Next-Generation Session Anti-Fraud: How IBM Trusteer Protects Against Social Engineering
The modern cyber threat landscape shows a clear trend: traditional account takeover attacks, which rely on stolen credentials, are gradually taking a back seat. According to IBM Trusteer’s 2025 analysis, fraudsters are increasingly targeting the most vulnerable link in the security chain—the human element.
There is a rapid increase in sophisticated targeted scams, social engineering methods, the use of deepfake voice technology, the implementation of data interceptors in browsers, as well as attacks during the remote account opening process (Account Opening Fraud). According to statistics, 61% of all fraudulent activities are currently carried out from trusted devices that customers have repeatedly used for legitimate transactions.
To address these challenges, IBM is developing IBM Trusteer—a specialized session anti-fraud platform that focuses on detecting data theft and behavioral anomalies in web resources and mobile applications.
Key technological features of IBM Trusteer
The platform operates as a cloud-based solution (SaaS), providing real-time global threat analysis. The product is built on IBM’s secure cloud infrastructure, which complies with international regulatory requirements and security standards.

- Global ecosystem: The solution is used in 190 countries worldwide and analyzes over 250 million active user profiles. This enables the instant detection of attackers based on matches in IP addresses, locations, applications used, and behavioral patterns.
- Consortium data model: all platform customers are participants in a unified threat intelligence network. As soon as a new fraud scheme or vulnerability appears for one of the users, the IBM engineering team develops a signature and adds it to subsequent releases to protect the entire network.
- In-depth behavioral analysis: the system evaluates not only device parameters but also how the user interacts with a webpage or app (e.g., typing dynamics and speed, screen navigation patterns).
Data integration and collection mechanism
The platform operates through two distinct technical channels:
- Mobile app: A specialized SDK is integrated into the app, which monitors the device’s environment, detects malware, and can trigger security scenarios (e.g., forced logout or blocking balance viewing).
- Web resource: part of the code is implemented directly into the bank’s or company’s web pages and is activated during each user session.
During a single session, the system can collect and analyze between 100 and 300 different parameters (device data, geolocation, network status, presence of VPNs, emulators, remote access tools, screen overlay detection, etc.).
Procedural support: IBM provides ready-made legal and technical procedures to legitimize the collection of such data for the Apple App Store and Google Play. If necessary, the system can be flexibly configured to collect anonymized or masked data to comply with local regulatory requirements.

Specifics of Threat Detection
The platform effectively combats critical attack vectors that are most prevalent in the Asian and Eastern European markets:
- An active call during a session. The system detects if an active voice call is in progress (via a cellular network or messaging apps such as Viber, Telegram, or WhatsApp) at the moment a transaction is initiated in the mobile app. This is the primary indicator of a successful social engineering attack.
- Remote control and malware. Detection of device compromises, the presence of Jailbreak/Root privileges, and the use of virtual machines or remote access tools (RATs). According to analytical data, the vast majority of device compromises occur on Android OS, though exploits on iOS are also being detected.
- Interception of OTP passwords. Detection of anomalies during card tokenization, when attackers attempt to intercept or coerce the customer into providing a one-time password.
- Onboarding fraud (Account Opening Fraud). A module for risk analysis during remote account opening, enabling the detection of so-called “drops.” Statistics from pilot projects in Eastern Europe (specifically, experience in Moldova) show that in certain high-risk regions, one in three remotely opened accounts was fraudulent.
Licensing Model
The cost of using IBM Trusteer does not depend on the volume of data transferred or the number of transactions. The product is licensed exclusively based on the number of unique active users (Identity) in a bank or organization per year. If a customer uses both the web version and the mobile app, the system identifies them as a single individual.
Integration of IBM Trusteer with IBM Safe Payments
The greatest efficiency and most comprehensive security picture is provided by the cross-channel integration of IBM Trusteer’s session-based anti-fraud with IBM Safer Payments’ transaction-based anti-fraud.
In this architecture, IBM Trusteer acts as a session context provider (Session Monitoring), collecting behavioral and device risk indicators. The final decision to block a transaction, suspend an account, or require an additional authentication factor is made at the IBM Safe Payments level at the time of the financial transaction.

Benefits of the integrated approach:
- A complete chain of actions. The ability to intentionally allow a suspicious session until the transaction occurs in order to capture the final recipient details and build a complete graph analysis of the attack.
- Simulation mechanism. IBM Safe Payments allows you to run new anti-fraud rules or machine learning models on historical data (from the past 3–6 months). This allows you to assess the false positive rate before deploying the rules to a production environment.
The combination of technologies enables financial institutions to achieve fraud detection rates of up to 90% while keeping the false positive rate (Fraud Alerts) below 0.05%.
Solidity is actively developing expertise in session-based anti-fraud and is deploying its own IBM Trusteer platform demo environment (demo dashboard) to test and evaluate the effectiveness of anti-fraud scenarios.
Protect your business and customers from sophisticated social engineering schemes. Get expert advice on implementing IBM Trusteer and integrating it with your current systems by emailing us at info@solidity.com.ua.