Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
Fraudology

AI Enabled Fraud: When Growth Comes Before Guardrails

39 min

Welcome back to Fraudology.

AI is here, and it’s making every kind of fraud we already know cheaper, faster, and harder to catch. We are going to walk through a handful of stories that show exactly how AI enabled fraud is showing up right now. From card testing at scale to one very messy fraud story.

That story is Polymarket, and I spend some real time on it. It’s rare that we get this much visibility into a company’s actual fraud details. A Wall Street Journal investigation lays out the stolen debit cards linked to thousands of new accounts and a fraudulent deposit rate that hit 80%. I also get into AI-generated deepfake delivery orders, a bank coalition’s new warning about agentic commerce fraud, and a warning about AI voice cloning scams.

We aren’t eliminating fraud, we never can, but we can get the information to be as fast or slightly faster than the fraudsters.

What you’ll hear in this episode:

  • Why AI-enabled BIN attack fraud and card testing are up over 75% according to at least one fraud vendor, and how fraudsters are now optimizing payment authorization the same way legitimate payment teams do
  • A full breakdown of the Polymarket fraud scandal, including the prediction market fraud risk baked into its business model and the leadership decisions that made things worse
  • Why Polymarket scrapped its same-source withdrawal rule to speed up payouts, and how that decision opened the door to real money laundering prevention failures
  • A serious account takeover fraud exploit where a new account created with someone's stolen SSN could inherit their existing balance and linked cards, no password needed
  • Why compliance staffing fraud programs need people with actual prevention experience, not just investigators brought in after the fact
  • How growth at all costs fraud risk plays out when a CEO's response to an 80% fraud rate is reportedly "just keep growing and pay a fine"
  • A new bank coalition report on agentic commerce fraud, and why AI shopping agent chargeback liability still has no real framework under current Visa and Mastercard rules
  • An AI-generated fake delivery order used to attempt a retail theft at Walmart, and a Georgia police chief's warning
  • What a real chargeback monitoring program actually looks like from the inside, and why Polymarket landing a fraud vendor like Riskified says a lot about how serious this problem became

You should listen to this episode if you:

  • Work in payments, card fraud, or retail fraud prevention and want a grounded look at how AI is scaling attacks you already know
  • Are building or evaluating a chargeback monitoring program and want a real, public example of what happens when fraud rates spiral
  • Care about prediction market fraud risk or are watching the regulatory and legal fallout at companies like Polymarket
  • Are responsible for compliance staffing fraud programs and want language for why prevention expertise matters as much as investigative expertise
  • Are tracking agentic commerce fraud and want to understand the AI shopping agent chargeback liability gap that still hasn't been solved
  • Want practical, real-world examples of AI-generated fake delivery orders and AI phishing scams to bring back to your own fraud team
Episode notes

AI enabled card fraud starts with faster, smarter card testing

Card testing used to mean someone manually entering card numbers one at a time. Now it's a spreadsheet upload and a script, which is a big part of why one fraud vendor reports card testing up over 75%. Fraudsters aren't just checking which cards are valid anymore. They're using payment authorization optimization the same way legitimate payments teams do, studying BIN data and transaction details to increase their own approval rates and make future purchases look more legitimate.

Inside the Polymarket fraud scandal

A Wall Street Journal investigation lays out just how bad things got at Polymarket, a prediction market platform now facing an IPO. Fraudsters linked stolen debit cards to thousands of new accounts, attempting to steal at least $10 million, with fraudulent deposits at one point hitting 80% of all transactions the payment processor was handling. According to the report, employees who raised concerns were reportedly told by leadership to keep growing and pay a fine if regulators ever noticed, a level of growth at all costs fraud risk that's rare to see documented this clearly.

Why the same-source withdrawal rule matters more than it sounds

One of the more useful fraud fundamentals in this story is a rule most people have never heard named directly. Requiring withdrawals to go back to the same payment source they came from is a simple, effective money laundering prevention control. Polymarket dropped that rule to speed up customer payouts, and predictably, fraud rates climbed right alongside it.

An account takeover fraud exploit that should concern every risk team

Later in the year, Polymarket users were hit with a different kind of account takeover fraud. If someone created a new account using another person's stolen personal information, including their Social Security number, they could gain instant access to that person's existing account, along with any linked bank accounts and cards, no password or username required. That's not a fraud problem so much as an engineering one, and it's worth remembering that fraud and security failures are often the same failure wearing different labels.

The chargeback gap in agentic commerce still hasn't closed

A coalition of banks recently published a report on agentic commerce fraud, flagging real concerns about AI shopping agents entering card details directly or steering people toward weaker payment protections. I still think the more urgent problem is AI shopping agent chargeback liability. If an AI agent makes a mistake or a purchase a customer didn't intend, there's currently no framework under Visa or Mastercard rules that holds the AI platform responsible instead of the merchant.

AI-generated fake delivery orders and voice cloning scams are already here

A Georgia arrest involved someone using an AI-generated fake delivery order to try to walk out of a Walmart with electronics, posing as a Spark driver fulfilling a fake pickup. The same police chief warned about a much more personal version of this problem, AI voice cloning scams that replicate a family member's voice convincingly enough to fake an emergency and demand money, alongside more familiar AI phishing scams impersonating brands people already trust.

Key takeaways
  • AI-enabled BIN attack fraud and card testing are up over 75% at some merchants, driven by automation that removes the old manual bottleneck.
  • The Polymarket fraud scandal shows what growth at all costs fraud risk actually looks like when leadership prioritizes speed over fraud controls.
  • Dropping a same-source withdrawal rule for faster payouts directly undermines money laundering prevention, even when other controls remain in place.
  • Account takeover fraud can now exploit new account creation flows, not just existing login credentials.
  • Compliance staffing fraud programs need genuine fraud prevention expertise, not just investigators experienced in after-the-fact enforcement.
  • Agentic commerce fraud is a real and growing concern, but AI shopping agent chargeback liability remains unresolved under current card network rules.
  • AI-generated fake delivery orders and AI voice cloning scams are already being used in real, documented crimes, not hypothetical ones.
  • A strong chargeback monitoring program and the right fraud vendor can bring fraud rates back to industry norms, but only once leadership takes the problem seriously.
Final takeaway

If there's one thread connecting every story in this episode, it's that AI enabled card fraud doesn't need a new playbook to be dangerous. It just makes the old playbook faster, cheaper, and easier to run at scale. Whether that's a fraud ring testing thousands of stolen cards in seconds, a company choosing growth over guardrails, or a scammer cloning a voice to fake a family emergency, the fundamentals we've always relied on, segregation of duties, same-source withdrawal rules, real compliance expertise, matter more now, not less.

Connect with Karisse Hendrick | LinkedIn
Host of the Fraudology Podcast
Award-Winning Cyberfraud Expert
Ecommerce Fraud Prevention Consultant
Startup Advisor, Keynote Speaker, and
Consultant to Fortune 500 merchants

Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:07
Welcome back to the Fraudology podcast. I'm Karisse Hendrik and I am happy that you're here. Uh today we're going to go through some news articles of the week and they all have a common theme and that is that AI is here. I know I'm not really telling you anything new. Uh AI is creeping into all areas of our lives it seems, but not surprisingly bad actors are using it to commit more fraud. Uh you know, we always say that our job as fraud fighters isn't to eliminate all fraud. While that would be nice, we know that that just isn't realistic. Uh but it is to make it harder and slower for them to do, right? And more expensive. That's always our goal. Make it more difficult for them to attack our site or our bank rather than, you know, someone else's. And unfortunately, it's one of those situations where, you know, you don't have to be as fast as the bear. You just have to be as fast or faster than the last person running from the bear. And the fraudster's goal is always to make things cheaper and faster for themselves. And AI does that to an extreme. It really uh provides a lot of ease. And there's so many different platforms out there that make it easier for them as well. They're not only using the ones that we're familiar with. Uh they have some of their own AI models as well as using tools that are meant for enterprise and all kinds of things. So today the news articles will be centered around different AI attacks. Certainly won't be an exhaustive list. I've been talking with merchants a lot in the last few weeks, especially preparing for the Merchant Fraud Alliance, which once this episode comes out, we will only be about five days away from. Which I if anyone knows me and outside of just the podcast, you know that this has consumed me for several months. And I'm really excited for it to be here. I've kind of been joking that it's going to be like my second wedding because I'll know so many people there and want to talk to everyone. But I feel a little selfish about that. But the cool thing is is that everyone else gets to meet each other, which isn't always the case. So, um we have a lot of great senior leaders coming from uh very large organizations in e-commerce uh and marketplaces that I'm very humbled that they're making the trek to Chicago. Um some of them live there, but a lot of them don't. And the reason I brought up MFA is because I've been talking to so many uh merchants getting ready for it. Uh whether that's to prepare for uh speaking uh presentations, panels, people asking questions about you know the conference.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
02:48
As well as I just recently had my merchant collaboration call that we do monthly. Uh it used to be just tailored to retailers and we opened it up to all kinds of merchants. So we have some in travel, we have some in event ticketing, we have some merchants in marketplaces like digital goods marketplaces, not just uh those that ship physical goods. And there's been a lot of talk about AI attacks. There's also been a lot of talk about using AI to fight fraud, which we're doing a whole 4 hour boot camp uh the day before MFA for merchants on that topic. You know, using generative AI to do a lot of things within fraud operations. Sometimes it's identifying fraud, other times it's evaluating the performance of your analysts. Or creating a dashboard with alerts uh for various metrics. Some merchants are using it to tailor their uh chargeback response documentation and seeing some good results. There's just a lot of different ways that merchants are using AI and I know that banks are as well. But today's episode's going to be focused mostly on AI attacks. One statistic that I came across this week uh regarding AI fraud attacks is that card testing um with e-commerce merchants is now up over 75% according to at least one merchant of fraud provider. And that's because it you don't have to do it manually anymore. You know, card testing used the long time ago when I started in fraud, it was just, you know, one person or a group of people plugging in card numbers and testing them one at a time. Well, now they can just upload a spreadsheet of card numbers and, you know, card holder name, address, etc., and find a website to attack or target and just run them up. And we see that a lot. Um, and we're seeing that a lot more because it's faster and cheaper for them to do it. They're also identifying more patterns than even we can sometimes when we're looking at payment acceptance. And that's more on the payment side, but I spent some of my life on the payment side, so I'm familiar with that. You know, a lot of uh payments people spend a lot of time and money on trying to optimize payment authorization. Well, fraudsters are doing the same thing.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:13
Looking at bin numbers, looking at, you know, various different pieces and data of the transaction to determine how they can increase their authorizations on your website. So, they're not just looking to find cards that are valid to then sell or use for higher dollar transactions. They're also gaining all of this data rich information by running these transactions. So, um I think we're going to start to see some merchants being hit with fines for those card testing. Because, uh from the view of the network, it is up to the merchants to prevent card testing. So, I think everyone listening knows, you know, what card testing looks like, but it's generally low dollar transactions with just a high volume of transactions all at once. Usually, especially using AI, they can be seconds or milliseconds apart from each other. And what they're doing is they're using your site as a feedback loop. They're determining from what you say if the transaction goes through or if it's canceled at the time of payment. That tells them if the card is valid or not. Once they know a card is valid, they can get more money for it or if they sell it or they can then look more legitimate at the next merchant that they place an order with. Because they won't see a whole bunch of declines as well. That is one of the markers of card testing is, you know, just as many declines as there are authorizations. So, that was just one piece of information that I ran across on LinkedIn this week about just one method of AI attacks. I know in speaking with online merchants and I know banks are seeing the same thing. They're also seeing AI enabled account takeovers AI enabled fishing to their customers to get the credentials to then take over an account. It is being used in full force and uh that's what I want to talk about today. Uh with one exception. So there's one article that isn't so much about AI specifically. However, we rarely get a glimpse into when merchants are having fraud issues.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:26
Uh, and we recently saw an article, and I talked about it, I think in our last fraud news episode, actually last month. Where Hims and Hers, the company that provides GLP1 and other health supplements for men and women, obviously, um, online. How they're in the, um, Visa chargeback monitoring program and how rare that is. Well, now we're getting to see a glimpse into this other merchant that is getting hit with fraud really heavily. And it's an interesting type of fraud because it's it's more than card testing. They're actually cashing out on that same website. So, typically, uh, when an e-commerce fraud happens, they're making a purchase on one website and cashing out on another or cashing out in person. Maybe they order an iPad, right? It gets shipped to their address or to an address near them. They pick it up, then they go sell it. That's how they cash out. That's how they get the cash for that, you know, stolen card transaction. In other cases, they'll, you know, book a hotel or entertainment tickets for a show or a sporting event and then they'll do that on one website and then on the other website they'll, you know, sell it in the secondhand market. But in this case, that the buying and the cashing out is happening on the same site. And the CEO doesn't seem to care. And I know a lot of fraud fighters might have a little PTSD when I read this article because we've all faced this. It, to some degree. I don't think we faced it to this degree. Not all of us have faced it to this degree, but it's a fairly new merchant and that's Poly Market. Poly Market has had a lot of scrutiny itself because it's essentially gambling on real world events. You know, whether a TV host on live TV is going to say a certain word or whether a politician is going to make a statement about something specific. I know there's a lot of investigations being had into, you know, politicians and basically insider trading. But they're not calling it insider trading because it's not.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
09:48
While it probably should be, it's not regulated um by the SEC as much as it should be. So, I don't know. I' I've listened to a couple podcasts about Poly Market, but that's about the extent of it. I've never used it, but you know, it's a betting website on real world events is just the shortest way I can explain it. The title of this in the Wall Street Journal is that Poly Market's rush to grow left a door wide open for fraudsters. CEO Shayne Coplan brushed off concerns about schemes involving stolen debit cards. Now, the prediction market is bolstering executive ranks as it eyes IPO. So, they want to go public, but yet they have a lot of fraud and that could be an issue. So, this article was published on September 19th. And it says, "In February, a company processing debit card transactions for Poly Market's US betting platform delivered some alarming news. Fraudsters were flooding the app." That's not too uncommon for us to hear, but you know, it is for a new company, especially if they didn't already know that they could have fraud. They probably weren't expecting it or ready for it. Because a lot of startups aren't. Users were linking stolen debit cards to Poly Market US accounts, then trying to use them to make wagers and withdraw the money that they won from those wagers into clean cards or accounts that they controlled. Thieves tried to make off with at least $10 million. At one point, the processor rejected as fraudulent more than 80% of the deposits it was handling. A rate that far exceeded industry standards of roughly 1%. Poly Market employees quickly raised their concerns with chief executive Shayne Coplan, according to people familiar with the events. The compliance team, those people recalled, was floored by Coplan's response. Just keep growing and pay a fine if regulators ever find out. Current and former employees said Coplan's reaction, which hasn't previously been reported, was characteristic of his plan for Poly Market growth at all costs. Poly Market is doing everything in its power to woo new users and investors. And in the process, said current and former employees and investors interviewed by the Wall Street Journal. The high-flying company has struggled with compliance failures, legal challenges, and software blenders. Rates of fraud remained elevated for months after the February Attack. People familiar with the matter said, though they didn't again reach 80%. In the wake of the incident, executives left and an internal investigation began. No one in compliance wants to have their name on that. That's a big reason why they probably left. Uh former regulators from the CFTC, Justice Department and Internal Revenue Service, said the level of attempted fraud and Poly Market's response was atypical for the commodities and gambling industries. Unlike traditional commodities exchanges, Poly Market accepts funds directly from retail traders, making it more vulnerable to fraud attacks. So they accept funds directly from consumers, basically. In a regulated space, this kind of thing does not happen, said former CFTC enforcement lawyer Joe Konizeski.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
13:12
Something like that. You have adults who handle customer funds and make sure they're sourced appropriately and handled appropriately. A Poly Market spokesperson said that the company is committed to maintaining accurate, fair, and transparent markets and working with regulators and law enforcement. Our market integrity framework includes processes to detect, review, and respond to suspicious activity, the spokesperson said. Poly Market's legal challenges are mounting on several fronts. The Commodity Futures Trading Commission uh so the CFTC is investigating it. The employees have been told to retain records related to the fraud attack and other topics according to people familiar with the matter. And the New York City Council is probing the advertising processes practices of Poly Market and other prediction markets. And Poly Market has been accused in lawsuits of deceptive business practices by almost two dozen traders. At the same time, more than a dozen state lawsuits are focusing on whether Poly Market and its prediction market competitors such as Kelshi and Coinbase are unlicensed gambling platforms. The outcome of those cases could reshape the industry. As legal risks pile up, Coplan is in the process of raising a billion dollars in a fundraising round that would value the company at around $21 billion. Donald Trump Jr.'s investment fund 1789 Capital is investing roughly 300 million in the round in addition to the roughly 200 million it has previously invested. So particular fund will have invested half a billion dollars into Poly Market. Poly Market which has a data partnership with Dow Jones the publisher of the Wall Street Journal has been working to reposition itself to investors and the general public as a more mature company focused on responsible growth. Since May, it has added experience risk management staffers including a former FBI agent. The company has improved its compliance protocols and improved product testing according to a person familiar with operations. I would say that while it's great to, this is me talking not the article. While it's great to hire, you know, former law enforcement for fraud after the fact. For investigations to, you know, identify who's behind the fraud and then work with prosecutors to prosecute fraud. My experience is that the majority of people with law enforcement experience don't have any experience in the prevention side of fraud. They haven't worked with fraud tools to prevent fraud. They don't know the strategy there, or how the systems work, or you know what how to build a successful risk stack. That's just not their area of expertise. They are phenomenal at investigations work after the fact after the fraud has happened. But if that's the only person they've hired for risk management, that would concern me a little bit. Uh, in late June, Coplan visited the Hampton's home of 1789 capital co-founder Omeed Malik to strategize about how to professionalize Poly Market's operations before a potential initial public offering or IPO in the next year. According to people familiar with the meeting, Malik advised Coplan to hire more experienced executives. Poly Market recently hired its first chief financial officer, Warren Jeff Jensen, who was Amazon's CFO in the early 2000s. Following a journal investigation into a deceptive social media campaign, Poly Market restructured its marketing team, including hiring the founder of electric scooter company Bird as chief of growth. Other marketing employees involved in the social media campaign have left the company or had their roles shrink. Poly Market is rapidly growing and getting better every day. A spokesman for the company says, "We are proud of our key leadership hires and continuous infrastructure upgrades and have quickly scaled and remains focused on growing responsibly at the frontier of finance, tech, and culture. But they do say that like the CEO has a reputation for being unfiltered and intense. He's bullied employees. He's uh apparently he likes to use adderall and that's very widely known. He's pushed people to the brink.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
17:39
That type of thing. And he said some bad words on Twitter that I don't want to repeat. They do say here's the part that I was referencing earlier. As one part of its protection against money laundering attacks, Poly Market US employed a rule commonly used by financial exchanges. Funds deposited from one payment source were required to be withdrawn to that same payment source. Without such a rule, a thief could deposit money using stolen debit cards, trade with it, and then withdraw winnings to a clean card. That's exactly what they were doing in February. Federal regulations don't require prediction markets to follow that rule. Other brokerage and betting apps, including DraftKings and FanDuel, do so. Poly Market's chief competitor Kalshi doesn't, though the company inspects funds withdrawn to different payment mechanisms and freezes suspicious payments. A person familiar with that company's protocols said. I can actually say that I'm familiar with who Kalshi uses for some of their fraud prevention and I think it's it's one of the top leaders in the space. So that might be why they feel more comfortable doing that but they I'm sure they scrutinize those more. I'm not familiar if Poly Market uses a third party fraud tool or if they're just using internal engineering rules or what they're doing. By January of this year, Poly Market's US app was handling only a fraction of the volume of its mammoth international exchange. So, it has an international exchange, but they um have taken that part off and moved it into the US. Copeland wanted any potential friction for users gone even though the app was still in beta testing and had launched to only a limited number of users. Near the top of the list, make sure users got their money quickly. By February, a Discord chat for Poly Market users had filled with complaints about how long it took to withdraw funds. Employees reassured users that their money was in transit, but that compliance checks could hold it up for days or weeks. Engineering glitches on the US app added to the pain. So, in addition to having a lot of fraud in February, they also had issues with people withdrawing getting their their winnings back or their the money that they still had back. Uh, in February, the swindlers attacked Poly Market, linking stolen debit cards to thousands of new accounts. The payment processor, Checkout.com, told Poly Market. So, uh, now we know who their processor is, and they alerted Poly Market of that. Most of the attempted deposits failed, said one person familiar with the matter who attributed the majority of the attack to seven users. One of whom attempted about 4,000 deposits. That tells me that their fraud stack is not very mature if they're allowing that many deposits to be made by one person. That could have changed since February, but that's what this tells me now, or at least at the time. Checkout.com, which continues to work with Poly Market, declined to comment on the incident or its relationship with Poly Market. Yeah, they probably sent an NDA. The attack overwhelmed the compliance staff backing up withdrawals further. Which is why it took so long for money to get back. Uh to get money back to customers faster, company leadership decided to scrap the rule requiring same source withdrawals. Even though some employees warned that it could open the door to money laundering. According to people familiar with the discussions, executives maintained that the other protocols in place were sufficient. Failure to adequately police money laundering could violate federal laws about money laundering, illicit transmission, and possibly bank fraud. Uh former federal prosecutors said the CFTC and the Justice Department have prosecuted firms including crypto exchanges like BitMEX and Binance for violating such laws. And some fines have extended into the hundreds and millions of dollars. Poly Market is subject to less stringent anti-money laundering regulations however. Their US chief compliance officer resigned in April after sending a lengthy report with an overview of some of the fraud issues to company executives. According to people familiar with the report, both Clifford and Poly Market declined to comment about his departure. Around that time, Poly Market closed a billion dollar investment round that valued the company at nearly 15 billion. And now they want another billion to value their company at 21 billion. Uh soon after Poly Market fired the US division CEO Justin Hertzberg and its head of US regulation and ant money laundering left. Hertzberg didn't respond to requests for comment and an investigation by the law firm Sullivan and Cromwell concluded the company had complied with regulations according to people familiar with the findings. Well, there's barely any regulations for them to comply with. So that doesn't necessarily mean that they're doing everything right. By May, Poly Market had brought fraud rates back into the industry norm. A person familiar with the matter said in part by limiting the number of debit cards that users could link to their accounts. The company also retained a new anti-fraud contractor, Riskified.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
22:59
Hm, that's interesting. That's a lot of pressure on Riskified for very fast high dollar transactions. Poly Market also has been trying to fix other problems stemming from the minimal testing it had done before rolling out new features. There's been platform issues and other things. Several people have been uh complaining that they can't get their money back. Poly Market has reimbursed some customers who suffered losses while others have worked with their banks to reverse unauthorized charges via chargebacks. Uh said a person familiar with the matter. Recently, it has improved its code review practices and hired more engineers. Copelan has pushed employees to create provocative new markets. For instance, how many times does Kanye West say a pretty bad, you know, word on his Twitter this week? Or, you know, other things. So, those are like some more provocative things you can bet on. Uh, letting users create their own markets could introduce new opportunities for market manipulation, said Rajiv Seth, a Barnard College economics professor who has studied prediction markets. Compliments pushed to make Poly Market a household name led to expensive deals with A-list celebrities. Oh, I guess in late July nearly 500 Poly Market users were victims of another fraud attack that appeared to exploit an engineering flaw. Uh, if a malicious actor attempted to create a new account using an existing trader's personal information, such as a stolen social security number, the hacker would immediately gain access to the trader's existing Poly Market account. Oh my gosh. And any of their linked bank accounts and debit cards without needing to know a password or a username. That deserves a face palm. Um, according to a person familiar with the matter who said the amount of money stolen was small. Um, that's crazy, but that yeah, it doesn't surprise me too much. Then they talked about the World Cup and how it's that. Anyway, it's a very long article. I apologize for reading as much of it as I did, but I think it's fascinating. It's always fascinating to me when the name of a company's payment processor and or risk provider is public.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
25:20
Made public in an investigative article such as this as well as just the fact that they have fraud and what the fraud attack was, right? What, which typography is impacting them the most. That's very uncommon for, you know, a few decades for the last two and a half decades that I've been in this industry. It's been very rare. So, I applaud the Wall Street Journal for doing this work because I think it's important. It's another way to hold companies accountable and especially new companies in tech that either don't understand the credit card and debit card liability laws or they just don't care and want to focus only on growth. This is what can happen. It's I hope that the new people in risk management that they've hired are getting a seat at the table. And getting to, you know, call out engineering mistakes such as the one I just mentioned or, you know, other things like that. I do think that having a rule that the card you use to fund the bet needs to be the same method of payment that gets the earnings of the bet back on it. I think that's a really good one for fraud. But Riskifi's going to have their work cut out for them because this is a pretty fraud business model. It just is. It's super risky. And what if somebody regrets their bet, right? What if someone bets $500 that, you know, a sports star is going to wear purple shoes at the next game. And they don't wear purple shoes, so they lost the $500. Who's to say they can't issue a chargeback on that? Uh for not as described or whatever else they want to do. Uh I think that they probably have significant chargeback issues for a lot of things, not just fraud, like I said, service and uh buyer's remorse as well. And they might have to learn a few more hard lessons if they're, you know, founder or lead executive isn't willing to put some guard rails in. And we know that guardrails don't have to apply to everyone. They can just reply to the riskiest transactions. That's, you know, the beauty of fighting fraud in 2026. It doesn't have to be with a blunt instrument anymore. It can be with surgical precision. So, I hope that they figure that out. I didn't mean to spend so much time on Poly Market, but I did really find it interesting, and I think those of you on the merchant side especially will, too. So, speaking about AI attacks, there's a couple of articles I wanted to share that are specific to AI attacking e-commerce or banks and just how it's being used for that. This next article is by AOL. Well, no, actually it was by Reuters. I'm sorry. I found it on AOL, but it was originally by Reuters. The title is banks warn that AI shopping bots or agent commerce will raise scam, fraud, and data privacy risks. I would agree with that on the surface, but let's read the article to see how you feel. So, uh, they're basing this article in Paris. Using AI agents for online shopping could increase the risk of scams, fraud, and data privacy breaches. Banks including Nat West and Bank of America said on Tuesday. As they set out principles for developing the technology. Technology companies including OpenAI, Anthropic, Google, and Meta are increasingly promoting AI chatbots as shopping tools. Envisioning a future in which shoppers use agents to select products and make purchases on their behalf. Retailers, meanwhile, are racing to influence chat bots recommendations.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
29:11
So, they want the chat bots to recommend the products on their website, not their competitor's website. British retailer John Lewis said in September that searches originating from AI agents had risen to 2.5% from just .3% a year earlier. Just three basis points. With the trend accelerating, I guess it's 30 basis points. Uh still it's not a lot. So just in one year for it to go up 8x more than 8x, that's pretty that's pretty significant. The group of banks which also includes ING New Zealand's ASB bank US lender Capital 1, Commonwealth Bank of Australia said in a report that customers were enthusiastic about the potential of Agentic commerce and keen to enable it. However, they warned that the technology was advancing faster than industry standards and consumer protections. Which is incredibly true, especially in the US since the current government has decided not to put restrictions on it at all. Uh, consumers are unclear if AI will act in their interests, the report said, they are concerned the AI agents may buy the wrong thing or spend too much or even worse, lose their money to scams and fraud. They are not sure whether they will be protected or who they will need to go to if things go wrong. I think that's especially true if someone instructs their agent to find the cheapest price and that agent doesn't take into account the not only the like the legitimacy of that website, right? Is how long has it been there? When was it, you know, first established? Are the prices just way too low and not, you know, even remotely close to reality. Or are they just going to go for the cheapest item? And often times, you know, those websites that have cheap items on it will never ship you the goods. They'll charge your card, but then they'll never ship you the items and next thing you know, you can't find the website. Uh, so I agree with that. I think this is going to be a big problem for agentic e-commerce. The report highlighted risks including AI agents requesting customers card detailers details and entering them directly into websites or steering users toward payment methods that offer weaker protections. The bank's plan to discuss a series of proposals with policymakers, including requiring disclosures when an AI agent is involved in a transaction, greater transparency over how AI agents make decisions, and safeguards to protect customer data. Consumers and merchants should also be free to choose which AI powered e-commerce services they use, while different systems should be interoperable, the report says. So I think this is great that banks are calling attention to it. However, the people that are really in charge of this, you know, being the case and the liability as well as the data privacy and the safety of agent commerce is actually the platforms and and it comes uh but also the networks have been involved because they want to be involved in the protocol piece. Uh when I was at SardineCon last month, it was about five or six weeks ago now. Uh there was someone there from Visa. And he was saying that there have been a lot of conversations with a lot of tech companies that are providing generative AI and agentic e-commerce in trying to set up these protocols. Because merchants especially are very nervous that you know if someone sets up an AI agent but to buy something and it's not the thing that they wanted or they change their mind they can issue a chargeback. And currently there are no provision provisions for merchants to be able to win chargebacks when an agent is involved. So, I will continue to say that until I am a dark color blue in the face. I really think that that needs to be highly considered uh the liability as well as how merchants can defend themselves and regain some of the funds if they do receive those types of chargebacks. Because if the AI platform makes a mistake, I think the AI platform should be responsible for the chargeback. However, with current Visa and Mastercard rules and regs verbiage, that's not the case and it won't be. So, that's why I brought this article up. Next, it's a article in uh Georgia. And it says, "A whole new horizon for us in quotation marks. Police make first arrest in AIdriven fraud case in Chatham County.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
33:58
So, the chief of police is warning the AI is being used to create fake orders, QR codes, and even cloned voices for scams. Unfortunately, we know this all too well. Uh, but I have a couple things to add to it. So, Chatham County police have made their first arrest involving artificial intelligence fraud. According to the department. Police said 20-year-old Dion Love posed as a delivery driver at the Walmart uh on a road I can't say uh using a fake AI generated Spark order in an attempt to leave the store with a Nintendo Switch and other electronics. So, I believe Spark is Walmart's delivery system and uh either for pickup in store or for delivery. It sounds like he picked it up in the store possibly for delivery. And he was using an AI generated order to try to attempt the warehouse or the store. So, um, he went in said, "Hey, I work for Spark. I'm a, you know, driver for, like on behalf of Walmart, kind of like an Uber driver. And I have this order for a Nintendo Switch and other electronics that I need to fulfill. In order to deliver to this person who ordered via your website. And thankfully, Walmart was like, "That doesn't look right, and it's not in our system." But he tried and it was you know at least somewhat successful for you know them to identify it in that way. Then the police chief went on to say, and because he persisted an off duty police officer there detained him and we got called there and we ended up making an arrest. It's a whole new horizon for us so to speak and we're just now learning of these scams and how we go about addressing them, Hadley said. The chief says that retail fraud is just the start. Hadley said retail fraud is the only is only part of the problem. He said, well AI can help businesses with automation images and videos. Criminals are using the same tools to commit crimes including replicating voices. Something we've talked about here. Uh AI has the ability to create fake requisitions, fake orders, fake QR codes in order for people to proliferate criminal activities. Hadley described how AI generated voice technology could be used to defraud victims. I think we already know this, but um he said, "For example, I get your voice, I find out who your mother is, and then I call and utilize AI technology to replicate your voice and say, I need money. I'm in jail. You know, create a panic. Your mother's going to say, Oh, gez, I need to help my son. And sends money and something like that to defraud them out of money. Uh, thinking that they're helping their own son out. Police are working with national think tanks. He says, Hadley said his agency is meeting with national police think tanks to develop new tactics for investigating AI-driven crimes. Hadley urged the public to verify information before trusting it. And that's where I want to stop today. I think that there are plenty more AI attacks. There was another one using ad software posing as HBO. And get basically fishing for credit card details. Um, and they were using AI to boost their ads as well as uh collect all of that information. But you guys get the hint, right? Like AI is going to be here to stay. It's going to just keep refining over and over again. I have heard a few stories of, you know, AI adapting in real time to various fraud rules or, you know, uh, stipulations within the risk stack. And something to watch out for is that they're figuring out how to manipulate all of the things that you've put in place to try to identify them. So, we need to be aware of that they're using AI and they're doing it more often. And that it's going to look believable in a lot of cases um in order to catch them. So, that's what I wanted to focus on today. I'm really excited about MFA, guys. I'm I'm bummed if you can't go this year. I hope that there's going to be a next year. We are waiting to make that decision until we know how successful the first year is. Um, but I just really am humbled and grateful for all the support we've gotten so far. Even some people that can't come have just written me the kindest notes about how they know that this has been on my heart for a long time. And that they're really excited for it. So, I appreciate that. I will see some of you at MFA. I, you know, sometimes people listen to my podcast when they're on the plane. So, maybe you're listening to this on the way to MFA. But I'm really excited about it. I appreciate everyone who's been so supportive. And I will be back next week with an interview and then the week after uh with kind of a a debrief or a download of some of the hottest topics discussed at MFA. So, I'm looking forward to that episode. I already know what some of the panels are going to be and I mean I'm telling you some of these prep calls for speakers I am like there's going to be so much good information. And and at a senior level too it's not all entry level. So I am very excited as you can tell. Uh but I am going to be done for this week. I appreciate all of your support. I've gotten a couple of really nice notes in the last week uh from listeners. I really appreciate it. Um that's what keeps me going. Uh that's what uh keeps my guests wanting to come back as well. So really appreciate that and I will talk to you more next week.