SardineCon SF/2026

Learn More
Fraudology

Supervisión de Comerciantes Fraudulentos de Mastercard y el Problema de las Alucinaciones de la IA

Gráfico para el episodio n.º 405 del pódcast "Fraud/ol/ogy", con la participación de la invitada Dra. Nicola Harding y Karisse Hendrick, mostradas en dos fotos tipo retrato.

Bienvenido de nuevo a Fraudology.

Les hablo desde unas vacaciones de trabajo frente a la playa en Florida para este episodio, justo después de la Cumbre Global de Clientes de Accertify. Y sí, el lugar era precioso.

En este episodio me acompaña la Dra. Nicola Harding para hablar de dos temas que al principio pueden parecer independientes: las alucinaciones de la IA en el fraude y el nuevo programa de supervisión de comercios de estafas de Mastercard.

Cuando miras más de cerca, ves que están conectados por el mismo problema de fondo.

A los equipos de fraude se les pide que tomen decisiones más rápidas y complejas en entornos donde las señales aparecen antes, la responsabilidad está cambiando y las herramientas que usamos para interpretar el riesgo no siempre son tan confiables como parecen.

Eso importa.

Por un lado, tenemos modelos de lenguaje (LLM) que se utilizan en la gestión de riesgos, la investigación de fraudes y la toma de decisiones operativas. Y, como comentamos en este episodio, eso se vuelve rápidamente arriesgado cuando la IA empieza a producir respuestas seguras a partir de información incompleta o de código abierto. Especialmente en el ámbito del fraude, donde el conocimiento más útil suele ser propietario por una buena razón.

Por otro lado, el programa de supervisión de comercios fraudulentos de Mastercard crea un marco mucho más agresivo para identificar e investigar a los comercios que puedan estar vinculados a estafas. Los nuevos umbrales, la supervisión de reembolsos y contracargos, y la ventana de 72 horas para investigar a los comercios ejercen una presión real sobre los comercios, los adquirentes y los equipos de pagos.

Así que este episodio trata realmente sobre la rendición de cuentas.

¿Quién toma la decisión?

¿Quién valida la señal?

¿Quién entiende el contexto?

¿Y qué sucede cuando un modelo o un programa de comercio se trata como si pudiera funcionar sin la experiencia humana adecuada a su alrededor?

Lo que escucharás en este episodio:

  • Qué significa el programa de supervisión de comercios fraudulentos de Mastercard para los comercios y los adquirentes
  • Por qué el panel de control de comerciantes fraudulentos de Mastercard es importante para los equipos de fraude de comercio electrónico
  • Cómo la supervisión de reembolsos y contracargos puede afectar las evaluaciones de riesgo de nuevos comercios
  • Por qué la ventana de 72 horas para la investigación de comerciantes genera urgencia operativa
  • Cómo las alucinaciones de la IA en el fraude pueden distorsionar el análisis de riesgos y la toma de decisiones
  • Por qué las alucinaciones de los LLM son especialmente riesgosas cuando el conocimiento sobre fraude es propietario
  • Por qué los equipos de fraude y ciberseguridad deben eliminar los silos a medida que las señales se adelantan en la ruta de ataque

Deberías escuchar este episodio si:

  • Trabajas en operaciones de fraude, riesgo de comercios, pagos o fraude en comercio electrónico
  • Son responsables de los umbrales de contracargos de Mastercard o de los flujos de trabajo de investigación de comercios fraudulentos
  • Necesitan entender cómo el programa de supervisión de comercios fraudulentos de Mastercard puede afectar a su equipo
  • Están evaluando modelos de lenguaje grandes (LLM) en la gestión del riesgo de fraude o en la investigación de fraudes generados por IA
  • Les importa la experiencia en el dominio, la alineación en fraude y ciberseguridad, y el nivel de preparación operativa

Si te gustó este episodio, asegúrate de suscribirte y dejar una reseña del pódcast en iTunes, Spotify, YouTube o donde sea que escuches pódcasts. Realmente ayuda a correr la voz.

Notas del episodio y puntos clave

Este episodio se sitúa en la intersección de dos problemas de fraude muy diferentes, pero ambos muy importantes.

El primero es el riesgo de alucinaciones de la IA. No del tipo gracioso en el que un chatbot inventa algo inofensivo y todos siguen adelante. Me refiero al tipo en el que una herramienta de IA produce con seguridad un análisis de fraude, una cita, una recomendación o una interpretación de riesgo que en realidad no está basada en la realidad.

Eso es un problema.

Los equipos de fraude no operan en un mundo donde toda la información útil es pública. Gran parte de la mejor inteligencia sobre fraude reside en sistemas internos, reglas propietarias, investigaciones, patrones de contracargos, historiales de comercios, datos de ciberseguridad y experiencia operativa. Por eso, cuando un LLM intenta razonar solo a partir de datos de código abierto, puede pasar por alto el contexto exacto que más importa.

El segundo problema es el programa de supervisión de comercios de estafas de Mastercard, que ejerce más presión sobre los comercios y los adquirentes para identificar, investigar y actuar rápidamente ante actividades de comercios relacionadas con estafas. Esto no es solo una actualización de políticas. Es un asunto de preparación operativa.

Y es ahí donde se conectan los dos temas.

Se les está pidiendo a los equipos de fraude que actúen con mayor rapidez mientras las señales de riesgo se vuelven más complejas. Esto significa que las empresas que destaquen en este ámbito no serán aquellas que confíen ciegamente en cada panel, en cada resultado de modelo o en cada métrica superficial.

Serán quienes comprendan las señales, validen los datos y aporten la experiencia de dominio adecuada a la decisión.

Por qué la supervisión de comerciantes fraudulentos de Mastercard cambia la presión sobre los adquirentes

El programa de supervisión de comercios fraudulentos de Mastercard está diseñado para identificar a los comercios que puedan estar vinculados con estafas, actividades engañosas o prácticas de venta perjudiciales. Esto significa que el enfoque no se limita al fraude tradicional en transacciones sin presencia de tarjeta. Se centra en el comportamiento del comercio, los patrones de reembolsos, los contracargos, las quejas de los emisores, el rendimiento de las autorizaciones y en si un comercio parece estar generando riesgo para la red.

Para los adquirentes, eso cambia la postura.

No basta con esperar hasta que el daño sea evidente. Los adquirentes deben ser capaces de investigar con rapidez, comprender las señales de riesgo de los comercios y decidir si un comercio es legítimo o debe ser dado de baja.

Ese es un tipo de presión muy diferente.

  • La supervisión de comercios fraudulentos de Mastercard aumenta la necesidad de una revisión de riesgo de comercios más rápida
  • Los adquirentes pueden necesitar flujos de trabajo más sólidos para la investigación de comercios involucrados en estafas
  • Los equipos de riesgo de comercios deben supervisar conjuntamente los patrones de reembolsos, contracargos y autorizaciones
  • El plazo de 72 horas para la investigación del comercio hace que la preparación operativa sea fundamental

Por qué el monitoreo de reembolsos y contracargos es importante para los nuevos comercios

Una de las partes más importantes de este programa es la forma en que analiza conjuntamente los reembolsos y los contracargos en las cuentas de comerciantes más recientes.

Los comercios fraudulentos no siempre se detectan mediante una única señal clara. A veces, el patrón es una combinación de quejas, reembolsos, contracargos, bajo rendimiento en las autorizaciones y un comportamiento que parece lo suficientemente legítimo como para seguir operando.

A primera vista, un reembolso puede parecer atención al cliente.

Pero cuando profundizas, los reembolsos también pueden ser una señal de que está ocurriendo algo más. Especialmente cuando van acompañados de quejas, actividad de contracargos o cambios repentinos en las tasas de aprobación.

Para los equipos de fraude, la conclusión es sencilla: no analicen estas señales de forma aislada.

  • La supervisión de reembolsos y contracargos puede revelar patrones de estafa antes
  • Es posible que las nuevas cuentas de comerciantes necesiten una revisión más exhaustiva durante los primeros seis meses
  • Los umbrales de fraude de Mastercard crean un incentivo más fuerte para supervisar el riesgo de forma continua
  • Los equipos de prevención de fraude en comercio electrónico deben vincular el comportamiento de los comercios con las señales de quejas de los clientes

Por qué las alucinaciones de la IA son peligrosas en la gestión del riesgo de fraude

Las alucinaciones de la IA en el fraude son peligrosas porque pueden generar confianza donde debería haber cautela.

Un modelo puede resumir. Puede redactar. Puede organizar información. Incluso puede ayudar a los equipos a avanzar más rápido.

Pero si los datos de origen están incompletos, son incorrectos o carecen del contexto propietario en el que confían los equipos de fraude, el resultado puede desmoronarse muy rápidamente.

Aquí es donde la experiencia en el dominio marca la diferencia. Un profesional del fraude puede mirar una declaración pulida generada por IA y preguntar: «Espera, ¿eso realmente tiene sentido?». Un modelo no siempre sabe cuándo está fuera de su ámbito.

Y en la gestión del riesgo de fraude, esa distinción es importante.

  • Las alucinaciones de los LLM pueden distorsionar el análisis de fraude y las recomendaciones operativas
  • Las herramientas de IA de código abierto pueden pasar por alto patrones de fraude propietarios
  • La experiencia en el dominio ayuda a los equipos a validar si un resultado de IA es utilizable
  • La IA debe apoyar las operaciones contra el fraude, no reemplazar el juicio humano

Por qué los silos entre fraude y ciberseguridad se están convirtiendo en una mayor responsabilidad

Uno de los temas más importantes que surgieron en la Cumbre Global de Clientes de Accertify fue que las señales de fraude se están desplazando hacia la parte alta del embudo.

Esto significa que las primeras señales de riesgo pueden dejar de aparecer en la propia transacción. Pueden manifestarse antes a través de la actividad de la cuenta, el comportamiento del dispositivo, el phishing, el malware, el uso indebido de credenciales u otras señales de ciberseguridad.

Entonces, si los equipos de fraude y ciberseguridad siguen operando por separado, eso crea una brecha.

Y a los delincuentes suelen gustarles esos vacíos.

Los equipos de fraude necesitan visibilidad de las señales que se producen antes del pago. Los equipos de ciberseguridad deben entender cómo esas señales acaban convirtiéndose en fraude de comercio electrónico, fraude de pagos, riesgo para el comercio o contracargos.

Cuanto más conectados estén esos equipos, antes podrán detectar el patrón.

  • Los silos entre fraude y ciberseguridad dificultan la detección temprana de riesgos
  • Las señales en la parte alta del embudo pueden ayudar a los equipos a comprender el fraude antes de la transacción
  • La prevención del fraude en pagos funciona mejor cuando los equipos comparten contexto
  • La visibilidad interfuncional ayuda a reducir los puntos ciegos en las operaciones de fraude

Por qué la experiencia en el dominio sigue siendo fundamental para la decisión

Este episodio vuelve una y otra vez a una idea: las herramientas son útiles, pero la experiencia sigue siendo lo que convierte la información en criterio.

Eso se aplica a las alucinaciones de la IA. Se aplica a la supervisión de comercios fraudulentos de Mastercard. Se aplica al riesgo de los comercios. Se aplica a la alineación entre fraude y ciberseguridad.

Un panel puede señalar que se ha superado un umbral.

Un modelo puede resumir un patrón.

Un informe puede identificar un riesgo.

Pero alguien todavía tiene que entender lo que significa.

Ahí es donde los profesionales experimentados en fraude son más importantes. Saben cuándo un patrón de un comercio se ve incorrecto. Saben cuándo un umbral de política necesita apoyo operativo. Saben cuándo una respuesta de IA suena demasiado perfecta. Saben cuándo diferentes señales apuntan al mismo problema subyacente.

El costo de equivocarse en esto no es solo un informe deficiente o un flujo de trabajo desordenado. Puede traducirse en pérdidas, responsabilidades legales, cancelación de comercios, redes de estafas que pasan desapercibidas o decisiones tomadas a partir de información que nunca fue debidamente validada.

Conclusión final

El programa de supervisión de comercios de estafas de Mastercard es otro recordatorio de que la prevención del fraude se está volviendo más conectada, más sensible al tiempo y más exigente a nivel operativo.

Al mismo tiempo, las alucinaciones de la IA nos recuerdan que la información más rápida no siempre es mejor información.

Así que la verdadera conclusión no es solo “vigila los umbrales” o “ten cuidado con la IA”.

Es esto: los equipos de fraude necesitan un contexto más sólido.

Contexto en todo el riesgo de los comercios.

Contexto en materia de fraude y ciberseguridad.

Contexto en reembolsos, contracargos, quejas y comportamiento de autorización.

Contexto entre los resultados de la IA y el conocimiento propietario que los modelos no poseen de forma automática.

Porque en el fraude, las herramientas pueden ayudarte a ver más.

Conecta con Karisse Hendrick | LinkedIn

  • Presentadora del pódcast Fraudology
  • Experta galardonada en ciberfraude
  • Consultor en prevención de fraudes en comercio electrónico
  • Asesor de startups, orador principal y
  • Consultor para comerciantes de Fortune 500

Guests

Dra. Nicola Harding
Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:02
Welcome to Fraudology Podcast, where we dive into the science and study of online fraud from the perspective of an ecommerce fraud fighter. I'm Karisse Hendrick. Welcome to this week's episode of the Fraudology Podcast. Well, if my background or microphone sound even just a little bit different, that's because I am not in my home office this week. When I ran into a merchant at a recent event I was at, which I will talk about in a minute, she joked with me that she never knows where in the world I am because either on the podcast or she's part of one of my biweekly merchant groups, often I have new backgrounds. I've been traveling a lot this year since February.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:45
I spent two weeks in Maui with my husband, which was just absolutely magical, and then I went to the MAG Conference in San Diego. A few weeks later, I went to MRC in Vegas. A few weeks after that, I went to Fraud Fight Club in North Carolina. And then after North Carolina, I went straight to San Francisco to see family friends and spend some time with them, and then back home. And then a few weeks after that, I flew into Tampa, but stayed in Saint Petersburg for the Accertify Customer Summit. So that's where I've been this week. I decided to make it a work vacation and, you know, was at the conference for three days, and then myself and a very good fraud friend who was also at the conference, we decided to stay a few extra days, rented an Airbnb on the beach with a private pool. I really don't want to leave. And it's just, it's been perfect weather. I think that's pretty, you know, pretty common for Florida, but it's a long flight back to Washington State. So I didn't want to just come for three days and then go back.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
01:51
Plus, you know, if you can do it, it's fun. And, you know, she and I have traveled a fair amount together over the years, so we split the house well and just do our own thing sometimes and then hang out and talk fraud other times. I'm sure if anyone staying at the condos next to us, there's like a condo building on either side of this house, they're probably really sick of hearing us talking about fraud, but that's okay. Anyway, today I wanted to talk about a few things. So one was I was going to give a little bit of a recap from the Accertify Customer Summit. I was very grateful that they allowed me to come and asked me to come, especially because that is a rarity. Usually it's strictly for customers. So there's a few things that I got out of it that I wanted to share, and there were also a few things I got out of it that I can't share yet, but will once I'm told I can.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
02:45
I'm also going to share with you a LinkedIn post about fraud and ChatGPT that kind of proves the point that both Holly and I were making on our previous episode just about data sources and things like that, and AI hallucinations and all of that, that I think could be really helpful if you are being told that you have to use an LLM for part of your job. I know there's a couple companies, they've been told they must be using an LLM, you know, a ChatGPT, a Claude, that's whatever it is for 25% of their job by X date. You'll want to probably share this story with your bosses if that's the case. So I will share that. And then we'll talk. The main topic I wanted to talk about is Mastercard's new scam program. If you're on LinkedIn at all, and if you're on fraud LinkedIn at all, you've probably seen a couple of posts about it over the last few weeks. It's kind of Mastercard's version of VAMP. It's very different, but it has similar goals. So I'll go through that program, and it has some pretty significant repercussions if you are included in that and if your metric gets you above a threshold.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
03:56
So I think it's important to be aware of if you are an ecommerce merchant, and even if you aren't, I think it's good to be aware of what the card brands are doing and what they're requiring of ecommerce merchants. So this is today's agenda. Diving into the Accertify Global Customer Summit, it was a great opportunity to network with about 150 people that work for merchant companies, merchant fraud fighters. If you're not familiar with companies that work with Accertify, I don't know which ones are public and which ones aren't. So I'm not going to name any, but I'm going to say they are primarily the largest brands in retail, in travel, in airlines, in some restaurants, a lot of different areas. But I would say 80% of their clients are household names. And Accertify is probably the longest running fraud tool out there.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
04:52
I remember when their very first sales rep came and pitched it to me when I worked for a startup in Seattle in probably 2009, right around there in 2008, 2009, something like that. And at the time I was impressed that they were building something like that, but it was very similar to what I had built with our dev team at the time for what we needed for our business model. So we didn't go with it, but it was impressive and it has since grown immensely since then. I was curious to know what was new for Accertify and got to learn a lot about that, as well as got to network with existing fraud friends and met several new ones. And my hope is that a lot of them will join us at the Merchant Fraud Alliance in October. That would be a lot, a lot of fun. I hope every merchant joins us at the Merchant Fraud Alliance in October. But I specifically, you know, one of the reasons I went to this event was to get the word out a little bit more. So it was a great opportunity for that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:54
They had a lot of networking opportunities, a lot of fun mixed in with sessions. And, you know, some on the big stage, some in breakouts, some were trainings, some were trainings on their new products, some were topics that people really care about in this industry and that, you know, they wanted to learn more about. Of course, AI was a topic of conversation. The theme of the event was how cybersecurity and fraud are better together, really talking about how fraud signals are moving up funnel. They're not just at point of checkout anymore. So there's a lot of fraud signals, especially for account protection, whether that's new account protection or account takeover protection, that type of thing, that live up funnel. And therefore, you need to make friends with your cybersecurity team. And they released a proprietary survey that they had commissioned that had a lot of really great benchmarking metrics that I've never seen published before, especially around cross-functional organizations working together. And they correlated that with their customers' fraud statistics. So like approval rate, chargeback rate, fraud rate, etcetera, to really demonstrate that there is, at least, a correlation, if not a causation, between cybersecurity and fraud working together and, you know, good outcomes in fraud metrics.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:22
So that's probably, I'm not saying anything specific, but that's probably all I can say for now. I did ask permission to share some of the statistics, and they said I absolutely can once the study is published, which will probably be in June. So you can look forward to that episode. I was really impressed with the questions they asked and the answers that came out of them. There's some good strategic direction, not only for this topic of fraud and cybersecurity working together, but for other things that we've all been asking for for a long time on the merchant side. So I think that will be something to look forward to. One of the breakout sessions that I attended was done by, you know, one of my favorite recent guests, Holly Sandberg. She did a terrific session on providing metrics with counterbalances to executives and senior leadership. She created a really great template for an executive scorecard and, you know, which metrics you should be measuring and then which metrics kind of counter those metrics and keep them honest.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
08:24
For instance, you can't just look at your fraud rate and say, woohoo, we're catching all the fraud without looking at your approval rate too. And you may be catching all the fraud, but your approval rate might be, you know, in the gutter and you're not approving enough orders. So you need to have both of those metrics to balance things out. That's just one example of the metrics that she shared. I thought it was a really good session and I asked her to please present it in a little bit of a different way with a different title and with a little different information, a few more specifics at MFA. So if you're looking for another reason to go to Merchant Fraud Alliance, that session is going to be fire. And I haven't told Holly this yet, but I want it on the big stage. I don't want it in one of the smaller breakout sessions because I think it's that good. And I think it's something that everybody needs to learn and wants to learn.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
09:17
I think communication with cross-functional teams as well as communicating with leadership are two things that we, on a whole, don't do well. And a lot of us recognize that and want to be informed by people who are doing it well. And Holly definitely is. So she'll be the perfect person to present on that. And if she wants a co-presenter, I will get her one, but she doesn't need one. Okay, well now I wanted to read this post from Nicola Harding. I found it really fascinating. It kind of made me laugh. It was the first thing I read one morning this week and I just, I kind of laughed to myself. And then my friend that was with me, I was like, what's so funny? And I read the post and, you know, as only fraud nerds would get it, she got it.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
10:06
So here's the post from Nicola and then I'll share some of my thoughts. EY. So like that EY, one of the top four biggest consultancies in the world, just published and then quietly pulled a 44-page cybersecurity report on fraud in loyalty schemes, all because it was riddled with AI hallucinations, fabricated citations and footnotes pointing to pages that don't exist, including a McKinsey report referred to throughout, a reference throughout that simply does not exist anywhere. So they were citing this McKinsey report of data, and that McKinsey report doesn't exist. This was not caught by EY's own review process, but by an external AI detection firm. As a criminologist, Nicola Harding, if you don't know her, has her doctorate. She's Dr. Nicola Harding and has her doctorate in criminology. I've gotten to see her speak in person and she is a wealth of knowledge on fraud.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:07
So as a criminologist who is an expert in this area, I can tell you that loyalty card fraud absolutely exists and it matters. The problem is that research like this doesn't just embarrass the firm that published it. It poisons the well. Hallucinated data gets picked up by other researchers, surfaces in AI search results, and corrupts the broader evidence base that practitioners, policymakers, and prosecutors rely on. That's not a minor quality control failure, it actually does serious harm to a field. AI is not the villain here. You wouldn't argue an accountant shouldn't use a calculator, but you would expect that accountant to be trained, accredited, and exercising professional judgment, not outsourcing the thinking to the tool and skipping the part where they check the workings.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:53
Research requires human judgment acquired through years of training, selecting appropriate methodology, reviewing the literature, understanding not just whether a source exists, but what the findings mean within the broader body of knowledge on a topic. That cannot be automated, and it shouldn't be. Research doesn't just need to be done, it needs to be presented within context by experts that understand the data in great detail and can defend the research and its implications. Fraud and financial crime prevention is an area where the stakes of getting it wrong are high. It is also increasingly an area where even the largest firms appear to believe they can blog expertise rather than invest in it. They cannot, and cases like this show exactly why.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
12:41
So there was an article, FT Times or yeah, the Financial Times that exposed this, but I really liked Dr. Nicola Harding's perspective on this and her take on this. My comment to her was, I was wondering when this would happen. AI is incapable of saying it doesn't know something, so it hallucinates. There's also the point, and if you've listened to this podcast in the last month or two, you know what point I'm about to make, that its data sources are open sources. And most of the real knowledge in fraud is either internal within companies or stored within the minds of fraud fighters. It's purposeful to keep what little advantage we have away from the criminals. And then I asked as a side note, did anyone copy or download this study before it was pulled? I'd love to read it, mostly for pure entertainment value.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
13:30
And she said, oh, all good points. And then she said, I have not. I don't have it, but I wonder if it's around. Shall we ask ChatGPT? Unfortunately, some of those points that may have been hallucinated in EY's study may now be in ChatGPT. So that if somebody, you know, asked ChatGPT about loyalty fraud, they may cite this EY study that was all based on AI hallucinations. That's part of the problem. The other part of the problem is this, not, you know, to have true expertise on a topic like loyalty fraud, you can't trust open source information. It's going to be all generalized. They're not going to be talking about the tools that you can specifically use to prevent loyalty fraud or even how hard it's impacting companies because a lot of impacted companies won't publicly say how much loyalty fraud is impacting them.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
14:19
So loyalty fraud is one of those that's kind of like account takeover fraud where it doesn't really have a metric. The metric you'll get, you know, you'll know it's happening when customer service is getting the calls of saying, you know, my air miles have been drained or my hotel points have been drained, or, you know, someone cashed in this voucher that I had because of how many times I've shopped with you, those type of things. And so they don't have the clear feedback loop that card fraud, traditional card fraud has with chargebacks. So there's a lot of nuances there that AI just doesn't have access to and doesn't know. So they'll make it up. And I did find it funny that one of the top four, you know, consulting firms that writes these big research papers obviously used AI to write it and didn't have a professional in the fraud industry read over it to verify that it was accurate. That is something I would have been happy to do had they asked, but now instead it's pretty embarrassing for them.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
15:20
But I think that this is a good article to share or posting to share with leadership if they are asking you to rely on LLMs to do research, as well as if they're thinking about using LLMs to replace somebody in strategy or someone in operations and fraud leadership. They cannot just ask ChatGPT a question and get the right answer. Just like with that example I've given earlier about, you know, what's pizza fraud? What's, you know, this kind of fraud? What's that kind of fraud? When Frank, we kind of did that in a group text I was a part of and then others did it too, ChatGPT was just making up different types of fraud that kind of made sense for pizza, right? I think one of them was pizza fraud is when someone goes into a pizzeria and steals a pizza. That's not, that's not fraud and that's theft.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
16:11
There were other examples as well that I can't remember, but there's no such thing as pizza fraud. But it couldn't say that. It was incapable of saying that. So instead, it made something up. How do you know if AI is making something up or not? You have an expert employed in your company who knows to spot BS and not, or at least knows who to ask. If they don't know, they can ask someone else in the fraud industry and say, does this sound right? You have to have someone with expertise and knowledge. You can't just rely on open source information for our industry. Maybe for others, but not for our industry. So that was the story. Like I said, I thought it was pretty funny, but also telling about the future that we are walking into or running into at this point.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
18:07
All right, let's talk about Mastercard's Scam Merchant Program, shall we? So Mastercard's new Scam Merchant monitoring is going to go into effect July 24th of 2026. They just announced it a few weeks ago. Its purpose is to find scam merchants. What they mean by scam merchants are merchants that are scamming consumers. The ones that pop up with a, you know, new merchant ID and they're offering free trials or they're shipping things like, or they're not shipping things at all, or they're promising something that they don't deliver on. Or, you know, they're promising something large and you get something small, or they're promising something, you know, that works and you get something that's broken. Those type of companies. Scam merchants. And so the way that Mastercard thinks that they can find them is by looking at a few key criteria. And they kind of have a multi-trigger framework is what they're calling it. But any one of these conditions can initiate a required investigation.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
19:10
So one of the more straightforward triggers is a breakdown in authorization performance. If a merchant's approval rate drops sharply over a short period, for example, a decline of 50 percentage points or falling below the 30% overall, that alone can put them into scope. The measurement window is tight. Acquirers are given a minimum of a 72-hour period or actually, oh no, this is different. This is not the acquirers. This is the measurement window for approvals falling quickly, a minimum 72-hour period with at least 25 transactions. So when any one of these triggers is, or one of these conditions is triggered, it'll initiate a required investigation with your acquirer. The acquirer has 72 hours to investigate and either provide Mastercard with an explanation on why this merchant is not scamming and not illegitimate. They have to provide a legitimate reason for that condition to be triggered, or they need to terminate that merchant and no longer allow them to accept Mastercards.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:18
And by the way, you can't just accept Visa without Mastercard. So if you're shut down for Mastercard, you also can't accept Visa. That merchant would only be allowed to accept Amex or Discover or maybe PayPal, which would greatly cripple online businesses. I'm reading from a post by Rick Lynch, who's been in the chargeback space for a long time. He goes on to say, there is also a direct escalation path from Mastercard itself. If a merchant is the subject of a Global Rules Investigation Program, or GRIP letter, that independently triggers the requirement to investigate. For newer merchants, defined as those with less than six months of processing history, there's an additional layer of sensitivity tied to issuer behavior and early performance signals. In those cases, just two different issuers reporting scam-related transactions under the manipulation of cardholder fraud classification is enough to initiate the process.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
21:16
So if you're a new merchant under six months and two issuers report that their cardholders have claimed that they were manipulated in some way, that's enough to initiate the investigative process within 72 hours. That can result in terminating your ability to accept Mastercard. The same applies if two issuers initiate chargebacks that reference scams or similar behavior. That's going to be more complicated because there are cardholders that claim that a merchant scammed them and they really didn't, right? So that's something to watch out for. Then there's a 5% threshold, and it sits specifically in this category. If a newer merchant, so I think within six months, sees more than 5% of its transactions result in refunds and chargebacks over a 30-day rolling period and has processed at least 500 transactions, that condition alone can trigger monitoring. So outside of that early life window, those issuer count and 5% thresholds are not explicitly defined as triggers in the same way. So I think that's important to know.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
22:26
But if you have a new merchant account and the combination of refunds and chargebacks equal more than 5% of your total volume of sales, you could be at risk for having your account activity investigated by your acquirer and possibly shut down. I think it's really interesting that they are combining refunds and chargebacks together. I understand why, but at the same time, Mastercard owns Ethoca, and when merchants enroll in Ethoca, they're enrolling in alerts that can allow them to issue refunds to avoid chargebacks. So they're kind of saying that for these purposes alone, but still for these purposes, Ethoca's not going to help you. It's going to hurt you. It's not going to, it's just, well, maybe it's not going to hurt you, but it's not going to help you because it's going to increase your refund amount. Additionally, there are some merchants that issue a lot of charge, or a lot of refunds because they have a lot of returns, right? A lot of retailers have a lot of legitimate returns that could look fishy to this, you know, program. You could be, you know, under monitoring. Granted, it is if you have, you know, at least 500 transactions, but I think in a 30-day rolling period. But I think most people on the merchant side that are listening to this podcast would very much blow that out of the water. So I think this applies to everyone.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
23:52
What they're not saying right now is if this applies to merchants that are older than six months. I don't know the answer to that. I have seen some people say it does. I have seen some people say it doesn't. I have heard other people say, well, they're rolling it out for the first six months, you know, of a merchant's lifetime now. But they're going to see how it goes and they're going to start tracking this metric more. And now that they can track this metric, if they see a high number of enterprise merchants, for example, that have a combined rate of refunds plus chargebacks divided by sales for that 30-day rolling period, it's not a calendar 30 day, it's a 30-day rolling period, that, you know, there could be repercussions. Right now, it hasn't been said one way or another, but I do think it's, you know, it's worth being aware of.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
24:41
Beyond performance and issuer-driven signals, third-party and network alerts can also initiate the process. If a merchant is flagged by a merchant monitoring service provider or through Mastercard's own monitoring programs, that alone can be sufficient. Once any of these conditions are met, the timeline is clear. The acquirer or payment facilitator has 72 hours to initiate an investigation, and if the merchant is confirmed to be conducting scam activity, they are required to block that merchant from processing Mastercard transactions. Separate from the trigger events themselves, Mastercard is reinforcing expectations around ongoing monitoring. Acquirers are expected to continuously evaluate transaction patterns, refund and chargeback activity, fraud indicators, and behavior that doesn't align with the merchant's stated business model. So if you say that you are a hotel but then you're only processing $20 transactions, that's going to look weird, or, you know, those type of things.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
25:48
There is also an expectation to review Mastercard's fraud and loss database on a daily basis for new signals. I think that's more for the acquirer than the merchant. Taken together, this is not a single metric program. It's a system with multiple entry points where performance changes, network escalation, issuer activity, and third-party alerts can all independently set the process in motion. So again, that's starting July 24th of 2026. I think most companies that are listening to this now on the ecommerce side have had their MIDs for way longer than six months. But I think it's important to be aware that Mastercard is tracking this data. This is new math that we don't usually do, right? Similar to VAMP, we don't usually do the exact math that they require for VAMP.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
26:38
We hadn't up until this time combined TC40s with chargeback numbers and then divided those by the number of sales. That was a new metric for us to start computing. Now there's a new metric to compute for Mastercard risk, and that is refunds plus chargebacks divided by sales, number of sales, the number of refunds plus number of chargebacks divided by number of sales. I think it's important to know that that's how things are being measured because you want to stay underneath those thresholds. And again, that threshold is 5%. I would hope that you would want to stay under that threshold for lots of reasons, specifically revenue. But at the same time, like I said, there are multiple reasons why merchants refund orders and some of them are very legitimate. I think that this could also impact subscription merchants who will often refund the last month of a transaction because they know that the cardholder can issue a chargeback.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
27:42
So, you know, technically the issuer, or the cardholder, can issue a chargeback for the last three months. So they'd rather give an appeasement refund of one month and then tell them, no, you can't get a refund at all, and then they go to their bank and find out they can charge back three months. So subscription merchants, high-risk merchants, some retailers, I think maybe over 500 basis points, I don't know, you know, it might be over that 5%. It's important to, you know, be aware of. All right, that is it for me today. That was kind of a shorter episode, just around 30 minutes or so. And it's not just because I want to get back to floating in the pool, I promise. But that was really, those are really the three things I wanted to update you on. I am expecting to have a guest for next week's episode. Also, Fraudology is coming to YouTube soon. This is kind of against my will, but it's been strongly encouraged by several people and as well as by my sponsor that I branch out to YouTube. So why not now?
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
28:49
So that will be happening in the next few weeks. Don't forget to look into the Merchant Fraud Alliance October 6th and 7th in Chicago. You're not going to want to miss it. Otherwise you're going to have significant FOMO. I promise. I am putting a lot of time and effort into sourcing the best speakers and, you know, representing the best companies. And by having those people in a room, those are conversations you get to have as well. And there will be the ability in the app to set up meetings with people. You can also set up your own schedule for meetings. There's just all kinds of cool features. So it's a great way to meet new people and see familiar faces as well.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
29:29
So with that, I'm going to talk to you more next week, but I hope that you are having a great day and I'll talk to you soon.