# Visual Data Analysis of Fraudulent Transactions

Your CFO has also requested detailed trends data on specific card holders. Use the starter notebook to query your database and generate visualizations that supply the requested information as follows, then add your visualizations and observations to your markdown report.

In [1]:
# Initial imports
import pandas as pd
import calendar
import hvplot.pandas
from sqlalchemy import create_engine
import os
from dotenv import load_dotenv

In [2]:
# Create a connection to the database
load_dotenv()
psw = os.getenv('Postgres')
engine = create_engine(f"postgresql://postgres:{psw}@localhost:5432/fraud_detection")
engine

Engine(postgresql://postgres:***@localhost:5432/fraud_detection)

## Data Analysis Question 1

The two most important customers of the firm may have been hacked. Verify if there are any fraudulent transactions in their history. For privacy reasons, you only know that their cardholder IDs are 2 and 18.

* Using hvPlot, create a line plot representing the time series of transactions over the course of the year for each cardholder separately. 

* Next, to better compare their patterns, create a single line plot that containins both card holders' trend data.  

* What difference do you observe between the consumption patterns? Does the difference suggest a fraudulent transaction? Explain your rationale in the markdown report.

In [3]:
# loading data for card holder 2 and 18 from the database
# Write the query
query = """
        SELECT * 
        FROM transactions INNER JOIN credit_card ON transactions.card = credit_card.card
                          INNER JOIN card_holder ON credit_card.cardholder_id = card_holder.id
        WHERE card_holder.id = 2 OR card_holder.id = 18;
        """
# Create a DataFrame from the query result. HINT: Use pd.read_sql(query, engine)
result = pd.read_sql(query, engine).T.drop_duplicates().T
result

Unnamed: 0,id,date,amount,card,id_merchant,cardholder_id,name
0,567,2018-01-01 23:15:10,2.95,4498002758300,64,18,Malik Carlson
1,2077,2018-01-05 07:19:27,1.36,344119623920892,30,18,Malik Carlson
2,2439,2018-01-06 02:16:41,1.33,4866761290278198714,127,2,Shane Shaffer
3,1867,2018-01-06 05:13:20,10.82,4866761290278198714,70,2,Shane Shaffer
4,3457,2018-01-07 01:10:54,175.0,344119623920892,12,18,Malik Carlson
...,...,...,...,...,...,...,...
227,1994,2018-12-27 18:46:57,1.7,344119623920892,55,18,Malik Carlson
228,114,2018-12-28 08:45:26,3.46,4498002758300,82,18,Malik Carlson
229,1228,2018-12-28 09:00:45,12.88,344119623920892,60,18,Malik Carlson
230,962,2018-12-28 15:30:55,11.03,675911140852,2,2,Shane Shaffer


In [4]:
# Plot for cardholder 2
cardholder_2 = result[result['cardholder_id'] == 2]
plot_ch2 = cardholder_2.hvplot.line(xlabel = 'Date', ylabel = 'Amount', x = 'date', y = 'amount',
                         label = 'Card holder 2 Transactions in 2018')
plot_ch2

In [5]:
# Plot for cardholder 18
cardholder_18 = result[result['cardholder_id'] == 18]
plot_ch18 = cardholder_18.hvplot.line(xlabel = 'Date', ylabel = 'Amount', x = 'date', y = 'amount',
                         label = 'Card holder 18 Transactions in 2018')
plot_ch18

In [6]:
# Combined plot for card holders 2 and 18
plot_ch2 * plot_ch18

## Fraud Dection

Overall speaking, `card holder 18` is probably hack, and `card holder 2` is probably not.

* The consumption data of `card holder 2` oscillates in a normal range, no outlier shows in the plot.
* There are several spikes in `card holder 18`'s plot, and the value of the spikes are almost 100x more than the others, so it is probably hacked.

## Data Analysis Question 2

The CEO of the biggest customer of the firm suspects that someone has used her corporate credit card without authorization in the first quarter of 2018 to pay quite expensive restaurant bills. Again, for privacy reasons, you know only that the cardholder ID in question is 25.

* Using hvPlot, create a box plot, representing the expenditure data from January 2018 to June 2018 for cardholder ID 25.

* Are there any outliers for cardholder ID 25? How many outliers are there per month?

* Do you notice any anomalies? Describe your observations and conclusions in your markdown report.

In [7]:
# loading data of daily transactions from jan to jun 2018 for card holder 25
# Write the query
query = """
        SELECT * 
        FROM transactions INNER JOIN credit_card ON transactions.card = credit_card.card
                         INNER JOIN card_holder ON credit_card.cardholder_id = card_holder.id
        WHERE card_holder.id = 25 AND date < '2018-07-01';
        """
# Create a DataFrame from the query result. HINT: Use pd.read_sql(query, engine)

cardholder_25 = pd.read_sql(query, engine).T.drop_duplicates().T
cardholder_25

Unnamed: 0,id,date,amount,card,id_merchant,cardholder_id,name
0,2083,2018-01-02 02:06:21,1.46,4319653513507,93,25,Nancy Contreras
1,1552,2018-01-05 06:26:45,10.74,372414832802279,86,25,Nancy Contreras
2,2108,2018-01-07 14:57:23,2.93,4319653513507,137,25,Nancy Contreras
3,754,2018-01-10 00:25:40,1.39,372414832802279,50,25,Nancy Contreras
4,3023,2018-01-14 05:02:22,17.84,372414832802279,52,25,Nancy Contreras
...,...,...,...,...,...,...,...
63,2582,2018-06-22 06:16:50,1813.0,4319653513507,40,25,Nancy Contreras
64,3218,2018-06-23 22:36:00,16.61,4319653513507,144,25,Nancy Contreras
65,1523,2018-06-25 09:17:05,11.53,372414832802279,77,25,Nancy Contreras
66,2264,2018-06-27 14:33:06,5.24,372414832802279,26,25,Nancy Contreras


In [8]:
# loop to change the numeric month to month names
cardholder_25['month'] = cardholder_25['date'].dt.strftime('%B')
cardholder_25

Unnamed: 0,id,date,amount,card,id_merchant,cardholder_id,name,month
0,2083,2018-01-02 02:06:21,1.46,4319653513507,93,25,Nancy Contreras,January
1,1552,2018-01-05 06:26:45,10.74,372414832802279,86,25,Nancy Contreras,January
2,2108,2018-01-07 14:57:23,2.93,4319653513507,137,25,Nancy Contreras,January
3,754,2018-01-10 00:25:40,1.39,372414832802279,50,25,Nancy Contreras,January
4,3023,2018-01-14 05:02:22,17.84,372414832802279,52,25,Nancy Contreras,January
...,...,...,...,...,...,...,...,...
63,2582,2018-06-22 06:16:50,1813.0,4319653513507,40,25,Nancy Contreras,June
64,3218,2018-06-23 22:36:00,16.61,4319653513507,144,25,Nancy Contreras,June
65,1523,2018-06-25 09:17:05,11.53,372414832802279,77,25,Nancy Contreras,June
66,2264,2018-06-27 14:33:06,5.24,372414832802279,26,25,Nancy Contreras,June


In [9]:
# Creating the six box plots using hvPlot
cardholder_25['amount'] = cardholder_25['amount'].astype(float)
cardholder_25.hvplot.box(y = 'amount', by = 'month', 
                         label = 'Card Holder ID 25 Transactions from January to June in 2018')

## Fraud Dection for Card Holder 25

There are evidences to show that the corporate credit card of card holder 25 is used without authorization.

* In the Box Plot, there are 9 points much further outside the boxes.

* There may be a trend up that the corporate credit card is used more frequently than before.

 ## Data Analysis Question 3
* Count the transactions that are less than $2.00 per cardholder. 

* What are the top 100 highest transactions made between 7:00 am and 9:00 am?

* Is there a higher number of fraudulent transactions made during this time frame versus the rest of the day?

### There are 353 transactions less than $2.00 per card holder.

In [10]:
# loading all data from the database
# Write the query
query3 = """
        SELECT * 
        FROM transactions INNER JOIN credit_card ON transactions.card = credit_card.card
                          INNER JOIN card_holder ON credit_card.cardholder_id = card_holder.id
        WHERE transactions.amount <= 2;
        """
# Create a DataFrame from the query result. HINT: Use pd.read_sql(query, engine)
df3 = pd.read_sql(query3, engine).T.drop_duplicates().T
df3

Unnamed: 0,id,date,amount,card,id_merchant,cardholder_id,name
0,2083,2018-01-02 02:06:21,1.46,4319653513507,93,25,Nancy Contreras
1,533,2018-01-03 15:23:58,1.39,4962915017023706562,100,10,Matthew Gutierrez
2,2120,2018-01-03 21:04:28,1.91,3561072557118696,108,19,Peter Mckay
3,2077,2018-01-05 07:19:27,1.36,344119623920892,30,18,Malik Carlson
4,2439,2018-01-06 02:16:41,1.33,4866761290278198714,127,2,Shane Shaffer
...,...,...,...,...,...,...,...
348,2251,2018-12-26 18:02:58,1.2,4834483169177062,65,8,Michael Floyd
349,10,2018-12-26 19:55:23,1.45,3561072557118696,18,19,Peter Mckay
350,1994,2018-12-27 18:46:57,1.7,344119623920892,55,18,Malik Carlson
351,3481,2018-12-27 18:47:35,1.32,4681896441519,112,24,Stephanie Dalton


### The top 100 amounts transactions between 7am and 9am

In [11]:
# loading all data from the database
# Write the query
query4 = """
        SELECT * 
        FROM transactions INNER JOIN credit_card ON transactions.card = credit_card.card
                          INNER JOIN card_holder ON credit_card.cardholder_id = card_holder.id
        WHERE EXTRACT(HOUR FROM transactions.date) BETWEEN 7 AND 8
        ORDER BY transactions.amount DESC
        LIMIT 100;
        """
# Create a DataFrame from the query result. HINT: Use pd.read_sql(query, engine)
df4 = pd.read_sql(query4, engine).T.drop_duplicates().T
df4['amount'] = df4['amount'].astype(float)
df4

Unnamed: 0,id,date,amount,card,id_merchant,cardholder_id,name
0,3163,2018-12-07 07:22:03,1894.00,4761049645711555811,9,1,Robert Johnson
1,2451,2018-03-05 08:26:08,1617.00,5570600642865857,4,16,Crystal Clark
2,2840,2018-03-06 07:18:09,1334.00,4319653513507,87,25,Nancy Contreras
3,1442,2018-01-22 08:07:03,1131.00,5570600642865857,144,16,Crystal Clark
4,968,2018-09-26 08:48:40,1060.00,4761049645711555811,134,1,Robert Johnson
...,...,...,...,...,...,...,...
95,1251,2018-04-08 07:06:20,11.73,3561954487988605,83,13,John Martin
96,1843,2018-09-15 08:33:49,11.72,5500708021555307,128,16,Crystal Clark
97,1797,2018-12-18 07:45:28,11.70,4279104135293225293,80,21,Dana Washington
98,1356,2018-02-25 07:37:03,11.68,5135837688671496,107,13,John Martin


In [12]:
df4.hvplot.box(y = 'amount', by = 'name', rot = 90, title = "Outliers Distribution Between 7AM and 9AM")

### There are more higher numbers of fraudulent transactions made during this time frame versus the rest of the day

In [13]:
# loading all data from the database
# Write the query
query5 = """
        SELECT * 
        FROM transactions INNER JOIN credit_card ON transactions.card = credit_card.card
                          INNER JOIN card_holder ON credit_card.cardholder_id = card_holder.id
        WHERE EXTRACT(HOUR FROM transactions.date) BETWEEN 9 AND 24
        ORDER BY transactions.amount DESC;
        """
# Create a DataFrame from the query result. HINT: Use pd.read_sql(query, engine)
df5 = pd.read_sql(query5, engine).T.drop_duplicates().T
df5['amount'] = df5['amount'].astype(float)
df5

Unnamed: 0,id,date,amount,card,id_merchant,cardholder_id,name
0,2945,2018-12-13 15:51:59,2249.00,3516952396080247,83,7,Sean Taylor
1,2710,2018-04-21 19:41:51,2108.00,3581345943543942,130,6,Beth Hernandez
2,2597,2018-11-13 17:07:25,1911.00,5570600642865857,77,16,Crystal Clark
3,3064,2018-05-08 13:21:01,1901.00,30142966699187,108,24,Stephanie Dalton
4,2984,2018-09-11 15:16:47,1856.00,3581345943543942,138,6,Beth Hernandez
...,...,...,...,...,...,...,...
2193,869,2018-09-02 19:10:09,0.62,180098539019105,112,11,Brandon Pineda
2194,777,2018-01-31 13:17:35,0.58,4741042733274,63,23,Mark Lewis
2195,558,2018-07-14 17:44:09,0.53,4506405265172173,81,20,Kevin Spencer
2196,755,2018-07-17 22:11:50,0.52,4506405265172173,142,20,Kevin Spencer


In [14]:
df5.hvplot.box(y = 'amount', by = 'name', rot = 90, title = "Outliers Distribution Excluding From 7AM to 9AM")