FRAUDFORWARD
#115

Charla informal: ataques de fraude impulsados por IA

46 min

¿Qué tal, luchadores contra el fraude? ¡Bienvenidos de nuevo a Fraud Forward!

Este episodio se grabó en directo en SardineCon como una charla informal. Van a escuchar la versión auténtica y sin guion de una conversación que mantuve con Andrew Austin, de Sardine, y Arjun Ramakrishnan, de GoDaddy. Aquí no hay argumentos ensayados, sino simplemente una conversación ante una sala llena de personas que se dedican a esto a diario. Arjun aportó la perspectiva de los comercios y los pagos; Andrew, la de la tecnología contra el fraude. Nos sentamos a hablar sobre el fraude impulsado por la IA y sobre lo barato y rápido que se ha vuelto todo esto.

La IA no está introduciendo un nuevo tipo de fraude. Son las mismas prácticas contra las que siempre hemos luchado: desde esquemas de fraude relámpago y pruebas de tarjetas hasta identidades sintéticas y empresas falsas. Lo que ha cambiado es la velocidad, la escala y el coste. Eso es lo que analizamos durante los siguientes cuarenta y cinco minutos.

Lo que escucharás:

  • Cómo los sitios web fraudulentos generados por IA y el fraude mediante la clonación de sitios web han eliminado uno de los indicios de fraude más antiguos en los que confiaban los equipos antifraude. Ya no podemos basarnos únicamente en si el sitio web de una empresa parece legítimo.
  • Cómo el fraude de tipo «bust-out» ha pasado de dos o tres cuentas gestionadas manualmente a redes de fraude con agentes de IA que operan simultáneamente entre 30 y 40 cuentas sintéticas.
  • Por qué los ataques de prueba de tarjetas ya no siguen patrones predecibles de importes o frecuencia, y qué implica esto para la detección de patrones de frecuencia en el fraude de pagos.
  • La verdadera tensión a la que se enfrentan los equipos antifraude al equilibrar las fricciones del proceso KYB con la prevención del fraude, y por qué añadir más obstáculos puede llevar a los clientes legítimos a optar por la competencia.
  • Por qué la detección del fraude mediante datos compartidos por consorcios y el análisis del fraude a nivel de red son más importantes que nunca cuando una sola red de fraude puede abarcar decenas de cuentas aparentemente inconexas.
  • Cómo la asimetría de costes en el fraude está transformando por completo la lucha, en la que los atacantes realizan múltiples intentos por unos centavos mientras que los defensores gastan sumas considerables para responder.
  • Por qué los modelos tradicionales de previsión de pérdidas por fraude están dejando de ser fiables en un mundo de ataques de fraude agéntico en constante evolución.
  • Cómo debe ser realmente la estrategia de innovación de los equipos antifraude de cara al futuro, incluida la detección del fraude en tiempo real, la automatización de los motores de reglas antifraude y la aceptación plena de la realidad que suponen las barreras de costes de la IA aplicada al fraude.

Deberías escuchar este episodio si:

  • Trabajas en la gestión del riesgo de fraude durante la incorporación de comercios, en pagos o en confianza y seguridad, y buscas una perspectiva práctica y realista sobre el fraude impulsado por la IA.
  • Son responsables de detectar el fraude de identidad sintética, el fraude con tarjeta no presente o el fraude de tipo «bust-out» en un banco, una fintech o una plataforma de pagos.
  • Alguna vez han tenido que defender ante su equipo de ventas o producto el equilibrio entre la fricción del proceso KYB y el fraude, y quieren argumentos para exponer mejor su postura.
  • Están evaluando herramientas de detección de fraude basadas en datos de consorcios o de análisis de fraude a nivel de red y quieren conocer casos reales que expliquen por qué son importantes ahora.
  • Lideras un equipo de prevención del fraude que intenta determinar dónde invertir realmente, ahora que los atacantes ya no se enfrentan a la barrera de costes que antes suponía el fraude mediante IA.
  • Quieres una conversación en directo, con opiniones sinceras de personas que luchan activamente contra esto cada día.
Notas del episodio

El fraude impulsado por IA sigue el mismo guion, solo que más rápido

El fraude impulsado por IA no está introduciendo nuevos tipos de ataques. Está haciendo que las mismas modalidades de fraude contra las que he luchado durante toda mi carrera sean muchísimo más rápidas, sofisticadas y difíciles de detectar. Este planteamiento marcó todo lo demás que abordamos durante esta sesión, porque el verdadero cambio no está en el aspecto que tiene el fraude, sino en la rapidez con la que evoluciona una vez que ya está en marcha.

Los sitios web fraudulentos generados por IA han eliminado una antigua señal

Durante años, una de mis tácticas habituales era revisar el sitio web de una empresa. Un sitio descuidado y con poco contenido solía ser un indicio fiable de que algo no era legítimo. Ahora esa señal prácticamente ha desaparecido. Los sitios web fraudulentos generados por IA y el fraude mediante la clonación de sitios web la han vuelto inútil. Andrew explicó cómo lo demostró en directo. Clonó un sitio web en diez minutos y dijo que se veía mejor que el original.

El fraude de vaciamiento ha pasado de unas pocas cuentas a decenas a la vez

Antes, el fraude de tipo «bust-out» consistía en que un estafador gestionaba manualmente dos o tres cuentas durante varios meses antes de retirar los fondos. Ahora, las redes de fraude que utilizan agentes de IA pueden abrir y mantener 30 o 40 cuentas sintéticas al mismo tiempo, todas ellas generando discretamente un historial de transacciones de bajo riesgo antes de ejecutar el fraude de forma simultánea. Se trata de una magnitud de pérdidas que la mayoría de los programas antifraude nunca fueron diseñados para detectar.

Los ataques de prueba de tarjetas ya no siguen patrones predecibles

Los equipos antifraude solían basarse en importes constantes y en la frecuencia de las transacciones para detectar ataques de prueba de tarjetas. Eso ya no es fiable. Los agentes de IA pueden variar ambas señales en tiempo real, lo que permite eludir los modelos de patrones de frecuencia del fraude en pagos en los que muchos equipos antifraude han confiado durante años.

El equilibrio entre la fricción del proceso KYB y el fraude se vuelve más difícil

Añadir obstáculos para detectar el fraude asistido por IA conlleva el riesgo de empujar a tus clientes legítimos directamente hacia un competidor con un proceso de registro más sencillo. En esta conversación dedicamos bastante tiempo a analizar cómo los equipos antifraude equilibran realmente la fricción en los procesos de KYB con la prevención del fraude, y por qué esa decisión ya no compete únicamente al equipo antifraude. Los equipos de ventas, producto y crecimiento presionan en la dirección opuesta, y esa presión no va a desaparecer.

Los datos de consorcios y el análisis a nivel de red son la verdadera defensa

Detectar redes de fraude impulsadas por IA exige dejar atrás la revisión individual de las cuentas. Se necesita detectar el fraude mediante datos compartidos por consorcios y realizar análisis a nivel de red para identificar bancos receptores comunes, instrumentos de pago coincidentes o la misma plataforma web presente en decenas de cuentas a la vez. Esa es la única forma de que esto pueda funcionar a gran escala.

El problema de la asimetría de costes

La asimetría de costes en el fraude implica que los atacantes pueden perfeccionar un ataque por apenas unos céntimos. Los defensores, en cambio, necesitan un presupuesto considerable, infraestructura y tiempo para responder. Si a esto le sumamos lo poco fiables que se han vuelto las previsiones de pérdidas por fraude en un mundo donde los ataques de fraude agéntico cambian constantemente, queda patente hasta qué punto esta lucha está realmente desequilibrada.

Lo próximo que deben desarrollar los equipos antifraude

Todo se reduce a la detección del fraude en tiempo real, a la automatización de motores de reglas antifraude que ajusten los umbrales al instante en lugar de esperar a que alguien genere un informe una vez por semana, y a una visión realmente más amplia del riesgo que incluya inteligencia de dispositivos y biometría del comportamiento. Esos son los verdaderos cambios que nuestro sector debe adoptar. No basta con centrarse únicamente en los datos transaccionales. Y esos cambios son cada vez menos opcionales.

Puntos clave
  • El fraude impulsado por IA no es una nueva categoría de ataque, sino que consiste en modalidades de fraude ya existentes que operan con mayor rapidez, a menor coste y a mayor escala.
  • Los sitios web fraudulentos generados por IA y el fraude mediante la clonación de sitios web han hecho que la calidad de un sitio web deje de ser un indicador fiable de fraude.
  • El fraude de tipo «bust-out» ha pasado de unas pocas cuentas gestionadas manualmente a redes de agentes de IA que coordinan entre 30 y 40 cuentas a la vez.
  • Los ataques de prueba de tarjetas ahora varían los importes y la frecuencia en tiempo real, lo que permite eludir los modelos basados en patrones predecibles de frecuencia del fraude en los pagos.
  • El equilibrio entre la fricción en el proceso de KYB y el fraude supone una verdadera disyuntiva empresarial, no solo una decisión del equipo de prevención del fraude, ya que añadir fricción puede ahuyentar a clientes legítimos.
  • La detección del fraude mediante datos compartidos por consorcios y el análisis del fraude a nivel de red son esenciales cuando las redes de fraude abarcan decenas de cuentas en lugar de solo dos o tres.
  • La asimetría de costes en el fraude implica que los atacantes gastan apenas unos céntimos en cada intento, mientras que los defensores deben invertir cantidades considerables para responder; un desequilibrio estructural que los equipos antifraude deben tener en cuenta al diseñar sus estrategias.
  • La previsión tradicional de pérdidas por fraude deja de ser fiable cuando los ataques de fraude agéntico evolucionan durante el propio ataque en lugar de seguir patrones históricos.
  • La inteligencia de dispositivos y la biometría del comportamiento siguen siendo algunas de las señales más fiables para combatir el fraude de identidad sintética y el fraude con tarjeta no presente, ya que todo defraudador deja algún indicio.
  • Una verdadera estrategia de innovación para los equipos antifraude implica detección del fraude en tiempo real y automatización del motor de reglas antifraude, no conjuntos de reglas estáticas que se actualizan a partir de un informe semanal.
Conclusión final

La barrera económica para cometer fraude con IA prácticamente ha desaparecido. Lo que antes requería conocimientos especializados, acceso a la web oscura y una inversión considerable ahora cuesta unos 20 dólares al mes y solo exige estar dispuesto a experimentar. Esa es la incómoda realidad. Los equipos antifraude no pueden superar en recursos a atacantes que no necesitan que nadie les apruebe un presupuesto. Pero sí pueden desarrollar mejores defensas adoptando la detección en tiempo real, compartiendo señales entre redes en lugar de revisar las cuentas de forma aislada y aceptando que el antiguo enfoque basado en reglas estáticas y revisiones trimestrales sencillamente ya no puede seguir el ritmo. Como dijo Andrew, el objetivo no es eliminar la brecha, sino ir un paso por detrás en vez de veinte.

Recursos y enlaces del episodio

Conecta con Andrew Austin | LinkedIn
Especialista en fraude y riesgo
Estrategia de producto y soluciones en Sardine

Conecta con Arjun Ramakrishnan | LinkedIn
Director de Riesgos en GoDaddy Payments

Conecta con Hailey Windham, CFCS | LinkedIn
Presentadora del pódcast Fraud Forward
Responsable de la comunidad bancaria en Sardine
Especialista certificada en delitos financieros (CFCS)
Estrella de las cooperativas de crédito de 2023, CU Magazine
Premio a la Mejora Continua, SAFE Federal Credit Union, 2023
Una de las 20 mejores profesionales menores de 40 años, The Sumter Item, 2022

Episode transcript
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
00:05
All right. So, we're going to get started for our fireside. And I see some confused looks on your faces. I'm the prettier Matt Vega. So, he unfortunately was not able to come. Uh, so we have, um, my name is Hailey Windham. I'm the community lead for banking for Sardine. And I've got Andrew Austin with us as well. And of course, we have Arjun, which you guys were expecting today. So, thank you so much for joining our fireside. And guys, thank you so much for having this conversation with me.
A smiling man with a beard in a blue shirt against a blue background.
Andrew Austin
00:31
Of course.
A man in sunglasses and a blue shirt sits in a chair, with a stone wall and blue railing behind him.
Arjun Ramakrishnan
00:32
Absolutely.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
00:33
Also, there's a camera up. So, just so you guys know. We are recording this for Fraud Forward. Uh, which is the podcast that we host every week. So, if you think that we sounded amazing and you want to hear it again, stay tuned, uh, for when that episode will release.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
00:51
Okay. So, we are going to talk today about AI driven fraud attacks. Uh, fraud teams have always adapted to new threats. What feels different now is the speed, scale, and sophistication AI gives the attacker. Signals we once trusted are becoming less reliable. Fraudsters can build convincing businesses, test defenses, um you know, change tactics, mid attack, and coordinate activity across dozens of accounts. Um you know, Arjun, I'll start with you. Before we explore specific attack types. How fundamentally is AI changing the fraud landscape? And do organizations fully understand what is coming?
A man in sunglasses and a blue shirt sits in a chair, with a stone wall and blue railing behind him.
Arjun Ramakrishnan
01:28
Yeah, I I'll maybe start with, you know, a little bit of context on what my team does and how that leads into this. Uh, so head of risk at at GoDaddy. So what does GoDaddy have anything to do with payments fraud, right? Uh so a lot of uh you probably know Godaddy as you know a website and domain provider. Um uh but it goes further than that, right? So when uh a business comes to Godaddy uh for a website, or a domain. You know, they start with setting up a website and a domain. And we provide all other tools that a uh business would need to run um you know their daily operations. Right? So you start with a website and a domain. But then we give you a payment account. Right? Uh, we enable you to accept payments on your website. Uh we, you know, ship out a terminal if you want to accept payments at your store. Uh we do like invoice payments, you know. Uh uh pay links, etc. Right? So that's where we see a lot of our fraud come in, right? Our payment accounts. Uh we have a lot of uh AI driven fraud attacks that come for our businesses, our websites, our domains and our payment uh uh payment accounts, right? So uh going back to Hailey’s question. So what do we see differently now uh with AI, you know, dictating a lot of our fraud attacks? Uh it's I I put it into like three different categories, right? The speed, uh the scale, and like the cost. Uh basically the asymmetry that we see across these three vectors, right? Uh we see a lot of evolution of fraud. Uh when it comes to how fast they attack us. And how fast they evolve when they attack our merchants, right? Uh and how do our solutions adapt to respond to these attacks is is basically uh the problem that we're facing today. Um what was the second part of your question, Hailey?
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
03:09
Uh just, do organizations fully understand what is coming?
A man in sunglasses and a blue shirt sits in a chair, with a stone wall and blue railing behind him.
Arjun Ramakrishnan
03:14
Uh yes and no. Uh, you know. What do I mean by yes and no? It's not like the types of fraud attacks have changed. It's just that the same kinds of attacks that we used to see in the past have become a whole lot more sophisticated. Right? So it's not like a whole different MO of fraud that we see uh with AI. It's the same different fraud attacks that we used to see in the past. It's just they're faster, more sophisticated. Uh, and a whole lot harder to detect because they evolve so fast. So that's the piece that I think today, uh, platforms and businesses fail to address. It is, you know, we're not looking for completely new kinds of fraud, uh, that are driven by AI. It's the same kind of fraud. It's just that it's a whole lot faster and a whole lot more sophisticated.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
04:02
Andrew, anything to add there?
A smiling man with a beard in a blue shirt against a blue background.
Andrew Austin
04:04
No, I think you're spot on there. And you you mentioned the speed, the cost, and really the barrier to entry for um fraudsters. Criminals, hackers, whatever you whatever you're getting attacked by. Is at times a $20 a month subscription to Claude or ChatGPT, right? It doesn't take a lot to to develop these attacks. You prompt something, you can test it out. And very quickly get something that can attack a merchant, a payment processor, a bank's defenses. And quickly scale that. Um until they adapt to it. And then you move on.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
04:43
So true. And I, you know, we were prepping for this session. Literally 10 minutes ago. Um, but one of the things we talked, we were started to talk about was, you know, when a professional website proves nothing. You know, I can remember when I investigated uh you know, businesses back in the day. The first thing I would do is check out their website. I'd go scroll all the way down to the bottom and click contact us. And usually that would be a blank page. There'd be nothing there. And that's how I would be able to tell a member or a customer, hey, this is probably not a legitimate place. Because obviously the website is not fully opened and operating like it should be. Um, you know, again, just checking whether or not the the links worked. Um and just looking for signs that the real business existed. Those checks used to tell us something. But now an AI agent can build an incredibly sophisticated and completely functional website within minutes. Um Arjun, I'll start with you again. How much growth are you seeing in websites created partially or entirely with AI?
A man in sunglasses and a blue shirt sits in a chair, with a stone wall and blue railing behind him.
Arjun Ramakrishnan
05:40
Uh a lot. Right? But when I say a lot, it's a lot both on the legitimate side and on the the fraud side, right? What I mean by that is even legitimate businesses now, you know, create their websites using AI, right? Everyone uses Lovable or whatever other platforms they might have to create a legitimate business, to represent their legitimate website. To represent their business, right? And so do fraudsters. So how do we tell the difference between the two is the the biggest challenge now, right? So in the past when a business used to open a payments account to accept payments. Uh for their business with us. One of the key indicators that we used to, uh, use, to detect fraud, was how legitimate is their website. Uh is it a very basic HTML website? Which is just you know one page where you scroll, and scroll, and scroll. Uh, and there's you know no depth to the website. It doesn't look sophisticated. It doesn't look serious. A real business would have spent more money to build a website that represents their business better, right? But now that difference is is pretty much gone, right? Fraudsters can now build a sophisticated website with layers, depth and sophistication in minutes, right? Uh so it's hard to tell uh if it is a legitimate business that owns that website or is it, you know, a completely a fraud entity that owns that website, right? So that vector and indicator that we use to distinguish between fraud and legitimacy, is is pretty much gone now. So so how do we go about now now that that difference is gone? Um figuring out if a business is real or not. Right? So in the past we used to have models which scored the seriousness of a website, right? Now that doesn't work. So you go one level deeper, Right? And look into the metadata of, hey what was the platform, um that that built this website? Are there common IPs where a number of these websites have been created? Is the contact us information on this website, is it among common amongst like 30 40 of these that onboarded on the same date, right? So you're beginning to look at aggregate data. And common data points as opposed to looking at one individual specific website to see is it fraud or not. Right? So we're moving from investigating individual data points on individual businesses and websites to the next layer on. Where we're trying to see across your portfolio. What are the common uh data points that you see between businesses? The websites that they have? The platforms that they were created in, the IP that they're coming from. Does the template look similar? Right? So you're looking at the aggregate level rather than individual uh, businesses to figure out fraud.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
08:12
I definitely appreciate that context of you know what we should look for when we investigate. Um, you know, and Andrew, I I want to bring you in on this, too. How legitimate um can an AI generated website appear, even when the the business behind it is fraudulent? You know, we talked through some of those things we can look for. But how legitimate are they looking right now?
A smiling man with a beard in a blue shirt against a blue background.
Andrew Austin
08:34
Uh, completely legitimate. Uh, you know, I I spoke at a conference back in June. Um where one of our clients was bringing in their clients. And they were all state governments. And as you know the state government might not always be fully funded, might not have the best developers to develop the website. And they wanted me to uh, as part of this, clone one of their clients website. So they got permission for this. It wasn't just on the fly scaring the hell out of everyone. Um, but I had 10 minutes. I went to the website. Uh had another tool that we use internally, uh to create demo sites sometimes. And I cloned the website. And the clone website was much better than the official government website that people sign up and deposit funds into. And I then went to, uh, I think it was GoDaddy.com and did a domain search that I, you know, let's say it was, uh, I'm from Ohio. So I'll say Ohio.com and I put that in. And I showed them for about 20 bucks I can buy OhioSaves.org OhioSaves.net OHsaves.com oHsaves.net OHsaves.net and like they were just terrified. You know, it's a it's a it is it is so simple to not only create a website that is on par with or better than the target website that you're trying to clone. Like so so in your in your case there are businesses that are completely fake, right? You you have fraudsters that are standing up fake websites. What what I'm talking about is another vector here where there is a legitimate website and someone is trying to clone it so they can harvest credentials or what have you. Right? The point is the websites can be just as good if not better. And again, the barrier to entry is 20 bucks a month. It all these are all subscription services. Uh it's it's you know a couple bucks to do to do one piece of it, a couple bucks to do the other and for not a whole lot of money you can generate you know multiple websites. And we we saw earlier, um this morning that you know you can clone a voice, you can clone a video, you can create a synthetic person out of nothing, you can create a synthetic business out of nothing, you can create a fake website to deceive people. Uh and the cost is virtually nothing now. It's it's virtually nothing and it's almost seamless how good some of these websites are.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
11:16
Speaking of deepfakes, you can go back to Fraud Forward two weeks ago and where Andrew deepfaked me and,
A smiling man with a beard in a blue shirt against a blue background.
Andrew Austin
11:22
I would never do that.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
11:24
Um, so obviously, yes these websites are concerning. But another thing that is really concerning as far as a threat is, not that an account that looks fraudulent from day one, but it is where a business can appear legitimate for months, builds history and trust, and then suddenly busts out. Uh you know the next evolution may be even more coordinated. It's not one business account collapsing, but 30 or 40 seemingly unrelated accounts executing the same strategy at once. So what does bust out fraud um look like today, and how is AI making it more convincing?
A man in sunglasses and a blue shirt sits in a chair, with a stone wall and blue railing behind him.
Arjun Ramakrishnan
12:01
Yeah, uh before we jump into bust out fraud today, maybe what was it like before and uh how has it changed, right? What does it look like today? So for those of you who are not aware, right? On the merchant side, bust out fraud is where, you know, uh a business or so-called business, comes to your platform. Opens up an account. And uh they start accepting payments, right? Uh typically these are low dollar payments. Um and they establish a history with you 3 months, 6 months, uh no chargebacks, nothing. It all looks good, right? And once uh this history has been established, there's a point where they decide to bust out. Where they start processing large dollar transactions. Which typically go undetected because they've established the the history with us, right? Uh and typically machine learning models focus on the initial period of a merchants's transaction activity. Uh that leads to this bust out behavior typically being missed off, right? So that used to happen. Uh one fraudster will be able to do that across say two or three accounts at a time, right? So you know they open two accounts uh a specific month, or maybe three. And then they go 6 months of this low-risk activity. And they bust out on these two to three accounts 6 months later. Now that has scaled to say 30 or 40 accounts at a time because AI and AI agents enable them to open all these accounts at once. Uh with, you know, synthetic ID synthetic business credentials, and they have the agents pay these accounts 30 to 40 accounts at a time. That's what we see now, you know, it could be uh of larger scale in the future. But they're feeding these accounts low risk low dollar transactions for say 6 months at a time, right? And all these 30 or 40 accounts then bust out at the same time. So we've gone from a scale of having two to three accounts where a human fraudster curated these accounts over 6 months. To AI agents being able to do the same process across, you know, at a much larger scale 30 40 50 accounts at a time. Uh compounding the losses that any payment product would see at a time. So that's the the biggest risk with bust out on you know how it used to operate in the old world versus the new AI world. It works the same way but scale is a whole lot different.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
14:09
Yeah, I was going to ask about specifically, like what activity helps to build um, or helps these businesses build enough credibility, to gain those higher limits, access additional products or reduce that scrutiny. I know you mentioned, you know, processing a couple of small dollar transactions. But what what activity, what does that activity look like that helps them build that credibility?
A man in sunglasses and a blue shirt sits in a chair, with a stone wall and blue railing behind him.
Arjun Ramakrishnan
14:30
Yeah, it's generally a slope, right? Uh let's take an example of a a fraudster that comes to you. And you know manually opens up an account. Say they're they claim that they're a handyman, right? And they're doing odd jobs here and there, plumbing jobs, building a deck, building a fence, whatever that might be, right? They typically start with small dollar, small job uh transactions, $100, $200 to fix this, fix that. Uh 3 months in, you know, they're going to start doing larger jobs, right? $2,000, $3,000, I'm, you know, fixing your deck, uh, uh, building a fence for you. And six months down the line, you're they're they're going to do like large contract jobs, right? $10,000, $20,000, right? And these typically are the breakout transactions. And these are not legitimate transactions and they end up coming back as chargebacks. So, where did they build trust and where did they build history? So, in the first 6 months, right? They showed a gradual growth in their business. They started off as a small handyman that was fixing things. To, you know, fixing larger things, building fences. To taking up large contracts, right? And that at this point, you know, they have like multiple large projects. It's going to be typically in the hundreds of thousands of dollars. All of that is going to come back as chargebacks. So, they built history with smaller transactions. Typically prepaid cards or debit cards, uh that they own, that they pay towards their own account. These are not going to come back as chargebacks, right? But then uh 6 months 7 months down the line when they start processing these huge transactions 10 20 30 grand per transaction. All of these you know when it's a bust out scenario, end up coming back back as chargebacks.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
16:00
So let's talk about when the strategy moves from the one account to the 30 or 40 accounts doing it simultaneously. How difficult is it to connect those accounts before the coordinated loss event occurs?
A man in sunglasses and a blue shirt sits in a chair, with a stone wall and blue railing behind him.
Arjun Ramakrishnan
16:15
So usually what happens is like I said there's only two to three accounts, right? And manual review of these two to three accounts when they bust out is typically you catch them there's a growth in volume. And you identify the growth in volume, and then you have a human analyst that's going to look at these accounts, and they're like yeah the transaction pattern doesn't match, and maybe I'm going to ask for more documents, and terminate this account if it is actually fraudulent, right? So what changes now is now that's happening across 30 to 40 accounts, right? And it's it's hard to tie a common pattern between these 30 to 40 accounts. So that's where the aggregate level metadata analysis comes into play. You can't be reviewing each of these accounts manually, requesting information, and then deciding if it's fraud or not. Right? The better way to approach this would be what's common amongst all these accounts. Why is there a spike in volume uh say in a certain vertical or industry across the portfolio? Uh do they share common elements like do they use the same credit card to pay across these 30 to 40 accounts? Right? that that would be a good giveaway that it's run by the same fraud ring. Uh similarly, hey, do their websites uh look uh uh similar uh where they all built on the same uh platform, right? So, these are going to be giveaways uh that there's a fraud ring going on in your portfolio rather than having to stoop to the individual account level like in the old world that we used to do.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
17:32
Um, Andrew, how should fraud teams balance the need to detect the sleeper businesses with the risk of creating friction for the legitimate new businesses?
A smiling man with a beard in a blue shirt against a blue background.
Andrew Austin
17:41
Yeah, I wasn't sure that that was the next question that was coming, but uh I was going to talk about that. You know, it's nobody wants friction. Nobody wants it. Uh, and I think about some of the tools that are available today, some of the AI tools that are able to defeat like doc KYC for example. You know, the the simple answer that we might have given a couple years ago was like, well, you had you had targeted friction, right? If some if if this is a a new business or they have certain risk factors, you can add additional um doc KYC, right? Is this person who they say they are? But now you can defeat that. Now it's defeatable. It's is it the easiest thing to do? No. Is it perfect? No. But it can be defeatable. So I think that's that's one of the big struggles that we we have as businesses is, I can add friction. But are my good clients going to go go away? Well the, you know, I think fraudsters, well real real businesses are going to go to the provider that is the easiest to sign up with. You know, if I'm signing up for a bank account uh, or at a at a fintech, or a at a traditional financial institution, and they say you need to do a KYC or do your out of wallet questions, your mother's maiden name, what did you have a 1997 Honda Civic? Uh what color was it? Like I hate that, right? So that's the type of friction people don't want. So if I can go to, you know, ABC bank. And they don't ask me those questions, it's just give me your social, your address, the CIP data that is required to open an account. Well, hell, I'm going to go there. So as as fraud program managers or or heads of fraud, we have to look at what's the balance, what's the trade-off to adding friction. If they're going to go somewhere else, you have to balance your fraud losses like what is an acceptable fraud loss rate uh versus drop off rate. You know, it's not just the fraud team because the fraud team is going to get pressure from the business, from sales, from product, from whoever. In their business, to well, you know, you're you are stifling business growth. And when you look at uh startup whether that's fintech or prediction markets or whatever it is what's the key that everyone wants growth growth at at sometimes at any cost, right? So I I think the the fraud team's responsibility is to be the voice of reason and try to manage that as much as they can within the risk tolerance of the business. Um yeah.
A man in sunglasses and a blue shirt sits in a chair, with a stone wall and blue railing behind him.
Arjun Ramakrishnan
20:24
You know you know, the uh, that reminds me. You know the fraudster does not have to deal with the sales or go to market team.
A smiling man with a beard in a blue shirt against a blue background.
Andrew Austin
20:31
No they don't
A man in sunglasses and a blue shirt sits in a chair, with a stone wall and blue railing behind him.
Arjun Ramakrishnan
20:32
They don't but we have to. So
A smiling man with a beard in a blue shirt against a blue background.
Andrew Austin
20:34
Yeah. They are they are the sales, the GTA, they are they're everything all-in-one. They don't have anyone to approve anything. They just go out and do. [Ad Break (20:48): Finally, I'm so happy to share with you all that The Saturday Fraud Strategist is now a podcast. What? Yeah. On top of my weekly newsletter you could now listen to and watch me talk about my and hopefully your favorite topic, fraud strategy. And from time to time, I'll be hosting operators and founders to discuss where the industry is headed and what we fraud fighters should pay attention to. I must say I'm super excited. And if I'm being honest, a bit nervous about all of this. I've been debating with myself whether to start a podcast for ages but kept putting it off. But now this is a result. So I guess there's no turning back. So if you want to join me for the ride, head over to Sardine's website and subscribe now. Are you ready? Am I ready? We'll find out next Saturday.]
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
21:46
So, we talked a little bit earlier on about those early signals um that might reveal that apparently legitimate businesses are being cultivated for, you know, future uh bustouts. Does detecting this require institutions to look beyond the individual accounts and analyze behavior across like entities, networks, and time?
A man in sunglasses and a blue shirt sits in a chair, with a stone wall and blue railing behind him.
Arjun Ramakrishnan
22:09
Typically, that's the answer, right? like consortium data. Like um have we seen these bad cards on different other uh platforms before? Uh that's going to help you you know stop that even before it starts. Uh is the same financial instrument being used across different accounts in your portfolio, right? Are they using the same payout bank where they get paid out to? Is that common across say 20 30 accounts? That that shows uh you know something's going on. Uh is the same credit card used against you know those 30 or 40 accounts they're cultivating? Uh you know people go to five different coffee shops but never to 30 or 40, right? So that's going to be a giveaway also. So uh it's probably going to be at that layer where you're trying to look at mass data. See how they uh graph and link to each other across the portfolio rather than looking at individual individual data points
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
22:57
I'm glad you mentioned cards because of course we can't talk about you know AI assisted or agentic fraud happening without talking about card testing. Um that adapts in real time. So card testing used to follow relatively recognizable patterns. Um an attacker would try a tactic, defenders would then identify it. Um and controls would be deployed to stop it. Now we're seeing something more dynamic. It's evolution within the same attack. The attacker can learn from the controls uh that are being applied and adjust the attack while it's still underway. Um, so Andrew, first, uh, what did card testing typically look like in the quote old world?
A smiling man with a beard in a blue shirt against a blue background.
Andrew Austin
23:38
Yeah, in the in the old world, so I I I came through payments on my way to Sardine, um, at a large payment processor. What we would see, I mean, from the from the attacker side, you know, you have to build the script, you have to load the bins and load the cards and everything, and then you're, uh, iterating on that and getting it. You have to test out and find a website where I can actually run these and they were going to instantly shut me down. Um. what what I would see a lot of times like I remember one example we we had a PSP um that only banked movie theaters or only process for movie theaters. And they would, the the the specific attack I'm talking about. They would hit the same checkout page for a movie theater about 50,000 times in an hour until Visa and Mastercard shut them down. And then they would go to another movie theater. This is during COVID so what are people doing? Like you could maybe go to movies, but um they were hitting it 50,000 times an hour. Get shut down they move to the next one. That's it. It was just finding uh a a lot of times it's like nonprofits and um you know charities that are getting hit and they just they're small. They don't have the tooling. Uh they you know you stand up a charity for whatever autism awareness, right? you're you're expecting to receive $50, $100, maybe $500 payments. And that's what you see for the first six months. And then all of a sudden you get an influx uh you know 50,000 of them in an hour. And it just crushes them. And a lot of them, like small businesses, can put them out of business. Uh that's that's what we used to see before AI. I think as as we progress uh it it gets a lot worse. It can be a lot more scalable and I'd love to hear about what you're seeing with like AI enabled card attacks.
A man in sunglasses and a blue shirt sits in a chair, with a stone wall and blue railing behind him.
Arjun Ramakrishnan
25:38
Yeah, you know, like you you mentioned the two biggest vectors that used to help us detect and prevent uh card testing attacks specifically where usually they used to be of the same dollar amount. Like you said, it's either like $0 authorizations, uh $1 transactions or $2 transactions. Because they're just testing the cards and not trying to spend money. They're not trying to trying to, you know, donate to autism, right?
A smiling man with a beard in a blue shirt against a blue background.
Andrew Austin
26:00
They want to sell them to someone else after they work.
A man in sunglasses and a blue shirt sits in a chair, with a stone wall and blue railing behind him.
Arjun Ramakrishnan
26:02
Yeah. So, typically the way it works is, you know, they test like a dollar, $2. They figure out which of the thousand cards they have are actually valid and still working. Once they figure out, you know, the hundred of these thousand cards are still valid and working, they go on to, uh, bigger, better things. Um, buy something, you know, gift cards, um, luxury watches, etc. Once they figure out which cards actually worked, right? So like like going back to what helped us detect that there was a certain attack that was card testing was usually they'd be of the same dollar amount and low dollar amount. Like $1, $2 over and over again at a very high velocity. Because they're typically using like a shell script or something of that kind of bot, to attack a certain website. Right? So key indicators dollar amount and velocity, right? With with AI with the new age card attacks now, both of those are out of the window. Meaning the AI agent can now, uh, it can change the velocity. It's not going going to be always a payment every 5 seconds. Which is what it used to be in the old world for example, right? Regular intervals that that our machine learning models could detect. But once the AI agent starts changing that, hey I'm going to do a payment now. One in 30 seconds, one a minute after, another one 2 minutes after. Now you lose that consistency and the pattern that you used to detect in the past. So that's out the window. So what about dollar amount now, right? It used to be uh the same consistent dollar amount or consistent range change, right? Where it would be like a dollar zero, like sometimes not even a dollar, 50 cents, a dollar, $2, right? But now again, the agents adapt, right? The moment they notice that your machine learning algorithm is beginning to decline uh transactions of a certain dollar amount and of a certain velocity, now they're going to change the dollar amount. They go up to five, six, it keeps changing all the time. Makes it a whole lot uh harder for your machine learning models to detect that it's card testing going on, and decline these payments, right? And it makes it harder to distinguish between what is a payment from a legitimate donation. Uh say if it's a nonprofit versus something that's for card testing, right? So with those two vectors gone, what do you do now? You need to make your models one level deeper, one level more sophisticated, which just means that you're spending more money to build these models. Right now, uh you can't just use velocity. You'll need to use velocity on a certain IP, velocity on a certain device, right? Dollar a month from a certain IP. So you're going to have to ingest more data to have to make decisions real time. And and remember adding more and more data to uh these decisions that happen real time when a transaction is being processed, comes with a cost. Comes with an investment in the platform, uh investment in infrastructure etc. Right? So that is the added complexity that we see nowadays with uh AI agent driven uh car testing attacks.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
28:44
Love that. Um, and you kind of answered my next question, but I will probe Andrew a little bit on it. You know, if fraud rules are built around yesterday's attack pattern, how do teams defend against an attack that is continuously modifying itself? Um, you know, like how does that change what that realtime fraud detection uh needs to mean?
A smiling man with a beard in a blue shirt against a blue background.
Andrew Austin
29:05
I think Arjun touched on it, right? I mean, you have to look at the signals that are coming in. You have to go a level deeper. Um, you know, it's it's interesting you brought up how they're they can change patterns. Uh, they can vary the the transaction amount. They can they can simulate different devices, different IPs. Uh I I've actually used this tool use a tool in some of our testing uh within POC's with our clients. To simulate traffic on their websites. Where we can we can use a tool that can simulate a specific device, specific IP addresses, do different transaction amounts. And uh this this whole conversation comes out like speed and cost, right? That is that is what AI is doing to enable fraud. Speed and cost. And if I can just write a prompt that says I, you know, make x number of transactions at these 50 websites, vary the speed, the velocity, the transaction amount, here's my base transaction amount, vary it up and down by x% for each transaction. It makes it much more difficult to detect um where that's coming from and how to shut it down. I think one of the things that that I I found very effective in in the the work that we've done with our clients is is utilizing a lot of those device signals. Um and being able to detect when an AI agent is doing that, uh is critical. And when it's like when there are bot signals when it's hopping around and and just looking at does this look and feel human, right? We can use some like device and behavioral biometric signals to to determine that. And that's you know, along with modeling and all the stuff that Arjun talked about, like those are some of the thing the key things key factors that we look at to make those determinations. Fraud teams are by nature always going to be one step hopefully only one step behind the fraudsters. What we have to do is ensure that we are continuous continuously innovating to ensure that we're only one step behind. And not three four five 20 steps behind them. Because that's when the losses can quickly very quickly pile up.
A man in sunglasses and a blue shirt sits in a chair, with a stone wall and blue railing behind him.
Arjun Ramakrishnan
31:22
I think one side effect of, you know, similar to what you're talking about. Not that it's just hard to detect these new attacks based on patterns that you've seen them seen in the past, but it makes loss forecasting tricky as well. Like if you're using your steady state losses from the past to kind of have like a time series model that's going to forecast what your fraud losses are going to be for the next 6 months. Now that equation doesn't work like it used to before. Because the attacks are evolving so much that your loss forecast is going to be way off.
A smiling man with a beard in a blue shirt against a blue background.
Andrew Austin
31:52
Yeah, I think it's really interesting you you were talking about small businesses, a handyman for example. If I'm starting a new business, you're not going to be able to find anything on me if you do KYB for example. I'm a new business. My website looks legitimate. Uh I'm doing smaller dollar, smaller dollar job, smaller dollar transactions because it's smaller jobs. I'm building my book of business. I look legitimate. Because if I'm starting a business, that's what it would look like. I have a job here, you know, I might not have a job for two weeks and I have another one that pays $500 instead of $300. So these with AI, you can make it look so legitimate that it's not even questioned. So using those signals, I I love that you mentioned like maybe the same payment method is used across uh all 40 of these merchants. And maybe it's not the same card, but maybe it's all 40 of them are prepaid cards. Well, that's kind of odd. I don't know many people paying for odd jobs on the prepaid card. Maybe they do. But you know, looking at the individual signals across the network. Um, not not the individual signals, the signals across the network. To make your determination of fraud. Is is much more effective than you were talking about like looking at the looking at them one and two at a time. Uh, you're never going to be able to shut down these these AI driven attacks,
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
33:15
Which again moves us to our next topic of that imbalance uh between attackers and defenders. Um, you know, a company has to build a solution, test it, uh, make sure it does not harm legitimate customers, and then deploy it responsibly. An attacker only needs to find one weakness. Um, AI appears to make that imbalance even greater now. Um, so how has AI changed the cost of launching and testing a fraud attack? And like what can an attacker now create in hours you know that previously required weeks, specialized skills, or a significant investment?
A man in sunglasses and a blue shirt sits in a chair, with a stone wall and blue railing behind him.
Arjun Ramakrishnan
33:51
Yeah, I I call this and use the term uh cost asymmetry, right? It um before it used to cost something to to kind of build a fraud attack, right? Someone in my team was telling me the other day uh you know payment AI has changed payment fraud completely. Um, fraudsters have AI agents running 24/7. Uh, you know, good news is we we do too, right? Bad news is they don't need budget approvals. We do. So, there is that that cost asymmetry that goes on. Where today it it costs cents on the dollar to create a or create a seemingly new new business, create a website to support that, create synthetic IDs to get it approved, uh, you know, have transactions run through then, right? But once that fraud goes through. Uh on our side, even even if you have AI agents you know looking at the data, coming up with solutions, building rules, and building models. Uh really quickly it's going to cost something to, you know, have the infrastructure to deploy that. Uh make sure you don't have a lot of false positives. That way you're you know declining legitimate revenue. Uh you have to you know uh contend and compete with your sales and GTM teams to make sure you know you're not declining a lot and leaving money on the table, right? So that costs something, right? It takes time. Which the fraudster and the attack, the fraud attack doesn't, right? They just have to change one small, uh you know, variable and indicator uh to change the attack and make it look different, right? So that is the significant cost asymmetry that comes into play. Where the fraudster can uh, change an attack for the cost of a few cents. But it's going to cost us several dollars for example in terms of scale to respond to that attack and you know prevent it in future.
A smiling man with a beard in a blue shirt against a blue background.
Andrew Austin
35:35
Yeah. Um, about 10 years ago, I was in banking and there was a a new payments product that was going to be launched soon. You may have heard of it. It's called the Zelle. Um, had a little bit of fraud associated with it.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
35:52
Just a tiny bit.
A smiling man with a beard in a blue shirt against a blue background.
Andrew Austin
35:52
Just a tiny bit. Uh, before it launched, the fraud department spent like six months trying to build this business case. Give us, I think it was at the time maybe $3 million for a real-time payments fraud platform. And the bank ultimately decided, ah, we don't really need that. You know, how bad could it be? Well, we all know how bad that was. Um, you know, that was without AI. Fast forward 10 years, and I'll give another shameless plug for Hailey's podcast, Fraud Forward. We talked about this just a few weeks ago, the the cost of doing this. So, I deep faked Hailey. And when I say I deep faked her, I cloned her voice. And all it took was again another $20 subscription, 30 seconds of audio. I found a video of her on YouTube. Paid another $5 for a subscription to sync the new audio that I created to the video. And for, you know, a a couple bucks, I can have her do and say whatever I want. Imagine that at scale. It, I could take a video of you talking out in the hall. And if I can hear, a lot of us here talk on in conferences, talk on podcasts, talk wherever. If or just like on a call with a client, someone records your voice. I can now take that and have you say whatever I want. Same thing goes for the business side. It's a couple bucks. You spin up a new website. Many times it's like I talked about earlier, it's better than the original. And then I spin up another agent to target email addresses in a certain state that accesses this or I I buy a client list. You know, I can I can target these things. I spin up whatever I need to spin up for a few bucks. I target these people. Now I've harvested credentials, uh SSN's, identities, maybe card numbers, bank account numbers. I have whatever I need to operate a large scale fraud attack against a financial institution, a payments processor, a merchant, whoever I want. And it cost me 20 bucks a month. That is what scares me about AI enabled fraud. The, you used to have to go on the dark web or, you know, the deep reaches of wherever. To to get, you know, uh, a card dump, right? Then you have to have the technological knowhow to build a script or load it in a tool. You have to do some research or find the website you're going to attack. And then you maybe find 10 cards out of 10,000 are legit. And then you go rush and try to buy your MacBook uh before it gets shut down, right? And then all that comes along with that to to sell the products and launder the money afterwards. But now for, you know, got a fly attacking me. Now for a couple bucks a month, I can I can target whoever I want. And it's, you don't have to be uh, a technology genius to do this. A lot of this could be like an 18-year-old kid that watches a couple YouTube videos and finds out, "Oh, this is easy. I can make a couple thousand dollars."
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
39:27
For the record, he made a yes day video for my youngest daughter with that deep fake and that cost me that cost me some money.
A smiling man with a beard in a blue shirt against a blue background.
Andrew Austin
39:34
Yeah.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
39:35
So, I appreciate you. Were you going to add something?
A man in sunglasses and a blue shirt sits in a chair, with a stone wall and blue railing behind him.
Arjun Ramakrishnan
39:38
I was going to say, like so you know it's it's faster, cheaper and a much lower technical barrier to to conduct fraud attacks today than say just about even a year and a half ago.
A smiling man with a beard in a blue shirt against a blue background.
Andrew Austin
39:50
Yeah. Yeah. One of my favorite podcasts other than Hailey's is uh Darknet Diaries. And there might be some people in here that listen to that, but he has an episode um from a couple years ago where he's interviewed this guy. I think at the time he was like 19 years old, but he he talked about how he got into fraud and uh he started uh when he was 12. He was playing Roblox and you need real money to buy things on Roblox. And he got involved with some guys that were setting up clones of websites that would, that were basically Visa prepaid card balance checks. And they SEOed their way to the top of Google search results and they started harvesting thousands dollars of uh from prepaid cards. They turn around, and what it ultimately culminated in was a a like SIM swap event, and an account takeover, and theft of like $24 million in cryptocurrency. So my point is that was without AI. And that was a 12-year-old. Think of where we are today and what what what is stopping anyone from doing this? The goodness in their heart, right? We hope. But, you know, it just takes it just takes a little bit of education, a little bit of trying uh to to figure out how to do this. And then you're off to the races.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
41:20
So, we're at our five minutes mark. I've got that little flasher thing that just said that. Um I have two more questions. You know, can defenders, our fraud fighters ever achieve that symmetry with attackers on cost, speed, and scale? Or do we need to fundamentally change the way we build our fraud controls?
A man in sunglasses and a blue shirt sits in a chair, with a stone wall and blue railing behind him.
Arjun Ramakrishnan
41:40
Yeah, I think the answer is the latter. We we'll need to think about this fundamentally different. This goes back to, you know, what Soups was showing us earlier, right? About uh risk agentic ops. Like how you react real time as the attack is going on. Like it was a cool uh presentation he had earlier, where uh you know the agent is reading the data as it's coming in, and changes the thresholds on rules. Because that's the fastest way you can respond. You can build a machine learning model, you know, inside a day. And deploy it so you change the rules and the thresholds that the rules have real time based on how the attack is uh going on, right? Like uh what is the success that the fraudster is seeing? And how do I change thresholds on my rules to make sure you know that they do not succeed? Uh, so that real-time action is how uh we we'll need to uh kind of balance the asymmetry that we're seeing right now, right? If we are to stop these attacks. Without having to spend quite as much as we used to in the past.
A smiling man with a beard in a blue shirt against a blue background.
Andrew Austin
42:35
Yeah, it's it's an absolute must. We we have to evolve the way we're doing things. You know, I've worked with clients uh, transitioning from older platforms. And several of them want to say, you know, like let's migrate our existing rule set over to you. And you look at their rules and it's like, if if my my partner ID or my merchant ID is X, and the IP address equals or is in this massive list, and there's been no transaction activity in the last 30 days, and all these other factors, and it's like this is super specific. And you find out how they created them. It's like, oh, well, someone runs a report every Tuesday and this is, you know, we make modifications off of it. Like, that is not the world we're in today. You know, using those AI agents, using uh models to to look at data in real time and make those modifications as as we get data in and it's not just the payment data anymore. You have to expand that, you know, thinking about KYC onboarding, uh, and having a more holistic view of your customer. So you can make more informed risk decisions. You have to do that. Um, and what one of the things I like is is, not just because of Sardine. This is Andrew Austin speaking. Is device intelligence and behavior biometrics. Like I have run so many tests with our clients, and seen, and like even before uh I was at Sardine, and seeing the power of device intelligence and biometrics. Like it it is very simple things that uh, that the fraudsters will do. That are their tells. And like Soups has a presentation, I' I've heard him give many times, that's every fraudster has a tell. And they do. Like everyone is going to do one thing that uh, you can reliably see. Oh yeah. Whether it's the same device, the same IP, or you know the country not matching, like the IP country not matching, their their address, or whatever it is. There's always going to be something there that you can pick up on. So yeah, I think we we absolutely, I know we must absolutely change the way that we're building tools. And that's what we we're doing here at Sardine. That's why we're having SardineCon. Is to show you guys what we're building. Uh how we're using AI, how we're on the agentic frontier as we have banners over here, to to make this better, to make it faster. Cuz if I'm going up against a 15-year-old kid that can spend 20 bucks a month to spin up 30 businesses and drain $100,000 in a month or six months. What do we have to do to stop that? I think people at Sardine with 10 20 years of fraud experience should be able to build something to effectively combat those things.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
45:30
All right, final question, last 40 seconds on the clock. Uh, what should everyone in this room be watching for before the next AI driven attack hits them?
A man in sunglasses and a blue shirt sits in a chair, with a stone wall and blue railing behind him.
Arjun Ramakrishnan
45:41
You want to vote first? No, I I I was going to say, you know, maybe one mistake that I've seen u risk teams um make in in this arena is like looking for new kinds of fraud. Uh I don't think it's new kinds of fraud, but the same kind of fraud. It's just more sophisticated, faster, and costs less, right? So, it's going to be the same stuff, but it's going to hit you faster. Um that's like the biggest takeaway that I've had, you know, from what you see so far.
A smiling man with a beard in a blue shirt against a blue background.
Andrew Austin
46:06
Yeah. Uh I have five seconds. I just say keep innovating. Don't stop innovating in this space. Uh not just from our side. I say that to the sardine folks, but to you guys out there that are doing this every day. Don't stop innovating because as I mentioned earlier, you don't want to be once you want to be one step behind, not 20 steps behind.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
46:26
All right. Thank you guys so much.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
46:34
Thanks for listening to Fraud Forward. Remember, every conversation, every connection, and every insight moves our industry one step closer to stronger fraud defenses. If today's episode sparked an idea, share it with your team or tag me on LinkedIn. I love hearing how you're moving fraud forward in your own organization. Until next time, stay curious, stay resilient, keep moving fraud forward.