The Saturday Fraud Strategist

What’s New in Merchant Fraud, with Dajana G.

Graphic: What's New in Merchant Fraud with Chen Zamir & Dajana Gajic-Fisic, featuring two smiling people.

I have been wanting to have this conversation for a while.

Dajana Gajic-Fisic has 26 years in merchant fraud. She started at Macy's in 2000, calling Visa and Mastercard in multiple languages to manually verify addresses at the point of sale. She has watched e-commerce fraud detection evolve from its earliest form through chip and pin migration, the explosion of online fraud, and now the AI era. She is currently VP of Fraud Strategy at The Wolfe Companies, working in the gift card space, which if you think has no fraud, you would be wrong.

What I liked most about this conversation is that Dajana is not someone who talks about merchant fraud from the sidelines. She fights it every day, including building out merchant fraud ring detection processes from scratch and figuring out how to detect merchant fraud attacks before they ever reach a payment page. That gives her a perspective on what is actually happening right now versus what the industry tends to talk about.

We covered a lot of ground. One thing I want to flag before you dive in. This is one of those conversations where we keep coming back to basics. Not because the threat landscape is simple. But because getting the basics right is actually how you handle whatever the threat landscape throws at you next. I thought that was worth saying up front.

What you’ll hear in this episode:

  • Why e-commerce fraud trends follow predictable patterns when the environment shifts, and what the chip and pin migration of 2015 tells us about AI today
  • How Dajana thinks about AI powered fraud attacks as a practitioner who is actively fighting them, not just theorizing about them
  • Why first party fraud and refund abuse in ecommerce may be the number one threat for merchants right now, not AI
  • How fraud as a service has made it possible to commit refund fraud without any technical knowledge, and what that means for merchant fraud teams
  • Why nearly fifty years of chargeback dispute rules regulation have not kept pace with the environment merchants are actually operating in
  • The cross-merchant fraud intelligence sharing story that could have prevented six months of losses at another merchant's business
  • Why end to end fraud monitoring is one of the most neglected basics in merchant fraud prevention strategies
  • Dajana's 360 approach to fraud operations, which separates the fraud process into four parts and maps how they feed each other
  • Why merchant fraud KPIs like chargeback rate alone tell an incomplete story and what to measure alongside them
  • How the lines between merchant fraud vs bank fraud are blurring at the identity and behavior layer

You should listen to this episode if you:

  • Work in e-commerce fraud detection and want a practitioner's view on what is actually changing versus what is being overhyped
  • Are dealing with first party fraud, friendly fraud chargebacks, or refund abuse and want to hear how someone with 26 years of merchant fraud experience thinks about it
  • Have felt frustrated that merchant fraud collaboration and intelligence sharing stops at your immediate network
  • Are building or restructuring your fraud team structure and want a framework that actually scales
  • Lead a merchant fraud team and are trying to figure out how to get upstream of the payment rather than catching fraud at checkout
  • Want to understand how merchant cyber security collaboration is evolving and what convergence actually looks like in practice on the merchant side
  • Are newer to the space and want a fraud fighter career development perspective from someone who grew up inside the industry
Episode notes & key takeaways

AI fraud isn't new, it's a faster version of an old problem

One of the things I loved most about this conversation is how Dajana refused to let AI be treated as some unprecedented threat. She took me back to 2015, the chip-and-PIN shift, and honestly, I’d completely forgotten how disruptive that moment was until she brought it up. Fraud moved from brick-and-mortar to e-commerce almost overnight, and most fraud teams didn’t see it coming because information just didn’t travel the way it does now. Her point, and I think it’s the right one, is that the discipline itself doesn’t change. Only the speed and sophistication of the tools attacking it do.

  • Machine learning has quietly been part of fraud tooling for over a decade. It’s not new, we just didn’t call it AI back then.
  • The 2015 chip-and-PIN liability shift pushed fraud from brick-and-mortar onto ecommerce almost overnight, a disruption comparable to what AI threatens now.
  • I keep coming back to her framing here. Focus on what fraud actually looks like, not on chasing whatever technology happens to be behind it.

Why automated attacks are easier to catch, not harder

This is the part of the conversation that genuinely surprised me. I went in assuming AI-driven fraud would be harder to detect, and Dajana pushed back hard on that. Her argument is that automation actually makes an attack more obvious once you know what you're looking for, which is really the foundation of good merchant fraud ring detection. The real danger isn't invisibility, it's speed, how much you can lose in the window before you catch it.

  • Bot-driven and automated attacks show up as clear anomalies in traffic, even if they're difficult to trace back to a specific actor.
  • I walked away thinking the real risk isn’t that these attacks are undetectable. It’s how much damage happens before detection.
  • Her advice, and it’s simple but it works, is to look for anomalies first, then dig into the pattern once something looks off.

First-party misuse is the threat getting the least attention

Dajana named this as her biggest pain point of the last twelve months, and I think she’s right that it doesn’t get nearly enough airtime compared to AI. She pointed to social media normalizing chargebacks and false refund claims as an easy way to get free products, and honestly, that trend concerns me more.

  • MRC's global fraud report ranks refund and policy abuse as a top threat across nearly every region and merchant size.
  • What struck me is her estimate that fewer than half of merchants are even fully measuring the impact of this, which means the real number is probably much worse than what gets reported.
  • "Fraud as a service" groups filing refund claims on behalf of everyday people for a cut. That’s a genuinely new wrinkle on an old problem.

the case for industry-wide intelligence sharing

Dajana told a story here, an address manipulation fraud ring that took her over two days to detect. One of the most sophisticated attacks she’s dealt with, and she only caught it because of ethical alerts. She was able to share the information and help others in a small informal WhatsApp group of merchant peers. Meanwhile, another merchant didn’t catch the same attack for six months due to the lack of information sharing.

  • The attackers slowly altered shipping addressed and identity details in small increments specifically to avoid looking suspicious.
  • Once detected, sharing the pattern informally with a handful of merchant peers stopped the attack across multiple sites almost immediately, proof of what real fraud collaboration for merchants can actually accomplish.
  • Without that kind of informal information sharing, the same attack pattern can sit undetected at other companies for months, invisible to their own merchant fraud visibility efforts.

Fraud, compliance, and cybersecurity are converging

Dajana’s role has expanded well beyond traditional fraud prevention into risk more broadly, compliance, AML, the works. And she made a case I found pretty compelling. Fraud today is about identity and behavior, not isolated transactions.

  • The same bad actors are often responsible for fraud, compliance risk, and cybersecurity incidents, making merchant cyber security collaboration a natural next step rather than a nice-to-have.
  • Fraud signals on the merchant side and the financial institution side are starting to look remarkably similar, both centered on identity and behavior patterns, which is exactly where merchant fraud vs bank fraud starts to blur.
  • Even something as simple as sharing a BIN number tied to suspicious activity can help another merchant or bank get ahead of an attack without touching anyone’s private data.

The 360 approach: Monitor, identify, mitigate

I really liked how Dajana broke down her framework here. She structures fraud operations around four connected functions: prevention, investigation, reporting, and strategic planning. But she was clear these are functions to fulfill, not necessarily new teams to build from scratch. Really a blueprint for fraud team cross-functional collaboration done right.

  • Existing teams and reports across the organization, customer service, finance, BI, can often be repurposed to serve fraud prevention needs rather than duplicating effort.
  • Monthly or quarterly cross-functional planning meetings with marketing, product, and customer service help fraud teams anticipate business changes before they look like anomalies.
  • End to end fraud monitoring, catching risk signals well upstream of the transaction itself, gives fraud teams more opportunities to stop an attacker before financial loss occurs. This is upstream fraud detection in practice, not just theory.

Why approval rate matters as much as chargeback rate

Dajana closed with a critique I want every fraud leader listening to sit with. A low chargeback rate means nothing if you’re achieving it by blocking too many good customers.

  • A 0.01% chargeback rate paired with a 50% approval rate is not a success story, it's a sign of overcorrection.
  • Approval rate, false positive rate, and chargeback rate need to be evaluated together, not as independent metrics. This is really the starting point for any real merchant fraud benchmarking effort.
  • I think this is why good fraud prevention often becomes invisible to leadership. It’s working, so nobody notices. This makes having clear metrics to show your impact even more important.
Final takeaway

If there’s one thing I hope sticks with you from this conversation, it’s that merchant fraud doesn’t get solved by chasing whatever threat is newest. It gets solved by getting your basics strong enough that the newest threat doesn’t rattle you.

Build real upstream fraud detection instead of waiting for an attacker to reach your payment page, take merchant fraud visibility seriously enough to actually measure first-party misuse instead of writing it off as a cost of doing business, and embrace fraud collaboration for merchants instead of treating every attack as a problem you are facing alone.

Dajana has spent 26 years learning this, including the corners of e-commerce and gift card fraud prevention that most people wrongly assume are low-risk. My honest hope for this episode is that it convinces at least one fraud leader listening to share information with a peer instead of sitting on it. That’s how we actually get ahead of this, instead of comparing war stories about it after the fact.

Not ready to stop the conversation about my, and hopefully your, favorite subject? Subscribe to The Saturday Fraud Strategist newsletter.

Connect with Dajana G. | LinkedIn
VP of Fraud Strategy, The Wolfe Companies
Founding Member, The House of Fraud
CEFI-Pacesetters 2019
2020 Merchant Team of the Year

Connect with Chen Zamir | LinkedIn
Host of The Saturday Fraud Strategist
Helping fintechs build smarter fraud defenses
Co-author of “The Fraud Fighter’s AI Playbook

Episode transcript
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
00:00
First party abuse is first party misuse, misuse, whatever we want to call it. Um, is definitely growing. I think that is in the last 12 months probably my biggest pain point. I remember it clearly because this was the only fraud attack that took me more than two days to detect. Because they were doing it so well, and we accidentally discovered it. If I start in a new role, if I start um some new project, there are two things I will always do. One is,
Chen Zamir
Chen Zamir
00:03
Hi everybody and welcome to another episode of The Saturday Fraud Strategist. With me today I have a special guest Dajana Gajic-Fisic. Wait, I need to do it properly. Dajana Gajic-Fisic. We just tried it a couple of times. Uh so second try. Not that bad. Not that bad. Uh Dajana, welcome to the show.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
00:54
Oh thank you so much for having me.
Chen Zamir
Chen Zamir
00:56
Uh my pleasure. Dajana, you've been, you know, for, a very active voice in the industry. And you've been to the space, especially on the merchant side, uh, for what, 20 years or so, uh, now. And yeah,
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
01:11
A little bit longer than that. 20, 25 years.
Chen Zamir
Chen Zamir
01:15
25 years. Okay. Wow. Uh, insane. Uh and still I'm guessing that some of my listeners uh may have not come across you. Because you've spent most of your career on the merchant side. So maybe you can tell us uh a bit more about yourself, your career.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
01:31
Absolutely. Well, um I'm trying to be very active on LinkedIn uh in the industry overall, but I don't think I'm as active as most of the people out there. So that could be a reason why some of the people did not run across uh my profile or some of my posts, some of my articles. But yes, I've been in an industry for probably 26 years almost. I think I started in 2000. Million years ago. And I always say I'm still 25. So let's just keep that in mind. But yes, I started in 2000 actually back at Macy's. I was working at Macy's credit granting department. Which wasn't really fraud team, but we were we were still reviewing credit applications of the people that were right there in the store at the POS. So there was some aspect of fraud in in my job. Um so there I started first working in a fraud team reviewing fraudulent applications, fraudulent online orders. I always like to joke and say that I was an ABS back 26 years ago. So we did not have these fancy systems that we have right now that addresses verified with the bank within a split second. But I was the person who was actually picking up the phone, calling Visa or Mastercard or American Express anywhere in the world and speaking several different languages trying to verify is your address one two three main street. So um now you can see how far along we came. But I always say that I kind of grew up with e-commerce industry and grew up with e-commerce uh fraud industry. And I just remember when we got first rulebased system I thought, this is the end of the world. This is so sophisticated and amazing. We have rules we can actually verify something quickly
Chen Zamir
Chen Zamir
03:15
And you're out of a job, right? Rule engines took your job.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
03:19
Yes. You know, that really is really funny anecdote. And I think we can use that one later in our conversation. But yes, um started very long time ago. And as the e-commerce industry and e-commerce fraud industry progressed, I think I grew progressed with it. And of course that gave me a very uh, I would want to say unique perspective in this industry. What the challenges are. What uh, what the things are we need to change. And how we need to change it. Um, during these 26 years I was also um, as working for financial institutions. I was working for uh Barclay's Bank, but Macy's was actually bank too. So, they had their own bank. So, I was um a little bit on the financial institution side, a little bit of on e-commerce side of Macy's as well. So, I think that gives you an unique perspective of how things look like, at the other side. Um you know, what challenges they have, how they work, how the process looks like. So, it helps you be a little bit more active on the on the merchant side. Um, I was also in transportation industry for a little bit. You would think there are no uh there is no fraud in transportation industry. But think about instead of stealing a package, stealing a whole truck. So it was really fun time, and I am back to e-commerce now. Um, I am working for a digital gift card company. Uh it's resell gift cards. It's pretty fun and interesting. No fraud at all. Uh there is no risk at all. Um, nothing to to do. But not not at all. But in the last 26 years, like I said, um worked at various different organizations, various different teams. My position was probably going from being in customer service and finance team, to being standalone teams. And that's another progression I have seen in these 26 years. How fraud as a career grew. I think 10 years ago, we didn't have fraud directors, e-commerce fraud directors. Banking, yes. We highly had managers. We usually had analysts that were sitting in customer service teams. Now we have directors, now we have vice presidents, now we have this whole standalone department. So I think I've seen a progression of the fraud industry and fraud fighting fighting world as well. Um, another aspect of my career is uh trainings, webinars, podcasts, um, speaking at the at the conferences. I really enjoyed this education. Advocating for the for the industry. Trying to be voice for the industry. You mentioned some people may not know me because I'm not as active as some other people on LinkedIn. The reason for that is I actually fight fraud. So I don't really have that much time to be active. Not as much as I would like to. Um, but then I know that that's how the entire industry is. So I'm trying to be that voice for our industry and trying to be an advocate for how things need to change on our end with all this technology changing with industry changing with e-commerce space changing overall I'm trying to make sure that fraud industry is part of that change in a positive way. So long long time in this space I have seen a lot. Um, there are some good things that came out of it. There are still some challenges that I think we need to work on, but overall it's been quite fun. 25, 6 years.
Chen Zamir
Chen Zamir
06:42
It's been a ride. Um, awesome, Dajana. Well, um, I'm sure you've seen your share of, um, of fraud. Uh, and also seen your share of fraud teams. Uh, super interesting. We'll dive into that in a minute. I I'll say, you know, uh, it's Friday morning right now. Uh, we're both in Europe. I'm I'm in Spain.You're now uh in in Greece, right?
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
07:06
I'm Greece. I'm on Kythira.
Chen Zamir
Chen Zamir
07:08
Yeah. Yeah. Uh, enjoying enjoying the sound. It's quite toasty out there. I've got my uh my my iced coffee. I saw that you are drinking coffee as well. Um so, while the the US guys uh folks are are still sleeping. Um, let's uh let's figure out what's new on the merchant side. Uh, you know, I I want to start by asking, a couple of weeks ago I had David Liu on the podcast. And me and David spoke about, a lot about AI. And AI powered fraud. And one of the things that David noted, and of course David is uh I I think you've seen a lot of the merchant side as well, but mainly more on the financial uh services side. One of the things that David mentioned was one that we're already seeing quite a lot of AI powered fraud. Especially on the deep fake side KYC, KYB and so on. Um and also, one very kind of like uh you know like main thread of our conversation was, how do we think fraudsters would be able to leverage AI, Agentic AI to commit fraud in the near future? And we kind of like shared a couple of, I don't want to say horror stories, but more kind of like uh concerning scenarios. And you know someone who's been in the space for so long. And someone who is an actual fraud fighter. Uh in a business that is known for some elevated fraud levels. How do you see the impact of AI on the fraud ecosystem? Uh, specifically like in in from your eyes, as a practitioner.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
09:03
Yeah. Um, I don't think that, I think you and I can both agree AI is not new in fraud industry. Not new for fraudsters, not new for fraud fighters. Um tools and abilities are not as sophisticated, uh, they were not as sophisticated 10 years ago. But AI at some, in some way existed 10 years ago, 5 years ago, even more. We all have and know of these machine learning, uh, tools. That are kind of AI tools. I mean that's what it is. And so I don't think it's anything new. And I think that the change in trend in fraud is nothing new. I want to bring up something that happened about 10 years ago, or maybe 11 years ago. Um, chip cards, chip and pin cards. That was, that wrecked havoc of e-commerce industry. The funny thing is because we didn't have fraud teams. Most of us didn't even know that this is happening. I did know because I had a pretty good team and pretty good partners. They're informed me time that this is happening. The shift is happening. And for those, uh, maybe younger listeners that don't know what that is. Is when the chip was inserted in a credit card. So now you did not have to have the actual, uh, authorization or actually you had to have authorization but you had to have an actual credit card present. You couldn't just type in the number you had to tap and get the PIN number. Um so that shifted fraud from the actual POS and brick and mortar, to internet. To to online space. and that's when we've seen so much creativity in a in a fraudster. And we seen the lack of creativity in a fraud team. So I just want to use that as an example of how the fraud world actually shifted drastically. And how the risk we were facing shifted drastically, because fraud rates went through the roof. Uh, it wasn't talked about as much. Internet was not used as as it is today. I don't know how many people were using LinkedIn and posting on LinkedIn as actively as they're posting right now. So, we didn't have much information of what's going on. So, when this went in place in October of 2015, I think. It was a nightmare.
Chen Zamir
Chen Zamir
11:15
Around that time, yeah.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
11:17
And imagine this is go, it was a nightmare. It's October of 2015 and we're looking into holiday season. We're looking into Black Friday, Cyber Monday season. And and fraud is going through the roof. Because fraudsters now moved from using um counterfeit cards into going online and using those gift card. Uh using those credit cards. And now we're seeing same thing in AI. I think it's a new thing. It's a new fad that everyone is using. And some people are overusing, to be honest. And I, do I think it's going to create some, um, challenges? Absolutely. But also, I think we have to be smart. And use this AI to our advantage. Um, in one of my posts, um, I wrote, maybe a year ago. I say the fraudsters are typically leading this innovation curve. And I think this is where we have to get smarter. There are some AI driven attacks. There are some tools that fraudsters can use that can hide their identities very well, and appear as a legitimate customers. Um, but also we have to be smarter. And use these tools to help us. And use these tools to get ahead of them. I I think traditionally we are always lagging. We're always catching up to what they're doing. So they commit fraud, we catch up with. Oh, we're going to do this to stop them. Then they commit fraud, we're going to do this to stop them. Why don't we anticipate what's going to happen? We have enough knowledge, enough experience. And start building our tools, our strategies and tactics around what could have possibly happened. So I think that's where AI will assist many very creative and very smart fraud fighters. To get ahead, maybe for first time, in a fraud history had these fraudsters.
Chen Zamir
Chen Zamir
12:56
That's super interesting. I mean first of all I must say that in my mind, this period of elevated kind of like e-commerce losses and the explosion of e-commerce. Uh, in my mind was always kind of like somehow, uh, related to the rise of, uh, mobile. And mobile shopping. Um, which happened more or less, um, in in the same period of time. And and when you told it, sorry I I was kind of like going back in my mind 10 years ago. And I said, yes, chip and pin. And and kind of like my, like fraudsters migrating from point of sale to ecom, was a thing. Which I completely blanked. And it shows how institutional knowledge, which you would assume is one of the greatest, uh um, advantages. That us fraud fighters, and fraud teams have, in the fight of fraud. Uh, or or fight against fraud. Um, it's not that simple. Because even for someone like me, who's been a fraud fighter for, fraud fighter for several years, when that happened. Even I completely blanked that. So that is interesting. The other point that you made is also very interesting. You were saying, look there will always be these kind of like new things that happen. Sometime it might be new technology. Sometime it might be new regulation. That will radically change how the space looks, how the threats, uh, look like. And that's not the end of the world. We we will probably manage it.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
14:34
It's not the end of the world. We just have to see this as a new challenge, and try to find a way around it. Try to find a way to stop it. I think this kind of open up, whole another topic. That you and I could probably spend another three hours, uh, on talking about. But it it's talking about position of your fraud team in your organization. And in this space, fraud teams traditionally were in silos. So I am sure that finance teams back in 2015, knew about chip and pin changes. I'm sure the brick-and-mortar teams knew. Because they had to change POS systems. But nobody communicated to fraud teams. Because fraud teams were typically in silo. And this is what I'm talking about, the progression of the fraud fighting industry. And our jobs as a careers. Is now we are more visible. Now we have, most of us, more equal seat at the table. Now we know of these things. We have resources, where we can read about what's happening. Visa changes, MasterCard changes, and all this new fun things. Um, so we can get ready. Back then we really didn't. Back then, I think I found out at mid September that this is coming in October. I'm like, oh well. What does that mean for me? But there is another aspect of at least the way I work. And this is back to AI. Yes it's going, we're going to probably see a lot more, um, AI powered attacks. We're going to see a lot more creativity of the fraudsters. But going back down to basics, is like, what are you trying to do? So let's stop thinking about how am I going to stop AI fraud attack? No, let's think about what am I trying to do? I'm trying to stop fraud. How fraud looks like. Well, this is how fraud looks like. It's not that I don't really care where it's coming from. Because if it's AI powered, it's probably going to be a lot faster, a lot more difficult to to detect and stop. But there has to be a a vector. There has to be some data that will indicate this anomaly. And help me detect it and stop it. So maybe first time it's going to take a day. Next time it's going to take two hours. Third time it's going to take 15 minutes. And fourth time I'm going to be ahead of it. But you know, let's let's talk about what is it that we are trying to do. We're trying to stop fraud. How fraud looks like. This is how it looks like. Well, let's stop it. It doesn't matter if it's third party fraud, first party fraud, or million other classifications and um names you have for it out there. It's like what are you trying to do? I'm not sure if you had a chance to read the book. It's called Working Backwards. Um,
Chen Zamir
Chen Zamir
17:09
Uh, I don't believe so.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
17:11
Um, it's it's pretty interesting book. I think he was one of the original, a uh Amazon AI executives, another Amazon executives. Um, and it talks about, my at least my understanding is like, where do you want to be? What is your end goal? And then you layer down to how can I reach my goal. Instead of I'm here and this is where I want to be. You start at the top. You start with the definition of your goal, and your mission, and then you layer. Create layers on how to reach this goal. So going back to fraud fighting, okay, AI is going to be very difficult. It is already very difficult to detect. It's really helping a lot of bad people out there. And some good people that are acting bad. But what do I want to do? I want to stop fraud. I don't want to stop AI fraud. I want to stop fraud period. And how can I do that? I'm getting a little bit more philosophical about it, but I hope it makes sense.
Chen Zamir
Chen Zamir
18:08
I love it. Because I find myself very often saying exactly the same. Um, it's about the basics. And and well, I okay. Let's not get too much, uh, deep into it. Other than saying that I I completely agree with you. Uh, and I completely agree with the approach. But tell me, um, does that mean that you're actually seeing AI powered fraud? Uh, right now, hitting your your, or at least attempting to hit your business. And does that, uh, that that, like do these attacks, look differently? Are they harder to detect? Um, or like, what is it that you're seeing? What's new?
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
18:54
To be honest with you, I don't think I've seen, I'm going to knock on wood. I don't think I've seen a major AI powered fraud attack yet. I do see fraudsters using AI, um, in some shape and form to commit fraud. So, I think it's not scale yet. At least I haven't seen it yet. But here is my fear. And maybe I'm going to help fraudsters right now. My fear is that if someone
Chen Zamir
Chen Zamir
19:25
Wait, wait, wait. Fraudsters, close your ears, please, and don't listen in the next minute. Okay. Yeah, you're good.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
19:32
I really think if someone figures out how to use AI. To execute, I'm not going to say this word, to execute a an attack. I don't think we'll be able to figure, to find it. To to truly fully use AI. The way that AI is being used right now, the the way AI capabilities right now for fraud attacks, it can still be detected with our regular traditional tools. Um, if you know how to look at it. And if you know what to look for. And I am not going to say what that is, because that's not what we want to deal with.
Chen Zamir
Chen Zamir
20:12
So it's interesting, because I think this is also kind of like, uh, was David's, uh, notion. That, I can see how AI can be used to create undetectable fraud. By the way, I think that us as fraud fighters, because we know the limits and the gaps in our systems, we can always think about what kind of fraud attacks would bypass it. With AI or without AI, as you said. AI might help fraudsters scale it. Um, but I think it is easier said than done. And you need to have, like a lot of intimate, uh, privileged knowledge, uh, to actually execute it. But what I found interesting, and I want to hear more about. Is that you said, I don't see AI powered fraud but I see fraudsters using AI. What does that mean? How do you see them using AI today?
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
21:03
I think there is a lot of, um, uh, creating accounts, creating different emails. Uh, using some type of automation to place the orders. So you can see the speed of the orders, and so on. And I don't think that's anything new. Because using some of these AI tools to create profiles, identities, um, and so on. Has been happening for quite some time. I just think right now is, as the as the AI is more accessible to fraud fighters and everyone else in the organization. That's how it's more accessible to the good people, that think they can use AI to commit fraud, gain financial benefits, without being detected. So I think it's just being much more adopted by the fraudsters, and fraudsters wannabe. So I'm going to call them that way. Um, and and and that's what I see. I see some of the AI tools being used to, uh, create identities. And and and maybe use the automation, place orders. I don't see really, so much more AI powered attack. And and maybe it's going to happen with some of these, um, agents. Like um commerce agents. Maybe it's going to happen more soon, but not yet.
Chen Zamir
Chen Zamir
22:17
You're not seeing it yet. Yeah, that's interesting. Because I always uh hold the belief, and and it may sound funny at first. That it is actually easier to detect fraud, when the attack is automated. Uh, regardless if you automate it with a script or with AI. Now, what makes it scary, is that because it's automated, and because the speed and the scale are quite high, every minute that passes and you didn't identify it, and you didn't stop it, you bleeding a lot of money. But the fraud attack itself, once you look at it, it it's obvious fraud. It's obvious fraud.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
22:59
Absolutely. Um, I don't know if you know that I was in a uh athletic footwear industry. That is extremely risky. And there is a lot of bot used for, by the resellers. And that's one thing I always said. Bot users probably are not committing fraud. They are buying limited, um, quantity shoes. So they can resell them for the high price. But it's a it's a possibility out there, that if someone intends to use that. It's going to buy a lot of shoes really fast. And by the time I react, it's going to be gone. So that is 100% sure, correct. And that's my biggest concern. It's not about what they are using it for, but what could they possibly use it for. But you are 100% right on the other side too. Is that's a lot easier to detect. Because that's how you should be detecting fraud. You, maybe we're giving a little bit too much information right now, but you should look for anomalies. Um, you should look for anomalies. And I always say. When you want to know what's going on in your traffic, in in your space, you look for anomalies. If you want to know exactly how it's being done, you look for patterns. So that's like, kind of working backwards. If you want to know if something is happening, is there an attack? Is there attack of any type? Is there something going on? Is there any issue with the system, with the process? You look for the anomalies in your traffic. But when you want to know what actually is going on, then you dig deeper and look for the patterns between those data points, between orders, between identities. So yes, these type of attacks would be a lot easier to discover. Because they are an anomaly. They are not something that is showing up, as a clear normal traffic. But the speed at which it's happening is what's causing and creating a risk.
Chen Zamir
Chen Zamir
24:58
Um, yeah. Uh, that is that is such a,
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
25:01
I can see the wheels turning there.
Chen Zamir
Chen Zamir
25:05
Yeah, because it is such an interesting phenomena. Because you, like you have this perception of what AI fraud actually means, and why it is dangerous. But actually when you, kind of like peel the surface a bit, you understand that it is not dangerous because it is undetectable. It is dangerous because it hits you fast. And so, the way to kind of like, uh uh um, defend against it, is not with black magic and technology. And somehow piercing the identity behind the agent. And so, no. It's just reacting faster. And to react faster you just need to like, have good basics, as you, as you said
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
25:44
And I would say increasing visibility. So your visibility is not anymore at the checkout. Your visibility needs to be everywhere. You need to monitor end to end traffic, end to end uh customer journey. And you need to identify all those risk gaps on that journey. You need to attempt to close those risk gaps. And you need to identify your key risk indicators. What are your indicators? And I think this is not giving away too much information. Because each business has different risk indicator. So what's risk to me, may not be risk to the travel industry, may not be risk to the athletic footwear industry, or or um sneakers. Um, so identify your key risk indicators. And then create alerts around those key indicators.
Chen Zamir
Chen Zamir
26:26
Yeah.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
26:27
And you can do that using AI right now 24/7.
Chen Zamir
Chen Zamir
26:31
Yeah. Basics. Like if we would have, uh uh, had this conversation 20 years ago, we would probably still have the same conversation. Uh, which is, which is kind of like, what what's mind boggling about this space. Yeah.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
26:47
Well, it did take me about 20 years to learn this. So I probably wouldn't know this 20 years. So. But but, that's I think, that comes with an experiences. I think a lot of fraud professionals, fraud fighters right now, are very focused on, um, operations. And they're very focused on the, each order and analysis analytics of the data. And, um, an analytics of the fraud attack trying to understand what happened. Instead of stepping out. And if you want to grow in your career, you have to step out of that. And see what did you learn from the past attack? What did you learn from the data, and how can you implement that on much larger scale? And as a big picture to prevent fraud from happening. Not, I think way too many fraud fighters are very operationally focused. Instead of being strategically focused. So, I think especially with AI. AI gives us such great opportunity to be more of a strategist, rather than operational. Um, so I think that's really great opportunity for fraud fighters.
Chen Zamir
Chen Zamir
27:48
100%. I Wow, that that is such a such a great advice. [Ad Break (27:53): Hey folks, I want to take a quick break to speak about today's sponsor, me. If you're finding this useful, do me a small favor, like and subscribe. It really helps with the algorithm. And if you're not already on my newsletter, The Saturday Fraud Strategist, you should definitely check it out. Every Saturday, I break down fraud trends, real cases, and strategies from my own experience of building and operating fraud prevention systems. Whether you're new to the space or a seasoned practitioner, I'm sure you'll find it interesting. Check the link in the description. Takes two seconds. You'll thank yourself next Saturday. Now, back to the video.]
Chen Zamir
Chen Zamir
28:26
For merchants today, I would say ever since COVID, uh more or less uh, first party fraud. Uh friendly fraud, policy abusers, whatever you want to call it. Is one of the main threats. Uh, or I would say one of the main loss drivers that endanger merchants. And I'm wondering if you've seen any changes around, uh around this kind of like, uh specific threat. Uh, regardless, or or maybe, you know, uh, with regard to to AI.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
29:04
Um, yes absolutely. I I think you're 100% correct that recent fraud, first party abuse is first party misuse, misuse, whatever we want to call it. Um, is definitely growing. I think that is in the last 12 months probably my biggest pain point. Um, and I think it's biggest pain point in the industry. Because if you look at some of these conversations on the social media, it there is a lot of conversation about, um, people filing dispute when it isn't fraud. People just calling bank. You can actually go to Instagram or Tik Tok, whatever you use, I don't use Tik Tok, I don't even have it. Uh, but, and I've seen a lot of these posts saying, if you don't like the service, just call the bank file a chargeback. And and these influencers are advising you to take the step of filing a chargeback if you don't like someone, the way someone did your nails. And I think normalizing this process as a way to get your money back, instead of communicating with the merchant, and and, um, going through the process, is actually really dangerous trend right now. And there are no rules and regulations. There is no accountability on anyone else's side other than merchants. And that is currently probably my biggest pain point. That this is becoming widespread use of the process intended to protect the consumer. And it's now turning against, not just merchants, but against banks as well. Uh, because people were just using this process of of the fraud, um, of the dispute, to get their money back. When it's really not fraud. So that's one aspect of it. The other one, um, we did see during COVID. Refund and DNRs, did not receive, INRs whatever. Someone calls them, uh, people claiming they didn't get the package in various different ways. Claiming they bought two, but they received only one. They send it, they didn't get the refund. So we have seen the increase in this trend of, again, filing a false claim. In this case, the claim was not filed with the bank. It was filed within the customer service teams, or within the organization company, um, but it's causing the same type of loss. And I think between those two, I'm not sure which one is more dangerous right now. Um, I would say maybe these internal claims, the refund abuse, uh, is a little bit more dangerous. Only because it's not really tracked appropriately by all of the organizations. So the full scale of impact and losses is not really measurable at this point. If you look at the last MRC global report, I think they have, I'm actually looking at it right now. They have refund policy and abuse number two, fraud trends in the United States. Realtime payments is number one. And first party misuse number three. Asia Pacific has refund and policy abuse number one. Latin America number one. Um, small business is also number one. And enterprise is also number one. Refund and, um, policy abuse. That tells you a lot. And I am still claiming that probably less than 50% of the merchants are truly measuring the impact of these, of this type and fraud. So can you imagine how high and how prevalent this would be if everyone measured it appropriately? It's still written off as a cost of doing business. So, um, I think we do have, we still have a big pandemic of a fraud issue here. I just don't think it's handled appropriately. And I personally think that industry is little little bit lost around how to define these fraud trends truly, what it is. I don't think we can still agree on what first party misuse is. I think one merchant thinks is this, other merchant thinks is that. People are obviously throwing several different definitions out there. So I think as an industry, we need to get a little bit more organized around these fraud trends. Maybe advocate more with issuing banks, with regulators on on getting this type of fraud under control.
Chen Zamir
Chen Zamir
33:05
Yeah, I I would say that on the financial services side, I think it's even worse. In the sense that I think nobody's really monitoring or or reporting it. Right? Um, and I think on the merchant side, it's really, I don't want to say confusion. Because maybe that's, like a very clear business decision, but it's it's a question of how do you balance customer experience with risk. Uh, and that that is always the case with fraud management. But specifically with first party fraud, it's um I am not 100% certain that when leadership teams make policy decisions they understand what is the cost of business that are, that that is basically tied to these decisions. Uh, for sure. Um, I wonder though, if the change that you that you've seen in the last 12 months is that, do you think it has somehow something to do with AI? Or is that, you know, is that a a shift, or I don't know, like a a search that, you know, is driven by other factors?
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
34:14
I think it's driven by this social accept acceptance of this behavior. Like like I mentioned, social media sharing these, uh, options as your first and only option. Instead of communicating with the merchants, resolving whatever problem you have. So I think that's maybe normalizing this behavior. And there is this funny thing I always say. If you have an enterprise level company that you claim chargeback against. And you claim 10 of them, and 20 people claim 10, um, chargebacks. Or file 10 chargebacks. You think, oh it's not going to hurt the CEO of that company. He doesn't care. It's going to hurt the the entry level agent. It's going to hurt the managers. So when that business is not doing well, you're not hurting business overall. You are hurting actually your peers, who are working there. Because when there are layoffs, when they are uh elimination of of staff. It's usually starting at the entry level agents at the low level managers, or mid mid managers. So you are impacting your friends, you are impacting your family and your colleagues. So you are not really creating a huge damage and loss to the company. Because they will usually say, oh they don't care. They can take this. This is nothing to them. It is nothing to them in a large in, on a large scale. But when the decisions are made because of the business being impacted, it's going to be impacting your neighbor, your friend, your family. So I think that's something they don't think about. Um, but in what I also see is that, I don't think the rules and regulations are changing fast enough for the environment we have. We talk about AI. AI is changing things so fast on various different fronts. We still have rules and regulations around disputes from 1978 that never changed. So the Reg E Reg Z changed maybe once or twice in in the last 40 years. There was a proposed change around the electronic payments disputes. Um, I want to say 2006. That was never adopted, never fully went into place. It could have been 2016. I'm not 100% sure. I had the data somewhere. But I want to say that we need to change rules and regulations to fit the environment we're in right now. Yes, we want as a consumer, I want to be protected by the bank. If there is a chargeback, if there is a fraud on my account. I want to be able to file the chargeback. But creating these mobile apps where you can just click twice. Allowing people to file 30 different chargebacks on 12 months worth of orders, without checking, without investigating. I know again that there are rules and regulations. That say you have to continue with the process. You have to file it. But let's do the investigation a little bit. And let's see what in this process, or in this regulation can change. That we not only protect the consumer, but that there is some type of accountability for us as an industry. Of of making sure that, you know, this protection does not have to mean lack of accountability. So I I think those two things can go hand in hand instead of being like an opposing forces here. So, um, and and the accountability have to be on all has to be on all of us. To me as a merchant, I feel there is so much more accountability on us. Than on anyone else out there. Maybe finance world feels feels the same. Maybe banking feels exactly the same. Um, but what I do want to say is, I feel sometimes I'm fighting, um, card networks. I'm fighting payment processors. I'm fighting, uh, issuing banks. I'm fighting everyone else, on a daily basis. And trying to appease everyone else, on daily basis. More than I'm fighting fraud. Because there are so many requirements and accountabilities on a merchant. And there is not, there is a lot less elsewhere. So maybe a little bit controversial, um, opinion here. But that's how I feel. Especially with all these changes that are happening lately.
Chen Zamir
Chen Zamir
38:18
I agree. It's like each each kind of like player in the on the chain is trying to push the ball to someone else's court. So they know, don't have to to deal with it. I mean the VAMP and VFMP, and all of these things. I mean it's exactly that. Um, but yeah, it's like it's interesting because we keep speaking about AI. We keep speaking about AI, as the threat that we fraud fighters need to address, and think about, and prepare for. While maybe, at least on the merchant side. Um, and by the way, side note. Maybe also on the financial services side, if they actually track it correctly. Maybe the the, um, the the the number one threat is still for years now, um, policy abusers and first party fraud. And you know, we we used to kind of like say, when when you wanted to learn how to commit fraud, you used to have, you know, this store uh access point. And you need to go on the dark web, and you need to be like very techy and so on. And today, no. You just need to go on Tik Tok. Uh, to learn how to do fraud, and how to make money. And yeah, I think, I mean someone like David Maimon speaks about it all the time. And I wonder if this is not the number one threat that we actually, uh uh, stand against. Again, especially on the merchant side. And this gets talked about much less.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
39:56
And you know what? You don't even have to go on Tik Tok. You can just go on Telegram and have someone else commit it for you. Because there there are these fraud as a service groups now. That you bought a computer, and you want a refund and keep the computer. You contact so and so somewhere on the other side of the world.
Chen Zamir
Chen Zamir
40:14
Yeah. Yeah.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
40:14
And they just file this claim for you. Because they have the clear instructions. They have step-by-step process on how to call the company, when to call, how to talk to to them, what to say, when to say it, if you need to do it second time, how fast you need to call back. There's there are like a clear instruction manuals for these people how to commit this type of fraud. And you don't even have to commit it. So, you feel good about yourself. Hey, I got the computer. I got $800 back. The fraud as a service kept $200. And we're all doing great. Except the merchant. And then what happens? Merchants overreact sometimes. They're creating all these strict policies. They're creating, um, fees or fees for returning like re return fees. They're creating all these steps that will end up impacting a good user. So either way, merchant is the one that gets the the the biggest impact with some of these, uh, fraud attacks. I think we opened a can of worms here. So I think we should move on.
Chen Zamir
Chen Zamir
41:23
Uh, I one of the things that you, that you told me, uh, in our previous conversation. Which really surprised me, was how in your current role as head of fraud, um, you actually transitioned more and more into a kind of like head of risk, uh, position. Where considerations like compliance, like AML, suddenly are relevant. And again, you're you're a merchant. Uh, and that took me by surprise. Because yeah, like, I I can see how in certain, uh, in certain environments, especially marketplaces maybe, there are like a bit more compliance issues maybe. Like in in high-risk verticals, you need like age verification and stuff like that. But I heard like, what I heard from you is that you looking at it on a much larger scale. And much more similarly to, um, how a fintech would, uh, look at these topics. And I I I'm curious to hear more about that.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
42:32
Well, that's probably my own curiosity. Because I like to keep an eye on everything. We do have a full compliance team that handles the full, uh, side of compliance work. Um, they do report to me right now. Uh, and that is more like a practical things of um trying to optimize the performance of their processes and their strategies. So, um, but as a fraud fighter, I think you have to be, uh, aware of what other risks are you facing. And and what other fraud can fraudster commit on your side. That it may not be payment fraud, it may not be credit card fraud. So sometimes you will observe. And I actually had this opportunity, I had this situation in my previous positions, too. Where I would see someone doing something that doesn't look fraudulent at all. But they're doing something that indicates it's off. Something is just not right. And I think a lot of fraud fighters can relate to this, like that bullet nagging gut feeling that tells you something is just not right. So I think, um, you have to follow that gut feeling. And start to digging and start investigating. And and this is where you go into more of a, when when is the risk to your company. So money laundering is, of course, serious issue. And especially in the gift card industry. It's heavily regulated industry. So we have to keep an eye on everything. But these, typically your fraudsters will be the same ones that are committing these type of fraud. So I think that's where the overlap is. And that's where we can actually share our intelligence. Share the data finding and analysis. Which then brought to this natural collaboration between two teams. And I think lines are not just getting blurred between compliance teams and fraud teams. I think lines are getting blurred between, um, cyber security and fraud teams as well. So I think naturally cyber security, information security, cyber security teams, fraud teams, compliance team, naturally that's one progression where we should be all one team. Because we're looking at the same things, at the same people, doing the same damage to our company, Which is financial risk, and that financial risk can grow seriously into some other risks as well. And that's why I think there is this natural kind of, uh, progression into collaboration of these. Another thing I noticed, and I'm going to talk a little bit. Maybe this is a good thing to say about, um, financial industry lines are getting blurred between fraud we are seeing as merchants and fraud financial institutions are seeing right now. It's about identity.
Chen Zamir
Chen Zamir
45:10
Say more.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
45:11
Yes. It's it's now fraud is more on the identity and behavior rather than the actual transaction. So I think, don't get me wrong, there is still transactional fraud. It's still happening. But with AI tools, fraud is getting more sophisticated. It is more about behavior. And behavior on the financial institution sides and behavior on the merchant side are kind of looking exactly the same. So this is something that led me to advocate more for let's collaborate more. Not just internally between all these wonderful departments. We have cyber security, and and fraud and compliance. But on the more larger scale with financial institutions as well. Because we are seeing same actors that are causing the same damage to all of us. Which is a financial loss and reputational loss too. So I I think lines are getting blurred here. And we need to recognize that and start thinking how we can take that to our advantage.
Chen Zamir
Chen Zamir
46:11
Can you give an example. And and this can be also a hypothetical example based on your experience. On like how that would look like. And how how such an anomaly, an attack, um, an occurrence in your system. How that would look like from the different teams perspective. Um, because basically, um, like I would guess that a fraud fighter that is listening right now would say, okay that's a good idea. But like how, what should I actually look for? And why why does that matter? Dajana Gajic-Fisic(46:47): So here is a very basic and simple example. You see a spike in traffic. And spike in traffic comes from three different BIN numbers and you look at the BIN numbers and they all belong to the same issuing bank. Wouldn't it be natural next step to go ahead and call this bank? Or send some information to this bank and say, "Hey, I have x amount of orders." It could be even like a card testing attack. Could be on the cyber security side, which sees it first. It could be anywhere in your process. Um, and then you communicate this to them. Maybe to them, that's really not important. Because it's so small compared to the number of credit cards they had. But maybe it's beginning of something that can grow. Because I'm 100% sure that if I see a BIN attack on my site, I am not the only merchant that sees that BIN attack. So instead of having an opportunity, having a tool, way, protocol, whatever you want to call it. To share this data, to share this intelligence with the industry and get ahead of this. What are we waiting for to happen in order to take next step? We're waiting for a chargeback. Because we're just assuming. We don't know. We didn't have any losses, because we stopped it. Fine, but we didn't have losses. That doesn't mean that someone else will not have losses So I understand the competitiveness. But I think when it comes to fraud we should collaborate a lot more. And sharing the data and intelligence. And there is a serious concern about PII. What we can and cannot share. I think there is a way to share intelligence, without sharing like private information of the individuals, to get ahead of these fraud attacks. And and there is one example. BIN number without any other data, can be shared with the bank or with another merchant. And say hey I'm seeing this. Do you see it? Um, I'm going to give you actually concrete example. And this happened oh maybe five six years ago. I remember it clearly. Because this was the only fraud attack that took me more than two days to detect. Because they were doing it so well. And, um, we accidentally discovered it. We discovered it because of ethical alerts. I'm going to be completely honest with you. Because the fraud attack was so well, uh, organized, coordinated, executed. That I was like bravo. It was really interesting. Um, so I remember getting orders, and I remember addresses changing. But addresses changed just slightly. I, you probably heard of this. Those, I think they called them address manipulators. I think that's how we call them later on. They were adding dashes, dots, changing the spelling of the address, um, of the actual street name. But they did it slowly. There was no huge amount of orders. They were doing it slowly for days. And then they would slowly increase. But what they did, they changed the address slightly. Then they would change zip codes, then they would change name, they would change email. But it was done so at a slower pace. That it kind of looked good. Good, uh, as a good, um, traffic. So we received I think one alert. And we have a process what happens when you receive one alert. Actually when you receive second alert, to me two is a coincidence. Three is a pattern. So I started digging right away. Doesn't matter how big your data, uh, is. So we started digging and then we found this there are some similarities. We took steps. We contacted our, um, fraud vendor. And they said immediately what we see. They actually recognized it. So we took steps and stopped it. I have a WhatsApp fraud group that I shared this with them. I have at least three other merchants that found it right away on their end. And it was like, "Oh my gosh, we just saw it." And of course, they stopped it. 6 months later, uh, we were at the conference. I run into the person who is not part of our WhatsApp group. And she's talking about fraud rates being seven, eight, 10%. And I ask her, "What happened? How did you see this?” This attacker was active on their page. So this was what September, October. Maybe September that we discovered it. So until March, this attacker was active on their site. And they didn't, they couldn't find how. And it increased their fraud rate to almost 10%. What if they were part of this group? What if we had a tool to share this information? They could have stopped it too. And this was not the only merchant that had the high fraud rate from the same type of attack. I think there were some, uh, webinars out there later on in podcast. And there were so many posts later on. Uh, I think they called them address manipulators or something like that. Um, because that was kind of one vector we found. Stopped them. But what if we had a way of share this information in more formal way, and help each other? We didn't. So something I knew in September, someone else didn't discover until they met me at the conference in March. So I think that's unfortunate. So maybe a as a industry we should get organized a lot more around how we can share this data. And I know I'm going to get like million fraud vendors right now and say “hey but we have it.” Yes, you do. You have it for your network. If someone is not in your network, they would not have visibility, and you can't expect everyone.
Chen Zamir
Chen Zamir
52:24
Yeah it's the same. It’s not the same as sharing data. It's not like, okay this email is associated to fraud. But really this is the pattern. This is exactly, kind of like, the attack, uh uh uh uh, pattern, that, um, or the the MO that the fraudster is using. This is what you need to look for. Yeah. Dajana Gajic-Fisic(52:44): Uh, have you ever been on Telegram in one of those fraud groups? Have you ever looked through them?
Chen Zamir
Chen Zamir
52:50
No. I I I always uh worried about doing that. With uh you know with with numbers that I own. And I never went through the trouble of, you know, like uh trying to do it through a burner.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
53:03
I think on a Telegram you can actually hide your number and your name. That's why fraudsters are using Telegram much more. I'm not sure how it is right now to be honest with you. I haven't used it in a while. But if you go there, and if you go to any other like um site, they share this data. They share the intelligence. They share everything. Because if you get attacked by one fraudster and it’s successful, you're going to get attacked by like another five. Because it's successful. So they share this information. Why don't we? I know they're not as regulated as we are. But I think we can find a way of creating more collaborative environment. And share intelligence in a more safe way, without sharing private individuals data. And and help each other. But I I've been preaching this for quite some time, and I am seriously getting nowhere.
Chen Zamir
Chen Zamir
53:53
Yeah, you're not the only one. Um Dajana, tell me. Um, you we we've spoken quite a lot about the changes that you've seen in the past 12 months or so. And the different drivers that that kind of like fuel these changes. I wonder from now, wearing kind of like the the fraud fighting hat and the practitioner hat. Um, if you can give some advice or maybe share some of the things that you've done internally. Changes that you've implemented to, uh, better, better not not only prepare. But, basically better perform, in in these times.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
54:35
There are two things that I always do. And especially when I, if I start in a new role, if I start um some new project. There are two things I will always do. One is the method or approach that I created probably, maybe more than 10 years ago. Which is kind of a result of all this experience that I have, and knowledge and working in different organization work. Having different challenges, uh, by being in different teams. Uh, it's my 360 approach. I am not a creative person. I'm a number person. I'm a fraud fighter. So I couldn't come up with any better name. Maybe I should ask ChatGPT. But it's like a, um, I call it 360 approach. Where I think that fraud operations are separated into four parts: prevention, investigation, reporting and uh strategic planning. And they are not separate. It's kind of a circular motion. You have prevention. Whatever you use in prevention, you share with investigation. Whatever investigation comes up with and finds, reporting can get organized, report on to send it to strategy and strategy can use this information for your next fraud prevention. And then it goes like this. So it's like: monitor, identify, mitigate. So I always start with that approach. But what's interesting about that approach is these are four part, four parts of the fraud process or risk management process, whatever you want to call it. But it's not four teams. It can be hundreds of teams in your organization. It can be your vendor’s part of this approach.
Chen Zamir
Chen Zamir
56:10
It could be one person.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
56:12
It could be one person. It really that's, what actually helps you scale down your teams and handle much more with a lot less resources. And that's what I learned really fast. Because as you know, fraud never have never has enough resources. Um, but you do have to identify who is a part of your fraud prevention process. It's your fraud team. It's your fraud vendor. It it could be your finance team. It can be your customer service team. Your customer service is your front end. They are the first ones talking to the customer and talking to the fraudster. So collect the information from your customer service team, to have better and more impact impacting fraud prevention. Who is your fraud investigation? You don't have to reinvent the wheel here. You don't have to create a whole new process. Look for the processes that already exist, uh, that kind of complete this fraud investigation part. Which was typically in the old times finance team that handle chargeback responses. Then reporting teams. Every organization has reporting teams, or or BI teams, or data teams, whatever you want to whatever they call them. So instead of trying to create reports that may help you do this or that, look what already exists. So instead of wasting time of creating report on some of your order, uh, volume, maybe that report already exists. I'm 100% sure it actually already exists. So we use repurpose existing reports. Resisting an, uh, existing analysis to what it you need. And then once you repurpose what already exists, then try to create something that is already missing. Instead of like jumping into I need a fraud report. Well maybe data already exists somewhere that's not really reporting fraud, but it's indicating fraud. So go ahead and repurpose this. It's saving you resources, is making it faster, and it's including everyone else in the organization. And then strategic planning is, um to me, you pull the important individuals from your organization. Into this monthly, once a quarter, strategic planning meetings. So, but it's not just you. It's your marketing team. It's your customer service team, your finance team, your e-commerce operations team. You pull in everyone. And if they don't want to share with you what they do, which they should, then you share with them what you're doing. So they are aware of what's going on. And what you're going to do. So you can fight fraud better. And if they have any new new initiatives, any new promo codes, any new marketing um ideas, you know about them. So when this marketing idea is launched, it doesn't look like anomaly on your fraud prevention uh side. But it looks like a normal traffic that you expected. So you can adjust to it. So I think it's kind of a very difficult to set it up. But it works well once you set it up. And it's not really have a, it's not really that difficult. It's just maybe time consuming to set it up in the beginning. And that's my first thing. I'm sorry it's a little bit lengthy. My other thing, I'll try to be fast, is end to end monitoring. Fraudsters will usually show its face really really early in a process. By the time it gets to your payment, if it's a fraudster who is attacking your payment place, like using fraudulent credit card. You already missed at least four places in that process where you could have stopped them. So it's very important to look at the end of that end to end life cycle of that transaction and life cycle of your entire traffic. And identify risk gaps where you could have identified that fraudster. And try to move your fraud processes as high upstream as possible. Because then you have at least two, three, four more stops or or gaps where you could stop them. Instead of waiting for them to come to the payment page, and then take the action. I mean, there are so many more benefits to this, uh, than just stopping fraudster. But also you'll learn how your traffic looks like. And then you learn how to spot these anomalies a lot faster. Because you know if you have 100 orders in an hour, and suddenly you have 250 orders an hour something is off. So before this person even gets to your payment and you use your fraud vendor to detect fraud there, you could probably detect them and stop them. So, end to end visibility to monitor, how do I say, monitor identify mitigate.
Chen Zamir
Chen Zamir
60:24
Yes, that's what I've written down. MIM. MIM.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
60:29
I didn't think of that. I need to give it a better name. I'm so not creative. I swear I should not be ever in charge of putting name to
Chen Zamir
Chen Zamir
60:39
Hey, fraud fighters are quote people. That's fine. Um, that is awesome. I mean what I like about it is that, you know, when you ask such a question ,it's very easy to be tempted to answer, um, you know with this new innovative, uh, approach or tool or policy or SOP. And I like how you, like, how you present it in such simple terms. It's just doing the basics right. It's just doing the basics right. And if you do the basics right, it doesn't matter what new technology comes in. Or what new threats, uh, come in. You have the capabilities to manage that. That that's why they are called basics. Um,
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
61:28
Correct.
Chen Zamir
Chen Zamir
61:28
So yeah, I I love it. I love it. Uh, and and I I must say that it like, it resonates with me so much. Because these are, again, like really the topics that I talk about as well. So I'm I'm I'm glad to see that we are in the same line here.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
61:44
Well, you are a fraud fighter. So you understand what those basics are. And you understand those pain points. And I think we are up against much more than just fraudsters in this space. And having those basics done right is not just going to help you fight this good fight. It's also help is going to help you showcase how impactful you are to the organization. And how beneficial you are to the organization. So, um, I know that a lot of fraud teams, I hope it's not the case right now but I know it used to be. Every time you ask them about their success, they will tell you what their chargeback rate is. It doesn't mean anything to me. Your chargeback rate can be 0.01. If your approval rate is 50% you're not doing a good job. So I think that as a teams we also have to understand, what is what are the KPIs? What are the metrics that showcase our successes? That showcase our importance in our performance for that organization. And to me, again. That's approval rate, that's um friction, false positive, insult rate, whatever you want to call it. And then risk rate, your judgment rate. And they have to, they have to be observed in a relationship to one another, not just as an independent method.
Chen Zamir
Chen Zamir
63:06
Yeah, I think it came up with my, uh, it came up on my conversation with uh Gilit Saporta. Where I think, she she said it, that the the biggest. How did she put it? Like that the irony is, that the better you are as a fraud fighter, the more invisible your results become.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
63:28
Fraud is never a problem until it becomes a problem.
Chen Zamir
Chen Zamir
63:31
Exactly. Exactly. You're either invisible or, um, you know in line to be hanged. Uh yeah. Um fact. Awesome. Dajana that was super super interesting. Uh, I want to kind of like go back and summarize a few takeaways that I noted down throughout the conversation. Uh, that I think are worth, uh, coming back to. Um so one, we said it repeatedly throughout the conversation. Going back to basics, uh, we'll detail that, uh, in a second. But I think the the main takeaway, um, from this conversation at, least in my eyes, is that going back to basics is not about making sure that you know the the the foundational floor is ready to build all the innovation that you need to, I don't know, like deal with. For example AI AI powered fraud. Going back to basics, and getting the basics right, is how you stop AI fraud. Is how you stop new threats that emerge and, uh, attack your business. So going back to basics is 100% of what a team needs to do. Um, it's not the first thing that you need to do. Um, you also mentioned part of that, and and I take it like the way that you mention it, I take it as, um, maybe one of the points that, uh, that you see, um, neglected, uh, more often. Uh, and I think again it echoes back, uh in in your in your recommendations as well, is visibility, That, um, going back to basics means understanding what your key risk indicators are. And these are probably different between businesses. And that tracking them, monitoring them is how you start. That's the monitor, the the the first stage of the circle of fraud. Um, that's how you start with, uh, the basics. I think one other thing that you, um, that you mentioned, um, I think by the way that that also came up in my conversation with, uh, with Gilit. Is that, um, another part of the basics, which again is often neglected, is collaboration. And I think you you you mentioned collaboration throughout our conversation, in two two types of of of echelons. I would say the first one is internally, uh, within the team. And maybe collaborate, or get closer to compliance teams, to AML teams, but also to cyber security teams. Uh, that by the way, also like very similar, uh um uh, examples were also given when I talked about it with, uh with, Cy Khormaee when we talked about should cyber security teams and fraud teams get closer to one another. Um, so this is one echelon. But there's another echelon, and that is externally. And this can be either the, you know, like banks or other partners. That uh, or or might be not even partners, right, might be that you don't really have an official relationship with. But you see a specific bank coming up in a in a fraud attack. So getting in touch with them might might do you some good. But at the same time, and I think this is even more important, peers. Peers that are, you know, that have the same role, wearing the same hat, in other other kind of like, similar businesses. Be it merchants, be the same, even vertical, uh, but not necessarily. And just exchanging what you see. Um, can sometimes, maybe, prevent a 10% fraud rate for 6 months. Uh so yeah. That can, uh, save your job. Uh, if you, if you collaborate, uh, pro, and I think, by the way, and I think this is also why you're such a prominent voice. I think there's a lot of collaboration that needs to happen here. And a lot of networking that needs to happen here. And networking doesn't have to be done on LinkedIn. It doesn't need to be done through posting on LinkedIn. Networking can happen in a lot of different manners. I think you embody that. Um, and this is such a crucial aspect of the role. That I think, uh, let's say, more newer fraud leaders tend to miss. Tend to really focus on my SOPs, my data, my tooling. And forget that, you know, a a a a real success lever for you can just be your network. Um, we also. Yeah, and this is where we went into like, really like what are the basics. And what are the things that you probably want to get right. So, you talked about your, I I dubbed it circle of fraud. I don't know if you have like a name for it, but that's that's the name,
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
68:58
360. I I call it.
Chen Zamir
Chen Zamir
68:59
The 360 approach.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
69:03
360. I'll I'll get GPT to give me a better name. Yeah.
Chen Zamir
Chen Zamir
69:06
Yeah. Yeah. It needs like some AI dropped in there somewhere, uh, for the hype. But yeah, monitor, identify, mitigate. I love it. It really reminds me of my own concept of, uh, the reaction cycle. Which is pretty much the same thing. Uh yours, I must say, is much more to the point. Um, and um, I think what I liked about your approach is also the fact that, um, it is not necessarily or where you want to start at. It is not necessarily, okay these are the things that I need, let's build them. But actually finding out and mapping what already exists in the, uh, in the organization. Maybe, by the way, it exists like it probably exists somewhere else. Maybe in finance, maybe in compliance, maybe in marketing, maybe in product, uh, that you can utilize. And I liked it. Because not only that it, you know, it saves time and it saves effort and it makes you, uh, you know, not a needy, uh, resource train on the on the organization. But also that if you're using tools, especially by the way when it comes to reports and monitoring dashboards, and so on. If you're using these tools that, uh, serve other teams, you increase the likelihood that others, other other teams would be open to it. That would they would look at it as as well. In like the fraud, uh uh, mindset and so on.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
70:36
You also create relationships and increase visibility. Because fraud is our job, but it's not only our responsibility. It is a responsibility of the entire company, of the entire organization. To know how to prevent this fraud. And bringing these teams in increases that visibility, and gives them that knowledge of their role. The role they play, and in in this fight
Chen Zamir
Chen Zamir
71:04
And and that relates directly to the other thing that you mentioned, uh, in that regard. Which is you called it the, or that's what I wrote on, the strategic, the monthly strategic cross functional planning meetings. Where you bring all the relevant, uh uh uh, parties. And I think especially, you know, marketing. You mentioned that product, probably, as well. And you basically align in advance, so you're not surprised by any kind of initiatives that would hit your, uh, hit your side of the of the team as well. Um, that that is like 100% agreed and endorsed, uh, from my side as well. Lastly, uh, you mentioned end to-end monitoring of the user agent. Um, which I also love. It came up in my conversation with Matt Vega when we talked about how do you want to to do fraud prevention in real time. And one of the things that we talked about was that you don't want to do that in real time. You want to do that well in advance. Of, you know, arriving to the transaction, or the monetization event. Um, so that is definitely something I I agree with. Uh, and I love hearing from you as well. Um, Dajana, that was, wow, we covered so much. Uh, I'm glad that we managed to talk about AI, but also not really talk about AI. Uh, that was a breath of fresh air. Yeah. Uh, definitely. Um, thank you very much. That was like super awesome.
Black and white portrait of a woman with blonde hair, glasses, and a blazer, arms crossed.
Dajana Gajic-Fisic
72:34
Well, thank you so much. It was really enjoyable talking to you. And I hope that we shared some of the information, uh, information to your listeners that they can practically implement and use in their jobs. I hope it was helpful.
Chen Zamir
Chen Zamir
72:48
Ah, I'm sure it was. I'm sure it was. I have no doubt. Um Dajana, thank you very much. It was a blast. And for all of you listeners at home, I see you next Saturday.