SardineCon SF/2026

Learn More
Fraudology

Informe trimestral de fraude 2026: Detectar el fraude de hoy mientras nos preparamos para las estafas de mañana

41 min

Bienvenido de nuevo a Fraudology.

De vez en cuando me encuentro con un informe que me hace dejar de lado lo que tenía pensado comentar porque es así de importante. Esta es una de esas semanas.

Matt Vega publicó recientemente su informe trimestral de fraude de 2026 y, después de leerlo, supe que teníamos que analizarlo juntos. No porque esté prediciendo lo que podría pasar el año que viene, sino porque cada ataque que se menciona en este informe ya está ocurriendo.

Uno de los temas principales que recorre el informe es que el fraude simplemente avanza más rápido que los equipos antifraude. La IA está haciendo que los ataques sofisticados sean más baratos, más fáciles de lanzar y mucho más difíciles de detectar. Los delincuentes ya no necesitan grandes conocimientos técnicos cuando pueden alquilar las herramientas que necesitan a través de mercados de fraude como servicio.

Entonces, ¿cómo se ve eso en la práctica?

En este episodio, analizo varias de las tácticas de fraude más recientes que ya están apareciendo en el mundo real, incluyendo malware oculto detrás de falsos enlaces para darse de baja, malware bancario que puede aprovecharse del dispositivo de confianza de un cliente y técnicas de secuestro de sesión que hacen que el fraude por toma de control de cuentas sea increíblemente difícil de detectar usando los modelos tradicionales de detección de fraude.

A primera vista, muchos de estos ataques parecen legítimos. Ese es precisamente el problema.

También hablamos de por qué los equipos de fraude ya no pueden confiar únicamente en señales de confianza individuales como la inteligencia de dispositivos, la reputación de IP o incluso la analítica de comportamiento por sí solas. Los delincuentes han aprendido a mezclarse con el comportamiento legítimo de los clientes, lo que significa que nuestro enfoque para la detección y la prevención del fraude también tiene que evolucionar.

Aquí es donde las cosas se ponen interesantes.

Una de las conclusiones más importantes que saco del informe de Matt es que la respuesta no es una nueva herramienta ni un nuevo modelo. Se trata de combinar una mejor inteligencia contra el fraude, compartir información a través de redes de consorcios y comprender las tendencias más amplias del cibercrimen que ocurren fuera de tu propia organización. Porque, para cuando un nuevo ataque llega a tu bandeja, es muy probable que otra empresa ya lo haya visto.

También dedico unos minutos a compartir una actualización sobre la conferencia de la Merchant Fraud Alliance, incluido nuestro nuevo bootcamp de IA centrado en formas prácticas en que los equipos de fraude pueden empezar a usar la IA en la prevención del fraude hoy mismo. No porque la IA sustituya a los analistas de fraude, sino porque ayuda a que los buenos equipos se muevan más rápido.

Si trabajas en fraude de comercios, fraude bancario, fraude en línea o fraude de comercio electrónico, este es uno de esos episodios que te ayudará a reconocer los patrones antes de que se conviertan en tu próximo incidente.

Lo que escucharás en este episodio:

  • Por qué el informe trimestral de fraude 2026 de Matt Vega es uno de los recursos de inteligencia sobre fraude más valiosos publicados este año.
  • Cómo la IA está acelerando el cibercrimen moderno y haciendo que los ataques sofisticados sean accesibles a través de plataformas de fraude como servicio.
  • Un análisis de varias tácticas de fraude emergentes que ya están dirigidas a comercios e instituciones financieras.
  • Cómo se están utilizando las campañas de phishing de cancelación de suscripción para instalar malware y registradores de teclas.
  • Por qué el malware bancario se está volviendo cada vez más eficaz para eludir los controles antifraude tradicionales.
  • Cómo el secuestro de sesiones permite a los delincuentes realizar fraudes de toma de control de cuentas desde dispositivos de clientes de confianza.
  • Por qué la inteligencia de dispositivos, la reputación de IP y el análisis de comportamiento deben evaluarse en conjunto y no de forma independiente.
  • Cómo el intercambio de inteligencia sobre fraudes y los datos de consorcios ayudan a las organizaciones a identificar más rápidamente las amenazas emergentes.
  • Una actualización sobre la conferencia de la Merchant Fraud Alliance y su nuevo bootcamp de IA en la prevención del fraude.

Deberías escuchar este episodio si:

  • Diriges equipos de fraude, riesgo o confianza y seguridad.
  • Gestiona la prevención del fraude para un comercio electrónico, fintech, banco o empresa de pagos.
  • Quieren mantenerse a la vanguardia de las últimas tendencias en ciberdelincuencia en lugar de reaccionar cuando los ataques ya se han generalizado.
  • Están evaluando cómo la IA está cambiando tanto la prevención del fraude como el fraude impulsado por IA.
  • Cree o gestione modelos de detección de fraude.
  • Investigar la toma de control de cuentas, la identidad sintética o el fraude en línea.
  • Quieren prácticas recomendadas prácticas para la prevención del fraude en lugar de discusiones teóricas.
  • Confía en la inteligencia del dispositivo, la reputación de la IP o el análisis del comportamiento como parte de tu estrategia contra el fraude.
Notas del episodio

Informe trimestral de fraude de Matt Vega 2026

Si has escuchado el pódcast antes, sabes que siempre he valorado la forma en que Matt aborda la inteligencia sobre fraude. Dedica su tiempo a observar donde la mayoría de nosotros no puede. Supervisa comunidades criminales, sigue las técnicas emergentes y conecta patrones mucho antes de que se conviertan en ataques generalizados. Esa perspectiva es importante porque el fraude no llega con una nota de prensa. Comienza en silencio, se propaga rápidamente y, para cuando la mayoría de las organizaciones lo reconoce, los delincuentes ya han pasado a la siguiente táctica.

El informe refuerza una realidad cada vez más evidente: los estafadores ya no necesitan conocimientos técnicos avanzados para lanzar ataques sofisticados. Las herramientas impulsadas por IA, el malware de alquiler y las plataformas de fraude como servicio han reducido drásticamente las barreras de entrada, permitiendo a los delincuentes escalar sus ataques más rápido que nunca.

El informe no está lleno de predicciones ni de escenarios hipotéticos. Se trata de técnicas activas que ya se están utilizando hoy contra instituciones financieras, comercios y prestamistas. El valor no está solo en saber que existen, sino en entender cómo funcionan para poder reconocerlas antes de que se conviertan en tu próximo incidente.

Tres técnicas de fraude emergentes

Analicemos tres ataques que realmente me llamaron mucho la atención.

  • Campañas de phishing de cancelación de suscripción generadas por IA que instalan malware de tipo keylogger.
  • Malware bancario que disfraza actividades fraudulentas al enrutar las transacciones a través de dispositivos legítimos de los clientes.
  • Ataques de secuestro de sesión que permiten a los delincuentes tomar control de cuentas sin activar muchas de las señales tradicionales de detección de fraude.

Muchas de las señales en las que tradicionalmente hemos confiado, como la inteligencia del dispositivo, el historial de sesiones, la reputación de la IP y la consistencia del comportamiento, pueden parecer completamente normales.

Y por eso estos ataques merecen atención.

La detección de fraude moderna requiere múltiples capas de inteligencia que trabajen juntas

Un tema central que recorre el informe de Matt es algo de lo que he hablado en este pódcast durante años. No existe una única señal que vaya a salvarte. Los atacantes siguen encontrando formas de imitar el comportamiento legítimo de los clientes. Los delincuentes están encontrando cada vez más maneras de convertir nuestras señales de confianza más sólidas en puntos débiles. Están secuestrando sesiones de confianza, utilizando dispositivos legítimos prestados y empleando la IA para automatizar ataques a un ritmo que las empresas individuales simplemente no pueden igualar.

Los programas de prevención de fraude más sólidos no dependen de un solo modelo ni de una sola regla. Combinan múltiples fuentes de inteligencia, validan continuamente las señales de confianza y analizan el contexto más amplio en lugar de tomar decisiones basadas en un único indicador.

Conferencia de la Alianza contra el Fraude Comercial

Una breve actualización sobre algo que me entusiasma muchísimo. La conferencia de la Merchant Fraud Alliance que se celebrará este octubre en Chicago tendrá una sesión que espero con especial interés.

Nuestro Boot Camp de IA no va a ser otra conversación sobre si la IA es importante. Ya sabemos que lo es. En cambio, nos centraremos en algo mucho más práctico: cómo los equipos de fraude pueden usar la IA en su trabajo diario.

Veremos indicaciones reales, flujos de trabajo reales, paneles de control, generación de informes, investigaciones y formas prácticas en que los profesionales del fraude pueden usar la IA para ser más eficaces.

No para sustituir la experiencia, sino para potenciarla. Ese enfoque refleja toda la filosofía detrás de Merchant Fraud Alliance.

Todo lo que figura en la agenda está diseñado para ayudar a los profesionales del fraude a irse con ideas que puedan aplicar de inmediato cuando vuelvan al trabajo. Y, sinceramente, ese es exactamente el tipo de conferencia que ojalá hubiera existido hace años.

Conclusiones clave
  • El informe trimestral de fraude 2026 se centra en ataques reales que ya están afectando a las organizaciones hoy en día, no en predicciones futuras.
  • La inteligencia artificial está haciendo que los ataques de fraude sofisticados sean más rápidos, más baratos y más accesibles.
  • El fraude como servicio sigue acelerando el crecimiento del cibercrimen organizado.
  • El malware bancario y el secuestro de sesiones explotan cada vez más los dispositivos de confianza de los clientes para eludir los métodos tradicionales de detección de fraude.
  • El fraude por toma de control de cuentas es cada vez más difícil de identificar utilizando únicamente señales individuales de confianza.
  • Los modelos sólidos de detección de fraude combinan analítica de comportamiento, inteligencia de dispositivos, datos de consorcio e inteligencia contra el fraude.
  • Compartir inteligencia sobre fraudes entre organizaciones ayuda a identificar antes nuevos patrones de ataque.
  • Los equipos de fraude deben monitorear continuamente las tendencias emergentes del ciberdelito para mejorar la detección y la respuesta.
Conclusión final

Las herramientas que utilizan los delincuentes siguen evolucionando y muchas de las señales en las que hemos confiado durante años son cada vez más fáciles de manipular. Eso no significa que esas señales hayan perdido su valor. Significa que funcionan mejor como parte de una estrategia de prevención del fraude por capas que como indicadores aislados.

Para quienes combaten el fraude, mantenerse informados se está volviendo tan importante como mejorar la detección. Informes como este nos ayudan a reconocer nuevos patrones de ataque antes de que se generalicen, dándonos la oportunidad de adaptarnos en lugar de simplemente reaccionar.

Porque, al final del día, el objetivo no es solo detectar el fraude de hoy, sino prepararse para el de mañana.

Recursos y enlaces del episodio:

Conéctate con Karisse Hendrick | LinkedIn

Presentador del pódcast Fraudology

Experto en ciberdelitos galardonado

Consultor en prevención de fraudes en comercio electrónico

Asesor de startups, orador principal y

Consultor para comerciantes de Fortune 500

Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:05
Welcome back to the Fraudology Podcast. Well, for those of you that are listening, everything sounds the same. For those of you that found me on YouTube, I'm gonna be honest, this is a little weird. I had my first episode on YouTube last week with Mark Portius, and that was easier because I've done webinars before, I've worked with other people before. It was just a conversation with a friend, right? And it just happened to be on camera. But now I'm talking by myself to myself, and I can see myself doing it, and that's a little strange. So bear with me. For those of you on YouTube, please bear with me for the next couple of weeks. We're still figuring out lighting and position of the camera and all of those things to try to make this easier for you to watch. I've been hearing for years from people who have wanted to watch or listen on YouTube and I've put it off long enough. And thanks to the encouragement of the team at Sardine Media, I they made it happen. Really, they did 95% of the work to make sure that this happened. And if you haven't checked out the new Fraudology website yet, which will be in the show notes, as well as I posted about it last week on LinkedIn, definitely take check it out. We've got every single episode. So all four hundred I guess today is four hundred and thirteen. So all four hundred and thirteen episodes where you can look, you can find the transcript, you can find a summary, you can find takeaways, there's you know links to connect with the speakers on LinkedIn. It's really cool and really amazing that they were able to do all of that. So make sure that you check that out, especially. You know, of course I want you to listen, but if there's a week where you're like, I can't listen, but the topic looks good. I'd love to know what it was about. Go check out the summary. It's, you know, just a couple paragraphs, and then there's some bullet points afterwards for takeaways and things like that. So that's my plug for this new platform and all of that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
02:21
Again, I'm just so grateful to the Sardine team for going above and beyond what a sponsor does to make all of this look even more professional than I think that it is. Anyway, so before I dive into going over, so today I'm gonna go over part of a quarterly report that our good friend Matt Vega just put together and released and published. Matt, as if you've heard him on the podcast before, he really has his ear to the ground when it comes to dark web stuff. So not that cyber criminals really operate on the dark web anymore, but what I mean by that is, you know, the people that he understands what the criminals are doing and it's often the tactics that we don't know about yet, those hardcore sophisticated cybercrime tactics that we haven't we don't have a name for yet or we haven't identified in our systems yet. Those are the things that Matt really specializes in because of his background, with the military and then with a certain agency with three letters that I'm not allowed to say publicly. As well as, you know, his time at Sardine, Matt is now at point predictive working closely with Frank McKenna. Which what a powerhouse duo that is. So Matt put this together for Point Predictive and it's really the top ten fraud tactics in cybercrime that we don't know about yet that we need to. And he's got it broken down by banking, you know, credit and lending, you know, who the targets are. And we're gonna go over the ones in cyber fraud. There's I think three. Three in the cyber fraud section. So that's what we're gonna do for today's episode. But first I just want to give a little bit of an insight into what's going on for the Merchant Fraud Alliance. I haven't talked about it in a couple weeks.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
04:30
Mostly because I've been heads down working on the agenda. It's unorganized, but I currently have two large foam boards to the left of me with post-it notes of all the sessions that we're having, all the educational sessions that we're having. And it's now my job to assign speakers to each each session. And that's really what I've been head down working on that for the last few weeks. So, haven't been talking about it, but one of the things I wanted to highlight was actually, you know, the conference is October 6th and 7th in Chicago. But on October 5th, what we're kind of calling day zero, we're having a boot camp. And that boot camp is for you know, merchants only. It'll be for about 50 merchants. There's an e-commerce merchant that has an office in The Willis Tower, where we're having the conference on Tuesday and Wednesday. And they have graciously offered us the a large conference room to do this boot camp so that the rest of our team can set up for the conference for Tuesday and for Wednesday. But anyway, it'll be at the Willis Tower and AI boot camp can be so general, but you know what we came about was when we were talking with the ambassadors and figuring out what they think merchants need to know and what they, what they wanted to learn and what they wanted their teams to learn more about. We identified utilizing AI to fight fraud. There's some e-commerce companies that have mandated across their company that all employees must be utilizing AI, you know, whether it's Claude or it's Copilot or Chat GPT, that they need to be utilizing often the enterprise solution. They need to be utilizing it for 25% of their job or more. There are other e-commerce companies that have set up a kind of a working group to review any company that claims that they do AI.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
06:45
To verify that they actually are using AI and that they're not just saying that because it's a buzzword. So different companies are handling it different ways. But what it comes down to is there's also this piece where we're watching colleagues of ours in the industry lose their jobs, either to the fact that their employer thinks that they can be replaced by AI. You know, they haven't been yet, but they think they can, or they're you know, in the US, they're outsourcing to overseas. We're watching that happen and I think a lot of fraud people are saying, well, I need to get with the times so that I don't lose my job. And that's not to say that the people that were laid off if they you know had implement integrated AI into their job for 25% of the time or whatever, that they wouldn't have been. But there's a lot of people who want to utilize AI in fighting fraud, whether that's running reports, creating dashboards, identifying new fraud vectors, all of those different things, you know, new data sets, upgrading their machine learning to be AI internally, just all of those things. But they don't really know where to get started. And so there's two merchants that are gonna be leading this. I'm not gonna announce who they are yet, but they work for very large companies. And one of them specifically has been training their team over the last year to use AI and really to do more faster and to catch more fraud. And the goal of this boot camp is that you walk away with a takeaway. With prompts to use, with you know, the outline of a dashboard. Just with a greater understanding of how to use AI to fight fraud. And that's what those three hours on Monday is going to be dedicated to. So I want, I really, I can't stress enough how critical all of these sessions are to help you do your job better. That is our hundred that is our main goal, and we're knocking it out of the park with these topics and with these speakers, guys. It's pretty impressive.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
09:04
I'm very humbled at the people who have graciously accepted my offer to be part of this conference in the content piece. Some of them refuse to go to other conferences, so you can't see them anywhere else, but they're choosing to take risk on this first year. And I hope that you do too as an attendee because you're gonna have a lot of FOMO the first week of October if you don't. I can tell you that. But yeah, so we are limiting entry to the people who sign up and who first, so it's first come, first serve for that boot camp. We're getting close to capacity, but that's why I wanted to share about it today. If you do register at Merchant Fraud Alliance dot com, you can email me or message me afterwards or include it in your registration that you want to be part of the boot camp. I think there's a part that you can check for that. If you want a discount you for a ticket, message me on LinkedIn. I've got a handful of 50% off discounts that I'd love to hand out to Fraudology listeners. And just a reminder that we're not selling vendor tickets. We are only sending selling tickets to merchants. There will be vendors at the conference, but they're sponsors of the conference. And that sold out months ago. So we only have 15 companies that are vendors that will be attending. That's I think the way it shakes out, it'll be about 47 vendors and the rest will be merchants. And our hope is to have, you know, four or five merchants to every one vendor. So that it's easier to identify your peers and that you can have really good conversations with the solution providers that are there. Rather than feeling like you're a continual target. So for those of you who want to come to the conference, just a reminder that you do have to be working for a merchant or have most recently worked for a merchant if you're laid off.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:13
Okay, that was probably a lot longer than I meant for it to be. I hope my editor kind of like makes that a little more succinct. He's very good at that. Sometimes I ramble and he's, he's good at kind of tightening it up a little bit. But I could honestly talk about the content for MFA for a long time because I'm just so proud of it. And I think I'm proud of it because it came from merchants. Instead of putting out a call for speakers and saying, “What do you want to speak about in six months?” We asked our audience. We asked merchants, the people that will either be there or their peers will be there, and said, “What do you want to learn about?” What do you need to learn about? And that's how we built the agenda. So I'm proud of it. And that's why I'm rambling. All right, let's talk about Matt Vega's report. It is lengthy. I will say that. It is in-depth and lengthy. So you definitely will want to download it yourself or I think, you know, the first page you can read without anything. And then at least for me when I got to the actual report after the executive summary, it just asked for my name address or not my address, my email address. So my name, my email address and the company I worked for. I think that that's just so that the next quarter that Matt releases it, he can email it to you. He's not gonna sell the data or try to sell anything to you. I will make sure that there is a link to this report in the show notes. But it's also on the Point Predictive blog. Like I said, Matt joined Frank about a month and a half ago, I think. He love the way he did it at Sardine. I think he was there for four years and did a lot to really build it up and make it a you know, great and really relevant. But he wanted a new challenge and Frank was looking to kinda focus more on his Frank on Fraud duties than having a full time job at Point Predictive and work on Frank on Fraud. So it was a win-win. I had the pleasure of giving Matt a raving recommendation when Frank called me about it. So it's their dynamic duo and just having the time of their life geeking out every day on fraud. But anyway, this report I'm gonna read a little bit of what Matt says because it just gives context to why he did it. The kind of the title is Fraud is Officially Faster than Fraud Fighters. I would agree with that. And that is a very stressful statement. He goes on to say the trend that continues to worry me is the speed of innovation and collaboration of the attackers. As fraud fighters, it is more important than ever before to share what we're seeing, pass along our lessons learned, stay on the front lines of fraud threat intelligence, and lean into data consortium models for herd immunity. Attack on one protects all.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
14:35
I am now releasing this free quarterly fraud intelligence report to help my fellow fraud fighters and industry professionals stay aware of the ever evolving threats that we face. I spend hundreds of hours a week, or a quarter, diving into the deepest corners of the dark web, infiltrating rings and monitoring threat actors to understand the new exploits they are proposing, the ones they're working on and deploying against the industry. The most common theme this quarter: the people attacking your institution are no longer advanced cybersecurity black hats, engineers, or skilled fraudsters. They are a new generation of threat actors who combine the lack of extradition treaties with AI and rent a fraud tool. Providers, I call it fraud as a service, but same thing, rent a fraud tool providers to attack financial institutions and businesses with little to no recourse. Camera injection kits that defeat document checks, now sell for the price of a movie streaming plan. Banking Trojans are custom built to silence a specific bank's fraud prevention alerts before the money moves. And two-thirds of the flagship fraud AI models you hear about across the industry have been flipped into scams aimed at people trying to research or stop them. Nothing in this report is a forecast. All 12 vectors are active techniques we tracked from early dark web chatter. Into active or scaling attacks over the last quarter. Some will have already hit your queue this quarter, and you probably will never know. Others are going to hit your system in the coming months, following the traditional path of least friction. Every one of them is cheaper, exponentially faster, and far more advanced than the version you defended against last year.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
16:36
Wow, Matt, let's invite you to a dinner party. But it's all so true. And this is stuff that I talk about on a regular basis. I was asked to present at a top internet 50 company, I think, like very well known brand, last week, and really just to help them understand what they're not seeing and what they don't know and kind of that bigger picture of fraud. As I explained to them, they're the experts of the fraud that happens under their roof, so to speak. But it's helpful to understand what it looks like everywhere because, you know, you may not understand the other half of that fraud vector. There might be pieces of it that if you understood them, you could fight them better. It also is good because you're not going to be receiving every single fraud vector. And so what your peers are seeing, if you're not seeing it yet, you will soon. So when I was talking to this merchant, and it was a group of about 30 or 40 people from their risk team, they have a very large risk team because they have a lot of fraud, just like most large, well-known companies do. I do know of a few very large companies that have very lean teams, but their numbers kind of speak for themselves. They're hanging on by a thread. Not that always throwing bodies at the problem is the right way, but in this case, I think they see a lot of ROI on that. So I'm just backing up what Matt said. The biggest thing that I said was that they no longer need to have, you know, PhDs in computer science or, you know, be a skilled hacker, or even understand the ins and outs of your flow the way that fraudsters of you know previous years have. They'll study every single part of your flow, they'll figure out how to you know exploit a vulnerability and these days you don't need that anymore every piece of the puzzle to commit fraud against specific companies is out there for sale. And it's not expensive.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
18:55
You can get tutorials, you know, whether that's in book form or video form or a one-on-one coach, so to speak. You can get a fraud coach to teach you how to do fraud. You know, this fraud as a service thing, I remember really calling it out when I started to see it for refund fraud because I thought, man, if this starts happening for payment fraud, it's gonna be difficult to catch because you know it's no longer one guy trying to figure out all the ins and outs of several companies. It's several companies trying to figure out or you know, several small fraud fraudulent companies, figuring out the vulnerabilities of one company at a time. Matt goes on to say advanced threats and fraud vectors can do and hide from one financial institution, lender, dealership, merchant, or business. They cannot hide from a shared knowledge network like the lenders on Point Predictives Data Consortium. Where an attack on one triggers the fraud immune response that protects everyone. Once they attack one, the network learns, adapts, and builds up on that herd immunity. Improving detection and prevention with each subsequent attack just like your immune system. One of the reasons why Matt and I get along so well is because we both love analogies. Every attack vector in this report survives by staying nearly invisible to any single institution or business, making these exploits extremely difficult to detect without sharing networks and consortium models. A seasoned synthetic looks prime in one portfolio, but that same file in front of the full network of lenders and the community of enhanced data sharing pierces the network to show its true risk.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:47
As you read, ask yourself whether you would be able to detect or stop them in your own systems and controls. Industry collaboration, knowledge sharing, and shared data networks are more critical than ever before, and we are always happy to help provide guidance or show you how Point Predictive's data consortium models are leading the way for lenders across the industry. So, I of course, you know, need to talk about the company that he represents. Point Predictive is really good at helping dealerships, car dealerships identify synthetic ID. And a big part of that is their consortium model. A lot of times someone who steals a car from one dealership is gonna go steal a car from another dealership. They're gonna use, you know, fake documentation and fake bank account, you know balances and you know fake job pay stubs and everything else, and they're gonna go to different dealerships. So that's why he's talking about, you know, if you a fight a hit against one is is against all, right? We'll all find out about it if you use a data consortium. So they're all, you know, some are better than others. But I definitely recommend with at least one of your fraud vendors, that you do take advantage of the data consortium. There can be challenges. And I've been vocal about that over the years, but I agree with Matt that that is one tool that should be in your, in your fraud fighting toolkit.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
22:25
So there's twelve vectors. I'm gonna go through the ones that are impacting cyber fraud. I’m going to go through the ones that are impacting cyber fraud. We talk about the first trend in cyber fraud. He says it’s hiding in plain sight. And that is the annoyance to unsubscribe attack. And I didn’t know about this either. So that’s why I love to, you know, do this kind of research. And why I wanted to share it with you guys. I might have Matt back on the podcast in the coming months, but he was just on a couple well a month or two ago, right before he left Sardine, and I didn't wanna ask him again so soon, so we can learn from him this way. Attackers found a use for your annoyance. They flood you with the same email until you reach for the unsubscribe link, and that link is the attack. This is kind of scary. Anyone whose email address appears on the dark web list, which is more than ninety-five percent of all emails globally, are the key targets in this.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
23:30
So this was first detected by Point Predictive in June of 2026. So just last month. Criminals use AI to build high quality clones of I'm gonna start over there. Criminals use AI to build high quality clones of real company email campaigns. Then spam you with them many times a day from a lookalike address. The links are safe, real products, real sales. Real promotions. Click a product image and you land on the real website. Nothing bad happens. So it's not similar to Starkiller, like we talked about a few months ago. Then after the 21st identical marketing email that day, you click unsubscribe. That link carries a hidden malware redirect that drops a keylogger onto your device, capturing everything you type. Passwords, credit card numbers. Addresses, banking details. It's on his radar because it rides on legitimate campaigns and real URLs, and it uses annoyance as the method. Irritated people forget to check the unsubscribe link. That combination, because the emails look fine. They're legit. So why would you check the unsubscribe link? That combination is giving this attack the highest success rate we have seen in years because it hides in plain sight. Ninety five percent of all email addresses globally sit on a dark web list and that is the targeting.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
24:58
Signals to watch. A rapid or daily jump in marketing volume from a brand that rarely emails you. Copy the unsubscribed URL before clicking. A random string is the tell. So it would just be a lot of alphanumeric characters dot net or dot com. If you don't know how to copy a URL without clicking it, you just simply right click or you hover over the hyperlink. I don't know if we still call it that in 2026, but you hover over the link to unsubscribe. And sometimes you have to right click depending on your software, and then it will show you what the URL is that you'll be directed to if you click the button. So if it's a random string of alpha numeric characters. You know it's not for the merchant that they're, you know, trying to be or the bank that they're trying to be. Legitimate looking campaigns. So also look out for legitimate looking campaigns from addresses that do not match post marketing. So, you know, take a look at the email address that traditionally sends you emails, you know, marketing emails, and then take a look at the email address that sent you this one and determine if it's accurate or not. I've never thought about, you know, utilizing the unsubscribed link as the way to get malware onto your system with a keylogger. But it doesn't surprise me and I think it's really good to be aware of. The next one.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
26:39
Is Trickmo. Turns victim phones into clean exit nodes. Same real device, same IP, same city. Every signal your model trust checks out and a fraudster's behind all of it. That is very similar to the Starkiller product that we talked about on the podcast about a month, or a month and a half ago. Maybe it was two months now, but I was really worried when I found out about that because it was, you know, had a lot of potential danger. It looks like something similar is out there too. So the key targets are banks, credit unions, lenders, e-commerce, and exchanges that lean on device or IP as a key trust signal. As I think we all know, there's not just one key trust signal anymore, right? It's the combination that makes the difference. So what is it? A Trickmo variant, first tracked by Threat Fabric. And sold as malware as a service, re-engineers a banking trojan into a managed foothold. A built-in SOX5 proxy turns the infected phone into a network exit node. I'm saying N O D E node. That gives the fraudster the ability to route their own session through the victim's actual device and IP address. IP reputation and geolocation signals come back clean. In plain terms, the fraudster's activity flows through the actual card holder's real phone and your system reads it is safe.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
28:19
But it's on their radar because this attacks the fraud detection layer itself. The transaction originates from the customer's trusted device, network, and geography, which is exactly what many models, rules, and score risk scores use to lower the risk on a login and its activity. So by being able to glob on to the consumer's session and device and everything else, that looks legitimate. A lot of times these types of attacks are happening after another purchase. So what you'll have is customers calling your customer service and saying, “Hey, I made purchase one for $60. I didn't make not make purchase number two for $600.” There's no way I didn't make it, it's fraud. So customer service contacts the fraud department, they look it up to see if, you know, they missed something. And as Matt says in this report, everything that we hold, you know, is a weighted advantage you know, can be used against us. And so if we're using device and session and all of those in geography, you know, geo geography on IP, like geographic locations, then that can be used against us if the fraudster can just piggyback on the first transaction. This attacks the fraud detection layer itself. The transaction regenates from the customer's trusted device, network, and geography. Which is exactly why many models, rules, and risk scores use to lower the risk on a login and its activity. Think I might have read that twice. Sorry guys.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
30:07
Trick mode doesn't beat your fraud model. It dresses the fraudster in the victim's clothes. That's why invisible, when that's only visible when you're looking across a network or consortium, not inside a single portfolio, said Bill Hall, who is CTO and chief of staff. I don't know if that's for Point Predictive or not, but give him a shout out for his quote. Signals to watch. So, you know, you can't just cancel every transaction that has a safe device and a good IP address because there wouldn't be a company anymore. So instead the signals to watch are trusted device and IP paired with brand new behavioral metrics. Impossible spy simultaneous sessions from one identity or device. So maybe they make the per, two purchases at once on the same device and same session. That would be odd. Residential proxy or exit node indicators on a consumer line. And then another way to identify this is internal network recognizance coming from a consumer device. So if you're seeing any of those things across your network, or like I said, if you're having customers contact customer service to say, wait, transaction one was right, transaction two was not, or I logged into my account to change my address, and after I logged out, they then change the payee information to send me the check for people staying at my house on like a hosted, you know, travel site, for example. Those would be some indicators as well that you're getting hit with this.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
31:59
The Puppet Master malware that waits. All of this malware just creeps me out. Like it's just there's so much of it and it's really powerful, that it really worries me. And I think it should worry you as well. And I think knowing it's half the battle, when you know that these attacks are possible. You can then be able to diagnose it so much faster, once it's attacking your company. But also it makes you very relevant to other departments within your company where you can say, hey, there's a problem here. These, this is not a case of a customer making one purchase and then making a much larger purchase the next day or the same day. They haven't even gotten their products yet. So why would they know that they were happy and they wanted to order more? So anyway, those are all of the reasons why I think this is really important to talk about and also to just remember that malware can be scary. Here's the last one the puppet master malware that waits. This is a tricky one. The fraud operator waits and strikes mid session inside the real username's genuine activity, like a puppet master.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
33:20
The key targets are banks, credit unions, and online banking customers. So not as much e-commerce companies, but if you're in online banking or I would imagine crypto as well, this is important. So described in Barracuda's June 2026 analysis, this banking malware does not auto-fire. Disguised as a browser or security update, it lets a human operator watch a live banking session and pick the exact moment to act. Capture the session or take over midstream like a puppet master working a toy puppet. Because takeover happens inside the customer's own normal session, the fraud blends into their real behavior patterns and device signals. Detection gets very hard. Why it's on their radar? Bot and behavioral models are tuned for machine speed and or out-of-pattern actions. A human striking mid-session from inside the real user's activity generates almost none of those tells. So because they could identify account takeover when they weren't on the same session, they weren't on the same device or IP or anything else, it's really difficult. So unfortunately fraudsters are trying to bypass those. A human striking mid-session from inside the real user's activity generates almost none of these tells. It looks like the victim because in every tran technical sense it's the victim's session.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
34:54
So it's gonna you know, it's gonna look like friendly fraud, so to speak, or, you know, first party fraud, but it's not. So they do provide a call out between human-driven and so it says human-driven is an operator watching live and picks time the picks the moment that no machine speed tells. Mid-session, the attack lands inside genuine logged in activity, not the log E. Signals to watch for, high value actions right before, right after a software security update. Because the software security update would be the download of the malware. Session hijack indicators with no new device event or signal. So you've seen two checkouts on one account, an hour apart, and the local time is very, very late. And you know, all those other signals that you can combine, you should be combining to be able to identify this. Session hijack indicators with no new device event or signal, subtle mid-session shifts in cadence or navigation behavior, and a legitimate login followed by out-of-character movement in the same session. So those are things that you can look for to identify this. There is one more about international ghost tapping on the global remote contactless fraud that we talked about a little bit before Christmas. I think that we are the holiday season in November. I think that I have not done a good job of educating consumers or retailers with physical stores on this tactic. But it's important to be educated. So the very short answer I would say on this issue, that's impacting card not present merchants and remember they're on the hook for their own chargebacks. So they want to not be on the list, right? They don't want to have those they don't want to have any more. Inner but anyway.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
37:10
It's important just to know that contactless fraud can happen and you can get chargebacks from it. I have yet to hear from one of the merchants I reached out a few weeks ago. To see what happened when they called their acquirer and said, look, this was a ghost app. This was not true fraud. We need to go after these people. And in this case they knew exactly who they were because they had surveillance cameras from in store, they had their information. So that they could get loyalty points. But it's not always gonna be the case. So now that I've thoroughly depressed you, I do think it's so important though to be up on these tactics so that when someone in your company comes to you and is like, this is really weird. This doesn't make a lot of sense. You can recall something that you heard on the podcast or a webinar I do or a private presentation and be like, hey, is this affecting me? Like, am I not am I the problem, but is this something I should be concerned about? What are those signs? You know, can you look through my reporting and identify it? That type of thing. So I really want to thank Matt for putting this together. I had other fraud articles that I was gonna read this week. But then I saw this come out and I was like, no, we definitely have to dive into this. Because Matt always knows he's like three steps ahead of where a lot of us are with or a lot of, you know, online companies and banks are with the software that's able to detect that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
38:57
This helps you be able to detect them early. And really that's what it's all about is being able to be aware of them so that you can find them early. I want to, again, like I said, thank Matt for putting this together, knowing this stuff can help us stop them faster. It also shows a lot of patterns around how they're using AI, how they're using our own systems against us. The things that we have come, become reliant on, can no longer be relied on. And I think that the other big takeaway from all of this is how important it is to look from a 10,000 foot view. Not just look at the device, not just look at the session details, not just look at the behavior, but look at all of it together. And then also bring in your consortium data with the fraud provider that you use that for. Bring it, you know, you need we've been saying it for years, but you need to have layers. Because just one piece of this isn't gonna catch it. And as soon as they can identify that this works on your system, they're gonna go full court press and really hit you hard. So we don't want that. That's why we talk about it early. All right, everyone, I am gonna be done for the week. I really appreciate you listening to the podcast, all of your support. Thank you for watching on YouTube. Like I said, my I'm gonna try to have the back of my little shelf back here be a little more lit. I swear I'm not in a cave. I'm on the second floor of my house. But because I'm lighting my face, I guess the rest of it looks dark. I don't know. I don't know a lot about lighting and stuff like that, but I have awesome people around me that are helping me pick out the right equipment, which will just take time. But let me know what you hope that we talk about next. Let me know who you want to see on YouTube. Go check out that website that Sardine created if you just want a summary of an episode. If there was an episode that you really enjoyed that you wanted to share with your team. It might be easier to find it on the web when you can search the transcripts for keywords. There's just a lot of good things happening with Fraudology, and it's because you guys listen and you support it.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
41:15
So I really appreciate that. All right. I'm gonna look forward to speaking with you more next week. And next week will be a guest episode. So I won't have to stare at myself while talking for forty five minutes. Thanks so much for watching and for listening. Bye.