CASE STUDY
++70% Onboarding Conversion and Zero Fraud:
How a Top LatAm Bank Dismantled Mule Account Farms
“Incognia hit the nail on the head. Approval rates went up, and fraud dropped significantly.
Zero
reported fraud cases after just five months of operation with Incognia.
increase in onboarding conversion rates, unlocking growth for legitimate users.
reduction in the volume of high-risk classifications within the user base.
The Challenge: Hidden Threats and Spoofed Signals
The bank was facing a systematic and sophisticated attack involving identity fraud and mule accounts.
Fraud Farms
Criminals concentrated their operations in specific micro-regions of the country, operating like organized crime offices. They used compromised devices, including emulators, rooted devices, and modified apps. This technical profile is a strong indicator of high-risk environments.
Recruiting Money Mules
The primary vector was not Account Takeover (ATO), but the use of real third-party data (PII). Investigations suggested fraudsters were paying individuals ("mules") to hand over their data and photos for account opening, bypassing traditional biometrics by using low-quality images or exploiting minors.
Persistence of Attack
A single device, if not detected quickly, was associated with the opening or access of dozens of distinct accounts. The financial impact was severe, resulting in average losses of five figures per consummated fraudulent account.
The Solution: Location Intelligence & Device Integrity
The institution integrated Incognia’s risk platform to replace reactive logic with a proactive defense based on physical behavior and deep device integrity.
1. Detecting Anomalies in the Physical World
Unlike purely digital signals that were being spoofed, Incognia analyzed the concentration of high-risk devices. The technology identified clusters of devices exhibiting anomalous behavior within specific micro-regions.
-
Proactive vs. Reactive: Incognia flagged the location as suspicious before the fraud peak occurred. When the bank later confirmed the attacks, the locations matched Incognia’s early warnings exactly.
2. Integrity & Cross-Device Blocking
The solution enabled the identification of devices attempting to open multiple accounts using different identities. Incognia implemented rules focused on:-
Device Integrity: Detecting devices with signs of tampering, emulators, or frequent factory resets.
-
Risk History: Blocking environments associated with previous identity fraud attempts.
-
Continuous Protection: Identification not only during onboarding but also within post-login sessions, preventing fraudulent devices from continuing to access accounts that had already been opened.
The results
The implementation drastically changed the bank's security landscape and operational efficiency in just four months.