
- 01Mobile app shielding (RASP, anti-tampering, device-fingerprint binding) is mature and measurable. Alexa Research analyzed fraud loss data across six banks deployed with our orchestrated stack between 2024 and 2025.
- 02What we measured: account takeover incidents per 100k active users monthly, money-mule activity flagged at session start, repackaged-app installs reaching authentication, direct fraud losses attributable to mobile attack vectors.
- 03What we found: 38% average reduction in mobile-attributable fraud losses over 18 months, 84% reduction in repackaged-app authentication attempts (most benefit comes from making simple attacks unviable), 24% decline in account takeover via SIM swap (device-binding adds a second factor that survives SIM swaps).
- 04What does not improve: social engineering attacks where the customer authorizes the fraudulent transaction themselves. That requires customer-facing controls (anomaly detection, transaction friction, voice-channel verification) — separate from the shielding investment.
Mobile application shielding (RASP, anti-tampering, device-fingerprint binding) is mature technology with measurable impact. Alexa Research analyzed fraud loss data across six banks deployed with our orchestrated mobile shielding stack between 2024 and 2025.
What we measured
- 01Account takeover incidents per 100k active users, monthly
- 02Money mule activity flagged at session start
- 03Repackaged-app installs reaching authentication
- 04Direct fraud losses attributable to mobile attack vectors
What we found
Average reduction in mobile-attributable fraud losses: 38% over 18 months. Reduction in repackaged-app authentication attempts: 84% (most of the benefit comes from making the simple attacks unviable). Account takeover via SIM swap declined 24%, primarily through device-binding adding a second factor that survives SIM swaps.
What does not improve
Social engineering attacks against the customer (the customer authorizing the fraudulent transaction themselves) is unaffected by app shielding. That problem requires customer-facing controls — anomaly detection, transaction friction, voice-channel verification — that are separate from the shielding investment.


