Fraud Prevention & AI-Abuse Analyst / Berlin

I find the abuse, prove it, and don't break the legitimate customers doing it.

legitimate flagged ring

Six years turning messy data into clear, defensible enforcement decisions — across cloud, fashion, automotive, and energy. Now at AWS Payments & Fraud Prevention, building LLM-powered investigation agents, detection systems, and the tooling they run on. The hard part was never catching abuse. It's catching it without punishing the people who weren't committing any.

6+ yrs
In fraud, risk & abuse
4 sectors
Cloud · fashion · auto · energy
3 langs
Arabic · German · English
Scroll
Interactive — the tradeoff, live

Anyone can catch more abuse. The craft is the cost of catching it.

Move the detection threshold. Catching more abuse is easy — drag it up and watch recall climb. The hard part is the second bar: every step too far flags real customers. The job is living in the narrow band where one is high and the other is near zero.

Abuse caught
86%
Legitimate customers flagged
2.4%
Lenient Aggressive

Selected work

A few that show the shape of it.

All 17 cases
  1. 01
    AWS Ring detection · graph analysis

    Making fraud rings visible in a whole population

    A seedless graph that loads an entire account population and lets coordinated rings fall out as clusters — without dragging legitimate customers in with them.

    Read the case
    Whole-population relations graph
    100% of a known ring in one cluster
    flagged ring legitimate broker
    Hover a node to isolate its component; toggle to strip the legitimate population and leave only the rings. Representative shape — the live graph runs on confidential data.

    Edges are hard shared signals weighted by excess-purity-over-base-rate × IDF; brokers are high-betweenness accounts bridging two rings.

  2. 02
    AWS Root-cause investigation

    Tracing six-figure compute abuse to a single regex gap

    A multi-six-figure SageMaker abuse incident that the enforcement layer should have stopped — traced to one newer instance family missing from a containment-score regex.

    Read the case
    Instance families the c-score regex governs 6/7 covered
    • Family A
    • Family B
    • Family C
    • Family D
    • Family E
    • Family F
    • Newer family gap
    Every governed family matched the threshold regex — except one newer family, which matched nothing and took the default zero-limit path straight past enforcement.
  3. 03
    AWS Investigation infrastructure

    The data platform that made the investigations possible

    A home-grown data-access layer that unifies two heterogeneous Redshift clusters behind one API and pays the SAML handshake once — turning a multi-second wait per query into a tenth of a second.

    Read the case
    Per-query latency -90%
    Cold (handshake each time)
    ~3.9s
    Warm daemon
    ~0.4s
    A persistent Unix-socket daemon pays the SAML handshake once per investigation.
  4. 04
    AWS False-positive prevention

    Catching rings without breaking the customers next to them

    Bulk shutdowns are the bluntest instrument in fraud prevention. I built the carve-out gates and false-positive anchors that let them stay sharp — catching rings while sparing the legitimate accounts caught in the blast radius.

    Read the case
    A bulk ring action, with carve-out gates
    Ring accounts actioned Ring caught
    Legitimate accounts wrongly shut ≈ 0 collateral
    Hard-identifier-only matching + a pre-action legitimate-impact carve-out keep real customers out of the wave.
View every case

German-Jordanian, Berlin-based. I build the infrastructure, the methodology, and the deliverables — and hold all three to a standard where a caught assumption is the point, not an embarrassment.