Skip to content

Alert Banner Text Goes Here Alert Banner Text Goes Here Alert Banner Text Goes Here Alert Banner Text Goes Here

Start Now

Commercial Payments Fraud Glossary

 

Account takeover. Behavioral analytics. Session replay. Business email compromise.
If you’ve been researching business and banking fraud trends, evaluating fraud prevention solutions, or exploring commercial payments fraud in general, you’ve likely encountered these terms and many others. This glossary provides straightforward definitions for common commercial payments fraud terms, helping you navigate concepts, technologies, and strategies shaping today’s fraud prevention efforts. Familiarizing yourself with these concepts can also help you and your bank stay steps ahead of today’s sophisticated schemes and bad actors.

Behavioral & Risk Analytics

Adaptive Analytics:

Analytics models that continuously adjust based on new information, user behaviors, and emerging risk patterns.

AI-Driven Fraud Detection:

The use of artificial intelligence, machine learning, and advanced analytics to identify fraud indicators, anomalies, and patterns that may be difficult to detect through traditional fraud monitoring tools alone, helping organizations detect threats at greater speed and scale.

Anomaly Detection:

The process of identifying activity that deviates from expected behavior and may indicate fraud or elevated risk.

Behavioral Analytics:

The analysis of user behavior patterns, such as login activity, navigation habits, and payment actions, to identify behavior that may indicate fraud.

Intelligence Augmentation:

The practice of enriching fraud detection and investigation efforts with additional data sources, behavioral data, and external risk signals to support decision-making.

Predictive Analytics:

Analytical techniques that use historical and current data to identify patterns and assess the likelihood of future fraud events.

Risk Indicators:

Specific characteristics, behaviors, or events that may suggest increased fraud risk.


Fraud Fundamentals

Account Takeover (ATO):

When a fraudster gains unauthorized access to a legitimate user account and uses it to initiate or manipulate payments.

Behavioral Analytics:

The analysis of user behavior patterns, such as login activity, navigation habits, and payment activity, to identify suspicious behavior that may indicate fraud.

Business Email Compromise (BEC):

A fraud scheme in which criminals impersonate a trusted individual or organization through email to convince a victim to send funds or sensitive information, so that they may infiltrate systems and/or carry out various schemes.

False Positive:

A legitimate payment or activity incorrectly identified as suspicious.

Fraud Detection:

The process of identifying activity, behavior, or transactions that may be fraudulent before financial loss occurs.

Fraud Monitoring:

The continuous analysis of customer activity, payment behavior, and transaction data to identify potential fraud risks.

Mule Account:

A bank account used to receive, transfer, or hide funds obtained through fraudulent activity. The account holder may knowingly or unknowingly assist the fraudster.

Risk Score:

A calculated value that indicates the likelihood that a payment or activity is fraudulent.

Social Engineering:

The use of deception or manipulation to persuade individuals to reveal information, grant access, or authorize fraudulent payments. Many BEC attacks rely on social engineering tactics.

Suspicious Activity:

User behavior, account activity, or payment actions that warrant additional review due to elevated fraud risk.

Synthetic Identity Fraud:

A fraud scheme in which criminals combine legitimate and fabricated information to create a false identity which they then use to open accounts or conduct financial crimes.

Transaction Monitoring:

The review of payment transactions for anomalies, risk indicators, or suspicious behavior.


Fraud Operations & Optimization

Analytics Tuning:

The process of adjusting fraud detection models, rules, and thresholds to improve accuracy, reduce false positives, and align detection strategies with evolving risks.

Fraud Orchestration:

The coordination of multiple fraud detection tools, intelligence sources, and workflows to support more consistent and efficient fraud decisions.

Payment Lifecycle:

The end-to-end flow of a payment from initiation through approval, processing, settlement, and, when necessary, investigation.


Investigation & Response

Alert Fatigue:

A condition that occurs when fraud teams receive large volumes of alerts, making it more difficult to quickly identify and act on genuine threats.

Case Management:

The process of organizing, investigating, documenting, and resolving fraud alerts and incidents.

Interdiction:

The act of stopping, delaying, reviewing, or escalating potentially fraudulent activity before funds are released or transactions are completed.

Investigation Center:

A centralized workspace where fraud analysts review alerts, investigate suspicious activity, determine next steps, and manage fraud cases.

Real-Time Detection:

The ability to identify suspicious activity as it occurs, enabling earlier intervention and faster response.

Step-Up Authentication:

An additional layer of identity verification, such as a one-time passcode, biometric verification or security challenge, triggered when suspicious activity or elevated risk is detected.


Session & User Activity Monitoring

Session Activity:

The actions a user performs within a system or application, such as logins, navigation patterns, entitlement changes, payment-related activity, and other interactions.

Session Replay:

The ability to track, recreate, and “see” a user's digital activity in a particular solution or app to better understand the events leading up to a potentially fraudulent action.

Upstream Activity:

User actions and behaviors that occur before a payment is initiated, such as logins, device activity, navigation patterns, entitlement changes, or profile updates.


Learn more about Payments Fraud