Zero-Day Fraud Detection

Detect the attack before there is a rule for it

Identify previously unseen fraud patterns before historical labels or explicit controls exist. DataVisor combines patented Unsupervised Machine Learning with behavioral, device, graph, and real-time intelligence to surface emerging attacks while there is still time to intervene.

Solution Pillars

Find the gap before known fraud

Start with the anomaly, connect the surrounding signals, reveal the cluster, and turn discovery into a repeatable control.

Start with the anomaly

Surface behavior that does not fit the population

Use unsupervised analysis to identify abnormal activity without requiring a known fraud signature or labeled example.

No known signature required
Connect the signals

Build context around the first suspicious event

Correlate behavioral, device, transaction, identity, velocity, and network signals to understand whether the anomaly is isolated or part of a coordinated attack.

Behavioral, device, and network correlation
Find the cluster

Reveal related entities as the attack develops

Use clustering and Knowledge Graph linkage analysis to connect events, accounts, devices, and infrastructure that may look unrelated in isolation.

Clustering and graph linkage analysis
Turn discovery into a control

Move from first sighting to repeatable protection

Investigate the emerging pattern and operationalize the intelligence through supported strategies, rules, features, workflows, or decisioning controls.

From first sighting to production control
Product Proof

An attack, taking shape

The first anomalous event, the emerging group it belongs to, linked entities, and supporting risk signals resolve into an investigation — and, from there, a deployable control.

Anomaly
→
Signal
correlation
→
Cluster
→
Control
An early signal is correlated, grouped into an emerging cluster, and converted into a deployed control.
How It Works

Detect risk before labels catch up

1

Surface abnormal behavior through unsupervised analysis.

2

Correlate related signals and events.

3

Identify linked entities and emerging clusters.

4

Assess risk without waiting for confirmed fraud labels.

5

Investigate and convert the new intelligence into protection.

Built for the gap before known fraud

Find what rules and labeled models have not learned yet

DataVisor's zero-day approach uses unsupervised detection to identify abnormal behavior before an explicit rule or historical fraud label exists, then strengthens that signal with graph, device, behavioral, and real-time context.

When the attack keeps changing

Protect against fast-evolving fraud

Use zero-day detection for coordinated card or BIN attacks, new fraud-ring behavior, evolving account takeover, mule activity, and other polymorphic or AI-enabled attacks where the pattern changes faster than conventional controls.

Card / BIN Attacks Emerging Fraud Rings Evolving Account Takeover Mule Activity
Make early detection concrete

What happened before the rule existed

No labels required
Abnormal behavior is surfaced through unsupervised ML before any fraud label exists
Signals, not guesswork
Behavioral, device, and graph correlation confirm risk before a rule is written

DataVisor is built to catch the attack while it is still new: unsupervised machine learning flags the anomaly, correlated behavioral, device, and graph signals confirm it, and clustering and linkage analysis reveal the network behind it — all before a rule or historical label exists to catch it.

Connected Platform

Bring multiple intelligence layers to the unknown

Combine Unsupervised ML, dEdge, behavioral intelligence, Knowledge Graph, Real-Time Data Orchestration, Rules & Features, Real-Time Decisioning, and Case Management around the emerging threat.

Control the anomaly signal

Separate meaningful change from legitimate novelty

Evaluate anomalous activity in context using peer behavior, risk scores, linked entities, and analyst feedback. Feed confirmed patterns back into detection strategies so defenses continue to adapt as fraud evolves.

  • Peer-group and score-distribution context
  • Linked-entity context for evaluating anomalies
  • Analyst feedback and tuning controls
  • Workflow for promoting new intelligence into detection
FAQ

Common questions

Can DataVisor detect fraud without historical labels?

Yes. DataVisor's Unsupervised Machine Learning is designed to identify abnormal behavior without requiring prior labeled fraud examples.

How does DataVisor control false positives in zero-day detection?

DataVisor evaluates anomalies with broader behavioral, device, transaction, and network context so risk is assessed using multiple dimensions rather than a single unusual signal.

What happens after DataVisor discovers a new attack pattern?

The pattern can be investigated and, through supported workflows, translated into strategies, rules, features, or other controls that make future instances easier to identify and stop.

See the first attack become a detection

Walk through zero-day fraud from anomaly to action

Explore how DataVisor surfaces an unknown pattern, connects the network, explains the risk, and helps teams turn the discovery into protection.