What to do if a risk result comes back as 'High Threat' for Online Fraud Indicators
A failed Online Fraud Check (High Threat) does not automatically confirm that a transaction is fraudulent.
The Online Fraud Check assesses the risk associated with a transaction. It works by comparing two key location indicators:
- Device Location: The geographical location of the device used to complete the verification.
- Internet Service Provider (ISP) Location: The location registered to the IP address of the internet connection being used.
A common cause for a High Threat flag is if iCloud Private Relay is enabled, which can be found under the INTERNET PROVIDER DERIVED LOCATION by clicking VIEW DETAILS. This feature is a privacy setting that's switched on by default for a lot of Apple users. It masks the user's true IP address, triggering an alert because the security system detects a location mismatch.
It cannot verify that the digital location (IP address) aligns with their physical identity, however the use of Location Services provides their true GPS coordinates.

An analysis of the IP address is also conducted to identify potential red flags:
- The use of services designed to obscure location, like Virtual Private Networks (VPNs), relays or firewalls.
- An origin from a country with a high-risk profile for fraudulent activities.
- Inclusion in databases of IP addresses previously linked to fraudulent behaviour. An IP address can be flagged as a "high threat" due to a poor IP reputation based on historical behaviour. This often has nothing to do with the current user's actions.
For a low-risk transaction, both the device location and the ISP location should be in the same country and in close geographical proximity to one another.
You can find further information from our geolocation provider https://db-ip.com/ and entering the IP address.
Overall, it means the verification session showed potential signs where connection or location signals are associated with fraud risk - such as VPN use, mismatched geolocation, or suspicious device behaviour - not that your client failed verification. These are items to just be aware of when looking at the overall result.
- Don't dismiss it automatically - treat it as a risk signal to resolve, like a screening match.
- Consider innocent explanations first: a client overseas, on a corporate VPN, or on a work device commonly triggers these flags.
- Ask the client where and how they completed the check - routine questions aren't tipping off.
- If unresolved, escalate to your Compliance Officer and consider Enhanced Due Diligence.
Further reading: Does easyAML check whether the client is using a VPN?