Share fraud intelligence under APRA CPS 234 and RBNZ guidance to meet information security and operational resilience obligations across AU and NZ.
Participate in the ECB's FRIDA initiative and share fraud data with the Banque de France using FNC-RF for fraud typology, mule account reporting, and anonymised fraud indicators across EU member banks.
Meet FCA operational resilience requirements by reporting APP fraud, account takeovers, and emerging threats.
Share fraud intelligence with central banks across the GCC region to support regulatory compliance and regional fraud prevention.

Assess your current state and design a fraud data sharing roadmap aligned to your regulatory obligations.
Deploy and configure CloudMISP with sharing groups, taxonomies, and integrations tailored for fraud data.
Meet APRA, FCA, ECB, and other regulatory fraud reporting requirements with automated, structured data exchange.
Establish trusted bilateral sharing channels with partner banks for real-time fraud indicator exchange.
Launch and operate a fraud intelligence sharing community for your region or sector.
Connect MISP to your fraud management platforms, transaction monitoring, and case management systems.
Fraud data sharing is the structured exchange of fraud indicators, typologies, and intelligence between financial institutions, regulators, and industry groups. It enables banks to collectively detect and prevent fraud by sharing information about known fraudsters, mule accounts, emerging attack patterns, and suspicious transactions in a standardised, machine-readable format.
Fraudsters target multiple banks simultaneously, but each bank typically detects fraud in isolation. Without shared intelligence, a fraudster blocked by one bank simply moves to the next. Sharing fraud data means banks can see threats detected by peers before they strike, block mule accounts across institutions in near real-time, meet growing regulatory requirements for fraud reporting, and reduce fraud losses collectively rather than individually.
We specialise in MISP (Malware Information Sharing Platform), the world's leading open-source threat intelligence sharing platform. Through MISP, we can connect you to regulatory sharing frameworks (APRA, ECB FRIDA, FCA, SAMA), peer-to-peer sharing groups with other banks, industry sharing communities (ISACs, sector-specific groups), and commercial threat intelligence feeds. We also integrate MISP with your existing fraud tools — SAS, NICE Actimize, Featurespace, Splunk, and others.
MISP (Malware Information Sharing Platform) is the world's most widely used open-source platform for sharing, storing, and correlating threat intelligence and fraud indicators. Originally developed for cyber threat intelligence, MISP is now used extensively by central banks, financial regulators, and banking communities for fraud data sharing. Cosive is a contributor to MISP and operates CloudMISP, a fully managed MISP hosting service.
CloudMISP is Cosive's fully managed MISP hosting service. Instead of deploying and maintaining your own MISP instance, CloudMISP gives you a dedicated, production-ready platform with automated updates, backups, monitoring, and support. It's pre-configured with fraud-specific taxonomies, sharing groups, and integrations so you can start sharing fraud data immediately without the operational overhead of running the infrastructure yourself.
Most organisations can be up and running with a CloudMISP instance within a few weeks. The initial platform deployment is fast — the majority of the time is spent on scoping your sharing requirements, configuring taxonomies and sharing groups to match your regulatory obligations, and connecting integrations to your existing fraud tools. For peer-to-peer or community sharing, timelines depend on the number of partner institutions being onboarded.
Yes. MISP provides granular controls over who can see what through its distribution levels and sharing groups. You decide exactly which organisations receive your data, and can restrict sharing at the event, attribute, or object level. Data is encrypted in transit and at rest, and sharing agreements govern how recipients may use the intelligence. You retain full control over your contributions at all times.
MISP supports a wide range of fraud-relevant indicator types including mule account details, suspicious transaction patterns, fraudster identifiers, device fingerprints, IP addresses, phishing URLs, and fraud typology descriptions. Cosive configures your instance with fraud-specific object templates and taxonomies so indicators are structured, searchable, and machine-readable — ready to feed directly into your detection and monitoring systems.

Tell us about your fraud data sharing goals and we'll get back to you.
Pipedrive form will go here.