Transaction Abuse – Castle
Transaction Abuse
Stop card testing before the transaction
Implement velocity checks to prevent a transaction attempt from reaching your payment processor in the first place.
Real-time blocking
Rules execute in milliseconds to block transaction abuse inline without noticeable delay.
Custom definitions
Define transaction abuse your way using advanced filtering and real-time velocity queries.
Granular analytics
Leverage BI-grade analytics to expose transaction abuse and fraud rings at scale.
Data enrichment
Enriched with device intelligence, risk scores, velocity metrics, and much more.
Segmentation
Define transaction abuse using custom logic
Castle lets you use advanced filtering, real-time velocity queries, and custom lists to segment out transaction abuse with high precision.
- deny
- Signals
includeBlocked Credit Card
or
Abuse Score
is > 90
and
Count of events Transaction by Device Fingerprint in the last 1 hour
is > 3
Automation
Action on transaction abuse in real-time
Rules execute in milliseconds and can be used to adapt the user experience based on risk in real-time.
- deny
- Abuse Score
is > 90
and
Disposable Email
is true
and
Count events Registration by Device Fingerprint in the last day
is > 3
or
Signals includeBlocked country
- Add User ID Warned Account Sharers
- Remove User ID Allowed Users
- Send webhook https://hooks.zapier.com/hooks/catch/4378238094/ch3dka
- Send to Slack #security-alerts
Real-time decisions
Assessments of data like user count per device or hourly failed logins executed in the blink of an eye.
Inline blocking
Initiate request blocks or step-up verifications anywhere in your app without disrupting the user experience.
Alerts & notifications
Ensure your team and users stay informed with triggered Slack notifications or webhooks.
Analytics
A holistic view of transaction abuse
Harness the power of BI-grade analytics to expose transaction abuse attacks and unravel fraud rings with precision.
Explore
1d Past day Save as
Event Name Registration Attempted, Login Attempted, …
and
Policy Action deny, challenge
Add filter Reset Events
3,159 Users
268 Devices
290 IPs
641
100500
| Timestamp | Policy | Event | User | Location | Connection | Device | Lists | Signals |
|---|---|---|---|---|---|---|---|---|
| Sat, Aug 8 07:59:08 | Challenge | Medium Abuse Score | 732496 | kevin.qfanjul@gmail.com | Spain33204, Gijón | Telefonica de Espana | 83.53.25.12 | Chrome on Windows 10 |
| 07:59:08 | Deny | Bad email | 471896 | oleg.kalinovskiy75@gmail.com | Ukraine29000, Khmelnytskyi | Kyivstar | 188.163.27.70 | Chrome on Windows 10 |
| 07:59:08 | Deny | [ScAuth] Attempted Login | 956616 | themba.ndlovu@gmail.com | South Africa8001, Cape Town | Starlink | 212.105.137.116 | Chrome on Windows 10 |
| 07:59:08 | Deny | Password Reset Policy | 849676 | priya.sharma@gmail.com | India400001, Mumbai | Jio | 157.49.135.38 | Chrome on Windows 10 |
| 07:59:08 | Challenge | Trusted Device Policy | 753516 | anton.volkov.2023@gmail.com | Russian Federation672000, Chita | Rostelecom | 95.189.74.74 | Chrome on Windows 10 |
Enrichment
All the data you need to pinpoint transaction abuse
Every interaction is enriched with comprehensive device intelligence, risk scores, location data, and much more.
- Battery State: Charging
- Emulator
- Rooted
- Device Fingerprint: mXZ29K2RRXeDDkdX
- Memory: Storage 256GB
Risk Scores
Out of the box risk scores for account abuse, account takeover, and bot abuse.
Velocities
Compute personalized signals based on real-time metrics like counts, sums, averages, and more.
Device fingerprinting
Persistent device identifiers resilient to storage resets and resistant to privacy plug-ins.
Bot detection
Identify bot actions via bot scores, headless indicators, or velocity and rate limit checks.