Sense
Sign inBook a demo
INDUSTRIESFINTECH & LENDING

You approve a borrower you never meet.

Ninety seconds, an app on someone else's phone, documents they chose to give you. Fraud in digital lending is not a rules problem any more — it is an evidence problem.

71%
of confirmed application fraud is identity-led rather than document-led
29%
is first-party — a real borrower, a false picture, no intent to repay
8.3%
of digital account creations were suspected fraudulent in H1 2025
24 h
to repatriate and delete borrower data processed outside India
Sources: Experian Fraud Index (2025 application-fraud composition) · industry account-opening fraud estimates, H1 2025 · RBI Digital Lending Directions, 2025, para 13.
Read the counter-moveDownload the lending brief
01 — THE CASE

One night, one emulator, four lenders.

Every field is filled correctly. Every document renders. Every check passes. The first EMI never arrives, and neither does the borrower.

21:04
One handset becomes forty borrowersA desktop VM runs a mobile emulator with a fresh device profile per application. Between them, one operator, one drawer of prepaid SIMs and a spreadsheet of identities.EMULATOR FARM · DEVICE PROFILE SPOOFED
21:07
The identity is assembled, not stolenA real government number is blended with a fabricated name, address and employer — a synthetic file with a thin but plausible bureau history built over the last eighteen months.SYNTHETIC IDENTITY · THIN-FILE BY DESIGN
21:12
KYC passes on injected mediaThe selfie step is fed a rendered video through a virtual camera; the address proof is generated from a template bought as a service, with matching fonts and issuer artefacts.INJECTION ATTACK · DOCUMENT TEMPLATE FARM
21:19
Income is manufactured to fit the cut-offSalary slips and a statement PDF are edited to land just above the policy threshold, and the employer's domain is registered a fortnight ago with a live mailbox for verification.FIRST-PARTY MISREPRESENTATION
21:26
The same file applies to four lendersApplications are stacked across four apps inside twelve minutes — faster than any bureau enquiry surfaces at the others. All four price it as a single new-to-credit borrower.APPLICATION STACKING · BUREAU LAG
21:31
Disbursal, then silenceFunds land in an account opened last month on the same farm. Two EMIs are paid to lift the limit, the limit is drawn in full, and the file goes quiet.BUST-OUT · BOOKED AS CREDIT LOSS
WITH SENSE
The application never reaches underwriting.At 21:07 the app is running in an emulated environment on a device already seen thirty-nine times, and the number on the form is not live on the handset. The application is held before the bureau is pulled — no CKYC cost, no disbursal, no bust-out to write off two months later.

A credit model can only judge what it is told. It never meets the borrower, the device, or the room.

WHY BUREAU AND KYC CHECKS RUN OUT
02 — THE MAP

Four surfaces in a lending business. What you see, and what they use.

Pick a surface to read the exposure in the terms your credit and risk committee uses.

WHAT THE LENDER SEESAn application submitted from a mobile device with a plausible fingerprint, inside the limits and journeys your app enforces.
WHAT THE FRAUD NETWORK USESEmulators and cloned instances to mass-produce devices, root and Frida to move the client-side checks, a virtual camera for the liveness step, and a repackaged build for whatever the real one refuses.
emulatordevice_reuse_x39virtual_camerafrida_hookrepackaged_build
03 — THE COUNTER-MOVE

Evidence from the device, the application and the decision — before the money leaves.

Sense does not score creditworthiness. It tells your credit stack whether the application in front of it came from a real borrower on a real device, in a session nobody else was driving.

POSITION 01On the deviceThe SDK runs inside your DLA and reports what the application form cannot: emulator and cloned-instance detection, device reuse across applications, root and hooking, virtual-camera and injected-media indicators, and whether the build is the one you shipped.RASPIN-THREADCode ObfuscationBUILD-TIMEApp AuthATTESTATION
POSITION 02At the applicationThe borrower's number is proven live on the handset instead of by an OTP anyone holding the SIM can answer, and the web funnel is separated into applicants and scripts — so stacking rings and bot submissions are visible before the bureau pull is paid for.Silent Mobile VerificationIDENTITYBot DetectionWEB & APIAccount TakeoverSESSION
POSITION 03Around the decisionCredit and collections assistants are inspected in flight — prompt, retrieved document, tool call, response — and every model, adapter and tokenizer in the decisioning path is scanned, signed and inventoried before it can price a borrower.AI Runtime SecurityIN-PATHModel Security & TrustPRE-SHIP
04 — THE EXPOSURE INDEX

Nine ways a lending book takes fraud losses as credit losses.

Open a line to read the mechanism and the control that answers it. Most of these arrive in your MIS as delinquency, not as fraud.

A real identifier blended with fabricated details, aged quietly into a thin bureau file, then applied at volume from emulated devices. Nothing in the application is checkable as false.Emulator, cloned-instance and device-reuse evidence plus on-device number proof make the farm visible even when every field is plausible.
Mechanisms drawn from published 2025–26 lending-fraud research: identity, first-party and synthetic composition (Experian, SentiLink), emulator and bot-led onboarding infrastructure, application stacking and bust-out patterns.
05 — THE FIRST NINETY DAYS

No change to your credit policy. One release per surface.

01DAYS 1–30The app, in report-onlySDK into your existing DLA. Nothing declines. Your risk team sees the emulator, device-reuse and tampering rate inside its own funnel for the first time.
02DAYS 31–60Hold at application, not at disbursalDevice and number evidence enters the decision before the bureau pull. Farmed and stacked applications are held; genuine applicants notice nothing.
03DAYS 61–90Partners, collections and the model pathLSP and white-label journeys attested, repayment flows covered, and the decisioning models scanned and inventoried with records your partner lender can audit.
WHAT THE PARTNER LENDER AND THE AUDITOR RECEIVE
A signed device and session record per applicationApp build inventory — yours and every partner DLA in the chainFraud-rate reporting separated from credit-loss reportingModel and adapter inventory for the decisioning pathIncident timelines assembled inside the reporting window
MAPPED TO
RBI Digital Lending Directions, 2025LSP due diligence & auditCIMS DLA registerData localisation · 24 hDPDP ActCIC reportingOWASP MASVSISO 27001 / SOC 2

The RBI's 2025 Directions make the regulated entity answerable for every app in its lending chain — its own and its LSPs'. When your partner bank audits the journey, the device and app evidence is already assembled, per application, per release.

NEXT STEP

Send us a month of applications. We'll show you which devices wrote them.

A device-and-funnel assessment across your lending app and web journey — emulator clusters, device reuse, tampered builds, injected-media indicators, number-not-on-handset applications and scraper load on the offer engine.

Run the assessmentTalk to our lending teamReport-only on your own funnel first — you see the fraud rate before anything declines.