How Banks Can Collaborate on Fraud Data Without Sharing Raw Transactions - 1 of 3

Published: Updated: 5 min read
How Banks Can Collaborate on Fraud Data Without Sharing Raw Transactions - 1 of 3

This is a 3-part series, the first part of which explores the ways current systems can be exploited by criminals, followed by 7 specific use cases in part two , and practical solutions in part three.

Privacy-preserving data linkage can reveal criminal networks that no institution can see alone

Banks have invested heavily in transaction monitoring, fraud analytics, identity verification, behavioral models, and customer authentication. These systems prevent enormous losses—but each institution still sees only a fragment of the criminal activity moving through the financial system.

A sending bank may see a customer being manipulated into making an unusual payment. The receiving bank may see funds arriving in a newly opened mule account. A third institution may see the money dispersed across several accounts. A payment provider may recognize a device used in previous attacks, while a telecom operator may hold evidence of account takeover or social engineering.

Individually, each event may appear inconclusive. Viewed together, they can reveal a coordinated fraud network.

The difficulty is that banks cannot simply pool customer files and transaction histories into a shared database. Raw financial records contain personal data, commercially sensitive information, confidential risk indicators, and details of banks’ internal detection methods. Sharing them indiscriminately would create legal, security, governance, and competitive risks.

Privacy-Preserving Data Linkage, or PPDL, offers a different approach.

Also described as Privacy-Preserving Record Linkage, or PPRL, it allows organizations to identify records relating to the same person, account, company, device, or event without exchanging the underlying identifiers in plaintext. Combined with secure multiparty computation, homomorphic encryption, controlled analytics, and other Privacy-Enhancing Technologies, it can support Multi-Party Privacy-Preserving Data Analysis across institutions.

The commercial proposition is straightforward:

Banks can detect patterns across institutional boundaries without giving one another unrestricted access to raw transactions.

Fraud is a network problem—but banks usually analyze it institution by institution

Modern fraud rarely remains inside one bank.

Criminals move money rapidly through chains of accounts, payment institutions, digital wallets, cryptocurrency services, merchants, and international payment networks. They exploit the fact that every participant has only a partial view.

The Bank for International Settlements has described siloed transaction monitoring as ineffective against complex laundering schemes that span institutions and borders. Its Project Aurora found that collaborative analysis using Privacy-Enhancing Technologies, machine learning, and network analysis was more effective than isolated monitoring. In its simulated environment, the project detected potentially up to three times more complex money-laundering activity and reduced false positives by as much as 80 percent.

Project Hertha, conducted by the BIS Innovation Hub and the Bank of England, examined the same problem in real-time retail payments. Criminals use networks of accounts across multiple financial institutions, while payment-system-level analysis can reveal connections that individual institutions cannot see.

The potential financial value is considerable. UK Finance reported that criminals stole almost £1.3 billion through payment fraud in the United Kingdom during 2025. Authorized Push Payment fraud alone reached £576.4 million, while the industry prevented £1.68 billion of attempted unauthorized fraud.

Those figures illustrate both sides of the business case. Fraud is already a major direct cost, but effective detection systems are also demonstrably capable of preventing large losses.

The remaining opportunity lies in detecting what a bank cannot see from its own data.

What Privacy-Preserving Data Linkage does

Record linkage is the process of determining whether records in separate datasets refer to the same entity.

In conventional linkage, banks might compare names, account numbers, addresses, telephone numbers, tax identifiers, device identifiers, or corporate registration data. The problem is that exchanging these fields in readable form exposes information about customers who may have no connection to fraud.

Privacy-Preserving Data Linkage (PPDL) changes the process.

Before data leaves a participating institution, selected identifiers can be normalized and transformed into protected representations. The collaboration environment then compares or links those protected records rather than the original identifiers.

Depending on the architecture, banks may be able to establish that:

  • the same person controls accounts at several institutions;
  • two suspicious beneficiaries use the same protected telephone number;
  • several applications originate from the same device;
  • a merchant appears in multiple chargeback investigations;
  • the same company director is linked to several suspect businesses;
  • funds pass through a recurring network of mule accounts;
  • several institutions have independently flagged the same entity;
  • a newly opened account matches an identifier associated with an earlier fraud case.

The participants do not need to receive complete customer lists from one another. They can learn the permitted match, risk indicator, network connection, or analytical result instead.

This is an important distinction. PPDL is not simply another encrypted file-transfer mechanism. It changes the collaboration model from sharing records to jointly calculating relationships among records.

Why conventional sharing approaches fall short

Banks already share information through regulatory reports, bilateral inquiries, industry databases, payment messages, law-enforcement requests, and formal information-sharing programs.

These mechanisms remain essential, but they often have operational limitations.

Manual requests are slow and tend to begin only after suspicion has already developed. Central databases create attractive security targets and require participants to trust the database operator. Shared watchlists may identify known entities but reveal less about emerging networks. Aggregated statistics protect confidentiality but cannot support record-level linkage. Bilateral data exchange becomes difficult to scale when dozens of institutions are involved.

Privacy-preserving analysis can complement these mechanisms by enabling repeatable, automated, multi-party checks under predefined rules.

The United States offers a useful public example of the demand for collaboration. Section 314(b) of the USA PATRIOT Act provides a safe harbor for eligible financial institutions that share information for specified financial-crime purposes. More than 7,200 institutions were registered in the program in fiscal year 2025, and more than 65,000 Suspicious Activity Reports referenced 314(b) information sharing.

FinCEN clarified in June 2026 that participating institutions can use the framework to share information about suspected fraud, subject to the program’s requirements.

The existence of legal sharing pathways does not, however, remove the technical and commercial concerns associated with exposing raw records. PPDL can provide an additional layer of data minimization by restricting what must be disclosed during the collaboration.

Coming up is part 2 of the 3-part series on How Banks Can Collaborate on Fraud Data Without Sharing Raw Transactions, where we shall discuss 7 specific use cases .

Try the AI Act risk classifier

Find out in 5 minutes which risk category your AI system falls into — free, 100% private, with a detailed PDF result.

Start the assessment
H
Pátkai András
Harvey's · AI & compliance team
Experts in AI Act compliance, testing and security audits. Reach out any time with questions.
LinkedIn

Harvey's newsletter

Stay up to date with our AI Act content

One practical monthly summary on EU AI Act compliance — no spam, unsubscribe any time.

← Back to the blog