DataSchutz Home Page
Sections
DataSchutz Journal Fraud intelligence
Journal menu
Journal home Latest analysis Categories About DataSchutz Talk to DataSchutz

DataSchutz Journal Fraud intelligence

Signals, schemes and the systems built to stop them.

Field notes for fraud, risk and payment teams navigating the fast-moving space between a suspicious signal and an irreversible loss.

Analysis by risk domain

Showing all 10 analyses

Card-not-present fraud is no longer a card-only problem.

A remote payment can look normal in isolation. The stronger signal often lives in the relationship between device integrity, session behaviour, location, merchant context and transaction history.

What changed

Attackers increasingly distribute activity across accounts, devices and short-lived sessions to avoid simple threshold controls.

What to watch

New device and location combinations, unusual merchant sequences and abrupt changes in transaction cadence.

DataSchutz Research DeskFraud Systems & Payment Risk
Read lead analysis Coming soon See how contextual decisions work
Context studyRemote payment · 08:42:16
Remote payment context map An abstract relationship map connecting device, location, session, merchant and transaction history signals to an elevated contextual-risk assessment. Device Location Session Merchant Transaction history Pattern shift Elevated contextual risk

Why Are We Still Trusting Passwords to Protect Millions in Digital Payments?

Correct credentials can verify access, but they cannot always verify intent. Payment security needs contextual, continuous trust.

Read the article

Latest Analysis

Concise briefings on the behaviours, infrastructure and contextual clues behind common fraud journeys.

01Account Access6 min read

Account takeover starts before the unusual payment.

Behavioural drift, device changes and location inconsistencies can reveal a compromised session before funds begin to move.

Read briefing

Review the full session rather than the final transaction alone. New recovery activity, unfamiliar device integrity, changed navigation patterns and beneficiary setup can form a stronger combined signal.

02Physical Card Risk4 min read

When a familiar card appears in an unfamiliar context.

Lost, stolen, skimmed and cloned cards often produce subtle breaks from established location and spending behaviour.

Read briefing

Look for impossible travel, changes in merchant type, unusual transaction velocity and a mismatch between the payment location and the customer’s trusted device context.

03Execution Threats8 min read

Replay, relay and remote access can imitate a trusted journey.

Valid credentials do not guarantee a valid session when traffic is proxied, requests are replayed or a device is remotely controlled.

Read briefing

Session timing, request sequencing, device integrity and network consistency help distinguish a genuine customer journey from activity being relayed or reproduced elsewhere.

04Manipulated Payments7 min read

The customer authorised the payment. The scammer designed the decision.

Authorised push payment fraud requires controls that can recognise coercion, beneficiary novelty and unusual payment behaviour without relying on credential theft.

Read briefing

Beneficiary age, payment purpose, recent account changes and deviations from normal transfer behaviour can create a useful intervention point before an instant payment is released.

05Identity Risk5 min read

Synthetic identities are built to look ordinary.

The risk appears in the inconsistencies between account history, device relationships, transaction context and the identity’s wider behaviour.

Read briefing

Single-point identity checks can miss profiles assembled from mixed real and fabricated attributes. Persistent contextual comparison can help expose activity that does not fit the claimed customer.

06Networked Fraud6 min read

Collusive fraud hides in relationships between events.

Coordinated behaviour becomes clearer when related devices, sessions, merchants and beneficiaries are viewed as a network.

Read briefing

Repeated infrastructure, shared device traits, converging destinations and patterned timing can connect activity that appears unrelated when each transaction is assessed separately.

07Beneficiary Risk5 min read

Mule accounts turn isolated scams into a payment network.

Unusual destinations, rapid movement and shared beneficiary patterns can reveal where stolen funds are being consolidated or dispersed.

Read briefing

Combine beneficiary novelty with velocity, account age, payment corridors and links to prior suspicious sessions. The destination can carry as much risk context as the sender.

08Instant Payments4 min read

Real-time payments compress the window for doubt.

UPI and other instant-payment environments need contextual decisions that arrive before authorisation becomes an irreversible loss.

Read briefing

Prioritise signals available inside the payment window: session integrity, beneficiary context, transaction deviation and recent changes to the customer’s device or account.

09Session Integrity6 min read

A trusted login can still contain an untrusted session.

Device spoofing and session manipulation can preserve familiar credentials while changing the conditions under which they are used.

Read briefing

Monitor integrity anomalies, unfamiliar device characteristics, location conflicts and sudden behavioural changes throughout the session—not only at the login boundary.

Turn these patterns into decision logic.

Explore how DataSchutz applies contextual signals across payment and digital banking journeys.