Skip to content
Blog Europe MENA Americas APAC

Multi-Model Behavioural Analytics: Understanding the User and the Fraudster

28 July 2026

Traditional fraud detection focuses on the transaction itself: who is sending money, where it is going, how much is being transferred, and whether similar transactions have been seen before. While these signals remain important, they often struggle with modern scams and Authorised Push Payment (APP) fraud because the transaction is frequently initiated by the genuine customer.

Looking Beyond Transactions

To address this challenge, ThreatFabric's Behaviour Risk capability uses a multi-model behavioural analytics approach that examines the journey leading up to the transaction. Rather than focusing solely on what happened, it analyses how the user interacted with the banking application and whether that behaviour aligns with expected patterns. This approach combines two independent models operating in parallel.

Understanding Normal Behaviour

The first model is built specifically for each individual user. The model learns the customer's unique behavioural patterns across web and mobile banking interactions. These patterns are derived from a rich set of behavioural sensors, including navigation behaviour, keystroke dynamics, touch interactions, mouse movements, motion sensors and device dynamics.

The objective is straightforward: determine whether the current session looks like the user's normal behaviour.

The model continuously compares current interactions against the customer's established behavioural baseline. It can identify situations where behaviour deviates significantly from normal patterns, potentially indicating account takeover, device takeover, remote access tool activity, or a user being manipulated by a scammer. Because the model is personalised to each individual and continuously retrained as behaviour evolves, it provides a highly adaptive and context-aware view of risk.

Understanding Known Scam Behaviour

While the First Model focuses on "known good" behaviour, the Second Model focuses on "known bad" behaviour.

The Second Model is trained using confirmed fraud, scam, social engineering and APP fraud cases. It learns the behavioural patterns commonly observed during fraudulent sessions and uses those learnings to assess new sessions in real time. Examples include excessive copy-and-paste activity, unusual navigation patterns, bot-like interaction speeds, hesitation during critical actions, irregular data entry behaviour, and interaction patterns commonly associated with scam coaching or remote control.

Rather than asking whether a user is behaving normally, the Fraudster Model asks a different question:

"Does this session resemble behaviour observed in confirmed fraud cases?"

This capability is particularly valuable for detecting scams and APP fraud where the genuine customer is still present, but their behaviour is being influenced, guided or manipulated by a fraudster.

Why Two Models Are Better Than One

Traditional “Behavioural Biometrics” has historically focused on user profiling alone. However, looking only for deviations from a user's baseline can generate false positives because human behaviour naturally changes, deviates, and drifts.

ThreatFabric's patented approach improves precision by combining two independent perspectives. The Identity Model identifies unusual behaviour relative to the user, while the Fraudster Model identifies behaviour associated with known fraud patterns. When both models indicate elevated risk, confidence increases significantly that a session represents genuine fraud rather than normal human variation.

The result is a more robust signal that can be combined with transaction data, device intelligence and fraud engine rules to support more accurate fraud decisions.

Delivering Consistent Value Detection Rate Improvements

The real value of behavioural analytics is measured by its impact on fraud outcomes. Across customer deployments, the combination of Identity and Fraudster models consistently delivers significant improvements in fraud detection when integrated with transactional context. Customer performance data shows behavioural scores driving fraud detection rates improving by 20% or more, when fused with transaction-based signals, while maintaining alert volumes at manageable levels. We’ll explain the metrics in VDR improvements in a separate blog.

The greatest improvements were observed in social engineering, impersonation scams, investment scams, romance scams and other APP fraud (scam) typologies where traditional transaction monitoring often struggles to identify customer manipulation.

Privacy by Design, Not Privacy by Compromise

Behavioural analytics should not require organisations to collect sensitive personal information. ThreatFabric's behavioural models are designed around privacy-by-design principles. The platform minimizes collection of personally identifiable information (PII) and does not rely on physical biometrics such as facial recognition, fingerprints or voice analysis. Behaviour is analysed using anonymised behavioural characteristics and pseudonymised correlation identifiers.

For example, keystroke analysis does not capture what a user types. Instead, it evaluates behavioural patterns such as timing, rhythm and interactions across keyboard regions. User input itself is never recorded. Similarly, raw behavioural signals are transformed into engineered features that describe behavioural characteristics rather than personal content.

This enables financial institutions to benefit from powerful fraud detection while maintaining compliance with privacy requirements and protecting customer data. The result is a behavioural analytics capability that is both highly effective and privacy preserving.

 

Screenshot 2026-07-27 at 14.07.53

The Future of Fraud & Scam Detection

As scams increasingly target human behaviour rather than technical vulnerabilities, fraud detection must evolve beyond transaction monitoring alone. By combining an understanding of how a genuine customer normally behaves with an understanding of how fraudsters behave during confirmed scams, multi-model behavioural analytics provides a more complete picture of risk.

The combination of per-user Identity Models and fraud-trained Fraudster Models enables banks to detect manipulation, coaching, account takeover and APP fraud earlier in the customer journey, improving Value Detection Rates by more than 20% while maintaining strong privacy protections and a low-friction customer experience.



 

Questions or demo?

CONTACT US