POST /loginVerifyRight password, unfamiliar device
- Device never seen on this account
- VPN exit, 900 km from usual city
- No automation detected
Industry
Fintech fraud is abuse of digital financial services: fake and synthetic accounts opened to borrow or launder, logins taken over to drain balances, mule accounts that move stolen money, and farmed referral rewards. Kavra assesses every onboarding, login and money movement from device, network and behavior evidence, alongside your KYC and AML checks.
POST /loginVerifyRight password, unfamiliar device
Digital financial services removed the branch visit, and fraudsters moved in through the same door as customers. An account can be opened from a phone in minutes, funded the same day and used to receive or send money right away. That speed is the product. It is also what makes a fake account, a stolen login or a rented mule account worth so much.
The attacks are organized. Rings open accounts in batches on emulators and device farms, with identities that are stolen, borrowed or built from mixed real and fake data. Others buy leaked passwords and run credential stuffing against the login, or talk a customer into sharing a code. Money then moves through accounts held by recruited or fake money mules until it is hard to trace.
The same actors move between verticals. What they take depends on what your product gives a new or trusted account.
| Threat | Where it strikes | Business impact |
|---|---|---|
| Fake account creation and synthetic identities | Onboarding, application forms | Credit losses, KYC spend, accounts used for laundering |
| Account takeover | Login, password reset, device enrollment | Drained balances, reimbursement claims, lost customer trust |
| Mule accounts | Onboarding, first incoming and outgoing transfers | Liability for received fraud, AML exposure, regulator attention |
| Referral and signup reward abuse | Onboarding, referral links, first transaction | Acquisition budget paid to multi-accounting rings |
| Loan stacking and application fraud | Credit applications, buy now pay later checkout | Defaults on loans that were never meant to be repaid |
| Payment fraud and card testing | Card top-up, card add, merchant checkout | Chargebacks, scheme fees, partner risk flags |
| SMS pumping | Phone verification and OTP endpoints | Messaging bills for codes nobody reads |
Each step adds trust to an account. Check the actor at each step, so trust is earned, not assumed.
Assess the device and network before you pay for document and database checks. Link the applicant to existing accounts and known bad devices.
Protect OTP endpoints from bots that pump messages or verify numbers in bulk.
Compare with the account's trusted devices, usual networks and locations. A correct password on a new device behind a proxy is not the same as a correct password at home.
The moment a takeover becomes permanent. Adding a new device, phone number or email after a risky login deserves a step-up.
New payees, first large transfers and crypto withdrawals are where value leaves. Re-assess the session here, not only at login.
A quiet account that suddenly receives many incoming payments and forwards them fast is a classic mule pattern.
Most of these need evidence from more than one session or account.
Applications from emulators or virtual machines that claim to be ordinary handsets.
Different names and documents submitted from the same hardware or household, often with rotating fingerprints.
Funds that arrive and leave within hours, to payees that are also new, from accounts that share devices or networks.
A login from a new device on a proxy, followed by a new phone number, new payee or higher limit.
Accounts that refer each other in chains, sign up within minutes of each other and never use the product after the reward.
A home-country IP from a residential proxy while the device timezone and language point elsewhere.
Financial firms must know their customers and monitor transactions under anti-money-laundering rules. Those checks are required, and Kavra does not replace them. But a document check answers whether an identity is real. It cannot tell you that the same person opened four other accounts this week, that the phone is an emulator, or that the applicant is a recruited mule using their own genuine ID.
Liability is also shifting. In the UK, mandatory reimbursement rules for authorized push payment scams split the cost between the sending and the receiving firm, which makes the account that received the money part of the problem. Keeping mule accounts out, and spotting them early, now protects the balance sheet as well as the customer.
At the same time, every extra onboarding step costs completed signups. The answer is not more steps for everyone. It is invisible evidence for everyone, and extra verification only for the applicants and sessions that earn it.
The aim is to make fraud expensive at every step while keeping the flow as fast as customers expect from a digital bank or wallet.
How Kavra helps
Kavra analyzes 3,000+ data points on every visit and every app session, then returns an explained recommendation. Your backend and your compliance rules decide.
Applicants on emulators, device farms or spoofed devices are flagged before you spend on document and credit checks.
Returning devices are recognized across applications, so one actor behind many accounts shows up as a linked cluster.
New device, new network, impossible travel and known bad devices are checked against each customer's trusted devices.
Kavra measures real exit IPs of commercial residential and mobile proxy networks, on top of 30+ public reputation feeds.
Each assessment is bound to the action with a signed, single-use, short-lived token. Replays are refused and reported.
Kavra adds evidence your checks cannot see and never blocks on its own. Mark devices good or bad and revoke them through the API.
FAQ
Something else? Talk to our team.
Fake and synthetic accounts at onboarding, account takeover at login, and mule accounts that receive and forward stolen money are the core risks. Referral abuse, loan stacking, card testing and SMS pumping add cost around them. Most share the same tools: emulators, device farms, proxies and stolen or borrowed identities, which is why device evidence helps across all of them.
They combine transaction monitoring with signals from the account itself. Mule accounts often share devices or networks with other new accounts, are opened from emulators or spoofed phones, and move money in and out within hours. Kavra supplies the device and linking evidence at onboarding and at each transfer, while your AML monitoring reviews the money flow.
It can, by running first. A device and network assessment is invisible and cheap compared with document and database checks. Applications from emulators, device farms or known bad devices can be stopped or sent to manual review before you pay for full KYC, while clean applicants move through the normal flow.
Tie friction to evidence and to intent. A login from a trusted device at home needs nothing extra. A correct password from a new device behind a proxy gets a step-up, especially before it adds a payee or changes a phone number. Kavra compares each login with the account's own history to make that call.
Yes, wherever a reward is paid per new account. Rings open accounts on emulators or with borrowed identities, refer each other and cash out the reward. Linking the new accounts to the device and network behind them, and paying the reward only after a real first use, removes most of the profit.
Yes. The same threats apply: fake signups to claim rewards or launder funds, takeover of accounts with balances, and withdrawals to wallets that many accounts share. Kavra assesses signup, login and withdrawal on the web and in native iOS and Android apps, alongside your KYC and on-chain monitoring.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.