Systems and methods for identifying a data compromise source
Abstract
A compromise detection computing device is configured to receive transaction data associated with a set of transactions performed at a plurality of merchants, each transaction conducted using a payment device, identify a first merchant, and generate a list of every payment device that was used to conduct a transaction at the first merchant. The compromise detection computing device is further configured to monitor subsequent transaction activity associated with each payment device on the list, and generate a fraud proxy score for each payment device based upon the activity. The compromise detection computing device is further configured to access fraud report records associated with any payment device on the list, generate an implication score for the first merchant based upon the fraud proxy score and the fraud report records, and, when the first implication score meets a first criteria, automatically transmit an alert message to a receiving party.
Claims
exact text as granted — not AI-modified1 . A compromise detection computing device comprising a processor in communication with a memory, the processor programmed to:
receive transaction data associated with a set of transactions performed at a plurality of merchants, each transaction of the set of transactions conducted using one of a plurality of payment devices; identify a first merchant of the plurality of merchants; generate a list of every payment device of the plurality of payment devices that was used to conduct one or more transactions of the set of transactions at the first merchant; monitor subsequent transaction activity associated with each payment device on the generated list; generate a fraud proxy score for each payment device on the generated list based upon the subsequent transaction activity; access one or more fraud report records associated with any payment device on the generated list; generate a first implication score for the first merchant based upon the generated fraud proxy score and the one or more fraud report records; and when the first implication score meets a first criteria indicating potential compromise of the first merchant, automatically transmit an alert message to at least one receiving party, the alert message notifying the receiving party of the potential compromise of the first merchant.
2 . The compromise detection computing device of claim 1 , wherein the alert message includes instructions causing a computing device of the receiving party to activate and notify the receiving party of the potential compromise of the first merchant.
3 . The compromise detection computing device of claim 1 , wherein the alert message includes instructions for the receiving party to block future transactions conducted at the first merchant.
4 . The compromise detection computing device of claim 1 , wherein the alert message includes instructions for the receiving party to impose an additional authentication process on future transactions conducted by any of the payment devices on the generated list.
5 . The compromise detection computing device of claim 1 , wherein the alert message includes instructions for the receiving party to block future transactions conducted by any of the payment devices on the generated list.
6 . The compromise detection computing device of claim 1 , wherein the alert message includes instructions for the receiving party to notify a user of each of the payment devices on the generated list of the potential compromise of the first merchant.
7 . The compromise detection computing device of claim 1 , wherein the processor is further programmed to generate the fraud proxy score of each payment device using at least one fraud model.
8 . The compromise detection computing device of claim 7 , wherein the processor is further programmed to update the at least one fraud model to include an updated fraud risk associated with the potential compromise of the first merchant based at least in part upon the first implication score.
9 . The compromise detection computing device of claim 1 , wherein the processor is further programmed to:
monitor the subsequent transaction activity associated with each payment device on the generated list for one or more predetermined intervals of time. generate an updated fraud proxy score for each payment device on the generated list after each one or more predetermined interval of time; access any new fraud report records associated with any payment device on the generated list after each one or more predetermined interval of time; and update the first implication score for the first merchant based upon the generated updated fraud proxy score and the new fraud report records.
10 . The compromise detection computing device of claim 1 , wherein the processor is further programmed to:
generate an inverse recommender score for one or more subsequent transactions initiated using one or more payment devices on the generated list; and generate the first implication score further based upon the inverse recommender score.
11 . A method for identifying a source of data compromise, the method implemented using a compromise detection computing device including a processor in communication with a memory, the method including:
receiving transaction data associated with a set of transactions performed at a plurality of merchants, each transaction of the set of transactions conducted using one of a plurality of payment devices; identifying a first merchant of the plurality of merchants; generating a list of every payment device of the plurality of payment devices that was used to conduct one or more transactions of the set of transactions at the first merchant; monitoring subsequent transaction activity associated with each payment device on the generated list; generating a fraud proxy score for each payment device on the generated list based upon the subsequent transaction activity; accessing one or more fraud report records associated with any payment device on the generated list; generating a first implication score for the first merchant based upon the generated fraud proxy score and the one or more fraud report records; and when the first implication score meets a first criteria indicating potential compromise of the first merchant, automatically transmitting an alert message to at least one receiving party, the alert message notifying the receiving party of the potential compromise of the first merchant.
12 . The method of claim 11 , further comprising generating the alert message to include instructions causing a computing device of the receiving party to activate and notify the receiving party of the potential compromise of the first merchant.
13 . The method of claim 11 , further comprising generating the alert message to include instructions for the receiving party to block future transactions conducted at the first merchant.
14 . The method of claim 11 , further comprising generating the alert message to include instructions for the receiving party to impose an additional authentication process on future transactions conducted by any of the payment devices on the generated list.
15 . The method of claim 11 , further comprising generating the alert message to include instructions for the receiving party to block future transactions conducted by any of the payment devices on the generated list.
16 . The method of claim 11 , further comprising generating the alert message to include instructions for the receiving party to notify a user of each of the payment devices on the generated list of the potential compromise of the first merchant.
17 . The method of claim 11 , wherein generating a fraud proxy score comprises generating the fraud proxy score of each payment device using at least one fraud model.
18 . The method of claim 17 further comprising updating the at least one fraud model to include an updated fraud risk associated with the potential compromise of the first merchant based at least in part upon the first implication score.
19 . The method of claim 11 further comprising:
monitoring the subsequent transaction activity associated with each payment device on the generated list for one or more predetermined intervals of time;
generating an updated fraud proxy score for each payment device on the generated list after each one or more predetermined interval of time;
accessing any new fraud report records associated with any payment device on the generated list after each one or more predetermined interval of time; and
updating the first implication score for the first merchant based upon the generated updated fraud proxy score and the new fraud report records.
20 . A non-transitory computer-readable storage medium having computer-executable instructions thereon, wherein when executed by a compromise detection computing device, the computer-executable instructions cause the compromise detection computing device to:
receive transaction data associated with a set of transactions performed at a plurality of merchants, each transaction of the set of transactions conducted using one of a plurality of payment devices; identify a first merchant of the plurality of merchants; generate a list of every payment device of the plurality of payment devices that was used to conduct one or more transactions of the set of transactions at the first merchant; monitor subsequent transaction activity associated with each payment device on the generated list; generate a fraud proxy score for each payment device on the generated list based upon the subsequent transaction activity; access one or more fraud report records associated with any payment device on the generated list; generate a first implication score for the first merchant based upon the generated fraud proxy score and the one or more fraud report records; and when the first implication score meets a first criteria indicating potential compromise of the first merchant, automatically transmit an alert message to at least one receiving party, the alert message notifying the receiving party of the potential compromise of the first merchant.Join the waitlist — get patent alerts
Track US2019130404A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.