Skip to content
Blog Europe MENA Americas APAC

When Device Facts meet Behavioural Analytics

04 August 2026

Scams, Authorised Push Payment (APP) fraud, and social engineering have become some of the largest sources of consumer fraud losses globally. Unlike traditional Account Takeover (ATO) attacks, these frauds often involve legitimate customers using their own trusted devices, credentials and authentication methods, from trusted locations. As a result, many institutions are shifting their focus from transaction monitoring towards collecting risk intelligence earlier in the customer journey.

Using Deterministic and Probabilistic Pre-Transaction Intelligence

The trend to collect early risk intelligence is further stimulated by fraud attacks that combine social engineering with device compromise. A common example is a bank impersonation scam where a customer is persuaded to install a Remote Access Tool (RAT). The fraudster then prepares or executes payment activity remotely while obtaining authentication codes through phone calls, chat messages or fake banking pages. These attacks blur the traditional boundaries between scams, account takeover (ATO) and device takeover (DTO).

Pre-Transaction Intelligence

Modern fraud prevention relies increasingly on signals collected during mobile and web banking sessions, before a payment is initiated. These signals provide insight into the security of the device, the behaviour of the user and the likelihood of fraud or manipulation. They broadly fall into two categories: deterministic and probabilistic signals.

Deterministic Signals

Deterministic signals are factual observations that indicate the presence of a specific technical condition.

Examples include:

  • Remote Access Tool (RAT) detection
  • Mobile malware detection
  • Active call intelligence signals
  • VPN, TOR or location anomalies
  • Device integrity issues
  • High-risk IP intelligence

These indicators are generally binary in nature: a RAT is either present or absent, a device is either on a call or it is not. Because of this certainty, deterministic signals are particularly effective at identifying technical compromise and device-driven fraud.

Probabilistic Signals

Probabilistic signals assess likelihood rather than certainty. Instead of identifying a technical artefact, they evaluate whether a customer's behaviour is consistent with their historical patterns or resembles known fraud activity.

Examples include:

  • Identity mismatch scores
  • Behavioural deviations from known user behaviour
  • Manipulation and coaching indicators
  • Signs of duress or pressure
  • Similarity to known scam journeys
  • Fraudster-model matches

These signals are well suited to detecting scams and social engineering attacks because such frauds often target the human rather than the device. A customer may be using a trusted device but still be acting under influence or manipulation. And these low-tech attacks are notoriously difficult to detect, requiring high-tech innovation.

Turning Signals into Detection Intelligence

The most effective fraud detection strategies combine both signal types.

Device intelligence provides high-confidence evidence of technical risk. Behavioural analytics provides additional context around customer intent and possible manipulation. A detection engine can therefore combine a deterministic signal, such as the presence of a RAT, with probabilistic indicators such as a significant identity mismatch or a high similarity score to a known scam modus operandi.

In practice, deterministic signals often act as strong standalone indicators, while probabilistic signals contribute weighted risk scores. For example:

  • RAT detected: High-confidence technical risk
  • Device on a phone call during payment setup: Elevated risk
  • Identity model shows 60% mismatch: Behavioural concern
  • Scam model shows 90% similarity to a known scam pattern: Strong manipulation indicator

Correlating these signals provides a more complete view of risk than any individual signal in isolation.

Conclusion

As fraud increasingly shifts towards scams, social engineering and hybrid attack models, transaction monitoring alone is no longer sufficient. Effective fraud prevention requires visibility into the customer journey before a payment is authorised.

Deterministic signals provide factual evidence of device compromise or technical risk. Probabilistic signals provide insight into behavioural anomalies, manipulation and potential social engineering. Together, they create actionable pre-transaction intelligence that helps detect scams, account takeover and device takeover earlier in the attack chain.

The result is a more accurate understanding of risk, improved fraud detection performance and a stronger ability to intervene before customer losses occur.

 

 

Questions or demo?

CONTACT US