Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
Fraudology

AIが可能にする不正:ガードレールより成長が優先されるとき

39 min

Fraudologyへようこそ。

AIはすでに私たちの身近にあり、既知のあらゆる不正行為を、より低コストかつ迅速に実行でき、しかも発見しにくいものにしています。今回は、AIを悪用した不正が今まさにどのような形で現れているのかを具体的に示す、いくつかの事例をご紹介します。大規模なカードテスティングから、非常に複雑な不正事件まで取り上げます。

その事例がPolymarketです。ここではかなり時間を割いて詳しく取り上げます。企業で実際に起きた不正の詳細が、ここまで明らかになることはめったにありません。ウォール・ストリート・ジャーナルの調査報道では、数千件の新規アカウントに紐づいた盗難デビットカードや、不正入金率が80%に達した実態が明らかにされています。さらに、AIで生成されたディープフェイクを使った配達注文、銀行連合が新たに発したエージェント型コマースにおける不正への警告、AI音声クローン詐欺への注意喚起についても掘り下げます。

不正を根絶することはできませんし、今後も決してできないでしょう。しかし、情報が不正を働く者たちと同じ速さ、あるいはわずかに先んじて届くようにすることはできます。

このエピソードでお届けする内容:

  • 少なくともある不正対策ベンダーによると、AIを活用したBINアタックによる不正やカードテスティングが75%以上増加している理由と、不正行為者が正規の決済チームと同じ手法で決済承認を最適化するようになっている実態
  • Polymarketの不正スキャンダルを徹底解説。ビジネスモデルに内在する予測市場の不正リスクや、事態を悪化させた経営陣の意思決定も取り上げます
  • Polymarketが支払いを迅速化するために同一入金元への出金ルールを撤廃した理由と、その決定が実際のマネーロンダリング防止対策の不備を招いた経緯
  • 盗まれた他人の社会保障番号(SSN)を使って新規アカウントを作成すると、パスワードなしでその人の既存残高や紐付け済みカードを引き継げてしまう、深刻なアカウント乗っ取り詐欺の脆弱性
  • コンプライアンス部門が不正対策プログラムの人員を配置する際、事後対応を担う調査担当者だけでなく、実際に不正防止の経験を持つ人材が必要な理由
  • 不正率が80%に達していることに対し、CEOが「成長を続けて罰金を払えばいい」と発言したとされる状況で、「何が何でも成長」という姿勢がもたらす不正リスクがどのように顕在化するのか
  • 銀行連合が新たに発表したエージェント型コマース詐欺に関する報告書と、現行のVisaおよびMastercardの規則では、AIショッピングエージェントに起因するチャージバックの責任について、いまだ実効性のある枠組みが存在しない理由
  • ウォルマートでの窃盗未遂に使われたAI生成の偽の配達注文書と、ジョージア州の警察署長による警告
  • 実際のチャージバック監視プログラムが内部でどのように運用されているのか、そしてPolymarketがRiskifiedのような不正対策ベンダーを導入したことが、この問題の深刻化をいかに物語っているのか

次のような方は、ぜひこのエピソードをお聴きください:

  • 決済、不正カード利用、小売業における不正防止に携わっており、AIが既知の攻撃をどのように大規模化しているのかを現実に即して理解したい方
  • チャージバック監視プログラムを構築または評価しており、不正率が急増した際に何が起こるのかを示す、実際に公表されている事例を知りたい方
  • 予測市場における不正リスクに関心がある、またはPolymarketのような企業をめぐる規制・法的問題の余波を注視している
  • 不正対策プログラムのコンプライアンス人員配置を担当し、調査の専門知識と同じくらい予防の専門知識も重要である理由を説明する表現を求めている
  • エージェント型コマースにおける不正を追跡しており、いまだ解決されていないAIショッピングエージェントのチャージバック責任の空白について理解したい
  • 自社の不正対策チームに共有できる、AIが生成した偽の配送注文やAIを悪用したフィッシング詐欺の実践的な実例を知りたい
エピソードノート

AIを悪用したカード不正は、より高速で巧妙なカードテストから始まる

以前のカードテスティングは、誰かがカード番号を1件ずつ手作業で入力するものでした。今では、スプレッドシートをアップロードしてスクリプトを実行するだけになっており、ある不正対策ベンダーがカードテスティングは75%以上増加したと報告している大きな要因となっています。詐欺犯はもはや、どのカードが有効かを確認するだけではありません。正規の決済チームと同じように決済承認の最適化を行い、BINデータや取引の詳細を分析することで、自らの承認率を高め、その後の購入をより正当なものに見せかけています。

Polymarket詐欺スキャンダルの内幕

ウォール・ストリート・ジャーナルの調査報道により、現在IPOを控える予測市場プラットフォーム「Polymarket」で、事態がいかに深刻化していたかが明らかになった。詐欺グループは盗んだデビットカードを数千件の新規アカウントに紐づけ、少なくとも1,000万ドルを盗もうとしていた。決済代行業者が処理する全取引のうち、不正な入金が一時80%に達したという。報道によると、懸念を訴えた従業員に対し、経営陣は成長を続け、規制当局に発覚したら罰金を払えばよいと伝えていたとされる。成長至上主義がもたらす不正リスクが、ここまで明確に記録されるのは珍しい。

同一入金元への出金ルールが、見た目以上に重要な理由

この話に登場する不正対策の基本原則の中でも特に有用なのが、ほとんどの人がその名称を直接耳にしたことのないルールです。出金先を入金元と同じ決済手段に限定することは、シンプルかつ効果的なマネーロンダリング防止策です。Polymarketは顧客への出金を迅速化するためにこのルールを撤廃しましたが、案の定、それに伴って不正発生率も上昇しました。

すべてのリスク管理チームが警戒すべきアカウント乗っ取り詐欺の手口

その年の後半、Polymarketのユーザーは別の種類のアカウント乗っ取り詐欺の被害に遭いました。第三者が、社会保障番号を含む他人の盗まれた個人情報を使って新しいアカウントを作成すると、パスワードやユーザー名なしで、その人物の既存アカウントに加え、紐付けられた銀行口座やカードにも即座にアクセスできてしまうというものでした。これは詐欺というよりエンジニアリング上の問題であり、詐欺対策の不備とセキュリティ上の不備は、異なる呼び方をされているだけで、実際には同じ問題であることが少なくありません。

エージェント型コマースにおけるチャージバックの空白はいまだ埋まっていない

複数の銀行で構成される連合体が最近、エージェント型コマースにおける不正に関する報告書を公表し、AIショッピングエージェントがカード情報を直接入力したり、決済保護の弱い手段へ利用者を誘導したりすることへの現実的な懸念を指摘しました。それでも、より差し迫った問題は、AIショッピングエージェントによるチャージバックの責任の所在だと私は考えています。AIエージェントが誤った処理をした場合や、顧客が意図していない購入を行った場合でも、現行のVisaまたはMastercardの規則には、加盟店ではなくAIプラットフォームに責任を負わせる枠組みがありません。

AIが生成した偽の配達注文や音声クローン詐欺は、すでに現実のものとなっています

ジョージア州では、AIで生成した偽の配達注文を使い、架空の受け取り依頼に対応するSparkの配達員を装って、Walmartから電子機器を持ち出そうとした人物が逮捕されました。同じ警察署長は、この問題のさらに身近な形として、家族の声を本物と信じ込ませるほど巧妙に再現し、緊急事態を装って金銭を要求するAI音声クローン詐欺や、すでに信頼されているブランドになりすます、より一般的なAIフィッシング詐欺についても警告しています。

重要なポイント
  • AIを活用したBIN攻撃による不正行為やカードテスティングは、従来の手作業によるボトルネックを解消する自動化の進展により、一部の加盟店で75%以上増加しています。
  • Polymarketの不正スキャンダルは、経営陣が不正対策よりもスピードを優先した場合、「何が何でも成長」を追求することによる不正リスクが実際にどのような形で現れるのかを示しています。
  • 支払いを迅速化するために、入金元と同一の口座への出金を義務付けるルールを撤廃すれば、たとえ他の管理策が維持されていても、マネーロンダリング防止策を直接損なうことになります。
  • アカウント乗っ取り詐欺では、既存のログイン認証情報だけでなく、新規アカウント作成フローも悪用される可能性があります。
  • コンプライアンス部門の人員配置に関する不正対策プログラムには、事後的な取り締まりの経験を持つ調査担当者だけでなく、真の不正防止に関する専門知識を持つ人材が必要です。
  • エージェント型コマースにおける不正は現実に存在し、深刻化している懸念事項ですが、AIショッピングエージェントに関するチャージバック責任については、現行のカードネットワーク規則では未解決のままです。
  • AIが生成した偽の配達注文や、AIによる音声クローン詐欺は、仮想的な話ではなく、すでに実際に記録された犯罪で利用されています。
  • 強固なチャージバック監視体制を構築し、適切な不正対策ベンダーを導入すれば、不正率を業界標準の水準まで戻すことができます。ただし、そのためにはまず経営陣がこの問題を深刻に受け止める必要があります。
最後に押さえておきたいポイント

今回のエピソードで取り上げたすべての話に共通する点があるとすれば、AIを悪用したカード詐欺は、危険なものになるために新たな手口を必要としないということです。AIは従来の手口を、より速く、より安く、そして大規模に実行しやすくするだけです。詐欺グループが盗んだ何千枚ものカードを数秒で試すケースであれ、企業が安全対策より成長を優先するケースであれ、詐欺師が声を複製して家族の緊急事態を装うケースであれ、職務の分離、入金元と同一の口座への出金ルール、実務に精通したコンプライアンスの専門家といった、私たちがこれまで頼りにしてきた基本原則は、今や重要性を失うどころか、これまで以上に重要になっています。

エピソードの参考資料とリンク

つながる:Karisse Hendrick | LinkedIn
Fraudologyポッドキャストのホスト
受賞歴のあるサイバー詐欺対策の専門家
Eコマース不正防止コンサルタント
スタートアップアドバイザー、基調講演者、
フォーチュン500企業向けコンサルタント

Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:07
Welcome back to the Fraudology podcast. I'm Karisse Hendrik and I am happy that you're here. Uh today we're going to go through some news articles of the week and they all have a common theme and that is that AI is here. I know I'm not really telling you anything new. Uh AI is creeping into all areas of our lives it seems, but not surprisingly bad actors are using it to commit more fraud. Uh you know, we always say that our job as fraud fighters isn't to eliminate all fraud. While that would be nice, we know that that just isn't realistic. Uh but it is to make it harder and slower for them to do, right? And more expensive. That's always our goal. Make it more difficult for them to attack our site or our bank rather than, you know, someone else's. And unfortunately, it's one of those situations where, you know, you don't have to be as fast as the bear. You just have to be as fast or faster than the last person running from the bear. And the fraudster's goal is always to make things cheaper and faster for themselves. And AI does that to an extreme. It really uh provides a lot of ease. And there's so many different platforms out there that make it easier for them as well. They're not only using the ones that we're familiar with. Uh they have some of their own AI models as well as using tools that are meant for enterprise and all kinds of things. So today the news articles will be centered around different AI attacks. Certainly won't be an exhaustive list. I've been talking with merchants a lot in the last few weeks, especially preparing for the Merchant Fraud Alliance, which once this episode comes out, we will only be about five days away from. Which I if anyone knows me and outside of just the podcast, you know that this has consumed me for several months. And I'm really excited for it to be here. I've kind of been joking that it's going to be like my second wedding because I'll know so many people there and want to talk to everyone. But I feel a little selfish about that. But the cool thing is is that everyone else gets to meet each other, which isn't always the case. So, um we have a lot of great senior leaders coming from uh very large organizations in e-commerce uh and marketplaces that I'm very humbled that they're making the trek to Chicago. Um some of them live there, but a lot of them don't. And the reason I brought up MFA is because I've been talking to so many uh merchants getting ready for it. Uh whether that's to prepare for uh speaking uh presentations, panels, people asking questions about you know the conference.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
02:48
As well as I just recently had my merchant collaboration call that we do monthly. Uh it used to be just tailored to retailers and we opened it up to all kinds of merchants. So we have some in travel, we have some in event ticketing, we have some merchants in marketplaces like digital goods marketplaces, not just uh those that ship physical goods. And there's been a lot of talk about AI attacks. There's also been a lot of talk about using AI to fight fraud, which we're doing a whole 4 hour boot camp uh the day before MFA for merchants on that topic. You know, using generative AI to do a lot of things within fraud operations. Sometimes it's identifying fraud, other times it's evaluating the performance of your analysts. Or creating a dashboard with alerts uh for various metrics. Some merchants are using it to tailor their uh chargeback response documentation and seeing some good results. There's just a lot of different ways that merchants are using AI and I know that banks are as well. But today's episode's going to be focused mostly on AI attacks. One statistic that I came across this week uh regarding AI fraud attacks is that card testing um with e-commerce merchants is now up over 75% according to at least one merchant of fraud provider. And that's because it you don't have to do it manually anymore. You know, card testing used the long time ago when I started in fraud, it was just, you know, one person or a group of people plugging in card numbers and testing them one at a time. Well, now they can just upload a spreadsheet of card numbers and, you know, card holder name, address, etc., and find a website to attack or target and just run them up. And we see that a lot. Um, and we're seeing that a lot more because it's faster and cheaper for them to do it. They're also identifying more patterns than even we can sometimes when we're looking at payment acceptance. And that's more on the payment side, but I spent some of my life on the payment side, so I'm familiar with that. You know, a lot of uh payments people spend a lot of time and money on trying to optimize payment authorization. Well, fraudsters are doing the same thing.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:13
Looking at bin numbers, looking at, you know, various different pieces and data of the transaction to determine how they can increase their authorizations on your website. So, they're not just looking to find cards that are valid to then sell or use for higher dollar transactions. They're also gaining all of this data rich information by running these transactions. So, um I think we're going to start to see some merchants being hit with fines for those card testing. Because, uh from the view of the network, it is up to the merchants to prevent card testing. So, I think everyone listening knows, you know, what card testing looks like, but it's generally low dollar transactions with just a high volume of transactions all at once. Usually, especially using AI, they can be seconds or milliseconds apart from each other. And what they're doing is they're using your site as a feedback loop. They're determining from what you say if the transaction goes through or if it's canceled at the time of payment. That tells them if the card is valid or not. Once they know a card is valid, they can get more money for it or if they sell it or they can then look more legitimate at the next merchant that they place an order with. Because they won't see a whole bunch of declines as well. That is one of the markers of card testing is, you know, just as many declines as there are authorizations. So, that was just one piece of information that I ran across on LinkedIn this week about just one method of AI attacks. I know in speaking with online merchants and I know banks are seeing the same thing. They're also seeing AI enabled account takeovers AI enabled fishing to their customers to get the credentials to then take over an account. It is being used in full force and uh that's what I want to talk about today. Uh with one exception. So there's one article that isn't so much about AI specifically. However, we rarely get a glimpse into when merchants are having fraud issues.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:26
Uh, and we recently saw an article, and I talked about it, I think in our last fraud news episode, actually last month. Where Hims and Hers, the company that provides GLP1 and other health supplements for men and women, obviously, um, online. How they're in the, um, Visa chargeback monitoring program and how rare that is. Well, now we're getting to see a glimpse into this other merchant that is getting hit with fraud really heavily. And it's an interesting type of fraud because it's it's more than card testing. They're actually cashing out on that same website. So, typically, uh, when an e-commerce fraud happens, they're making a purchase on one website and cashing out on another or cashing out in person. Maybe they order an iPad, right? It gets shipped to their address or to an address near them. They pick it up, then they go sell it. That's how they cash out. That's how they get the cash for that, you know, stolen card transaction. In other cases, they'll, you know, book a hotel or entertainment tickets for a show or a sporting event and then they'll do that on one website and then on the other website they'll, you know, sell it in the secondhand market. But in this case, that the buying and the cashing out is happening on the same site. And the CEO doesn't seem to care. And I know a lot of fraud fighters might have a little PTSD when I read this article because we've all faced this. It, to some degree. I don't think we faced it to this degree. Not all of us have faced it to this degree, but it's a fairly new merchant and that's Poly Market. Poly Market has had a lot of scrutiny itself because it's essentially gambling on real world events. You know, whether a TV host on live TV is going to say a certain word or whether a politician is going to make a statement about something specific. I know there's a lot of investigations being had into, you know, politicians and basically insider trading. But they're not calling it insider trading because it's not.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
09:48
While it probably should be, it's not regulated um by the SEC as much as it should be. So, I don't know. I' I've listened to a couple podcasts about Poly Market, but that's about the extent of it. I've never used it, but you know, it's a betting website on real world events is just the shortest way I can explain it. The title of this in the Wall Street Journal is that Poly Market's rush to grow left a door wide open for fraudsters. CEO Shayne Coplan brushed off concerns about schemes involving stolen debit cards. Now, the prediction market is bolstering executive ranks as it eyes IPO. So, they want to go public, but yet they have a lot of fraud and that could be an issue. So, this article was published on September 19th. And it says, "In February, a company processing debit card transactions for Poly Market's US betting platform delivered some alarming news. Fraudsters were flooding the app." That's not too uncommon for us to hear, but you know, it is for a new company, especially if they didn't already know that they could have fraud. They probably weren't expecting it or ready for it. Because a lot of startups aren't. Users were linking stolen debit cards to Poly Market US accounts, then trying to use them to make wagers and withdraw the money that they won from those wagers into clean cards or accounts that they controlled. Thieves tried to make off with at least $10 million. At one point, the processor rejected as fraudulent more than 80% of the deposits it was handling. A rate that far exceeded industry standards of roughly 1%. Poly Market employees quickly raised their concerns with chief executive Shayne Coplan, according to people familiar with the events. The compliance team, those people recalled, was floored by Coplan's response. Just keep growing and pay a fine if regulators ever find out. Current and former employees said Coplan's reaction, which hasn't previously been reported, was characteristic of his plan for Poly Market growth at all costs. Poly Market is doing everything in its power to woo new users and investors. And in the process, said current and former employees and investors interviewed by the Wall Street Journal. The high-flying company has struggled with compliance failures, legal challenges, and software blenders. Rates of fraud remained elevated for months after the February Attack. People familiar with the matter said, though they didn't again reach 80%. In the wake of the incident, executives left and an internal investigation began. No one in compliance wants to have their name on that. That's a big reason why they probably left. Uh former regulators from the CFTC, Justice Department and Internal Revenue Service, said the level of attempted fraud and Poly Market's response was atypical for the commodities and gambling industries. Unlike traditional commodities exchanges, Poly Market accepts funds directly from retail traders, making it more vulnerable to fraud attacks. So they accept funds directly from consumers, basically. In a regulated space, this kind of thing does not happen, said former CFTC enforcement lawyer Joe Konizeski.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
13:12
Something like that. You have adults who handle customer funds and make sure they're sourced appropriately and handled appropriately. A Poly Market spokesperson said that the company is committed to maintaining accurate, fair, and transparent markets and working with regulators and law enforcement. Our market integrity framework includes processes to detect, review, and respond to suspicious activity, the spokesperson said. Poly Market's legal challenges are mounting on several fronts. The Commodity Futures Trading Commission uh so the CFTC is investigating it. The employees have been told to retain records related to the fraud attack and other topics according to people familiar with the matter. And the New York City Council is probing the advertising processes practices of Poly Market and other prediction markets. And Poly Market has been accused in lawsuits of deceptive business practices by almost two dozen traders. At the same time, more than a dozen state lawsuits are focusing on whether Poly Market and its prediction market competitors such as Kelshi and Coinbase are unlicensed gambling platforms. The outcome of those cases could reshape the industry. As legal risks pile up, Coplan is in the process of raising a billion dollars in a fundraising round that would value the company at around $21 billion. Donald Trump Jr.'s investment fund 1789 Capital is investing roughly 300 million in the round in addition to the roughly 200 million it has previously invested. So particular fund will have invested half a billion dollars into Poly Market. Poly Market which has a data partnership with Dow Jones the publisher of the Wall Street Journal has been working to reposition itself to investors and the general public as a more mature company focused on responsible growth. Since May, it has added experience risk management staffers including a former FBI agent. The company has improved its compliance protocols and improved product testing according to a person familiar with operations. I would say that while it's great to, this is me talking not the article. While it's great to hire, you know, former law enforcement for fraud after the fact. For investigations to, you know, identify who's behind the fraud and then work with prosecutors to prosecute fraud. My experience is that the majority of people with law enforcement experience don't have any experience in the prevention side of fraud. They haven't worked with fraud tools to prevent fraud. They don't know the strategy there, or how the systems work, or you know what how to build a successful risk stack. That's just not their area of expertise. They are phenomenal at investigations work after the fact after the fraud has happened. But if that's the only person they've hired for risk management, that would concern me a little bit. Uh, in late June, Coplan visited the Hampton's home of 1789 capital co-founder Omeed Malik to strategize about how to professionalize Poly Market's operations before a potential initial public offering or IPO in the next year. According to people familiar with the meeting, Malik advised Coplan to hire more experienced executives. Poly Market recently hired its first chief financial officer, Warren Jeff Jensen, who was Amazon's CFO in the early 2000s. Following a journal investigation into a deceptive social media campaign, Poly Market restructured its marketing team, including hiring the founder of electric scooter company Bird as chief of growth. Other marketing employees involved in the social media campaign have left the company or had their roles shrink. Poly Market is rapidly growing and getting better every day. A spokesman for the company says, "We are proud of our key leadership hires and continuous infrastructure upgrades and have quickly scaled and remains focused on growing responsibly at the frontier of finance, tech, and culture. But they do say that like the CEO has a reputation for being unfiltered and intense. He's bullied employees. He's uh apparently he likes to use adderall and that's very widely known. He's pushed people to the brink.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
17:39
That type of thing. And he said some bad words on Twitter that I don't want to repeat. They do say here's the part that I was referencing earlier. As one part of its protection against money laundering attacks, Poly Market US employed a rule commonly used by financial exchanges. Funds deposited from one payment source were required to be withdrawn to that same payment source. Without such a rule, a thief could deposit money using stolen debit cards, trade with it, and then withdraw winnings to a clean card. That's exactly what they were doing in February. Federal regulations don't require prediction markets to follow that rule. Other brokerage and betting apps, including DraftKings and FanDuel, do so. Poly Market's chief competitor Kalshi doesn't, though the company inspects funds withdrawn to different payment mechanisms and freezes suspicious payments. A person familiar with that company's protocols said. I can actually say that I'm familiar with who Kalshi uses for some of their fraud prevention and I think it's it's one of the top leaders in the space. So that might be why they feel more comfortable doing that but they I'm sure they scrutinize those more. I'm not familiar if Poly Market uses a third party fraud tool or if they're just using internal engineering rules or what they're doing. By January of this year, Poly Market's US app was handling only a fraction of the volume of its mammoth international exchange. So, it has an international exchange, but they um have taken that part off and moved it into the US. Copeland wanted any potential friction for users gone even though the app was still in beta testing and had launched to only a limited number of users. Near the top of the list, make sure users got their money quickly. By February, a Discord chat for Poly Market users had filled with complaints about how long it took to withdraw funds. Employees reassured users that their money was in transit, but that compliance checks could hold it up for days or weeks. Engineering glitches on the US app added to the pain. So, in addition to having a lot of fraud in February, they also had issues with people withdrawing getting their their winnings back or their the money that they still had back. Uh, in February, the swindlers attacked Poly Market, linking stolen debit cards to thousands of new accounts. The payment processor, Checkout.com, told Poly Market. So, uh, now we know who their processor is, and they alerted Poly Market of that. Most of the attempted deposits failed, said one person familiar with the matter who attributed the majority of the attack to seven users. One of whom attempted about 4,000 deposits. That tells me that their fraud stack is not very mature if they're allowing that many deposits to be made by one person. That could have changed since February, but that's what this tells me now, or at least at the time. Checkout.com, which continues to work with Poly Market, declined to comment on the incident or its relationship with Poly Market. Yeah, they probably sent an NDA. The attack overwhelmed the compliance staff backing up withdrawals further. Which is why it took so long for money to get back. Uh to get money back to customers faster, company leadership decided to scrap the rule requiring same source withdrawals. Even though some employees warned that it could open the door to money laundering. According to people familiar with the discussions, executives maintained that the other protocols in place were sufficient. Failure to adequately police money laundering could violate federal laws about money laundering, illicit transmission, and possibly bank fraud. Uh former federal prosecutors said the CFTC and the Justice Department have prosecuted firms including crypto exchanges like BitMEX and Binance for violating such laws. And some fines have extended into the hundreds and millions of dollars. Poly Market is subject to less stringent anti-money laundering regulations however. Their US chief compliance officer resigned in April after sending a lengthy report with an overview of some of the fraud issues to company executives. According to people familiar with the report, both Clifford and Poly Market declined to comment about his departure. Around that time, Poly Market closed a billion dollar investment round that valued the company at nearly 15 billion. And now they want another billion to value their company at 21 billion. Uh soon after Poly Market fired the US division CEO Justin Hertzberg and its head of US regulation and ant money laundering left. Hertzberg didn't respond to requests for comment and an investigation by the law firm Sullivan and Cromwell concluded the company had complied with regulations according to people familiar with the findings. Well, there's barely any regulations for them to comply with. So that doesn't necessarily mean that they're doing everything right. By May, Poly Market had brought fraud rates back into the industry norm. A person familiar with the matter said in part by limiting the number of debit cards that users could link to their accounts. The company also retained a new anti-fraud contractor, Riskified.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
22:59
Hm, that's interesting. That's a lot of pressure on Riskified for very fast high dollar transactions. Poly Market also has been trying to fix other problems stemming from the minimal testing it had done before rolling out new features. There's been platform issues and other things. Several people have been uh complaining that they can't get their money back. Poly Market has reimbursed some customers who suffered losses while others have worked with their banks to reverse unauthorized charges via chargebacks. Uh said a person familiar with the matter. Recently, it has improved its code review practices and hired more engineers. Copelan has pushed employees to create provocative new markets. For instance, how many times does Kanye West say a pretty bad, you know, word on his Twitter this week? Or, you know, other things. So, those are like some more provocative things you can bet on. Uh, letting users create their own markets could introduce new opportunities for market manipulation, said Rajiv Seth, a Barnard College economics professor who has studied prediction markets. Compliments pushed to make Poly Market a household name led to expensive deals with A-list celebrities. Oh, I guess in late July nearly 500 Poly Market users were victims of another fraud attack that appeared to exploit an engineering flaw. Uh, if a malicious actor attempted to create a new account using an existing trader's personal information, such as a stolen social security number, the hacker would immediately gain access to the trader's existing Poly Market account. Oh my gosh. And any of their linked bank accounts and debit cards without needing to know a password or a username. That deserves a face palm. Um, according to a person familiar with the matter who said the amount of money stolen was small. Um, that's crazy, but that yeah, it doesn't surprise me too much. Then they talked about the World Cup and how it's that. Anyway, it's a very long article. I apologize for reading as much of it as I did, but I think it's fascinating. It's always fascinating to me when the name of a company's payment processor and or risk provider is public.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
25:20
Made public in an investigative article such as this as well as just the fact that they have fraud and what the fraud attack was, right? What, which typography is impacting them the most. That's very uncommon for, you know, a few decades for the last two and a half decades that I've been in this industry. It's been very rare. So, I applaud the Wall Street Journal for doing this work because I think it's important. It's another way to hold companies accountable and especially new companies in tech that either don't understand the credit card and debit card liability laws or they just don't care and want to focus only on growth. This is what can happen. It's I hope that the new people in risk management that they've hired are getting a seat at the table. And getting to, you know, call out engineering mistakes such as the one I just mentioned or, you know, other things like that. I do think that having a rule that the card you use to fund the bet needs to be the same method of payment that gets the earnings of the bet back on it. I think that's a really good one for fraud. But Riskifi's going to have their work cut out for them because this is a pretty fraud business model. It just is. It's super risky. And what if somebody regrets their bet, right? What if someone bets $500 that, you know, a sports star is going to wear purple shoes at the next game. And they don't wear purple shoes, so they lost the $500. Who's to say they can't issue a chargeback on that? Uh for not as described or whatever else they want to do. Uh I think that they probably have significant chargeback issues for a lot of things, not just fraud, like I said, service and uh buyer's remorse as well. And they might have to learn a few more hard lessons if they're, you know, founder or lead executive isn't willing to put some guard rails in. And we know that guardrails don't have to apply to everyone. They can just reply to the riskiest transactions. That's, you know, the beauty of fighting fraud in 2026. It doesn't have to be with a blunt instrument anymore. It can be with surgical precision. So, I hope that they figure that out. I didn't mean to spend so much time on Poly Market, but I did really find it interesting, and I think those of you on the merchant side especially will, too. So, speaking about AI attacks, there's a couple of articles I wanted to share that are specific to AI attacking e-commerce or banks and just how it's being used for that. This next article is by AOL. Well, no, actually it was by Reuters. I'm sorry. I found it on AOL, but it was originally by Reuters. The title is banks warn that AI shopping bots or agent commerce will raise scam, fraud, and data privacy risks. I would agree with that on the surface, but let's read the article to see how you feel. So, uh, they're basing this article in Paris. Using AI agents for online shopping could increase the risk of scams, fraud, and data privacy breaches. Banks including Nat West and Bank of America said on Tuesday. As they set out principles for developing the technology. Technology companies including OpenAI, Anthropic, Google, and Meta are increasingly promoting AI chatbots as shopping tools. Envisioning a future in which shoppers use agents to select products and make purchases on their behalf. Retailers, meanwhile, are racing to influence chat bots recommendations.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
29:11
So, they want the chat bots to recommend the products on their website, not their competitor's website. British retailer John Lewis said in September that searches originating from AI agents had risen to 2.5% from just .3% a year earlier. Just three basis points. With the trend accelerating, I guess it's 30 basis points. Uh still it's not a lot. So just in one year for it to go up 8x more than 8x, that's pretty that's pretty significant. The group of banks which also includes ING New Zealand's ASB bank US lender Capital 1, Commonwealth Bank of Australia said in a report that customers were enthusiastic about the potential of Agentic commerce and keen to enable it. However, they warned that the technology was advancing faster than industry standards and consumer protections. Which is incredibly true, especially in the US since the current government has decided not to put restrictions on it at all. Uh, consumers are unclear if AI will act in their interests, the report said, they are concerned the AI agents may buy the wrong thing or spend too much or even worse, lose their money to scams and fraud. They are not sure whether they will be protected or who they will need to go to if things go wrong. I think that's especially true if someone instructs their agent to find the cheapest price and that agent doesn't take into account the not only the like the legitimacy of that website, right? Is how long has it been there? When was it, you know, first established? Are the prices just way too low and not, you know, even remotely close to reality. Or are they just going to go for the cheapest item? And often times, you know, those websites that have cheap items on it will never ship you the goods. They'll charge your card, but then they'll never ship you the items and next thing you know, you can't find the website. Uh, so I agree with that. I think this is going to be a big problem for agentic e-commerce. The report highlighted risks including AI agents requesting customers card detailers details and entering them directly into websites or steering users toward payment methods that offer weaker protections. The bank's plan to discuss a series of proposals with policymakers, including requiring disclosures when an AI agent is involved in a transaction, greater transparency over how AI agents make decisions, and safeguards to protect customer data. Consumers and merchants should also be free to choose which AI powered e-commerce services they use, while different systems should be interoperable, the report says. So I think this is great that banks are calling attention to it. However, the people that are really in charge of this, you know, being the case and the liability as well as the data privacy and the safety of agent commerce is actually the platforms and and it comes uh but also the networks have been involved because they want to be involved in the protocol piece. Uh when I was at SardineCon last month, it was about five or six weeks ago now. Uh there was someone there from Visa. And he was saying that there have been a lot of conversations with a lot of tech companies that are providing generative AI and agentic e-commerce in trying to set up these protocols. Because merchants especially are very nervous that you know if someone sets up an AI agent but to buy something and it's not the thing that they wanted or they change their mind they can issue a chargeback. And currently there are no provision provisions for merchants to be able to win chargebacks when an agent is involved. So, I will continue to say that until I am a dark color blue in the face. I really think that that needs to be highly considered uh the liability as well as how merchants can defend themselves and regain some of the funds if they do receive those types of chargebacks. Because if the AI platform makes a mistake, I think the AI platform should be responsible for the chargeback. However, with current Visa and Mastercard rules and regs verbiage, that's not the case and it won't be. So, that's why I brought this article up. Next, it's a article in uh Georgia. And it says, "A whole new horizon for us in quotation marks. Police make first arrest in AIdriven fraud case in Chatham County.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
33:58
So, the chief of police is warning the AI is being used to create fake orders, QR codes, and even cloned voices for scams. Unfortunately, we know this all too well. Uh, but I have a couple things to add to it. So, Chatham County police have made their first arrest involving artificial intelligence fraud. According to the department. Police said 20-year-old Dion Love posed as a delivery driver at the Walmart uh on a road I can't say uh using a fake AI generated Spark order in an attempt to leave the store with a Nintendo Switch and other electronics. So, I believe Spark is Walmart's delivery system and uh either for pickup in store or for delivery. It sounds like he picked it up in the store possibly for delivery. And he was using an AI generated order to try to attempt the warehouse or the store. So, um, he went in said, "Hey, I work for Spark. I'm a, you know, driver for, like on behalf of Walmart, kind of like an Uber driver. And I have this order for a Nintendo Switch and other electronics that I need to fulfill. In order to deliver to this person who ordered via your website. And thankfully, Walmart was like, "That doesn't look right, and it's not in our system." But he tried and it was you know at least somewhat successful for you know them to identify it in that way. Then the police chief went on to say, and because he persisted an off duty police officer there detained him and we got called there and we ended up making an arrest. It's a whole new horizon for us so to speak and we're just now learning of these scams and how we go about addressing them, Hadley said. The chief says that retail fraud is just the start. Hadley said retail fraud is the only is only part of the problem. He said, well AI can help businesses with automation images and videos. Criminals are using the same tools to commit crimes including replicating voices. Something we've talked about here. Uh AI has the ability to create fake requisitions, fake orders, fake QR codes in order for people to proliferate criminal activities. Hadley described how AI generated voice technology could be used to defraud victims. I think we already know this, but um he said, "For example, I get your voice, I find out who your mother is, and then I call and utilize AI technology to replicate your voice and say, I need money. I'm in jail. You know, create a panic. Your mother's going to say, Oh, gez, I need to help my son. And sends money and something like that to defraud them out of money. Uh, thinking that they're helping their own son out. Police are working with national think tanks. He says, Hadley said his agency is meeting with national police think tanks to develop new tactics for investigating AI-driven crimes. Hadley urged the public to verify information before trusting it. And that's where I want to stop today. I think that there are plenty more AI attacks. There was another one using ad software posing as HBO. And get basically fishing for credit card details. Um, and they were using AI to boost their ads as well as uh collect all of that information. But you guys get the hint, right? Like AI is going to be here to stay. It's going to just keep refining over and over again. I have heard a few stories of, you know, AI adapting in real time to various fraud rules or, you know, uh, stipulations within the risk stack. And something to watch out for is that they're figuring out how to manipulate all of the things that you've put in place to try to identify them. So, we need to be aware of that they're using AI and they're doing it more often. And that it's going to look believable in a lot of cases um in order to catch them. So, that's what I wanted to focus on today. I'm really excited about MFA, guys. I'm I'm bummed if you can't go this year. I hope that there's going to be a next year. We are waiting to make that decision until we know how successful the first year is. Um, but I just really am humbled and grateful for all the support we've gotten so far. Even some people that can't come have just written me the kindest notes about how they know that this has been on my heart for a long time. And that they're really excited for it. So, I appreciate that. I will see some of you at MFA. I, you know, sometimes people listen to my podcast when they're on the plane. So, maybe you're listening to this on the way to MFA. But I'm really excited about it. I appreciate everyone who's been so supportive. And I will be back next week with an interview and then the week after uh with kind of a a debrief or a download of some of the hottest topics discussed at MFA. So, I'm looking forward to that episode. I already know what some of the panels are going to be and I mean I'm telling you some of these prep calls for speakers I am like there's going to be so much good information. And and at a senior level too it's not all entry level. So I am very excited as you can tell. Uh but I am going to be done for this week. I appreciate all of your support. I've gotten a couple of really nice notes in the last week uh from listeners. I really appreciate it. Um that's what keeps me going. Uh that's what uh keeps my guests wanting to come back as well. So really appreciate that and I will talk to you more next week.