Two credit accounts land on a risk analyst's desk in the same month. Both sit near their respective limits. Both have stopped paying. Both are sliding into delinquency. On this month's statement, they are indistinguishable.

One is a family that lost an income and is drowning. The other is a fraudster who spent half a year building a spotless record so the line would be raised, and has now drawn every available dollar with no intention of paying it back.

Freeze the wrong one and you either let a fraud loss run to charge-off, or you slam the line on a struggling borrower at the worst possible moment. This is the problem behind [bustout detection (https://github.com/gbadedata/bustout-detection), and it is the latest in a short series about fraud signals that are not what they first appear. The first was a card-fraud ring that turned out to be an artefact of the data. The second (https://github.com/gbadedata/mule-network-detection) was a money mule the graph flagged, and the evidence did not support. This one is the opposite trap: the fraud that hides by looking like your best customer, and the struggling borrower a lazy model would punish in its place.

What a bust-out is

Bust-out is first-party fraud, and it is the expensive kind. There is no stolen card and no victim to call. The account holder is the fraud. The pattern runs in three acts.