‹ Blog
Estimated read time
In this article
Section heading
September 21, 2026

Location signals in fraud prevention: Why precise location reveals the connections IP misses

Nick Patrick
Co-Founder and CEO

Fraud teams have more signals than ever to help determine whether a user or transaction can be trusted. Identity, device, network, and IP signals can each provide useful context.

Location is often part of that picture through IP geolocation. It's easy to understand why: IP geolocation requires no permissions and can return information about a connection's country, state, city, network type, ISP, and whether it's associated with a VPN or proxy.

But IP geolocation and precise location tell you different things.

IP geolocation estimates where a network connection originates. Precise location asks the device for its current location and can determine position down to a few meters.

For fraud teams, that difference is about more than accuracy. Precise location can reveal connections between accounts and devices that look unrelated through other signals, helping uncover coordinated activity happening in the same physical place.

Key takeaway: IP provides useful network and location context. Precise location adds a view into where activity is actually happening, making it possible to identify physical connections across accounts and devices that IP and device signals alone can miss.

What IP geolocation actually tells you

Every device connected to the internet has an IP address. IP geolocation takes that IP address or range and looks it up in a database.

That lookup can return:

  • Country, state, and city
  • Estimated latitude and longitude
  • Accuracy and confidence level
  • ISP
  • Network type
  • Whether the IP is associated with a VPN or proxy

Unlike precise device location, this doesn't require the user to grant location permissions and can work client-side or server-side.

IP databases are built using inputs such as WHOIS records, BGP announcements, network latency measurements, and observed relationships between IP addresses and device latitude and longitude.

That makes IP useful for understanding both approximate location and characteristics of the network behind a session.

The important distinction is what the location represents. An IP lookup is an estimate based on the network connection. It isn't the same thing as asking the device where it is.

Where IP geolocation is limited 

The accuracy of an IP lookup depends heavily on the type of network.

A residential IP is often accurate at the city level. A corporate IP may resolve to an office or corporate VPN egress. A cellular IP may only be accurate at the state level, with many devices sharing the same IP. A data center or hosting IP points to the location of the server rather than the user.

That creates an important limitation for fraud teams.

If an IP resolves to New York, for example, that doesn't necessarily mean the device itself is in New York. The lookup is telling you where the network connection appears to originate.

IP-based location can also be manipulated. Fraudsters can hide their real IP with a VPN or proxy, changing what the network tells you about their location.

Again, that doesn't make IP a bad fraud signal. VPNs, proxies, residential proxies, and IP geolocation can themselves provide useful network risk signals.

But if the question is, " " ;is this user where they are supposed to be?" IP alone has limits.

Precise location answers a different question

Precise location works differently.

Instead of looking up an IP address in a database, precise or GPS location asks the device for its current location. It can establish location down to a few meters, compared with IP geolocation, which is city-level at best.

That precision creates several additional fraud signals.

Radar Protect can evaluate whether the reported location appears spoofed or inconsistent with the IP location. Device and browser signals can identify conditions such as rooting, jailbreaking, emulators, app tampering, or incognito browsing. Network signals can identify VPNs, proxies, and residential proxies.

These signals provide different pieces of context. But precise location also enables something that becomes difficult when location is only available at the city or state level:

You can start connecting activity happening in the same location and the same time.

Precision turns location into a connection

Imagine several accounts that appear unrelated.

They have different identities that each passed traditional identity verification at onboarding. Their device IDs don't match. Their IP addresses are different.

Looking at those signals individually, there may be no obvious reason to connect the accounts.

But precise location can show that the activity is happening at the same street address within seconds of each other. 

That's not a hypothetical capability. One of the patterns Radar can identify is activity where device IDs and IPs appear unrelated, but precise location reveals coordinated activity at a single street address.

This is where the difference between approximate and precise location becomes particularly important.

Knowing that several accounts are somewhere in the same city doesn't tell you much. Knowing that they are operating from the same precise location can provide a very different signal when combined with the rest of the fraud stack.

Instead of evaluating each user, account, or device only in isolation, location provides another way to identify relationships between them, flag coordinated activity, and block risky activity before it results in fraud.

Coordinated fraud is designed to go undetected

Fraud rings depend on finding an effective attack vector and scaling it to cause as much damage as possible before they’re detected.

With promo or bonus abuse, someone can create many "new" accounts to claim the same incentive repeatedly.

With multi-accounting, someone can operate many accounts that look unrelated to multiply payouts, manipulate activity, or avoid limits.

With device farms, emulators, and bots, fraudsters can scale activity across hundreds or thousands of accounts, logins, claims, purchases, or jobs. These patterns create a challenge for systems evaluating each account separately.

Precise location gives fraud teams another signal that seemingly unrelated activity may actually be coordinated.

Radar can detect multiple accounts operating from the same location even when their IP addresses and device fingerprints differ. 

The digital signals can look different while the physical location stays connected.

Location can connect behavior over time, too

The same principle applies when the account stays the same but its behavior changes.

Consider an account that suddenly jumps from New York to California within five minutes. Even if the IP and device information appears consistent, precise location can flag impossible travel as a signal of possible account takeover.

That creates another way to evaluate risk: compare a user or device's current location behavior with its historical behavior.

Changes in location behavior can help detect account takeover, account sharing, and mule account handovers.

In each case, location isn't just being used to answer whether someone is where they say they are. It's providing context about how accounts and devices relate to one another and how those relationships change.

Location, device, and network signals work together

None of this means fraud teams should stop using IP.

IP and network signals can identify VPNs, proxies, residential proxies, and other network risk. Device signals can identify rooted or jailbroken devices, emulators, and tampering. Precise location adds another layer, including whether a location appears spoofed or inconsistent with the IP.

Radar Protect brings these signals together to provide a more complete picture of risk. Fraud teams can use precise location alongside device and network intelligence to identify suspicious activity, uncover connections across accounts and devices, and make more confident decisions about when to approve, block, or step up activity.

The goal isn't to choose between IP and precise location. It's to combine signals that answer different questions, with precise location adding the physical context that IP and device signals alone can miss.

Add precise location to the fraud stack you already have

Most teams we talk to already have a fraud tech stack in place. Precise location fits directly into it, adding geo-location context to the signals and decisions teams already rely on.

Adding to the existing fraud stack as another signal, alongside identity, device, IP, network, and transaction data. Radar's fraud rules can use those signals directly, or location insights can feed into an existing risk decisioning engine to strengthen models, rules, and investigations.
IP still plays an important role. It's permissionless, widely available, and useful for understanding approximate location and network risk.

Precise location provides a different level of context.

It can show that accounts with different IPs and device IDs are operating from the same street address. It can connect reset devices to activity that came before them. It can identify changes in real-world behavior that may signal account takeover, account sharing, or mule handoffs.

For fraud teams, that's the bigger advantage of going beyond IP: not just knowing location more precisely, but seeing the risk that wasn't visible before.