Search
Choose a style
Dark
Light
Time to read: 6 min

Sift: Fraud is no longer a transaction problem, it is a network problem

System hacked fraud warning alert. Cyber security on mobile app
Editorial credit: TippaPatt / Shutterstock.com

Fraud has traditionally been treated as a transaction-level problem. A suspicious payment appears, a risk system flags it and a decision is made on whether to approve or block it.

However, the coordinated nature of digital fraud is challenging that model.

According to Maria Benjamin, Trust & Safety Architect at Sift, businesses need to look past individual transactions and accounts to understand the infrastructure connecting fraudulent activity across platforms, payment methods and industries.

Data from Sift’s latest Digital Trust Index underlines the scale of that challenge. Users associated with fraudulent chargebacks recorded a 15.8x higher Mean Global Linkage than legitimate users, indicating that fraudulent accounts are significantly more likely to share devices, payment instruments and identity information.

For Benjamin, the figure provides compelling evidence that businesses are facing organised networks rather than isolated opportunists.

“A number like 15.8x rules out coincidence,” she told Payment Expert. “Legitimate users don’t share devices, payment instruments, and identity fragments at that density. Fraud rings do, because they’re built on reusable infrastructure.

“That’s the real shift: a chargeback stops being a single event to close out and becomes a thread to pull.”

Rather than simply investigating the transaction responsible for triggering an alert, Benjamin argued that risk teams should examine the wider network attached to it.

“The linkage score tells you there’s a network attached to it, and the response has to match: mapping and disrupting the shared infrastructure, not just reviewing the one transaction that tripped the alert,” she continued.

“Usually what’s attached is bigger than the initial case suggested.”

Partial visibility gives fraudsters an advantage

The difficulty for individual merchants is that they rarely see the entire network.

Fraudsters can distribute activity across multiple businesses and industries, leaving each risk team with only a small piece of a much larger operation. Benjamin described this “partial visibility” as fundamental to how coordinated fraud rings operate.

She explained: “A merchant catching 40 fraudulent attempts feels like a bad week. It doesn’t feel like evidence of a 13,000-transaction ring, because from where they’re sitting, it isn’t.”

That creates a structural disadvantage for merchants operating with only their own first-party intelligence.

“No single team fixes this alone,” Benjamin said. “It takes shared signals across merchants, so a block on one platform actually informs risk scoring on another. Otherwise everyone’s stuck relearning the same lesson in isolation, one merchant at a time.”

The challenge is becoming more pronounced as digital commerce continues to expand. Transaction volumes across Sift’s Global Data Network increased 15.2% year-over-year, bringing new customers, markets and integrations into payment ecosystems.

Growth itself does not necessarily create fraud, Benjamin stressed, but it can generate uncertainty that organised networks are equipped to exploit.

“It’s more surface area and more decisions made with less context, and rings tend to find wherever that gap is widest.”

Fraud rings learn to hide in legitimate traffic

That sophistication is also changing how fraudulent accounts behave.

Traditional rules-based fraud systems often depend on identifying a sufficiently suspicious account or transaction. Yet advanced Account Takeover (ATO) networks are combining compromised legitimate accounts with accounts created specifically for fraud.

“Rules want a clean signal: this account is suspicious, block it. Mixed-risk fraud rings don’t give you that,” Benjamin stated.

“A manually blocked account and a manually accepted one turn up in the very same network, so any rule aggressive enough to catch the fraud also catches trusted customers.”

For risk teams, the implication is significant. Increasing the sensitivity of individual rules can generate false positives and introduce unnecessary friction for legitimate customers without exposing the wider fraud network.

Benjamin therefore believes businesses should change the question they ask. She added: “The better question isn’t ‘does this account look risky,’ it’s ‘what is this account connected to’. A ring can fake individual behaviour; it’s much harder to hide the connections between accounts.”

Sift identified one example involving more than 90 businesses and almost 13,000 attempted transactions, with attackers targeting loyalty programmes across multiple industries.

Some compromised accounts mirrored legitimate customer behaviour for months before points were drained, while others were created by fraudsters from the outset.

Benjamin noted: “The defence has to assume the threat is coming from wherever the credentials leaked, not from a competitor in your own vertical.”

Global fraud rates hide vertical pressure

Network-level analysis is also becoming important because headline fraud statistics can conceal differences between sectors.

Globally, payment fraud block rates fell 14% year-over-year, yet individual industries moved sharply in the opposite direction. Sift recorded a 383% increase in iGaming payment fraud, while Food & Delivery worsened by 19%.

Benjamin commented: “A 14% global improvement sounds like good news until you notice iGaming moved 383% in the other direction. Averages like that hide a lot.”

She highlighted withdrawal speed as one reason certain sectors can become particularly attractive targets.

She added: “Fraud doesn’t just chase weak onboarding, it chases fast payouts, and iGaming has some of the fastest real-money withdrawals of any vertical, even with the ID and location checks required to open an account.”

The same principle applies when assessing payment methods. Sift recorded a 9.46% fraud attack rate for cryptocurrency and 8.36% for Electronic Fund Transfers (EFT).

Rather than removing payment methods that attract higher fraud rates, however, Benjamin advocated a more targeted application of friction.

“The better approach is uneven friction on purpose,” she said. “More scrutiny on the payment method and dollar amount combinations that actually carry the risk, and staying out of the way everywhere else.

“Blanket friction just annoys your best customers without slowing down the people you’re actually worried about.”

The true cost of fraud goes beyond the chargeback

For payments leaders, perhaps the biggest shift required is recognising that fraud prevention is connected to customer lifetime value rather than simply loss prevention.

Sift found that 27% of consumers would permanently abandon a platform after experiencing payment fraud, while only 28% would continue using it without hesitation.

Benjamin argued that this fundamentally changes the economics of an incident.

She said: “The fraud loss itself is usually recovered within a quarter. The customers aren’t coming back on that timeline, if at all, and replacing them means paying full customer acquisition costs all over again.

“Run the math that way and a ‘small’ fraud incident gets a lot more expensive than the chargeback total suggests.”

Trust can still be recovered. According to Sift, 82% of consumers said fast resolution would improve their trust following fraud, while proactive communication has a 76% positive impact.

Benjamin concluded: “If fraud has 2,000 cases sitting in queue, a customer gets their resolution when the queue reaches them, not when the case is actually simple.

“Three to five business days isn’t a policy failure, it’s a capacity failure.”

Subscribe to our newsletter