{
  "model": "grayson-1",
  "context": {
    "claim": {
      "claim_id": "CLM-2026-09-0418",
      "opened": "2026-09-23T13:58:00Z",
      "reported_by": "Member, by phone to the number on the back of her card",
      "payments_in_claim": [
        {
          "payment_id": "P2P-77120",
          "type": "P2P transfer (bank network, Zelle-style)",
          "amount_usd": 2850,
          "sent": "2026-09-22T15:10:01Z",
          "from_account": "checking x3306",
          "to": "R. Daniels, phone token x4471, first payment to this recipient",
          "initiated_from": "Android 14 phone, Chrome, first seen 2026-09-22T15:05:40Z, IP 198.51.100.62 (hosting provider)",
          "authentication": "Password correct on first try; new-device code and new-recipient payment code, both sent by SMS to the phone on file, entered correctly"
        },
        {
          "payment_id": "WIRE-30551",
          "type": "Outgoing domestic wire",
          "amount_usd": 7500,
          "sent": "2026-09-22T17:31:00Z",
          "from_account": "checking x3306",
          "to": "Crestline Holdings Group LLC, account x5512 at a commercial bank in Houston, TX",
          "initiated_from": "In person at the Bayside branch; driver's license checked; member signed the wire request"
        }
      ],
      "payment_under_review": "WIRE-30551"
    },
    "member": {
      "member_since": "2011-04-08",
      "accounts": [
        "checking x3306",
        "savings x8841"
      ],
      "usual_activity": "Payroll by ACH twice a month; utility and card bill payments; P2P to 3 recurring recipients, largest $400",
      "outgoing_wires_last_24_months": 0,
      "trusted_devices": [
        "iPhone 14, trusted since 2023-01-17"
      ],
      "phone_on_file_last_changed": "2017-06-30",
      "earlier_fraud_claims": "None",
      "earlier_scam_reimbursements": "None"
    },
    "events": [
      {
        "ts": "2026-09-21T22:47:00Z",
        "type": "sign_in_attempt",
        "device": "Windows 11, Chrome, first seen",
        "ip": "198.51.100.62",
        "network": "Hosting provider",
        "result": "Password correct; new-device code sent by SMS; code not entered; abandoned"
      },
      {
        "ts": "2026-09-22T15:04:12Z",
        "type": "code_sent",
        "purpose": "Sign-in from a new device",
        "sms_text": "Harbor Federal: Your code is ******. Use it to sign in on a new device. We will never call you to ask for this code."
      },
      {
        "ts": "2026-09-22T15:05:40Z",
        "type": "sign_in",
        "device": "Android 14, Chrome, first seen",
        "ip": "198.51.100.62",
        "network": "Hosting provider",
        "result": "Success"
      },
      {
        "ts": "2026-09-22T15:08:02Z",
        "type": "p2p_recipient_added",
        "recipient": "R. Daniels, phone token x4471",
        "device": "Android 14, Chrome"
      },
      {
        "ts": "2026-09-22T15:09:20Z",
        "type": "code_sent",
        "purpose": "P2P payment over $1,000 to a new recipient",
        "sms_text": "Harbor Federal: Your code to send $2,850.00 to R. Daniels is ******. Never share this code."
      },
      {
        "ts": "2026-09-22T15:10:01Z",
        "type": "p2p_sent",
        "payment_id": "P2P-77120",
        "amount_usd": 2850,
        "device": "Android 14, Chrome"
      },
      {
        "ts": "2026-09-22T15:13:44Z",
        "type": "sign_out",
        "device": "Android 14, Chrome"
      },
      {
        "ts": "2026-09-22T15:36:10Z",
        "type": "sign_in",
        "device": "iPhone 14 (trusted)",
        "ip": "203.0.113.18",
        "network": "Residential broadband",
        "result": "Success"
      },
      {
        "ts": "2026-09-22T15:38:55Z",
        "type": "internal_transfer",
        "from": "savings x8841",
        "to": "checking x3306",
        "amount_usd": 7000,
        "device": "iPhone 14 (trusted)"
      },
      {
        "ts": "2026-09-22T17:12:00Z",
        "type": "branch_wire_request",
        "payment_id": "WIRE-30551",
        "teller_note": "Member asked to wire $7,500 to 'my new account at another bank'. Beneficiary on the instructions she read from her phone is Crestline Holdings Group LLC; she said it is a holding account for her funds. Asked whether anyone had called and told her to move money; she said no. Member's first wire. Standard wire disclosure signed."
      },
      {
        "ts": "2026-09-22T17:31:00Z",
        "type": "wire_sent",
        "payment_id": "WIRE-30551",
        "amount_usd": 7500
      },
      {
        "ts": "2026-09-23T13:58:00Z",
        "type": "claim_opened"
      },
      {
        "ts": "2026-09-23T15:02:00Z",
        "type": "wire_recall_requested",
        "detail": "Recall request sent to the beneficiary bank; no response as of 2026-09-24T12:00:00Z"
      },
      {
        "ts": "2026-09-23T15:20:00Z",
        "type": "p2p_fraud_report",
        "detail": "Fraud report filed with the P2P network for P2P-77120"
      }
    ],
    "member_statement": "Recorded by the agent on 2026-09-23: 'Monday evening I got a text saying my Harbor Federal account was locked, with a link. I tapped it and signed in, but the page just kept loading. Tuesday around 11 a.m. a man called and the caller ID said Harbor Federal. He knew my name and that I have checking and savings. He said someone was trying to send money out of my account and he needed to verify it was me, so a code would come by text and I should read it to him. I did. Then another code came and he said it was to cancel the hacker's payment, so I read that one too. He said the hacker still had my login and my savings weren't safe, and the only way to protect them was to move everything into a holding account their security team had opened for me, by wire from the branch. He told me to say it was my own account and that nobody had asked me to move money, because someone at the branch might be involved. He stayed on the line while I was at the branch. He said I would get a call back today. Nobody called, and his number just rings, so I called the number on my card.'",
    "agent_notes": "Member says she did not send P2P-77120 and did not know a payment was being made until she checked her history at 11:36 a.m. She moved $7,000 from savings to checking on the caller's instructions before going to the branch."
  },
  "questions": {
    "fraud_classifier": {
      "type": "choice",
      "instructions": "Using the Federal Reserve's FraudClassifier model, how should the payment under review be classified? An authorized party is someone with the right to initiate the payment; an unauthorized party is someone without that right.",
      "options": {
        "manipulated_products_services": "Authorized party was manipulated: products and services fraud (paid for goods or services that were never delivered or were grossly inferior)",
        "manipulated_relationship_trust": "Authorized party was manipulated: relationship and trust fraud (sent money to a trusted party, or an impostor posing as one, with no goods or services expected in return)",
        "acted_embezzlement": "Authorized party acted fraudulently: embezzlement (misused funds placed in their trust or belonging to their employer)",
        "acted_false_claim": "Authorized party acted fraudulently: false claim (lied to receive a payment or avoid a payment obligation)",
        "acted_synthetic_id": "Authorized party acted fraudulently: synthetic identity (used a fabricated identity built from real and invented personal information)",
        "modified_compromised_credentials": "Unauthorized party modified the payment information after initiation, using stolen login credentials",
        "modified_impersonation": "Unauthorized party modified the payment information after initiation, by impersonating the authorized party without their login credentials",
        "modified_physical_alteration": "Unauthorized party modified the payment information after initiation, by altering a physical payment instrument such as a check",
        "takeover_compromised_credentials": "Unauthorized party took over the account using stolen login credentials, and initiated the payment",
        "takeover_impersonation": "Unauthorized party took over the account by impersonating the authorized party without their login credentials, and initiated the payment",
        "misused_digital": "Unauthorized party, without control of the account, used legitimate account information to initiate an electronic payment",
        "misused_physical_counterfeit": "Unauthorized party used a forged or counterfeit physical payment instrument",
        "not_fraud": "Not fraud: the account holder made the payment without being deceived"
      }
    },
    "scam_type": {
      "type": "choice",
      "instructions": "Using the Federal Reserve's ScamClassifier model, which scam type is this case? A scam is the use of deception or manipulation intended to achieve financial gain, whether the account holder sent the money or let someone else into the account.",
      "options": {
        "merchandise": "Merchandise: paid for goods that were never delivered or were substantially different from what was advertised",
        "investment": "Investment: invested in a financial asset on false promises of a high return",
        "property_sale_rental": "Property sale or rental: paid for a home, apartment or property that was fictitious, unavailable or not owned by the seller",
        "romance_impostor": "Romance impostor: a fictitious online identity built a romantic or friendly relationship, then asked for money",
        "government_impostor": "Government impostor: someone posed as a government agency, law enforcement or a court",
        "bank_impostor": "Bank impostor: someone posed as a financial institution, its fraud department or its staff",
        "business_impostor": "Business impostor: someone posed as a legitimate business or brand, such as tech support, a utility or an employer",
        "relative_family_friend": "Relative, family or friend: someone posed as a relative or friend, or someone acting for one, with a false emergency",
        "other_trusted_party": "Other trusted party: someone posed in another role, such as a charity, to ask for money on a false expectation",
        "not_scam": "Not a scam: no one deceived or manipulated the account holder"
      }
    },
    "contributing_factors": {
      "type": "multi_choice",
      "instructions": "Which of these happened in this case?",
      "options": {
        "unsolicited_contact": "Someone contacted the customer first, by call, text, email or message, and that contact led to the payments",
        "credentials_phished": "The customer entered or gave their online banking password somewhere other than the institution's own app or website",
        "code_shared": "The customer gave a one-time passcode or security code to another person",
        "remote_access": "The customer installed or allowed remote-access software on their device",
        "new_device": "A device the customer had never used signed in to the account",
        "new_recipient": "Money went to a recipient the customer had never paid before",
        "coached": "The customer was told to mislead the institution's staff or hide the real reason for a payment",
        "pressure": "The customer was pressured with urgency or a threat, such as losing their money, arrest or a deadline"
      }
    },
    "reimburse": {
      "type": "noul",
      "instructions": "Under the law and any reimbursement policy stated in this case, should the institution reimburse the customer for the payment under review?"
    }
  }
}
