Achtung: Your browser is outdated. Please note that Gunfinder may not work properly in some places. You should update your browser as soon as possible. Learn more here!
Gunfinder Magazine

Studies on External Data in Fraud Scoring 2026

Studies on External Data in Fraud Scoring 2026

In short: External data can clearly improve fraud scoring if used purposefully. The text basically comes down to four points: more detected fraud, fewer false alarms, better decisions at login, checkout, and payout, and strict rules under GDPR and PSD2.

I would sum up the article like this:

  • Fraud is increasing: In the EEA, the fraud amount in 2024 was €4.2 billion.
  • Combined signals bring the most: especially device, IP/network, identity/consortium, email/phone, and behavior.
  • The biggest leverage is at risk points in the process: registration, login, listing, payment, auction, and payout.
  • Not every study is 1:1 transferable: You always have to look at baseline, fraud type, sample, and false positives.
  • Legally, only a well-founded use counts: purpose limitation, data minimization, deletion deadlines, and for strict automated decisions also human review.

For me, the main message is clear: External data is no cure-all. It’s mainly worth it when it adds measurable value at the right steps in the process and when its use is well documented.

Quick Comparison

Area What it’s about What the article says
Effect More hits, fewer false alarms External signals often help most in combination
Data types Device, IP, identity, consortium, email, phone, behavior No single signal usually suffices alone
Use cases Registration, login, listing, checkout, payout Additional benefit is usually highest there
Economics Costs versus fraud losses, review effort, and dropouts Only pays off with clear net effect
Law GDPR, PSD2-TRA, partly WaffG Use only with a clean legal basis

So when you read the article, don’t see it as a collection of uplift numbers, but as a clear question: Which external signals reduce fraud and false alarms at the same time in your process – without violating data protection rules?

Preventing and detecting fraud with data analytics | Focus on Forensics

Which external data sources matter most in 2026

In 2026, combined external signals will provide the biggest leverage against fraud. It’s not the amount of data that makes the difference, but the additional signal value in ongoing risk decisions.

Device, network, and location signals

Device fingerprinting bundles browser, device, and network features into a stable device ID. The key point: it often remains usable even if cookies are deleted or the IP address changes.[19] Added to this are network reputation data, such as known fraud hotspots, Tor usage, suspicious ASN clusters, and the comparison between IP location and provided address.[13][14]

For Gunfinder this is very concrete: if a known account suddenly logs in via a high-risk IP with a completely new device pattern and shortly after triggers a high-value transaction or changes payout details, this can be detected in real time and secured with an additional check.[8][9][14] This is exactly where the appeal of this data lies. They provide early clues, often within seconds. Their strongest significance, however, only emerges when combined with identity and behavioral data.

Identity, Consortium and Registry Data

Device and network signals often raise suspicion at first. Whether a case holds up is then shown by the identity verification. Consortium data bundles fraud signals from many dealer environments simultaneously. This makes devices, email addresses, phone numbers, and identities visible that have already been flagged elsewhere with chargebacks or disputes, even if the profile on a new marketplace still appears inconspicuous.[9][10] For marketplaces, this is exactly the core benefit: Detect cross-merchant risk before it becomes visible in your own inventory.

In the firearms environment, WBK and government registry data also flow directly into verification.[5] Address consistency checks and sanction lists complement the verification.[9][11][13] This makes the difference between a mere warning signal and a reliable assessment.

Email, Phone and Behavioral Data

Email and phone signals are often cheap, quickly available, and useful early in the process. These include, for example, the age of an email address, the domain type, known leaks, and the use of the same address across multiple dealers. It’s similar with phone numbers, for example with short lifespan, VoIP usage, or indications of SIM swaps.[6][9][10]

Behavioral data at the session level are added, such as typing rhythm, mouse movements, scrolling behavior, and the pace of completing a purchase. Automated processes often show typical patterns here: uniform typing and clicking sequences, straight mouse paths, and no hesitation at points where people usually pause briefly.[6][7][12][14][15]

On their own, these signals are often too weak for reliable decisions. But when email, phone, and behavioral data are evaluated together, their significance increases significantly.[16][17][18]

Measured Impact: Detection Rates, False Alarms, and Operational Effects

Fraud detection rates compared: Internal vs. External data signals 2026

Fraud detection rates compared: Internal vs. External data signals 2026

Detection Gain Through External Data

It’s no longer about which signals exist, but what they ultimately measurably bring to the model. The study situation is quite clear here: When external signals are added, detection rate and precision increase significantly. At the same time, false alarms decrease.[24]

Approach False Positive Rate Fraud Detection Rate
Pure internal rules 5–10 % 70–80 %
Rules + simple ML 2–5 % 85–90 %
Advanced ML + network analysis 1–2 % 95–97 %
ML + behavior + external signals 0.5–1.5 % 97–99 %

You can see quite quickly where this is going: The more useful external signals flow into the system, the better the model separates suspicious from legitimate cases.[24]

A concrete case makes this tangible. HSBC reduced the volume of its fraud alerts by more than 60% with AI-powered monitoring together with Google Cloud. At the same time, two to four times more truly suspicious activities were detected.[20]

Reduce false alarms, improve customer experience

In practice, false declines are often more expensive than many think. For every €1 lost to fraud, an estimated €13 in revenue loss occurs due to wrongly declined legitimate customers.[24] For a marketplace, this is not a small problem but directly affects revenue and operations.

This shows up in several areas:

  • fewer manual reviews
  • fewer dropouts
  • less friction at checkout

External data helps exactly at this point. When device and identity signals classify a person as trustworthy, often an additional authentication step can be skipped. This saves time and lowers the barrier in the payment process.

Corporate practice in Germany also shows this effect. 85% of German companies report better detection accuracy through the use of machine learning.[23] Even more interesting is the second figure: 71% find cases that would have remained undetected with purely internal systems.[23]

Limits, biases, and weak signals

Despite the good effects, external data is not a miracle cure. Individual signals are often weak, and models lose 1–2% accuracy per month without retraining.[22][24] That sounds small at first. But over several months, it adds up noticeably.

There is also a problem that makes many standard checks look outdated: synthetic identities. They already account for 11% of all fraud cases in 2026.[21] Real and fake data points are mixed so cleverly that normal verification paths often don’t trigger.

If you use external data, you must carefully consider the ongoing effort. This includes maintaining models, checking data sources, and critically assessing signal quality and biases. This is exactly what brings costs, operational effort, and compliance into the focus of evaluation.

Costs, Benefits and Compliance Trade-offs in Germany and the EU

Costs, Returns and Expected ROI

After effectiveness, profitability counts. In the end, it’s not enough just to reduce fraud. The solution must also pay off.

On the cost side, especially license and API fees, integration, model monitoring, as well as effort for data protection, governance, and support arise.

The benefits show up in several places at once: less fraud, fewer chargebacks, fewer manual checks, and fewer false declines. That’s often what makes the business case exciting. EU dealers lose on average around 2.8% of their revenue due to fraud, 3% of all orders are fraudulent, and 24% of checks are still done manually.[36]

The following overview shows typical ranges from studies and market analyses.[25][4][26][27][32][33]

Data Category Typical Benefit Main Risk
Device & Network Intelligence 20–40% fraud reduction; helpful for PSD2-TRA Initially increased false alarms before tuning
E-Mail & Phone Risk Scoring 10–25% fraud reduction; fewer false alarms with known contacts Low reliability with new addresses
Consortium/Network Data 30–50% with known patterns; high leverage with volume Outdated data increases false alarms; GDPR diligence required
Behavior Analysis 30–60% with bot attacks; significant false alarm reduction High integration effort
Identity/Address Verification 15–35% with identity fraud; useful for high-risk products Outdated data can increase false alarms

You can see quickly: Not every signal pays off equally. Some sources deliver good hits early but cause more false alarms in the startup phase. Others require more setup work but then significantly reduce bot attacks or identity fraud.

PSD2 Transaction Risk Analysis and SCA Exemptions

Under PSD2, payment service providers may only use SCA exemptions if their fraud rate remains below the set thresholds.[1][34][35] The EBA calculates this rate based on a rolling 90-day period. The decisive factor is the fraud rate of the payment service provider who wants to apply the exemption.[1][34][35]

In practice, this means: External risk signals can help to specifically mark risky transactions for SCA and allow non-critical processes to pass with little friction.[25][11] This is exactly where the leverage lies. Those who separate cleanly lose fewer good purchases and at the same time keep the fraud rate under control.

Whether this approach is legally sound is then decided by the GDPR.

GDPR, data minimization and lawful use of third-party data

Using third-party data requires a clear approach: a precise description of the processing purpose, a documented balancing of interests, clear deletion deadlines, and – for far-reaching automated decisions – the option for human review.[28][30]

Especially with consortium data, caution is advised. If such scores lead to automated rejections or similarly significant effects, the protections from Art. 22 apply: human review, an understandable explanation, and the possibility to challenge the decision.[29][31] Additionally, purpose limitation, transparency, and proportionality must be clearly documented.[2]

For Gunfinder, only the measurable net effect per transaction counts in the end. Only signals that clearly add value and are based on a solid legal basis belong in the scoring.

What the results mean for marketplaces like Gunfinder

From the studies, Gunfinder can derive very concrete application areas: registration, login, listing, checkout, and payout.

Marketplace risks and suitable external signals

Gunfinder is not a normal online shop. The marketplace trades regulated and high-value goods – firearms, ammunition, and optics. If fraud occurs here, it affects not only revenue but also user trust and makes verification more complex.

The studies show a clear point: external data is especially effective where the greatest risks lie in the transaction process. It’s not about collecting as much data as possible. More important is to use exactly the signals per step that provide the greatest added value.

Transaction type Relevant external data Expected benefit
New seller registration Device fingerprint & consortium data; identity, registry, and license verification Fewer fake dealers; better compliance in firearms trade
Login & account access Device & IP reputation; behavioral anomalies; email/phone risk Less account takeover; more targeted additional verification
Listing regulated products Public registries; sanction lists; license data Higher listing quality; fewer unauthorized offers
Payment for high-value items Device risk; network/geolocation signals; consortium data on fraud cases Better fraud detection; secure TRA decisions under PSD2
Auction bids and closing Behavior models; bot and collusion detection Less shill bidding; more trust in auctions
Payouts to sellers Bank account verification; consortium data on pass-through accounts; KYB checks Less payout fraud; payout changes after risky login are a strong ATO signal

The legal framework is clear: GDPR, PSD2-TRA, and WaffG set the boundaries for all steps. Documented legitimate interest, data minimization, and clear purpose limitation are mandatory.

Reading studies from 2026 correctly

Not every strong metric from a study can be transferred 1:1 to Gunfinder. In the end, context and measurement type always matter. Five points help with classification:

  • Sample size and context: Does the study come from high-volume retail or low-frequency, high-value transactions? Large bank datasets can rarely be directly applied to Gunfinder.[26][4][38]
  • Baseline model: What was the uplift measured against? A simple rule set or an already good ML model? Improvements of 40–60% often only appear when the baseline system was rather weak.[37][40]
  • Types of fraud: What forms of fraud have actually been recorded? EU reports show that social engineering fraud is growing. This exact part can only be limitedly detected by technical external data.[26][3][41] For Gunfinder, ATO, Seller Fraud, Listing Abuse, and Payout Fraud are more important. Additionally: studies over multiple periods are usually more reliable than a single snapshot.[42][43][44][26][4][3]
  • Study transparency: Are recall, precision, and false-positive rate reported together? If provider studies don’t include independent review and don’t mention false alarms, caution is advised.[37][39][40]

Only the signals that work in your own process, for your own type of fraud, and within the appropriate legal framework ultimately bring a real net effect.

Conclusion: The Most Important Insights

External signals measurably improve fraud detection. They are most effective at critical points like registration, login, listing, checkout, and payout. You should only adopt uplift figures if the sample, baseline, and type of fraud also fit Gunfinder. And if you want to implement GDPR and PSD2 properly, you need documented legitimate interest, data minimization, and a clear purpose limitation.[45][46][47]

FAQs

Which External Data Is Worth It First?

First, the basic data counts. It forms the foundation for every compliance check: amount, chosen payment method, identity data of buyer and seller, as well as date and time.

Only then do contextual signals like IP addresses or device IDs make sense. The same applies to behavioral signals, such as an unusual order frequency. For regulated items, verifying purchase eligibility is also central.

How Do I Avoid False Alarms from External Signals?

Rely on clear rules and an analysis in context, instead of viewing individual signals in isolation. A high order value alone is often not yet an indication of fraud. Only when several signs come together should a manual review start.

Equally important: connect signals from all steps in the process and give clear instructions for uploads. This way, fewer unreadable documents end up in the system, decisions become more consistent, and legitimate users are not unnecessarily blocked.

When Is the Use of External Data GDPR-Compliant?

The use of external data is GDPR-compliant if you adhere to the principles of data minimization and security. So only store the information you actually need for the respective check.

You should protect these sensitive data with modern encryption and clear access controls. At Gunfinder, the process of identity verification and risk assessment must also be openly documented to ensure traceability and legal certainty.

Matching listings

Sponsored listings

You might also like

More articles on this topic

View all items
View all items