Reinventing Fraud Detection Through Digital Fingerprinting and Link Analysis

Blog-Apr-15-2026-12-02-51-0755-PM

Fraud detection systems are designed to assess risk at the level of individual transactions or accounts. However, this approach is becoming less effective as fraud becomes more complex.

Fraud is often spread across multiple accounts, devices, and interactions rather than appearing as a single event, making it difficult for traditional detection models to capture this kind of activity.

A white paper from Microsoft, Reinventing Link Analysis: How Digital Fingerprinting and LLMs Are Transforming Enterprise Fraud Detection, authored by Akhil Singhal and Sadhana Viswanathan, explores how combining digital fingerprinting with link analysis can shift fraud detection from isolated events to network intelligence across systems.

From Isolated Detection to Network Intelligence

Traditional approaches work well for known patterns, but are less effective when fraud is distributed across multiple entities.

This has led to a shift towards network intelligence, where relationships between entities are analysed to uncover hidden connections. Rather than asking whether a single transaction is fraudulent, this approach focuses on how multiple interactions relate to one another across time and systems.

Identifying the User Behind Fraud Activity

A central component of this approach is digital fingerprinting, which creates a probabilistic representation of a user based on device, network, and behavioural signals.

These signals can include device characteristics, IP attributes, environmental configurations, and interaction patterns. By analysing how a user behaves, rather than relying solely on static identifiers, organisations can move closer to identifying the individual operating the system.

Identifying the “user at the keyboard” enables more accurate classification of risk, particularly in cases where fraudsters rotate accounts or reuse infrastructure to evade detection.

Connecting Fraud Through Link Analysis

Once suspicious activity is identified, link analysis is used to uncover relationships across historical and real-time data.

By connecting shared attributes such as device identifiers, login credentials, IP addresses, and behavioural patterns, systems can construct a network of related entities. This allows organisations to identify not only the initial fraud signal but also other accounts and transactions that may be connected.

This approach supports earlier detection by enabling organisations to reassess previously approved activity and prevent further abuse. It also shifts detection from identifying individual events to exposing broader fraud networks.

Looking to contribute to collaborative anti-scam initiatives? GASA Working Groups bring members together to develop practical, real-world solutions.

The Role of LLMs in Detection

The paper also outlines how LLMs can enhance link analysis by introducing a reasoning layer on top of traditional rule-based systems.

Instead of relying solely on predefined rules, LLMs can interpret patterns across complex datasets, identifying relationships that may not be captured through static logic. This allows detection systems to adapt more effectively to evolving fraud behaviours while reducing the need for continuous manual rule updates.

Importantly, this layer operates alongside existing controls, supporting decision-making while maintaining governance and oversight.

What This Changes for Fraud Prevention

Together, digital fingerprinting and link analysis enable a shift from reactive detection to preventive disruption of fraud activity.

By identifying connections across users, devices, and transactions, organisations can detect coordinated behaviour earlier and respond at scale.

This approach also delivers clear operational benefits:

  • Higher fraud coverage by detecting coordinated networks
  • Reduced false positives through probabilistic fingerprinting
  • Faster response through automated linkage and blocking
  • Greater scalability across large datasets
  • Improved explainability through connected fraud relationships

Network-level intelligence offers a more resilient model for detecting and disrupting organised fraud.

From Detection to Disruption

The approach outlined in the paper reflects a broader transition in fraud prevention, where detection is no longer limited to individual events but extends to understanding how activity is connected across systems.

This allows organisations to act earlier and more consistently, addressing fraud patterns before they scale.

The full white paper explores these concepts in greater detail, including the underlying architecture and practical considerations for implementation.

Sign up for the GASA newsletter to receive regular updates on scam prevention, research, and best practices.

Apr 21, 2026
4 minute read
Category
Research Topic - Fraud Prevention Region - Global Topic - Scam Detection Region - North America Industry - Big Tech / Social Media
Written by
Global Anti-Scam Alliance (GASA)
Global Anti-Scam Alliance (GASA)
Share article

Latest blogs & research

Turning Fraud Data Into Actionable Intelligence

From Information Sharing to Intelligence Production: GASA Mexico in Forbes

Sissi de la Peña, Director of the GASA Mexico Chapter, examines in Forbes México what the U.S. memorandum on cyber operations against fraud networks means for the country.

Best Practices Topic - Fraud Prevention Topic - Data Sharing Industry - Financial Authorities
GASA Africa Chapter & Google South Africa Trust & Safety Workshop

GASA and Google Trust & Safety Workshop Sets Priorities for Anti-Scam Cooperation Across Africa

GASA Africa Chapter and Google South Africa brought anti-fraud leaders together to strengthen cross-border cooperation and scam prevention.

News Topic - Fraud Prevention Topic - Data Sharing Topic - Scam Detection
Allstate Identity Protections joins GASA

Allstate Identity Protection Joins the Global Anti-Scam Alliance to Strengthen the Fight Against Scams and Identity Theft

Allstate Identity Protection has joined the Global Anti-Scam Alliance (GASA) as a Corporate Member within the North America Chapter.

News Topic - Fraud Prevention Topic - Scam Detection Industry - Financial Authorities

GASA and Whoscall Release 2026 Asia Scam Report – Taiwan

The 2026 Asia Scam Report – Taiwan, provides an in-depth look at scam exposure, channels, victim experiences, and scam awareness among people in Taiwan.

Research Industry - Telecom Operators / Hosts Scam Trends Region - Asia-Pacific
bancoppel joins gasa

BanCoppel joins the Global Anti-Scam Alliance to bolster fraud prevention and safeguard individuals entering the banking system.

BanCoppel has joined the Global Anti-Scam Alliance (GASA) as a Corporate Member of the GASA Mexico Chapter.

News Topic - Fraud Prevention Topic - Scam Awareness Industry - Financial Authorities
Consejos para no caer en fraudes

The emotions scammers exploit: how social engineering influences our decisions

How scammers use fear, urgency, excitement and trust to influence decisions, and how recognising these tactics can help people prevent fraud.

Topic - Scam Awareness Video Scam Trends Region - Latin America
mastercard joins gasa mexico chapter

Global Anti-Scam Alliance Welcomes Mastercard as Founding Member of Its Mexico Chapter

The Global Anti-Scam Alliance (GASA) announces the membership of Mastercard as a Member of its Mexico Chapter.

News Topic - Fraud Prevention Industry - Financial Authorities Region - Latin America
Building Scam Prevention Capability Through IVR Training

What Uganda’s IVR Trial Shows About Practice-Based Scam Prevention

A Uganda IVR trial shows how practice-based fraud prevention helped mobile money users reduce losses and increase reporting.

Best Practices Industry - Telecom Operators / Hosts Topic - Fraud Prevention Topic - Scam Awareness