EducationPublished July 20, 2026·4 min read

In fraud the same behaviour can be fraudulent in one business and completely legitimate in another

A sneaker-drop “bot attack” that looked like fraud was actually top customers. Context — not raw anomalies — decides what a fraud rule should do.

IH

Idan Hayon

Co-Founder & CEO

In fraud the same behaviour can be fraudulent in one business and completely legitimate in another

Early in my career, I worked with one of the world’s largest sneaker brands. They were launching a limited-edition release.

Within minutes, the website was flooded with what looked like a textbook fraud attack — bots, disposable email addresses, suspicious IPs, customers trying to create multiple accounts, and dozens of purchase attempts happening simultaneously.

We did what any fraud team would do. We started blocking them. About an hour later, I got a call asking, what exactly did you do?

It turned out those weren’t fraudsters. They were some of the brand’s best customers — professional sneaker resellers.

In that market, limited releases create enormous demand. People prepare bots, multiple accounts, and automated purchasing tools because products sell out within minutes and can often be resold for two, three, or even five times the original price.

So what looked like suspicious behaviour was simply how that market operated.

The challenge was understanding which unusual behaviour was legitimate. That experience changed how I think about fraud.

Every industry has its own customer behaviour, incentives, and normal. A fraud act that works perfectly for a SaaS business might perform terribly for sneaker drops. A model trained on eCommerce transactions may fail completely in travel or gaming.

The data alone won’t tell you that. Context will.

That’s why I’ve always believed fraud analysis is about much more than finding statistical anomalies. It’s about understanding the business behind the transactions.

If you’re seeing similar patterns, or just want a clearer view of how your system is behaving, feel free to reach out. Happy to take a look.

Frequently asked questions

Can the same checkout behaviour be fraud in one business and fine in another?

Yes. Bots, multiple accounts, and burst purchasing can be attacks in one vertical and normal customer behaviour in another — for example limited sneaker releases. Rules need business context, not just anomaly detection.

Why do generic fraud models fail across industries?

Each industry has different incentives and “normal” behaviour. A rule that works for SaaS can hurt sneaker drops; a model trained on eCommerce may fail in travel or gaming.

Ready to See It on Your Data?

Book a live walkthrough and see how FraudPulse turns your payment data into actionable fraud intelligence.

Book a Demo