US2021182954A1PendingUtilityA1

System and method for detecting account compromises

Assignee: WELLS FARGO BANK NAPriority: Jul 27, 2007Filed: Dec 6, 2013Published: Jun 17, 2021
Est. expiryJul 27, 2027(~1 yrs left)· nominal 20-yr term from priority
Inventors:Shuo-Ting Yan
G06Q 20/4016G06Q 40/00G06Q 40/02G06Q 20/405
67
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method of identifying a point of compromise includes accessing data stored in a data storage system, the data being associated with a plurality of identified at-risk accounts, identifying a plurality of common points of transaction, each of the plurality of common points of transaction being associated with a minimum number of the plurality of identified at-risk accounts, and identifying a point of compromise from the plurality of common points of transaction based on (i) the number of the identified at-risk accounts involved in transactions executed via each common point of transaction during a time period, and (ii) a total number of accounts involved in transactions executed via the common point of transaction during the time period.

Claims

exact text as granted — not AI-modified
1 . A method of mitigating the impact of an account compromise, comprising:
 accessing data stored in a data storage system, the data being associated with a plurality of accounts including both compromised and non-compromised accounts associated with a single financial institution;   identifying a plurality of common points of transaction using computer implemented compromise detection logic, each of the plurality of common points of transaction being associated with a threshold minimum number of a plurality of identified at-risk accounts associated with a single financial institution, wherein at least one of the identified at-risk accounts is identified based on a received fraud claim and wherein at least one of the identified at-risk accounts is identified by analyzing transaction history data to identify clusters of potentially fraudulent transactions, the clusters of potentially fraudulent transactions being identified based on thresholds of (i) a minimum number of transactions executed via a single transaction location, (ii) a minimum currency amount for each of the minimum number of transactions, and (iii) a maximum period of time during which the minimum number of transactions are executed;   identifying a point of compromise from the plurality of common points of transaction using the computer implemented compromise detection logic based on (i) the number of the identified at-risk accounts involved in transactions executed via each common point of transaction during a time period, and (ii) a total number of accounts involved in transactions executed via the common point of transaction during the time period;   analyzing daily comparison data of the point of compromise using the computer implemented point of compromise detection logic and indicated trends in fraudulent activity, wherein the daily comparison data comprises a transaction channel, a transaction location, a merchant name or a merchant ID, the number of identified at-risk accounts, an average transaction amount for the at-risk accounts, and an at-risk percentage;   identifying an exposure time period for the point of compromise and identifying additional accounts that are identified at-risk accounts, the exposure time period being selected from a plurality of different time periods based on (i) satisfying a desired capture rate, the desired capture rate being user configurable, wherein the user is provided with an interactive user interface that permits the user to view the costs and benefits of adjusting the capture rate to different levels, and representing a desired percentage of the identified at-risk accounts involved in transactions executed via the point of compromise during each of the plurality of time periods, and (ii) minimizing a total number of accounts involved in transactions executed via the point of compromise during each of the plurality of time periods, wherein the additional at-risk accounts are identified based on being involved in at least one transaction executed via the common point of transaction during the exposure time period;   generating a notification identifying the total number of accounts involved in transactions executed via the point of compromise during the exposure time period;   automatically deactivating one or more of the identified at-risk accounts using risk mitigation logic based on the point of compromise and the plurality of accounts included in the total number of accounts involved in transactions executed via the point of compromise during the exposure time period; and   providing a notification to account holders associated with the identified at-risk accounts.   
     
     
         2 . (canceled) 
     
     
         3 . The method of  claim 1 , wherein the single transaction location is an automated teller machine (ATM). 
     
     
         4 . The method of  claim 1 , wherein the thresholds are configurable by a user. 
     
     
         5 . The method of  claim 1 , wherein identifying the point of compromise includes comparing a ratio of (i) the number of the identified at-risk accounts involved in transactions executed via each common point of transaction during a time period to (ii) the total number of accounts involved in transactions executed via the common point of transaction during the time period to a threshold ratio. 
     
     
         6 . The method of  claim 5 , wherein the point of compromise includes any of the common points of transaction where the ratio is greater than the threshold ratio. 
     
     
         7 . (canceled) 
     
     
         8 . The method of  claim 1 , wherein the notification provided to the account holders associated with the one or more identified at-risk accounts includes a name and a location of the point of compromise. 
     
     
         9 . A method of mitigating the impact of potentially fraudulent transactions, comprising:
 receiving a reported-fraud claim from a customer associated with a first financial account;   accessing, by a computer programmed with logic, transaction data stored in a data storage system, the transaction data being associated with a plurality of financial accounts and a plurality of transaction locations, wherein the transaction data is further associated with a single financial institution;   analyzing, by the computer, the transaction data associated with the plurality of financial accounts and the plurality of transaction locations to identify at least one group of transactions based on a threshold of a maximum time period during which a minimum number of transactions are executed via a single transaction location, the at least one group of transactions including the first financial account;   providing an output using the computer including data associated with the group of transactions;   varying the threshold of the maximum time period based on data regarding the plurality of transactions, including at least one of a number of transactions executed via the single transaction location and a minimum dollar amount for each of the transactions executed via the single transaction location, wherein varying the threshold of the maximum time period maximizes identification of potentially fraudulent transactions and satisfies a desired capture rate, the desired capture rate being user configurable, wherein the user is provided with an interactive user interface that permits the user to view the costs and benefits of adjusting the capture rate to different levels;   identifying a number of at-risk accounts associated with the at least one group of transactions and automatically deactivating one or more of the at-risk accounts based on risk mitigation logic; and   providing a notification to account holders of the at-risk accounts associated with the at least one group of transaction.   
     
     
         10 . The method of  claim 9 , wherein the single transaction location is an automated teller machine. 
     
     
         11 . The method of  claim 10 , wherein accessing the transaction data includes accessing the transaction data for a single day. 
     
     
         12 . The method of  claim 10 , further comprising identifying a point of compromise based on analyzing accounts associated with the at least one group of transactions. 
     
     
         13 . (canceled) 
     
     
         14 . (canceled) 
     
     
         15 . A method of mitigating the impact of an account compromise, comprising:
 accessing, by a computer programmed with logic, data stored in a data storage system, the data being associated with a plurality of identified at-risk accounts and a single financial institution;   identifying a plurality of common points of transaction, each of the plurality of common points of transaction being associated with a minimum number of the plurality of identified at-risk accounts, wherein at least one account of the plurality of identified at-risk accounts is associated with a reported fraud claim and wherein at least one of the identified at-risk accounts is identified by analyzing transaction history data to identify clusters of potentially fraudulent transactions, the clusters of potentially fraudulent transactions being identified based on thresholds of (i) a minimum number of transactions executed via a single transaction location, (ii) a minimum currency amount for each of the minimum number of transactions, and (iii) a maximum period of time during which the minimum number of transactions are executed;   identifying a point of compromise from the plurality of common points of transaction based on (i) the number of the identified at-risk accounts involved in transactions executed via each common point of transaction during a time period, wherein the time period satisfies a desired capture rate, the desired capture rate being user configurable, wherein the user is provided with an interactive user interface that permits the user to view the costs and benefits of adjusting the capture rate to different levels, and (ii) a total number of accounts involved in transactions executed via the common point of transaction during the time period;   analyzing daily comparison data of the point of compromise using the computer implemented point of compromise detection logic and indicated trends in fraudulent activity, wherein the daily comparison data comprises a transaction channel, a transaction location, a merchant name or a merchant ID, the number of identified at-risk accounts, an average transaction amount for the at-risk accounts, and an at-risk percentage;   automatically deactivating one or more of the at-risk accounts involved in transactions at the point of compromise based on risk mitigation logic; and   notifying account holders associated with the at-risk accounts of the point of compromise.   
     
     
         16 . (canceled) 
     
     
         17 . (canceled) 
     
     
         18 . (canceled) 
     
     
         19 . The method of  claim 15 , wherein the thresholds are configurable by a user. 
     
     
         20 . The method of  claim 15 , wherein identifying the point of compromise includes comparing the ratio of (i) the number of the identified at-risk accounts involved in transactions executed via each common point of transaction during a time period to (ii) the total number of accounts involved in transactions executed via the common point of transaction during the time period to a threshold ratio.

Join the waitlist — get patent alerts

Track US2021182954A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.