‹  Research

Case study · Thesis project · Information security

Fraud Monitor

A prototype that reads finance news and public Telegram channels, scores every message for signs of fraud, and hands the suspicious ones to an analyst to confirm or reject.

Status

Open source · prototype

Period

May – June 2026

Stack

FastAPI · scikit-learn · NetworkX · React

Missing a fraud is worse than showing an analyst a borderline post.

Four independent signals, one weighted score. The threshold is set low on purpose: the system surfaces, a person decides.

1Problem

Fraud aimed at bank customers spreads through the same channels as the news about it. The messages repeat a handful of scripts: a card or account “blocked” until you pay, a prize that needs a fee, a call from a fake bank security service asking for an SMS code, fake state payouts, delivery and customs fees, investment and crypto schemes, loans with an upfront fee, fake tech support, and remote jobs that are recruitment scams.

2Task

Build the implementation part of a thesis in information security (10.03.01): a working system that monitors messages and flags likely fraud, with targets of F1 at least 0.68 and precision at least 0.70. Later the priority changed to recall — a missed fraud costs more than an analyst’s click.

3Method

  1. Collect

    Messages come in over a REST endpoint and CSV upload, from RSS feeds of finance press and the central bank, and from public Telegram channels through their web preview.

  2. Clean

    Text is lowercased; links, phone numbers and emails are masked; author ids are stored only as hashes.

  3. Rules

    A list of Russian keyword stems for the scripts above; each hit adds to a rule score.

  4. Classifier

    TF-IDF over character n-grams of 2–4 letters with logistic regression. Character n-grams survive Russian word endings and the Latin-for-Cyrillic letter swaps spammers use.

  5. Training data

    21,853 messages: a public dataset of real Russian Telegram spam, plus about 400 phishing messages generated from templates and 30 hand-written legitimate ads and news items — there is no open Russian phishing dataset.

  6. Author graph

    Authors are linked when their messages trigger the same flags. An author’s score mixes their own worst message, their neighbours’ average and how often they repeat themselves.

  7. Decide

    The four signals combine into one risk score. Anything at 0.2 or above becomes an incident that an analyst confirms or rejects in the web interface.

4Results

14 of 14Hand-picked scam messages caught at the 0.2 threshold; legitimate news and ads scored 0.17 or lower.
0.74 F1On the first small labelled set of 99 messages: precision 0.78, recall 0.70.
0.99 F1On a held-out split of the full dataset. Likely optimistic: part of the positive class is template-generated and resembles itself.
126 testsAcross the pipeline, collectors, scheduler and API.
char_wb n-grams: robust to Russian morphology AND the latin/cyrillic letter-swapping obfuscation that spammers use.app/ml/model.py

5Limitations

  • No real social-network APIs: collection is RSS, public Telegram previews and uploads, chosen for reproducibility.
  • The graph is simple and lives in memory — no centrality or community detection — and only messages sent through the API get a graph score.
  • Fixed weights; no retraining from the analyst’s decisions; no explanation of individual scores.
  • The broad keyword list knowingly flags some legitimate ads and news.
  • The evaluation numbers come from development runs, not a separate, fixed test set.

Sources