Welcome back to Fraudology. I'm Karisse Hendrick. I am really excited for you guys to learn from my guest today. He was highly recommended by Matt Vega, who we know on the podcast. And Matt's one of the smartest people I know in the industry. So when he tells me I need to have a friend of his on the podcast, I listen. And I can tell you based on the fact that we've already been yapping for 45 minutes, not recording, this is gonna be a great episode. Cy has been in this space for a really long time and has had a purview that not many people have. So we're gonna talk about AI, of course. We're gonna talk about a lot of what the adversaries are doing with AI, and how they're using it. But I would just love to welcome Cy Khormaee, from Aegis.AI. He's the CEO and co-founder of Aegis, and I just he just got back from Black Hat. So, survived that. Welcome to Fraudology Cy.
Graceful hey. Such a pleasure to be on the podcast. I've listened to a bunch of the episodes. So I've been a fan for a while. And then I think Matt said the same thing about you. Where you're just one of the people that really drive the fraud community. And just Matt knows, just so many amazing people. It's always a fun time when we get to chat. And like you said, I think we could have chatted for another two or three hours before hitting record. So I'm glad we hit record. And then we'll dive in, but it's a it's a fascinating journey. And so many fascinating overlaps in you, and me, and Matt, and the worlds of fraud and security. Which I'm sure we're gonna dive deeply into in this episode.
Mm-hmm. Yeah. So I always start, and I didn't warn you ahead of time, but I always start at with the same question for all my guests. So you you know, if you've listened to a few episodes, you know. It's because everyone has a very different answer. How did you get into fraud?
Yeah, it's a great question. Yeah, again, not surprising. I also I love the way you asked that. Because I think it it helps sets the stage for everything else to say after that. It's like how did I get here? What's my perspective?
Yeah. It gives you context for everything you're gonna say next. Yeah.
Exactly. It's it's the why. And I'll tell you, so I really started my fraud career at Google. And it started a little bit accidentally. So there was a a leader named Gordon Chaffee who I worked with when I was at Lightspeed Ventures. He was the VP of engineering at Riverbed for a long time, then became a senior leader at Google who started the Google security business. He's someone I respected incredibly, but I thought was still running a startup, and so I was pinging him looking for something else to do in the space. And I'd not really done much in security before. And he was like, hey, I have this amazing team at Google called Safe Browsing. If folks don't know what that is, this is the team that has phishing and malware defenses that are deployed across pretty much every device on the planet. Billions and billions of devices. Every phone, every computer, I bet every device this podcast is being listened to is protected by Safe Browsing. And so, you know, we need to start commercializing this. We need to take this from an internal security tool, a really amazing thing that Google has built for the planet. And we need to make some money off of it. Because it's gotta be part of cloud. And he was like, you're the guy who knows just enough about the technology. And just enough about business to really help this very technical team come into the commercial world. And that was really my introduction and landing at Google and getting to really interact with these incredible engineers that built this platform that largely protects the entire world from phishing and malware and fraud. I'd never really gotten to operate at that scale. I'd never really engaged with a mission I just connected with so deeply of keeping the internet safe. As a long-standing nerd, I care a lot about the internet.
And then helping connect them to an enterprise sales motion, so they could profit off. And again, most of the companies on the planet now use this technology as the underpinnings of all of their fishing fraud and malware defenses. And so that was kind of my entry into the world of security and fraud. Kind of by surprise. But like all good things led with the best of possible people. And historically, I've just followed the best people, and it's worked out really well for me.
Wow, and you were a big part of the reCAPTCHA team as well.
That's right. So, you know, as part of this journey, we started building what we call the user protection platform at Google. Which is a broader set of people and teams that I ran, that were responsible for defending users across all of Google's products, as well as broadly in the world. So, how do we keep more people safe? How do we sell services to companies like Zoom and PayPal, and even other cloud scalers, in order to keep their users safe. And it started with, you know, phishing in malware. And then the next thing, if you phish someone's password, what do you do? I use it in credential stuffing, I use it in carding, I use it in synthetic identity. How do we stop that? It's by using something like reCAPTCHA to look at the behavior on the page and determine whether it's malicious or not, legitimate or not. And it's funny. You know, we, you know, tell you the story later. But we transitioned this tool from, you know, initially it was this AI training tool, it'd been part of the maps division, it was kind of looking for a home. And we said, hey, as credential stuffing is spiking, this was twenty seventeen. So many more passwords being leaked, there's so much credential stuffing happening. We're like, hey, we can use this tool, that observes all this behavior, and can start to determine legitimate from illegitimate behavior, and use that to stop adversaries who actually have the right password and the right username. And that was a big evolution in the space. And we've added several other technologies on that team, eventually became a hundred plus million dollar business for Google. But you know, from very, very humble beginnings of you know, zero dollars for us, zero dollars in the Google security business. I think when I left, the Google security business was, you know, a billion dollars, and we were probably a hundred million plus of it.
Wow, that's quite a ride.
It was an amazing ride. Again, a a real gift where I'm I'm very grateful to Gordon and then my manager Jess. Both by the way, who work together at Riverbed. So again, the this theme of you see the same groups of good people popping up over and over again. And then by the way, you fast forward to ages a little bit and look largely the same crew that we work with back there. So again, this theme of find great people, like yourself, find great people like Matt, find great people like Gordon, follow them around has been a persistently helpful strategy for me.
Well, you're not so bad yourself, with all that you know as well. So I kinda, knowing that we're gonna take some twists and turns, I kinda wanted to start out with where we started out talking when we got on the phone before we were recording. I had asked you what the themes of Black Hat were. I've never been. It's been something that I've kind of wanted to go to, but it's always in the like heat of summer, just so hot in Vegas. And I've been intimidated to go, but that's a whole other story. But I I asked you the themes of Vegas, and then that got us on some good topic or of Black Hat. So it that got us on really good topics of what's impacting fraud right now? So, you know, you said AI, of course. Of course that's gonna be the topic. But what is it about AI that you've observed is, you know, should keep us up at night, is keeping up us us up at night? That we need to be, like, aware of.
It's a great question. But before we go into that, just two seconds for folks, you know, from the fraud world attending security events. We'd love to see more of it. Despite the 114 degree heat. Which that I can't tell you is good. It's it's it's brutal. I will tell you, outside of that, like the community is super welcoming. And from being on both sides of these communities, they're extremely similar. And we'll talk more about this. There's a lot of overlap. And just like, I mean, folks who go to MRC, fraud is really intimidating. But you meet the people there and they're genuinely trying to do great things. They're super sweet. They're so nice. They're so giving with their time and energy. And they want to educate others. It's very much the same type of human, on the security side. So while it might seem very foreign, I think it's just two sides of the same coin. So I hope to see you next year there, or come up and hang out at RSA for our next one. So open invitation. But to your specific question, I think the two things that are really emerging as kind of things to be aware of, especially on the fraud side, is one, is there's first of all, it's it's really becoming real. So I think two years ago, it was kind of a theory. A year ago, it was kind of a thing, you started to see little sparks of it, started to be a concern. Now AI attacks are real, they are breaking the existing stack. It is not a question, it is happening now, and the biggest fear overall is that it's happening so fast. We are not positioned for success the next year or two. The rate of attack, and severity of attack, and bypass rates, is rapidly outstripping the adjustment of existing platforms. So everyone acknowledges we need to move to a totally different stack. We need to move from this classic scene attack, ride a rule, get some animals involved, which is by the way the exact same across security and fraud.
To full AI automation, right? It's this it's the same stack, and save movement. And the challenges are organizations, particularly from you know FIs and the financial space across fraud and security, are very nervous about this. Because you're asking them to now move at a pace of weeks, not years. But now they have to, otherwise, the downside from the adversary is gonna be worse than the downside from technology implementation. I think that's a good.
Right. It's gonna cost a lot more to lose money than it is to invest quickly. Right. Good point.
Exactly. Like if you do not move, you will be compromised. Full stop. One of my favorite stats is, you know, we look in the email space. We look at the rate of emails bypassing existing controls. It's now over 50%. So the average email we see is a 50-50 pass rate for existing filter controls. Which considering the cost of sending emails is like somewhere around free. If you're using one of those controls, you will be compromised, full stop. Just a matter of a short period of time. So you must move. So the good thing is everyone recognizes that. So what they're trying to do, struggle one, is adjust the organizations so they can actually adopt technology faster. You can't have a three-quarter, four-quarter procurement process, if the technology is shifting every three weeks. I think that's one. I think two is they've got to get the human out of the loop. And the thing that we talk about a lot is thinking about humans with AI as gardeners, not carpenters. Meaning typically with a platform in fraud or security, you have analysts and engineers building the solution. They're saying every single step, here's what we're doing, here's the process, here's the GTP for every single thing we're doing. Inevitably what you want to do with AI is actually let it grow. And you wanna foster it and trim it and nurture it, but you're not in the middle of it. You're really letting the AI grow and cook and do its thing. While you're there guiding and watering and feeding with data and results and things like that. So I think we've got to move from that. Very discrete, very human-driven process to a much more organic, AI-driven process. That by the way will evolve a lot faster and evolve faster to respond to the threats that AI presents. And then the last, which is really relevant to the security and fraud conversation, is these tools now need to integrate with each other to get a little more nerdy here. By the way, my first job ever was as an ETL engineer at Microsoft, so we'll get really deep in here, is that, and fraud fighters probably resonate with this really well. Getting different data types to merge into cohesive results and conclusions is really challenging. I'm sure a lot of people listening spent a lot of time fighting SQL to get it to do what they wanted it to do, to find the data they needed. The really cool thing about AI is it's really good at understanding context, and you can actually point it at a heterogeneous kind of data lake or data swamp in this case, which is not that well organized. And it will kind of figure it out for you, and draw conclusions that you couldn't before. And it can do things that maybe a fully, perfectly normalized database could do without having to normalize it, which is kind of the dream. And so I believe there's this massive convergence of tools, not just in fraud, not just in security, but across fraud and security that's going to happen. So for me, those are the three major themes put on my fraud fighter hat that I heard at Black Hat from the security community.
I like that. And I think those are all things when I'm having conversations with enterprise merchants that they're struggling with. I think the only other thing that they're also struggling with, and this is not to go down the rabbit hole, but just to kind of call it out, is these mandates from on high. From C-suite being like, you must integrate AI for 25% of your job by the end of the year. Or something crazy like that. But they want it to be like open source tools, not necessarily like a third-party fraud provider that uses AI. And so that's been a real challenge for, you know, enterprise fraud. And I assume it, that banks are having the same conversations. But putting that aside for now, I might have you come back for us to talk about like if Claude could actually, you know, stop fraud. But that's a whole other, that's actually a title, a session title that I just created for Merchant Fraud Alliance. Because I'm hearing from so many merchants that that's basically what they're being asked to do. And I don't think we're there yet, but that's that's a whole other conversation. But going off of those three points that you said, I absolutely agree that the adversaries are moving so much faster than we ever can. They don't have to ask for budget approval. They don't have to get legal involved. They don't have to get, you know, security screen. Like all the things that we on the, you know, quote unquote good side have to do to implement something new. Not to mention the RFP process and vetting the vendor and deciding which vendor to work with. And which vendors are full of shit and which ones actually have AI that that can conquer adversarial AI. So we have so many more steps to our process than they do, which is why we move slower. So trying to speed that up is gonna be a challenge. Especially when the point at the end of that process is to hand all of your data off to a third party to analyze and put you, for AI. It's not just like you're, you know, you're hiring someone for a job. You're giving them the keys to your kingdom. So you gotta trust them a lot. And you have to know that they're, that they're gonna work. and that they're moving as fast as they need to too, right? You need to find the right vendors that are moving fast enough to be able to cut the adversarial AI off at the pass, right?
Yeah, you gotta move faster than the adversaries. By the way, I think one thing we talked about, I'm happy to share the audience, those who have video. And if not, I'll I'll do my best to narrate in the middle, is maybe some of this evolution of technology from the adversarial standpoint, right? So the first thing we're gonna show is to your point, you asked kind of can I use Claude to spot fraud? Well, let's say can I use, in this case, ChatGPT to create fraud. What I'll show is kind of example of how you can use Chat GPT to create phishing emails to phish, in this case myself. And like you said, adversaries are not bound to using data they have approved or had, you know, a compliance committee on. They're just gonna go in there. In this case, what the demo is showing is like I typed in, hey, find a bunch of data about Cy. Goes in and finds a bunch of data about me. Finds podcasts, finds conferences I'm presenting at, finds a bunch of good information about me that's potentially useful in crafting a contextualized attack, including
What this implies, upcoming and recent event appearances. Wow, yeah, a lot of things.
I but I built this demo for the e-crime 2025 conference. So that's why it was particularly relevant at that time. And then you can ask it to give you some ideas and it'll give you like, you know, PR notices. My favorite here was
What types of emails to send you. Wow.
Yeah. My favorite was, hey, you know, a speaker conference confirmation. Which I thought was particularly clever. I would have, on an airplane, I would have clicked on that.
And then finally, it'll build, and it shows live here an entire website that mimics the format and content of the conference website. To mimic as it does my data collection. Now, this is an example of the lowest of the low-tech approaches. Where this is Chat GPT, no context, me typing prompts in live. This is one-shotting my way towards being a fraudster. It's just that easy. And that's kind of the native model side. That's just like the basics of the basic. And then the kind of the next question is like, what could we do if we had people much smarter than me, like some of my teammates, go and fully automate this? And so the next demo will show is an example of what that looks like with customized AI. Which is really the next level. We find generally is that, you know, you can get 10%, 20% of the way there with native AI like Claude, like ChatGPT. But building custom models, you can dramatically exceed the capability of any analyst. And by the way, I used to run our SOC team. After about three months, I got fired because I was less useful than the AI. So that's the one other career twist that happened. Just like it was so much better than I was, I stopped being useful. And so again, we think about that carpenter versus gardening. I moved out of that role. And so just quickly, I know there's a lot of text in this example, but you're finding is that the AI behind the scenes is, again, researching our company. It's researching the researcher, who is the attack target in this case. Trying to figure out a way in. It's thinking about vectors, who can I impersonate, how can I add pressure? It's aware we're security company, so it's planning an attack that's specific to some of the most hardened security-aware professionals it can attack. It's gonna go through and look at comparisons and kind of start to run internal tests to figure out A-B testing internally in its own mind what might work, what might not work. And then eventually it comes out with these picture perfect documents. Where one says, you know, hey, like, it's a document from me, the CEO, to one of our researchers. Asking him to, you know, an RFC, asking him to comment on a thing. And then another is a note from our investor. To this researcher saying, Cy, the CEO is too busy. Do you have 10 minutes to jump on a call with me? So these are contextual, they're accurate, and they're all done using purely open source information. And so one of the topics we spent a lot of talking about for recording, I think is really relevant for the audience to think about is, how vulnerable am I if someone knew everything there was to know about? Me, or at least everything on the internet. And then the second question is: how vulnerable am I if someone used that same data about all of my connections? It's school, my dog walker, my colleagues, my friends. Pick your top two least security-aware people that you work with, or you communicate with on a daily basis, and imagine if they are fully compromised, and imagine how easily they could compromise you. And just so you know, this is not a theoretical, you know, Google, we really cut our teeth fighting state actors. This is common behavior for state actors. And only because it was expensive ten years ago, and I just showed you an example of how to do this in a fully automated way. Because it's fully automatable now, the cost is effectively zero. And so it's going to become common and if not already as common.
No longer are spear phishing emails, you know, a copy-paste template that gets sent out to, you know, all the CFOs, you know, at Fortune 100 companies. Or whatever it is. Now they're tailored very quickly and at a very low cost. To have context. To have, you know, from a connection that you know, have it appear from a connection you know. With a context that would make sense of why they were reaching out to you, with the goal of either, you know, wiring money or having them click a link, get malware, get into their system, possibly turn into ransomware. All of those different, you know, things. Then it can turn into account compromise at banks. I mean, there's just so many different layers. If they've got key loggers and that malware, then they can, you know, get their logins to their bank and their investment portfolio and everything else. That is terrifying and also shows though just how easy and cheap it is. I mean, maybe business email compromise isn't within the purview of some you know, of my listeners. But I think that knowledge can be easily applied to the kind of fraud that they are fighting and seeing.
Yeah, absolutely. And by the way, it affects regular users all the time as well. I mean, maybe another example I can share is you know, and this is obviously a dummied up example of the recent Robin Hood attack, if folks are aware. Where, you know, a marketing server at Robinhood was used to send phishing emails to customers. But it was fully legitimate from the perspective of any email security tool, unless you looked at the content. And so you basically see, now again we dummied up this information to protect user privacy, but this is all from a real attack. It's coming from the right source, it's coming from the right DMARC SPFDKIM IPs, everything, because it's literally coming from real servers. And so you need to find, that is actually, you need to start to analyze things every single time. So we're showing here is kind of how you can go beyond Claude. This is kind of the next level. And start to automate the investigative steps. Every analyst has a playbook. Every analyst has a playbook they're running through. They're limited by the fact that they're human, for now. And they're like trying to do things step by step. They limited time and energy. The cool thing about AI is it has essentially unlimited compute, unlimited time, and it can look at all the data every time, which is really powerful. So it can spot really strange things. Like in this case, the HTML diverges from the canonical Robinhood template. And what we really mean by that is like, I have seen a lot of Robinhood emails as agents. We know their CMS system uses this specific tailor marks. There's kind of things they do that are pretty common across the CMS. This message diverged from that. Weird. No analysts, no no at least I wouldn't as an analyst be able to spot them, but as an AI, it's gonna detect very odd things like that that you couldn't write a rule to detect. And then of course we can crawl in real time and find these malicious outcomes through things like automated sandboxing. So again, you know what a lot of analysts will do is they'll go and they'll go from one of these attacks or brand impersonations, and they'll go use that to steal user data, et cetera. And so we'll be able to spot that by replaying the attack in a browser. I'll show you example kind of what that looks like. In real time, before the user gets there. And so in this case, this is an attack where they've hidden a password and an email, and they got the user to open the email and type the password in. This affects consumers and businesses, so it's a source of fraud on both sides. But we can open it, we can look at the document, we can bypass fake captions, we can do all the things that regular humans can do in order to find the fraud and detonate it before the user gets there. That's why that we call the system Vanguard, because it runs ahead of the users in order to ensure that the path ahead is safe and kind of light the way. So that's one of the many examples of how we can start to use AI to combat these more advanced AI techniques because I think they're moving past a point where the human eye is really going to be capable of spotting them.
So another thing that I wanted to touch on. You kind of hinted at a little bit. But actually in last week's episode, I went over a study that had been done by Lumen and Accertify. About why fraud and security need to work together. And they talked about how the tools being used by cyber and fraud are very similar. They're looking at pretty much the same signals. They're looking at, you know, same kind of data. They're analyzing that data in a different way. They're cross-checking that data in a different way. There's consortium data that, you know, that they each have access to. But they said in the study, and I'm hoping that I don't butcher this too much, but they measured the success rate of a fraud team. They found a metric that could be used. I think it was like something to do with the your percentage of approved transactions divided by the percentage of your chargeback rate. Or something like that. And that created this metric. And they looked at the the performance of over 50, you know, very large enterprise companies. They work with most of the, you know, a lot of them. And asked those people, you know, how many use cases where cyber and fraud interact, like, you know, login or, you know, account creation or, you know, whatever it is, bots, you know, that type of thing. How many of these six, seven use cases do you work with your cyber team on? And the more use cases they worked on together, the better their metric was. And they also talked about, you know, it wasn't so much about like the convergence of tools. Like using the same tool all the way through. But it was saying, like, hey, this is really important to work with them because cyber criminals don't care if they're, you know, penetrating your cybersecurity team or your fraud team. And most of the time they're gonna do both at the same time. Especially with AI, because AI is finding all kinds of gaps and vulnerabilities, especially in those spaces between those two teams. I know that this is a a subject that's near and dear to your heart too. So I'd I'd love to just hear you talk a little a little bit about it.
Totally, and actually it kind of brings us full circle back to also like how I started working with Matt. So, you know, Matt was at Instacart. This is you know during COVID when fraud was all sorts of interesting things were happening in fraud. So Matt was at Instacart, I was at reCAPTCHA. We were a security tool. Matt was a fraud fighter. We were different, different worlds. And then there was a bunch of carding issues they had at Instacart, and it was becoming a pretty critical concern. And they had reCAPTCHA and they asked the question, like, can we use a security tool to stop this fraud problem? And my honest answer is like, I have no idea, but let's dive in and see. And what we found is, it actually works really well. And so reCAPTCHA traditionally has been a tool that identifies if this login is legitimate or not. So kind of very top of funnel. And you can imagine a lot of the fraud signals are at the very back of the funnel. So that checkout effectually or takeout, right?
Mm-hmm. Traditionally, I mean the better, newer solutions are looking across the entire customer journey. But traditionally, yes. We only look at, you know, checkout.
It was pretty recent by the, so you know again, not to date myself. Like this is back in you know 2020. I think we started on this journey in 2017, and they were very, you know, it's literally fraud was at the back end, securities at the front end. They didn't talk. And are like, that's weird. And exactly what you said, makes all the difference. Is that the attacker is gonna come onto your site. It's gonna start by, at the you know, scraping your pages. And then it's gonna log in and try and use a compromised credential, or do a synthetic identity. It's gonna navigate your site, and try and emulate behavior. And then it's gonna do the checkout. Two things are true. One is that the further up the funnel you can stop the attack, the cheaper it is to stop the attacker. The second is, the more data you use about that behavior, the harder it is to commit that fraud. An example I use, if I walk into a store for one second, you gotta determine I'm a fraud store or not, very difficult. If I'm in your store and you have camera video of me for an hour, it's very hard for me to pretend to be a good or reasonable person. And so it just makes their job harder because there's more data. And I'll show you one thing. Me and Matt both worked on this. I took, I take you know 10% credit for this. A lot of this is Matt’s brilliance, but, looking at also the tooling. Where not only do you want to look at the same behavior, but it to your point, Karisse, it's literally all the exact same tools of security and fraud kill chain management. So, what are the signals on the networking side? What are the interactions on the client side? And then identity. Who is this person? Where do you find them on the internet? And then using these interactions to merge the two. Even with Sardine, like we work close with Sardine, because Sardine and the signal has like a lot of good data on ACH accounts and account reputation, information that we don't know anything about. And we have a lot of information on email identity and client-side behavior that isn't visible to a transaction-based service. By marrying the two for our customers, we're able to fight a lot of this emergent fraud, particularly on the B2B side, where an example, many manufacturers struggle with their smaller vendors being compromised and used to attack them. Imagine you get an ACH request from a known vendor. The number has changed, everything else is the same. How do you spot that? You really need both signals. And so this is kind of an architecture Matt and I worked on that's kind of showing how both of these teams could work together. Because what's cool is not only are they looking at the same data, not only do they think about the data in the same way, they just have slightly different goals. So actually, my push towards the audience here is to go look across the aisle what your friends in security have and encourage them to be the same. And say, one is how can we get access to your data? Two is how can we start to combine both of our data into a single data lake or at least provide joint access? And three, how can we start running queries across the joint data sets, maybe initially with existing tools like SQL, but very soon with tools like MPC? That again can start to ignore all of the data normalization hassle that happens with SQL. And just ask a question of like, do you see anything weird about this user side when you look across all of our networking logs, all of our EDR logs, and all of our credit card data and transaction data? What looks weird to you? I think that's a fascinating opportunity. And I just think these worlds are just inexorably moving closer and closer together as the processors get more complex, and also as integrating them becomes much easier.
Yeah, that's a good point too. Yeah. I don't disagree with anything that you said. And I I and it doesn't surprise me that, you know, you and Matt came up with that, you know, kind of you know, visual to show, you know, how they can work together. And yeah, because traditionally, I mean, in the past there's been like some rivalry between fraud and security. There's been a lot of misunderstandings and you know, that type of thing. But I but I wholeheartedly agree that the companies I know that have created some kind of fraud fusion center, some kind of fraud cyber fusion center, are light years ahead of the companies that haven't. Additionally when they're looking at fraud tools, the fraud leaders that are able to keep up and you know see what's coming, are looking at tools. Like Sardine is an example. Of tools that are across the entire customer journey. And that are pulling, you know, from the time they go on the website all the way past checkout. And every single signal. And then they're, you know, comparing that to the last time they logged on. And, you know, creating a profile. So that then if someone else logs into that account, you know, whether they're spoofing the device or not, you know, maybe they are hijacking the session. They can still identify that that isn't the same person that is logged in the 20 other times.
Yeah, 100%. And it, funny you mentioned the rivalry. I always find it's like siblings. Like rivalry always happens when you're very close. You can either be best of friends or you can fight it out. Like one of the two. I encourage you to work together, but you know, both happen. I mean by the, even at Google. By the way, you know, we work very closely with Google's own fraud team over there. In order to build a lot of these solutions. Cause like we observe the same thing happening. Us and our customers. So I just saw this across us as a vendor, across our customers. To your point, this is a really broad theme that's happening. Despite maybe organizational friction to make it happen. It's kind of this inevitable path the teams are going. Which I think by the way, maybe I'll I'll close and say that's also what makes life hard for the adversaries, right? If we think about the 187 between defenders and attackers. What makes it hard for defenders is we gotta be right every time. Adversaries just gotta be right one time. The advantage of the defenders is we can be broadly collaborative, not just within our own teams, but as an industry and a community. We all share data, we're all trying to fight the same war, we're all on each other's sides. Small rivalries aside. And that data estate makes it very difficult to fake identities and emulate and fool systems. So kind of, the more we work together, the broader that team becomes. That is to hold our community. The stronger we all are together and the more difficult we make it for the adversaries. And my strong belief is that's the one advantage we have as defenders. Is working together in mass. Everything else is working against us. So I think the more we can collaborate, the more we can draw these connections, the more we can share data and ideas and technologies and work together, the better we're all going to be.
I'm so glad that you brought it back to that. Because that's exactly what I was gonna bring it back to. Was, you know, at the beginning of our conversation today, you were talking about you just how fast the, you know, adversaries are getting with AI. And how easy it is for them to spot vulnerabilities. And the the longer the chain of data, the longer that, you know, the like with your analysis, you know, analogy of going into a store. Like the longer time that you have to observe a potential adversary, the more likely you are to identify their intent. And if you're working from, you know, the cybersecurity side all the way through fraud and the payment data and the checkout, you have a full picture. And that allows you to identify those AI attacks so much faster. Which as you said is, you know, cheaper. And also just keeps your system a little bit more clean. You know, you don't have as many like down the line declined transactions from the bank, because, you know, you had a carding attack. Right? So, this is fascinating. We could honestly talk for three more hours and I think it would still be relatively interesting to my audience. I'm gonna have to have you come back soon. I would love that. I just love geeking out on fraud with smart people. And I guess, just is there anything else, I mean we've talked about a lot in a short amount of time. But anything else that you'd wanna, you know, say to fraud fighters?
No, I think that was it. By the way Karisse, thanks for having me on. I always love to talk to this audience. And just I'll just re-emphasize like, please go reach across the aisle and work with your fraud partners. I'll say the same thing to security. Sorry, the security folks, please work with the fraud folks, fraud folks work with the security folks. Again, this connective tissue, the collaboration, is the number one advantage we have. So let's like, push it to its fullest.
Yeah, Yeah. And I, the one other thing I wanted to mention, is just like how I genuinely thought the business email compromise had kind of been solved for. And I've learned from you today, on both the non-recorded and the recorded conversation, that that's not the case. Because AI continues to get better, and make them be better. So I think even just, you know, kind of applying that to enterprise fraud or banking fraud. Don't be surprised if we see some older tricks of the trade, that we thought had been solved for, that we thought our fraud tool, you know, could pick up, you know, starting to come back.
What's old is new. By the way, I talked to the FBI recently here in closing, and just BEC email attacks are consistently the number one report of fraud. And then the com, we got a dozen agents working on it, and there's tens of thousands of reports, billions of dollars lost. I think it was three billion dollars last year. And so there's like, please as an industry, you and me, do better because I'm working really hard here. But I can't investigate all of these. So please, please, please do better. So, we’re working hard.
Yeah. Yeah, no, I and that's, and thank God you are, right? 'Cause if you didn't, who would?
You and me. Us together. Security and fraud. Better together, forever and ever.
I'm here for it. I'm here for the campfires and the kumbaya and the whole thing. I really appreciate you stopping by and everything you said. I will include a link to your LinkedIn in the show notes so people can connect with you. You're obviously, you know, very accessible and very, you know, a very brilliant person to follow on LinkedIn. So thank you so much. And good luck with you at Aegis. I'm, not that you need my luck, but you know, I'm excited to see what comes out of Aegis as well.
Thank you so much, Karisse. And and until next time, I can't wait.
Yeah, me too. Have a great rest of the day.