Demo data
Threat Intelligence
Patterns fused from correlated transactions, ranked by severity and model confidence.
Coordinated Account Takeover
THR-001 · first seen 19 Aug 17:52 UTC
Credential-stuffing entry followed by device enrolment, low-value probing and rapid escalation to a crypto off-ramp payout on ACC-40219.
Confidence
96%
Accounts affected
5
Recommended: Freeze outbound payouts on the account and force step-up re-authentication.
Card Testing Ring
THR-002 · first seen 19 Aug 13:20 UTC
Micro-authorisations between $0.80 and $2.60 hitting a single PSP endpoint across 42 unrelated cards within 18 minutes.
Confidence
88%
Accounts affected
42
Recommended: Rate-limit the PSP merchant descriptor and enable 3DS challenge on sub-$5 auths.
Impossible Travel Cluster
THR-003 · first seen 19 Aug 15:10 UTC
Nine accounts show sessions in two continents inside a window that is not physically traversable, all via residential proxy exit nodes.
Confidence
91%
Accounts affected
9
Recommended: Invalidate active sessions and require device re-enrolment.
Transaction Velocity Attack
THR-004 · first seen 19 Aug 16:10 UTC
Bursts of 6–9 transactions per account per hour against baseline 1.2/hour, concentrated on gambling and luxury merchants.
Confidence
79%
Accounts affected
17
Recommended: Apply adaptive velocity ceilings for the affected merchant categories.
New Device Abuse
THR-005 · first seen 19 Aug 08:40 UTC
Unrecognised device fingerprints enrolled without step-up verification, followed by profile and payee changes.
Confidence
73%
Accounts affected
23
Recommended: Require step-up verification for any payee change within 24h of device enrolment.