Fraud Data Sharing

We help banks and financial institutions share fraud data securely to detect and prevent suspicious activity faster.

Select your goal

APRA RBNZ

Australian & New Zealand Banks

Share fraud intelligence under APRA CPS 234 and RBNZ guidance to meet information security and operational resilience obligations across AU and NZ.

FRIDA FNC-RF

European Regulated Banks

Participate in the ECB's FRIDA initiative and share fraud data with the Banque de France using FNC-RF for fraud typology, mule account reporting, and anonymised fraud indicators across EU member banks.

FCA OpRes

UK Regulated Banks

Meet FCA operational resilience requirements by reporting APP fraud, account takeovers, and emerging threats.

SAMA CBUAE

Middle Eastern Central Banks

Share fraud intelligence with central banks across the GCC region to support regulatory compliance and regional fraud prevention.

Why work with us

Fraud data sharing expertise you can trust

Trusted by central banks around the world
Operated sharing communities for central banks and financial institutions
Protecting financial institutions against attacks since 2016 with Antifraud
Deep understanding of banking environments and regulations
Chris Horsley presenting at AUSCERT
Cosive co-founder Chris Horsley presenting at AUSCERT.

Fraud data sharing services

Fraud sharing strategy

Assess your current state and design a fraud data sharing roadmap aligned to your regulatory obligations.

Platform deployment

Deploy and configure CloudMISP with sharing groups, taxonomies, and integrations tailored for fraud data.

Regulator compliance

Meet APRA, FCA, ECB, and other regulatory fraud reporting requirements with automated, structured data exchange.

Peer-to-peer sharing

Establish trusted bilateral sharing channels with partner banks for real-time fraud indicator exchange.

Community building

Launch and operate a fraud intelligence sharing community for your region or sector.

Tool integration

Connect MISP to your fraud management platforms, transaction monitoring, and case management systems.

Common questions about fraud data sharing

What is Fraud Data Sharing?
Fraud data sharing is the structured exchange of fraud indicators, typologies, and intelligence between financial institutions, regulators, and industry groups. It enables banks to collectively detect and prevent fraud by sharing information about known fraudsters, mule accounts, emerging attack patterns, and suspicious transactions in a standardised, machine-readable format.
Why is Fraud Data Sharing important?
Fraudsters target multiple banks simultaneously, but each bank typically detects fraud in isolation. Without shared intelligence, a fraudster blocked by one bank simply moves to the next. Sharing fraud data means banks can see threats detected by peers before they strike, block mule accounts across institutions in near real-time, meet growing regulatory requirements for fraud reporting, and reduce fraud losses collectively rather than individually.
What fraud data sharing platforms can you help connect us to?
We specialise in MISP (Malware Information Sharing Platform), the world's leading open-source threat intelligence sharing platform. Through MISP, we can connect you to regulatory sharing frameworks (APRA, ECB FRIDA, FCA, SAMA), peer-to-peer sharing groups with other banks, industry sharing communities (ISACs, sector-specific groups), and commercial threat intelligence feeds. We also integrate MISP with your existing fraud tools — SAS, NICE Actimize, Featurespace, Splunk, and others.
What is MISP?
MISP (Malware Information Sharing Platform) is the world's most widely used open-source platform for sharing, storing, and correlating threat intelligence and fraud indicators. Originally developed for cyber threat intelligence, MISP is now used extensively by central banks, financial regulators, and banking communities for fraud data sharing. Cosive is a contributor to MISP and operates CloudMISP, a fully managed MISP hosting service.
What is CloudMISP?
CloudMISP is Cosive's fully managed MISP hosting service. Instead of deploying and maintaining your own MISP instance, CloudMISP gives you a dedicated, production-ready platform with automated updates, backups, monitoring, and support. It's pre-configured with fraud-specific taxonomies, sharing groups, and integrations so you can start sharing fraud data immediately without the operational overhead of running the infrastructure yourself.
How long does it take to get started?
Most organisations can be up and running with a CloudMISP instance within a few weeks. The initial platform deployment is fast — the majority of the time is spent on scoping your sharing requirements, configuring taxonomies and sharing groups to match your regulatory obligations, and connecting integrations to your existing fraud tools. For peer-to-peer or community sharing, timelines depend on the number of partner institutions being onboarded.
Is shared fraud data kept confidential?
Yes. MISP provides granular controls over who can see what through its distribution levels and sharing groups. You decide exactly which organisations receive your data, and can restrict sharing at the event, attribute, or object level. Data is encrypted in transit and at rest, and sharing agreements govern how recipients may use the intelligence. You retain full control over your contributions at all times.
What types of fraud indicators can be shared?
MISP supports a wide range of fraud-relevant indicator types including mule account details, suspicious transaction patterns, fraudster identifiers, device fingerprints, IP addresses, phishing URLs, and fraud typology descriptions. Cosive configures your instance with fraud-specific object templates and taxonomies so indicators are structured, searchable, and machine-readable — ready to feed directly into your detection and monitoring systems.
Credit cards and banking

Start sharing fraud data

Tell us about your fraud data sharing goals and we'll get back to you.