Remittance action detection system, remittance action detection method, and remittance action detection program

The remittance detection system analyzes account and transaction data to identify and flag potentially fraudulent accounts, improving the detection of illicit financial activities by enhancing the continuous verification of transactions across multiple institutions.

JP2026016353APending Publication Date: 2026-02-03CAULIS INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2025142385
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-08-28
Publication Date
2026-02-03

AI Technical Summary

Technical Problem

Existing technologies are inadequate in identifying accounts susceptible to fraudulent use and detecting fraudulent transactions in financial systems, particularly in cases of money laundering and other illicit activities, due to insufficient continuous verification and slow recognition by financial institutions.

Method used

A remittance detection system and method that analyzes account information and deposit/withdrawal data across multiple financial institutions to identify accounts at risk of fraudulent use, using correlation analysis and encryption to detect patterns indicative of fraudulent activity, and shares this information with other institutions.

Benefits of technology

Efficiently detects accounts engaging in fraudulent transactions by identifying patterns and correlations in financial data, enhancing the ability of financial institutions to prevent and respond to money laundering and other fraudulent activities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026016353000001_ABST
    Figure 2026016353000001_ABST
Patent Text Reader

Abstract

To provide a system for specifying an account having the possibility of illegal use by using information such as account information and money reception / payment information.SOLUTION: An account information acquisition unit that acquires account information from a plurality of financial institutions; a deposit and withdrawal information acquisition unit that acquires deposit and withdrawal information of the plurality of pieces of account information; A remittance action detection system comprising: a specification unit that specifies an account as an account having a possibility of fraudulent use when it is determined that the account has a possibility of fraudulent use; an output unit that outputs information on the account having a possibility of fraudulent use to a plurality of financial institutions; and a storage unit that stores the account information, the deposit / withdrawal information, and the information on the account having a possibility of fraudulent use.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a remittance detection system, a remittance detection method, and a remittance detection program that identify accounts that may be subject to fraudulent use based on large amounts of deposit and withdrawal information and account information that may be subject to fraudulent use provided to financial institutions. [Background technology]

[0002] In recent years, with the spread of the Internet, money laundering has become a serious problem, with account holders disguising funds obtained through crimes or illicit transactions (hereinafter referred to as "illegal funds") as funds obtained through legitimate transactions or transferring the funds through multiple financial institutions to conceal the source of the funds.As a result, there are concerns that the misappropriation of illicit funds will encourage organized criminal activities and affect economic activity in society.

[0003] In order to prevent fraudulent transactions such as money laundering as described above, financial institutions have implemented measures such as disclosing information on fraudulent use of deposit accounts and sharing it with other financial institutions, and requiring operators to implement customer due diligence and other preventive measures to a certain extent. Although fraudulent transactions can be detected through identity verification at the time of account opening or monitoring at the remittance stage, due to financial institutions' slow recognition and response to money laundering, there are still problems such as false detection of suspicious transactions and insufficient continuous verification of account holders.

[0004] Therefore, in order to solve the above problems, it is necessary to detect fraudulent transactions by utilizing large amounts of deposit and withdrawal information obtained from financial institutions. Patent Document 1 discloses a method for preventing fraudulent remittances in Internet banking, and the method described in Patent Document 1 determines whether the remittance destination sent in response to a remittance command is on an existing list of fraudulent accounts, and if the remittance destination is not on the list of fraudulent accounts, Internet banking can remit the money to the specified remittance destination based on the remittance command.

[0005] Furthermore, Patent Document 2 discloses a technology for detecting fraudulent financial transactions. Specifically, the technology described in Patent Document 2 acquires difference pattern information related to the transaction history of a bank account of a new person to be detected for fraudulent transactions and reference difference pattern information related to the transaction history of the bank account of the person to be detected in the past, which has been acquired in advance, and determines the possibility of a fraudulent transaction by referring to three or more levels of correlation with the possibility of a fraudulent transaction of the person to be detected in the past. The difference pattern described in this publication indicates the difference in the transaction history between two or more terms, which has been acquired in advance from the transaction history of the bank account of the person to be detected in the past. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] Japanese Patent Application Laid-Open No. 2016-170761 [Patent Document 2] Japanese Patent Publication No. 2021-144356 Summary of the Invention [Problem to be solved by the invention]

[0007] However, the technology disclosed in Patent Document 1 only determines whether a remittance can be permitted, and is unable to identify accounts that may be subject to fraudulent use. Furthermore, the technology disclosed in Patent Document 2 determines the possibility of a fraudulent transaction by referencing three or more levels of correlation based on new transaction history and past transaction history, but is unable to identify whether an account may be subject to fraudulent use.

[0008] Therefore, the present invention has been made in consideration of the above problems, and aims to provide a method for determining the possibility of fraudulent transactions based on account information, deposit and withdrawal information, and information regarding accounts that may be subject to fraudulent use, and for detecting accounts that may be subject to fraudulent use in financial transactions through multiple types of embodiments. [Means for solving the problem]

[0009] A remittance detection system according to one embodiment of the present invention comprises an account information acquisition unit that acquires account information from multiple financial institutions, a deposit / withdrawal information acquisition unit that acquires deposit / withdrawal information for the multiple account information, an identification unit that determines whether an account may have been fraudulently used based on the deposit / withdrawal information and account information and identifies the account as one that may be subject to fraudulent use if it determines that the account may have been fraudulently used, an output unit that outputs information regarding accounts that may be subject to fraudulent use to multiple financial institutions, and a memory unit that stores account information, deposit / withdrawal information, and information regarding accounts that may be subject to fraudulent use.

[0010] In one embodiment of the remittance detection system of the present invention, the identification unit may identify, based on deposit and withdrawal information, an account that is at least one of an account that serves as a collection point for withdrawals and an account that serves as a collection point for deposits, as an account that may be subject to fraudulent use.

[0011] In one embodiment of the remittance activity detection system, the identification unit may identify, based on the deposit and withdrawal information acquired by the deposit and withdrawal information acquisition unit, as accounts that may be subject to fraudulent use, an account to which money is being transferred to an account that the identification unit has previously identified as being potentially subject to fraudulent use, an account to which money has been transferred from an account that the identification unit has previously identified as being potentially subject to fraudulent use, an account held by multiple financial institutions to which money is being transferred to an account that may be subject to fraudulent use, and an account held by multiple financial institutions to which money has been transferred from an account that may be subject to fraudulent use.

[0012] A remittance detection system according to one embodiment of the present invention further includes a determination unit that compares account deposit and withdrawal information with history information indicating the deposit and withdrawal history of the account stored in a memory unit, calculates the degree of correlation between the deposit and withdrawal information and the history information based on the comparison result, and determines whether the account is likely to be used fraudulently; if the degree of correlation is higher than a predetermined threshold, the determination unit determines that the account is likely to be used fraudulently; if the degree of correlation is lower than the predetermined threshold, the determination unit determines that the account is not likely to be used fraudulently; and the identification unit may identify an account that the determination unit has determined to be likely to be used fraudulently.

[0013] The remittance activity detection system according to one embodiment of the present invention may further include an encryption unit that encrypts account information acquired from a plurality of financial institutions.

[0014] A method for detecting remittance activity according to one embodiment of the present invention is a method for detecting remittance activity, including the steps of: an account information acquisition step in which a computer acquires account information from multiple financial institutions; a deposit and withdrawal information acquisition step in which the computer acquires deposit and withdrawal information for the multiple account information; an identification step in which the computer determines whether an account is likely to be used fraudulently based on the deposit and withdrawal information and the account information, and identifies the account as one that may be subject to fraudulent use if the computer determines that the account is likely to be used fraudulently; an output step in which the computer outputs information about the account that may be subject to fraudulent use identified in the identification step to multiple financial institutions; and a storage step in which the computer stores the account information, deposit and withdrawal information, and information about the account that may be subject to fraudulent use.

[0015] A remittance activity detection program according to one embodiment of the present invention causes a computer to execute an account information acquisition function for acquiring account information from a plurality of financial institutions, a deposit and withdrawal information acquisition function for acquiring deposit and withdrawal information for the plurality of account information, a specification function for determining whether an account will be fraudulently used based on the deposit and withdrawal information and the account information, and for identifying the account as an account that may be fraudulently used if it is determined that the account may be fraudulently used, an output function for outputting information about the account that may be fraudulently used and that has been identified by the specification function to a plurality of financial institutions, and a storage function for storing the account information, deposit and withdrawal information, and information about the account that may be fraudulently used. This is a money transfer detection program that includes the following: [Effects of the Invention]

[0016] The remittance detection system, remittance detection method, and remittance detection program disclosed herein efficiently detect accounts engaging in fraudulent transactions based on account information, deposit and withdrawal information, and information regarding accounts that may be being used fraudulently. [Brief explanation of the drawings]

[0017] [Figure 1] FIG. 1 is a system diagram illustrating a configuration example of the present disclosure. [Figure 2] FIG. 2 is a block diagram illustrating an example configuration of a server according to the present disclosure. [Figure 3] FIG. 1 is a diagram illustrating an example of detecting fraudulent accounts according to the present disclosure. [Figure 4] FIG. 1 is a diagram illustrating an example of detecting fraudulent accounts according to the present disclosure. [Figure 5] 1A and 1B are diagrams illustrating an example of detecting fraudulent accounts according to the present disclosure. [Figure 6] 4 is a flowchart showing an example of the operation of a server for realizing the embodiment shown in FIG. 3. [Figure 7] 5 is a flowchart showing an example of the operation of a server for realizing the embodiment shown in FIG. 4. [Figure 8] 6 is a flowchart showing an example of the operation of a server for realizing the embodiment shown in FIG. 5. DETAILED DESCRIPTION OF THE INVENTION

[0018] <Embodiment> <Summary> Fig. 1 is an example of a system diagram according to this embodiment. As shown in Fig. 1, a remittance activity detection system 10 according to this embodiment includes a server 100 and a financial institution terminal 200, which are connected to each other via a network NW so that they can communicate with each other.

[0019] Server 100 identifies accounts that may be used for fraudulent transactions or accounts of victims of fraud based on deposit and withdrawal information between accounts at the financial institution. Server 100 according to this embodiment exchanges information with financial institution terminal 200 via network NW and acquires information (e.g., account information, deposit and withdrawal information, etc.) for determining whether or not a fraudulent transaction has occurred. Financial institutions according to this embodiment are not limited to banks and may be organizations that provide funds, intermediate funds, or otherwise engage in financial transaction-related activities. Furthermore, account information according to this embodiment may include information identifying account-related information, such as account number, personal information of the account holder (e.g., name of the account holder, address information, telephone number, etc.), and deposit and withdrawal information. Account information according to this embodiment may be included in the account information and simultaneously acquired from financial institution terminal 200, or it may not be included in the account information and may be acquired by referring to the account information acquired from financial institution terminal 200.

[0020] There may be multiple financial institutions exchanging information with server 100 according to this embodiment. In the example shown in FIG. 1 , for example, financial institution terminal 200A of financial institution A, financial institution terminal 200B of financial institution B, and financial institution terminal 200C of financial institution C are shown. In this specification, when there is no need to distinguish between them, they will be collectively referred to as financial institution terminal 200. Financial institution terminal 200 according to this embodiment is an information processing device used by financial institutions such as banks and credit unions, and stores information related to deposits and withdrawals at the financial institution used. Financial institution terminal 200 according to this embodiment is configured to share information such as account information and account deposit and withdrawal information stored therein in a manner recognized by server 100. As an example, financial institution terminal 200 stores information on multiple accounts, and before sharing the multiple account information with server 100, the account information may be encrypted to prevent leakage of personal information and address information of the account holders, detailed account numbers, and other information contained in the account information. Next, the financial institution terminal 200 may send the encrypted information (which may include, for example, the encrypted personal information and address information of the account holder, and the encrypted account number) to the server 100, and have the server 100 determine whether the account is subject to fraudulent use (hereinafter referred to as a fraudulent account).

[0021] Furthermore, financial institution terminal 200 may be a general PC or an information processing terminal such as a smartphone, and is a terminal used by the owner's financial institution where the owner's account is opened. There may be multiple financial institution terminals 200 according to this embodiment. In this case, server 100 may acquire account information, deposit and withdrawal information, etc. from multiple financial institution terminals 200 and store this in memory unit 150. Note that financial institution terminal 200 according to this embodiment may be any computer capable of exchanging information, and a detailed description of its configuration will be omitted.

[0022] The network NW may include a wireless network or a wired network. As an example, the network NW may be a wireless LAN (WLAN), a wide area network (WAN), wireless LANs, a mobile communication system for fourth generation communication (4G), fifth generation communication (5G), sixth generation communication (6G) or later, etc. The network NW is not limited to these examples and may be, for example, a public switched telephone network (PSTN), an optical fiber line, a satellite communication network, etc. The network NW may also be a combination of these.

[0023] <Configuration> The following describes in detail the mechanisms of each component of the server 100 according to this embodiment. FIG. 2 is a block diagram showing an example of the configuration of the server 100. The server 100 is a computer system including a RAM (random access memory, not shown), a ROM (read only memory, not shown), and a processor, and may be implemented as a personal computer (PC), a tablet terminal, or the like. As shown in FIG. 2, the server 100 includes a communication unit 110, an input unit 120, a control unit 130 (including an account information acquisition unit 131, a deposit / withdrawal information acquisition unit 132, an identification unit 133, a determination unit 134, and an encryption unit 135), an output unit 140, and a storage unit 150. However, the configuration of the server 100 is not limited to the above, and the server 100 may be provided with a classification unit that classifies accounts according to deposit / withdrawal information based on information acquired from the account information acquisition unit 131 and the deposit / withdrawal information acquisition unit 132.

[0024] The communication unit 110 allows the server 100 to exchange information with the financial institution terminal 200 via the network NW. As an example, the communication unit 110 may be connected to the outside of the server 100 via a cable such as a LAN cable, optical fiber, or Ethernet (ETHERNET (registered trademark)), or may be a communication module equipped with a communication function such as a wireless chip.

[0025] The input unit 120 is provided in the server 100, and may be a keyboard, a mouse, a camera, a microphone, a touch panel, etc. Furthermore, the input unit 120 according to this embodiment may include an input interface having a function of receiving input from an operator of the server 100 or the like and transmitting the information to the control unit 130.

[0026] Control unit 130 is a processor that uses various programs and data stored in memory unit 150 to realize the functions to be realized by server 100. Control unit 130 according to this embodiment functions as account information acquisition unit 131, deposit / withdrawal information acquisition unit 132, identification unit 133, determination unit 134, and encryption unit 135. Among these, account information acquisition unit 131 is configured to acquire account information from multiple financial institution terminals 200. The account information acquired from multiple financial institution terminals 200 is not limited, and account information acquisition unit 131 may acquire encrypted information from financial institution terminal 200, or may acquire specific information from financial institution terminal 200. After account information acquisition unit 131 acquires the account information, it is stored in memory unit 150.

[0027] Deposit and withdrawal information acquisition unit 132 is configured to acquire deposit and withdrawal information related to the accounts acquired by account information acquisition unit 131. Furthermore, the method of acquiring deposit and withdrawal information is not limited, and as an example, after account information acquisition unit 131 acquires account information from financial institution terminal 200, deposit and withdrawal information acquisition unit 132 may acquire deposit and withdrawal information for each account from the account information acquired by account information acquisition unit 131.

[0028] The identification unit 133 can identify fraudulent accounts based on account information and deposit / withdrawal information. Specifically, the identification unit 133 determines whether an account is a fraudulent account based on various information (e.g., account number, deposit / withdrawal information, etc.) acquired by the account information acquisition unit 131 and the deposit / withdrawal information acquisition unit 132. As an example, the identification unit 133 may identify a fraudulent account by determining whether there is a collection point for deposits or withdrawals based on the deposit / withdrawal information of multiple accounts. The identification unit 133 may also identify an account that serves as a collection point for deposits or withdrawals as a fraudulent account based on the deposit / withdrawal information acquired by the deposit / withdrawal information acquisition unit 132. The identification unit 133 may also identify an account that the determination unit 134 has determined to be a possible fraudulent account. The identification unit 133 may also identify a fraudulent account by determining whether to deposit or withdraw money to a previously acquired blacklisted account based on the deposit / withdrawal information acquired by the deposit / withdrawal information acquisition unit 132. The blacklist according to this embodiment is a list of accounts determined to have a history of fraudulent activities at financial institutions, etc., and accounts listed on the blacklist may be blacklisted accounts. Details are provided below.

[0029] The determination unit 134 is configured to determine whether an account is fraudulent based on the latest deposit and withdrawal information for that account and the deposit and withdrawal history of that account previously stored in the storage unit 150. Specifically, the determination unit 134 compares newly acquired deposit and withdrawal information with the deposit and withdrawal history to calculate a correlation, and compares the correlation with a predetermined threshold to determine whether the account is fraudulent based on the comparison result. In this case, if the correlation is higher than the predetermined threshold, the account is determined to be fraudulent, and if the correlation is lower than the predetermined threshold, the account is determined to be a general account. For example, if the deposit and withdrawal patterns of an account change over time, it can be assumed that the account user has changed. Therefore, if the account name has not been changed, the account may be determined to be fraudulent. In other words, the account is likely to have been resold or be subject to fraudulent use, and the determination unit 134 can detect such accounts. Note that the threshold in this embodiment may be set by the owner of the remittance activity detection system 10 or may be set based on the correlation calculated by the determination unit 134.

[0030] Encryption unit 135 is configured to encrypt information acquired from financial institution terminal 200. Specifically, when server 100 receives various information, including account information and deposit and withdrawal information, from financial institution terminal 200, encryption unit 135 may encrypt the various information, including the account information and deposit and withdrawal information, and store the information in storage unit 150. The encryption method according to this embodiment is not limited to this embodiment, and encryption unit 135 may encrypt the various information using a common key or a public key. As an example of a method for encrypting various information using a common key, when encryption unit 135 encrypts information acquired from financial institution terminal 200 using a common key cryptosystem, server 100 may encrypt the various information acquired from financial institution terminal 200 using the same key for encryption and decryption and store the information in storage unit 150. In this case, the information before encryption is not stored in storage unit 150. On the other hand, when financial institution terminal 200 encrypts the various information, server 100 does not need to be provided with encryption unit 135 according to this embodiment.

[0031] The output unit 140 is configured to output information about fraudulent accounts identified by the identification unit 133 or the determination unit 134 to the financial institution terminal 200. As an example, the output unit 140 may output information only to the financial institution terminal 200 of the financial institution that holds an account with a possible fraudulent transaction, or may share and output information about accounts with a possible fraudulent transaction to the financial institution terminals 200 of all financial institutions. Specifically, when the identification unit 133 or the determination unit 134 identifies a fraudulent account, the output unit 140 outputs information about the fraudulent account to the financial institution terminal 200, and the financial institution terminal 200 determines whether to approve the transaction based on the information about the fraudulent account. As an example, if the financial institution terminal 200 needs to re-evaluate the information about the fraudulent account, the output unit 140 outputs the information about the fraudulent account to the financial institution terminal 200, and the financial institution terminal 200 may re-evaluate whether the account is definitely a fraudulent account according to a determination rule unique to the financial institution. If the account is definitely a fraudulent account, the financial institution terminal 200 may determine to freeze the account. If the account is not a fraudulent account, financial institution terminal 200 may decide to approve the transaction for that account. Also, if financial institution terminal 200 does not need to re-evaluate information about the fraudulent account, output unit 140 may output information about the fraudulent account to financial institution terminal 200, and financial institution terminal 200 may reject the transaction for that account.

[0032] The storage unit 150 is a storage medium that stores various programs and various data required for the operation of the server 100. The storage unit 150 may be realized by, for example, but not limited to, a hard disk drive (HDD), a solid state drive (SSD), or flash memory. The storage unit 150 may also be configured as a random access memory (ROM) or random access memory (RAM) that serves as a working area for executing programs. The storage unit 150 may store information about fraudulent accounts identified by the account information acquisition unit 131, the deposit / withdrawal information acquisition unit 132, and the identification unit 133.

[0033] The above is the description of the server 100 and the financial institution terminal 200 according to this embodiment.

[0034] Next, an example according to this embodiment will be described with reference to FIGS. 3, 4 and 5. FIG.

[0035] <First Example> A first example of this embodiment will be described below. FIG. 3 is a schematic diagram illustrating an example of fraudulent account detection according to the present disclosure, showing an example of transactions between accounts. The server 100 identifies fraudulent accounts by analyzing the network of deposits and withdrawals based on deposit and withdrawal information acquired from the financial institution terminal 200. The deposit and withdrawal information according to this embodiment may include historical information such as information about the intermediate account 220 to which the deposit or withdrawal is made, the number of deposits and withdrawals, the amount of the deposit and withdrawal, the number of deposit and withdrawal accounts, and the frequency of deposits and withdrawals. Furthermore, the first account 210 according to this embodiment is the account from which the first fraudulent remittance is made. The first account 210 may be a frozen account for fraudulent transactions as determined by the Metropolitan Police Department or the financial institution, or it may be an account that is as close to a frozen account as possible based on the determination of the remittance activity detection system 10 according to this embodiment or the financial institution's own screening criteria. The owner of the first account 210 uses the first account 210 to conceal fraudulent remittances, transferring money to multiple intermediate accounts 220 as a centralized withdrawal account to carry out fraudulent transactions. Furthermore, the intermediate account 220 is an account through which deposits are made from the first account 210 or another intermediate account 220, and remittances are made to the second account 230 or another intermediate account 220. In this case, the intermediate account 220 may be determined by the remittance activity detection system 10 to be a fraudulent account, or may be determined to be a general account. The second account 230 may be an account that receives deposits from the first account 210 and the intermediate account 220, and may also transfer funds to the first account 210. As an example, the second account 230 may be an account that receives deposits from multiple intermediate accounts 220, acts as a collection point for deposits, and transfers the acquired funds to the first account 210.

[0036] The server 100 according to the first embodiment may identify the first account 210, the intermediate account 220, and the second account 230 using the deposit and withdrawal information of multiple accounts acquired from the financial institution terminal 200. Specifically, the server 100 identifies at least one of the accounts that serve as a withdrawal aggregation point and a deposit aggregation point based on the acquired deposit and withdrawal information of the multiple accounts. An account that serves as a withdrawal aggregation point according to this embodiment is an account that withdraws funds from more than a predetermined number of withdrawal accounts. Specifically, if an account withdraws funds to multiple accounts and the number of these multiple accounts is higher than a predetermined value, the account may be designated as a withdrawal aggregation point. Furthermore, if an account receives deposits from multiple accounts and the number of these multiple accounts is higher than a predetermined value, the account may be designated as a deposit aggregation point. Note that when a certain account serves as a withdrawal aggregation point and withdraws funds to multiple accounts, the server 100 may designate the account as the first account 210 based on the withdrawal information. Furthermore, the account that receives deposits from the identified first account 210 may be designated as the intermediate account 220. On the other hand, when a certain account is used as a collection point for deposits from multiple accounts, the remittance activity detection system 10 may designate the account as the second account 230 based on the deposit information. Also, the account that transfers money to the identified second account 230 may be the intermediate account 220. The account that serves as the collection point in this embodiment is not limited, and a fraudulent account shared by the financial institution terminal 200 may be the collection point account.

[0037] On the other hand, server 100 according to the first embodiment extracts fraudulent accounts identified by financial institution terminal 200 based on account information acquired from financial institution terminal 200. Server 100 may then determine whether the account that deposits and withdraws money from the fraudulent account is a fraudulent account or a victim account, based on the deposit and withdrawal information of first account 210 and second account 230 of the fraudulent account identified by financial institution terminal 200.

[0038] <Second Example> 4 is a schematic diagram showing one embodiment of fraudulent account detection according to the present disclosure, and shows an example of transactions between accounts. Server 100 identifies as a fraudulent account an account that makes a withdrawal or transfer to a fraudulent account identified by server 100 and financial institution terminal 200. However, this is not limited to this, and server 100 may obtain information about the fraudulent account identified by another external terminal (which may include, for example, a terminal of the Tokyo Metropolitan Police Department), and identify as a fraudulent account an account that makes a withdrawal or transfer to the fraudulent account obtained from the external terminal.

[0039] The server 100 according to the second embodiment can identify as fraudulent accounts determined by the financial institution terminal 200, and accounts that make deposits or withdrawals to fraudulent accounts identified by the server 100. As shown in FIG. 4, when an account holder of account A 240 at financial institution A transfers money to an account in financial institution B, including account B 250, if account B 250 is determined by financial institution B to be a fraudulent account, the identification unit 133 of the server 100 may determine account A 240, which transfers money to account B 250, which is determined to be a fraudulent account, as a fraudulent account. If account B 250 is determined by financial institution B to be a general account, the identification unit 133 of the server 100 may determine account A 240, which transfers money to account B 250, which is determined to be a general account, as a general account.

[0040] On the other hand, when account A 240 of financial institution A receives a deposit from account B 250 of financial institution B (not shown), if account B 250 is recognized as a fraudulent account by financial institution B, the identification unit 133 of server 100 may determine that account A 240, to which money has been transferred from account B 250, which is recognized as a fraudulent account, is a fraudulent account. If account B 250 is recognized as a general account by financial institution B, the identification unit 133 of server 100 may determine that account A 240, to which money has been transferred from account B 250, which is recognized as a general account, is a general account.

[0041] <Third Example> 5 is a schematic diagram showing an example of fraudulent account detection according to the present disclosure, illustrating an example of transactions between accounts. Server 100 may detect suspicious transactions or transactions that differ from previous behavior from the individual deposit and withdrawal patterns of an account, and determine whether the account is a fraudulent account.

[0042] The server 100 of the third embodiment compares the history information indicating the deposit and withdrawal history of an account stored in the memory unit 150 with the deposit and withdrawal information newly acquired by the server 100 (hereinafter referred to as the latest information), calculates the correlation degree indicating the correlation between the deposit and withdrawal history information and the latest information, and determines whether the account is a fraudulent account.

[0043] Specifically, as shown in Figure 5(A), server 100 acquires deposit and withdrawal information for target account 260 from financial institution terminal 200 and stores it as history information indicating the deposit and withdrawal history in memory unit 150. As shown in Figure 5(B), server 100 stores the latest information for target account 260 from financial institution terminal 200 in memory unit 150.

[0044] Next, the determination unit 134 compares the deposit and withdrawal history information with the latest information, calculates the correlation based on the comparison result, and determines whether the account is a fraudulent account. For example, if the target account 260 has transferred money to the intermediary account 220 twice in the past, the storage unit 150 may store the number of transfers from the target account 260 as history information "2." If the target account 260 currently transfers money to the intermediary account 220 four times, the storage unit 150 may store the number of transfers from the target account 260 as latest information "4." The remittance activity detection system 10 may compare the history information "2" with the latest information "4" and calculate the correlation between the history information and the latest information based on the comparison result. Furthermore, the determination unit 134 may generate, for example, a first vector consisting of remittance destinations and remittance amounts as history information on deposits and withdrawals over a predetermined period in the past, and a second vector consisting of remittance destinations and remittance amounts as history information on deposits and withdrawals over a most recent predetermined period. Next, the judgment unit 134 may calculate the correlation degree based on the inter-vector distance between the first vector and the second vector, and determine whether the correlation degree is greater than or equal to a predetermined value to determine whether the account is fraudulent.

[0045] Furthermore, if the historical information and the latest information match, the remittance activity detection system 10 may calculate the correlation degree as "1." However, if the historical information and the latest information do not match, the remittance activity detection system 10 may calculate the correlation degree as "0." However, the method for calculating the correlation degree in this embodiment is not limited, and if the historical information and the latest information include multiple pieces of information (e.g., the number of deposits and withdrawals, the deposit and withdrawal amounts, the number of deposit and withdrawal accounts, and the deposit and withdrawal frequency), the correlation degree may be calculated using a calculation method preset by the owner of the remittance activity detection system 10. After calculating the correlation degree, the determination unit 134 may determine whether the account is a fraudulent account by comparing the correlation degree calculated by the remittance activity detection system 10 with a threshold preset by the owner of the remittance activity detection system 10. For example, if the calculated correlation degree is higher than the preset threshold, the account may be determined to be a fraudulent account. Conversely, if the calculated correlation degree for an account is lower than the preset threshold, the account may be determined to be a general account.

[0046] The above is an example of identifying fraudulent accounts according to this embodiment. However, the method of identifying fraudulent accounts is not limited to this, and fraudulent accounts may be identified by detecting suspicious transactions based on account information and deposit and withdrawal information.

[0047] <Operation> Hereinafter, the operation of the remittance detection program for each embodiment will be described.

[0048] FIG. 6 is a flowchart of a first example of the embodiment shown in FIG. 3. As shown in FIG. 6, server 100 acquires account information and deposit / withdrawal information from multiple financial institution terminals 200 (step S601). Server 100 may store the account information and deposit / withdrawal information acquired from financial institution terminals 200 in storage unit 150. Next, server 100 determines whether or not there is an account that serves as a collection point for deposits and withdrawals based on the deposit / withdrawal information for each account (step S602). If there is an account that serves as a collection point for deposits and withdrawals (YES in step S602), identification unit 133 identifies the account that serves as a collection point for deposits and withdrawals as a fraudulent account (step S603). Finally, server 100 shares information about the fraudulent account identified by identification unit 133 with other financial institutions (step S605). On the other hand, if there is no account that serves as a collection point for deposits and withdrawals (NO in step S602), identification unit 133 identifies each account acquired from financial institution terminal 200 as a general account (step S604).

[0049] Fig. 7 is a flowchart of a second example of the embodiment shown in Fig. 4. As shown in Fig. 7, server 100 first acquires account information and deposit / withdrawal information related to the account information from multiple financial institution terminals 200 (step S701). Server 100 then determines whether there is an account to which a deposit or withdrawal is to be made to the fraudulent account stored in memory unit 150, based on the account information and deposit / withdrawal information acquired from financial institution terminal 200 (step S702). The information about fraudulent accounts stored in memory unit 150 may include, but is not limited to, information about fraudulent accounts previously identified by identification unit 133, and may also include information about fraudulent accounts shared from an external terminal such as financial institution terminal 200.

[0050] Next, if there is an account that deposits or withdraws money from the fraudulent account stored in memory unit 150 (YES in step S702), identification unit 133 may identify the account that deposits or withdraws money from the fraudulent account stored in memory unit 150 as a fraudulent account (step S703). Conversely, if there is no account that deposits or withdraws money from the fraudulent account stored in memory unit 150 (NO in step S702), identification unit 133 may identify the account corresponding to each account information acquired from financial institution terminal 200 as a general account (step S703). The accounts that deposit or withdraw money from the fraudulent account according to this embodiment may include an account that is attempting to transfer money to an account that may have been fraudulently used and that identification unit 133 has previously identified, an account to which money has been transferred from an account that may have been fraudulently used and that identification unit 133 has previously identified, accounts held by multiple financial institution terminals 200 that are attempting to transfer money to an account that may have been fraudulently used, and accounts held by multiple financial institution terminals 200 to which money has been transferred from an account that may have been fraudulently used. Finally, the server 100 shares information about the fraudulent account identified by the identification unit 133 with other financial institutions (step S705).

[0051] Fig. 8 is a flowchart of a third example embodiment of the present embodiment shown in Fig. 5. As shown in Fig. 8, server 100 acquires deposit and withdrawal information for each account from financial institution terminal 200 (step S801). As an example, server 100 may acquire from financial institution terminal 200 the destination of each account, the name of the person requesting the transfer, the number of deposits and remittances, the amount of deposits and remittances, the number of accounts that have received and remitted funds, the frequency of deposits and remittances, etc. as deposit and withdrawal information.

[0052] After acquiring the deposit and withdrawal information for each account from the financial institution terminal 200, the determination unit 134 compares it with the history information indicating the deposit and withdrawal history of the account stored in the storage unit 150 (step 802). After comparing the latest information with the history information stored in the storage unit 150, the determination unit 134 calculates the degree of correlation between the latest information and the history information based on the comparison result (step S803). The method of calculating the degree of correlation in this embodiment is not limited, and may be freely set by the owner of the remittance activity detection system 10.

[0053] Next, after calculating the degree of correlation, the determination unit 134 compares the degree of correlation with a threshold value for determining whether the account is fraudulent (step S804). If the degree of correlation calculated by the determination unit 134 is higher than a predetermined threshold value (YES in step S804), the determination unit 134 may determine the account as a fraudulent account (step S805). Finally, the server 100 shares information about the fraudulent account determined by the determination unit 134 with other financial institutions (step S807). Conversely, if the degree of correlation calculated by the determination unit 134 is lower than the predetermined threshold value (NO in step S804), the determination unit 134 may determine the account as a general account (step S806).

[0054] The above are operational examples of three embodiments of the remittance activity detection system 10 according to this embodiment. The operational examples and embodiments of the server 100 are not limited to these, and an information analysis unit for further analyzing deposit and withdrawal information may be provided. Meanwhile, identical or equivalent components, processes, and signals shown in each drawing are given the same reference numerals, and redundant explanations will be omitted where appropriate. Also, some components that are not important for explanation will be omitted in each drawing.

[0055] <Supplementary explanation> Although the server 100 according to the embodiment has been described above, it goes without saying that the present invention is not limited to the above embodiment. Various modifications will be described below.

[0056] (1) In the above embodiment, the remittance activity detection system 10 may be used for money laundering, but may also be utilized for investment fraud and side job fraud. As an example, the server 100 can extract the number of remittances, the remittance amount, and the number of accounts to which remittances have been made from the deposit and withdrawal information acquired from the financial institution terminal 200. In this case, the identification unit 133 may designate the target account for remittances as an "investment account" or a "side job account" based on the number of remittances, the remittance amount, and the number of accounts to which remittances have been made. If the server 100 receives a request to freeze the "investment account" or "side job account" from an external terminal including the financial institution terminal 200, the server 100 may identify the "investment account" or "side job account" as a fraudulent account.

[0057] (2) In the above embodiment, the remittance activity detection system 10 may periodically acquire account information and deposit and withdrawal information from the financial institution terminal 200 and update the information stored in the memory unit 150. As an example, the server 100 may acquire account information and deposit and withdrawal information related to the account from the financial institution terminal 200 on a monthly basis. In this case, the server 100 infers the account holder's transaction habits based on the deposit and withdrawal information acquired each month. The transaction habits in this embodiment may be the account holder's transaction habits, such as "when does the account holder make transactions (frequency)?", "how many times does the account holder make transactions each month (frequency)?", and "how much does each transaction amount (deposit and withdrawal tendency)?". The server 100 may determine whether or not a fraudulent transaction has occurred based on the account holder's transaction habits.

[0058] (3) In the above embodiment, the remittance activity detection system 10 may detect fraudulent transactions by targeting short-term deposit and withdrawal activities. As an example, the server 100 may determine transaction trends based on the number or frequency of remittances made by an account holder over a certain period of time, and the remittance amount. For example, if an account holder remits a large amount of money multiple times (two or more times) within one hour, the server 100 may determine that the account holder is suspected of committing fraudulent transactions. As another example, if the server 100 detects an account that has received and remitted money intensively over several days, the identification unit 133 may identify the account as one that may be subject to fraudulent use.

[0059] (4) In the above embodiment, the remittance activity detection system 10 may detect the presence or absence of fraudulent transactions based on information on deposit and withdrawal destinations obtained from the financial institution terminal 200. As an example, if an account that has previously frequently conducted transactions with "Mr. A" suddenly starts making deposits and withdrawals to accounts in the names of "Mr. B," "Mr. C," etc., the server 100 may identify that account as one that may be subject to fraudulent use.

[0060] (5) In the above embodiment, the remittance activity detection system 10 may identify financial institutions that frequently conduct fraudulent transactions based on account information and deposit and withdrawal information related to the account obtained from the financial institution terminal 200, and information on frozen accounts obtained from other external terminals (e.g., terminals of the Tokyo Metropolitan Police Department, etc.). In this case, the server 100 may identify accounts that deposit and withdraw funds from financial institutions that frequently conduct fraudulent transactions as accounts that may be subject to fraudulent use.

[0061] (6) In the above embodiment, the remittance activity detection system 10 may identify an account that has made a deposit into an account that serves as a collection point for deposits based on deposit and withdrawal information as a victim account of a fraudulent act such as a bank transfer fraud. As an example, if the identification unit 133 identifies an account that serves as a collection point for deposits as a fraudulent account, the remittance activity detection system 10 may identify an account that will be used to deposit money into this fraudulent account as a victim account. Furthermore, if the account of a person who has been defrauded is included among the accounts that will be used to deposit money into the fraudulent account, the financial institution may cancel the deposit process from that person's account to the fraudulent account or provide some kind of compensation to the fraud victim.

[0062] (7) In each of the above examples, the remittance detection program according to this embodiment may be implemented in an object-oriented programming language such as ActionScript, JavaScript (registered trademark), Python (registered trademark), C, C++, C#, or Java (registered trademark).

[0063] (8) In the above examples, in the remittance detection method, remittance detection program, and control procedures according to this embodiment, particularly the processing procedures explained using flowcharts and block diagrams, the processing methods and procedures may omit parts, add new parts, or substitute or change the order of steps. Processing procedures with such omissions, additions, or changes in order are also included in the scope of this disclosure as long as they do not deviate from the spirit of this exhibition. [Explanation of symbols]

[0064] 10. Money transfer detection system 100 servers 200A Financial Institution Terminal A 200B Financial institution terminal B 200C Financial institution terminal C 200 Financial institution terminals 110 Communications Department 120 Input section 130 Control Unit 131 Account Information Acquisition Department 132 Deposit / withdrawal information acquisition department 133 Specific part 134 Judgment section 135 Encryption section 140 Output section 150 Storage section 210 First Account 220 Intermediate Account 230 Second Account 240 A Account 250 B account 260 target accounts

Claims

1. an account information acquisition unit that acquires account information from a plurality of financial institutions; a deposit / withdrawal information acquisition unit that acquires deposit / withdrawal information of the plurality of account information; an identification unit that determines whether or not there is a possibility that the account has been fraudulently used based on the deposit and withdrawal information and the account information, and identifies the account as an account that may be fraudulently used if it is determined that there is a possibility that the account has been fraudulently used; an output unit that outputs information about the account that may be fraudulently used to the plurality of financial institutions; a storage unit that stores the account information, the deposit and withdrawal information, and information on the account that may be subject to fraudulent use. Remittance activity detection system.

2. The identification unit Based on the deposit and withdrawal information, an account that is at least one of an account that is a collection point for withdrawals and an account that is a collection point for deposits is identified as an account that may be subject to fraudulent use. The remittance activity detection system according to claim 1 .

3. The identification unit Based on the deposit and withdrawal information acquired by the deposit and withdrawal information acquisition unit, the following accounts are identified as potentially fraudulent accounts: an account to which money is to be transferred to an account previously identified by the identification unit that may be fraudulently used; an account to which money has been transferred from an account previously identified by the identification unit that may be fraudulently used; an account held by a plurality of financial institutions to which money is to be transferred to an account previously identified that may be fraudulently used; and an account held by a plurality of financial institutions to which money has been transferred from an account previously identified that may be fraudulently used. The remittance activity detection system according to claim 1 .

4. The remittance activity detection system comprises: a determination unit that compares the deposit and withdrawal information of the account with history information that indicates the deposit and withdrawal history of the account stored in the storage unit, calculates a correlation between the deposit and withdrawal information and the history information based on the comparison result, and determines whether or not there is a possibility that the account may be fraudulently used, The determination unit determines that the account is an account that may be subject to fraudulent use if the degree of correlation is higher than a predetermined threshold, and determines that the account is not an account that may be subject to fraudulent use if the degree of correlation is lower than a predetermined threshold, The identification unit identifies an account that the determination unit has determined to be potentially subject to fraudulent use. The remittance activity detection system according to claim 1 .

5. The remittance activity detection system comprises: and an encryption unit that encrypts the account information acquired from the plurality of financial institutions.

5. The remittance activity detection system according to claim 1, wherein:

6. The computer, an account information acquisition step of acquiring account information from a plurality of financial institutions; a deposit / withdrawal information acquisition step for acquiring deposit / withdrawal information of the plurality of account information; a step of determining whether the account may be fraudulently used based on the deposit / withdrawal information and the account information, and identifying the account as an account that may be fraudulently used if it is determined that the account may be fraudulently used; an output step of outputting information about the accounts identified in the identification step that may be subject to fraudulent use to the plurality of financial institutions; a storage step of storing the account information, the deposit and withdrawal information, and information regarding the account that may be subject to fraudulent use. A method for detecting remittance activity.

7. On the computer, Account information acquisition function that acquires account information from multiple financial institutions, a deposit / withdrawal information acquisition function for acquiring deposit / withdrawal information of the plurality of account information; a function of determining whether the account is likely to be fraudulently used based on the deposit and withdrawal information and the account information, and identifying the account as an account that may be fraudulently used if it is determined that the account is likely to be fraudulently used; an output function that outputs information about the accounts identified by the identification function that may be fraudulently used to multiple financial institutions; a storage function for storing the account information, the deposit and withdrawal information, and information regarding the account that may be subject to fraudulent use; Money transfer detection program.

Citation Information

Patent Citations

  • Financial account management system

    JP2019057184A

  • Notification system and method of notifying financial institution of account information

    JP2021163056A

  • Management apparatus, financial institution terminal, and management method

    WO2022244129A1

  • Fraudulent money transfer prevention method and fraudulent money transfer prevention system

    JP2016170761A

  • Illegal financial transaction detection program

    JP2021144356A