Organized fraud groups use multiple accounts, devices and identities to obfuscate their actions, making it difficult to detect patterns when looking at transactions or behavior in isolation. Network and link analysis fills this gap by mapping the connections between individuals, accounts and activity, revealing associations between seemingly disparate data points that would otherwise remain undetected.
Investigators use graph analysis to visualize how money, data or logins flow through a network and social network analysis to expose clusters of coordinated activity that may point to collusion. Link analysis then connects identifiers such as email addresses, phone numbers, IP addresses and social media profiles into a single intelligence picture.
In anti-money laundering (AML) casework, these graph analytics surface mule account networks and layered transactions that transaction-level scoring cannot see. For the chart-building methodology, see the guide to using link analysis in investigations.
How investigators detect collusion rings and account linking fraud
Collusion rings and account linking fraud surface when platforms connect identifiers that fraudsters try to keep separate. Investigators detect collusion rings by linking accounts that share devices, IP addresses, payment instruments, phone numbers or shipping addresses, then scoring those clusters for coordinated behavior such as synchronized logins, circular refunds or review manipulation.
Device fingerprinting ties multiple personas back to one machine even when names and emails differ. Graph analysis then exposes the ring structure: a handful of hub accounts connected to dozens of disposable ones.
New-account fraud, a staple of ring activity, jumped 31 percent in 2025 to 5.4 million U.S. victims, according to Javelin Strategy and Research (2026).
The scale of coordinated fraud is why graph-based methods now anchor serious programs:
“We are currently in the midst of a full-blown financial crime crisis, powered by criminal networks that are leveraging AI to super-charge scam playbooks and operating with the scale and coordination of multinational corporations.”
– Stephanie Champion, Executive Vice President and Head of Nasdaq Verafin. Nasdaq press release, March 2026
Networks organized like corporations leave corporate-scale link trails. That is the surface network analysis attacks.
ShadowDragon’s suite of open-source intelligence (OSINT) tools gives fraud investigators graph analytics, link analysis and case-ready reporting inside one platform. Horizon® Identity resolves disparate identifiers into real-world identity profiles for rapid triage. SocialNet® extracts connections from hundreds of online sources to reveal social and digital associations, feeding link analysis charts that map fraud rings for AML case management. Horizon Monitor® continuously watches those networks and alerts investigators when new activity appears, supporting anti-money laundering investigations, cybercrime casework and threat intelligence operations end to end.
Together, these tools give investigators the ability to build a complete intelligence picture starting from a single data point, uncovering hidden relationships, tracking evolving threat actor activity, and connecting online behaviors to real-world entities. This end-to-end visibility not only shortens investigation timelines but also strengthens attribution, enabling teams to make faster, more confident decisions in fraud detection, cybercrime investigations, and threat intelligence operations all within one platform.
Applications and use cases
- Financial Services: AML (anti-money laundering) investigations uncovering layered transactions.
- Insurance: Detecting fraud rings staging multiple fake accidents.
- E-commerce: Linking synthetic identities across multiple fake accounts.
- Telecom: Tracing collusion between insiders and external fraudsters.
- Law Enforcement: Mapping criminal organizations using digital footprints.
Benefits
- Reveals large-scale, organized fraud schemes.
- Provides visual insights for investigators and compliance teams.
- Helps connect seemingly unrelated data points.
- Strengthens AML and regulatory compliance.
Challenges and limitations
- Requires advanced computing power for large datasets.
- Visualization can be complex with massive networks.
- Risk of false associations if data quality is poor.