# Fraud & Abuse

## Live Data

Our network blocked $67M in attempted fraud this period, identifying a 12% rise in sophisticated ATO patterns.

### Large New Fraud Ring Detected on Our Network

Instant-fulfillment verticals, particularly gift cards, crypto, and digital goods, absorb the highest fraud ring pressure, with weekday spikes emerging as a clear pattern.

Fraud ring traffic remains highly structured, with automated activity peaking during standard weekdays and tapering off over weekends as legitimate consumer traffic climbs. Instant-fulfillment sectors, led by gift cards, cryptocurrency transactions, and digital media, draw the heaviest concentration of organized ring activity. This targeting is driven entirely by the rapid settlement speed and inherent anonymity of digital delivery methods, allowing bad actors to monetize compromised credentials almost instantly before detection occurs.

### Flow of Attacks: Top 5 Source to Target

USA is the dominant source of fraudulent traffic, primarily targeting US payment methods.

Significant laundering patterns are visible from Mexico and Brazil; 65% of Brazilian IP attacks are successfully redirected toward non-domestic Payment Methods (PMs), suggesting high use of stolen international credentials.

| From IP Country        | Percentage  |
|-----------------------|-------------|
| United States         | 41.97%      |
| Brazil                | 8.75%       |
| Japan                 | 3.78%       |
| Mexico                | 3.09%       |
| Canada                | 2.62%       |

| To PM Country         | Percentage  |
|-----------------------|-------------|
| United States         | 47.95%      |
| Other                 | 36.63%      |
| Brazil                | 8.74%       |
| Japan                 | 3.66%       |
| Mexico                | 3.01%       |

### Fraud Distribution vs. Traffic Share by Connection Type

The Vast Majority of Blocked Fraud Is Concentrated in Non-Residential Connection Types.

Analysis of blocked sessions reveals that a disproportionate volume of mitigated threats originates from non-residential connections, such as Data Centers, VPNs, and Public Wi-Fi. This validated blocking strategy allows us to safely scale alongside AI-driven traffic growth, as the system effectively isolates synthetic activity from genuine human engagement.

| Traffic Share %       | Fraud Share %|
|-----------------------|---------------|
| residential           | 52.48%       |
| mobile                | 37.5%        |
| hosting               | 3.61%        |
| corporate             | 3.37%        |
| proxy_suspicious      | 3.04%        |

### Fraud Distribution vs. Traffic Share by Device Type

Desktop sessions carry a disproportionate share of detected fraud relative to their actual volume of web traffic.

The data indicates that desktop environments represent an elevated risk profile when compared directly against their overall traffic baseline. Conversely, mobile fraud risk remains notably low relative to its broad traffic dominance. This systemic variation is heavily driven by the presence of advanced device integrity checks, hardware-backed secure enclaves, and integrated biometric authentication features native to modern mobile platforms.

| Traffic Share %       | Fraud Share %|
|-----------------------|---------------|
| mobile                | 72.02%       |
| other                 | 17%          |
| desktop               | 10.98%       |

### Attack Method Distribution

Stolen Credit Card attempts remain the dominant threat vector, alongside a broader upward trend in secondary attack methods across the network.

The data shows a consistent, heavy volume of stolen credit card activity, pointing toward a persistent focus by bad actors on direct monetization of compromised payment credentials. Concurrently, other vectors such as account takeovers and policy abuse have also shown signs of expanding over time, highlighting a diversifying threat landscape where multiple attack types are gaining ground.

- Account Take Over
- Stolen Credit Cards
- Friendly Fraud
- Policy Abuse
- Other

### Fraud pressure per vertical

The Digital Goods and Financial Services sectors absorb the largest share of overall fraud pressure across the network.

While transactional volumes shift across sectors, instant-fulfillment and digital services consistently represent the most significant areas of concentration for bad actors. Concurrently, other retail categories (apparel, accessories) show ongoing engagement, highlighting a varied distribution where high-velocity digital assets remain the primary targets.

- Digital Goods / Internet
- Others
- Electronic Goods
- Travel
- Apparel, Accessories & Beauty
- Retail Distribution (Incl. Home & Garden)
- Food & Beverage
