Fare System Transaction Fraud Investigation

Investigated abnormal fare-card transaction behavior and identified three users exploiting a payment-system vulnerability that allowed balance increases without the normal recharge workflow.

Key Outcomes

3 Users
Fraudulent activity identified
Anomaly Detection
Abnormal balance behavior isolated
Payment Vulnerability
Recharge bypass pattern identified
Corrective Action
Findings documented for security response

Project Context

The fare system used cards that were normally recharged through authorized ticket offices, machines, or other approved recharge points before travel. Certain cards began showing unexpected balance increases without corresponding legitimate recharge transactions. The investigation examined whether this behavior reflected data errors, transaction-processing issues, card behavior, or misuse of the payment system.

Investigation Approach

Transaction Reconstruction

Correlated Card ID, timestamp, station, transaction type, balances before and after each transaction, recharge events, and fare validations to reconstruct expected versus actual card behavior.

Balance Anomaly Detection

Isolated balance increases that had no corresponding legitimate recharge event or authorized recharge activity.

Behavioral Pattern Analysis

Compared anomalous activity across stations and time periods to determine whether the behavior followed a consistent pattern.

Repeat Pattern Confirmation

Confirmed repeated anomalous sequences across multiple stations and time windows, distinguishing the behavior from isolated data errors.

Investigation Signals

  • Cards receiving balance increases without recharge transactions.
  • Recharge amounts not associated with authorized recharge activity.
  • Transaction sequences inconsistent with normal passenger behavior.
  • Repeated anomalous patterns across multiple stations and time windows.

Accessible transaction diagram

Transaction Pattern to Security Finding

Expected recharge and fare-use sequences were compared with anomalous card behavior, then traced from individual transactions to repeated user-level patterns.

Normal Behavior

  1. 01Authorized recharge
  2. 02Balance increase
  3. 03Fare validation
  4. 04Balance decrease

Anomalous Behavior

  1. 01No authorized recharge
  2. 02Unexplained balance increase
  3. 03Fare usage

Investigation Sequence

  1. 01Anomalous transaction
  2. 02Card-level review
  3. 03Sequence reconstruction
  4. 04Cross-station and time comparison
  5. 05Repeated pattern
  6. 06User identification
  7. 07Security findings

Verified Outcome

Three fraudulent users identified

The investigation identified three users repeatedly exhibiting the anomalous transaction pattern and exploiting a vulnerability in the payment system.

Operational Change

The findings were documented and delivered to the appropriate internal teams to support corrective action and security improvements within the fare system.

Investigation domains

Transaction Analytics Fraud Investigation Anomaly Detection Fare Collection Operational Security Power BI