Skip to content
Ledgerline
Menu

6Course 6Fraud & risk analyticsIntermediate

Fraud Analytics

Find fraud in transaction data: the patterns, the queries, the rules, and the investigation write-up that holds up.

Chapters
11
Time
10 hours
Format
Self-paced
Tools
SQL and spreadsheets; Python optional. A synthetic transactions dataset with labelled fraud is included

What you will be able to do

  • Describe the main fraud types in Indian digital payments and lending and what each looks like in data.
  • Compute velocity, concentration, and shared-attribute signals: per device, IP, card token, account, and phone.
  • Find mule networks and account farms through shared attributes and money-flow patterns.
  • Write, test, and tune rules with precision and recall, and know the cost of a false positive.
  • Investigate a case and write it up so a bank, a partner, or a regulator can follow the evidence.

Chapters

11 chapters. Chapter 1 is free below.

  1. 1

    How fraud shows up in dataFree to read

    Stolen credentials, account takeover, first-party misuse, mule accounts, merchant fraud, collusion. Data fingerprints of each.

  2. 2

    The dataset

    Transactions, accounts, devices, and labels. How labelled fraud data is made, and its blind spots.

  3. 3

    Velocity

    Counts and amounts per entity per time window. Windows that work, and the query patterns.

  4. 4

    Concentration and sharing

    Many accounts on one device, one phone on many accounts, repeated amounts, round-tripping.

  5. 5

    Graphs without a graph database

    Finding rings through shared attributes with joins and a little recursion.

  6. 6

    Chargebacks, disputes, and losses

    Turning dispute data into a fraud loss metric and a feedback signal.

  7. 7

    Rules

    Writing rules from patterns, back-testing them, precision versus recall, and the cost of friction.

  8. 8

    Manual review queues

    What to send to a human, in what order, with what context.

  9. 9

    Monitoring and drift

    Fraud adapts. Weekly checks that show when a rule stops working.

  10. 10

    The investigation write-up

    Timeline, evidence, entities, amount, recommendation. A template that has survived audits.

  11. 11

    Capstone: a fraud review pack

    From raw data to detected rings, tuned rules, and a written case file.

Free chapter 1 of 11

How fraud shows up in data

Fraud is a story about incentives, but it leaves a trail in tables. A stolen card is used fast, on new devices, for goods that can be resold, before the real owner notices. An account takeover changes the phone number or email and then drains value within hours. A mule network moves money through many accounts that share a device, an IP range, a phone, or a pattern of amounts. First-party misuse looks like a normal customer until the dispute arrives.

Each of these is a different question to ask the data. Speed is a velocity question: how many transactions per account per hour, compared to that account's own history. Sharing is a concentration question: how many accounts touch one device. Draining is a sequence question: what happened in the two hours after a profile change. Disputes are a feedback question: which past transactions, which we thought were fine, turned out not to be.

The trap is to start with a tool or a model. Start with the fraud type you are losing money to, write down what it would look like in your tables, and then write the query. Most fraud teams that struggle have plenty of data and no written description of what they are looking for.

This course uses a synthetic dataset built to contain each of these patterns at realistic rates, with labels so you can check your work. Real fraud data is rarely labelled well, and chapter 2 covers why, and what that means for anyone building rules or models on it.

Buy this course — ₹4,000The other 10 chapters, exercises, and the dataset come with the course.

Who it is for

Risk, fraud, and operations analysts at fintechs, payment companies, marketplaces, lenders, and any business that loses money to fraud and wants to see it in the data first.

Before you start

SQL for Analysts or equivalent. Working knowledge of how payments or lending operate helps but is not required.

Taught by

Paul Montero

Founder and instructor

About the instructor

Questions about this course

How long do I have access?
For as long as we run the course, and at least 12 months from purchase. Updates to the course during that time are included.
Is the dataset included?
Yes. SQL and spreadsheets; Python optional. A synthetic transactions dataset with labelled fraud is included. Everything needed for the exercises is provided with the course.
Can I get a refund?
Within 7 days of purchase, in full, no reason needed. See the Refund & Cancellation Policy.
₹4,000

incl. GST, 7-day refund

Buy — ₹4,000