Fraud & AML Monitoring · Use case

Prevent account takeover at login

Short answer

Account takeover starts with a login that looks legitimate. Monitoring providers combine device, behavioural and network signals to score each login and sensitive action, so you can allow, challenge or block without adding friction for genuine customers.

What this use case is

Account takeover starts with a login that looks legitimate. Monitoring providers combine device, behavioural and network signals to score each login and sensitive action, so you can allow, challenge or block without adding friction for genuine customers.

Who builds this

Neobanks and wallets
Brokerages
Crypto platforms
Any app holding customer funds

What your customer sees

  1. 1Logs in normally
  2. 2Occasionally gets an extra check on a new device
  3. 3Gets alerted if someone else tries

How Fraud & AML Monitoring solves it

1

Login or sensitive action captured with device and behaviour data

Login or sensitive action captured with device and behaviour data

2

Risk scored in real time

Risk scored in real time

3

Low risk allowed

Low risk allowed

4

Medium risk challenged with step-up authentication

Medium risk challenged with step-up authentication

5

High risk blocked and alerted

High risk blocked and alerted

6

Outcomes fed back to improve models

Outcomes fed back to improve models

Want to have

  1. Device fingerprinting
  2. Behavioural signals
  3. Real-time scoring API
  4. Configurable responses
  5. Step-up integration
  6. Alerting
  7. Feedback loop

Optional

  1. Consortium device intelligence
  2. Session monitoring after login
  3. Bot detection

Design decisions

Response

Challenge
Block
Allow and monitor

loss prevention versus friction.

Coverage

Login only
All sensitive actions

simplicity versus protection against session hijacking.

What to put in your RFP

Signals

  • device
  • behaviour
  • network

Decisions

  • latency
  • responses
  • step-up

Operations

  • alerts
  • investigation

Data

  • privacy
  • retention

Commercials

  • per event pricing
Add these to an RFP

How to evaluate providers for this use case

  1. 1Detection on your historical incidents
  2. 2Friction for genuine users
  3. 3Latency
  4. 4Privacy approach

Pitfalls

  • Protecting login but not payee changes
  • Over-challenging loyal customers
  • Behavioural data collected without the right notices

What providers will ask you

  1. Monthly active users and logins
  2. Known attack patterns
  3. Authentication setup

Other Finlane categories that cover parts of this

This use case is solved mainly with Fraud & AML Monitoring. These categories cover specific parts of it and can be tendered alongside it.

Frequently asked questions

Other Fraud & AML Monitoring use cases

Scope prevent account takeover at login with Fraud & AML Monitoring providers

Scope this use case