Cybera
Cybera sells banks, crypto platforms and cyber insurers two products aimed at authorised payment scams. Mule Intelligence feeds verified accounts and wallet addresses used by scammers into an institution's existing fraud and compliance systems so outgoing payments can be blocked in real time and mule accounts inside its own customer base surfaced, with the intelligence gathered from active defence operations, victim reports and law enforcement collaboration rather than inferred from behaviour, which the company calls non probabilistic.
Scam Response handles the aftermath: a victim reports online and within minutes the case is dispatched to law enforcement, beneficiary banks and exchanges, with a dedicated team managing victim communications on the institution's behalf. The company claims recovery chances improve up to tenfold.
Capability Axes
Capability grades
15 of 15 axes rated · 9 graded A or B
The company describes an artificial intelligence driven compliance watchlist generating over 300 daily high risk fraud and scam indicators, and models plainly do work in processing scam reports and identifying patterns across mule networks. Held at B because the defining asset is not modelled.
Its intelligence is described as verified and non probabilistic, sourced from active defence operations, victim reports and law enforcement collaboration, which is human intelligence gathering, and stripping the models would leave a curated mule account watchlist and a case dispatch service that institutions would still buy. The differentiation is the sourcing, not the inference.
The division of labour is clean and stated. The intelligence product does not decide anything, feeding verified matches into an institution's existing fraud and compliance systems so those systems block outgoing payments, which leaves the decision and its governance with the bank that already owns it.
On the response side, case dispatch to authorities is automated for speed, which is the right thing to automate because recovery depends on hours, while a dedicated human team manages victim communications rather than automating contact with someone who has just lost money. What is absent is any description of review before an account enters the feed.
An accuracy figure is published at 99 percent, and unusually the method behind it is described rather than asserted, with intelligence drawn directly from real scammer activity and interactions through active defence operations rather than inferred, which is what the non probabilistic claim rests on. That is a coherent and testable position.
What is missing is the verification procedure itself: nothing states what evidence qualifies an account as confirmed, who reviews it, how the 99 percent was measured or against what ground truth, and for a product whose output brands specific accounts as criminal that methodology is the disclosure that matters most.
Output volume is quantified and continuous, with thousands of newly identified mule accounts and wallet addresses delivered monthly and a watchlist carrying more than 300 daily indicators, alongside claimed intelligence accuracy of 99 percent and up to tenfold improvement in recovery chances.
Two partnerships are named, one a blockchain investigation firm staffed by former law enforcement officers and legal experts providing priority asset tracing and free recovery assessments, the other a victim support charity. The company has operated since 2020 and raised around 11 million dollars across several rounds. No financial institution, exchange or insurer is named as a customer.
Pooling is inherent to the model and partially disclosed, since intelligence is stated to come from victim reports and law enforcement collaboration, which means a scam suffered by one institution's customer produces watchlist entries used by every other subscriber.
That is the mechanism's value and it is also the unaddressed question: nothing states what an institution contributes when it uses the response service, whether victim report details beyond the receiving account enter the shared feed, what consent victims give, or how long entries persist.
No data protection agreement, retention schedule, subprocessor list or deletion commitment was located, and the holdings on both sides of the product are sensitive. Victim reports contain the circumstances of a financial loss along with personal and account details, and the intelligence feed identifies specific bank accounts and wallets as belonging to scammers, which is an assertion about named individuals distributed to many institutions. Neither the handling of the first nor the governance of the second is described.
No attestation, certification, trust centre or enumerated framework was located, though a secure investigation portal is referenced. Banks and exchanges are the intended buyers and both gate any system receiving customer scam reports through supplier assessment, so the review has occurred privately while nothing is published for a prospective institution to examine.
A national cybercrime reporting centre is named as a dispatch destination, which is a channel rather than a supervisor, and compliance is referenced generically as helping institutions meet evolving anti money laundering and fraud prevention standards.
The notable omission is the regime that most directly drives demand for this product: authorised push payment fraud now carries mandatory reimbursement obligations in some markets, which transforms scam losses from a customer misfortune into a bank liability, and neither that framework nor any supervisor is named.
The central design claim is a fairness argument and a good one. Intelligence is described as verified and non probabilistic, meaning accounts are identified as mules through direct observation rather than scored by behavioural pattern matching, and probabilistic scoring is precisely what produces the everyday harm in fraud control, namely blocked payments and frozen accounts belonging to people whose only offence is transacting unusually. Confirmed intelligence should catch fewer of them.
The counterweight is serious and unaddressed: being listed as a mule account is a severe designation with lasting banking consequences, mule accounts are frequently held by coerced, deceived or recruited people who are themselves victims of a different crime, and nothing published describes how a listing is contested, reviewed or removed.
This is the rare vendor whose second product is recourse. Victims report online and within minutes cases are dispatched to law enforcement, beneficiary banks and exchanges, a dedicated team manages their communications, and the company guides them through reporting to reduce the delays that make recovery impossible, with a partner providing free asset recovery assessments and priority tracing. That directly addresses the affected individual, which almost nothing else in this index does. Two things hold it at B: no service commitment or guarantee attaches to any of it, and the recourse gap runs the other way for anyone wrongly listed as a mule, who has no described route at all.
Sources are named by type rather than left implicit, with intelligence attributed to active defence operations, victim reports and law enforcement collaboration, which tells a buyer that the feed depends on operational capability and institutional relationships rather than on purchased data. Two partners are identified, a blockchain investigation firm and a victim support organisation, so the recovery chain is partially visible. No underlying model provider, blockchain analytics supplier or hosting arrangement is disclosed, and no subprocessor list was located.
The architecture is deliberately additive rather than replacing anything, with a programmable interface delivering matches in real time into the fraud and compliance systems an institution already runs, which is the right shape for an intelligence product since no bank will swap its detection stack to consume a feed. A secure portal supports investigation teams working suspicious entities directly. Integration is claimed across both banking and crypto exchange risk systems. No named platform, vendor or system appears and no developer documentation was located.
No hosting provider, region selection, residency commitment or private deployment option was located. The service is inherently cross border, dispatching cases to agencies and beneficiary institutions worldwide and distributing intelligence to subscribers in many jurisdictions, which makes the absence of any statement about where victim reports and account intelligence are held more consequential than for a single market vendor.
No pricing, packaging or basis of charge was located for either product. The two differ commercially in kind, one being a continuously refreshed intelligence feed and the other a managed service with staff handling victim communications, and nothing describes whether the second is priced per case, per institution or by volume, which is the question a fraud team would need answered before committing to outsourced victim handling.
Three buyer types are served and the third is unusual: banks, crypto exchanges and virtual asset service providers, and cyber insurance providers, the last of which sits at the point where scam losses become claims. Reach is genuinely international, with published case examples spanning India, the United States, England, France and Nigeria, and the response product dispatches to a national cybercrime reporting centre alongside global agencies. Coverage is deliberately narrow in subject, addressing authorised payment scams and the mule networks that receive the money rather than fraud generally.
Alternatives to Cybera
The closest documented capability profiles to Cybera in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents Commercial Transparency and Regulatory Status and Licensure where Cybera does not
Stronger documented coverage on AI Centrality
Stronger documented coverage on AI Centrality
Documents AI Safety and Data Stewardship where Cybera does not
Stronger documented coverage on Institution and Segment Coverage
Documents Regulatory Status and Licensure where Cybera does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.