Link analysis maps the relationships among parties, accounts, devices, addresses, and transactions to surface hidden connections that single-transaction rules cannot see. A shared phone or address quietly tying together customers who look unrelated is exactly the kind of thread it exists to pull.
What is link analysis, in plain English?
Most detection rules look at one thing at a time: one transaction, one account, one customer. Link analysis looks at the connections between them. It maps how parties, accounts, devices, phone numbers, addresses, and transactions relate, so that customers who appear independent on their own records show up as connected once the shared attributes are drawn out.
The power is in exposing what isolated rules miss. A single mule account looks ordinary; but when several accounts share a device fingerprint, a phone number, or a physical address, link analysis reveals the ring behind them. It is the standard technique for uncovering mule networks, synthetic-identity clusters, and coordinated activity that no single-transaction rule could ever catch.
In an investigation, link analysis is what lets an analyst widen the frame, going from one subject out to the whole network around it, and it often supplies the justification for escalating a case from a single alert to something much larger.
How a link analysis widens a case
- Seed — Start from one subject. The analyst begins with a single flagged account or customer at the center of the map.
- Connect — Pull shared attributes. Devices, phones, addresses, counterparties, and beneficiaries are matched to find who else shares them.
- Weigh — Judge the strength of each link. Rare shared attributes signal a real connection; common ones like a public Wi-Fi may mean nothing. Weak linkCommon attributeA shared employer or public network connects many unrelated people; on its own it is noise.Strong linkRare attributeA shared device fingerprint or unusual address tying several accounts is a genuine signal worth pursuing.
- Act — Escalate the network. A confirmed cluster expands the investigation and justifies escalation beyond the original single alert.
What it looks like in practice
In practice
An analyst is handed one account flagged for receiving and quickly forwarding funds. On its own it is borderline. She runs a link analysis and finds this account shares a device fingerprint with eleven others, and four of those share a single residential address that matches none of the account holders' stated homes.
The shared device and the odd common address are rare enough to be meaningful, not coincidental. What began as one thin alert becomes a documented cluster of a dozen mule accounts operated from one setup. She escalates the whole network, and the map of shared attributes becomes the evidence that the accounts are coordinated rather than independent.
Why it matters to operators
Link analysis is how a program moves from chasing individual alerts to dismantling networks. Mule rings and synthetic-identity clusters are designed to look like a crowd of unrelated customers; the connections are the only thing that gives them away, and those connections are invisible to any rule that examines one account at a time. Finding them is often what justifies escalation and turns a minor case into a major one.
The discipline has one dominant pitfall: over-linking on weak attributes. Connecting customers because they share a common employer, a bank branch, or a public Wi-Fi network manufactures false relationships and floods analysts with noise. Strong links depend on attributes that are genuinely rare, like a specific device fingerprint or an unusual shared address. Getting the strength judgment right is the difference between exposing a real ring and drowning in coincidences.
Operator notes
- Rarity makes a link. A shared attribute is only meaningful if it is uncommon; rare device or address matches beat common ones every time.
- Beware over-linking. Connecting people by a shared employer or public network creates false ties and buries you in noise.
- Devices and addresses travel well. Fingerprints, phone numbers, and physical addresses often expose rings that money movement alone hides.
- Use it to justify escalation. A confirmed cluster is strong evidence that activity is coordinated, not coincidental.
- Confirm before you conclude. A link suggests a connection; corroborate with behavior before treating a cluster as a ring.
Quick questions
How is link analysis different from network analysis?
Link analysis focuses on identifying the connections between entities, often to widen a single case. Network analysis studies the whole connected structure as a graph to find coordinated behavior across it. Link analysis is frequently the first step that network analysis then builds on.
What attributes make the strongest links?
Rare, hard-to-share ones: a specific device fingerprint, an unusual physical address, a reused phone number, or a common beneficiary. Attributes that many unrelated people naturally share, like a big employer or public Wi-Fi, make weak links.
What is over-linking?
Connecting entities on weak, common shared attributes so that unrelated customers appear related. It generates false connections and floods analysts with noise, undermining the value of the technique. Avoiding it means insisting on rare, meaningful links.
What typologies does it expose best?
Mule networks, synthetic-identity clusters, and other coordinated activity where many accounts are secretly operated together. These are precisely the schemes that single-transaction rules cannot detect.
Can a single link justify action?
Rarely on its own. A strong link is a lead, not proof. It should be corroborated with behavior or additional connections before it drives escalation or a filing.
Go deeper
- FinCEN ↗ — The US financial intelligence unit. Bank Secrecy Act rules, advisories, and SAR and CTR guidance.
- FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.

