Fraud or Credit? Why Misattributing Losses Makes You Fix the Wrong Thing
Fraud or Credit? Why Misattributing Losses Makes You Fix the Wrong Thing
Losses rise. The credit committee reviews charge-offs, concludes underwriting was too loose, and tightens the cutoff. Approvals fall, good applicants are declined, and the losses continue — because a meaningful share of them were never credit losses at all. They were fraud, booked as credit losses because nobody separated them. The distinction matters more than almost any other classification in lending, because the two have entirely different remedies: a credit loss says you misjudged capacity; a fraud loss says you lent to someone who wasn't who they claimed. Tightening credit criteria addresses the first and does nothing about the second, since a fraudster presents whatever profile the criteria require.
What you'll learn
Why the distinction decides the remedy
| Credit loss | Fraud loss | |
|---|---|---|
| What went wrong | Capacity or willingness misjudged | The applicant wasn't who they claimed |
| Borrower existed? | Yes | Frequently not, or not as presented |
| Intended to repay? | Usually | No |
| Timing | Emerges over months | Immediate or near-immediate |
| Recoverable? | Partially | Almost never |
| Remedy | Better capacity assessment | Better identity verification |
| Responds to tighter cutoffs? | Yes | No |
The last row is the whole argument. Credit risk is a distribution you can move a threshold across. Fraud is an adversary who observes the threshold and presents above it.
Which means a fraud problem responds to a credit tightening in a specific and frustrating way: approvals fall, good applicants are lost, and the fraud rate as a share of approvals rises — because the genuine applicants were the ones the tightening removed. The response then looks like it made things worse, prompting further tightening, in a loop that ends with a small book and the same fraud.
The general form of the error is one this desk keeps encountering: a remedy applied to the wrong mechanism. Our option analysis made the same point about ability-driven versus incentive-driven default — responding to elevated subprime losses with more income documentation addresses a channel that isn't the problem. Here the misdiagnosis is one level up, in whether the loss belongs to lending at all.
First-payment default
The single strongest attribution signal, and it's already in your data.
A first-payment default is an account that never makes its first scheduled payment. It's a fraud indicator because of a simple behavioural fact: a borrower who intended to repay almost always makes at least one payment.
Consider what has to happen for a genuine borrower to miss the very first payment. They applied, were approved, received funds, used them — and then, within weeks, became unable to make one payment. Possible, and rare. Circumstances usually take longer than that to deteriorate, and the funds have just arrived.
Whereas for fraud it's the expected outcome. The money was taken. There was never an intention to service the account.
How to use it:
- Track first-payment default as a standing metric, separate from overall delinquency.
- Watch it as an early indicator. It's visible within weeks of origination while credit losses take many months — which makes it the fastest signal any lender has that something changed.
- Segment it by channel, campaign, and geography, since fraud concentrates and genuine credit failure doesn't.
- Investigate spikes immediately. A rising first-payment default rate is a fraud alarm well before it's a credit signal.
- Extend to early-payment default — accounts defaulting within the first two or three payments — which captures fraud that made one payment to establish plausibility.
The operational value is the timing. A lender monitoring first-payment default learns about a fraud attack in weeks; one monitoring charge-offs learns about it in a year, having originated twelve more months of it.
The full signal set
Beyond timing, what distinguishes the two:
| Signal | Suggests credit | Suggests fraud |
|---|---|---|
| Payments made | Some, then stopped | None, or one then nothing |
| Contact after default | Responds, at least initially | Immediately unreachable |
| Explanation offered | Yes, and usually specific | None |
| Contact details | Verify; may go stale | Fail verification retrospectively |
| Employment | Verifiable | Unverifiable or non-existent |
| Use of funds | Consistent with stated purpose | Immediate withdrawal or transfer |
| Pattern across applications | Independent | Clustered — shared attributes |
| Application velocity | Normal | Multiple applications in a short window |
Two rows carry disproportionate weight.
Contactability after default. A borrower in genuine distress is frequently reachable — embarrassed, sometimes avoidant, but locatable and often willing to explain. An account that becomes immediately and permanently unreachable, with details that fail retrospective verification, is a different phenomenon. This is where the contact data work in our contact guide produces attribution information as a byproduct.
Clustering. Genuine credit failure arrives independently — households fail for their own reasons. Fraud arrives in patterns: shared device fingerprints, addresses, phone number ranges, application timing, employer names, or bank routing. A cluster of defaults sharing attributes is the clearest available evidence, and finding it requires looking at defaults as a set rather than as individual accounts.
Synthetic identity
The category that defeats attribution most thoroughly and is most often booked as credit loss.
A synthetic identity is constructed — real and fabricated elements combined into a profile that doesn't correspond to a person. It's then cultivated: small obligations opened and paid, a credit history accumulated, a file built over months or years. Then it borrows as much as possible and disappears.
Why it's so hard:
- The history is genuine. Those payments were really made. The file is real; the person isn't.
- It behaves exactly like a thin-file customer during cultivation — the population our thin-file analysis describes.
- There's no victim. Nobody reports it, because no real person was harmed in a way they'd notice. Absent a report, the loss defaults to credit loss — which is the entire attribution problem in one sentence.
- Detection is retrospective, if it happens.
The consequence is the reason this section exists. Synthetic losses booked as credit losses appear as thin-file underwriting failure, and the response is to tighten thin-file criteria — which declines the genuine thin-file applicants the synthetics were imitating, while the synthetics simply cultivate longer to clear the new bar.
The remedy that works is identity verification rather than credit tightening — establishing that the applicant corresponds to a real person, through source-connected verification of the kind our verification guide describes. The two responses cost roughly the same and only one addresses the problem.
Why misclassification is the default
The structural reasons losses end up in the wrong bucket, none of which involve anyone deciding to misclassify:
- Fraud requires proof; credit loss doesn't. Booking a loss as fraud implies a determination; booking it as credit loss requires only that the account didn't pay. The path of least resistance is credit loss.
- Nobody investigates individual defaults. Establishing fraud on a modest balance costs more than the balance in most cases, so the investigation doesn't happen and the account ages into charge-off.
- Separate ownership. Fraud sits with one function and credit with another, and an account that could belong to either lands with whoever's process catches it first — usually collections, which books credit.
- Reporting incentives. A high fraud rate is a control failure; a high credit loss rate is a market condition. The classification with the softer implication is the one that gets chosen when the evidence is ambiguous.
- No feedback loop. Once booked, nothing revisits the classification, so the error never surfaces.
The net effect is a systematic bias in one direction: ambiguous losses become credit losses. Which means credit loss rates are overstated, fraud rates are understated, and the remedies applied are weighted toward underwriting regardless of what actually happened.
What the wrong diagnosis costs
Work the arithmetic. A lender with 20,000 annual originations, an 8% loss rate, and $4,000 average balance is losing $6.4 million. Suppose 22% of that is actually fraud — $1.4 million misattributed.
Under the wrong diagnosis:
- Credit cutoff tightened to reduce a "credit" loss rate
- Approvals fall, say 12% — 2,400 applicants declined
- Credit losses fall proportionally on the genuine portion
- Fraud losses are unchanged, since fraudsters present above whatever the cutoff is
- Fraud as a share of remaining losses rises, prompting further tightening
- The good applicants declined are a permanent revenue loss, and — per our reject inference analysis — the lender will never learn how they would have performed
Under the right diagnosis:
- Identity verification strengthened at origination
- Fraud losses fall
- Credit cutoff unchanged, so approvals are preserved
- The remaining credit loss rate is now measured correctly, so underwriting can be assessed on its actual performance
The second point in that list is the one worth emphasizing. Until fraud is removed from the denominator, you cannot evaluate your underwriting at all — every model comparison, every champion-challenger test in our deployment guide, and every loss forecast is being run against a target variable that contains a different phenomenon.
Building the attribution process
- Define the criteria in writing — what evidence puts a loss in each bucket — and apply them consistently.
- Review every first-payment default. Small enough in volume to examine individually and the highest-yield population.
- Run cluster analysis on defaults, looking for shared device, address, contact, employer, or banking attributes. This finds what account-by-account review can't.
- Retrospectively verify defaulted accounts on a sample basis, testing whether application details hold up.
- Capture collections intelligence. Collectors learn things — a number that never worked, an employer that doesn't exist, an address that isn't residential. Build a path for that to reach the fraud function, because it's currently lost.
- Reclassify and restate. Recompute loss rates with fraud removed, and use the corrected figure for every underwriting assessment.
- Report both separately, permanently, and never blend them into a single loss rate.
- Feed confirmed fraud back to origination detection, since patterns repeat.
The third and fifth are the ones most operations lack. Cluster analysis finds fraud that individual review never will, and collections holds the best fraud intelligence in the institution with no route to the people who need it.
Matching remedy to diagnosis
| Diagnosis | Remedy | What doesn't help |
|---|---|---|
| Credit loss | Better capacity assessment, cash flow data, cutoff adjustment | Identity verification |
| Application fraud | Identity verification, document authentication, velocity checks | Tighter credit cutoffs |
| Synthetic identity | Identity resolution, source-connected verification, thin-file scrutiny that tests existence rather than creditworthiness | Thin-file credit tightening |
| Account takeover | Authentication and change-of-detail controls | Origination controls entirely |
| Bust-out | Behavioural monitoring on existing accounts | Origination controls, since the account was legitimate at opening |
Two rows deserve a note.
Bust-out — where an account is opened legitimately, operated normally, then run to the limit and abandoned — cannot be caught at origination by anything, because there was nothing wrong at origination. It requires the account management monitoring in our early warning guide, and a lender responding to bust-out losses by tightening origination is addressing a stage the fraud never passed through in a detectable form.
The thin-file row makes the distinction that matters most for access. Verifying that someone exists and verifying that they're creditworthy are different operations, and conflating them is why synthetic identity fraud reduces credit access for genuine thin-file applicants. A lender that separates the two can verify existence rigorously while underwriting credit generously — which is both better fraud control and better access.
Two problems, two controls, measured separately
HL Hunt AI Underwriting runs identity verification and credit assessment as distinct stages with separate reason codes and outcome tracking — including first-payment default monitoring and cluster detection — so a fraud attack doesn't arrive on your desk labelled as a credit problem.
Frequently asked questions
Timing and behaviour. Genuine borrowers make some payments, respond to contact initially, and can be located. Accounts that never pay, go immediately unreachable, and fail retrospective verification are usually fraud.
The remedies differ entirely. Tightening credit criteria addresses misjudged capacity and does nothing about fraud, because a fraudster presents whatever profile the criteria require.
An account that never makes its first payment. A borrower who intended to repay almost always pays once — the funds just arrived. It's also visible in weeks rather than months.
A constructed identity cultivated with real payment history then borrowed against. There's no victim to report it, so it books as credit loss — and the response tightens thin-file criteria against genuine applicants.
Key takeaways
- Credit risk is a distribution you can move a threshold across; fraud is an adversary who presents above whatever threshold you set.
- First-payment default is the strongest attribution signal and is visible in weeks rather than the months credit losses take.
- Clustering across applications distinguishes fraud from credit failure, and it requires examining defaults as a set rather than individually.
- Synthetic identity losses book as credit losses because there's no victim to report them — and the resulting tightening hits genuine thin-file applicants.
- Ambiguous losses default to the credit bucket for structural reasons, so credit loss rates are overstated and fraud understated.
- Until fraud is removed from the denominator you cannot evaluate underwriting at all, because every model test runs against a contaminated target.
Know which problem you have before you fix it
Get started with HL Hunt AI Underwriting to tag verification and credit outcomes separately from origination — so loss attribution is a report you can run rather than an investigation nobody has time for.
This guide is educational and does not constitute legal or compliance advice. Worked figures are stylized illustrations. Fraud investigation, adverse action, and suspicious activity reporting obligations vary by institution type and jurisdiction; consult qualified counsel and your compliance function.