Marketplace Fraud Pattern Detection Logs

This synthetic dataset provides detailed, anonymized event logs from online B2B marketplace transactions, capturing session, transaction, device, and behavioral characteristics. It is specifically designed for developing and evaluating AI-driven fraud detection models, enabling compliance teams and operators to identify subtle and complex fraud patterns without exposing real customer data. The dataset supports both supervised and unsupervised machine learning use cases, with rich contextual information for advanced analytics.

  • last updated 20 Jan 2026
  • by GoMask
The brief that made it

Training and testing AI/ML models for marketplace fraud detection

Sample rows

preview · 8 of 72 rows · all 22 columns
event_idstringfraud_labelstringanomaly_scorefloattransaction_idstringevent_timestampdatetimesession_idstringuser_idstringevent_typestringevent_resultstringdevice_idstringdevice_typestringdevice_osstringbrowserstringip_addressstringgeo_countrystringgeo_regionstringgeo_citystringtransaction_amountfloatcurrencystringpayment_methodstringis_syntheticbooleannotesstring
EVT0001normal0.12blank2024-06-01T09:15:32ZSES1001USR001loginsuccessDEV001desktopWindowsChrome192.168.8.11USCaliforniaSan FranciscoblankblankblanktrueNormal login pattern, US desktop
EVT0002normal0.13blank2024-06-01T09:16:10ZSES1001USR001add_to_cartsuccessDEV001desktopWindowsChrome192.168.8.11USCaliforniaSan FranciscoblankblankblanktrueItem added to cart, normal session
EVT0003normal0.14TRX10012024-06-01T09:17:08ZSES1001USR001checkoutsuccessDEV001desktopWindowsChrome192.168.8.11USCaliforniaSan Francisco254.99USDcredit_cardtrueCheckout completed, normal transaction
EVT0004normal0.15TRX10012024-06-01T09:17:23ZSES1001USR001payment_attemptsuccessDEV001desktopWindowsChrome192.168.8.11USCaliforniaSan Francisco254.99USDcredit_cardtruePayment attempt, normal
EVT0005normal0.13TRX10012024-06-01T09:17:27ZSES1001USR001payment_successsuccessDEV001desktopWindowsChrome192.168.8.11USCaliforniaSan Francisco254.99USDcredit_cardtruePayment success, normal
EVT0006normal0.19blank2024-06-02T13:31:58ZSES1002USR002loginsuccessDEV002mobileAndroidChrome10.0.0.21DEBerlinBerlinblankblankblanktrueMobile login from Germany
EVT0007normal0.2blank2024-06-02T13:32:24ZSES1002USR002add_to_cartsuccessDEV002mobileAndroidChrome10.0.0.21DEBerlinBerlinblankblankblanktrueGerman user shopping via mobile
EVT0008normal0.17blank2024-06-02T13:33:12ZSES1002USR002logoutsuccessDEV002mobileAndroidChrome10.0.0.21DEBerlinBerlinblankblankblanktrueLogout, normal

What the 72 rows show

from the 72-row sample

Normal (fraud label) stands out: mean anomaly_score is 0.12, against 0.72 for the rest.

  • 0.13median anomaly_score
  • 3payment methods
  • 4device types
  • 5event results
  • 5browsers
  • 6device oses
Mean anomaly_score by fraud_label72 rows
00.510.12normal62 rows0.64suspicious7 rows0.89fraud3 rows
anomaly_score72 rows, in bands of 0.1
0204021374002411200.51anomaly_score →

Median 0.13, from 0.03 to 0.93.

transaction_id31 rows with a value · 41 left blank
  1. TRX10013
  2. TRX10023
  3. TRX10033
  4. TRX10043
  5. TRX10053
  6. TRX-109b173
  7. TRX-2d6f983
  8. TRX-9f2c173
  9. TRX-7d2f012
  10. TRX-3e1c292
22 columns by typefrom the column list below
  • string 18
  • float 2
  • datetime 1
  • boolean 1

Columns

22 columns in four groups
blueprint · 22 columns
columntypedescriptionexample
Text 18 columns
event_idstringUnique identifier for each event log entryuniqueEVT0001
session_idstringAnonymized unique identifier for the user sessionSES1001
transaction_idstringAnonymized unique identifier for the transaction (if applicable)12 transactions · optionalTRX1001
user_idstringAnonymized unique identifier for the user accountUSR001
event_typestringType of event (e.g., login, add_to_cart, checkout, payment_attempt, account_update, etc.)12 valueslogin
event_resultstringOutcome of the event (e.g., success, failure, suspicious, timeout)success · failure · suspicious · timeout · other · optionalsuccess
device_idstringAnonymized unique identifier for the device used in the sessionDEV001
device_typestringType of device (e.g., desktop, mobile, tablet, unknown)desktop · mobile · tablet · unknown · optionaldesktop
device_osstringOperating system of the device (e.g., Windows, macOS, Android, iOS, Linux, unknown)6 oses · optionalWindows
browserstringBrowser or user agent used in the session (e.g., Chrome, Firefox, Safari, Edge, unknown)5 browsers · optionalChrome
ip_addressstringAnonymized or masked IP address associated with the eventoptional192.168.8.11
geo_countrystringCountry derived from the IP address or device locationoptionalUS
geo_regionstringRegion or state derived from the IP address or device locationoptionalCalifornia
geo_citystringCity derived from the IP address or device locationoptionalSan Francisco
currencystringCurrency code for the transaction (e.g., USD, EUR, GBP)8 currencies · optionalUSD
payment_methodstringPayment method used (e.g., credit_card, bank_transfer, digital_wallet, unknown)3 methods · optionalcredit_card
fraud_labelstringLabel indicating if the event is normal, suspicious, or confirmed fraud (for supervised learning/testing)normal · suspicious · fraud · optionalnormal
notesstringOptional free-text notes or comments about the event (e.g., synthetic pattern description, scenario)optionalPayment attempt, normal
Numbers 2 columns
transaction_amountfloatAmount involved in the transaction (if applicable)0 or more · optional254.99
anomaly_scorefloatOptional anomaly score assigned to the event (0-1, higher means more anomalous)0 to 1 · optional0.12
Dates and times 1 column
event_timestampdatetimeDate and time when the event occurred (UTC)2024-06-01T09:15:32Z
True or false 1 column
is_syntheticbooleanIndicates whether the event is synthetic (always true for this dataset)true

Use it for

  • median anomaly…0.1372 rowsmean anomaly score by…0.12normal0.64suspic…0.89fraud

    A finance dashboard

    Anomaly_score by fraud_label and a breakdown of transaction_id. Excel, Power BI or Tableau.

  • Why do the 62 normal rows have a mean anomaly_score of 0.12?

    A root-cause class exercise

    Hand out the rows and one question. The answer is in the data, not in the brief.

  • A software demo

    Believable events with event_timestamp, session_id and transaction_id to fill a screen in front of a buyer.

Not quite right?

Make it yours.

Same 22 columns, your size and your rules. See 20 rows before you pay.

Preview 20 rows free

10,000 rows of yours: $12.99One-time. No subscription. All prices

This dataset72 rows22 columns
Yours10,000 rows22 columnsip_address: UK only

blueprint · marketplace-fraud-pattern-detection-logs

Behind this dataset

Same schema. As many rows as you need.

These 72 rows came out of a blueprint — 22 columns with generation rules behind each one. Open it in Data Factory to retune a column, add your own, wire in foreign keys, and run it at the size you actually need.

Rules it was built with
  • No real customer PII or payment data included.
  • Each row represents a unique suspicious session with event timestamps.
  • Event types include unusual login behavior, transaction anomalies, and API access flags.
  • Risk scores are computed using rule-based and simulated ML triggers.
  • Device/browser fingerprints are randomized but consistent within a session.
  • Fraud patterns should be diverse and cover account takeovers, synthetic identities, and automated bot activity.
Rows
Open the blueprint in Data Factory

1 credit per row. New accounts start with 25 free credits.

Exports
CSV, JSON, JSONL, Parquet, SQL, Excel, TSV, XML
Licence
yours to use, including commercially
API slug
marketplace-fraud-pattern-detection-logs

What should your data show?

Preview 20 rows free
No signup. No card.