
In short: External data can clearly improve fraud scoring if used purposefully. The text basically comes down to four points: more detected fraud, fewer false alarms, better decisions at login, checkout, and payout, and strict rules under GDPR and PSD2.
I would sum up the article like this:
For me, the main message is clear: External data is no cure-all. It’s mainly worth it when it adds measurable value at the right steps in the process and when its use is well documented.
Quick Comparison
| Area | What it’s about | What the article says |
|---|---|---|
| Effect | More hits, fewer false alarms | External signals often help most in combination |
| Data types | Device, IP, identity, consortium, email, phone, behavior | No single signal usually suffices alone |
| Use cases | Registration, login, listing, checkout, payout | Additional benefit is usually highest there |
| Economics | Costs versus fraud losses, review effort, and dropouts | Only pays off with clear net effect |
| Law | GDPR, PSD2-TRA, partly WaffG | Use only with a clean legal basis |
So when you read the article, don’t see it as a collection of uplift numbers, but as a clear question: Which external signals reduce fraud and false alarms at the same time in your process – without violating data protection rules?
In 2026, combined external signals will provide the biggest leverage against fraud. It’s not the amount of data that makes the difference, but the additional signal value in ongoing risk decisions.
Device fingerprinting bundles browser, device, and network features into a stable device ID. The key point: it often remains usable even if cookies are deleted or the IP address changes.[19] Added to this are network reputation data, such as known fraud hotspots, Tor usage, suspicious ASN clusters, and the comparison between IP location and provided address.[13][14]
For Gunfinder this is very concrete: if a known account suddenly logs in via a high-risk IP with a completely new device pattern and shortly after triggers a high-value transaction or changes payout details, this can be detected in real time and secured with an additional check.[8][9][14] This is exactly where the appeal of this data lies. They provide early clues, often within seconds. Their strongest significance, however, only emerges when combined with identity and behavioral data.
Device and network signals often raise suspicion at first. Whether a case holds up is then shown by the identity verification. Consortium data bundles fraud signals from many dealer environments simultaneously. This makes devices, email addresses, phone numbers, and identities visible that have already been flagged elsewhere with chargebacks or disputes, even if the profile on a new marketplace still appears inconspicuous.[9][10] For marketplaces, this is exactly the core benefit: Detect cross-merchant risk before it becomes visible in your own inventory.
In the firearms environment, WBK and government registry data also flow directly into verification.[5] Address consistency checks and sanction lists complement the verification.[9][11][13] This makes the difference between a mere warning signal and a reliable assessment.
Email and phone signals are often cheap, quickly available, and useful early in the process. These include, for example, the age of an email address, the domain type, known leaks, and the use of the same address across multiple dealers. It’s similar with phone numbers, for example with short lifespan, VoIP usage, or indications of SIM swaps.[6][9][10]
Behavioral data at the session level are added, such as typing rhythm, mouse movements, scrolling behavior, and the pace of completing a purchase. Automated processes often show typical patterns here: uniform typing and clicking sequences, straight mouse paths, and no hesitation at points where people usually pause briefly.[6][7][12][14][15]
On their own, these signals are often too weak for reliable decisions. But when email, phone, and behavioral data are evaluated together, their significance increases significantly.[16][17][18]
Fraud detection rates compared: Internal vs. External data signals 2026
It’s no longer about which signals exist, but what they ultimately measurably bring to the model. The study situation is quite clear here: When external signals are added, detection rate and precision increase significantly. At the same time, false alarms decrease.[24]
| Approach | False Positive Rate | Fraud Detection Rate |
|---|---|---|
| Pure internal rules | 5–10 % | 70–80 % |
| Rules + simple ML | 2–5 % | 85–90 % |
| Advanced ML + network analysis | 1–2 % | 95–97 % |
| ML + behavior + external signals | 0.5–1.5 % | 97–99 % |
You can see quite quickly where this is going: The more useful external signals flow into the system, the better the model separates suspicious from legitimate cases.[24]
A concrete case makes this tangible. HSBC reduced the volume of its fraud alerts by more than 60% with AI-powered monitoring together with Google Cloud. At the same time, two to four times more truly suspicious activities were detected.[20]
In practice, false declines are often more expensive than many think. For every €1 lost to fraud, an estimated €13 in revenue loss occurs due to wrongly declined legitimate customers.[24] For a marketplace, this is not a small problem but directly affects revenue and operations.
This shows up in several areas:
External data helps exactly at this point. When device and identity signals classify a person as trustworthy, often an additional authentication step can be skipped. This saves time and lowers the barrier in the payment process.
Corporate practice in Germany also shows this effect. 85% of German companies report better detection accuracy through the use of machine learning.[23] Even more interesting is the second figure: 71% find cases that would have remained undetected with purely internal systems.[23]
Despite the good effects, external data is not a miracle cure. Individual signals are often weak, and models lose 1–2% accuracy per month without retraining.[22][24] That sounds small at first. But over several months, it adds up noticeably.
There is also a problem that makes many standard checks look outdated: synthetic identities. They already account for 11% of all fraud cases in 2026.[21] Real and fake data points are mixed so cleverly that normal verification paths often don’t trigger.
If you use external data, you must carefully consider the ongoing effort. This includes maintaining models, checking data sources, and critically assessing signal quality and biases. This is exactly what brings costs, operational effort, and compliance into the focus of evaluation.
After effectiveness, profitability counts. In the end, it’s not enough just to reduce fraud. The solution must also pay off.
On the cost side, especially license and API fees, integration, model monitoring, as well as effort for data protection, governance, and support arise.
The benefits show up in several places at once: less fraud, fewer chargebacks, fewer manual checks, and fewer false declines. That’s often what makes the business case exciting. EU dealers lose on average around 2.8% of their revenue due to fraud, 3% of all orders are fraudulent, and 24% of checks are still done manually.[36]
The following overview shows typical ranges from studies and market analyses.[25][4][26][27][32][33]
| Data Category | Typical Benefit | Main Risk |
|---|---|---|
| Device & Network Intelligence | 20–40% fraud reduction; helpful for PSD2-TRA | Initially increased false alarms before tuning |
| E-Mail & Phone Risk Scoring | 10–25% fraud reduction; fewer false alarms with known contacts | Low reliability with new addresses |
| Consortium/Network Data | 30–50% with known patterns; high leverage with volume | Outdated data increases false alarms; GDPR diligence required |
| Behavior Analysis | 30–60% with bot attacks; significant false alarm reduction | High integration effort |
| Identity/Address Verification | 15–35% with identity fraud; useful for high-risk products | Outdated data can increase false alarms |
You can see quickly: Not every signal pays off equally. Some sources deliver good hits early but cause more false alarms in the startup phase. Others require more setup work but then significantly reduce bot attacks or identity fraud.
Under PSD2, payment service providers may only use SCA exemptions if their fraud rate remains below the set thresholds.[1][34][35] The EBA calculates this rate based on a rolling 90-day period. The decisive factor is the fraud rate of the payment service provider who wants to apply the exemption.[1][34][35]
In practice, this means: External risk signals can help to specifically mark risky transactions for SCA and allow non-critical processes to pass with little friction.[25][11] This is exactly where the leverage lies. Those who separate cleanly lose fewer good purchases and at the same time keep the fraud rate under control.
Whether this approach is legally sound is then decided by the GDPR.
Using third-party data requires a clear approach: a precise description of the processing purpose, a documented balancing of interests, clear deletion deadlines, and – for far-reaching automated decisions – the option for human review.[28][30]
Especially with consortium data, caution is advised. If such scores lead to automated rejections or similarly significant effects, the protections from Art. 22 apply: human review, an understandable explanation, and the possibility to challenge the decision.[29][31] Additionally, purpose limitation, transparency, and proportionality must be clearly documented.[2]
For Gunfinder, only the measurable net effect per transaction counts in the end. Only signals that clearly add value and are based on a solid legal basis belong in the scoring.
From the studies, Gunfinder can derive very concrete application areas: registration, login, listing, checkout, and payout.
Gunfinder is not a normal online shop. The marketplace trades regulated and high-value goods – firearms, ammunition, and optics. If fraud occurs here, it affects not only revenue but also user trust and makes verification more complex.
The studies show a clear point: external data is especially effective where the greatest risks lie in the transaction process. It’s not about collecting as much data as possible. More important is to use exactly the signals per step that provide the greatest added value.
| Transaction type | Relevant external data | Expected benefit |
|---|---|---|
| New seller registration | Device fingerprint & consortium data; identity, registry, and license verification | Fewer fake dealers; better compliance in firearms trade |
| Login & account access | Device & IP reputation; behavioral anomalies; email/phone risk | Less account takeover; more targeted additional verification |
| Listing regulated products | Public registries; sanction lists; license data | Higher listing quality; fewer unauthorized offers |
| Payment for high-value items | Device risk; network/geolocation signals; consortium data on fraud cases | Better fraud detection; secure TRA decisions under PSD2 |
| Auction bids and closing | Behavior models; bot and collusion detection | Less shill bidding; more trust in auctions |
| Payouts to sellers | Bank account verification; consortium data on pass-through accounts; KYB checks | Less payout fraud; payout changes after risky login are a strong ATO signal |
The legal framework is clear: GDPR, PSD2-TRA, and WaffG set the boundaries for all steps. Documented legitimate interest, data minimization, and clear purpose limitation are mandatory.
Not every strong metric from a study can be transferred 1:1 to Gunfinder. In the end, context and measurement type always matter. Five points help with classification:
Only the signals that work in your own process, for your own type of fraud, and within the appropriate legal framework ultimately bring a real net effect.
External signals measurably improve fraud detection. They are most effective at critical points like registration, login, listing, checkout, and payout. You should only adopt uplift figures if the sample, baseline, and type of fraud also fit Gunfinder. And if you want to implement GDPR and PSD2 properly, you need documented legitimate interest, data minimization, and a clear purpose limitation.[45][46][47]
First, the basic data counts. It forms the foundation for every compliance check: amount, chosen payment method, identity data of buyer and seller, as well as date and time.
Only then do contextual signals like IP addresses or device IDs make sense. The same applies to behavioral signals, such as an unusual order frequency. For regulated items, verifying purchase eligibility is also central.
Rely on clear rules and an analysis in context, instead of viewing individual signals in isolation. A high order value alone is often not yet an indication of fraud. Only when several signs come together should a manual review start.
Equally important: connect signals from all steps in the process and give clear instructions for uploads. This way, fewer unreadable documents end up in the system, decisions become more consistent, and legitimate users are not unnecessarily blocked.
The use of external data is GDPR-compliant if you adhere to the principles of data minimization and security. So only store the information you actually need for the respective check.
You should protect these sensitive data with modern encryption and clear access controls. At Gunfinder, the process of identity verification and risk assessment must also be openly documented to ensure traceability and legal certainty.