Skip to main content

Fraud Attack Radar

Fraud Attack Radar: Set Up and Use

Fraud Attack Radar (FAR) is an Alloy monitoring model that detects coordinated, high-velocity fraud attacks across onboarding activity. Unlike individual applicant scoring, FAR analyzes patterns across a workflow and alerts you when activity deviates significantly from expected behavior.

Before you begin

Fraud Attack Radar (FAR) must be added to your Alloy dashboard first. If this entitlement is not available for your dashboard, reach out to your Customer Success Manager or Account Executive.

Turn on Fraud Attack Radar

Before you can see the option to turn on FAR, it must be available for your account and your role must have permissions enabled to manage FAR.

If these are available, the steps are:

  1. Sign in to the Alloy Dashboard.

  2. Go to Workflows.

  3. Find the workflow you want to monitor.

  4. Click the three-dot menu (⋮) on the right side of the workflow.

  5. Select Fraud Attack Radar.

  6. In the configuration window, enable FAR.

  7. Select the roles that should receive FAR alerts.

  8. Save your configuration.

The workflow must have sufficient historical onboarding activity for the model to establish a baseline. Alloy recommends at least two months of historical data.

FAR notifications can be sent by email to designated roles, and alerts are also displayed in the Alloy Dashboard.

Training and activation

After FAR is enabled on a Workflow, the model begins preparing a workflow-specific baseline. The initial training period may take approximately one hour in the product setup flow; clients should also have sufficient historical onboarding data—typically at least two months—for reliable anomaly detection.

The dashboard indicates when FAR is ready and begins displaying scores and indicators once scoring starts.

How Fraud Attack Radar works

FAR evaluates aggregate activity across a workflow rather than determining whether an individual applicant is fraudulent. It combines time-series analysis and anomaly detection to identify unusual changes from the workflow’s historical patterns.

The model may consider signals such as:

  • Application and evaluation volume

  • Denial volume

  • Fraud-related tags and outcomes

  • Fraud vendor scores

  • Reuse or velocity of personally identifiable information, such as email addresses, phone numbers, SSNs, licenses, IP addresses, or states

  • Unusual email-domain or state distributions

FAR is trained using client-specific onboarding data and may be recalibrated when monitoring identifies changes in data patterns or model performance.

Only designated roles configured to receive a FAR alert will be notified. A notification is sent when Alloy has detected unusual activity that may indicate a coordinated fraud attempt that differed significantly from your workflow’s historical baseline. The alert does not mean that every application is fraudulent. Instead, it indicates that activity across multiple applications—such as repeated PII, unusual application or denial volume, abnormal geographic or email-domain patterns, or elevated fraud-related scores—resembled a potential high-velocity fraud attack and needs further investigation. Your fraud or risk team should review every FAR alert and decide whether the activity represents a true attack.

Scores and alerts

FAR runs approximately every 30 minutes and produces a confidence score from 0 to 1. An alert is generated when the score exceeds 0.8.

The FAR dashboard provides:

  • The workflow’s fraud attack score

  • Leading indicators contributing to the score

  • The time period associated with the suspected attack

  • Contributing entities and applications

  • Explainable information to support investigation and response

There is no fixed number of applications that automatically triggers an alert. FAR evaluates whether the volume and characteristics of activity are statistically unusual for the workflow’s baseline. The alert threshold and detection logic are not configurable at the client level.

What to do when you receive an alert

  1. Open the FAR alert in the Alloy Dashboard.

  2. Review the leading indicators and attack timeframe.

  3. Review the contributing entities and applications.

  4. Filter the Application Queue using the relevant timeframe and indicators.

  5. Investigate the affected applications and confirm whether the activity represents a true attack.

  6. Apply appropriate controls, such as increased identity verification, document verification, multifactor authentication, or a preconfigured safety workflow.

  7. Review and update your workflow policies to address the leading indicators.

Alloy may provide near-term containment recommendations and longer-term policy recommendations.

Important limitations

  • FAR detects coordinated patterns at the workflow level; it does not assign an individual-level fraud risk score. Fraud Signal is the solution for evaluating an individual applicant or customer using onboarding, account, transaction, login, and other behavioral signals.

  • FAR alerts are intended to prompt human review and investigation, not automated decisioning.

  • If required onboarding data is unavailable or stale, FAR may not run and alerts may not be generated.

  • If FAR is unavailable, your existing onboarding workflow continues operating as configured; FAR does not change workflow behavior automatically.

Related resources

Did this answer your question?