Review Prompt to Hunt Impossible-Travel Fraud Ring Velocity
This **Luna** review prompt takes 180 days of verification history and the ring-velocity pattern from the 2026 fraud data, then hunts the movements no passport can make. Luna, the deepidv compliance overseer, flags every **asset velocity** event where a document fingerprint, face template match, or device identifier appears in two or more countries within a 24-hour window, computes **impossible travel** against minimum feasible travel time, performs **cluster expansion** to pull every account sharing an impossible-travel asset's fingerprints, devices, or infrastructure into a candidate ring graph, runs an **exposure assessment** summing approved accounts, transaction volume, and outstanding balances per cluster, and drafts the **compliance output**, a suspicious activity narrative with the velocity evidence attached, for clusters over your risk threshold. Built for fraud and AML teams who need to convert the ring economy's sub-ten-minute cross-border hops into a ranked, filing-ready register.
How to use this prompt
- 1
Open Luna in the deepidv dashboard and paste the full prompt, or run it in Claude, ChatGPT, or Gemini if you are scoping the velocity review outside the platform.
- 2
Replace the INPUT section with your verification history window, your geolocation data, and your fingerprint and device identifiers.
- 3
Run the prompt and read the ranked ring register first, ordered by shortest cross-border interval and per-cluster confidence.
- 4
Route clusters over your risk threshold to the SAR drafter with the velocity evidence attached, and hold or restrict the highest-confidence accounts where regulation allows.
- 5
Schedule the review weekly and read the deltas against the prior run so a forming ring is caught while it is still small.
The prompt
Luna, run a cross-border velocity review across our verification history. Context: 2026 industry data shows fraud ring assets appearing in different countries an average of 9 minutes 33 seconds apart, with observed intervals as short as 38 seconds. Physical travel cannot do this; credential sharing across a ring can. Analyze the last 180 days of sessions: 1. Asset velocity: flag every document fingerprint, face template match, or device identifier that appears in two or more countries within a 24-hour window, ranked by shortest interval. 2. Impossible travel: within each flagged pair, compute minimum feasible travel time between the geolocations and mark intervals below it. 3. Cluster expansion: for each impossible-travel asset, pull every account and session sharing its fingerprints, devices, or network infrastructure, and assemble the candidate ring graph. 4. Exposure assessment: sum the approved accounts, transaction volume, and outstanding balances attached to each candidate ring. 5. Compliance output: for clusters exceeding our risk threshold, draft the suspicious activity narrative with the velocity evidence attached, ready for filing-window review. Deliver a ranked ring register with per-cluster confidence scores, and schedule this review weekly with deltas against the prior run.
Test it in Claude or another LLM
This prompt is built for the Luna agent inside deepidv, where Luna correlates a firm's real verification history against velocity thresholds. You can dry-run the analysis shape in any general LLM first with synthetic session data before running it live.
- 1
Paste the full prompt into Claude, ChatGPT, or Gemini, but replace the opening 'Luna,' with a role instruction such as 'Act as a cross-border fraud velocity analyst reviewing a verification archive.' Keep the OUTPUT sections exactly as written.
- 2
Under the INPUT section, paste the synthetic sample block below so the model has assets, geolocations, and timestamps to analyze.
- 3
Add one framing line: 'This is synthetic test data. Where feasible travel time cannot be computed from the input, flag the pair rather than assuming impossibility.'
- 4
Check the output shape: a ranked velocity register, impossible-travel flags, candidate ring graphs, exposure per cluster, and drafted SAR narratives. If a cluster is asserted without shared-asset evidence, tighten the framing line and re-run.
- 5
Once the output shape is right, run it live in the deepidv dashboard where Luna analyzes your real verification history.
Synthetic sample data to paste alongside the prompt
Fake test data, safe to share with any LLM. Swap in your own once the output looks right.
SESSIONS (synthetic, fake): 180 days, ~500k checks with document fingerprint, face template id, device id, geolocation, timestamp VELOCITY HITS (fake): document DOC-9931 appears in Lagos and Manila 41 seconds apart; device DEV-118 anchors 16 sessions across 3 countries GEO DATA (fake): country and city per session RISK THRESHOLD (fake): cluster of 3+ accounts sharing an impossible-travel asset OPEN ITEM (fake): a pair whose two geolocations are ambiguous and cannot yield a feasible-travel estimate
Pairs with on deepidv
Sources & further reading
FAQ
What is cross-border asset velocity in fraud detection?
It is the reappearance of the same identity asset, a document, face, or device, in different countries faster than a person could travel between them. In 2026 industry data, ring assets appeared in different countries an average of 9 minutes 33 seconds apart, with intervals as short as 38 seconds, a signature of credential sharing across a ring rather than real travel.
What does this prompt produce?
A ranked register of impossible-travel assets, each expanded into a candidate ring graph of the accounts and sessions sharing its fingerprints or infrastructure, an exposure figure per cluster, and a drafted suspicious activity narrative with the velocity evidence attached for clusters over your risk threshold.
Can I run this outside the deepidv dashboard?
Yes. The structure works in Claude, ChatGPT, or Gemini as a velocity-analysis framework. Running it against your real verification history, geolocation, and device fingerprints, and drafting filing-ready SAR narratives from them, only happens inside the deepidv dashboard through Luna.
Related prompts
Run it with live verification data
These prompts work in any LLM. Inside the deepidv dashboard, Luna, Arbiter, and Arc run them against your real sessions, screening lists, and audit trails.
Book a Demo