Day-0 Fraud Telemetry for FMS
Pitch workflow · Bank case ⨝ Threat indicators
Victim is already logged in. Identity stays in the bank case system — never sent to Waspada.
CIF-DEMO-0001
+60-12-000-0001
000000-00-0001
—
Creates an opaque partner_case_id the bank keeps with the victim record.
On-device extraction from receipt / chat evidence. Optional suspicious link → RDAP domain age (registry lookup — not a web search, not a “scam verdict”).
Never in Waspada telemetry.
Run synthetic extract to populate.
Pitch story: mule account from the receipt + domain age from RDAP on the link. We do not open or crawl the page.
Uses unmistakably fake mule/URL fixtures — not live FI data. Optional: upload a file in the main sandbox for a live OCR run.
The Fraud Management System (FMS) sees one case: victim context from the bank + advisory indicators from Waspada.
———Held only by bank
———No victim PII
partner_case_id; structured mule + RDAP signal in FMS