Blog / Link analysis & graph databases, Fraud analytics

How to detect ecommerce fraud rings and online fraud networks

We believe that graph networks are an unequivocally powerful technique to detect and prevent the activities of fraud rings.

How to detect ecommerce fraud rings and online fraud networks

That fraudsters often collude is well-known.

If a merchant has poor security, that information is shared at rapid speed, making a small problem very large indeed. And fraudsters will often operate across a number of merchants taking whatever goods they can, with as large a value as they can.

Fraud rings are important to get right, and in this article we're going to see why. We're also going to discuss Ravelin's approach to link analysis for ecommerce fraud.

From Fraud-as-a-Service operations to old-school setups where several criminals have a separate role each, and all the way to criminal AI agents, fraud rings take many forms – and can cause a lot of harm to ecommerce businesses.

What is a fraud ring?

Also called a fraud network, a fraud ring is an organized group of fraudsters who are working together, coordinating to commit large-scale schemes. In ecommerce, fraud rings can be formed to take over accounts, commit promo or refund abuse, set up burner accounts using synthetic identities and more.

The concept of multi-accounting is related to this: This is several accounts that appear connected but may not belong to several different fraudsters but one, setting them up in their attempt to appear legitimate and/or scale their operations.

Detecting networks using graphs and link analysis

To catch multi-accounting and fraud rings, Ravelin has built a powerful graph network interface for link analysis called Connect.

For Ravelin, a network is made up of user accounts linked by shared characteristics such as

  • email address
  • telephone number
  • device ID
  • vehicle (for suppliers/drivers)
  • payment card
    etc

These links may have differing strengths, from the tentative (shared temporal behavior), to the intermediate (shared locations, similar email patterns, shared IP addresses), to the strong (shared cards, shared devices).

You can see a complete list of the points that connect different accounts on Connect in our Developer Documentation for Connect.

Graph networks at Ravelin

We love networks, and have developed networks as part of our fraud detection technologies from the outset. Graphing a network is an unequivocally powerful technique, melding the best of computer processing (linking millions of data points and displaying patterns) with human processing (visually detecting and judging meaningful patterns).

Once we have identified a network, we test each node in the network for fraudulent patterns. Many networks display collective fraudulent attributes distributed across many or several nodes – a clear indication of fraud.

In such cases we can move swiftly to disable or suspend that network, in a way which may or may not be apparent to the members, depending on the strategy we deploy.

Some networks may appear to contain only a few fraudulent nodes, with the rest appearing to be normal customers. In such cases we can put the entire network on an alert list and monitor the collective behavior closely until the tolerance threshold is breached.

Connect serves several different purposes at Ravelin. It can

  • help investigations and human understanding of the fraudscape,
  • be leveraged to build machine learning features,
  • as well as be used to quickly respond to coordinated fraud rings by near-instantly blocking associated accounts during a live fraud attack incident.

Fraud rings vs shared shopper attributes

We have found on many occasions that networks of accounts linked by various characteristics (shared credit cards, shared locations, shared behavior) are actually describing real groups of people who know each other in real life. This is not surprising – criminal activity is frequently social and credit card fraud even more so. We have uncovered networks of criminals in Toronto, London, Singapore, Dublin and elsewhere, in which credit card fraud was just a small part of the criminality – yet still detectable by this technique.

At the same time, we're well aware that there are legitimate shoppers out there who share some characteristics. For example, family members with shared access to a device, or housemates sharing an address. Although the network will make these connections clear, we will not classify reasonable use as fraud. Criminal networks have a lot more shared, and their fraud scores are higher than legitimate shoppers.

Single-merchant networks: The most effective dataset against fraud rings

At Ravelin, we are confident that single-merchant network link analysis is the best way to detect fraud rings. Although we employ consortium data to help detect fraud, it does not form part of our graph network analysis. This way, Ravelin merchants get the best of both worlds: efficient link analysis as well as some wider network intelligence, where useful.

In uncovering fraud networks, the conclusion we have reached is that the best dataset is a single merchant’s own network. The simple reason for this is that fraudsters often return to a merchant to exploit a weakness they’re now familiar with. After all, we know that each merchant's fraud is different, even within the same sector – and fraud networks are the same.

When a merchant's defenses have a weakness, fraudsters share it online, and may also set up multiple accounts to take advantage. Any weaknesses in these defenses constitute patterns that we can quickly detect. So we can stop a repeat offender and we can stop fraudsters connected to that user. It’s the 21st-century version of the aphorism that the thief always returns to the scene of the crime.

Why extending link analysis across merchants can be problematic

You would think therefore that extending this capability across merchants (thus employing consortium data within link analysis) should be effective. The truth is that there are significant caveats.

1. False positives and victim insults: A troubling problem with this approach is that it can potentially lead to blacklisting the wrong person: the victim of the fraud, rather than the perpetrator. This can be mitigated to some extent by use of techniques such as device fingerprinting and behavioral analysis. However, you need to be very confident of having the right tools in place to detect this and even then, the risk of false positives is higher than many of our growth-focused clients would like to bear.

2. Criminals are shoppers too: Such an approach would also assume that a fraudster with one merchant will be a fraudster with all others. This is possibly (although not completely) accurate for a certain type of criminal fraudster – the one who actively buys stolen card data to make online purchases.

However, it is equally possible (and common), that some fraudsters conduct some business with stolen cards while making legitimate purchases with their own. One may argue that such people should be denied all rights to online purchasing but this casts merchants and fraud providers into an uncomfortable position of labeling someone as a criminal even when they are not in the act of committing a crime.

3. What about first-party fraud? A third flaw in unfettered network effect fraud detection is that it is inadequate to address the complexities surrounding first-party (“friendly”) fraud. This is an interesting mix of the two scenarios outlined above. Rather than mitigated by device fingerprinting, the problem is compounded by it, because there is no third party, and the fingerprinting describes the actual customer.

Moreover, we would be again cast in the role of ethical judge – should we block Customer A with Client X because Customer A falsely charged back some transactions with Client Y, citing fraud?

Right tools, right place for the right result against fraud rings

In combination with AI fraud detection technology in ecommerce, graph network link analysis is a fantastic technique that delivers results against fraud networks and fraud rings, as well as multi-accounting.

However, it is not a panacea. It is important to mitigate against the potential for false positives and for weak connections to be mistaken for strong by limiting such analysis to each merchant separately. Within a single merchant's network, graph networks such as Connect provide astonishing insight by matching the best of computing power with human insight, resulting in a fantastic fraud detection strategy that every merchant should consider leveraging.

Ravelin Logo

Industry-leading graph networks

See Ravelin's leading graph networks in practice by setting up a demo with our team.

Further reading

Author