Scams, Authorised Push Payment (APP) fraud, and social engineering have become some of the largest sources of consumer fraud losses globally. Unlike traditional Account Takeover (ATO) attacks, these frauds often involve legitimate customers using their own trusted devices, credentials and authentication methods, from trusted locations. As a result, many institutions are shifting their focus from transaction monitoring towards collecting risk intelligence earlier in the customer journey. The trend to collect early risk intelligence is further stimulated by fraud attacks that combine social engineering with device compromise. A common example is a bank impersonation scam where a customer is persuaded to install a Remote Access Tool (RAT). The fraudster then prepares or executes payment activity remotely while obtaining authentication codes through phone calls, chat messages or fake banking pages. These attacks blur the traditional boundaries between scams, account takeover (ATO) and device takeover (DTO). Modern fraud prevention relies increasingly on signals collected during mobile and web banking sessions, before a payment is initiated. These signals provide insight into the security of the device, the behaviour of the user and the likelihood of fraud or manipulation. They broadly fall into two categories: deterministic and probabilistic signals. Deterministic signals are factual observations that indicate the presence of a specific technical condition. Examples include: These indicators are generally binary in nature: a RAT is either present or absent, a device is either on a call or it is not. Because of this certainty, deterministic signals are particularly effective at identifying technical compromise and device-driven fraud. Probabilistic signals assess likelihood rather than certainty. Instead of identifying a technical artefact, they evaluate whether a customer's behaviour is consistent with their historical patterns or resembles known fraud activity. Examples include: These signals are well suited to detecting scams and social engineering attacks because such frauds often target the human rather than the device. A customer may be using a trusted device but still be acting under influence or manipulation. And these low-tech attacks are notoriously difficult to detect, requiring high-tech innovation. The most effective fraud detection strategies combine both signal types. Device intelligence provides high-confidence evidence of technical risk. Behavioural analytics provides additional context around customer intent and possible manipulation. A detection engine can therefore combine a deterministic signal, such as the presence of a RAT, with probabilistic indicators such as a significant identity mismatch or a high similarity score to a known scam modus operandi. In practice, deterministic signals often act as strong standalone indicators, while probabilistic signals contribute weighted risk scores. For example: Correlating these signals provides a more complete view of risk than any individual signal in isolation. As fraud increasingly shifts towards scams, social engineering and hybrid attack models, transaction monitoring alone is no longer sufficient. Effective fraud prevention requires visibility into the customer journey before a payment is authorised. Deterministic signals provide factual evidence of device compromise or technical risk. Probabilistic signals provide insight into behavioural anomalies, manipulation and potential social engineering. Together, they create actionable pre-transaction intelligence that helps detect scams, account takeover and device takeover earlier in the attack chain. The result is a more accurate understanding of risk, improved fraud detection performance and a stronger ability to intervene before customer losses occur.Using Deterministic and Probabilistic Pre-Transaction Intelligence
Pre-Transaction Intelligence
Deterministic Signals
Probabilistic Signals
Turning Signals into Detection Intelligence
Conclusion