The biggest mistake in fraud analysis is trusting individual indicators
High amount, disposable email, new device, VPN — none of those signals mean much alone. Good fraud analysis asks whether the red flags tell a coherent fraud story.
Idan Hayon
Co-Founder & CEO
When people first start working in fraud, they often treat every indicator the same.
- High transaction amount? Bad.
- Disposable email? Bad.
- New device? Bad.
- VPN? Bad.
It’s much more nuanced. Every one of those signals can belong to a perfectly legitimate customer, and every fraudulent transaction can sometimes look completely normal.
A disposable email address might be suspicious, or it might belong to a privacy-conscious customer. A VPN could be someone hiding their identity, or an employee working remotely.
A customer making five payment attempts could be testing stolen cards, or they could be struggling with their bank.
The indicator itself tells you very little.
That’s why experienced fraud analysts don’t just ask, which risk signals do we have?
But more importantly, what’s the fraud story? Can I explain how this fraud happened? What was the fraudster trying to achieve? How did they get there? Do these signals make sense together? Or are they simply a collection of unrelated bad indicators?
I’ve seen plenty of transactions with several suspicious signals that turned out to be completely legitimate. I’ve also seen fraudulent transactions with almost no obvious indicators at all. The difference was the ability to understand the behaviour behind it.
Good fraud analysis is about asking whether those red flags tell a coherent story. If you can’t explain the fraud itself, there’s a good chance you’re looking at noise instead of risk.
That’s also why fraud looks different across every industry.
The same behaviour can be perfectly normal for one business and highly suspicious for another. Without understanding the context, it’s very easy to optimise for the wrong signals.
Over time, I’ve found that the best fraud analysts develop a sense for fraud. The goal isn’t to find suspicious transactions. It’s to understand fraudulent behaviour.
That’s where the decisions become much clearer.
If you want a clearer view of how your system is behaving, feel free to reach out. Happy to take a look.
Frequently asked questions
Are individual fraud signals enough to decline a transaction?
Usually not. Signals like disposable email, VPN, or high ticket size can be legitimate. Strong decisions come from whether the signals together tell a coherent fraud story for that business.
What should fraud analysts ask beyond risk scores?
Ask what the fraudster was trying to achieve, how they got there, and whether the signals make sense together — or whether you are looking at unrelated noise.
More from the blog
Ready to See It on Your Data?
Book a live walkthrough and see how FraudPulse turns your payment data into actionable fraud intelligence.
Book a Demo