SardineCon SF/2026

Learn More
Fraudology

マスターカードの不正加盟店監視とAIの幻覚問題

ポッドキャスト番組「Fraud/ol/ogy」第405回のグラフィック。ゲストのニコラ・ハーディング博士とカリス・ヘンドリックが、それぞれの顔写真で紹介されている。

Fraudologyへお帰りなさい。

今回は、フロリダのビーチ沿いでワーケーションをしながらお届けしています。ちょうど Accertify Global Customer Summit が終わった直後です。本当に素晴らしいロケーションでした。

今回のエピソードでは、ニコラ・ハーディング博士をお迎えして、一見別々のテーマに思える2つのこと――不正検知におけるAIのハルシネーションと、Mastercardの新しい詐欺マーチャント監視プログラム――についてお話しします。

よく見ると、それらは同じ大きな問題によってつながっていることがわかります。

不正対策チームは、兆候がこれまでよりも早い段階で現れ、責任の所在が変化し、リスクを判断するために使うツールも必ずしもその説明どおり信頼できるとは限らない環境の中で、より迅速かつ複雑な意思決定を求められています。

それは重要です。

一方では、リスク管理、不正調査、そして業務上の意思決定にLLMが使われています。そしてこのエピソードで話しているように、不完全な情報やオープンソースの情報からAIが自信満々な答えを出し始めると、状況は一気に危険になります。特に不正対策の分野では、本当に役に立つ知識の多くが、理由があって自社専有情報になっているからです。

一方で、Mastercard の詐欺商人監視プログラムは、詐欺に関与している可能性のある加盟店を特定・調査するための、はるかに厳格な枠組みを構築しています。新たな閾値設定、返金およびチャージバックのモニタリング、そして72時間以内の加盟店調査期間により、加盟店、アクワイアラー、決済チームには大きなプレッシャーがかかります。

つまり、このエピソードの本質は、責任をどう果たすかという点にあります。

誰がその決定の責任者なのか?

誰がシグナルを検証しますか?

誰がその文脈を理解していますか?

そして、モデルやマーチャント向けプログラムのどちらかが、適切な人間の専門知識がないままでも運用できるかのように扱われたら、何が起きるのでしょうか?

このエピソードでお届けする内容:

  • Mastercard の詐欺商人監視プログラムが加盟店とアクワイアラーにとって何を意味するのか
  • なぜMastercardの詐欺商人ダッシュボードがeコマース不正対策チームにとって重要なのか
  • 返金およびチャージバックの監視が新規加盟店のリスク審査に与える影響
  • なぜ72時間の加盟店調査期間が業務上の緊急性を生むのか
  • 不正検知におけるAIの幻覚が、リスク分析と意思決定をどのように歪めるか
  • 詐欺に関する知識が専有情報である場合、LLMの幻覚が特に危険となる理由
  • 攻撃経路のより早い段階で兆候が現れる中で、なぜ不正対策チームとサイバーセキュリティチームは縦割り組織を解消する必要があるのか

このエピソードは次のような方におすすめです:

  • 不正対策業務、マーチャントリスク、決済、またはeコマース不正に携わっている方
  • Mastercardのチャージバック閾値や詐欺商人の調査ワークフローを担当している
  • Mastercard の詐欺加盟店モニタリングプログラムが自分たちのチームにどのような影響を与えるかを理解する必要がある
  • 不正リスク管理やAI生成による不正調査においてLLMの導入を検討している
  • ドメインの専門知識、不正対策とサイバーセキュリティの整合性、そして運用準備性を重視している

このエピソードを気に入っていただけたら、ぜひ購読して、iTunes、Spotify、YouTube、または普段お使いのポッドキャストアプリでレビューをお願いします。番組を多くの方に知ってもらう大きな助けになります。

エピソードの概要と主なポイント

このエピソードは、性質の異なるもののいずれも非常に重要な2つの不正問題が交差する地点に位置しています。

最初の問題は、AIのハルシネーション(幻覚)リスクです。ここで言っているのは、チャットボットが無害なことをでっち上げて、みんなが笑って済ませるような「面白い」タイプの話ではありません。現実には根拠がないのに、AIツールが自信満々の不正分析や引用、推奨事項、リスク解釈を生成してしまうタイプのリスクのことです。

それは問題です。

不正対策チームは、有用な情報がすべて公開されている世界で活動しているわけではありません。最も価値の高い不正関連のインテリジェンスの多くは、社内システム、独自のルール、調査結果、チャージバックのパターン、加盟店の履歴、サイバーセキュリティデータ、そして現場での運用経験といった内部に存在しています。そのため、LLM がオープンソースのデータだけをもとに推論しようとすると、本当に重要な文脈を見落としてしまう可能性があります。

2つ目の問題は、Mastercard の詐欺商人監視プログラムです。これは、加盟店やアクワイアラーに対し、詐欺に関連する加盟店の活動を迅速に特定・調査し、対応することをより強く求めるものです。これは単なるポリシーの更新ではなく、業務運用上の準備態勢に関わる問題です。

そして、そこでこの2つのテーマがつながります。

不正対策チームには、リスクシグナルがますます複雑になる中で、より迅速に動くことが求められています。つまり、ここで成果を上げる企業とは、あらゆるダッシュボードやモデルの出力、表面的な指標を盲目的に信頼する企業ではないということです。

彼らこそが、シグナルを正しく理解し、データを検証し、適切なドメインの専門知識を意思決定に反映できる人たちです。

なぜMastercardの詐欺加盟店モニタリングはアクワイアラーへのプレッシャーを変えるのか

Mastercard の詐欺加盟店モニタリング・プログラムは、詐欺行為や不正行為、有害な販売慣行に関与している可能性のある加盟店を特定するために設計されています。つまり、焦点は従来型のカード非対面取引における不正だけではありません。加盟店の行動、返金パターン、チャージバック、イシュアーからの苦情、オーソリゼーションのパフォーマンス、そしてその加盟店がネットワークにリスクを生じさせているように見えるかどうかが対象となります。

アクワイアラーにとっては、そのことで対応姿勢が変わります。

被害が明らかになってから待っているだけでは不十分です。アクワイアラーは、迅速に調査を行い、加盟店のリスクシグナルを把握し、その加盟店が正当な事業者なのか、契約を終了すべきなのかを判断できる必要があります。

それはまったく別種のプレッシャーです。

  • Mastercard の詐欺加盟店モニタリングにより、加盟店リスク審査をより迅速に行う必要性が高まっています
  • スキーム加盟店の不正調査に対して、アクワイアラーはより強力なワークフローを整備する必要がある場合があります
  • 加盟店リスク管理チームは、返金、チャージバック、および承認のパターンを総合的に監視する必要があります
  • 72時間という加盟店の調査期間があるため、オペレーション体制の準備が極めて重要となります

なぜ新規加盟店にとって返金およびチャージバックのモニタリングが重要なのか

このプログラムで最も重要な要素の一つは、新しい加盟店アカウントに対して、返金とチャージバックをまとめて評価する仕組みです。

詐欺業者は、常に一つの明確なシグナルだけで浮かび上がってくるわけではありません。多くの場合、そのパターンは、苦情、返金、チャージバック、承認率の低さ、そして営業を続けられる程度には一見正当なように見える行動が混ざり合ったものとして現れます。

一見すると、返金はカスタマーサービスの一環のように見えるかもしれません。

しかし詳しく見てみると、返金は別の問題が起きているサインでもあります。特に、苦情やチャージバックの増加、承認率の急な変動などと組み合わさっている場合は要注意です。

不正対策チームにとってのポイントはシンプルです。これらのシグナルを単独で見るのではなく、他の要素とあわせて判断してください。

  • 返金やチャージバックの監視によって、詐欺のパターンをより早期に見抜くことができます
  • 新規加盟店アカウントは、最初の6か月間はより慎重な審査が必要となる場合があります
  • Mastercardの詐欺基準により、リスクを継続的に監視するインセンティブが一層強まります
  • Eコマースの不正対策チームは、加盟店の行動を顧客からの苦情シグナルと結び付けて把握すべきです

なぜAIの幻覚は不正リスク管理において危険なのか

不正対策におけるAIの幻覚は、本来注意すべき場面で誤った自信を生み出してしまうため、非常に危険です。

モデルは要約できます。下書きを作成できます。情報を整理できます。さらに、チームがより迅速に動けるよう支援することもできます。

しかし、元のデータが不完全であったり、誤っていたり、不正対策チームが頼りにしている独自のコンテキストが欠けていたりすると、出力結果はあっという間に崩れてしまう可能性があります。

ここで重要になるのがドメインの専門知識です。詐欺対策のプロフェッショナルであれば、洗練されたAI生成の文章を見て「ちょっと待って、本当にこれは筋が通っているのか?」と問い直すことができます。モデルは、自分が専門外の領域に踏み込んでいることを常に自覚しているわけではありません。

そして、不正リスク管理においては、その違いが重要になります。

  • LLM の幻覚は、不正分析や業務上の提言をゆがめてしまう可能性があります
  • オープンソースのAIツールでは、自社独自の不正パターンを見逃してしまう可能性があります
  • ドメインの専門知識があれば、チームはAIの出力が実用に耐えるかどうかを検証できる
  • AIは人間の判断を置き換えるのではなく、不正対策業務を支援するべきである

なぜ不正対策とサイバーセキュリティの分断は、より大きなリスクになりつつあるのか

Accertify グローバルカスタマーサミットで特に大きなテーマの一つは、不正の兆候がより上流の段階で現れ始めているという点でした。

つまり、最初のリスクの兆候は、もはや取引の場面には現れないかもしれません。代わりに、アカウントのアクティビティやデバイスの挙動、フィッシング、マルウェア、認証情報の不正使用、その他のサイバーセキュリティ上のシグナルとして、より早い段階で現れる可能性があります。

そのため、不正対策チームとサイバーセキュリティチームが依然として別々に活動していると、そこにギャップが生じてしまいます。

そして犯罪者たちは、そのような隙を好む傾向があります。

不正対策チームは、支払いが行われる前に発生するあらゆるシグナルを可視化する必要があります。サイバーセキュリティチームは、それらのシグナルが最終的にどのようにして EC 不正、決済不正、加盟店リスク、あるいはチャージバックへとつながるのかを理解しなければなりません。

それらのチームが連携していればいるほど、より早い段階でパターンを見抜くことができます。

  • 不正対策とサイバーセキュリティが縦割りになっていると、リスクを早期に検知することが難しくなる
  • ファネル上流のシグナルを活用することで、取引が行われる前に不正を把握することができます
  • チームが情報を共有することで、決済不正の防止はより効果的になります
  • 部門横断的な可視性により、不正対策業務における見落としを減らすことができます

なぜ意思決定には依然としてドメイン専門知識が軸として必要なのか

このエピソードで繰り返し語られているのは一つの点です。ツールは役に立つが、情報を判断に変えるのは、やはり専門知識だということです。

それはAIの幻覚にも当てはまります。Mastercardによる詐欺商人の監視にも当てはまります。マーチャントリスクにも当てはまります。不正対策とサイバーセキュリティの連携にも当てはまります。

ダッシュボードでしきい値にフラグを立てることができます。

モデルはパターンを要約できます。

レポートはリスクを特定することができます。

しかし、その意味を理解する人が必要です。

だからこそ、経験豊富な不正対策のプロフェッショナルが最も重要になるのです。彼らは、加盟店のパターンがおかしく見えるときがわかります。ポリシーのしきい値に業務面でのサポートが必要なときがわかります。AIの回答がきれいすぎて不自然なときがわかります。さまざまなシグナルが同じ根本的な問題を指し示しているときがわかります。

これを誤って行うことの代償は、単なる悪いレポートや煩雑なワークフローにとどまりません。損失や責任の発生、加盟店契約の解除、見逃された詐欺ネットワーク、そして適切に検証されていない情報に基づいて下された意思決定などにつながりかねないのです。

最終的なポイント

Mastercard の詐欺商人監視プログラムは、不正防止がこれまで以上に相互に連携し、時間的な制約が厳しくなり、運用面で高い要求が課されるようになっていることを改めて示しています。

同時に、AIの幻覚は、情報が速く得られることが必ずしもより良い情報につながるわけではないことを思い出させてくれます。

つまり、本当に重要なのは「しきい値に気をつけろ」とか「AIに注意しろ」といったことだけではない、という点です。

つまり、不正対策チームには、より強力なコンテキストが必要なのです。

マーチャントリスク全体にわたるコンテキスト。

不正行為とサイバーセキュリティ全体の文脈。

返金、チャージバック、苦情、および認証行動にまたがる文脈。

モデルが自動的には持たない専有知識と、AI出力全体にわたるコンテキスト。

なぜなら、不正対策では、ツールを使うことでより多くのことを把握できるからです。

つながる:Karisse Hendrick | LinkedIn

  • Fraudologyポッドキャストのホスト
  • 受賞歴のあるサイバー詐欺の専門家
  • Eコマース不正防止コンサルタント
  • スタートアップアドバイザー、基調講演者、そして
  • フォーチュン500企業向けコンサルタント

Guests

ニコラ医師 ハーディング
Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:02
Welcome to Fraudology Podcast, where we dive into the science and study of online fraud from the perspective of an ecommerce fraud fighter. I'm Karisse Hendrick. Welcome to this week's episode of the Fraudology Podcast. Well, if my background or microphone sound even just a little bit different, that's because I am not in my home office this week. When I ran into a merchant at a recent event I was at, which I will talk about in a minute, she joked with me that she never knows where in the world I am because either on the podcast or she's part of one of my biweekly merchant groups, often I have new backgrounds. I've been traveling a lot this year since February.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:45
I spent two weeks in Maui with my husband, which was just absolutely magical, and then I went to the MAG Conference in San Diego. A few weeks later, I went to MRC in Vegas. A few weeks after that, I went to Fraud Fight Club in North Carolina. And then after North Carolina, I went straight to San Francisco to see family friends and spend some time with them, and then back home. And then a few weeks after that, I flew into Tampa, but stayed in Saint Petersburg for the Accertify Customer Summit. So that's where I've been this week. I decided to make it a work vacation and, you know, was at the conference for three days, and then myself and a very good fraud friend who was also at the conference, we decided to stay a few extra days, rented an Airbnb on the beach with a private pool. I really don't want to leave. And it's just, it's been perfect weather. I think that's pretty, you know, pretty common for Florida, but it's a long flight back to Washington State. So I didn't want to just come for three days and then go back.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
01:51
Plus, you know, if you can do it, it's fun. And, you know, she and I have traveled a fair amount together over the years, so we split the house well and just do our own thing sometimes and then hang out and talk fraud other times. I'm sure if anyone staying at the condos next to us, there's like a condo building on either side of this house, they're probably really sick of hearing us talking about fraud, but that's okay. Anyway, today I wanted to talk about a few things. So one was I was going to give a little bit of a recap from the Accertify Customer Summit. I was very grateful that they allowed me to come and asked me to come, especially because that is a rarity. Usually it's strictly for customers. So there's a few things that I got out of it that I wanted to share, and there were also a few things I got out of it that I can't share yet, but will once I'm told I can.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
02:45
I'm also going to share with you a LinkedIn post about fraud and ChatGPT that kind of proves the point that both Holly and I were making on our previous episode just about data sources and things like that, and AI hallucinations and all of that, that I think could be really helpful if you are being told that you have to use an LLM for part of your job. I know there's a couple companies, they've been told they must be using an LLM, you know, a ChatGPT, a Claude, that's whatever it is for 25% of their job by X date. You'll want to probably share this story with your bosses if that's the case. So I will share that. And then we'll talk. The main topic I wanted to talk about is Mastercard's new scam program. If you're on LinkedIn at all, and if you're on fraud LinkedIn at all, you've probably seen a couple of posts about it over the last few weeks. It's kind of Mastercard's version of VAMP. It's very different, but it has similar goals. So I'll go through that program, and it has some pretty significant repercussions if you are included in that and if your metric gets you above a threshold.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
03:56
So I think it's important to be aware of if you are an ecommerce merchant, and even if you aren't, I think it's good to be aware of what the card brands are doing and what they're requiring of ecommerce merchants. So this is today's agenda. Diving into the Accertify Global Customer Summit, it was a great opportunity to network with about 150 people that work for merchant companies, merchant fraud fighters. If you're not familiar with companies that work with Accertify, I don't know which ones are public and which ones aren't. So I'm not going to name any, but I'm going to say they are primarily the largest brands in retail, in travel, in airlines, in some restaurants, a lot of different areas. But I would say 80% of their clients are household names. And Accertify is probably the longest running fraud tool out there.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
04:52
I remember when their very first sales rep came and pitched it to me when I worked for a startup in Seattle in probably 2009, right around there in 2008, 2009, something like that. And at the time I was impressed that they were building something like that, but it was very similar to what I had built with our dev team at the time for what we needed for our business model. So we didn't go with it, but it was impressive and it has since grown immensely since then. I was curious to know what was new for Accertify and got to learn a lot about that, as well as got to network with existing fraud friends and met several new ones. And my hope is that a lot of them will join us at the Merchant Fraud Alliance in October. That would be a lot, a lot of fun. I hope every merchant joins us at the Merchant Fraud Alliance in October. But I specifically, you know, one of the reasons I went to this event was to get the word out a little bit more. So it was a great opportunity for that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:54
They had a lot of networking opportunities, a lot of fun mixed in with sessions. And, you know, some on the big stage, some in breakouts, some were trainings, some were trainings on their new products, some were topics that people really care about in this industry and that, you know, they wanted to learn more about. Of course, AI was a topic of conversation. The theme of the event was how cybersecurity and fraud are better together, really talking about how fraud signals are moving up funnel. They're not just at point of checkout anymore. So there's a lot of fraud signals, especially for account protection, whether that's new account protection or account takeover protection, that type of thing, that live up funnel. And therefore, you need to make friends with your cybersecurity team. And they released a proprietary survey that they had commissioned that had a lot of really great benchmarking metrics that I've never seen published before, especially around cross-functional organizations working together. And they correlated that with their customers' fraud statistics. So like approval rate, chargeback rate, fraud rate, etcetera, to really demonstrate that there is, at least, a correlation, if not a causation, between cybersecurity and fraud working together and, you know, good outcomes in fraud metrics.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:22
So that's probably, I'm not saying anything specific, but that's probably all I can say for now. I did ask permission to share some of the statistics, and they said I absolutely can once the study is published, which will probably be in June. So you can look forward to that episode. I was really impressed with the questions they asked and the answers that came out of them. There's some good strategic direction, not only for this topic of fraud and cybersecurity working together, but for other things that we've all been asking for for a long time on the merchant side. So I think that will be something to look forward to. One of the breakout sessions that I attended was done by, you know, one of my favorite recent guests, Holly Sandberg. She did a terrific session on providing metrics with counterbalances to executives and senior leadership. She created a really great template for an executive scorecard and, you know, which metrics you should be measuring and then which metrics kind of counter those metrics and keep them honest.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
08:24
For instance, you can't just look at your fraud rate and say, woohoo, we're catching all the fraud without looking at your approval rate too. And you may be catching all the fraud, but your approval rate might be, you know, in the gutter and you're not approving enough orders. So you need to have both of those metrics to balance things out. That's just one example of the metrics that she shared. I thought it was a really good session and I asked her to please present it in a little bit of a different way with a different title and with a little different information, a few more specifics at MFA. So if you're looking for another reason to go to Merchant Fraud Alliance, that session is going to be fire. And I haven't told Holly this yet, but I want it on the big stage. I don't want it in one of the smaller breakout sessions because I think it's that good. And I think it's something that everybody needs to learn and wants to learn.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
09:17
I think communication with cross-functional teams as well as communicating with leadership are two things that we, on a whole, don't do well. And a lot of us recognize that and want to be informed by people who are doing it well. And Holly definitely is. So she'll be the perfect person to present on that. And if she wants a co-presenter, I will get her one, but she doesn't need one. Okay, well now I wanted to read this post from Nicola Harding. I found it really fascinating. It kind of made me laugh. It was the first thing I read one morning this week and I just, I kind of laughed to myself. And then my friend that was with me, I was like, what's so funny? And I read the post and, you know, as only fraud nerds would get it, she got it.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
10:06
So here's the post from Nicola and then I'll share some of my thoughts. EY. So like that EY, one of the top four biggest consultancies in the world, just published and then quietly pulled a 44-page cybersecurity report on fraud in loyalty schemes, all because it was riddled with AI hallucinations, fabricated citations and footnotes pointing to pages that don't exist, including a McKinsey report referred to throughout, a reference throughout that simply does not exist anywhere. So they were citing this McKinsey report of data, and that McKinsey report doesn't exist. This was not caught by EY's own review process, but by an external AI detection firm. As a criminologist, Nicola Harding, if you don't know her, has her doctorate. She's Dr. Nicola Harding and has her doctorate in criminology. I've gotten to see her speak in person and she is a wealth of knowledge on fraud.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:07
So as a criminologist who is an expert in this area, I can tell you that loyalty card fraud absolutely exists and it matters. The problem is that research like this doesn't just embarrass the firm that published it. It poisons the well. Hallucinated data gets picked up by other researchers, surfaces in AI search results, and corrupts the broader evidence base that practitioners, policymakers, and prosecutors rely on. That's not a minor quality control failure, it actually does serious harm to a field. AI is not the villain here. You wouldn't argue an accountant shouldn't use a calculator, but you would expect that accountant to be trained, accredited, and exercising professional judgment, not outsourcing the thinking to the tool and skipping the part where they check the workings.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:53
Research requires human judgment acquired through years of training, selecting appropriate methodology, reviewing the literature, understanding not just whether a source exists, but what the findings mean within the broader body of knowledge on a topic. That cannot be automated, and it shouldn't be. Research doesn't just need to be done, it needs to be presented within context by experts that understand the data in great detail and can defend the research and its implications. Fraud and financial crime prevention is an area where the stakes of getting it wrong are high. It is also increasingly an area where even the largest firms appear to believe they can blog expertise rather than invest in it. They cannot, and cases like this show exactly why.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
12:41
So there was an article, FT Times or yeah, the Financial Times that exposed this, but I really liked Dr. Nicola Harding's perspective on this and her take on this. My comment to her was, I was wondering when this would happen. AI is incapable of saying it doesn't know something, so it hallucinates. There's also the point, and if you've listened to this podcast in the last month or two, you know what point I'm about to make, that its data sources are open sources. And most of the real knowledge in fraud is either internal within companies or stored within the minds of fraud fighters. It's purposeful to keep what little advantage we have away from the criminals. And then I asked as a side note, did anyone copy or download this study before it was pulled? I'd love to read it, mostly for pure entertainment value.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
13:30
And she said, oh, all good points. And then she said, I have not. I don't have it, but I wonder if it's around. Shall we ask ChatGPT? Unfortunately, some of those points that may have been hallucinated in EY's study may now be in ChatGPT. So that if somebody, you know, asked ChatGPT about loyalty fraud, they may cite this EY study that was all based on AI hallucinations. That's part of the problem. The other part of the problem is this, not, you know, to have true expertise on a topic like loyalty fraud, you can't trust open source information. It's going to be all generalized. They're not going to be talking about the tools that you can specifically use to prevent loyalty fraud or even how hard it's impacting companies because a lot of impacted companies won't publicly say how much loyalty fraud is impacting them.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
14:19
So loyalty fraud is one of those that's kind of like account takeover fraud where it doesn't really have a metric. The metric you'll get, you know, you'll know it's happening when customer service is getting the calls of saying, you know, my air miles have been drained or my hotel points have been drained, or, you know, someone cashed in this voucher that I had because of how many times I've shopped with you, those type of things. And so they don't have the clear feedback loop that card fraud, traditional card fraud has with chargebacks. So there's a lot of nuances there that AI just doesn't have access to and doesn't know. So they'll make it up. And I did find it funny that one of the top four, you know, consulting firms that writes these big research papers obviously used AI to write it and didn't have a professional in the fraud industry read over it to verify that it was accurate. That is something I would have been happy to do had they asked, but now instead it's pretty embarrassing for them.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
15:20
But I think that this is a good article to share or posting to share with leadership if they are asking you to rely on LLMs to do research, as well as if they're thinking about using LLMs to replace somebody in strategy or someone in operations and fraud leadership. They cannot just ask ChatGPT a question and get the right answer. Just like with that example I've given earlier about, you know, what's pizza fraud? What's, you know, this kind of fraud? What's that kind of fraud? When Frank, we kind of did that in a group text I was a part of and then others did it too, ChatGPT was just making up different types of fraud that kind of made sense for pizza, right? I think one of them was pizza fraud is when someone goes into a pizzeria and steals a pizza. That's not, that's not fraud and that's theft.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
16:11
There were other examples as well that I can't remember, but there's no such thing as pizza fraud. But it couldn't say that. It was incapable of saying that. So instead, it made something up. How do you know if AI is making something up or not? You have an expert employed in your company who knows to spot BS and not, or at least knows who to ask. If they don't know, they can ask someone else in the fraud industry and say, does this sound right? You have to have someone with expertise and knowledge. You can't just rely on open source information for our industry. Maybe for others, but not for our industry. So that was the story. Like I said, I thought it was pretty funny, but also telling about the future that we are walking into or running into at this point.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
18:07
All right, let's talk about Mastercard's Scam Merchant Program, shall we? So Mastercard's new Scam Merchant monitoring is going to go into effect July 24th of 2026. They just announced it a few weeks ago. Its purpose is to find scam merchants. What they mean by scam merchants are merchants that are scamming consumers. The ones that pop up with a, you know, new merchant ID and they're offering free trials or they're shipping things like, or they're not shipping things at all, or they're promising something that they don't deliver on. Or, you know, they're promising something large and you get something small, or they're promising something, you know, that works and you get something that's broken. Those type of companies. Scam merchants. And so the way that Mastercard thinks that they can find them is by looking at a few key criteria. And they kind of have a multi-trigger framework is what they're calling it. But any one of these conditions can initiate a required investigation.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
19:10
So one of the more straightforward triggers is a breakdown in authorization performance. If a merchant's approval rate drops sharply over a short period, for example, a decline of 50 percentage points or falling below the 30% overall, that alone can put them into scope. The measurement window is tight. Acquirers are given a minimum of a 72-hour period or actually, oh no, this is different. This is not the acquirers. This is the measurement window for approvals falling quickly, a minimum 72-hour period with at least 25 transactions. So when any one of these triggers is, or one of these conditions is triggered, it'll initiate a required investigation with your acquirer. The acquirer has 72 hours to investigate and either provide Mastercard with an explanation on why this merchant is not scamming and not illegitimate. They have to provide a legitimate reason for that condition to be triggered, or they need to terminate that merchant and no longer allow them to accept Mastercards.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:18
And by the way, you can't just accept Visa without Mastercard. So if you're shut down for Mastercard, you also can't accept Visa. That merchant would only be allowed to accept Amex or Discover or maybe PayPal, which would greatly cripple online businesses. I'm reading from a post by Rick Lynch, who's been in the chargeback space for a long time. He goes on to say, there is also a direct escalation path from Mastercard itself. If a merchant is the subject of a Global Rules Investigation Program, or GRIP letter, that independently triggers the requirement to investigate. For newer merchants, defined as those with less than six months of processing history, there's an additional layer of sensitivity tied to issuer behavior and early performance signals. In those cases, just two different issuers reporting scam-related transactions under the manipulation of cardholder fraud classification is enough to initiate the process.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
21:16
So if you're a new merchant under six months and two issuers report that their cardholders have claimed that they were manipulated in some way, that's enough to initiate the investigative process within 72 hours. That can result in terminating your ability to accept Mastercard. The same applies if two issuers initiate chargebacks that reference scams or similar behavior. That's going to be more complicated because there are cardholders that claim that a merchant scammed them and they really didn't, right? So that's something to watch out for. Then there's a 5% threshold, and it sits specifically in this category. If a newer merchant, so I think within six months, sees more than 5% of its transactions result in refunds and chargebacks over a 30-day rolling period and has processed at least 500 transactions, that condition alone can trigger monitoring. So outside of that early life window, those issuer count and 5% thresholds are not explicitly defined as triggers in the same way. So I think that's important to know.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
22:26
But if you have a new merchant account and the combination of refunds and chargebacks equal more than 5% of your total volume of sales, you could be at risk for having your account activity investigated by your acquirer and possibly shut down. I think it's really interesting that they are combining refunds and chargebacks together. I understand why, but at the same time, Mastercard owns Ethoca, and when merchants enroll in Ethoca, they're enrolling in alerts that can allow them to issue refunds to avoid chargebacks. So they're kind of saying that for these purposes alone, but still for these purposes, Ethoca's not going to help you. It's going to hurt you. It's not going to, it's just, well, maybe it's not going to hurt you, but it's not going to help you because it's going to increase your refund amount. Additionally, there are some merchants that issue a lot of charge, or a lot of refunds because they have a lot of returns, right? A lot of retailers have a lot of legitimate returns that could look fishy to this, you know, program. You could be, you know, under monitoring. Granted, it is if you have, you know, at least 500 transactions, but I think in a 30-day rolling period. But I think most people on the merchant side that are listening to this podcast would very much blow that out of the water. So I think this applies to everyone.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
23:52
What they're not saying right now is if this applies to merchants that are older than six months. I don't know the answer to that. I have seen some people say it does. I have seen some people say it doesn't. I have heard other people say, well, they're rolling it out for the first six months, you know, of a merchant's lifetime now. But they're going to see how it goes and they're going to start tracking this metric more. And now that they can track this metric, if they see a high number of enterprise merchants, for example, that have a combined rate of refunds plus chargebacks divided by sales for that 30-day rolling period, it's not a calendar 30 day, it's a 30-day rolling period, that, you know, there could be repercussions. Right now, it hasn't been said one way or another, but I do think it's, you know, it's worth being aware of.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
24:41
Beyond performance and issuer-driven signals, third-party and network alerts can also initiate the process. If a merchant is flagged by a merchant monitoring service provider or through Mastercard's own monitoring programs, that alone can be sufficient. Once any of these conditions are met, the timeline is clear. The acquirer or payment facilitator has 72 hours to initiate an investigation, and if the merchant is confirmed to be conducting scam activity, they are required to block that merchant from processing Mastercard transactions. Separate from the trigger events themselves, Mastercard is reinforcing expectations around ongoing monitoring. Acquirers are expected to continuously evaluate transaction patterns, refund and chargeback activity, fraud indicators, and behavior that doesn't align with the merchant's stated business model. So if you say that you are a hotel but then you're only processing $20 transactions, that's going to look weird, or, you know, those type of things.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
25:48
There is also an expectation to review Mastercard's fraud and loss database on a daily basis for new signals. I think that's more for the acquirer than the merchant. Taken together, this is not a single metric program. It's a system with multiple entry points where performance changes, network escalation, issuer activity, and third-party alerts can all independently set the process in motion. So again, that's starting July 24th of 2026. I think most companies that are listening to this now on the ecommerce side have had their MIDs for way longer than six months. But I think it's important to be aware that Mastercard is tracking this data. This is new math that we don't usually do, right? Similar to VAMP, we don't usually do the exact math that they require for VAMP.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
26:38
We hadn't up until this time combined TC40s with chargeback numbers and then divided those by the number of sales. That was a new metric for us to start computing. Now there's a new metric to compute for Mastercard risk, and that is refunds plus chargebacks divided by sales, number of sales, the number of refunds plus number of chargebacks divided by number of sales. I think it's important to know that that's how things are being measured because you want to stay underneath those thresholds. And again, that threshold is 5%. I would hope that you would want to stay under that threshold for lots of reasons, specifically revenue. But at the same time, like I said, there are multiple reasons why merchants refund orders and some of them are very legitimate. I think that this could also impact subscription merchants who will often refund the last month of a transaction because they know that the cardholder can issue a chargeback.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
27:42
So, you know, technically the issuer, or the cardholder, can issue a chargeback for the last three months. So they'd rather give an appeasement refund of one month and then tell them, no, you can't get a refund at all, and then they go to their bank and find out they can charge back three months. So subscription merchants, high-risk merchants, some retailers, I think maybe over 500 basis points, I don't know, you know, it might be over that 5%. It's important to, you know, be aware of. All right, that is it for me today. That was kind of a shorter episode, just around 30 minutes or so. And it's not just because I want to get back to floating in the pool, I promise. But that was really, those are really the three things I wanted to update you on. I am expecting to have a guest for next week's episode. Also, Fraudology is coming to YouTube soon. This is kind of against my will, but it's been strongly encouraged by several people and as well as by my sponsor that I branch out to YouTube. So why not now?
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
28:49
So that will be happening in the next few weeks. Don't forget to look into the Merchant Fraud Alliance October 6th and 7th in Chicago. You're not going to want to miss it. Otherwise you're going to have significant FOMO. I promise. I am putting a lot of time and effort into sourcing the best speakers and, you know, representing the best companies. And by having those people in a room, those are conversations you get to have as well. And there will be the ability in the app to set up meetings with people. You can also set up your own schedule for meetings. There's just all kinds of cool features. So it's a great way to meet new people and see familiar faces as well.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
29:29
So with that, I'm going to talk to you more next week, but I hope that you are having a great day and I'll talk to you soon.