Skip to content

Fraud & Abuse

Fraud and abuse-feed presence: phishing, scam, fake-shop, brand-impersonation. Each fires with named evidence and a 3-question analyst Q&A trail.

About

What Fraud & Abuse captures

Fraud and abuse-feed presence: phishing, scam, fake-shop, brand-impersonation. Tier-1 SOC analysts use them to cut triage time on suspicious threat intelligence feed behavior; CTI teams pivot from them to the broader campaign graph.

Browse

3 signals in Fraud & Abuse

Each row opens a leaf page with the signal's direction, named evidence, and 3-question Q&A trail. Use them as audit anchors when a verdict surfaces this subgroup.

Verdict scenarios

How Fraud & Abuse shapes the call

Three real-world situations where Fraud & Abuse evidence dominates the decision. Verdict and explanation are how VerdictIQ would frame the outcome to an analyst, not raw signal slugs.

High riskVERDICT · BLOCK
The situation

A domain present on multiple fraud-abuse feeds in the last 14 days, with at least one citing brand impersonation.

VerdictIQ explains

Decline. Multiple recent fraud feeds converging on the same asset is high-confidence external signal. Block until the feeds clear it.

Medium riskVERDICT · REVIEW
The situation

A domain with one stale fraud-feed hit from over six months ago and no recent reports.

VerdictIQ explains

Send to analyst review. One stale hit isn't enough to block but warrants confirmation that the asset has changed behavior.

Low riskVERDICT · ALLOW
The situation

A domain with no presence on any fraud or abuse feed and a clean reporting history.

VerdictIQ explains

Allow. The fraud surface is clean. No abuse-side reason to delay.

Sibling subgroups

Other subgroups in Threat Intelligence Feed

4 more subgroups in this group, each bundling signals that share a different mechanism. Tap one to inspect its signal names.

See subgroup detail
See subgroup detail
See subgroup detail
See subgroup detail

See Fraud & Abuse signals fire on your data

Free tier: 100 IOCs/day, LLM layer included.