A fraudster can generate a convincing profile, buy a working phone number, script a browser and route traffic through a different country. Each fragment appears to be a plausible component of a legitimate account on its own.
However, making every fragment contribute to a coherent identity is the harder part.
Real contact details need history. A device needs a credible configuration. The route, address and payment methods must fit the claim. The individual completing the customer journey needs to behave digitally as a real person would.
This is where multidimensional risk signals matter. They let a risk team test an identity from multiple angles and ask whether the narrative holds together.
What is a dimension?
A dimension is one independent source of evidence about a person, their environment or their action. Email is a dimension. So is the device, physical address, online presence and fraud history.
No single dimension proves that something is fraudulent. The value of signal breadth, depth and time lies in the ability to examine a range of evidence to determine whether the identity and intent story remains consistent.
Access to an unrivaled breadth and depth of signals enables a matrix view that puts identity under pressure.
A fraud decision is stronger when the evidence goes beyond one single point on a map.
What is signal depth?
Signal depth is the level of context and specificity available within one dimension. It tells an analyst more about what a particular observation means, such as understanding information associated with an email, including how many data breaches it has been associated with, the email’s age and string analysis relay a lot more than whether an email address is deliverable or not.

What is signal breadth?
Signal breadth is the range of evidential dimensions that span the customer journey, allowing risk analysts to compare contextual data and assess whether the information available about a user is logical or reasonable. It looks at dimensions such as email, phone, online presence, addresses, payments, network and location data, behavior, device characteristics and device integrity — and whether this cross-pollination of signals can credibly belong to the same presented identity.

Where time comes into the picture
Depth and breadth enable the evaluation of any one moment in time. An identity that survives each check at the point of registration can change hands one hour later, thanks to KYC mules and other bad-actor tactics. A session that starts with a genuine customer can end with someone else finishing the form.
Time evaluates the path between moments: what happened before the critical action, what changed during it and what followed. Several dimensions carry time evidence at different scales — behavioral biometrics within a single interaction, session monitoring across a journey, velocity analysis across events and entities and fraud consortium history over a longer horizon.
How the Dimensions Work Together
The strongest and most defensible investigations unite evidence that captures different parts of a person, an environment and a transaction.
The five pillars of human trust
| Question | What the evidence answers | The dimensions behind it |
| Can I reach this person? | Whether the account details the customer provides make sense and whether the email address and phone number are working, credible and established. | Customer identity & account context Email information Phone information |
| Has this identity existed beyond this moment? | Whether there is history behind the claim, or whether it was assembled for this transaction. | Online presence Fraud history |
| Have we seen this environment before, and can it be trusted? | Whether the device can be trusted, and whether it links accounts that are supposed to be unrelated | Device identity Device characteristics Device integrity Network & location |
| Is a human actually doing this, and are they in control? | Whether the journey is human, automated, coached or remotely controlled. | Automation, bots & virtualized environments Remote access detection Behavioral biometrics Session monitoring |
| Does the action fit the identity and the wider pattern? | Whether the address, payment, location and activity pattern support the identity pattern the customer is presenting. | Address intelligence Payment information Velocity analysis |
Context decides the meaning. A suspicious signal kickstarts a hypothesis, not a verdict.
An unusual device setting may be normal for a developer, a shared physical address may be expected for a household and a remote session may be legitimate during technical support. A suspicious signal raises a question; the answer to whether something is fraud depends on if the rest of the account’s story supports a legitimate explanation.
In one investigation, a device country mismatch was the only red flag in a batch of accounts, and it turned out to be the least stable part of the pattern.
This is also where commercial value sits. A platform that treats every anomaly as a decline blocks the developer, the family and the customer on the call with a support team, as well as fraud. Depth and breadth of signals provide a richer picture, letting teams clear good users, instead of routing them to manual review or turning them away.
Two ways to use these dimensions
Start with the signal that generates the question. Choose another independent dimension to test the first signal for suspicious behavior. Then use the depth of signals to determine whether the account fits a legitimate pattern or whether contradictions point to a connected group.
First, test the identity
Use when a single customer raises suspicions. Your investigation should be able to determine that the customer is who they claim to be.
01
Start with the thread
A suspicious signal, country mismatch, unfamiliar device, account-control change, unexpected automation indicator or repeated address is not the answer; it’s the first question.
02
Build the case
Ask what else should be true if the account is fabricated, compromised, automated or coordinated. Use one or two independent dimensions to test that theory.
03
Try to disprove it
Look for an explanation that would make the pattern legitimate: a shared household, a developer profile, expected travel, a returning device, support interaction or a coherent account history. Use the depth within each dimension to determine whether that explanation holds true or proves itself false.
04
Explain the connection
If independent evidence contradicts the account story, investigate the shared device, repeated network, physical address, payment context or contact anchor. The goal is to find a rational reason why the accounts belong in a connected pattern.
The strongest investigation builds the most defensible explanation.
Then find the infrastructure
Use this investigation methodology when no single customer is disqualifying, but a group of customers feels wrong. The results of your investigation should be able to answer if these accounts are linked as an operation or if they are indeed solo, unrelated accounts.
01
Establish the population
Assemble a cohort around whatever weak thread is available, such as a registration window, a promotion, product or a single soft flag and accept that no member of the cohort may be individually declinable.
02
Look for values that should vary and don’t
Real people and hardware produce natural variation. Form completion times differ and font libraries accumulate unevenly. Hardware-derived fingerprints yield near-unique values, so when a value is identical across a population, it is usually a property of who or what entity provisioned the accounts rather than a deliberate choice by a user. A fixed screen brightness, an identical font count or a small set of repeated fingerprint hashes is each unremarkable when appearing in one account, but that same detail across two hundred accounts is structural.
In device intelligence, this variation is measured as entropy: how much identifying information an attribute carries across a population. High-entropy attributes like audio or rendering hashes differ enough between real devices to tell them apart. Low-entropy attributes like a default screen resolution are shared too widely to mean much alone. Real populations produce high entropy because real hardware is assembled, configured and used unevenly. A cohort that collapses describes a provisioning method, not a set of real customers.
03
Confirm the sameness spans dimensions that should be unrelated
High entropy in a single attribute can be chance but if it appears the same way across attributes that are independent on real hardware, that likely is not. This is the step that separates a finding from coincidence. Audio processing, installed fonts, and graphic rendering are unrelated on genuine hardware. If they split the population along the same lines, they are not describing numerous devices. Agreement across unrelated layers is a signature of shared infrastructure and is the one thing a spoofing tool cannot coordinate.
04
Rule out commonness
Before trusting a static value, check whether it is common. Look for the same value across a large, unrelated population. If it appears everywhere, it is a default and worth nothing. If it appears only in scattered, low-reputation cases elsewhere and saturates your cohort, it is a fingerprint of the provisioning method. Skipping this step is how teams build rules against ordinary settings.
05
Build detection on the uniformity
Fraudsters rotate identifiers, values and templates, but what they rarely change is the fact that their accounts resemble each other more than real accounts do. Detection written against uniformity itself re-links the next generation of clones automatically, regardless of which values they report.
Seen in the field
A rewards farming ring ran 197 accounts with zero shared device identifiers. Behavior opened the door to uncover five related hardware layers that agreed.
16 dimensions you need to detect AI-generated fraud
Each dimension below affords deep context. No single signal or connection determines fraud, but as signals accumulate and are aggregated, new connections can be identified, enabling an analyst to conduct a more thorough and informed investigation.
Can I reach this person, and is it still them?
1. Customer Identity & Account Context
Every investigation needs a reference point. Customer identity and account context is the claimed story: who the customer says they are, how long the account has existed, the actions they take and the commercial settings that surround their choices. Name, account age, verification level, account balance, product, transaction type and value can all change what a suspicious signal means. A new account created with a promotional code is different from a long-standing customer attempting a high-value withdrawal after completing an account-recovery flow.
AI-assisted fraud often gets this surface layer right. A fabricated identity can present a name, birthday, address and polished application as easily as a real customer. The useful question is whether the surrounding evidence supports that claim. First-party account, transaction, payment, location and session information create the factual frame that enrichment and behavioral evidence must either corroborate or challenge.
It establishes that the account profile itself is internally coherent. Name and username string analysis can surface recycled patterns such as account age, product use and prior account state, which help explain why a customer may look new, high-value or unusual.
Blind spot if it is missing:
Without account context, a team can identify unusual signals but cannot explain what exactly they contradict. The same device, for example, can mean something very different in an ordinary signup, a high-value withdrawal or a recovery flow. Fraud review becomes detached from the actual risk of the action.
Cross-check next:
Test the claim against email, phone, online presence, device identity and the session around the action to corroborate the person’s legitimacy. A new customer may have little history. The rest of the evidence should explain why that is true rather than simply treating the absence of history as suspicious.
2. Email Information
A deliverable email address is not the same thing as a credible identity anchor. It only tells you that a mailbox may be able to receive a message. The more useful question is what lies behind the address: how long it has been visible online, whether its construction looks natural or algorithmic, whether the domain has real infrastructure, whether the address has appeared in breach data and whether it connects to a wider digital history.
Email intelligence can provide much more than a pass/fail outcome. Each of the following supports a different question: validity and inbox information, approximate minimum age, earliest observed profile date, string-randomness context, domain and provider details, breach data, profile aggregates, associated-domain registrations, fraud history and a network-risk score. For example, an earlier breach or profile date can help establish the minimum observed age of an email; it does not prove the exact date the email address was created.
Blind spot if it is missing:
A shallow email check can approve a fabricated identity simply because the inbox accepts email. The analyst loses the ability to distinguish between a usable address and a strong contact anchor with a history that fits the customer’s story.
Cross-check next:
Read email evidence alongside online presence, phone and device identity. A new or sparsely used address can be entirely legitimate. It becomes more meaningful when the contact history, device, journey and claimed customer profile all point in the same direction.
3. Phone Information
Phone intelligence is often treated as a binary gate: the number is valid, so the customer must be reachable. In account takeover and scam scenarios, the central question is often whether the number is stable and under the expected person’s control at the time of a sensitive action.
Carrier, country, line type, disposable status, live network information, caller name detail where available, SIM-swap events, porting history, linked online presence, fraud history and a network risk score provide the context that a simple validity check cannot. A recent SIM swap or carrier port does not prove an account takeover. It can be completely legitimate. But if it appears immediately before account recovery, password reset, payment or a change in withdrawal details, it gives an analyst a concrete reason to slow down and test the rest of the story.
Blind spot if it is missing:
Confirming you can reach a number is not the same as knowing who controls it. Without visibility into whether control shifted shortly before the action under review, account takeover and recovery fraud hide behind an ordinary phone validation result.
Cross-check next:
Compare phone context with device identity, remote access detection and session monitoring. A legitimate carrier change should be easier to reconcile with the customer’s normal environment and behavior than a coordinated change in contact, device and session context.
Has this identity existed before this moment?
4. Online Presence
People leave uneven digital traces. Some have active social profiles, professional accounts, travel registrations, technology services and years of online activity. Others keep a very limited footprint. The job of assessing online presence is to determine whether the contact details in an account are consistent with a history that makes sense for the claimed identity.
Profile enrichment can organize results into categories, rather than forcing a fraud team to build rules for each individual platform. That gives the analyst a broader read on the shape of an identity: whether an email or phone is connected to personal or business accounts, whether there is any visible history and whether the available history fits the person who is applying, logging in or paying. It is particularly helpful when assessing synthetic identities, fake account creation and contact details assembled solely for one transaction.
Presence is a proof of personhood signal. A phone and email with a decade of platform history describes a person is an indicator that a person existed before this transaction. An email whose only observable trace is a registration two weeks ago describes something assembled to carry a myth.
Blind spot if it is missing:
A contact detail may look credible locally while leaving little evidence that it belongs to a valid identity beyond the immediate transaction.
Cross-check next:
Read online presence against email and phone first, then against device identity and customer identity and account context. Low online presence is not always fraud, but it becomes meaningful only when other dimensions also fail to support the claimed history.
Beyond fraud signals:
Digital footprint signals carry value outside of fraud. Lending and buy now, pay later (BNPL) organizations use online presence and device-tier data as indicators of discretionary income in affordability assessments when their customers don’t have available credit history. For example, a person who has accounts at multiple entertainment streaming sites like Disney+, Netflix and Spotify, as well as online gambling platforms, shows they have income to spare.
5. Fraud History
These signals provide privacy-safe cross-customer observations showing how a person or entity has appeared, behaved or been associated with risk across a broader network in other organizations. They provide the analyst with historical and cross-customer context that the individual business could not observe on its own. This signal can indicate whether the email, phone number and other signals associated with the account have appeared in fraudulent transaction events at other organizations and been marked as fraud.
Blind spot if it is missing:
A customer can appear completely new because the business has not encountered them before, even when the same email or phone number has appeared in prior risk contexts beyond the company’s own data.
Cross-check next:
Use fraud history evidence with email, phone, device identity, payment Information and velocity intelligence. Historical information is context for investigation, not an automatic decline. The question is whether the current action independently supports the concern.
Have we seen this environment before, and can it be trusted?
Device fingerprinting and device intelligence answer different questions. Fingerprinting helps recognize an environment through identifiers and hashes. Intelligence uses a wider set of characteristics, integrity checks and suspicious indicators to explain what that environment may mean. One identifies the device, and the other helps assess it.
6. Device Identity
Device identity consists of a set of individual identifiers, such as a cookie hash or browser hash, along with a persistent device identifier that can recognize devices, even after routine changes. It checks if the device, browser or component pattern returns over time; whether accounts that claim to be unrelated share a common environment; and whether a known customer is using a familiar or unfamiliar context. Multi-accounting, coordinated synthetic identities, bonus abuse, account takeover and fraud rings become easier to see when the same device environment reappears behind supposedly unrelated people.
Blind spot if it is missing:
Identifier logic catches fraud operators who reuse a device environment, but it goes blind against fraudsters who manufacture a fresh identifier per account.
Coordinated groups regenerate device identifiers per account specifically so that device-linking rules see unrelated strangers, and cloud device farms reset hardware attributes on click. This is why device identity should not be evaluated in isolation, and the characteristics underneath a device can show clues to another durable connection between accounts.
Cross-check next:
Test device identity against device characteristics first, then email information, phone information, address intelligence, payment information and velocity analysis. A device can be legitimately shared by a household, workplace or family. The right question is not whether it is reused, but whether reuse is expected for these accounts.
7. Device Characteristics
Device characteristics capture observable hardware, operating system, browser, display, rendering, capability, configuration, sensor and runtime attributes. They describe what the environment is and what it is capable of doing, whether a device setup is ordinary for the customer and channel, unusually configured, missing expected capabilities or showing an environment that warrants further inspection.
These are also the signals that the detection of fraud infrastructure depends on. Device characteristics are properties that built the session. When a population reports an identical font, the characteristics are describing infrastructure rather than users.
Blind spot if it is missing:
Lack of depth in this signal set may limit a risk team able to recognize a device without being able to assess it. It may miss a configuration built to hide automation, emulate a device, suppress normal signals or make a cloud-hosted environment look like a consumer device — and it loses the only layer where population-level uniformity becomes visible.
Cross-check next:
Read device characteristics against device integrity, automation, bots and virtualized environments, network, location and behavioral biometrics. Atypical configurations can reflect accessibility tools, developers, privacy choices, older or spoofed hardware and all of this context helps decide the meaning.
8. Device Integrity
Device integrity assesses whether the device, operating system, application, browser or fingerprinting environment has been compromised, modified, concealed or engineered to deceive. It asks whether the technical evidence should be taken at face value by assessing the rooted or jailbroken state, iOS or Android platform integrity and checking for fingerprint spoofing, client tampering and privacy and anti-detection tooling.
These signals can provide insight into whether the environment can be trusted, modified, concealed or spoofed. Still, integrity evidence is context, not a diagnosis. Some devices are rooted or modified for legitimate reasons; enterprise-managed environments can look different from consumer devices.
Blind spot if it is missing:
Trusting a clean-looking device profile without knowing that the environment was built to hide the very signals used to assess it can openly invite fraud rings onto your platform.
Cross-check next:
Read device integrity against device characteristics, automation, bots and virtualized environments, network and location. Privacy tools or anti-detection tooling provide context and are not, by themselves, a reason to deem a user fraudulent.
9. Network & Location
Network and location signals help answer a deceptively simple question: where is this action really coming from, and does that route make sense for this customer? An IP address can reveal country, city, timezone, ISP, connection type, open ports, Tor, harmful-IP context, VPN and proxy indicators and whether the route appears residential, datacenter-based or relayed through a privacy service.
This evidence is useful when investigating account takeover, carding, phishing, geo-restricted abuse, location spoofing and proxy-mediated identity fabrication. It can show a mismatch between the network route, device location, timezone, billing or shipping address and card country. It can also capture changes in network context during a sensitive session, which is one reason network data becomes much more useful when combined with session monitoring.
Blind spot if it is missing:
Fraudsters can obscure the origin of activity, rotate routes or make a location claim look plausible. Without network context, a mismatch can go unnoticed until after an account is opened or funds move.
Cross-check next:
Compare network context with address intelligence, payment information, device characteristics and session monitoring. A VPN is not a verdict, and neither is a proxy; these could be signs of an enterprise private network, or a customer traveling abroad, which is why consistency across the rest of the story is the true test.
Is a human actually doing this, and are they in control?
10. Automation, Bots & Virtualized Environments
This is the dimension that turns the abstract concern about AI-generated fraud into something observable. An AI agent can produce a polished application, fill forms accurately, write natural language and move through a workflow faster than any human. These signals should answer if the environment and interaction reveal whether the journey is being created by code, emulation, scalable infrastructure or an actual real person.
Emulator and virtualization detection is effective against emulators and virtual machines, but it could fall apart when detecting real hardware operated remotely to capture a rack of genuine Android devices with valid IP configurations, real IP data, working phone numbers and authentic sensor motion, driven through browser-based remote control. That traffic presents as organic because, at the device level, it is. Detection moves from the session to the population to see what an entire cohort of clean-looking devices shares that none of them would reveal alone.
Blind spot if it is missing:
Automated enrollment, promotion abuse, account workflows and scaled testing can look like a high volume of clean new customers. The values submitted may all be valid, but you have a gap if you cannot see the mechanism producing them or the scale at which the same workflow can be repeated. And where the mechanism is real hardware rather than code, this dimension alone will not surface it.
Cross-check next:
Pair automation evidence with behavioral biometrics, session monitoring, device integrity, network and location. Behavior, environment and business context have to support the explanation and where automation evidence comes back looking clean on a cohort that still looks wrong, assessing the infrastructure is another way to rule out suspicion.
11. Remote Access Detection (RAT)
Some of the hardest fraud to identify is not fully synthetic at all. It involves a real customer who has been manipulated, coached or remotely controlled by someone else. They may pass authentication, their phone may be valid and the account may be well established. Yet the critical action is being directed by a scammer.
Remote access detection is designed to surface that hidden control layer. It can draw on behavioral evidence, network evidence, screen-sharing indicators, remote-control context, and, in native environments, process monitoring or active remote-access tooling.
It can surface account takeover, vishing, assisted fraud or coercive payment flows that appear to be a legitimate customer acting alone.
Blind spot if it is missing:
While these signals could identify a valid customer and a valid session, they could miss the control layer behind the action. A highly authenticated transaction can still be a scam if the customer is being guided by a criminal in real time.
Cross-check next:
Read remote access detection against phone, behavioral biometrics and session monitoring to understand whether the customer’s interaction is being interrupted, coached or controlled. Remote tools and screen sharing can be legitimate support activities, so the confidence level of the detection and the sensitivity of the action both matter.
12. Behavioral Biometrics
Behavioral biometrics describes the observable interaction patterns when a claimed identity interacts with your platform, analyzing keystrokes and text behavior, pointer movement, touch and swipe behavior, form completion, navigation and other interaction patterns. The question is whether the interaction looks human, copies, scripted, guided, unusually repetitive or inconsistent with the claimed context. It adds meaning to a form that otherwise appears perfectly completed.
Real interaction varies. A person pauses before a screen they haven’t read, mistypes and corrects and scrolls past a paragraph they don’t care about faster than one they do. None of that is deliberate; it is what a human attention span produces, and it is never the same twice. Rapid, low-correction form completion may indicate automation. Repeated paste may suggest copied credentials or scripted input. An unusual pause pattern may point toward coercion or remote assistance.
This dimension also carries time at its shortest scale. It is where the absence of the variation first becomes visible and where a cohort moving through identical steps at an identical pace stops reading as numerous customers.
This behavior could be connected to bot and automation attacks, device farms, vishing, account takeover, synthetic identity enrollment, payment fraud and unauthorized access.
Blind spot if it is missing:
Copied credentials, pre-filled stolen data, scripted form completion and assisted navigation can pass static checks because the fields themselves are valid. Without behavioral biometrics analysis, you cannot see the difference between a plausible answer and a way of producing it.
Cross-check next:
Test behavioral biometrics against automation, bots, virtualized environments, remote access detection and session monitoring. Interaction styles vary across people, devices, input methods, and accessibility needs. Behavioral evidence is also the layer that fraudsters adjust first, since a scripted pause is cheap, which is why it opens an investigation more often than it closes one.
13. Session Monitoring
Most enrichment tells you what was present at the moment an event occurred. Session monitoring tells you how the event came to happen. It follows the journey across registration, login, account recovery, checkout, money movement or other sensitive actions, preserving the sequence that a single post-event score can erase.
That sequence can include analyzing the screens a user visited, active and idle time, off-screen time, field interaction duration, entry type, corrections, paste and autofill events, risk flags, linked transactions and changes in IP, proxy, locale, browser, or device context.
This creates a fuller record of automated signup, account takeover, credential stuffing, coached fraud, vishing, identity theft, synthetic account creation and payment fraud. A session that looks routine at submission may reveal a long off-screen pause before a bank-detail change, copied values across identity fields, a location change or an IP shift before checkout.
Blind spot if it is missing:
A point-in-time snapshot cannot show what happened before the action was completed. Automation, copied inputs, long waits for instructions, off-screen activity during sensitive entry and remote access or a network shift immediately before payment can disappear once the transaction is reduced to a single event.
Cross-check next:
Read session monitoring against behavioral biometrics, remote access detection, network, location, automation, bots, virtualized environments and device identity. Atypical timing can reflect complex tasks, poor connectivity, legitimate support or accessibility needs. The sequence and independent context determine its meaning.
Does the action fit the identity or the wider pattern?
14. Address Intelligence
An address begins as a string of text, but the real analytical value lies in the location behind it. Address intelligence turns messy, easily-spoofed address strings into verified, normalized, fraud-relevant risk signals. Every formatting variant of the same address maps to a set of canonical IDs enabling Apt 1, Unit 1 and #1 at the same building to all collapse into a set of shared identifiers, regardless of abbreviations, casing or punctuation, which is useful for detecting fraud rings who are cycling unit numbers across dozens of accounts.
Analyzing addresses can also indicate whether the physical location is residential, commercial, vacant, a legitimate shared property, a freight-forwarding arrangement, or a recurring operational location. It distinguishes an address that validates from one that is relevant to the claimed customer, and it answers which real-world place an address represents and what that place connects to.
Address signals should answer where in the real world this address represents and what physical location it connects to.
Blind spot if it is missing:
Fraud rings can reuse the same location across identities built to appear unrelated, changing punctuation or unit labels to avoid exact-match rules. Further, without address signals, risk teams lose the physical-world connection and cannot tell whether an address is a household, a drop point or an infrastructure node.
Cross-check next:
Test address intelligence against payment information, network and location and device identity. A shared address may be a legitimate household, dorm, office or business and other dimensions can determine whether the relationship is expected.
15. Payment Information
Payment information describes the identity, provenance, validity, linkage and geographic consistency of a payment card. A successful payment is not automatically a credible payment. The form of payment has to make sense in the wider account story. This risk signal can also provide BIN and issuer context, card type, country, card-hash reuse and the relationship between the payment instrument, the claimed identity and the location of the activity. It should tell fraud and risk teams if the funding method fits the customer, location and transaction context.
Blind spot if it is missing:
Stolen, mismatched or repeatedly reused payment cards can look ordinary because the fraud team cannot see whether the funding method has a history, origin or reuse pattern that contradicts the customer claim.
Cross-check next:
Pair payment information with address intelligence, network and location signals, then use device identity and velocity checks to investigate reuse. A customer may legitimately use a family card, corporate card or cross-border instrument; the analyst needs the broader context before making a decision.
16. Velocity Analysis
Fraud attacks rarely announce themselves in one event. Fraud can emerge in repetition: the same device behind several identities, many accounts appearing from one physical location, rapid payment attempts, a burst of registrations or activity that departs sharply from a customer’s own pattern. Velocity intelligence derives real-time signals from activity, distinct entities and relationships across events and time windows.
Blind spot if it is missing:
A fraud attack remains invisible because every event is judged as a standalone customer interaction. Fraudsters can distribute activity across identities and time windows precisely to keep any one event below an obvious threshold.
Cross-check next:
Investigate velocity intelligence alongside device identity, payment information, address intelligence, customer identity and account context and fraud consortium history. High activity can be legitimate for launches, shared devices, large customers or particular business models; the linked entities explain the pattern.
Where each dimension carries weight in the journey
Not every dimension carries the same weight at every point in the customer journey. At account opening, there is no baseline, so contact anchors and accumulated history carry the weight. At the point of login, there is an established baseline, so the question becomes whether the environment and the person still match. During transactions, the question is whether the money movement fits everything already established.
| Dimension | Account opening | Login and account access | Transaction and payment |
| Customer Identity & Account Context | Primary | Primary | Primary |
| Email Information | Primary | Supporting | Supporting |
| Phone Information | Primary | Primary | Supporting |
| Online Presence | Primary | Limited | Limited |
| Fraud History | Primary | Supporting | Supporting |
| Device Identity | Primary | Primary | Supporting |
| Device Characteristics | Primary | Primary | Primary |
| Device Integrity | Primary | Primary | Primary |
| Network & Location | Supporting | Primary | Primary |
| Automation, Bots & Virtualized Environments | Primary | Supporting | Supporting |
| Remote Access Detection | Supporting | Primary | Primary |
| Behavioral Biometrics | Primary | Primary | Supporting |
| Session Monitoring | Primary | Primary | Primary |
| Address Intelligence | Primary | Limited | Primary |
| Payment Information | Limited | Limited | Primary |
| Velocity Analysis | Primary | Supporting | Primary |
How to pressure test a fabricated identity
| Observation | A legitimate explanation to test | The independent reading that resolves the question |
| A deliverable email and active phone number | A genuine new customer may have limited online history. | Compare online presence with the customer-stated age, other account context and device identity to detect unexpected reuse. |
| A new account from an allowed country | The customer may be traveling, privacy-conscious, or using a legitimate corporate network. | Compare network and location against address intelligence, device characteristics and payment information. |
| A clean, first-seen device | The customer may have upgraded or replaced a device. | Compare device integrity and device characteristics against prior detection with account activity and live session information. |
| A repeated fulfillment location | The location may represent a household, dorm, office or legitimate shared destination. | Compare address intelligence against payment information, network and location and device identity to determine whether the shared destination is expected or whether unrelated identities, payment methods and devices are converging on a single drop point. |
| A cohort with no individually disqualifying signal | The accounts may be unrelated customers arriving through the same marketing campaign channel. | Compare device characteristics across the population for values that should vary, confirm any sameness that spans across unrelated layers and then verify the value is not simply common elsewhere. |
If the evidence supports the legitimate explanation, lower the suspicion. If it does not, the connection becomes meaningful.
Auditing your own signal coverage
Every dimension above names what a team loses without it. The practical question is which ones you are currently missing.
Here are six questions to run against your existing stack:
- Which dimensions do you have at depth, and which do you have at a surface level? Count the decisions each one lets you make.
- Which dimensions are absent entirely? Address session and behavioral evidence are the most common gaps.
- Which dimensions can you compare in a single view? Breadth that you can’t cross-reference in one pass is likely not something that will be used under time pressure.
- Can you query a population easily, or only an account? If your tooling answers tell me about this user, but you can’t filter by connected fraud infrastructure, regardless of how many signals you have, or the signals can’t be used in risk decisioning, how helpful are they really?
- Where does your device linking depend on a single identifier?
- What proportion of your manual review queue consists of anomalies you already know are legitimate?
If more than two of these are hard to answer, the gap could be signal dimension coverage rather than tuning.
The full story about a person’s identity needs deep evidence and broad context
AI has lowered the cost of creating plausible fragments of an identity. Each one can be bought, generated or spoofed. What cannot be manufactured cheaply is an agreeable story among dimensions, such as an email’s history and a phone’s continuity, device characteristics and claimed hardware.
Depth makes each fragment answer a harder question. Breadth makes the fragments answer one another. Time makes them hold that answer across the journey.
An operator has to win all three at once, on every account and at scale; that is where the sameness starts to show.
Your AI Command Center for Fraud and AML
SEON brings deep, first-party risk intelligence across these dimensions into one command center, so teams can turn context into faster, more defensible decisions to detect AI-generated fraud.


