SardineCon SF/2026

Learn More
Fraudology

2026年第4半期不正行為レポート:現在の不正を見抜き、明日の手口に備える

41分43秒

Fraudologyへお帰りなさい。

ときどき、あまりにも重要なレポートに出会って、それまで話すつもりだった内容をやめてしまうことがあります。今週はまさにそんな週のひとつです。

マット・ベガは最近、2026年版の四半期不正レポートを発表しました。その内容を読んで、これは一緒に詳しく見ていく必要があると確信しました。来年何が起こるかを予測しているからではありません。このレポートで取り上げられているあらゆる攻撃が、すでに現実に起きているからです。

このレポート全体を通して流れている最大のテーマのひとつは、不正行為が単純に、不正対策チームよりも速いスピードで進化しているという点です。AI によって、高度な攻撃はより低コストで、実行しやすく、そして発見がはるかに困難になっています。犯罪者は、必要なツールを「Fraud as a Service(サービスとしての不正)」型のマーケットプレイスで借りられるようになったため、もはや高度な技術スキルを持つ必要がなくなっています。

それは実際にはどのようなものなのでしょうか?

このエピソードでは、すでに実際の現場で確認されている最新の詐欺手口をいくつか取り上げます。具体的には、偽の「配信停止」リンクの裏に仕込まれたマルウェア、顧客の信頼されたデバイスに便乗するバンキングマルウェア、そして従来型の不正検知モデルでは口座乗っ取りを見抜くことが極めて難しくなるセッションハイジャックの手法などについて解説します。

一見すると、これらの攻撃の多くは正当なものに見えます。まさにそれこそが問題なのです。

また、なぜ不正対策チームが、デバイスインテリジェンスやIPレピュテーション、さらには行動分析といった個々のトラストシグナルだけに、もはや頼ることができないのかについても説明しています。犯罪者たちは正規の顧客行動に紛れ込む術を身につけており、それに伴って私たちの不正検知・不正防止のアプローチも進化させなければならないのです。

ここからが本当に面白くなってきます。

マットのレポートから得た最大の学びのひとつは、答えが「新しいツールをひとつ導入すること」でも「新しいモデルをひとつ入れること」でもない、という点です。重要なのは、より高度な不正検知インテリジェンスを積み重ね、コンソーシアムネットワーク全体で情報を共有し、自社の外側で起きているサイバー犯罪の大きな潮流を理解することです。なぜなら、新たな攻撃があなたのキューに届く頃には、すでに別の企業がその攻撃を経験している可能性が高いからです。

また、マーチャント・フロード・アライアンスのカンファレンスについての最新情報を、数分ほどかけて共有しています。そこでは、詐欺対策チームが今日から実務でAIを活用し始めるための、実践的な方法に焦点を当てた新しいAIブートキャンプについても紹介しています。AIが不正調査担当者に取って代わるからではなく、優れたチームがより速く動けるようにするためです。

もしあなたがマーチャント不正、銀行不正、オンライン不正、あるいは eコマース不正に携わっているなら、これは次のインシデントになる前にパターンを見抜く手助けとなるエピソードのひとつです。

このエピソードでお届けする内容:

  • なぜマット・ベガの2026年四半期不正レポートが、今年公開された中で最も価値の高い不正対策インテリジェンス資料の一つなのか。
  • AI が現代のサイバー犯罪を加速させ、詐欺サービスプラットフォームを通じて高度な攻撃を誰でも利用できるようにしている。
  • すでに加盟店や金融機関を標的としている、いくつかの新たな不正手口の詳細な解説。
  • マルウェアやキーロガーをインストールするために、配信停止を装ったフィッシングキャンペーンがどのように悪用されているか。
  • なぜバンキングマルウェアは、従来型の不正防止対策をすり抜ける効果をますます高めているのか。
  • セッションハイジャックによって、犯罪者が信頼された顧客デバイスからアカウント乗っ取り詐欺を行えるようになる仕組み。
  • デバイスインテリジェンス、IPレピュテーション、そして行動分析は、それぞれ個別ではなく、すべてを組み合わせて評価する必要がある理由。
  • 不正対策インテリジェンスの共有とコンソーシアムデータが、組織による新たな脅威の早期発見にどのように役立つか。
  • Merchant Fraud Alliance カンファレンスと、その新しい不正防止向け AI ブートキャンプに関する最新情報。

このエピソードは次のような方におすすめです:

  • 不正対策、リスク管理、またはトラスト&セーフティのチームを率いている方。
  • eコマース事業者、フィンテック企業、銀行、または決済会社における不正防止を管理する。
  • 攻撃が広く蔓延してから対応するのではなく、最新のサイバー犯罪の動向を先取りして把握しておきたい。
  • AI が不正防止と AI を使った不正行為の両方をどのように変えているかを評価している。
  • 不正検知モデルを構築または運用する。
  • アカウント乗っ取りや架空(シンセティック)ID、不正なオンライン取引を調査します。
  • 理論的な議論ではなく、実践的な不正防止のベストプラクティスを求めている。
  • 不正対策の一環として、デバイスインテリジェンス、IPレピュテーション、行動分析を活用してください。
エピソードノート

マット・ベガの2026年第○四半期不正行為レポート

これまでにこのポッドキャストをお聞きいただいているなら、私がいつもマットの不正対策インテリジェンスへの取り組み方を高く評価してきたことをご存じだと思います。彼は、私たちの多くが目を向けられない場所を見続けています。犯罪者コミュニティを監視し、新たに現れる手口を追い、主流の攻撃として表面化するずっと前からパターンをつなぎ合わせているのです。この視点が重要なのは、不正はプレスリリースとともにやって来るわけではないからです。不正は静かに始まり、あっという間に広がり、多くの組織がその存在に気づいたときには、犯罪者たちはすでに次の手口へと移ってしまっているのです。

このレポートは、次第に現実となりつつある状況を裏付けています。つまり、詐欺師たちはもはや高度な技術的専門知識がなくても、巧妙な攻撃を仕掛けられるということです。AI を活用したツールやレンタル型マルウェア、Fraud-as-a-Service(サービスとしての不正行為)プラットフォームによって参入障壁は劇的に下がり、犯罪者はこれまでになく速いペースで攻撃を拡大できるようになっています。

このレポートは、予測や仮説的なシナリオばかりを並べたものではありません。ここで紹介しているのは、すでに今日、金融機関や加盟店、貸し手に対して使われている実際の手口です。重要なのは、それらの存在を知ることだけではなく、その仕組みを理解し、自社の次のインシデントになる前に見抜けるようになることです。

新たに台頭する3つの詐欺手口

特に印象に残った3つの攻撃手法を詳しく見ていきましょう。

  • キー ロガー型マルウェアを送り込む、AI生成の「配信停止」フィッシング攻撃キャンペーン。
  • 正規の顧客デバイスを経由して取引を迂回させることで、不正行為を隠蔽するバンキングマルウェア。
  • 従来の多くの不正検知シグナルを作動させることなく、犯罪者によるアカウント乗っ取りを可能にするセッションハイジャック攻撃。

デバイスインテリジェンスやセッション履歴のIPレピュテーション、行動の一貫性など、これまで頼りにしてきた多くのシグナルが、すべて正常に見えてしまうことがあります。

だからこそ、これらの攻撃には注意を払う必要があります。

現代の不正検知には、複数のインテリジェンス層が連携して機能することが求められます

マットのレポート全体を通して流れている大きなテーマは、私がこのポッドキャストで何年も話してきたことです。あなたを救ってくれる「これひとつ」というシグナルは存在しません。攻撃者たちは、正規の顧客行動を真似る方法を次々と見つけ続けています。犯罪者たちは、私たちが最も強力な信頼の証だと考えてきたシグナルを、ますます弱点へと変えているのです。彼らは信頼されたセッションを乗っ取り、正規のデバイスを借用し、AIを使って攻撃を自動化し、個々の企業では到底太刀打ちできないスピードで攻撃を仕掛けています。

最も強力な不正防止プログラムは、1つのモデルや1つのルールだけに頼ることはありません。複数の情報源を組み合わせて活用し、信頼シグナルを継続的に検証し、単一の指標だけで判断するのではなく、より広い文脈を踏まえて意思決定を行います。

マーチャント・フロード・アライアンス・カンファレンス

とても楽しみにしていることについて、簡単にお知らせします。今度の10月にシカゴで開催される Merchant Fraud Alliance Conference では、私がとりわけ楽しみにしているセッションが1つあります。

私たちのAIブートキャンプは、「AIが重要かどうか」を議論する場ではありません。それが重要なのは、すでに分かっています。その代わりに、もっと実践的なテーマ――不正対策チームが日々の業務の中でAIをどう活用できるか――に焦点を当てます。

実際のプロンプトやワークフロー、ダッシュボード、レポーティング、調査に加え、不正対策の専門家がAIを活用して業務をより効果的に行うための実践的な方法について取り上げます。

専門知識を置き換えるのではなく、それを増幅させること。そのアプローチこそが、Merchant Fraud Alliance の根底にある理念を体現しています。

アジェンダにあるすべての内容は、詐欺対策のプロフェッショナルが職場に戻ったその日からすぐに実践できるアイデアを持ち帰れるように設計されています。そして正直なところ、まさにこういうカンファレンスこそ、何年も前からあってほしかったと私が思っていたものです。

重要なポイント
  • 2026年四半期不正行為レポートは、将来の予測ではなく、すでに現在の組織に影響を与えている実際の攻撃に焦点を当てています。
  • AI によって、高度な不正行為の攻撃がこれまで以上に迅速かつ低コストで、誰にでも利用しやすいものになっています。
  • サービスとしての不正行為は、組織的なサイバー犯罪の拡大をさらに加速させています。
  • バンキングマルウェアやセッションハイジャックは、従来型の不正検知を回避するために、信頼された顧客デバイスを悪用するケースがますます増えています。
  • アカウント乗っ取りによる不正は、個々の信頼シグナルだけでは特定することがますます難しくなっています。
  • 高度な不正検知モデルは、行動分析、デバイスインテリジェンス、コンソーシアムデータ、不正インテリジェンスを組み合わせて活用します。
  • 組織間で不正に関するインテリジェンスを共有することで、新たな攻撃パターンをより早期に特定できます。
  • 不正対策チームは、検知と対応を強化するために、新たに出現するサイバー犯罪の動向を継続的に監視する必要があります。
最終的なポイント

犯罪者が使う手口やツールは進化し続けており、私たちが長年頼りにしてきた多くのシグナルは、以前よりも操作されやすくなっています。だからといって、それらのシグナルの価値が失われたわけではありません。むしろ、それらは単独の指標として使うのではなく、多層的な不正防止戦略の一部として活用したときに最も効果を発揮するということです。

不正対策に携わる人々にとっては、検知精度を高めることと同じくらい、常に最新情報を把握しておくことが重要になっています。このようなレポートは、新たな攻撃パターンが広く蔓延する前にそれを見極める助けとなり、ただ後追いで対応するのではなく、先回りして対策を講じる機会を与えてくれます。

結局のところ、目標は今日の不正を見つけることだけではありません。明日の不正に備えることなのです。

エピソードのリソースとリンク:

つながるKarisse Hendrick | LinkedIn

Fraudologyポッドキャストのホスト

受賞歴のあるサイバー詐欺対策の専門家

Eコマース不正防止コンサルタント

スタートアップアドバイザー、基調講演者、そして

フォーチュン500企業のマーチャント向けコンサルタント

Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:05
Welcome back to the Fraudology Podcast. Well, for those of you that are listening, everything sounds the same. For those of you that found me on YouTube, I'm gonna be honest, this is a little weird. I had my first episode on YouTube last week with Mark Portius, and that was easier because I've done webinars before, I've worked with other people before. It was just a conversation with a friend, right? And it just happened to be on camera. But now I'm talking by myself to myself, and I can see myself doing it, and that's a little strange. So bear with me. For those of you on YouTube, please bear with me for the next couple of weeks. We're still figuring out lighting and position of the camera and all of those things to try to make this easier for you to watch. I've been hearing for years from people who have wanted to watch or listen on YouTube and I've put it off long enough. And thanks to the encouragement of the team at Sardine Media, I they made it happen. Really, they did 95% of the work to make sure that this happened. And if you haven't checked out the new Fraudology website yet, which will be in the show notes, as well as I posted about it last week on LinkedIn, definitely take check it out. We've got every single episode. So all four hundred I guess today is four hundred and thirteen. So all four hundred and thirteen episodes where you can look, you can find the transcript, you can find a summary, you can find takeaways, there's you know links to connect with the speakers on LinkedIn. It's really cool and really amazing that they were able to do all of that. So make sure that you check that out, especially. You know, of course I want you to listen, but if there's a week where you're like, I can't listen, but the topic looks good. I'd love to know what it was about. Go check out the summary. It's, you know, just a couple paragraphs, and then there's some bullet points afterwards for takeaways and things like that. So that's my plug for this new platform and all of that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
02:21
Again, I'm just so grateful to the Sardine team for going above and beyond what a sponsor does to make all of this look even more professional than I think that it is. Anyway, so before I dive into going over, so today I'm gonna go over part of a quarterly report that our good friend Matt Vega just put together and released and published. Matt, as if you've heard him on the podcast before, he really has his ear to the ground when it comes to dark web stuff. So not that cyber criminals really operate on the dark web anymore, but what I mean by that is, you know, the people that he understands what the criminals are doing and it's often the tactics that we don't know about yet, those hardcore sophisticated cybercrime tactics that we haven't we don't have a name for yet or we haven't identified in our systems yet. Those are the things that Matt really specializes in because of his background, with the military and then with a certain agency with three letters that I'm not allowed to say publicly. As well as, you know, his time at Sardine, Matt is now at point predictive working closely with Frank McKenna. Which what a powerhouse duo that is. So Matt put this together for Point Predictive and it's really the top ten fraud tactics in cybercrime that we don't know about yet that we need to. And he's got it broken down by banking, you know, credit and lending, you know, who the targets are. And we're gonna go over the ones in cyber fraud. There's I think three. Three in the cyber fraud section. So that's what we're gonna do for today's episode. But first I just want to give a little bit of an insight into what's going on for the Merchant Fraud Alliance. I haven't talked about it in a couple weeks.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
04:30
Mostly because I've been heads down working on the agenda. It's unorganized, but I currently have two large foam boards to the left of me with post-it notes of all the sessions that we're having, all the educational sessions that we're having. And it's now my job to assign speakers to each each session. And that's really what I've been head down working on that for the last few weeks. So, haven't been talking about it, but one of the things I wanted to highlight was actually, you know, the conference is October 6th and 7th in Chicago. But on October 5th, what we're kind of calling day zero, we're having a boot camp. And that boot camp is for you know, merchants only. It'll be for about 50 merchants. There's an e-commerce merchant that has an office in The Willis Tower, where we're having the conference on Tuesday and Wednesday. And they have graciously offered us the a large conference room to do this boot camp so that the rest of our team can set up for the conference for Tuesday and for Wednesday. But anyway, it'll be at the Willis Tower and AI boot camp can be so general, but you know what we came about was when we were talking with the ambassadors and figuring out what they think merchants need to know and what they, what they wanted to learn and what they wanted their teams to learn more about. We identified utilizing AI to fight fraud. There's some e-commerce companies that have mandated across their company that all employees must be utilizing AI, you know, whether it's Claude or it's Copilot or Chat GPT, that they need to be utilizing often the enterprise solution. They need to be utilizing it for 25% of their job or more. There are other e-commerce companies that have set up a kind of a working group to review any company that claims that they do AI.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
06:45
To verify that they actually are using AI and that they're not just saying that because it's a buzzword. So different companies are handling it different ways. But what it comes down to is there's also this piece where we're watching colleagues of ours in the industry lose their jobs, either to the fact that their employer thinks that they can be replaced by AI. You know, they haven't been yet, but they think they can, or they're you know, in the US, they're outsourcing to overseas. We're watching that happen and I think a lot of fraud people are saying, well, I need to get with the times so that I don't lose my job. And that's not to say that the people that were laid off if they you know had implement integrated AI into their job for 25% of the time or whatever, that they wouldn't have been. But there's a lot of people who want to utilize AI in fighting fraud, whether that's running reports, creating dashboards, identifying new fraud vectors, all of those different things, you know, new data sets, upgrading their machine learning to be AI internally, just all of those things. But they don't really know where to get started. And so there's two merchants that are gonna be leading this. I'm not gonna announce who they are yet, but they work for very large companies. And one of them specifically has been training their team over the last year to use AI and really to do more faster and to catch more fraud. And the goal of this boot camp is that you walk away with a takeaway. With prompts to use, with you know, the outline of a dashboard. Just with a greater understanding of how to use AI to fight fraud. And that's what those three hours on Monday is going to be dedicated to. So I want, I really, I can't stress enough how critical all of these sessions are to help you do your job better. That is our hundred that is our main goal, and we're knocking it out of the park with these topics and with these speakers, guys. It's pretty impressive.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
09:04
I'm very humbled at the people who have graciously accepted my offer to be part of this conference in the content piece. Some of them refuse to go to other conferences, so you can't see them anywhere else, but they're choosing to take risk on this first year. And I hope that you do too as an attendee because you're gonna have a lot of FOMO the first week of October if you don't. I can tell you that. But yeah, so we are limiting entry to the people who sign up and who first, so it's first come, first serve for that boot camp. We're getting close to capacity, but that's why I wanted to share about it today. If you do register at Merchant Fraud Alliance dot com, you can email me or message me afterwards or include it in your registration that you want to be part of the boot camp. I think there's a part that you can check for that. If you want a discount you for a ticket, message me on LinkedIn. I've got a handful of 50% off discounts that I'd love to hand out to Fraudology listeners. And just a reminder that we're not selling vendor tickets. We are only sending selling tickets to merchants. There will be vendors at the conference, but they're sponsors of the conference. And that sold out months ago. So we only have 15 companies that are vendors that will be attending. That's I think the way it shakes out, it'll be about 47 vendors and the rest will be merchants. And our hope is to have, you know, four or five merchants to every one vendor. So that it's easier to identify your peers and that you can have really good conversations with the solution providers that are there. Rather than feeling like you're a continual target. So for those of you who want to come to the conference, just a reminder that you do have to be working for a merchant or have most recently worked for a merchant if you're laid off.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:13
Okay, that was probably a lot longer than I meant for it to be. I hope my editor kind of like makes that a little more succinct. He's very good at that. Sometimes I ramble and he's, he's good at kind of tightening it up a little bit. But I could honestly talk about the content for MFA for a long time because I'm just so proud of it. And I think I'm proud of it because it came from merchants. Instead of putting out a call for speakers and saying, “What do you want to speak about in six months?” We asked our audience. We asked merchants, the people that will either be there or their peers will be there, and said, “What do you want to learn about?” What do you need to learn about? And that's how we built the agenda. So I'm proud of it. And that's why I'm rambling. All right, let's talk about Matt Vega's report. It is lengthy. I will say that. It is in-depth and lengthy. So you definitely will want to download it yourself or I think, you know, the first page you can read without anything. And then at least for me when I got to the actual report after the executive summary, it just asked for my name address or not my address, my email address. So my name, my email address and the company I worked for. I think that that's just so that the next quarter that Matt releases it, he can email it to you. He's not gonna sell the data or try to sell anything to you. I will make sure that there is a link to this report in the show notes. But it's also on the Point Predictive blog. Like I said, Matt joined Frank about a month and a half ago, I think. He love the way he did it at Sardine. I think he was there for four years and did a lot to really build it up and make it a you know, great and really relevant. But he wanted a new challenge and Frank was looking to kinda focus more on his Frank on Fraud duties than having a full time job at Point Predictive and work on Frank on Fraud. So it was a win-win. I had the pleasure of giving Matt a raving recommendation when Frank called me about it. So it's their dynamic duo and just having the time of their life geeking out every day on fraud. But anyway, this report I'm gonna read a little bit of what Matt says because it just gives context to why he did it. The kind of the title is Fraud is Officially Faster than Fraud Fighters. I would agree with that. And that is a very stressful statement. He goes on to say the trend that continues to worry me is the speed of innovation and collaboration of the attackers. As fraud fighters, it is more important than ever before to share what we're seeing, pass along our lessons learned, stay on the front lines of fraud threat intelligence, and lean into data consortium models for herd immunity. Attack on one protects all.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
14:35
I am now releasing this free quarterly fraud intelligence report to help my fellow fraud fighters and industry professionals stay aware of the ever evolving threats that we face. I spend hundreds of hours a week, or a quarter, diving into the deepest corners of the dark web, infiltrating rings and monitoring threat actors to understand the new exploits they are proposing, the ones they're working on and deploying against the industry. The most common theme this quarter: the people attacking your institution are no longer advanced cybersecurity black hats, engineers, or skilled fraudsters. They are a new generation of threat actors who combine the lack of extradition treaties with AI and rent a fraud tool. Providers, I call it fraud as a service, but same thing, rent a fraud tool providers to attack financial institutions and businesses with little to no recourse. Camera injection kits that defeat document checks, now sell for the price of a movie streaming plan. Banking Trojans are custom built to silence a specific bank's fraud prevention alerts before the money moves. And two-thirds of the flagship fraud AI models you hear about across the industry have been flipped into scams aimed at people trying to research or stop them. Nothing in this report is a forecast. All 12 vectors are active techniques we tracked from early dark web chatter. Into active or scaling attacks over the last quarter. Some will have already hit your queue this quarter, and you probably will never know. Others are going to hit your system in the coming months, following the traditional path of least friction. Every one of them is cheaper, exponentially faster, and far more advanced than the version you defended against last year.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
16:36
Wow, Matt, let's invite you to a dinner party. But it's all so true. And this is stuff that I talk about on a regular basis. I was asked to present at a top internet 50 company, I think, like very well known brand, last week, and really just to help them understand what they're not seeing and what they don't know and kind of that bigger picture of fraud. As I explained to them, they're the experts of the fraud that happens under their roof, so to speak. But it's helpful to understand what it looks like everywhere because, you know, you may not understand the other half of that fraud vector. There might be pieces of it that if you understood them, you could fight them better. It also is good because you're not going to be receiving every single fraud vector. And so what your peers are seeing, if you're not seeing it yet, you will soon. So when I was talking to this merchant, and it was a group of about 30 or 40 people from their risk team, they have a very large risk team because they have a lot of fraud, just like most large, well-known companies do. I do know of a few very large companies that have very lean teams, but their numbers kind of speak for themselves. They're hanging on by a thread. Not that always throwing bodies at the problem is the right way, but in this case, I think they see a lot of ROI on that. So I'm just backing up what Matt said. The biggest thing that I said was that they no longer need to have, you know, PhDs in computer science or, you know, be a skilled hacker, or even understand the ins and outs of your flow the way that fraudsters of you know previous years have. They'll study every single part of your flow, they'll figure out how to you know exploit a vulnerability and these days you don't need that anymore every piece of the puzzle to commit fraud against specific companies is out there for sale. And it's not expensive.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
18:55
You can get tutorials, you know, whether that's in book form or video form or a one-on-one coach, so to speak. You can get a fraud coach to teach you how to do fraud. You know, this fraud as a service thing, I remember really calling it out when I started to see it for refund fraud because I thought, man, if this starts happening for payment fraud, it's gonna be difficult to catch because you know it's no longer one guy trying to figure out all the ins and outs of several companies. It's several companies trying to figure out or you know, several small fraud fraudulent companies, figuring out the vulnerabilities of one company at a time. Matt goes on to say advanced threats and fraud vectors can do and hide from one financial institution, lender, dealership, merchant, or business. They cannot hide from a shared knowledge network like the lenders on Point Predictives Data Consortium. Where an attack on one triggers the fraud immune response that protects everyone. Once they attack one, the network learns, adapts, and builds up on that herd immunity. Improving detection and prevention with each subsequent attack just like your immune system. One of the reasons why Matt and I get along so well is because we both love analogies. Every attack vector in this report survives by staying nearly invisible to any single institution or business, making these exploits extremely difficult to detect without sharing networks and consortium models. A seasoned synthetic looks prime in one portfolio, but that same file in front of the full network of lenders and the community of enhanced data sharing pierces the network to show its true risk.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:47
As you read, ask yourself whether you would be able to detect or stop them in your own systems and controls. Industry collaboration, knowledge sharing, and shared data networks are more critical than ever before, and we are always happy to help provide guidance or show you how Point Predictive's data consortium models are leading the way for lenders across the industry. So, I of course, you know, need to talk about the company that he represents. Point Predictive is really good at helping dealerships, car dealerships identify synthetic ID. And a big part of that is their consortium model. A lot of times someone who steals a car from one dealership is gonna go steal a car from another dealership. They're gonna use, you know, fake documentation and fake bank account, you know balances and you know fake job pay stubs and everything else, and they're gonna go to different dealerships. So that's why he's talking about, you know, if you a fight a hit against one is is against all, right? We'll all find out about it if you use a data consortium. So they're all, you know, some are better than others. But I definitely recommend with at least one of your fraud vendors, that you do take advantage of the data consortium. There can be challenges. And I've been vocal about that over the years, but I agree with Matt that that is one tool that should be in your, in your fraud fighting toolkit.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
22:25
So there's twelve vectors. I'm gonna go through the ones that are impacting cyber fraud. I’m going to go through the ones that are impacting cyber fraud. We talk about the first trend in cyber fraud. He says it’s hiding in plain sight. And that is the annoyance to unsubscribe attack. And I didn’t know about this either. So that’s why I love to, you know, do this kind of research. And why I wanted to share it with you guys. I might have Matt back on the podcast in the coming months, but he was just on a couple well a month or two ago, right before he left Sardine, and I didn't wanna ask him again so soon, so we can learn from him this way. Attackers found a use for your annoyance. They flood you with the same email until you reach for the unsubscribe link, and that link is the attack. This is kind of scary. Anyone whose email address appears on the dark web list, which is more than ninety-five percent of all emails globally, are the key targets in this.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
23:30
So this was first detected by Point Predictive in June of 2026. So just last month. Criminals use AI to build high quality clones of I'm gonna start over there. Criminals use AI to build high quality clones of real company email campaigns. Then spam you with them many times a day from a lookalike address. The links are safe, real products, real sales. Real promotions. Click a product image and you land on the real website. Nothing bad happens. So it's not similar to Starkiller, like we talked about a few months ago. Then after the 21st identical marketing email that day, you click unsubscribe. That link carries a hidden malware redirect that drops a keylogger onto your device, capturing everything you type. Passwords, credit card numbers. Addresses, banking details. It's on his radar because it rides on legitimate campaigns and real URLs, and it uses annoyance as the method. Irritated people forget to check the unsubscribe link. That combination, because the emails look fine. They're legit. So why would you check the unsubscribe link? That combination is giving this attack the highest success rate we have seen in years because it hides in plain sight. Ninety five percent of all email addresses globally sit on a dark web list and that is the targeting.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
24:58
Signals to watch. A rapid or daily jump in marketing volume from a brand that rarely emails you. Copy the unsubscribed URL before clicking. A random string is the tell. So it would just be a lot of alphanumeric characters dot net or dot com. If you don't know how to copy a URL without clicking it, you just simply right click or you hover over the hyperlink. I don't know if we still call it that in 2026, but you hover over the link to unsubscribe. And sometimes you have to right click depending on your software, and then it will show you what the URL is that you'll be directed to if you click the button. So if it's a random string of alpha numeric characters. You know it's not for the merchant that they're, you know, trying to be or the bank that they're trying to be. Legitimate looking campaigns. So also look out for legitimate looking campaigns from addresses that do not match post marketing. So, you know, take a look at the email address that traditionally sends you emails, you know, marketing emails, and then take a look at the email address that sent you this one and determine if it's accurate or not. I've never thought about, you know, utilizing the unsubscribed link as the way to get malware onto your system with a keylogger. But it doesn't surprise me and I think it's really good to be aware of. The next one.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
26:39
Is Trickmo. Turns victim phones into clean exit nodes. Same real device, same IP, same city. Every signal your model trust checks out and a fraudster's behind all of it. That is very similar to the Starkiller product that we talked about on the podcast about a month, or a month and a half ago. Maybe it was two months now, but I was really worried when I found out about that because it was, you know, had a lot of potential danger. It looks like something similar is out there too. So the key targets are banks, credit unions, lenders, e-commerce, and exchanges that lean on device or IP as a key trust signal. As I think we all know, there's not just one key trust signal anymore, right? It's the combination that makes the difference. So what is it? A Trickmo variant, first tracked by Threat Fabric. And sold as malware as a service, re-engineers a banking trojan into a managed foothold. A built-in SOX5 proxy turns the infected phone into a network exit node. I'm saying N O D E node. That gives the fraudster the ability to route their own session through the victim's actual device and IP address. IP reputation and geolocation signals come back clean. In plain terms, the fraudster's activity flows through the actual card holder's real phone and your system reads it is safe.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
28:19
But it's on their radar because this attacks the fraud detection layer itself. The transaction originates from the customer's trusted device, network, and geography, which is exactly what many models, rules, and score risk scores use to lower the risk on a login and its activity. So by being able to glob on to the consumer's session and device and everything else, that looks legitimate. A lot of times these types of attacks are happening after another purchase. So what you'll have is customers calling your customer service and saying, “Hey, I made purchase one for $60. I didn't make not make purchase number two for $600.” There's no way I didn't make it, it's fraud. So customer service contacts the fraud department, they look it up to see if, you know, they missed something. And as Matt says in this report, everything that we hold, you know, is a weighted advantage you know, can be used against us. And so if we're using device and session and all of those in geography, you know, geo geography on IP, like geographic locations, then that can be used against us if the fraudster can just piggyback on the first transaction. This attacks the fraud detection layer itself. The transaction regenates from the customer's trusted device, network, and geography. Which is exactly why many models, rules, and risk scores use to lower the risk on a login and its activity. Think I might have read that twice. Sorry guys.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
30:07
Trick mode doesn't beat your fraud model. It dresses the fraudster in the victim's clothes. That's why invisible, when that's only visible when you're looking across a network or consortium, not inside a single portfolio, said Bill Hall, who is CTO and chief of staff. I don't know if that's for Point Predictive or not, but give him a shout out for his quote. Signals to watch. So, you know, you can't just cancel every transaction that has a safe device and a good IP address because there wouldn't be a company anymore. So instead the signals to watch are trusted device and IP paired with brand new behavioral metrics. Impossible spy simultaneous sessions from one identity or device. So maybe they make the per, two purchases at once on the same device and same session. That would be odd. Residential proxy or exit node indicators on a consumer line. And then another way to identify this is internal network recognizance coming from a consumer device. So if you're seeing any of those things across your network, or like I said, if you're having customers contact customer service to say, wait, transaction one was right, transaction two was not, or I logged into my account to change my address, and after I logged out, they then change the payee information to send me the check for people staying at my house on like a hosted, you know, travel site, for example. Those would be some indicators as well that you're getting hit with this.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
31:59
The Puppet Master malware that waits. All of this malware just creeps me out. Like it's just there's so much of it and it's really powerful, that it really worries me. And I think it should worry you as well. And I think knowing it's half the battle, when you know that these attacks are possible. You can then be able to diagnose it so much faster, once it's attacking your company. But also it makes you very relevant to other departments within your company where you can say, hey, there's a problem here. These, this is not a case of a customer making one purchase and then making a much larger purchase the next day or the same day. They haven't even gotten their products yet. So why would they know that they were happy and they wanted to order more? So anyway, those are all of the reasons why I think this is really important to talk about and also to just remember that malware can be scary. Here's the last one the puppet master malware that waits. This is a tricky one. The fraud operator waits and strikes mid session inside the real username's genuine activity, like a puppet master.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
33:20
The key targets are banks, credit unions, and online banking customers. So not as much e-commerce companies, but if you're in online banking or I would imagine crypto as well, this is important. So described in Barracuda's June 2026 analysis, this banking malware does not auto-fire. Disguised as a browser or security update, it lets a human operator watch a live banking session and pick the exact moment to act. Capture the session or take over midstream like a puppet master working a toy puppet. Because takeover happens inside the customer's own normal session, the fraud blends into their real behavior patterns and device signals. Detection gets very hard. Why it's on their radar? Bot and behavioral models are tuned for machine speed and or out-of-pattern actions. A human striking mid-session from inside the real user's activity generates almost none of those tells. So because they could identify account takeover when they weren't on the same session, they weren't on the same device or IP or anything else, it's really difficult. So unfortunately fraudsters are trying to bypass those. A human striking mid-session from inside the real user's activity generates almost none of these tells. It looks like the victim because in every tran technical sense it's the victim's session.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
34:54
So it's gonna you know, it's gonna look like friendly fraud, so to speak, or, you know, first party fraud, but it's not. So they do provide a call out between human-driven and so it says human-driven is an operator watching live and picks time the picks the moment that no machine speed tells. Mid-session, the attack lands inside genuine logged in activity, not the log E. Signals to watch for, high value actions right before, right after a software security update. Because the software security update would be the download of the malware. Session hijack indicators with no new device event or signal. So you've seen two checkouts on one account, an hour apart, and the local time is very, very late. And you know, all those other signals that you can combine, you should be combining to be able to identify this. Session hijack indicators with no new device event or signal, subtle mid-session shifts in cadence or navigation behavior, and a legitimate login followed by out-of-character movement in the same session. So those are things that you can look for to identify this. There is one more about international ghost tapping on the global remote contactless fraud that we talked about a little bit before Christmas. I think that we are the holiday season in November. I think that I have not done a good job of educating consumers or retailers with physical stores on this tactic. But it's important to be educated. So the very short answer I would say on this issue, that's impacting card not present merchants and remember they're on the hook for their own chargebacks. So they want to not be on the list, right? They don't want to have those they don't want to have any more. Inner but anyway.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
37:10
It's important just to know that contactless fraud can happen and you can get chargebacks from it. I have yet to hear from one of the merchants I reached out a few weeks ago. To see what happened when they called their acquirer and said, look, this was a ghost app. This was not true fraud. We need to go after these people. And in this case they knew exactly who they were because they had surveillance cameras from in store, they had their information. So that they could get loyalty points. But it's not always gonna be the case. So now that I've thoroughly depressed you, I do think it's so important though to be up on these tactics so that when someone in your company comes to you and is like, this is really weird. This doesn't make a lot of sense. You can recall something that you heard on the podcast or a webinar I do or a private presentation and be like, hey, is this affecting me? Like, am I not am I the problem, but is this something I should be concerned about? What are those signs? You know, can you look through my reporting and identify it? That type of thing. So I really want to thank Matt for putting this together. I had other fraud articles that I was gonna read this week. But then I saw this come out and I was like, no, we definitely have to dive into this. Because Matt always knows he's like three steps ahead of where a lot of us are with or a lot of, you know, online companies and banks are with the software that's able to detect that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
38:57
This helps you be able to detect them early. And really that's what it's all about is being able to be aware of them so that you can find them early. I want to, again, like I said, thank Matt for putting this together, knowing this stuff can help us stop them faster. It also shows a lot of patterns around how they're using AI, how they're using our own systems against us. The things that we have come, become reliant on, can no longer be relied on. And I think that the other big takeaway from all of this is how important it is to look from a 10,000 foot view. Not just look at the device, not just look at the session details, not just look at the behavior, but look at all of it together. And then also bring in your consortium data with the fraud provider that you use that for. Bring it, you know, you need we've been saying it for years, but you need to have layers. Because just one piece of this isn't gonna catch it. And as soon as they can identify that this works on your system, they're gonna go full court press and really hit you hard. So we don't want that. That's why we talk about it early. All right, everyone, I am gonna be done for the week. I really appreciate you listening to the podcast, all of your support. Thank you for watching on YouTube. Like I said, my I'm gonna try to have the back of my little shelf back here be a little more lit. I swear I'm not in a cave. I'm on the second floor of my house. But because I'm lighting my face, I guess the rest of it looks dark. I don't know. I don't know a lot about lighting and stuff like that, but I have awesome people around me that are helping me pick out the right equipment, which will just take time. But let me know what you hope that we talk about next. Let me know who you want to see on YouTube. Go check out that website that Sardine created if you just want a summary of an episode. If there was an episode that you really enjoyed that you wanted to share with your team. It might be easier to find it on the web when you can search the transcripts for keywords. There's just a lot of good things happening with Fraudology, and it's because you guys listen and you support it.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
41:15
So I really appreciate that. All right. I'm gonna look forward to speaking with you more next week. And next week will be a guest episode. So I won't have to stare at myself while talking for forty five minutes. Thanks so much for watching and for listening. Bye.