Earlier quoted context omitted.
That's pretty standard for any sort of fraud prevention. You never tell people what triggered it because when it's not a false positive you're telling scammers what to avoid next time.
Ahh yes, the old security through obscurity.
The security in fraud protection (or any detective control) is in the thresholds and triggers being activated and protecting the system.
Protecting the values of those controls is common sense. This is on a need-to-know basis. Users don't need to know.
If you advertise that your system will permit 9,999 transactions per minute, then every client will calibrate to max out at 9,999, malicious or not. Then, you adjust that up or down, and not everyone follows suit. Whoops!