Fideo Blog: Identity Fraud, Product: Lens
From a Fragment to a Network: Real-Time Identity Connections Reveal the Networks Behind Fraud and Financial Crime
A government agency investigating a cyberattack had an unusual clue.
The attack began with targeted phishing emails disguised as Adobe signature requests designed to steal Microsoft 365 credentials. After compromising accounts, the attacker appeared to use administrator privileges to move laterally and target additional government employees.
Investigators noticed something unusual in the list of email addresses associated with the attack. Nearly every address belonged to the government’s domain except one. That single outside email address stood out as a potential connection to the person behind the attack.
Starting with only that email address, Fideo Lens enabled exploration of relationships across Fideo’s identity intelligence graph. The email connected to a Telegram account associated with the sale of phishing kits and other exploits. From there, we uncovered additional email addresses, a name associated with the suspected foreign actor and other evidence connecting the original email address to compromised government employee accounts.
One fragment had opened a path unmasking an international criminal.
Thousands of miles away, investigators encountered a very different crime.
A major retailer’s organized retail crime team, working with Homeland Security Investigations, was investigating a sophisticated post-purchase markdown fraud scheme. Suspects purchased high-end electronics and shipped them to multiple addresses in New York. They then manipulated local copies of the retailer’s webpages to make the products appear to be offered at substantially lower prices and used those pages to make fraudulent claims under the retailer’s price-match guarantee.
The resulting credits were issued as pre-activated gift cards and sent to multiple email addresses, with some transactions also sharing a common phone number.
Individually, the emails, phone numbers and shipping addresses provided investigators with pieces of the story. The question was how they connected.
Graph intelligence reveals the answer. Relationships among email addresses, phone numbers and physical addresses connected seemingly separate transactions to two individuals associated with a transnational criminal organization. The merchandise was being shipped overseas to China.
Two investigations. Two very different crimes. In each case, the breakthrough came from the same shift in perspective: stop looking only at the record and start looking at the network.
When the investigation becomes manual
Most investigations begin with incomplete information. An investigator may have an email address, phone number, Social Security number, name, physical address, company or other identifier associated with suspicious activity.
Then the manual work begins.
Investigators move among internal case-management systems, transaction records, identity tools, public records, search engines and external databases. They collect evidence from each source and try to determine how the pieces relate.
The investigator is effectively constructing a graph manually: this phone belongs to this person; this person used this address; this email is associated with another identity; that identity connects to a company; and that company shares attributes with something else already under investigation.
The process requires expertise, but it also consumes something investigative teams have in increasingly short supply: time.
A record can point to a network
A single identity attribute can appear completely ordinary in isolation.
An email address becomes more interesting when it connects to several names or phone numbers. An address takes on new significance when it is shared by a cluster of identities or businesses. A company that initially appears legitimate may warrant additional investigation when relationships among its officers, addresses and associated identities reveal unexpected connections.
This is particularly important when investigating coordinated fraud and cybercrime because sophisticated actors deliberately fragment their activities.
They use aliases, synthetic identities, multiple accounts, businesses, phone numbers and email addresses to make related activity appear unrelated. Looking at each record independently can therefore obscure the very thing an investigator needs to understand: the network behind the activity.
The investigative question becomes more powerful when it changes from “What do I know about this identity?” to “What is this identity connected to, and what do those relationships tell me?”
Making relationships usable and connected
Organizations already possess valuable first-party information about their customers, accounts, transactions and incidents. But first-party data naturally describes only what an organization can observe within its own four walls.
Graph-linked identity intelligence can extend that field of view.
By connecting identity attributes across a broader intelligence network, investigators can identify relationships that may be invisible in their internal systems. This does not require replacing existing investigative platforms or workflows. Instead, external identity intelligence can enhance them with context that first-party data alone cannot provide.
That context also needs to be explainable.
Investigators need more than a risk score or an opaque assertion that two entities might be related. They need to see the underlying attributes and relationships so they can evaluate the evidence, follow additional investigative paths and explain how they reached their conclusions.
Applying the model with Fideo Lens
We built Fideo Lens around this idea.
An investigator can start with a single fragment or look for correlations across multiple data points. Emails, phone numbers, Social Security numbers, names, addresses and companies can all become starting points for exploring connected identity intelligence.
Lens draws from Fideo’s identity intelligence network, built through thousands of merchants, publishers and institutional partners, together with intelligence derived from dark web research, government datasets and authoritative data sources governed by GLBA.
Rather than returning those signals as disconnected search results, Lens maps relationships among them, allowing investigators to follow connections among people, businesses and identity attributes.
A suspicious email can lead to an identity. That identity can expose a phone number or address. Those attributes can reveal additional people, businesses or digital identities. As the graph expands, patterns that were invisible at the individual-record level can become apparent.
The result is a clearer path from signal to evidence to understanding.
Seeing the network in real time
The value of this approach is ultimately about more than making investigations easier. It is about making them faster.
When investigators spend hours or days searching multiple systems, reconciling records and manually connecting identities, the underlying activity does not stop. Fraudsters can move money, compromise additional accounts, victimize more consumers and businesses, or shift to new identities while an investigation is still underway.
Graph intelligence can compress work that once took days into minutes.
That means investigators can spend less time searching for connections and more time deciding what those connections mean. It can accelerate the path to interdiction, help teams prioritize limited investigative resources and strengthen the evidence available when a case needs to be escalated or prosecuted.
Fraud and cybercrime increasingly operate as networks.
Investigators should be able to see the network before the damage is done.
Connect with our team to learn more or request a demo.
Which Fideo product is right for your business?
Fideo protects people and brands by empowering more trustworthy digital interactions. Start your journey with us to safeguard what your business values most.