Research: why fraud prevention must start before login

The next generation of fraud fighters is already in the ring. 🥊 Nominate someone for Fraud Fight Club's Rising 10

Memcyco Blog

Get the latest insights and protect your business and your customers from website spoofing fraud.

Fraud and ATO prevention

PoSA™ v1.11: Turning Fragmented Attack Signals Into Actionable Risk

With PoSA v1.11, we focused on a practical problem: detecting more attack activity does not necessarily help fraud and security teams make better decisions.

PoSA already identifies activity across digital impersonation, credential theft, attacker devices and account access. The challenge is making the connections between that activity easier to understand, identifying which users and devices require attention, and making that intelligence available to the systems and teams responsible for responding.

Version 1.11 improves that process with new ways to prioritize related attack activity around affected users, identify attacker devices earlier, bring user and device risk intelligence into existing login and fraud systems, and control how protection is applied.

The goal is to reduce the time between identifying meaningful attack activity and being able to act on it.

Understand risk around the affected user

Protective capabilities aside, PoSA already gives teams visibility into individual events, users, devices and incidents. In v1.11, we added Attack Overview to make it easier to prioritize that activity around the affected user.

If a user is phished, then has credentials used in a stuffing attempt and later has a login associated with an unfamiliar device, those events are more useful when viewed together than as three entries in an event queue.

Attack Overview surfaces these combinations over a selected period, helping analysts identify users associated with multiple forms of attack activity and decide where to investigate first. These combined events also aggregate to a high risk score that automation can then act on to mitigate attacks? 

The same view provides a period-level summary of affected users, leading attack vectors, phishing sites and known users by exposure level, giving teams a faster way to understand where risk is concentrated.




Bring high fidelity risk intelligence into existing decisioning

PoSA continuously builds context around users and devices from activity observed earlier in the attack, prior to reaching login. With the new Risk API, that intelligence can be made available to existing login and fraud systems when an access attempt is evaluated.

The API delivers real-time user and device risk scores, along with the signals behind them, before access is granted. Customers can use that information within their own policies and decision logic, giving existing controls additional context about the user or device behind the access attempt.

The login or fraud system continues to own the decision, using relevant context PoSA established earlier in the attack rather than evaluating the access attempt only on the signals available at that point.

Give teams more control over protection

Adaptive Protection gives customers more control over how PoSA responds to activity on impersonating sites.

Teams can choose how PoSA responds, including warning the user, redirecting them to the genuine site, displaying an error page or blocking sensitive input. They can also control the proportion of detected traffic that receives the selected response, allowing protective actions to be introduced gradually and adjusted according to their requirements.

This separates the detection of impersonating-site activity from the customer’s choice of how PoSA should respond to it.

Send PoSA events into existing workflows

The new Push API allows PoSA events to be sent directly to customer systems as they are detected, instead of relying only on existing retrieval workflows.

Events can feed existing SIEM, case-management and fraud workflows, where they can be processed alongside other security and fraud data and used by established playbooks.

The Push API serves a different purpose from the Risk API. The Risk API provides user and device risk intelligence when an access decision is being made, while the Push API delivers detected events into operational systems as they occur.

What changes with PoSA v1.11

PoSA v1.11 strengthens several points between detecting attack activity and putting that intelligence to use:

  • Attack Overview brings related activity together around affected users so analysts can prioritize investigation.
  • Risk API brings user and device risk intelligence into existing login and fraud decisioning.
  • Adaptive Protection gives teams more control over protective responses.
  • Push API delivers detected events directly into established operational workflows.

Together, these changes make the intelligence generated across an attack easier to understand and easier to use within the security and fraud systems customers already have.

PoSA v1.11 continues the direction we have taken with the platform: connect attack activity to the users and devices it puts at risk, then make that context available while there is still an opportunity to prevent account compromise.

See PoSA in action

See how Memcyco connects attack activity to user and device risk, helping your teams act before account compromise.

Book your Memcyco demo →

Arthur Zavalkovsky

VP of Product at Memcyco

What’s New?