TNG RiskOps Agent

Account takeover operations workspace

21 active investigationsSeeded environment
seed demo-core-v2Seeded demo. Analyst override stays available.

CASE-ATO-001 | A*** H****

Transfer-enabled wallet | Wallet MY-4432 | Kuala Lumpur

Score
92
Recommendation
Freeze Account
Prompt
Simulated
Resolution
Pending User

What happened

Timeline first. Then what was attempted. Then what is still missing.

TimeEventResult
01:58
Login from new device
Android device first seen in wallet history
Completed
02:01
PIN reset completed
Reset from same session
Completed
02:06
High-value transfer attempted
Amount exceeds 30-day average by 8.7x
Blocked
02:07
Freeze action applied
Automatic severe-control path
Completed
Suspicious actions
Transfer attempt | MYR 8,500
Blocked by the action ladder
Missing data
No successful customer contact confirmation yet.

Why this case is high-risk

Keep the proof tight. Facts first, interpretation second, network signals after that.

Facts
Device age is 2 hours.
PIN reset completed 6 minutes before transfer attempt.
Transfer was blocked before completion.
Analyst assessment
The sequence matches a high-confidence account takeover pattern.
Session changes
Account
PIN reset at 02:01
Beneficiary addition at 02:04
Device
First-seen Android device
Location drift overnight
IP signalGeo / ASNFlagsLinked cases
203.153.31.44
Hosting-provider exit node
Seen across two seeded fraud paths inside the same 10-minute window.
Kuala Lumpur, MY
AS45899 Digital Core Network
CRITICALBlocked
CASE-ATO-001, CASE-UTX-204
175.140.84.19
Residential IP with sudden ASN drift
New session moved from normal home broadband to a known hosting route.
Selangor, MY
AS4788 Telekom Malaysia
HIGHWatch
CASE-ATO-001
Linked entityRelationshipRisk note
Android 15 / DEV-772
DEVICE
Shared fingerprint with prior reviewed caseSeen in one resolved unauthorized-transaction investigation
New payee J** L***
BENEFICIARY
Beneficiary added 18 min before transferPayee added in same session as device change
Destination account / ACC-221
ACCOUNT
Receiving account flagged in prior clusterAppeared in CLUSTER-2025-09 mule investigation

Evidence register

Move the bulky cards into a proper table so operators can scan source and policy coverage faster.

EvidenceKindSourcePolicy
New device within 24h
Device DEV-772 first seen 2 hours ago.
FACT
behavior_events
2026-04-25T01:58:00+08:00
POL-ATO-03
PIN reset before transfer
PIN reset occurred 5 minutes before transfer attempt.
FACT
account_changes
2026-04-25T02:01:00+08:00
POL-ATO-03
Transfer amount exceeds baseline
Attempted transfer is 8.7x the 30-day average.
FACT
transactions
2026-04-25T02:06:00+08:00
POL-OPS-04
Critical IP overlap
The session IP overlaps with another seeded fraud case and is already blocked in network controls.
FACT
network_graph
2026-04-25T02:06:30+08:00
POL-ATO-03, POL-OPS-04
ATO sequence is highly coherent
Signals appear in the classic takeover order: login, change, move money.
INFERENCE
ai_explanation
2026-04-25T02:08:00+08:00
POL-ATO-03

Decision rail

Recommended action
Freeze Account
84%
Freeze now, send re-verification, and keep human override visible until identity proof arrives.
Customer prompt
SimulatedAwaiting replySeeded demo prompt
This case is still carrying a seeded demo prompt. Twilio did not send that original message.
Please go to Touch 'n Go to complete relogin / MFA / face recognition. Reply /tng-login once done.
Latest audit
WhatsApp re-verification prompt simulated in seeded demo mode.
PromptService | 2026-04-25T02:08:21+08:00
Freeze applied automatically on high-confidence path.
ActionOrchestrator | 2026-04-25T02:07:11+08:00
Deterministic score computed at 92.
ScoreEngine | 2026-04-25T02:06:30+08:00
Human override