Nine fraud types in payments and their legitimate twin
Lists of fraud types describe what the attacker does. This one adds who else, inside your own customer base, leaves exactly the same trace.
That customer always exists, and they are the one who pays the bill when you block a pattern blindly. We call them the legitimate twin of the fraud type: the honest behaviour that produces the same signal as the attack.
This series covers nine fraud types. There are many more, and new variants show up all the time. These nine are the ones that come up daily in payments and lending, and the ones that most often end up hitting an honest customer by mistake.
Each one comes in three parts: how it attacks, who looks the same and is honest, and how the attacker mutates once you start detecting them. They run from the loudest to the most invisible.
- Card testing
- Velocity
- First big purchase
- Identity rings
- Social engineering
- The patient one
- The sleeper
- Synthetic identity
- Bad-faith dispute
1. Card testing
Attacks by: running through a batch of stolen cards with minimum charges to see which ones are still alive, dropping the ones that decline.
Legitimate twin: the student who always buys the cheapest thing, the customer with no money left retrying for less each time, and the new user who types the CVV wrong.
2. Velocity
Attacks by: squeezing a single stolen card for everything it has before the cardholder reports it.
Legitimate twin: the shop owner running all the business purchases in two hours, and the person who pays every bill of the month in one sitting.
3. First big purchase
Attacks by: a freshly built identity, one large purchase, then gone.
Legitimate twin: the customer who barely uses your product and today is buying the appliance they had been putting off.
4. Identity rings
Attacks by: several fake identities run by the same person, with fewer devices than identities.
Legitimate twin: the family sharing one card across four phones, and the person rotating cards to optimise rewards.
5. Social engineering
Attacks by: holding every real detail of the victim, so the transaction looks flawless except for the device.
Legitimate twin: the customer travelling, and the family sharing a card across several devices.
6. The patient one
Attacks by: avoiding every obvious signal, watching their own risk level and pulling back the moment it rises.
Legitimate twin: any customer with a mid-range ticket and mid-range frequency.
7. The sleeper
Attacks by: weeks of boring, correct activity, and a single day where they take everything.
Legitimate twin: the freelancer who gets paid for a project, catches up on everything in three days, and goes quiet again.
8. Synthetic identity
Attacks by: fake details that look real, weeks of building trust with on-time payments, and one day draining the entire credit line.
Legitimate twin: the genuinely new customer, who also starts small and grows.
9. Bad-faith dispute
Attacks by: the real cardholder buying, receiving the product, and weeks later claiming they do not recognise the charge.
Legitimate twin: the teenager who used their parent's card, and the parent disputing in good faith.
Why the twin matters
Risk teams know the fraud types. The problem shows up when the rule that cuts one of them also cuts its twin.
That is why the useful question is which of your customers looks like the fraud type hitting you.
So how do you solve it?
Tuning this by hand takes days, and every day costs chargebacks and good sales. That is what we are solving at Frauddi. We will show you on your own data.
Book a free demo