‹ Blog
Estimated read time
In this article
Section heading
September 22, 2026

Three ways to use precise location to detect and prevent fraud

Nick Patrick
Co-Founder and CEO

Most fraud teams already have a robust stack: identity verification at onboarding, device fingerprinting at login, transaction monitoring when money moves, and an orchestration layer for risk decisions. 

Location is usually part of that stack too, but in most cases, “location” means IP geolocation. That tells you where a network connection appears to come from. It might get you to the right city, it can be made inaccurate by cellular networks, while bad actors utilize proxies to change their true location in seconds. 

When we talk to fraud leaders about precise location, one of the first questions we hear is: how would I actually use it in practice?

The answer goes beyond another signal, connecting devices, accounts, and users to reveal patterns that IP alone can miss.

Key takeaway: Precise location helps fraud teams answer three distinct questions: Is this user where they’re supposed to be? Is this activity connected to other activity happening in the same place? And does this location match how the account normally behaves? These signals can help detect fraud patterns that identity, device, and IP-based signals may miss.

Precise location can help answer these questions at different points in the user lifecycle:

  1. Location verification: Is this user where they’re supposed to be?
  2. Location clustering: Is this activity connected to other activity happening in the same place?
  3. Location behavior: Does this match where this account normally operates?

Most teams are familiar with location verification as a compliance requirement. But precise location can also connect activity happening in the same place and identify when an account’s location behavior changes over time.

A fraudster can buy credentials, fabricate an identity, reset a device, or rent a residential IP for a few dollars an hour. They still have to physically be somewhere. That physical presence can be much harder to fake.

What does "precise location" actually mean?

Precise location asks the device where it is and then determines whether that location can be trusted. That can include GPS alongside Wi-Fi, Bluetooth, and cellular signals, plus device integrity checks for rooting, jailbreaking, emulators, and tampering.

The result can be accurate to within a few meters. Spoofing also becomes much harder because manipulating one signal isn’t enough.

In contrast, IP geolocation looks up an IP address and estimates where the network connection originates. It’s an inference about a network.

1. Location verification: Is this user where they’re supposed to be?

This is the most straightforward application of precise location. You have a rule about where someone needs to be, and you verify that they’re actually there.

Geo-compliance is a common example. Online sportsbooks and casinos need to confirm that players are inside permitted jurisdictions before accepting wagers. Certain financial products have jurisdiction requirements. Companies handling export-controlled data may also need stronger evidence of where someone is before granting access.

The same approach can prevent fraud outside regulated industries. And, location verification also matters when an event triggers a payment or other valuable action.

Location can add context to higher-risk transactions too. A withdrawal originating from a country an account has never operated in doesn’t automatically mean fraud, but it can be a strong reason to require additional verification.

Two things matter when implementing these checks.

The location itself needs to be trustworthy. Simply reading the coordinates reported by a device leaves the system vulnerable to mock location apps and other forms of spoofing.

Timing matters too. If you verify someone’s location after a wager, payout, or pickup has already happened, you’ve documented the event rather than prevented the loss. The check needs to happen when the decision is being made.

2. Location clustering: Is this activity coordinated?

Coordinated fraud depends on making related accounts look unrelated, allowing bad actors to operate undetected and scale their impact.

Fraudsters can use new email addresses, rotate residential proxies, reset device identifiers, and create synthetic identities that pass KYC independently. Looking at each account in isolation can make the activity appear legitimate.

Precise location gives fraud teams another way to connect those accounts.

Consider 50 accounts with different identities, IP addresses, and device identifiers. If they’re all operating within a few meters of one another in a short period of time, that combination of physical proximity and high-velocity activity becomes a useful signal that the accounts may be connected.

Promo and bonus abuse

A fraud ring might create dozens or hundreds of accounts to claim the same signup offer. Each can look like a legitimate new customer until you see that many are operating from the same physical location. That activity can also distort acquisition reporting.

Device farms

A device farm uses smartphones and/or tablets, wired to power and networks and run by automation software, to mimic genuine human activity and generate fraudulent mobile traffic at scale. Because each device carries a real IP and a real IMEI, traditional identity, device, and IP signals often treat this traffic as legitimate. Location clustering is what exposes it, by revealing that hundreds of supposedly “unique” sessions are all physically operating out of the same room.

Ban evasion

Ban evasion is when a user who’s been blocked or banned creates a new account to get back onto a platform, typically using a new email, device fingerprint, or IP to look like a first-time user. Because each new account presents fresh identity and device signals, traditional fraud stacks often can’t tell it apart from a genuine new signup.

None of the abuse above necessarily moves the device or devices somewhere else.

Fraud rings

Fraud rings can use synthetic identities to create multiple accounts that appear legitimate and unrelated. In one case, we recently spoke with a team that saw multiple loan applications submitted in a short period using different synthetic identities, with each application clearing identity checks independently.

The applications all originated from the same address.

That concentration of activity revealed a connection between accounts that appeared legitimate when evaluated individually. Location clustering can surface these relationships across users, devices, and locations, helping teams identify coordinated fraud that existing signals may not reveal.

Radar’s fraud rules can flag these clusters and route detections into an existing review queue or fraud stack.

3. Location behavior: Does this match how the account normally behaves?

Legitimate users operate within a relatively predictable geographic footprint. After a few weeks, that history can become another way to distinguish the legitimate account holder from someone who has gained access.

A fraudster might have the password, replicate a device profile, and pass an OTP. Reproducing the account holder’s physical location history is much harder.

Account takeover

Credentials get compromised and an account starts operating from a place it has never operated from before.

U.S. account takeover losses rose to more than $20 billion in 2025, according to a federal report, a 26 percent increase over the prior year.

Device and behavioral signals already play a major role in detecting these attacks. Location provides an independent input.

Account sharing and mule activity

In rideshare and delivery, a verified worker may hand an account to someone who never completed the required background checks. Mule activity can create a similar pattern when an account opened legitimately is later handed to someone else to move funds.

In both cases, the identity associated with the account can stay the same while its location behavior changes.

Impossible travel

A leading prediction market monitors for situations where the same device appears in one location, is blocked for location spoofing, and then suddenly jumps somewhere else on the same account. The bad actor may change locations to try to regain access, but the device and spoofing signals remain connected.

For example, a device may show a true location in China and then appear in the U.S. shortly after with location spoofing signals. Those events may look different individually, but together they reveal an impossible location change and an attempt to evade location controls.

Historical location can also work as a trust signal. If a known device is operating from a place an account has used repeatedly, that can support a lower-friction experience.

How the three approaches fit together

Application Question What it can help detect Where it sits
Location verification Is this user where they’re supposed to be? Geo-compliance violations, location spoofing, fake check-ins, geofenced offer abuse Transaction, wager, claim, or access decision
Location clustering Is this activity coordinated? Promo abuse, multi-accounting, device farms, device resetting, fraud rings Signup, payout, and review
Location behavior Does this match the account’s history? Account takeover, account sharing, mule handoffs, impossible travel Login, transfer, and withdrawal

A single customer journey can use all three. At signup, location clustering can determine whether this is the fortieth account created from the same address that week. At a later login, location behavior can compare the session with the account’s established history. When the user initiates a withdrawal, location verification can confirm whether the transaction is happening from somewhere it’s allowed to occur.

Where to start

If you’re evaluating precise location for fraud prevention, start with one fraud vector you can measure.

“Reduce fraud” is too broad to evaluate. “Catch multi-accounting at signup” gives you something specific to test. Ideally, it’s also a problem you can attach a dollar amount to.

Run it in shadow mode first

Add the signal without changing customer-facing decisions for 30 days. Then look at the incremental fraud your current stack missed, any false positives introduced, and the additional operational load on your review team.

Add to your existing stack

There’s no reason to replace systems that are already working. Precise location is most useful as an additional input into the fraud platform, orchestration layer, or internal model you already use.

Be thoughtful about permissions

Asking every user for precise location can introduce unnecessary friction. One approach is to assess device and network risk first using Radar Reveal, which doesn’t require location permissions, then step up to precise location only when a session warrants additional verification.

Physical presence as a fraud signal

Many of the signals fraud teams rely on have become easier to manipulate. Credentials can be bought. Devices can be reset or emulated. Residential IPs can be rented cheaply, and synthetic identities continue to improve.

Physical presence has a different constraint: the person or device still has to be somewhere.

Radar Protect gives fraud and compliance teams access to precise, spoof-resistant location and device signals that can support verification, clustering, and behavioral analysis. Teams can configure their own rules and reporting, then integrate those signals into the fraud stack they already use. Get a demo.