Surface two — inbound
Check every URL a user or an agent pastes in
The support conversation is where fintech fraud is discovered and where it is frequently completed. A user writes in because a payment failed, and somewhere in that thread a URL appears. It arrives in one of three ways.
- The user pastes the link they received, asking whether it is genuine.
- An attacker who has already compromised the account posts a link into a community thread under a helpful-looking username.
- A well-meaning agent pastes a link from a knowledge-base article that has been stale for eighteen months.
Screening at that moment is the highest-value inbound placement you have, because unlike outbound it also produces intelligence. Every URL a user submits is a report from the field about a campaign currently targeting your customers. Attach a verdict at ingest, and a support queue becomes a live impersonation sensor: cluster the flagged hostnames by day and you can see a campaign starting hours before the complaint volume makes it obvious.
Every place a URL can enter
Instrument the same call in each of them: the in-app support composer, the email support intake, the dispute and chargeback form, the community or forum post editor, and the agent console — so a responder never pastes a link that would fail your own check.
In-app support composer
Email intake
Dispute forms
Community posts
Agent console
Report-a-scam flow
For community platforms, screening at post time rather than on report is what stops the link being live for the three hours before a moderator sees it. The mechanics for that pattern are covered further on our messaging apps and URL shorteners pages.