The Signal: FinServ | Incognia

Location, location, location

Written by André Ferraz | Jul 30, 2026, 4:00:01 PM

Location, location, location. It’s not just for real estate.

From what I’m hearing from banks, many of the signals fraud teams have relied on for years are reaching their limits.

Passwords and credentials can be phished or purchased.

OTPs can be intercepted or socially engineered.

IP addresses can be hidden behind proxies and VPNs.

GPS can be spoofed.

Device identifiers can disappear after a factory reset.

And AI is making all of this even easier.

These signals still matter. But they’re becoming easier to manipulate and less useful on their own against some of the more complex fraud problems banks are dealing with.

The missing piece is physical context.

Precise location intelligence can show you whether a device is behaving consistently with the customer behind the account, whether supposedly unrelated accounts are operating from the same environment, and whether a “new” device is connected to fraud you’ve already seen.

It gives you a way to solve problems that traditional identity and device signals struggle to see, while adding more confidence to the controls you already use.

The two biggest unlocks for banks

From my perspective, there are two areas where precise location makes the biggest difference.

1. Detecting activity that is currently hard to see

Precise location can expose connections that may otherwise be invisible when accounts, identities, and devices are evaluated separately.

That includes devices returning after factory resets, coordinated fraud operations, and accounts whose physical behavior no longer matches the customer behind them.

2. Giving legitimate customers a better experience

Precise location can also give you more confidence in legitimate activity.

It can help verify customers in the background when they open an account from home, log in from a new device at a trusted location, recover an account, or complete a sensitive transaction.

That confidence can reduce manual reviews and unnecessary step-ups, including OTPs, MFA, and facial verification.

What this looks like in practice

Location intelligence can do a lot. Here are some of the most common ways our customers benefit from it:

Detecting mule account handovers

I’ve talked about the challenges of detecting mule account handovers before. We know they’re difficult.

The account may have been opened by a real person, passed KYC, and behaved normally for a while. The fraud typically starts later, after the account or credentials are handed over.

Location allows you to see when the account’s physical behavior suddenly changes.

A new device may start accessing the account from places that don’t match the customer’s history. It may never appear near the address connected to the account. Or several mule accounts may begin operating from the same physical environment.

We saw this clearly in one case.

A bank had identified 11 mule accounts on its platform. With precise location intelligence, we uncovered more than 2,900 connected accounts linked to 28 devices operating from the same location.

Connecting devices after they reset

A factory reset can be enough to make a known device look new again. In our data, 70% of devices used for fraud go through a factory reset each week.

Once the device returns, the app may have been reinstalled, its identifiers may have changed, and the link to previous fraud may be gone.

Precise location intelligence can preserve that connection.

If the “new” device starts operating from the same apartment, house, or physical environment as a device you blocked before, that becomes a strong risk signal.

We saw this during a proof of value with a bank that was using a leading device fingerprinting vendor. One fraudster was using automation to factory-reset the same iOS device every 30 seconds.

Their vendor assigned 498 separate device IDs across those sessions. Incognia recognized the same physical device being repeatedly reset from the same location.

Fraudsters can reset a device. They cannot easily reset the physical world around it.

Identifying coordinated fraud more accurately

Sometimes a group of accounts seem connected, but the evidence is too weak to act on.

Banks may look at ZIP codes, demographic patterns, or other similarities to find possible links. Those are broad indicators, and relying on them can create false positives or introduce regulatory risk.

They may suggest a connection, but they don’t reliably establish that the accounts are part of the same operation.

Precise location intelligence gives you something more concrete.

You can actually see when multiple accounts are being operated from the same apartment, when devices tied to confirmed fraud keep returning to the same environment, or when separate accounts share the same physical pattern.

That gives you a more defensible basis for action because the connection comes from observed activity rather than an assumption about a broader population.

Here’s one example of what coordinated fraud activity can look like:

In a separate recent case, we found roughly 200 devices operating from the same apartment and connected to 4,500 bank accounts.

Viewed individually, those accounts looked unrelated. The shared physical environment revealed the operation behind them.

Approving more legitimate customers

Many fraud teams are also being asked to reduce unnecessary friction without taking on more risk.

When your signals don’t give you enough confidence, the usual response is more friction.

More manual reviews. More identity checks. More OTPs, selfies, and step-up challenges.

In some cases, the customer is rejected altogether.

A lot of the banks we speak with are approving less than half of the applications they receive right now because of this.

Precise location intelligence helps you make a more confident decision about whether the activity is legitimate.

Is the customer where they claim to be? Does the device’s physical behavior match what you know about them? Is the surrounding environment trusted, or has it been connected to fraud before?

When those signals point in the right direction, you can verify more legitimate customers quietly in the background.

For one customer, adding location increased onboarding conversion by more than 70%, allowing far more good customers to open accounts without unnecessary friction.

A strong fraud signal should help you identify bad activity and give you more confidence in the customers you want to approve.

What makes precise location different

Most banks already use some form of geolocation, usually an IP address or GPS. That’s not what I’m talking about here.

Precise location intelligence goes much further than that. It doesn’t rely on a single coordinate or a one-time location claim.

Instead, it combines multiple signals from the device and its surrounding environment to understand where the device is actually operating, whether the data has been manipulated, and whether that behavior makes sense for the customer behind the account.

Apartment-level precision makes location actionable

Traditional geolocation may place a device within a neighborhood, a general area, or somewhere inside a large apartment building.

Precise location intelligence combines signals like Wi-Fi, Bluetooth, cellular information, compass data, and more to understand the device’s physical environment.

That allows us to distinguish between devices operating from separate apartments in the same building, with accuracy down to 9 feet.

For banks, that level of accuracy supports more confident decisions with fewer false positives.

For example, instead of blocking an entire apartment building because of one bad actor, you can act on the one specific user or device associated with the fraud.

Multiple signals make manipulation harder

An IP address can be changed with a VPN or proxy. GPS can be manipulated through developer settings, spoofing apps, or app tampering.

A fraudster may be able to spoof one coordinate or change an IP address. But since precise location relies on multiple signals, faking all of them consistently and at once is much harder, especially at scale.

Location behavior provides continuity over time

Location becomes even more useful over time.

It can show whether a device consistently appears in a customer’s trusted locations and whether its physical behavior continues to match the history of the account.

That continuity becomes especially useful after a factory reset. The device identifier may disappear, but the physical device can still be associated with the same apartment, house, or operating environment connected to earlier fraud.

We’ve seen this translate into better detection.

In one recent case, adding location increased fraud detection by 50%. In another, it reduced false negatives by 70%.

Spoofing one coordinate is relatively easy. Reproducing where a real customer lives, works, and moves over time is much harder and more expensive.

The signal that can’t be faked at scale

You need to be able to recognize the same customer, device, or fraud operation even after the credentials change, the device is reset, or the identifiers disappear.

Most identity verification, authentication, and fraud prevention signals rely on a point-in-time check. Location behavior reflects the user’s history, which is much harder to manufacture or spoof at scale.

Precise location intelligence gives you a way to preserve that connection through physical behavior.

As fraudsters get better at manipulating digital signals, the real-world behavior behind an account becomes harder to ignore.

That’s where I expect location to matter most over the next few years. It gives you a signal that is much harder for fraudsters to manufacture repeatedly and at scale.

What are the biggest fraud challenges you’re dealing with right now? Reply and let me know. I’m curious where location could make the biggest difference.