‹ Blog
Estimated read time
In this article
Section heading
September 17, 2026

How does location intelligence detect coordinated fraud in financial services?

Kyler Day
Senior Fraud Operations Manager

Coordinated fraud rings and second party fraud drive billions in annual fraud losses and expose financial institutions to increasing AML and KYC scrutiny. Contributing to that loss is the fact many of these transactions look completely normal on the surface: a clean IP address, a recognized browser, no red flags in traditional fraud signals.

That’s the blind spot in risk stacks I see over and over again. How many transactions seem legitimate because the IP looks normal, even when they’re part of coordinated fraud ring activity? More importantly, what signals can help us uncover those connections before any money moves?

Location intelligence closes that gap. A transfer or payment looks unremarkable under standard fraud checks; normal IP, clean browser, nothing to flag. But when that same session runs through Radar Reveal, a residential proxy shows up, signaling potential location spoofing. That triggers an elevation to Radar Protect for precise location verification, and the truth is in plain sight: unrelated accounts, devices, and IP addresses turn out to be transacting from the same physical location.

The transaction hasn’t changed, but the intelligence behind it has.

This is a pattern I see constantly in fraud operations, and it’s exactly what I’ll be breaking down live on September 24, in a webinar on how precise location uncovers the fraud traditional signals miss. I’ll go deeper into two of the fraud vectors this pattern shows up in most: account takeover and coordinated fraud rings, including how to incorporate location into your existing stack without adding friction.  

Register here

Why do IP, device, and document checks miss coordinated fraud?

Most fraud teams already rely on documents, device, IP, and transaction signals. These traditional fraud signals are essential, but they’re increasingly easier to manipulate:

  • Stolen credentials: make an attacker look like a legitimate, returning customer
  • AI-generated and synthetic identities: pass onboarding and KYC checks designed to catch human error, not fabricated identities
  • Residential proxies: make attacker traffic look like it’s coming from an ordinary household network
  • Reset or emulated devices: appear risk-free by erasing the device history fraud tools rely on

As a result, multiple transactions can look legitimate when evaluated independently while actually being part of the same fraud ring. When these signals are manipulated, fraud rings can move money through multiple accounts before triggering a SAR filing or chargeback dispute, leaving the institution exposed on both the loss and the compliance side.

Teams that implement precise location add better context to their fraud detection: Where exactly is this activity actually happening, and what else is happening there?

Knowing that 30 accounts are in the same city isn’t particularly useful. Knowing that 30 accounts with different identities, devices, and IP addresses are operating from the same precise location can mean something much different. Signals that look clean individually can still belong to the same fraud ring.

How does location intelligence work as a fraud risk signal?

Radar Reveal, Radar’s device and network risk detection, evaluates device and network risk upfront, flagging signals like VPNs, proxies, and residential proxies, as well as emulators, rooted Android devices, and jailbroken iOS devices, without requiring location permission. If something looks suspicious, users can step up to Radar Protect for precise location verification.

A Reveal call may flag that an otherwise normal-looking session is using a mobile or residential proxy. That signal alone doesn’t establish fraud, but it can indicate elevated risk and provide a reason to step up to precise location before approving a withdrawal.

Precise location can uncover inconsistencies between the presented IP and real-world location. For example, the IP may place the customer in the U.S. while verified device location places them in Russia.

That distinction matters. It’s not enough to ask where a device says it is; you need to know whether you can trust the location it reports.

How does location intelligence expose fraud networks?

Beyond flagging individual risk, location intelligence can identify clusters of fraud hotspots. Fraudsters can change identities, rotate IPs, reset devices, and create new accounts but they still have to operate somewhere.

When many seemingly unrelated accounts and devices repeatedly operate from the same precise location, that physical concentration provides another signal that the activity may be coordinated.

A shared address alone doesn’t establish fraud. The value comes from combining precise location with device, network, account, and behavioral context to identify suspicious concentrations of activity.

That can help surface fraud rings, multi-accounting, device farms, and other coordinated activity that can be difficult to identify when accounts are evaluated individually.

Does location intelligence replace existing fraud tools?

Precise location isn’t a replacement for identity or payment signals. It makes those signals more useful by adding physical-world context.

Radar’s fraud prevention combines precise location intelligence with device, network, proprietary signals, and network-level insights to understand where users really are and uncover connections across accounts and devices.

Location intelligence can be applied at the moments that matter most: withdrawals, transfers, payout changes, password resets, account creation, or other high-risk actions. And, adding location intelligence doesn’t just reduce fraud losses; it strengthens the audit trail institutions need to support AML compliance and SAR filings.

One withdrawal can look normal. Nearly 50 seemingly unrelated accounts operating from the same suspicious hotspot tell you something different.

Better fraud prevention starts with seeing those connections before money moves. 

Join the session