SardineCon SF/2026

Learn More
Device & behavioral4 分で読めます

Collusionとは?

SUBSCRIBE

Collusion is two or more parties secretly working together to commit fraud, where each participant can look perfectly legitimate on their own. Because no single account looks wrong, collusion hides from account-level controls and surfaces mainly through link and network analysis of the relationships between parties.

What is collusion, in plain English?

Collusion is fraud committed by agreement between parties rather than by one actor against a victim. A merchant and a cardholder can conspire to run fake transactions and split the proceeds. An employee and an outside customer can coordinate to move goods or credits improperly. A ring can share the roles of a scheme so that no one person's activity crosses a threshold. The defining feature is that the parties are not adversaries; they are partners hiding a shared intent.

What makes it slippery is that each participant passes review in isolation. The cardholder has a real card and a real history. The merchant is a genuine business. The employee is a trusted insider. Controls that judge one account, one login, or one transaction at a time see nothing wrong, because the wrongdoing lives in the coordination, not in any single record. Collusion is where the fraud is the relationship.

That is why it belongs to the world of link analysis and network analysis. You detect it by connecting the dots between parties: shared devices, addresses, bank accounts, or beneficiaries; transactions that always pair the same two counterparties; and timing that lines up too neatly to be coincidence. Investigate the money flow and the connections between people, not just each account on its own.

Where collusion shows up

Setting

How the collusion works

Merchant and customer

A merchant and cardholder run friendly-fraud or refund schemes and split the recovered money.

Employee and outsider

An insider approves, credits, or ships to a colluding customer in exchange for a cut.

Buyer and seller

Marketplace counterparties fake sales to launder funds, farm reviews, or trigger payouts.

Bust-out ring

Multiple parties coordinate to build credit, then draw it all down together and vanish.

Lending ring

Applicants and a middleman coordinate documents and references to pass underwriting as a group.

Who is involved?

Who

Their role

The counterparties

Two or more actors who each look legitimate alone and coordinate the scheme between them.

The insider

An employee or partner who abuses access to approve, credit, or route transactions to co-conspirators.

The ring organizer

Where a group is involved, the person coordinating roles, timing, and the split of proceeds.

The platform

The bank, marketplace, or processor whose data links the parties, often the only place the relationship is visible.

What it looks like in practice

In practice

A marketplace notices that one seller's sales, while modest in total, almost all come from the same handful of buyer accounts, and every order clears at full price with a five-star review minutes later. No single account trips a rule. The buyers have clean histories, the seller has good standing, and each transaction is small.

Link analysis tells a different story. The buyer accounts share two devices and a common payout bank account with the seller. The pattern is not real commerce; it is coordinated activity to trigger seller payouts and build a fake reputation, most likely to launder card proceeds. The team maps the cluster, freezes the linked accounts together, and files a report on the network rather than chasing each transaction in isolation.

Why collusion matters to operators

Collusion is the blind spot of any control that scores accounts one at a time. Because every participant looks legitimate alone, rules, risk scores, and manual reviews built around a single subject will keep passing colluding parties indefinitely. The fraud is invisible until you change the unit of analysis from the account to the relationship.

For operators that means investing in entity resolution, shared-attribute linking, and network analysis, and building investigation habits that ask who is on the other side of this transaction and how are they connected. It also means treating suspicious coordination as a cluster: when you find one colluding pair or ring, freeze and investigate the whole linked group together, because acting on one node just lets the rest continue.

What to watch for

  • Repeating counterparties. The same two parties always transacting with each other, especially when outside activity is thin.
  • Shared hidden attributes. Distinct accounts linked by common devices, addresses, bank accounts, or payout beneficiaries.
  • Too-neat timing. Transactions, approvals, or reviews that land in tight, coordinated sequences rather than natural spread.
  • Insider proximity. An employee whose approvals, credits, or overrides cluster around a specific set of customers.
  • Clean-on-their-own subjects. Parties that each pass account-level review yet only ever benefit each other are a link-analysis flag, not reassurance.

Quick questions

How is collusion different from a fraud ring?

A fraud ring is one common form of collusion, a group coordinating for scale. Collusion is the broader idea of parties conspiring, which can be just two people, like a single merchant and cardholder. All rings involve collusion, but not all collusion is a ring.

Why do account-level controls miss it?

Because those controls judge one subject at a time, and each colluding party looks legitimate on their own. The wrongdoing lives in the coordination between parties, which only becomes visible when you link accounts by shared attributes and examine the money flow between them.

What tools detect collusion?

Link analysis, network analysis, and entity resolution are the core tools. They connect accounts through shared devices, addresses, bank accounts, and counterparty patterns, then surface clusters that transact mainly with each other or benefit a common party.

Is insider fraud a form of collusion?

It often is. When an employee coordinates with an outside party to approve, credit, or ship improperly in exchange for a cut, that is collusion. Insider access makes it especially damaging because the insider can bypass or override the very controls meant to catch it.

Can colluding parties be unwitting?

Sometimes one party is manipulated rather than fully complicit, which complicates intent. But true collusion requires agreement to the scheme. Investigations focus on the pattern of coordination and benefit to establish whether parties acted together knowingly.

What should a team do when it spots collusion?

Treat it as a network, not a single case. Map the linked parties, freeze the cluster together, preserve the connection evidence, and consider a suspicious activity report. Acting on one participant alone usually just lets the others regroup and continue.

Go deeper

Collusionと併せて知っておきたい用語