Full response reference
Here is a complete flagged response for reference:Status field
Thestatus field is the top-level classification. It will always be one of two values:
When
status is CLEARED, all risk fields (confidence, cluster_id, risk_category, sources) return as null or empty.
Confidence score
Theconfidence field is a floating-point number between 0.0 and 1.0 that represents how strongly the evidence supports the flagged classification. It is only present when status is FLAGGED.
A medium-confidence flag still warrants attention. It can indicate a VPA that has recently appeared on fraud infrastructure, where the evidence corpus is still growing. Treat medium flags as “pending investigation” rather than “probably fine.”
Risk category
Therisk_category field describes the nature of the fraud activity the VPA has been linked to.
A single VPA can be linked to multiple categories across different evidence sources. The
risk_category field reflects the primary or highest-severity category detected.
Cluster membership
When a VPA is part of a coordinated fraud network, it is assigned to a cluster — a group of VPAs that appear together across multiple fraud sources, share infrastructure, or exhibit correlated behaviour.
A large
cluster_size (e.g. 7 or more VPAs) suggests an organised fraud operation rather than an isolated bad actor. Use the cluster_id to pull the full cluster via the cluster endpoint:
Evidence sources
Thesources array contains the individual pieces of evidence that contributed to the flag. Each entry represents a specific web page or platform on which the VPA was found.
When
screenshot_available is true, contact your account manager or use the FraudTrace dashboard to retrieve the screenshot. Screenshots are useful when escalating a case internally or filing a complaint with NPCI or law enforcement.
The evidence_count field reflects the total number of distinct evidence items for this VPA, which may be higher than the number of entries in the sources array if some sources are withheld for operational security reasons.
first_seen and last_seen
These timestamps tell you when FraudTrace first and most recently observed the VPA on fraud infrastructure.
Use
last_seen as a recency signal to prioritise your review queue: a VPA last seen yesterday is a more urgent case than one last seen eight months ago with the same confidence score.
CLEARED caveats
ACLEARED response means FraudTrace has no evidence of this VPA in its database at the time of the request. It does not mean the VPA is safe.
Always combine FraudTrace results with your existing KYC, transaction monitoring, and behavioural analytics. FraudTrace is a powerful signal — it is most effective as one layer of a defence-in-depth strategy.
Frequently asked questions
What should I do when confidence is medium (0.60–0.84)?
What should I do when confidence is medium (0.60–0.84)?
Do not auto-approve or auto-reject. Route the case to a human reviewer with
the full FraudTrace response — particularly the
sources array and
cluster_id. Medium confidence often reflects a VPA that has appeared
recently on fraud infrastructure where evidence is still accumulating. Your
reviewer should check the merchant’s or customer’s profile for other risk
signals before making a decision. If in doubt, request additional
documentation before proceeding.Can I get false positives?
Can I get false positives?
Yes, false positives are possible. A VPA is flagged when it appears on fraud
or gambling infrastructure, but there are edge cases — for example, a
legitimate business whose VPA was harvested and re-posted by a fraudulent
site without their knowledge. The confidence score and evidence sources help
you assess the likelihood: multiple independent sources, a large cluster, and
recent
last_seen timestamps increase confidence that a flag is genuine.
When you believe a result is a false positive, use the FraudTrace dashboard
to submit a dispute — confirmed false positives are reviewed and removed
promptly.How quickly are new mule VPAs added to the database?
How quickly are new mule VPAs added to the database?
FraudTrace continuously crawls fraud sites, gambling platforms, phishing
pages, and scam infrastructure. New VPAs discovered during a crawl are
typically indexed within a few hours of capture. For time-critical use cases
— such as large-value real-time payments — combine FraudTrace screening with
your own transaction velocity and behavioural checks, since a VPA that went
live on a fraud site minutes ago may not yet be indexed.
What does CLEARED mean exactly?
What does CLEARED mean exactly?
CLEARED means the queried VPA does not appear in the FraudTrace database at
the moment you made the request. It reflects the absence of evidence, not the
presence of safety. The database is comprehensive but not exhaustive — new
fraud infrastructure is discovered continuously. Treat CLEARED as “no known
risk signal” and continue applying your standard due diligence processes
alongside it.