Here is what a fraud analyst at an Indian payment aggregator found during a routine review.
Forty-three merchants. Separate business names, GST registrations, KYC files. Each one clean in isolation. All forty-three connected through a single mobile number buried four relationships deep in their beneficial ownership chains - used to seed every entity in the network.
The legacy system never flagged any of them. The fraud only became visible when an analyst drew the connections by hand. Three days. A whiteboard. Rs 2.3 crore already settled.
That gap - between what legacy detection sees and what actually happened - is the subject of this article.
Legacy fraud detection was built for a different threat model.
Rules engines, velocity checks, threshold alerts - this architecture was designed to catch individual bad actors doing individually suspicious things. A stolen card used too many times. A transaction exceeding a preset limit. A new account transacting at unusual volume. For that threat, these systems still work.
The problem is that organised fraud does not look like individual suspicious behaviour. It looks like many individually normal behaviours that are collectively coordinated. And legacy systems have no mechanism - architectural or analytical - for seeing the collective.
This is not a tuning problem. You cannot fix it by adjusting thresholds or adding rules. The limitation is structural. Rules-based systems evaluate entities and transactions one at a time. Fraud rings operate across entities and transactions simultaneously. The detection unit of analysis and the fraud unit of analysis are fundamentally different things. That gap is where fraud rings live.
Fraud rings in the Indian payments ecosystem are not loosely affiliated individuals. They are coordinated networks - built deliberately to defeat point-in-time entity review.
In every case, the fraud is invisible at the entity level. It is only visible at the network level.
A rules engine evaluates one entity or one transaction at a time against a set of conditional statements. Fraud rings are specifically engineered so that no single entity or transaction triggers any individual condition. Each accommodation merchant processes volumes below the threshold. Each mule account maintains velocity within normal parameters. Each KYC file is internally consistent.
The rules never fire. The ring operates freely.
The only place the fraud is visible - in the connections, the shared attributes, the network topology - is precisely the place the rules engine does not look. This cannot be patched. It is a consequence of the architecture.
A graph maps entities as nodes - merchants, customers, accounts, devices, phone numbers, addresses - and relationships between them as edges. Graph intelligence builds and continuously updates this map across an entire portfolio, then asks a different question than any rules engine can.
A rules engine asks: is this entity suspicious? Graph intelligence asks: is this entity connected to other entities in patterns consistent with known fraud network structures? These are different analytical operations. Only the second can identify a fraud ring.
When a new merchant is onboarded, graph intelligence maps their identity attributes against the existing network. If any attribute connects - directly or through intermediate nodes - to previously flagged entities, the connection surfaces immediately. The forty-three-merchant ring described above would not have required three days and a whiteboard. The shared mobile number would have been visible the moment the second merchant was onboarded.
UPI's transaction velocity makes detection latency measured in hours too slow to prevent fraudulent settlements. The PA merchant onboarding model means accommodation networks operate within the PA's own portfolio - the PA is not just a channel for the fraud, it is the infrastructure. RBI's Master Directions on Payment Aggregators require ongoing merchant monitoring, not point-in-time KYC review. Graph intelligence is the mechanism through which that obligation can be met operationally. Loan app fraud networks, investment scam payment channels, and impersonation fraud operations are all specifically engineered to exploit entity-level detection. Legacy systems were not designed for this environment.
Verafye is built around the same graph-native intelligence architecture described above. When a new merchant, sub-merchant, or account is onboarded, Verafye maps its identity attributes - device fingerprints, phone numbers, beneficial ownership connections, beneficiary accounts - against the existing network across the full portfolio.
If any attribute connects - directly or through intermediate nodes - to previously flagged entities, the connection surfaces at the point of onboarding, not after losses have settled. The forty-three-merchant ring from the opening of this article would have surfaced differently with Verafye: the shared mobile number four relationships deep would have appeared as a connection the moment the second merchant was onboarded - not after an analyst spent three days with a whiteboard.
The investigation case Verafye produces is already structured: the entity connections, the path between them, the shared attributes that reveal the network, and the full audit trail from detection to decision. For payment aggregators operating under RBI's ongoing monitoring requirements, graph-native intelligence is not a supplement to the compliance programme. It is the mechanism through which ongoing merchant monitoring becomes operationally possible at scale - not just at the point of onboarding but continuously, as the network evolves.
To see whether fraud ring connections currently exist undetected in your merchant portfolio, the Verafye Risk Shadowing Review assesses your signal coverage with no commitment required.
Legacy detection catches the fraudster who makes a mistake at the entity level.
Graph intelligence catches the fraud ring that makes no individual mistake - but whose network structure, mapped completely, is unmistakably organised for a purpose that has nothing to do with legitimate commerce.
The fraud growing in India is the second kind. Detection systems built only for the first kind are not keeping pace. And the cost of that gap is measured in settlement cycles, regulatory observations, and the consequence of having been the infrastructure through which a coordinated network operated - invisibly, for months.
The whiteboard and the three days are not a strategy. The graph is.
Akash
Head of Growth & Marketing, Verafye
Verafye is a graph-native network risk intelligence platform built for lean fraud, AML, and risk teams at payment aggregators, PSPs, MSBs, and regulated fintech platforms.
See where your monitoring stack has blind spots
The Risk Shadowing Review maps your current coverage against relationship-level gaps.