is an assessment of an IP address's trustworthiness based on factors like whether it's associated with known proxy or VPN services, prior fraud activity, or hosting/datacenter infrastructure rather than genuine residential or mobile networks.

Example

Traffic originating from a known datacenter IP range associated with automated bot infrastructure carries a different reputation signal than traffic from a typical residential ISP address.

Why it matters

IP address alone is an increasingly unreliable standalone signal — legitimate users regularly use VPNs for privacy, and IP addresses are frequently shared or reassigned — but IP reputation combined with other signals still provides useful context.

How it's used

IP reputation is best used as one contributing signal alongside device and behavioral data, rather than as a blocking rule, given how common legitimate VPN and shared-network use has become.

Identity Graph

An identity graph is a network of connected data points — devices, emails, phone numbers, addresses, and behavioral signals — linked to a single identity over time. Rather than evaluating one attribute in isolation, an identity graph shows how attributes relate to and corroborate each other.

Example

A single person might be linked in an identity graph through a consistent pattern: the same device used across several accounts, an email created years ago and used consistently since, and a phone number tied to a stable address history.

Why it matters

Individual data points (an email, a device ID) can each look valid whether the identity behind them is real or synthetic. The relationships between those points — how long they've existed together, how consistently they co-occur — are much harder to fabricate convincingly.

How it's used

Risk models query the graph to assess whether an identity's attributes have a plausible, consistent history, rather than only checking whether each attribute passes independently.

Identity Resolution vs. Identity Verification

Identity resolution and identity verification are related but distinct: verification confirms that a specific claimed identity (this name, this document) is real and matches the person presenting it, while resolution determines whether multiple data points across time and channels belong to the same underlying identity, verified or not.

Example

Verification answers "does this driver's license belong to this person?" Resolution answers "are these three accounts, opened with different emails and phone numbers over two years, actually the same person?"

Why it matters

A system built only for verification can pass a synthetic identity that has a convincing (even genuine) document, because verification alone doesn't check whether that identity's broader signal history is coherent. Resolution catches inconsistencies verification alone would miss.

How they work together

Most robust risk programs use both: verification at the point of a specific claim (onboarding, a high-value transaction) and resolution continuously, to catch identities that pass verification individually but don't connect coherently over time.

Identity Theft

Identity theft is the unauthorized use of another person's personal identifying information to commit fraud — opening accounts, making purchases, or accessing existing accounts in the victim's name without their knowledge or consent.

Example

A fraudster uses a victim's stolen Social Security number and other personal details to open a new credit account in the victim's name.

Why it matters

Beyond the direct financial fraud, identity theft can have lasting consequences for the victim — damaged credit history, difficulty accessing legitimate financial services — that persist well after the fraudulent activity itself is stopped.

How it's distinguished

Identity theft differs from synthetic identity fraud in that it uses a genuine person's complete identity, rather than combining real and fabricated elements into a new, non-existent identity.

K

Know Your Business (KYB)

Know Your Business is the equivalent of KYC applied to business entities rather than individuals — verifying a company's legal existence, ownership structure, and beneficial owners before onboarding it as a customer or partner.

Example

A payment processor onboarding a new merchant verifies the business's registration, checks its beneficial owners against sanctions and PEP lists, and confirms its stated business activity matches observable signals.

Why it matters

Businesses can be used as fronts for fraud or money laundering, and beneficial ownership can be deliberately obscured through layered corporate structures, making KYB more complex than verifying an individual.

How it's performed

KYB typically combines business registry checks, beneficial ownership verification, and screening of associated individuals against watchlists.

Know Your Customer (KYC)

Know Your Customer is the regulatory and business process of verifying a customer's identity before or during onboarding, typically required in regulated industries like financial services to prevent fraud, money laundering, and other illicit activity.

Example

A bank opening a new account collects and verifies a customer's government-issued ID, address, and date of birth as part of its KYC process before the account is activated.

Why it matters

KYC is often a legal requirement, not just a risk-management best practice, particularly in banking, fintech, and other regulated sectors — non-compliance can carry regulatory penalties independent of any actual fraud outcome.

How it's performed

KYC combines document verification, database checks against known identity records, and sometimes biometric liveness checks to confirm the person onboarding matches the identity they claim.

L

Large Risk Model

A large risk model is a machine learning system trained on a broad set of historical identity and behavioral signals to produce a risk assessment — typically a score — for a given identity, account, or transaction. "Large" refers to the breadth and depth of the underlying signal set, not a specific model architecture.

Example

A large risk model might evaluate hundreds of signals simultaneously — device history, email age, address stability, behavioral patterns — to produce a single score used in an automated approve/decline/review decision.

Why it matters

Models trained on broader, longer-history signal sets generally generalize better to fraud patterns they haven't seen before than narrow, rules-based systems, which only catch fraud patterns someone has explicitly coded for.

How it's built and maintained

These models require continuous retraining against fresh outcome data (confirmed fraud, confirmed legitimate) to avoid drifting out of date as fraud patterns evolve.

Liveness Detection

Liveness detection is a technique used during identity verification to confirm that a live person is present during the verification process, rather than a photo, video, mask, or other spoofing attempt being presented to the camera.

Example

A verification flow might ask a user to blink, turn their head, or read a randomly generated number aloud, actions difficult to replicate convincingly with a static photo or pre-recorded video.

Why it matters

Without liveness detection, document and facial verification checks can potentially be defeated by presenting a photo or deepfake of the legitimate document holder rather than the actual person.

How it's performed

Liveness checks combine active challenges (prompted actions) and passive analysis (detecting subtle signs of screen replay, mask artifacts, or unnatural motion) to distinguish a live person from a spoofing attempt.

M

Manual Review

Manual review is the process of a human analyst evaluating a transaction, account, or identity that an automated system has flagged as ambiguous — not confidently legitimate, but not confidently fraudulent either.

Example

A transaction scores in a "gray zone" between the auto-approve and auto-decline thresholds, so it's routed to a fraud analyst who reviews the available signals and makes a final decision.

Why it matters

Manual review is typically the most expensive part of a fraud program per transaction, since it requires human time; minimizing the volume routed to manual review (without increasing false negatives) is a common efficiency goal.

How it's optimized

Providing reviewers with clear, explainable reason codes alongside a risk score — rather than a bare score — reduces review time per case and improves consistency across different reviewers.

Mule Account

A mule account is an account — sometimes belonging to a genuine but complicit or unwitting person, sometimes synthetic — used to receive, hold, and transfer illicitly obtained funds, typically as an intermediate step to obscure the money's origin.

Example

A person is recruited (sometimes unknowingly, believing it's a legitimate job) to receive funds into their personal bank account and quickly forward them elsewhere, taking a small commission — the funds are proceeds of fraud committed against someone else.

Why it matters

Mule accounts are a critical link in laundering fraud proceeds; detecting and disrupting mule networks can prevent losses from a wide range of upstream fraud types, not just the mule activity itself.

How it's detected

Accounts that receive funds from many unrelated sources and quickly transfer them onward — a pattern inconsistent with typical personal account activity — are a common mule signal.

Multi-Factor Authentication (MFA)

Multi-factor authentication requires a user to verify their identity using two or more independent methods — typically something they know (a password), something they have (a phone or hardware key), or something they are (a fingerprint) — before granting access.

Example

Logging into an account with a correct password, then confirming a code sent to a registered phone number, is a common two-factor implementation of MFA.

Why it matters

MFA significantly raises the difficulty of account takeover, since a fraudster who has obtained stolen credentials (something the user knows) typically still lacks the second factor (something the user has).

How it's implemented

Common second factors include SMS codes, authenticator apps, hardware security keys, and biometric checks — each with different tradeoffs in security and user friction.

N

Network/Link Analysis

Network analysis (or link analysis) examines the connections between identities, accounts, devices, and other entities to identify clusters or patterns suggestive of coordinated fraud, rather than evaluating each entity independently.

Example

A group of accounts that individually appear unrelated may share a device, a payment method, and overlapping IP ranges — a pattern that link analysis surfaces but single-account review would miss.

Why it matters

Organized fraud rings deliberately structure individual accounts to look unrelated; network analysis is often the only way to detect coordinated abuse that's invisible when each account is evaluated in isolation.

How it's used

Graph-based techniques identify clusters of connected entities and flag unusually dense or suspicious connection patterns for review.

O

Onboarding Friction

Onboarding friction refers to the effort, time, and steps a new customer must go through to complete account creation or a similar process — additional identity checks, document uploads, or verification steps all add friction.

Example

Requiring a government ID upload and a selfie liveness check adds friction compared to a signup flow that only requires an email and password, but may be necessary depending on the risk profile of the product.

Why it matters

Friction has a measurable cost — abandoned signups — that must be weighed against the risk-reduction benefit of additional checks; the right balance depends heavily on the specific product and its risk profile.

How it's optimized

Risk-based approaches apply friction selectively — light checks for most users, escalating to stronger verification only for identities or behaviors that present elevated risk signals — rather than applying uniform friction to every signup.

P

Personally Identifiable Information (PII)

Personally Identifiable Information is any data that can be used, alone or combined with other data, to identify a specific individual — names, Social Security numbers, addresses, dates of birth, and similar identifiers.

Example

A name alone might not uniquely identify someone, but a name combined with a date of birth and address typically does — that combination is treated as PII even if no single element is.

Why it matters

PII handling is subject to data protection regulations in most jurisdictions (GDPR, CCPA, and others), and businesses that collect or process it for identity verification and fraud prevention purposes take on corresponding compliance obligations.

How it's protected

Common practices include minimizing the PII collected to what's genuinely necessary, encrypting it at rest and in transit, and limiting internal access on a need-to-know basis.

Phishing

Phishing is a social engineering technique where a fraudster impersonates a legitimate entity — typically via email, text, or a fake website — to trick a victim into revealing credentials, personal information, or making a fraudulent payment.

Example

A fraudster sends an email that closely mimics a bank's official communication, directing the recipient to a fake login page that captures their username and password when entered.

Why it matters

Phishing is frequently the entry point for other fraud types — stolen credentials from a phishing attack can then be used for account takeover, and stolen personal information can feed synthetic identity construction.

How it's mitigated

User education helps, but technical mitigations — flagging logins immediately following a likely-phished credential entry, or requiring a second factor that phishing alone can't capture — are more reliable at scale.

Phone Reputation

Phone reputation is an assessment of a phone number's trustworthiness based on factors like carrier type (mobile vs. VoIP), how long the number has been associated with a given identity, and whether it's been linked to prior fraud.

Example

A mobile number with a multi-year association to a consistent identity generally carries a different reputation signal than a newly issued VoIP number with no prior history.

Why it matters

VoIP and disposable virtual numbers are cheaper and faster to obtain than traditional mobile lines, making phone type and history a useful signal for distinguishing genuine users from those seeking to avoid traceability.

How it's used

Phone reputation combines carrier-type data with historical association data, weighed alongside other identity signals rather than used as a standalone block.

Politically Exposed Person (PEP)

A Politically Exposed Person is an individual who holds, or has held, a prominent public position — such as a senior government official, judge, or military leader — or is closely associated with someone who does, and is therefore considered higher-risk for potential involvement in bribery or corruption.

Example

A former government minister opening an account at a financial institution would typically be flagged as a PEP, triggering enhanced due diligence beyond standard onboarding checks.

Why it matters

PEP status doesn't imply wrongdoing, but regulations in most jurisdictions require additional scrutiny for PEPs given their elevated exposure to corruption risk by virtue of their position.

How it's identified

PEP screening relies on maintained databases of public officials and their known associates, cross-referenced against a customer's identifying information during onboarding.

Proxy/VPN Detection

Proxy and VPN detection identifies when a connection is being routed through an intermediary service designed to mask the user's true IP address or location.

Example

A transaction claiming to originate from one country but routed through a commercial VPN service registered in a different country would be flagged by proxy/VPN detection.

Why it matters

While VPN use is common and legitimate for privacy reasons, it's also a technique used to evade geographic restrictions, mask true location during fraud, or obscure connections between related fraudulent accounts.

How it's implemented

Detection relies on maintained databases of known proxy, VPN, and datacenter IP ranges, combined with technical signals (latency patterns, routing characteristics) that can indicate masked traffic even from services not in a known database.

R

Refund Fraud

Refund fraud is when someone obtains a refund they aren't legitimately entitled to — for example, by falsely claiming non-delivery, returning a different or damaged item than what was purchased, or exploiting a merchant's refund process directly.

Example

A customer claims a package never arrived despite delivery confirmation, or returns an empty box while claiming a refund for the full contents.

Why it matters

Refund fraud directly erodes margin, and generous, low-friction refund policies — while good for genuine customer experience — can be disproportionately exploited by repeat abusers if not monitored.

How it's detected

Behavioral patterns — a customer with an unusually high refund rate relative to typical customers, or claims that don't align with delivery and tracking data — help distinguish abuse from genuine refund requests.

Return Fraud

Return fraud involves exploiting a retailer's return policy — such as returning stolen or used merchandise for a refund, or returning a different (often lower-value) item than what was originally purchased.

Example

A person purchases an item, uses it, then returns it claiming it was defective or unwanted, exploiting a liberal return window.

Why it matters

Retailers with generous, customer-friendly return policies are more attractive targets for this fraud type, creating a direct tension between customer experience goals and fraud exposure.

How it's detected

Tracking return frequency and patterns per customer, and flagging accounts with disproportionately high return rates relative to purchase volume, helps identify abuse without penalizing occasional genuine returns.

Risk Appetite

Risk appetite is the level of fraud risk a business is willing to accept in exchange for growth, revenue, or customer experience goals — an explicit or implicit tradeoff, since eliminating fraud risk entirely would also eliminate most legitimate business.

Example

A business might explicitly decide it's willing to accept a certain fraud loss rate if it corresponds to a meaningfully higher approval rate and lower onboarding friction for legitimate customers.

Why it matters

Risk thresholds and model tuning decisions should be grounded in an explicit risk appetite rather than defaulting to maximum conservatism, since overly conservative settings suppress legitimate growth without necessarily being a deliberate business choice.

How it's set

Risk appetite is typically set by weighing historical fraud loss data, false decline cost, and broader business growth priorities — and should be revisited periodically as those factors change.

Risk Score

A risk score is a numeric output — often inversely related to a trust score — indicating the likelihood that an identity, transaction, or account is fraudulent or otherwise poses risk, generated by a risk model based on available signals.

Example

A transaction with a mismatched billing address, a new device, and an unusually large purchase amount for that customer might receive an elevated risk score, prompting additional review.

Why it matters

Risk scores let a business set a single consistent policy (thresholds for approve/review/decline) across large transaction volumes rather than making ad hoc individual judgment calls.

How it's calibrated

Thresholds should be set and periodically re-validated against actual outcome data — confirmed fraud and confirmed legitimate cases — since a model's score distribution can drift as fraud patterns and customer behavior change over time.

Risk Signal

A risk signal is any single data point — a device ID, an email's age, a behavioral pattern, a velocity metric — used as an input into a broader risk assessment, distinct from a score or decision, which is an output derived from combining many signals.

Example

"Email created 3 days ago" is a risk signal; it isn't itself a decision, but it's one input a risk model weighs alongside other signals to reach a score.

Why it matters

No single signal is reliably decisive on its own — a new email alone doesn't mean fraud, since many genuine customers also have new emails — which is why robust risk decisioning combines many signals rather than relying on any one.

How it's used

Signals are typically weighted and combined within a model rather than evaluated with simple pass/fail rules, allowing the system to account for context (a new email plus a new device plus an unusual purchase pattern is more meaningful than any signal alone).

S

SIM Swap Fraud

SIM swap fraud occurs when a fraudster convinces a mobile carrier — often through social engineering or an insider — to transfer a victim's phone number to a SIM card the fraudster controls, allowing them to intercept SMS-based verification codes.

Example

A fraudster impersonates a victim to their mobile carrier, claiming a lost phone, and requests the victim's number be transferred to a new SIM card, after which they can receive SMS one-time passcodes intended for the real account owner.

Why it matters

SIM swap fraud specifically undermines SMS-based multi-factor authentication — a factor many services rely on as their primary "something you have" check — making accounts protected only by SMS MFA vulnerable despite MFA being enabled.

How it's mitigated

Using authentication factors that don't rely on SMS (authenticator apps, hardware keys) reduces exposure; behavioral and device signals can also flag account access following a suspicious phone number change.

Sanctions Screening

Sanctions screening is the process of checking an individual or business against government-maintained lists of sanctioned entities — people, organizations, or countries subject to legal restrictions — before or during onboarding and transaction processing.

Example

A financial institution checks a new customer's name and identifying details against the OFAC Specially Designated Nationals list and similar international sanctions lists before approving the account.

Why it matters

Transacting with a sanctioned entity can expose a business to significant legal and regulatory penalties, independent of whether any fraud occurred — this is a compliance requirement, not just a risk-reduction measure.

How it's performed

Screening typically involves fuzzy name-matching against sanctions databases (to catch spelling variations and transliterations) combined with additional identifying details to reduce false matches.

Step-Up Authentication

Step-up authentication is the practice of requesting additional identity verification only when a specific action or context triggers elevated risk, rather than applying the same authentication requirement to every interaction.

Example

A customer logging in from their usual device isn't prompted for anything extra, but the same customer attempting a large transfer to a new recipient is prompted for an additional verification step.

Why it matters

Applying strong authentication uniformly to every action creates unnecessary friction for low-risk activity; step-up authentication concentrates that friction where the risk actually justifies it.

How it's triggered

Step-up prompts are typically triggered by a risk score crossing a threshold, an anomalous behavioral signal, or a specific high-value action type.

Synthetic Identity Fraud

Synthetic identity fraud is a type of fraud where someone combines real and fabricated personal information — such as a real Social Security number paired with a false name, birthdate, or address — to create a new identity that doesn't correspond to any real person. It's sometimes called "Frankenstein fraud."

Example

A fraudster pairs a real, stolen or purchased Social Security number with a fabricated name and address to open a new account. Because no existing credit file is being altered, standard identity-theft alerts don't trigger — the "person" simply doesn't exist yet, so the fraud can go undetected for months while the synthetic identity builds a track record.

Why it matters

Synthetic identities are built to pass single-attribute checks — email, phone, and device can each look individually legitimate. Losses are harder to attribute to a specific victim than traditional identity theft, since there's no real person to report it, which makes this fraud type both underreported and slow to detect through conventional means.

How it's detected

Because synthetic identities are fabricated rather than stolen, they lack a genuine history of connected, consistent behavior over time. Detection approaches that evaluate signal history and connectivity, rather than checking attributes in isolation, are generally more effective than single-signal verification.

T

Thin-File Identity

A thin-file identity is a real person with a limited digital or credit history — for example, a young adult, a recent immigrant, or someone who transacts primarily offline — making it harder for identity systems to verify them using conventional history-based signals.

Example

A college student applying for their first credit product has no existing credit history and a short digital footprint, which can cause automated systems to flag them as high-risk by default, even though they present no actual fraud risk.

Why it matters

Systems that rely heavily on historical depth to establish trust risk producing false declines for legitimate thin-file customers — a segment that, over time, represents real and growing revenue if approved responsibly.

How it's addressed

Evaluating a broader mix of signal types (not just credit history) — device consistency, verified contact information, behavioral plausibility — allows thin-file identities to be assessed on the signals they do have, rather than penalized for the ones they lack.

Third-Party Fraud

Third-party fraud is fraud committed by someone using another person's identity or account without their knowledge or consent — the traditional model most people associate with "identity theft" or "fraud."

Example

A fraudster uses a stolen credit card number to make an unauthorized purchase; the actual cardholder had no knowledge of or involvement in the transaction.

Why it matters

Third-party fraud is generally more amenable to identity-verification and device/behavioral signal detection than first-party fraud, since the perpetrator's identity or behavior genuinely differs from the legitimate account holder's.

How it's detected

Mismatches between the transacting party's signals (device, location, behavior) and the legitimate account holder's established patterns are the primary detection mechanism.

Triangulation Fraud

Triangulation fraud involves a fraudster setting up a fake storefront, taking real orders and payment from genuine customers, then using stolen card details to actually fulfill those orders through a legitimate retailer — the genuine customer receives their product, but the legitimate retailer is defrauded via the stolen card.

Example

A fraudster lists a popular product at a below-market price on a fake marketplace listing; when a genuine buyer orders and pays, the fraudster uses a stolen credit card to purchase and ship that exact product from a real retailer directly to the buyer, pocketing the buyer's payment.

Why it matters

This fraud type is unusually hard to detect from the defrauded retailer's side, since the shipping address is a genuine, non-fraudulent recipient — the fraud signal is entirely in the payment method, not the delivery pattern.

How it's detected

Detection relies on identifying the stolen card itself (via card-network fraud signals) rather than shipping or recipient anomalies, since the delivery side of the transaction looks entirely normal.

True Positive

A true positive is when a risk system correctly identifies an identity, transaction, or account as fraudulent, and that assessment is subsequently confirmed.

Example

A transaction flagged for review due to a mismatched device and identity graph inconsistency is confirmed as fraudulent after investigation.

Why it matters

True positive rate, alongside false positive rate, is one of the core metrics used to evaluate whether a risk model is actually performing well, rather than just generating a high volume of flags.

How it's tracked

True positives require a confirmed outcome (a chargeback, a fraud report, an investigation finding) to count — a flagged transaction alone isn't yet a confirmed true positive until the outcome is known.

Trust Score

A trust score is a single numeric or categorical output summarizing a risk model's assessment of how likely an identity, account, or transaction is to be legitimate, based on the underlying signals evaluated.

Example

A trust score might combine device history, identity graph consistency, and behavioral signals into a single 0–100 value used to automatically approve, decline, or route a transaction to manual review.

Why it matters

A single score allows risk decisions to be automated at scale and consistently applied, but a score is only as good as the signals and model behind it — the number itself doesn't explain the reasoning without accompanying reason codes.

How it's used

Businesses typically set score thresholds (e.g., approve above X, review between X and Y, decline below Y) calibrated against their own risk appetite and historical outcome data, rather than using a universal cutoff.

U

Underwriting (Risk)

In a risk context, underwriting is the process of evaluating an applicant or transaction against a set of criteria to decide whether to accept the associated risk — historically associated with insurance and lending, but applicable to any approve/decline risk decision.

Example

A lender evaluates a loan applicant's identity, credit history, and other risk signals to decide whether to approve the loan and on what terms.

Why it matters

Underwriting decisions directly shape a business's risk exposure and growth — overly strict underwriting limits growth by rejecting viable customers, while overly loose underwriting increases losses.

How it's automated

Modern underwriting increasingly combines automated risk scoring with human review for edge cases, rather than relying entirely on either manual judgment or a fully automated black-box decision.

V

Velocity Check

A velocity check evaluates how frequently a given signal (an email, device, card number, IP address) appears across transactions or account activity within a defined time window, flagging unusually high frequency as a risk indicator.

Example

A single device attempting to create 20 new accounts within an hour would trigger a velocity check, since that frequency is implausible for genuine, independent users.

Why it matters

Velocity checks are effective at catching automated, high-volume abuse (bot-driven account creation, card testing) that wouldn't necessarily look suspicious evaluated one transaction at a time.

How it's implemented

Velocity thresholds need to be calibrated per use case — what's a suspicious frequency for account creation is different from a suspicious frequency for repeat purchases from a loyal customer.

Top