The Challenge
Your fraud operations team might notice an unusual pattern: thousands of sequentially created email addresses appearing across multiple merchant environments daily. These activities seem harmless when viewed in isolation, one email registering for a bank account here, another purchasing sneakers there. Each transaction passes standard fraud checks. The email addresses aren't on blocklists, and the purchase amounts stay under typical review thresholds.
However, when aggregated across a platform, this pattern reveals a coordinated campaign using agentic AI to generate sequential email addresses at scale, deploying them across unrelated merchants to avoid detection. This technique exploits a fundamental flaw in traditional fraud detection, which evaluates transactions primarily within their own merchant context.
"Individually, it looks fine; there's nothing wrong there," says Diarmuid Thoma, Head of Fraud and Data Strategy at AtData. "At a platform level, we see the cumulative effect."
Your team faces a detection problem that can't be solved with conventional rules. You need to identify automation deliberately mimicking legitimate user behavior across disconnected systems.
The Environment and Constraints
Operating in a cross-merchant data environment allows you to observe email addresses, device fingerprints, and behavioral signals across multiple clients. This visibility reveals patterns that individual merchants can't see. However, your existing detection models evaluate transactions within merchant boundaries. An email address creating an account at Merchant A has no visible connection to the same address making a purchase at Merchant B an hour later. Merchants are working with incomplete pictures.
Timing is also a constraint. By the time sequential patterns become obvious in retrospective analysis, fraudulent accounts are already active and generating chargebacks. You need a way to detect coordinated campaigns in real time, not days later during incident review.
Adding complexity, the rise of agentic commerce means you can't simply flag all automated activity. Legitimate AI agents are beginning to conduct transactions on behalf of consumers, blurring the line between malicious bots and authorized AI proxies.
The Approach Taken
Your team shifts from transaction-level evaluation to entity-level continuity analysis. Instead of asking, "Does this transaction look legitimate?" you ask, "Does this email address have a coherent history?"
You start tracking the age of email addresses, usage patterns over time, and whether associated identity elements, names, addresses, device fingerprints, show normal evolution or suspicious discontinuity. An email address that appeared for the first time yesterday and is already active across five unrelated merchants triggers different scrutiny than one with years of consistent activity.
For the sequential email problem, you build detection logic that identifies rapid creation patterns across your platform. When you see batches of similar addresses (variations on a theme, sequential numbers, or common construction patterns) appearing simultaneously across multiple merchants, you can flag the cluster for review before significant damage occurs.
Critically, you don't rely solely on negative signals. You incorporate positive verification data, confirmed email activity, historical transaction patterns, stable identity elements, to distinguish between legitimate new customers and synthetic profiles. This is especially important as you prepare for agentic commerce scenarios, where authorized AI agents need to pass fraud checks without excessive friction.
You also work to break down data silos between fraud and payments functions. "In the most advanced organizations that I work with, those two functions are working hand-in-hand," says Brandt Hoffman, Sales Director for Fraud Services at AtData. "They know exactly what's going on from a payments perspective and how that affects the flow of fraud."
Results and Metrics
Platform-level visibility allows you to detect coordinated campaigns that individual merchants can't see. By identifying sequential email patterns and analyzing entity continuity across clients, you can flag suspicious clusters before they generate significant chargeback volume.
The shift to historical data analysis reduces false positives. Instead of blocking legitimate new customers who trigger isolated risk signals, you evaluate whether identity elements show normal evolution over time. A customer who moves addresses but maintains consistent email usage, device patterns, and purchase behavior doesn't trigger the same scrutiny as a profile with discontinuous elements.
What You Would Do Differently
Looking back, you recognize you've been treating fraud data as merchant-specific intelligence when it has broader organizational value. The same signals used for fraud detection, geolocation, behavioral patterns, demographic data, can inform marketing targeting, conversion optimization, and customer experience decisions.
"Everybody thinks that's a lot of money for fraud prevention, but it becomes very cheap because you're splitting that into multiple budgets," Thoma says. "The marketing team can use it for targeted products, and you can increase conversions."
You also wish you'd moved faster on integrating fraud and payments team workflows. The delay in breaking down those silos meant missed opportunities to correlate payment authorization patterns with fraud signals in real time.
Takeaways for Your Team
Evaluate continuity, not just snapshots. Your fraud models likely analyze transactions in isolation. Add entity-level checks to assess whether email addresses, device fingerprints, and identity elements show coherent histories or suspicious discontinuity. A profile that appears fully formed yesterday is different from one that's evolved over years.
Look for patterns across your ecosystem. If you operate multiple merchant relationships or have platform-level visibility, build detection logic that identifies coordinated campaigns. Sequential email creation, rapid identity reuse, and synchronized activity across unrelated merchants often stay invisible to individual fraud queues.
Incorporate positive signals now. As agentic commerce grows, you'll need to distinguish between malicious automation and legitimate AI proxies. Start building verification logic that confirms authorized relationships, email age, historical activity, stable identity elements, rather than only flagging negative indicators.
Merge fraud and payments workflows. Your fraud team sees risk patterns. Your payments team sees authorization behavior and revenue impact. When those groups operate in silos, both miss critical context. Create shared visibility into transaction flows and fraud topology.
Treat fraud data as organizational intelligence. The same continuity data that detects synthetic identities can inform customer segmentation, conversion optimization, and experience design. Justify your fraud prevention infrastructure by demonstrating its value across departments, not just in chargeback reduction.
The sequential email campaign illustrates a broader shift: fraud detection is moving from rules-based transaction review to continuity analysis across entities and time. Your ability to contextualize identity elements within historical patterns, and to share that intelligence across organizational boundaries, will determine whether you're detecting coordinated campaigns or just cleaning up the damage after they've run.



