Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
Fraudology

Fraude facilitado por la IA: cuando el crecimiento se antepone a las salvaguardias

39 min

Bienvenidos de nuevo a Fraudology.

La IA ya está aquí y está haciendo que todos los tipos de fraude que ya conocemos sean más baratos, rápidos y difíciles de detectar. Vamos a repasar varias historias que muestran exactamente cómo se está manifestando actualmente el fraude facilitado por la IA: desde las pruebas masivas de tarjetas hasta un caso de fraude muy complicado.

Esa historia es la de Polymarket, y le dedico bastante tiempo. Es poco habitual tener tanta visibilidad sobre los detalles concretos del fraude en una empresa. Una investigación de The Wall Street Journal expone el uso de tarjetas de débito robadas vinculadas a miles de cuentas nuevas y una tasa de depósitos fraudulentos que llegó al 80 %. También hablo de pedidos de reparto realizados mediante deepfakes generados por IA, de una nueva advertencia de una coalición bancaria sobre el fraude en el comercio mediante agentes autónomos y de las estafas que utilizan la clonación de voz con IA.

No estamos eliminando el fraude, porque nunca podremos hacerlo, pero sí podemos conseguir que la información circule tan rápido como los defraudadores, o incluso un poco más rápido.

Lo que escucharás en este episodio:

  • Por qué el fraude mediante ataques BIN y las pruebas de tarjetas con IA han aumentado más de un 75 %, según al menos un proveedor de soluciones antifraude, y cómo los estafadores están optimizando ahora la autorización de pagos del mismo modo que los equipos de pagos legítimos
  • Un análisis completo del escándalo de fraude de Polymarket, incluido el riesgo de fraude en los mercados de predicción inherente a su modelo de negocio y las decisiones de la dirección que empeoraron la situación
  • Por qué Polymarket eliminó su regla que exigía retirar los fondos a través de la misma fuente para agilizar los pagos, y cómo esa decisión dio lugar a graves fallos en la prevención del blanqueo de capitales
  • Una grave vulnerabilidad de fraude por apropiación de cuentas permitía que una cuenta nueva, creada con el número de Seguro Social robado de otra persona, heredara su saldo existente y sus tarjetas vinculadas, sin necesidad de contraseña
  • Por qué, al contratar personal para los programas antifraude de cumplimiento normativo, se necesitan personas con experiencia real en prevención, y no solo investigadores que intervengan después de los hechos
  • Cómo se materializa el riesgo de fraude asociado al crecimiento a toda costa cuando, según se informa, la respuesta de un CEO ante una tasa de fraude del 80 % es «simplemente sigan creciendo y paguen una multa»
  • Un nuevo informe de una coalición bancaria sobre el fraude en el comercio agéntico y por qué la responsabilidad por contracargos de los agentes de compra con IA aún carece de un marco real conforme a las normas actuales de Visa y Mastercard
  • Una orden de entrega falsa generada por IA que se utilizó en un intento de robo en una tienda Walmart, y la advertencia de un jefe de policía de Georgia
  • Cómo es realmente por dentro un programa de supervisión de contracargos y por qué el hecho de que Polymarket haya contratado a un proveedor de prevención del fraude como Riskified dice mucho sobre la gravedad que llegó a alcanzar este problema

Deberías escuchar este episodio si:

  • Trabajas en pagos o en la prevención del fraude con tarjetas o en el comercio minorista, y quieres una visión realista de cómo la IA está ampliando ataques que ya conoces
  • Están desarrollando o evaluando un programa de supervisión de contracargos y quieren un ejemplo real y público de lo que ocurre cuando las tasas de fraude se disparan
  • Les preocupa el riesgo de fraude en los mercados de predicción o siguen las repercusiones regulatorias y legales en empresas como Polymarket
  • Son responsables de dotar de personal a los programas de cumplimiento contra el fraude y buscan argumentos que expliquen por qué la experiencia en prevención es tan importante como la experiencia en investigación
  • Hacen un seguimiento del fraude en el comercio agéntico y quieren comprender el vacío aún no resuelto en materia de responsabilidad por contracargos relacionados con agentes de compra de IA
  • Quieren ejemplos prácticos y reales de pedidos de entrega falsos generados por IA y estafas de phishing con IA para compartir con su propio equipo de prevención del fraude
Notas del episodio

El fraude con tarjetas facilitado por la IA comienza con pruebas de tarjetas más rápidas e inteligentes

Antes, la comprobación de tarjetas consistía en introducir manualmente los números de tarjeta uno por uno. Ahora basta con cargar una hoja de cálculo y ejecutar un script, lo que explica en gran medida que un proveedor de soluciones contra el fraude haya registrado un aumento superior al 75 % en esta práctica. Los estafadores ya no se limitan a comprobar qué tarjetas son válidas. Utilizan la optimización de la autorización de pagos del mismo modo que los equipos de pagos legítimos: analizan los datos BIN y los detalles de las transacciones para aumentar sus propias tasas de aprobación y hacer que las compras futuras parezcan más legítimas.

Dentro del escándalo de fraude de Polymarket

Una investigación de The Wall Street Journal revela hasta qué punto se deterioró la situación en Polymarket, una plataforma de mercados de predicción que ahora se prepara para salir a bolsa. Los estafadores vincularon tarjetas de débito robadas a miles de cuentas nuevas e intentaron sustraer al menos 10 millones de dólares; en un momento dado, los depósitos fraudulentos llegaron a representar el 80 % de todas las transacciones gestionadas por el procesador de pagos. Según el informe, la dirección habría dicho a los empleados que expresaron su preocupación que siguieran impulsando el crecimiento y pagaran una multa si los reguladores llegaban a percatarse, un nivel de riesgo de fraude derivado de la estrategia de crecer a toda costa que rara vez se ve documentado con tanta claridad.

Por qué la regla de retirar fondos a la misma fuente es más importante de lo que parece

Uno de los principios más útiles para prevenir el fraude que se desprenden de esta historia es una regla que la mayoría de la gente nunca ha oído mencionar de forma explícita. Exigir que los retiros se devuelvan a la misma fuente de pago de la que proceden es una medida sencilla y eficaz para prevenir el blanqueo de capitales. Polymarket eliminó esa regla para agilizar los pagos a los clientes y, como era de esperar, las tasas de fraude aumentaron a la par.

Una vulnerabilidad de fraude por apropiación de cuentas que debería preocupar a todos los equipos de riesgos

Más adelante ese mismo año, los usuarios de Polymarket se vieron afectados por otro tipo de fraude de apropiación de cuentas. Si alguien creaba una cuenta nueva utilizando la información personal robada de otra persona, incluido su número de la Seguridad Social, podía acceder de inmediato a la cuenta existente de esa persona, así como a las cuentas bancarias y tarjetas vinculadas, sin necesidad de contraseña ni nombre de usuario. No se trata tanto de un problema de fraude como de ingeniería, y conviene recordar que los fallos relacionados con el fraude y la seguridad suelen ser el mismo fallo con etiquetas diferentes.

La brecha en materia de contracargos en el comercio agéntico aún no se ha cerrado

Una coalición de bancos publicó recientemente un informe sobre el fraude en el comercio agéntico, en el que señaló preocupaciones reales sobre los agentes de compra con IA que introducen directamente los datos de las tarjetas o dirigen a los usuarios hacia métodos de pago con menos protección. Sigo pensando que el problema más urgente es la responsabilidad por los contracargos derivados de las compras realizadas por agentes de IA. Si un agente de IA comete un error o realiza una compra que el cliente no pretendía hacer, actualmente no existe ningún marco en las normas de Visa o Mastercard que responsabilice a la plataforma de IA en lugar de al comercio.

Los pedidos de entrega falsos generados por IA y las estafas de clonación de voz ya son una realidad

En Georgia, una persona fue detenida tras intentar salir de un Walmart con productos electrónicos utilizando una orden de entrega falsa generada por IA y haciéndose pasar por un repartidor de Spark que recogía un pedido ficticio. El mismo jefe de policía advirtió sobre una variante mucho más personal de este problema: las estafas de clonación de voz mediante IA, que reproducen la voz de un familiar con suficiente realismo como para fingir una emergencia y pedir dinero, además de las ya conocidas estafas de phishing con IA que suplantan a marcas en las que la gente ya confía.

Conclusiones clave
  • En algunos comercios, el fraude mediante ataques BIN y las pruebas de tarjetas con IA han aumentado más de un 75 %, impulsados por una automatización que elimina el antiguo cuello de botella de los procesos manuales.
  • El escándalo de fraude de Polymarket muestra cómo se materializa realmente el riesgo de fraude asociado al crecimiento a toda costa cuando la dirección prioriza la rapidez por encima de los controles antifraude.
  • Eliminar una regla que exige retirar fondos a través de la misma fuente para agilizar los pagos socava directamente la prevención del blanqueo de capitales, incluso cuando se mantienen otros controles.
  • El fraude por apropiación de cuentas ahora puede aprovechar los nuevos procesos de creación de cuentas, no solo las credenciales de inicio de sesión existentes.
  • Los programas de dotación de personal para combatir el fraude en el ámbito del cumplimiento normativo necesitan verdaderos expertos en prevención del fraude, no solo investigadores con experiencia en medidas coercitivas posteriores a los hechos.
  • El fraude en el comercio agéntico es una preocupación real y creciente, pero la responsabilidad por los contracargos de los agentes de compra con IA sigue sin resolverse conforme a las normas actuales de las redes de tarjetas.
  • Los pedidos de entrega falsos generados por IA y las estafas mediante clonación de voz con IA ya se están utilizando en delitos reales y documentados, no en casos hipotéticos.
  • Un programa sólido de monitoreo de contracargos y un proveedor de soluciones antifraude adecuado pueden reducir las tasas de fraude hasta situarlas de nuevo en los niveles habituales del sector, pero solo cuando la dirección se toma el problema en serio.
Conclusión final

Si hay un hilo conductor que une todas las historias de este episodio, es que el fraude con tarjetas facilitado por la IA no necesita un nuevo manual para ser peligroso. Simplemente permite aplicar el de siempre con mayor rapidez, a menor coste y a gran escala. Ya sea una red de fraude que prueba miles de tarjetas robadas en cuestión de segundos, una empresa que prioriza el crecimiento frente a las medidas de protección o un estafador que clona una voz para fingir una emergencia familiar, los principios fundamentales en los que siempre hemos confiado —la segregación de funciones, las reglas que exigen retirar fondos a través de la misma fuente y una verdadera experiencia en cumplimiento normativo— importan ahora más que nunca.

Recursos y enlaces del episodio

Conecta con Karisse Hendrick | LinkedIn
Presentadora del pódcast Fraudology
Experta galardonada en fraude cibernético
Consultora en prevención del fraude en el comercio electrónico
Asesora de startups, conferenciante y
consultora para empresas de la lista Fortune 500

Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:07
Welcome back to the Fraudology podcast. I'm Karisse Hendrik and I am happy that you're here. Uh today we're going to go through some news articles of the week and they all have a common theme and that is that AI is here. I know I'm not really telling you anything new. Uh AI is creeping into all areas of our lives it seems, but not surprisingly bad actors are using it to commit more fraud. Uh you know, we always say that our job as fraud fighters isn't to eliminate all fraud. While that would be nice, we know that that just isn't realistic. Uh but it is to make it harder and slower for them to do, right? And more expensive. That's always our goal. Make it more difficult for them to attack our site or our bank rather than, you know, someone else's. And unfortunately, it's one of those situations where, you know, you don't have to be as fast as the bear. You just have to be as fast or faster than the last person running from the bear. And the fraudster's goal is always to make things cheaper and faster for themselves. And AI does that to an extreme. It really uh provides a lot of ease. And there's so many different platforms out there that make it easier for them as well. They're not only using the ones that we're familiar with. Uh they have some of their own AI models as well as using tools that are meant for enterprise and all kinds of things. So today the news articles will be centered around different AI attacks. Certainly won't be an exhaustive list. I've been talking with merchants a lot in the last few weeks, especially preparing for the Merchant Fraud Alliance, which once this episode comes out, we will only be about five days away from. Which I if anyone knows me and outside of just the podcast, you know that this has consumed me for several months. And I'm really excited for it to be here. I've kind of been joking that it's going to be like my second wedding because I'll know so many people there and want to talk to everyone. But I feel a little selfish about that. But the cool thing is is that everyone else gets to meet each other, which isn't always the case. So, um we have a lot of great senior leaders coming from uh very large organizations in e-commerce uh and marketplaces that I'm very humbled that they're making the trek to Chicago. Um some of them live there, but a lot of them don't. And the reason I brought up MFA is because I've been talking to so many uh merchants getting ready for it. Uh whether that's to prepare for uh speaking uh presentations, panels, people asking questions about you know the conference.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
02:48
As well as I just recently had my merchant collaboration call that we do monthly. Uh it used to be just tailored to retailers and we opened it up to all kinds of merchants. So we have some in travel, we have some in event ticketing, we have some merchants in marketplaces like digital goods marketplaces, not just uh those that ship physical goods. And there's been a lot of talk about AI attacks. There's also been a lot of talk about using AI to fight fraud, which we're doing a whole 4 hour boot camp uh the day before MFA for merchants on that topic. You know, using generative AI to do a lot of things within fraud operations. Sometimes it's identifying fraud, other times it's evaluating the performance of your analysts. Or creating a dashboard with alerts uh for various metrics. Some merchants are using it to tailor their uh chargeback response documentation and seeing some good results. There's just a lot of different ways that merchants are using AI and I know that banks are as well. But today's episode's going to be focused mostly on AI attacks. One statistic that I came across this week uh regarding AI fraud attacks is that card testing um with e-commerce merchants is now up over 75% according to at least one merchant of fraud provider. And that's because it you don't have to do it manually anymore. You know, card testing used the long time ago when I started in fraud, it was just, you know, one person or a group of people plugging in card numbers and testing them one at a time. Well, now they can just upload a spreadsheet of card numbers and, you know, card holder name, address, etc., and find a website to attack or target and just run them up. And we see that a lot. Um, and we're seeing that a lot more because it's faster and cheaper for them to do it. They're also identifying more patterns than even we can sometimes when we're looking at payment acceptance. And that's more on the payment side, but I spent some of my life on the payment side, so I'm familiar with that. You know, a lot of uh payments people spend a lot of time and money on trying to optimize payment authorization. Well, fraudsters are doing the same thing.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:13
Looking at bin numbers, looking at, you know, various different pieces and data of the transaction to determine how they can increase their authorizations on your website. So, they're not just looking to find cards that are valid to then sell or use for higher dollar transactions. They're also gaining all of this data rich information by running these transactions. So, um I think we're going to start to see some merchants being hit with fines for those card testing. Because, uh from the view of the network, it is up to the merchants to prevent card testing. So, I think everyone listening knows, you know, what card testing looks like, but it's generally low dollar transactions with just a high volume of transactions all at once. Usually, especially using AI, they can be seconds or milliseconds apart from each other. And what they're doing is they're using your site as a feedback loop. They're determining from what you say if the transaction goes through or if it's canceled at the time of payment. That tells them if the card is valid or not. Once they know a card is valid, they can get more money for it or if they sell it or they can then look more legitimate at the next merchant that they place an order with. Because they won't see a whole bunch of declines as well. That is one of the markers of card testing is, you know, just as many declines as there are authorizations. So, that was just one piece of information that I ran across on LinkedIn this week about just one method of AI attacks. I know in speaking with online merchants and I know banks are seeing the same thing. They're also seeing AI enabled account takeovers AI enabled fishing to their customers to get the credentials to then take over an account. It is being used in full force and uh that's what I want to talk about today. Uh with one exception. So there's one article that isn't so much about AI specifically. However, we rarely get a glimpse into when merchants are having fraud issues.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:26
Uh, and we recently saw an article, and I talked about it, I think in our last fraud news episode, actually last month. Where Hims and Hers, the company that provides GLP1 and other health supplements for men and women, obviously, um, online. How they're in the, um, Visa chargeback monitoring program and how rare that is. Well, now we're getting to see a glimpse into this other merchant that is getting hit with fraud really heavily. And it's an interesting type of fraud because it's it's more than card testing. They're actually cashing out on that same website. So, typically, uh, when an e-commerce fraud happens, they're making a purchase on one website and cashing out on another or cashing out in person. Maybe they order an iPad, right? It gets shipped to their address or to an address near them. They pick it up, then they go sell it. That's how they cash out. That's how they get the cash for that, you know, stolen card transaction. In other cases, they'll, you know, book a hotel or entertainment tickets for a show or a sporting event and then they'll do that on one website and then on the other website they'll, you know, sell it in the secondhand market. But in this case, that the buying and the cashing out is happening on the same site. And the CEO doesn't seem to care. And I know a lot of fraud fighters might have a little PTSD when I read this article because we've all faced this. It, to some degree. I don't think we faced it to this degree. Not all of us have faced it to this degree, but it's a fairly new merchant and that's Poly Market. Poly Market has had a lot of scrutiny itself because it's essentially gambling on real world events. You know, whether a TV host on live TV is going to say a certain word or whether a politician is going to make a statement about something specific. I know there's a lot of investigations being had into, you know, politicians and basically insider trading. But they're not calling it insider trading because it's not.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
09:48
While it probably should be, it's not regulated um by the SEC as much as it should be. So, I don't know. I' I've listened to a couple podcasts about Poly Market, but that's about the extent of it. I've never used it, but you know, it's a betting website on real world events is just the shortest way I can explain it. The title of this in the Wall Street Journal is that Poly Market's rush to grow left a door wide open for fraudsters. CEO Shayne Coplan brushed off concerns about schemes involving stolen debit cards. Now, the prediction market is bolstering executive ranks as it eyes IPO. So, they want to go public, but yet they have a lot of fraud and that could be an issue. So, this article was published on September 19th. And it says, "In February, a company processing debit card transactions for Poly Market's US betting platform delivered some alarming news. Fraudsters were flooding the app." That's not too uncommon for us to hear, but you know, it is for a new company, especially if they didn't already know that they could have fraud. They probably weren't expecting it or ready for it. Because a lot of startups aren't. Users were linking stolen debit cards to Poly Market US accounts, then trying to use them to make wagers and withdraw the money that they won from those wagers into clean cards or accounts that they controlled. Thieves tried to make off with at least $10 million. At one point, the processor rejected as fraudulent more than 80% of the deposits it was handling. A rate that far exceeded industry standards of roughly 1%. Poly Market employees quickly raised their concerns with chief executive Shayne Coplan, according to people familiar with the events. The compliance team, those people recalled, was floored by Coplan's response. Just keep growing and pay a fine if regulators ever find out. Current and former employees said Coplan's reaction, which hasn't previously been reported, was characteristic of his plan for Poly Market growth at all costs. Poly Market is doing everything in its power to woo new users and investors. And in the process, said current and former employees and investors interviewed by the Wall Street Journal. The high-flying company has struggled with compliance failures, legal challenges, and software blenders. Rates of fraud remained elevated for months after the February Attack. People familiar with the matter said, though they didn't again reach 80%. In the wake of the incident, executives left and an internal investigation began. No one in compliance wants to have their name on that. That's a big reason why they probably left. Uh former regulators from the CFTC, Justice Department and Internal Revenue Service, said the level of attempted fraud and Poly Market's response was atypical for the commodities and gambling industries. Unlike traditional commodities exchanges, Poly Market accepts funds directly from retail traders, making it more vulnerable to fraud attacks. So they accept funds directly from consumers, basically. In a regulated space, this kind of thing does not happen, said former CFTC enforcement lawyer Joe Konizeski.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
13:12
Something like that. You have adults who handle customer funds and make sure they're sourced appropriately and handled appropriately. A Poly Market spokesperson said that the company is committed to maintaining accurate, fair, and transparent markets and working with regulators and law enforcement. Our market integrity framework includes processes to detect, review, and respond to suspicious activity, the spokesperson said. Poly Market's legal challenges are mounting on several fronts. The Commodity Futures Trading Commission uh so the CFTC is investigating it. The employees have been told to retain records related to the fraud attack and other topics according to people familiar with the matter. And the New York City Council is probing the advertising processes practices of Poly Market and other prediction markets. And Poly Market has been accused in lawsuits of deceptive business practices by almost two dozen traders. At the same time, more than a dozen state lawsuits are focusing on whether Poly Market and its prediction market competitors such as Kelshi and Coinbase are unlicensed gambling platforms. The outcome of those cases could reshape the industry. As legal risks pile up, Coplan is in the process of raising a billion dollars in a fundraising round that would value the company at around $21 billion. Donald Trump Jr.'s investment fund 1789 Capital is investing roughly 300 million in the round in addition to the roughly 200 million it has previously invested. So particular fund will have invested half a billion dollars into Poly Market. Poly Market which has a data partnership with Dow Jones the publisher of the Wall Street Journal has been working to reposition itself to investors and the general public as a more mature company focused on responsible growth. Since May, it has added experience risk management staffers including a former FBI agent. The company has improved its compliance protocols and improved product testing according to a person familiar with operations. I would say that while it's great to, this is me talking not the article. While it's great to hire, you know, former law enforcement for fraud after the fact. For investigations to, you know, identify who's behind the fraud and then work with prosecutors to prosecute fraud. My experience is that the majority of people with law enforcement experience don't have any experience in the prevention side of fraud. They haven't worked with fraud tools to prevent fraud. They don't know the strategy there, or how the systems work, or you know what how to build a successful risk stack. That's just not their area of expertise. They are phenomenal at investigations work after the fact after the fraud has happened. But if that's the only person they've hired for risk management, that would concern me a little bit. Uh, in late June, Coplan visited the Hampton's home of 1789 capital co-founder Omeed Malik to strategize about how to professionalize Poly Market's operations before a potential initial public offering or IPO in the next year. According to people familiar with the meeting, Malik advised Coplan to hire more experienced executives. Poly Market recently hired its first chief financial officer, Warren Jeff Jensen, who was Amazon's CFO in the early 2000s. Following a journal investigation into a deceptive social media campaign, Poly Market restructured its marketing team, including hiring the founder of electric scooter company Bird as chief of growth. Other marketing employees involved in the social media campaign have left the company or had their roles shrink. Poly Market is rapidly growing and getting better every day. A spokesman for the company says, "We are proud of our key leadership hires and continuous infrastructure upgrades and have quickly scaled and remains focused on growing responsibly at the frontier of finance, tech, and culture. But they do say that like the CEO has a reputation for being unfiltered and intense. He's bullied employees. He's uh apparently he likes to use adderall and that's very widely known. He's pushed people to the brink.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
17:39
That type of thing. And he said some bad words on Twitter that I don't want to repeat. They do say here's the part that I was referencing earlier. As one part of its protection against money laundering attacks, Poly Market US employed a rule commonly used by financial exchanges. Funds deposited from one payment source were required to be withdrawn to that same payment source. Without such a rule, a thief could deposit money using stolen debit cards, trade with it, and then withdraw winnings to a clean card. That's exactly what they were doing in February. Federal regulations don't require prediction markets to follow that rule. Other brokerage and betting apps, including DraftKings and FanDuel, do so. Poly Market's chief competitor Kalshi doesn't, though the company inspects funds withdrawn to different payment mechanisms and freezes suspicious payments. A person familiar with that company's protocols said. I can actually say that I'm familiar with who Kalshi uses for some of their fraud prevention and I think it's it's one of the top leaders in the space. So that might be why they feel more comfortable doing that but they I'm sure they scrutinize those more. I'm not familiar if Poly Market uses a third party fraud tool or if they're just using internal engineering rules or what they're doing. By January of this year, Poly Market's US app was handling only a fraction of the volume of its mammoth international exchange. So, it has an international exchange, but they um have taken that part off and moved it into the US. Copeland wanted any potential friction for users gone even though the app was still in beta testing and had launched to only a limited number of users. Near the top of the list, make sure users got their money quickly. By February, a Discord chat for Poly Market users had filled with complaints about how long it took to withdraw funds. Employees reassured users that their money was in transit, but that compliance checks could hold it up for days or weeks. Engineering glitches on the US app added to the pain. So, in addition to having a lot of fraud in February, they also had issues with people withdrawing getting their their winnings back or their the money that they still had back. Uh, in February, the swindlers attacked Poly Market, linking stolen debit cards to thousands of new accounts. The payment processor, Checkout.com, told Poly Market. So, uh, now we know who their processor is, and they alerted Poly Market of that. Most of the attempted deposits failed, said one person familiar with the matter who attributed the majority of the attack to seven users. One of whom attempted about 4,000 deposits. That tells me that their fraud stack is not very mature if they're allowing that many deposits to be made by one person. That could have changed since February, but that's what this tells me now, or at least at the time. Checkout.com, which continues to work with Poly Market, declined to comment on the incident or its relationship with Poly Market. Yeah, they probably sent an NDA. The attack overwhelmed the compliance staff backing up withdrawals further. Which is why it took so long for money to get back. Uh to get money back to customers faster, company leadership decided to scrap the rule requiring same source withdrawals. Even though some employees warned that it could open the door to money laundering. According to people familiar with the discussions, executives maintained that the other protocols in place were sufficient. Failure to adequately police money laundering could violate federal laws about money laundering, illicit transmission, and possibly bank fraud. Uh former federal prosecutors said the CFTC and the Justice Department have prosecuted firms including crypto exchanges like BitMEX and Binance for violating such laws. And some fines have extended into the hundreds and millions of dollars. Poly Market is subject to less stringent anti-money laundering regulations however. Their US chief compliance officer resigned in April after sending a lengthy report with an overview of some of the fraud issues to company executives. According to people familiar with the report, both Clifford and Poly Market declined to comment about his departure. Around that time, Poly Market closed a billion dollar investment round that valued the company at nearly 15 billion. And now they want another billion to value their company at 21 billion. Uh soon after Poly Market fired the US division CEO Justin Hertzberg and its head of US regulation and ant money laundering left. Hertzberg didn't respond to requests for comment and an investigation by the law firm Sullivan and Cromwell concluded the company had complied with regulations according to people familiar with the findings. Well, there's barely any regulations for them to comply with. So that doesn't necessarily mean that they're doing everything right. By May, Poly Market had brought fraud rates back into the industry norm. A person familiar with the matter said in part by limiting the number of debit cards that users could link to their accounts. The company also retained a new anti-fraud contractor, Riskified.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
22:59
Hm, that's interesting. That's a lot of pressure on Riskified for very fast high dollar transactions. Poly Market also has been trying to fix other problems stemming from the minimal testing it had done before rolling out new features. There's been platform issues and other things. Several people have been uh complaining that they can't get their money back. Poly Market has reimbursed some customers who suffered losses while others have worked with their banks to reverse unauthorized charges via chargebacks. Uh said a person familiar with the matter. Recently, it has improved its code review practices and hired more engineers. Copelan has pushed employees to create provocative new markets. For instance, how many times does Kanye West say a pretty bad, you know, word on his Twitter this week? Or, you know, other things. So, those are like some more provocative things you can bet on. Uh, letting users create their own markets could introduce new opportunities for market manipulation, said Rajiv Seth, a Barnard College economics professor who has studied prediction markets. Compliments pushed to make Poly Market a household name led to expensive deals with A-list celebrities. Oh, I guess in late July nearly 500 Poly Market users were victims of another fraud attack that appeared to exploit an engineering flaw. Uh, if a malicious actor attempted to create a new account using an existing trader's personal information, such as a stolen social security number, the hacker would immediately gain access to the trader's existing Poly Market account. Oh my gosh. And any of their linked bank accounts and debit cards without needing to know a password or a username. That deserves a face palm. Um, according to a person familiar with the matter who said the amount of money stolen was small. Um, that's crazy, but that yeah, it doesn't surprise me too much. Then they talked about the World Cup and how it's that. Anyway, it's a very long article. I apologize for reading as much of it as I did, but I think it's fascinating. It's always fascinating to me when the name of a company's payment processor and or risk provider is public.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
25:20
Made public in an investigative article such as this as well as just the fact that they have fraud and what the fraud attack was, right? What, which typography is impacting them the most. That's very uncommon for, you know, a few decades for the last two and a half decades that I've been in this industry. It's been very rare. So, I applaud the Wall Street Journal for doing this work because I think it's important. It's another way to hold companies accountable and especially new companies in tech that either don't understand the credit card and debit card liability laws or they just don't care and want to focus only on growth. This is what can happen. It's I hope that the new people in risk management that they've hired are getting a seat at the table. And getting to, you know, call out engineering mistakes such as the one I just mentioned or, you know, other things like that. I do think that having a rule that the card you use to fund the bet needs to be the same method of payment that gets the earnings of the bet back on it. I think that's a really good one for fraud. But Riskifi's going to have their work cut out for them because this is a pretty fraud business model. It just is. It's super risky. And what if somebody regrets their bet, right? What if someone bets $500 that, you know, a sports star is going to wear purple shoes at the next game. And they don't wear purple shoes, so they lost the $500. Who's to say they can't issue a chargeback on that? Uh for not as described or whatever else they want to do. Uh I think that they probably have significant chargeback issues for a lot of things, not just fraud, like I said, service and uh buyer's remorse as well. And they might have to learn a few more hard lessons if they're, you know, founder or lead executive isn't willing to put some guard rails in. And we know that guardrails don't have to apply to everyone. They can just reply to the riskiest transactions. That's, you know, the beauty of fighting fraud in 2026. It doesn't have to be with a blunt instrument anymore. It can be with surgical precision. So, I hope that they figure that out. I didn't mean to spend so much time on Poly Market, but I did really find it interesting, and I think those of you on the merchant side especially will, too. So, speaking about AI attacks, there's a couple of articles I wanted to share that are specific to AI attacking e-commerce or banks and just how it's being used for that. This next article is by AOL. Well, no, actually it was by Reuters. I'm sorry. I found it on AOL, but it was originally by Reuters. The title is banks warn that AI shopping bots or agent commerce will raise scam, fraud, and data privacy risks. I would agree with that on the surface, but let's read the article to see how you feel. So, uh, they're basing this article in Paris. Using AI agents for online shopping could increase the risk of scams, fraud, and data privacy breaches. Banks including Nat West and Bank of America said on Tuesday. As they set out principles for developing the technology. Technology companies including OpenAI, Anthropic, Google, and Meta are increasingly promoting AI chatbots as shopping tools. Envisioning a future in which shoppers use agents to select products and make purchases on their behalf. Retailers, meanwhile, are racing to influence chat bots recommendations.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
29:11
So, they want the chat bots to recommend the products on their website, not their competitor's website. British retailer John Lewis said in September that searches originating from AI agents had risen to 2.5% from just .3% a year earlier. Just three basis points. With the trend accelerating, I guess it's 30 basis points. Uh still it's not a lot. So just in one year for it to go up 8x more than 8x, that's pretty that's pretty significant. The group of banks which also includes ING New Zealand's ASB bank US lender Capital 1, Commonwealth Bank of Australia said in a report that customers were enthusiastic about the potential of Agentic commerce and keen to enable it. However, they warned that the technology was advancing faster than industry standards and consumer protections. Which is incredibly true, especially in the US since the current government has decided not to put restrictions on it at all. Uh, consumers are unclear if AI will act in their interests, the report said, they are concerned the AI agents may buy the wrong thing or spend too much or even worse, lose their money to scams and fraud. They are not sure whether they will be protected or who they will need to go to if things go wrong. I think that's especially true if someone instructs their agent to find the cheapest price and that agent doesn't take into account the not only the like the legitimacy of that website, right? Is how long has it been there? When was it, you know, first established? Are the prices just way too low and not, you know, even remotely close to reality. Or are they just going to go for the cheapest item? And often times, you know, those websites that have cheap items on it will never ship you the goods. They'll charge your card, but then they'll never ship you the items and next thing you know, you can't find the website. Uh, so I agree with that. I think this is going to be a big problem for agentic e-commerce. The report highlighted risks including AI agents requesting customers card detailers details and entering them directly into websites or steering users toward payment methods that offer weaker protections. The bank's plan to discuss a series of proposals with policymakers, including requiring disclosures when an AI agent is involved in a transaction, greater transparency over how AI agents make decisions, and safeguards to protect customer data. Consumers and merchants should also be free to choose which AI powered e-commerce services they use, while different systems should be interoperable, the report says. So I think this is great that banks are calling attention to it. However, the people that are really in charge of this, you know, being the case and the liability as well as the data privacy and the safety of agent commerce is actually the platforms and and it comes uh but also the networks have been involved because they want to be involved in the protocol piece. Uh when I was at SardineCon last month, it was about five or six weeks ago now. Uh there was someone there from Visa. And he was saying that there have been a lot of conversations with a lot of tech companies that are providing generative AI and agentic e-commerce in trying to set up these protocols. Because merchants especially are very nervous that you know if someone sets up an AI agent but to buy something and it's not the thing that they wanted or they change their mind they can issue a chargeback. And currently there are no provision provisions for merchants to be able to win chargebacks when an agent is involved. So, I will continue to say that until I am a dark color blue in the face. I really think that that needs to be highly considered uh the liability as well as how merchants can defend themselves and regain some of the funds if they do receive those types of chargebacks. Because if the AI platform makes a mistake, I think the AI platform should be responsible for the chargeback. However, with current Visa and Mastercard rules and regs verbiage, that's not the case and it won't be. So, that's why I brought this article up. Next, it's a article in uh Georgia. And it says, "A whole new horizon for us in quotation marks. Police make first arrest in AIdriven fraud case in Chatham County.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
33:58
So, the chief of police is warning the AI is being used to create fake orders, QR codes, and even cloned voices for scams. Unfortunately, we know this all too well. Uh, but I have a couple things to add to it. So, Chatham County police have made their first arrest involving artificial intelligence fraud. According to the department. Police said 20-year-old Dion Love posed as a delivery driver at the Walmart uh on a road I can't say uh using a fake AI generated Spark order in an attempt to leave the store with a Nintendo Switch and other electronics. So, I believe Spark is Walmart's delivery system and uh either for pickup in store or for delivery. It sounds like he picked it up in the store possibly for delivery. And he was using an AI generated order to try to attempt the warehouse or the store. So, um, he went in said, "Hey, I work for Spark. I'm a, you know, driver for, like on behalf of Walmart, kind of like an Uber driver. And I have this order for a Nintendo Switch and other electronics that I need to fulfill. In order to deliver to this person who ordered via your website. And thankfully, Walmart was like, "That doesn't look right, and it's not in our system." But he tried and it was you know at least somewhat successful for you know them to identify it in that way. Then the police chief went on to say, and because he persisted an off duty police officer there detained him and we got called there and we ended up making an arrest. It's a whole new horizon for us so to speak and we're just now learning of these scams and how we go about addressing them, Hadley said. The chief says that retail fraud is just the start. Hadley said retail fraud is the only is only part of the problem. He said, well AI can help businesses with automation images and videos. Criminals are using the same tools to commit crimes including replicating voices. Something we've talked about here. Uh AI has the ability to create fake requisitions, fake orders, fake QR codes in order for people to proliferate criminal activities. Hadley described how AI generated voice technology could be used to defraud victims. I think we already know this, but um he said, "For example, I get your voice, I find out who your mother is, and then I call and utilize AI technology to replicate your voice and say, I need money. I'm in jail. You know, create a panic. Your mother's going to say, Oh, gez, I need to help my son. And sends money and something like that to defraud them out of money. Uh, thinking that they're helping their own son out. Police are working with national think tanks. He says, Hadley said his agency is meeting with national police think tanks to develop new tactics for investigating AI-driven crimes. Hadley urged the public to verify information before trusting it. And that's where I want to stop today. I think that there are plenty more AI attacks. There was another one using ad software posing as HBO. And get basically fishing for credit card details. Um, and they were using AI to boost their ads as well as uh collect all of that information. But you guys get the hint, right? Like AI is going to be here to stay. It's going to just keep refining over and over again. I have heard a few stories of, you know, AI adapting in real time to various fraud rules or, you know, uh, stipulations within the risk stack. And something to watch out for is that they're figuring out how to manipulate all of the things that you've put in place to try to identify them. So, we need to be aware of that they're using AI and they're doing it more often. And that it's going to look believable in a lot of cases um in order to catch them. So, that's what I wanted to focus on today. I'm really excited about MFA, guys. I'm I'm bummed if you can't go this year. I hope that there's going to be a next year. We are waiting to make that decision until we know how successful the first year is. Um, but I just really am humbled and grateful for all the support we've gotten so far. Even some people that can't come have just written me the kindest notes about how they know that this has been on my heart for a long time. And that they're really excited for it. So, I appreciate that. I will see some of you at MFA. I, you know, sometimes people listen to my podcast when they're on the plane. So, maybe you're listening to this on the way to MFA. But I'm really excited about it. I appreciate everyone who's been so supportive. And I will be back next week with an interview and then the week after uh with kind of a a debrief or a download of some of the hottest topics discussed at MFA. So, I'm looking forward to that episode. I already know what some of the panels are going to be and I mean I'm telling you some of these prep calls for speakers I am like there's going to be so much good information. And and at a senior level too it's not all entry level. So I am very excited as you can tell. Uh but I am going to be done for this week. I appreciate all of your support. I've gotten a couple of really nice notes in the last week uh from listeners. I really appreciate it. Um that's what keeps me going. Uh that's what uh keeps my guests wanting to come back as well. So really appreciate that and I will talk to you more next week.