UK mobile operator reduces fraud by 69% with Sardine

A major UK mobile operator needed to modernize its fraud stack without adding operational weight. Its fraud operations team had been running the same core process for over a decade, and the tooling around it had evolved in name only.
The challenge: Friction-heavy decisioning with no safe path to iteration
The operator's fraud environment covered two distinct decisioning surfaces: an automated credit strategy for device finance applications and a manual review queue for suspect orders flagged before delivery. The automated side handled volume; the manual side handled judgment. Neither had the tooling to do either job well.
On the automated side, all online applications for upgrades, additional lines, and new orders were subject to fraud screening. The credit team needed high confidence in the model's output before it could act on signals automatically. Without that confidence, every rule change required careful coordination and carried risk.
On the manual side, the offshore fraud review team was working through suspect orders using tools that offered little analytical depth. The standard process was well-established, but the signal quality supporting it was inconsistent. Reviewing sessions in detail, linking exports to fraud accounts, and backtesting potential new rules were all either impossible or impractical at scale.
A secondary constraint was data access. Export limits on prior tooling capped the volume of records that analysts could pull at once, making it difficult to run meaningful fraud pattern analysis across large cohorts. Teams could identify individual cases, but struggled to surface systemic trends.
The fraud program was running, but what it lacked was any controlled mechanism for improving without accepting more operational risk.
The solution: Prediction confidence and a safe iteration loop
The operator deployed Sardine across both decisioning surfaces in Spring 2025. The automated credit strategy routes all online device finance applications through Sardine, with any application triggering a "high" rule output declined automatically. Mobile broadband and SIM-only applications are sampled at 10% through the same pipeline. The offline fraud review queue runs separately: every suspect order flagged by the fraud ops team is checked against Sardine signals before a disposition decision is made.
The credit team's adoption of the automated output was faster than expected. Sardine's accuracy was described internally as "very predictive," with the credit team treating the signal as a reliable input rather than one factor among many. That confidence level reduced the coordination overhead that had historically slowed rule deployment.
For iteration, shadow rules became the primary mechanism. The fraud team uses shadow rules to trial new logic against live traffic without impacting production. Combined with feature backtesting on shadow rules and field-level frequency analysis in the Feature Details view, the team developed a structured method for evaluating signals before committing to them.
The result? A genuinely controlled iteration loop rather than a choice between accepting risk and standing still.
Operationally, two changes had outsized impact:
- The increase in export limits of records per pull directly unblocked analysis workflows that were previously bottlenecked. The daily automated extract became a fixed part of the team's rhythm, replacing a manual step that had required recurring effort to maintain.
- The operator's fraud ops team also noted that rule changes were meaningfully easier to execute than on prior platforms. The comparison was explicit: the team had described other platforms as difficult to work with at the rule-change level. With Sardine, the fraud team can roll in new rules and updates without involving credit strategy at all, which shortens the feedback loop between detection and deployment.
The results: 69% reduction in losses and a measurable deterrent effect
Between Q1 and Q4 2025, the operator recorded a 69% reduction in fraud losses. The reduction in fraud attempts tracked at approximately the same rate, a pattern consistent with a deterrent effect: fraudsters recognized the operator had become a harder target and deprioritized it accordingly. Detection improvement and attack volume reduction are typically separate outcomes; recording both at similar magnitude is a stronger composite result.
Two specific capabilities earned unprompted positive feedback from the team. Documentation was described as "really good" and easily searchable directly from the UI, which reduced friction during onboarding and ongoing training.
Monthly release notes were cited as a valued signal of active product development. Both are infrastructure-level details, but they matter to teams that need to trust a tool enough to build their daily process around it.
Today, the team's operational process is dramatically slimmed down, with limited FTE impact and faster training cycles. Knowing that only high-risk rule outputs affect credit decisioning has given the fraud team room to experiment in the fraud ops layer, without coordinating with credit for every change. After more than a decade running the same process around tooling that couldn't keep up, the team now shapes its own rules day to day, without waiting on a vendor or a sign-off from credit to try the next idea.



