Reinventing Fraud Detection Through Digital Fingerprinting and Link Analysis

Blog-Apr-15-2026-12-02-51-0755-PM

Fraud detection systems are designed to assess risk at the level of individual transactions or accounts. However, this approach is becoming less effective as fraud becomes more complex.

Fraud is often spread across multiple accounts, devices, and interactions rather than appearing as a single event, making it difficult for traditional detection models to capture this kind of activity.

A white paper from Microsoft, Reinventing Link Analysis: How Digital Fingerprinting and LLMs Are Transforming Enterprise Fraud Detection, authored by Akhil Singhal and Sadhana Viswanathan, explores how combining digital fingerprinting with link analysis can shift fraud detection from isolated events to network intelligence across systems.

From Isolated Detection to Network Intelligence

Traditional approaches work well for known patterns, but are less effective when fraud is distributed across multiple entities.

This has led to a shift towards network intelligence, where relationships between entities are analysed to uncover hidden connections. Rather than asking whether a single transaction is fraudulent, this approach focuses on how multiple interactions relate to one another across time and systems.

Identifying the User Behind Fraud Activity

A central component of this approach is digital fingerprinting, which creates a probabilistic representation of a user based on device, network, and behavioural signals.

These signals can include device characteristics, IP attributes, environmental configurations, and interaction patterns. By analysing how a user behaves, rather than relying solely on static identifiers, organisations can move closer to identifying the individual operating the system.

Identifying the “user at the keyboard” enables more accurate classification of risk, particularly in cases where fraudsters rotate accounts or reuse infrastructure to evade detection.

Connecting Fraud Through Link Analysis

Once suspicious activity is identified, link analysis is used to uncover relationships across historical and real-time data.

By connecting shared attributes such as device identifiers, login credentials, IP addresses, and behavioural patterns, systems can construct a network of related entities. This allows organisations to identify not only the initial fraud signal but also other accounts and transactions that may be connected.

This approach supports earlier detection by enabling organisations to reassess previously approved activity and prevent further abuse. It also shifts detection from identifying individual events to exposing broader fraud networks.

Looking to contribute to collaborative anti-scam initiatives? GASA Working Groups bring members together to develop practical, real-world solutions.

The Role of LLMs in Detection

The paper also outlines how LLMs can enhance link analysis by introducing a reasoning layer on top of traditional rule-based systems.

Instead of relying solely on predefined rules, LLMs can interpret patterns across complex datasets, identifying relationships that may not be captured through static logic. This allows detection systems to adapt more effectively to evolving fraud behaviours while reducing the need for continuous manual rule updates.

Importantly, this layer operates alongside existing controls, supporting decision-making while maintaining governance and oversight.

What This Changes for Fraud Prevention

Together, digital fingerprinting and link analysis enable a shift from reactive detection to preventive disruption of fraud activity.

By identifying connections across users, devices, and transactions, organisations can detect coordinated behaviour earlier and respond at scale.

This approach also delivers clear operational benefits:

  • Higher fraud coverage by detecting coordinated networks
  • Reduced false positives through probabilistic fingerprinting
  • Faster response through automated linkage and blocking
  • Greater scalability across large datasets
  • Improved explainability through connected fraud relationships

Network-level intelligence offers a more resilient model for detecting and disrupting organised fraud.

From Detection to Disruption

The approach outlined in the paper reflects a broader transition in fraud prevention, where detection is no longer limited to individual events but extends to understanding how activity is connected across systems.

This allows organisations to act earlier and more consistently, addressing fraud patterns before they scale.

The full white paper explores these concepts in greater detail, including the underlying architecture and practical considerations for implementation.

Sign up for the GASA newsletter to receive regular updates on scam prevention, research, and best practices.

Apr 21, 2026
4 minute read
Category
Research Topic - Fraud Prevention Region - Global Topic - Scam Detection Region - North America Industry - Big Tech / Social Media
Written by
Global Anti-Scam Alliance (GASA)
Global Anti-Scam Alliance (GASA)
Share article

Latest blogs & research

bancoppel joins gasa

BanCoppel joins the Global Anti-Scam Alliance to bolster fraud prevention and safeguard individuals entering the banking system.

BanCoppel has joined the Global Anti-Scam Alliance (GASA) as a Corporate Member of the GASA Mexico Chapter.

News Topic - Fraud Prevention Topic - Scam Awareness Industry - Financial Authorities
Consejos para no caer en fraudes

The emotions scammers exploit: how social engineering influences our decisions

How scammers use fear, urgency, excitement and trust to influence decisions, and how recognising these tactics can help people prevent fraud.

Topic - Scam Awareness Video Scam Trends Region - Latin America
mastercard joins gasa mexico chapter

Global Anti-Scam Alliance Welcomes Mastercard as Founding Member of Its Mexico Chapter

The Global Anti-Scam Alliance (GASA) announces the membership of Mastercard as a Member of its Mexico Chapter.

News Topic - Fraud Prevention Industry - Financial Authorities Region - Latin America
Building Scam Prevention Capability Through IVR Training

What Uganda’s IVR Trial Shows About Practice-Based Scam Prevention

A Uganda IVR trial shows how practice-based fraud prevention helped mobile money users reduce losses and increase reporting.

Best Practices Industry - Telecom Operators / Hosts Topic - Fraud Prevention Topic - Scam Awareness
How the FTC’s Never EVER Campaign Tackles Imposter Scams

FTC’s Never EVER Campaign Helps Prevent Elder Financial Abuse With Simple, Specific Scam Warnings

The FTC’s Never EVER campaign uses simple, specific imposter scam warnings to help prevent elder financial abuse and support coordinated consumer education.

Best Practices Topic - Fraud Prevention Topic - Scam Awareness Region - North America
gasa mexico chapter 2nd roundtable

GASA Mexico's Second Roundtable Advances Coordinated Action Against Digital Fraud

GASA Mexico's second roundtable brought together more than 35 representatives to strengthen coordination across cybersecurity, fraud prevention and other sectors.

News Topic - Data Sharing Topic - Fraud Policy Industry - Law Enforcement
Cognyte joins GASA

Cognyte Joins Global Anti-Scam Alliance to Fight Financial Fraud Threats

Cognyte, a global leader in investigative analytics software, today announced its membership in the Global Anti-Scam Alliance (GASA).

News Topic - Scam Detection Industry - Law Enforcement Industry - Big Tech / Social Media
Banking Collaboration Strengthens Fraud Prevention

A network is beaten by a network: Mexico's banks move from remediation to prevention

GASA convened the ABM Fraud Committee and Mexican banks to advance the enriched agreement and strengthen coordinated fraud prevention across the sector.

Best Practices Topic - Fraud Prevention Video Industry - Financial Authorities