SardineCon SF/2026

Learn More
Fraudology

Quarterly fraud report 2026: Catching today’s fraud while preparing for tomorrow’s schemes

41 min

Welcome back to Fraudology.

Every once in a while I come across a report that makes me stop what I was planning to talk about because it's just that important. This is one of those weeks.

Matt Vega recently released his quarterly fraud report 2026, and after reading it, I knew we needed to break it down together. Not because it's predicting what might happen next year. Because every attack covered in this report is already happening.

One of the biggest themes running through the report is that fraud is simply moving faster than fraud teams are. AI is making sophisticated attacks cheaper, easier to launch, and much harder to detect. Criminals no longer need deep technical skills when they can rent the tools they need through fraud as a service marketplaces.

So what does that actually look like?

In this episode, I walk through several of the newest fraud tactics already showing up in the wild, including malware hidden behind fake unsubscribe links, banking malware that can piggyback on a customer's trusted device, and session hijacking techniques that make account takeover fraud incredibly difficult to detect using traditional fraud detection models.

At first glance, many of these attacks look legitimate. That's exactly the problem.

We also talk about why fraud teams can't rely on individual trust signals like device intelligence, IP reputation, or even behavioral analytics by themselves anymore. Criminals have learned how to blend into legitimate customer behavior, which means our approach to fraud detection and fraud prevention has to evolve too.

This is where things get interesting.

One of my biggest takeaways from Matt's report is that the answer isn't one new tool or one new model. It's layering better fraud intelligence, sharing information across consortium networks, and understanding the broader cybercrime trends happening outside your own organization. Because by the time a new attack reaches your queue, there's a good chance another company has already seen it.

I also spend a few minutes sharing an update on the Merchant Fraud Alliance conference, including our new AI bootcamp that's focused on practical ways fraud teams can start using AI in fraud prevention today. Not because AI replaces fraud analysts, but because it helps good teams move faster.

If you work in merchant fraud, banking fraud, online fraud, or e-commerce fraud, this is one of those episodes that will help you recognize the patterns before they become your next incident.

What you'll hear in this episode:

  • Why Matt Vega's quarterly fraud report 2026 is one of the most valuable fraud intelligence resources released this year.
  • How AI is accelerating modern cybercrime and making sophisticated attacks accessible through fraud-as-a-service platforms.
  • A breakdown of several emerging fraud tactics already targeting merchants and financial institutions.
  • How unsubscribe phishing campaigns are being used to install malware and keyloggers.
  • Why banking malware is becoming increasingly effective at bypassing traditional fraud controls.
  • How session hijacking enables criminals to perform account takeover fraud from trusted customer devices.
  • Why device intelligence, IP reputation, and behavioral analytics all need to be evaluated together instead of independently.
  • How fraud intelligence sharing and consortium data help organizations identify emerging threats faster.
  • An update on the Merchant Fraud Alliance conference and its new AI in fraud prevention bootcamp.

You should listen to this episode if you:

  • Lead fraud, risk, or trust & safety teams.
  • Manage fraud prevention for an ecommerce merchant, fintech, bank, or payments company.
  • Want to stay ahead of the latest cybercrime trends instead of reacting after attacks become widespread.
  • Are evaluating how AI is changing both fraud prevention and AI fraud.
  • Build or manage fraud detection models.
  • Investigate account takeover, synthetic identity, or online fraud.
  • Want practical fraud prevention best practices instead of theoretical discussions.
  • Rely on device intelligence, IP reputation, or behavioral analytics as part of your fraud strategy.
Episode notes

Matt Vega's quarterly fraud report 2026

If you’ve listened to the podcast before, you know I’ve always appreciated the way Matt approaches fraud intelligence. He spends his time looking where most of us can’t. Monitoring criminal communities, following emerging techniques, and connecting patterns long before they become mainstream attacks. That perspective matters because fraud doesn’t arrive with a press release. It starts quietly, spreads quickly, and by the time most organizations recognize it, criminals have already moved on to the next tactic.

The report reinforces a growing reality: fraudsters no longer need advanced technical expertise to launch sophisticated attacks. AI-powered tools, rented malware, and fraud-as-a-service platforms have dramatically lowered the barrier to entry, allowing criminals to scale attacks faster than ever before.

The report isn’t full of predictions or hypothetical scenarios. These are active techniques already being used against financial institutions, merchants, and lenders today. The value isn’t just knowing they exist. It’s understanding how they work so you can recognize them before they become your next incident.

Three emerging fraud techniques

Let’s break down three attacks that really stood out to me.

  • AI-generated unsubscribe phishing campaigns that deliver keylogger malware.
  • Banking malware that disguises fraudulent activity by routing transactions through legitimate customer devices.
  • Session hijacking attacks that allow criminals to perform account takeover without triggering many traditional fraud detection signals.

Many of the signals we’ve traditionally relied on such as device intelligence, session history IP reputation, and behavioral consistency can all appear normal.

And that’s why these attacks deserve attention.

Modern fraud detection requires multiple layers of intelligence working together

A big theme running through Matt’s report is something I’ve talked about on this podcast for years. There is no single signal that’s going to save you. Attackers continue finding ways to mimic legitimate customer behavior. Criminals are increasingly finding ways to turn our strongest trust signals into weaknesses. They’re hijacking trusted sessions, borrowing legitimate devices, and using AI to automate attacks at a pace that individual companies simply can’t match.

The strongest fraud prevention programs don’t rely on one model or one rule. They combine multiple sources of intelligence, continuously validate trust signals, and look at the broader context instead of making decisions based on a single indicator.

Merchant Fraud Alliance Conference

A quick update on something I’m incredibly excited about. The Merchant Fraud Alliance Conference this October in Chicago will have one session I’m especially looking forward to.

Our AI Boot Camp isn’t going to be another conversation about whether AI matters. We already know it does. Instead, we’re focusing on something much more practical: how fraud teams can use AI in their day-to-day work.

We’ll be covering real prompts, real workflows, dashboards, reporting, investigations, and practical ways fraud professionals can use AI to become more effective.

Not to replace expertise, but to amplify it. That approach reflects the entire philosophy behind Merchant Fraud Alliance.

Everything on the agenda is designed to help fraud professionals leave with ideas they can immediately apply when they get back to work. And honestly, that's exactly the kind of conference I wish had existed years ago.

Key takeaways
  • The quarterly fraud report 2026 focuses on real attacks already affecting organizations today. Not future predictions.
  • AI is making sophisticated fraud attacks faster, cheaper, and more accessible.
  • Fraud-as-a-service continues to accelerate the growth of organized cybercrime.
  • Banking malware and session hijacking increasingly exploit trusted customer devices to bypass traditional fraud detection.
  • Account takeover fraud is becoming more difficult to identify using individual trust signals alone.
  • Strong fraud detection models combine behavioral analytics, device intelligence, consortium data, and fraud intelligence.
  • Sharing fraud intelligence across organizations helps identify new attack patterns earlier.
  • Fraud teams should continuously monitor emerging cybercrime trends to improve detection and response.
Final takeaway

The tools criminals are using continue to evolve, and many of the signals we've relied on for years are becoming easier to manipulate. That doesn't mean those signals have lost their value. It means they work best as part of a layered fraud prevention strategy rather than as standalone indicators.

For fraud fighters, staying informed is becoming just as important as improving detection. Reports like this help us recognize new attack patterns before they become widespread, giving us an opportunity to adapt instead of simply reacting.

Because at the end of the day, the goal isn't just catching today's fraud. It's preparing for tomorrow's.

Connect with Karisse Hendrick | LinkedIn

Host of the Fraudology Podcast

Award-Winning Cyberfraud Expert

Ecommerce Fraud Prevention Consultant

Startup Advisor, Keynote Speaker, and

Consultant to Fortune 500 merchants

Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:05
Welcome back to the Fraudology Podcast. Well, for those of you that are listening, everything sounds the same. For those of you that found me on YouTube, I'm gonna be honest, this is a little weird. I had my first episode on YouTube last week with Mark Portius, and that was easier because I've done webinars before, I've worked with other people before. It was just a conversation with a friend, right? And it just happened to be on camera. But now I'm talking by myself to myself, and I can see myself doing it, and that's a little strange. So bear with me. For those of you on YouTube, please bear with me for the next couple of weeks. We're still figuring out lighting and position of the camera and all of those things to try to make this easier for you to watch. I've been hearing for years from people who have wanted to watch or listen on YouTube and I've put it off long enough. And thanks to the encouragement of the team at Sardine Media, I they made it happen. Really, they did 95% of the work to make sure that this happened. And if you haven't checked out the new Fraudology website yet, which will be in the show notes, as well as I posted about it last week on LinkedIn, definitely take check it out. We've got every single episode. So all four hundred I guess today is four hundred and thirteen. So all four hundred and thirteen episodes where you can look, you can find the transcript, you can find a summary, you can find takeaways, there's you know links to connect with the speakers on LinkedIn. It's really cool and really amazing that they were able to do all of that. So make sure that you check that out, especially. You know, of course I want you to listen, but if there's a week where you're like, I can't listen, but the topic looks good. I'd love to know what it was about. Go check out the summary. It's, you know, just a couple paragraphs, and then there's some bullet points afterwards for takeaways and things like that. So that's my plug for this new platform and all of that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
02:21
Again, I'm just so grateful to the Sardine team for going above and beyond what a sponsor does to make all of this look even more professional than I think that it is. Anyway, so before I dive into going over, so today I'm gonna go over part of a quarterly report that our good friend Matt Vega just put together and released and published. Matt, as if you've heard him on the podcast before, he really has his ear to the ground when it comes to dark web stuff. So not that cyber criminals really operate on the dark web anymore, but what I mean by that is, you know, the people that he understands what the criminals are doing and it's often the tactics that we don't know about yet, those hardcore sophisticated cybercrime tactics that we haven't we don't have a name for yet or we haven't identified in our systems yet. Those are the things that Matt really specializes in because of his background, with the military and then with a certain agency with three letters that I'm not allowed to say publicly. As well as, you know, his time at Sardine, Matt is now at point predictive working closely with Frank McKenna. Which what a powerhouse duo that is. So Matt put this together for Point Predictive and it's really the top ten fraud tactics in cybercrime that we don't know about yet that we need to. And he's got it broken down by banking, you know, credit and lending, you know, who the targets are. And we're gonna go over the ones in cyber fraud. There's I think three. Three in the cyber fraud section. So that's what we're gonna do for today's episode. But first I just want to give a little bit of an insight into what's going on for the Merchant Fraud Alliance. I haven't talked about it in a couple weeks.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
04:30
Mostly because I've been heads down working on the agenda. It's unorganized, but I currently have two large foam boards to the left of me with post-it notes of all the sessions that we're having, all the educational sessions that we're having. And it's now my job to assign speakers to each each session. And that's really what I've been head down working on that for the last few weeks. So, haven't been talking about it, but one of the things I wanted to highlight was actually, you know, the conference is October 6th and 7th in Chicago. But on October 5th, what we're kind of calling day zero, we're having a boot camp. And that boot camp is for you know, merchants only. It'll be for about 50 merchants. There's an e-commerce merchant that has an office in The Willis Tower, where we're having the conference on Tuesday and Wednesday. And they have graciously offered us the a large conference room to do this boot camp so that the rest of our team can set up for the conference for Tuesday and for Wednesday. But anyway, it'll be at the Willis Tower and AI boot camp can be so general, but you know what we came about was when we were talking with the ambassadors and figuring out what they think merchants need to know and what they, what they wanted to learn and what they wanted their teams to learn more about. We identified utilizing AI to fight fraud. There's some e-commerce companies that have mandated across their company that all employees must be utilizing AI, you know, whether it's Claude or it's Copilot or Chat GPT, that they need to be utilizing often the enterprise solution. They need to be utilizing it for 25% of their job or more. There are other e-commerce companies that have set up a kind of a working group to review any company that claims that they do AI.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
06:45
To verify that they actually are using AI and that they're not just saying that because it's a buzzword. So different companies are handling it different ways. But what it comes down to is there's also this piece where we're watching colleagues of ours in the industry lose their jobs, either to the fact that their employer thinks that they can be replaced by AI. You know, they haven't been yet, but they think they can, or they're you know, in the US, they're outsourcing to overseas. We're watching that happen and I think a lot of fraud people are saying, well, I need to get with the times so that I don't lose my job. And that's not to say that the people that were laid off if they you know had implement integrated AI into their job for 25% of the time or whatever, that they wouldn't have been. But there's a lot of people who want to utilize AI in fighting fraud, whether that's running reports, creating dashboards, identifying new fraud vectors, all of those different things, you know, new data sets, upgrading their machine learning to be AI internally, just all of those things. But they don't really know where to get started. And so there's two merchants that are gonna be leading this. I'm not gonna announce who they are yet, but they work for very large companies. And one of them specifically has been training their team over the last year to use AI and really to do more faster and to catch more fraud. And the goal of this boot camp is that you walk away with a takeaway. With prompts to use, with you know, the outline of a dashboard. Just with a greater understanding of how to use AI to fight fraud. And that's what those three hours on Monday is going to be dedicated to. So I want, I really, I can't stress enough how critical all of these sessions are to help you do your job better. That is our hundred that is our main goal, and we're knocking it out of the park with these topics and with these speakers, guys. It's pretty impressive.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
09:04
I'm very humbled at the people who have graciously accepted my offer to be part of this conference in the content piece. Some of them refuse to go to other conferences, so you can't see them anywhere else, but they're choosing to take risk on this first year. And I hope that you do too as an attendee because you're gonna have a lot of FOMO the first week of October if you don't. I can tell you that. But yeah, so we are limiting entry to the people who sign up and who first, so it's first come, first serve for that boot camp. We're getting close to capacity, but that's why I wanted to share about it today. If you do register at Merchant Fraud Alliance dot com, you can email me or message me afterwards or include it in your registration that you want to be part of the boot camp. I think there's a part that you can check for that. If you want a discount you for a ticket, message me on LinkedIn. I've got a handful of 50% off discounts that I'd love to hand out to Fraudology listeners. And just a reminder that we're not selling vendor tickets. We are only sending selling tickets to merchants. There will be vendors at the conference, but they're sponsors of the conference. And that sold out months ago. So we only have 15 companies that are vendors that will be attending. That's I think the way it shakes out, it'll be about 47 vendors and the rest will be merchants. And our hope is to have, you know, four or five merchants to every one vendor. So that it's easier to identify your peers and that you can have really good conversations with the solution providers that are there. Rather than feeling like you're a continual target. So for those of you who want to come to the conference, just a reminder that you do have to be working for a merchant or have most recently worked for a merchant if you're laid off.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:13
Okay, that was probably a lot longer than I meant for it to be. I hope my editor kind of like makes that a little more succinct. He's very good at that. Sometimes I ramble and he's, he's good at kind of tightening it up a little bit. But I could honestly talk about the content for MFA for a long time because I'm just so proud of it. And I think I'm proud of it because it came from merchants. Instead of putting out a call for speakers and saying, “What do you want to speak about in six months?” We asked our audience. We asked merchants, the people that will either be there or their peers will be there, and said, “What do you want to learn about?” What do you need to learn about? And that's how we built the agenda. So I'm proud of it. And that's why I'm rambling. All right, let's talk about Matt Vega's report. It is lengthy. I will say that. It is in-depth and lengthy. So you definitely will want to download it yourself or I think, you know, the first page you can read without anything. And then at least for me when I got to the actual report after the executive summary, it just asked for my name address or not my address, my email address. So my name, my email address and the company I worked for. I think that that's just so that the next quarter that Matt releases it, he can email it to you. He's not gonna sell the data or try to sell anything to you. I will make sure that there is a link to this report in the show notes. But it's also on the Point Predictive blog. Like I said, Matt joined Frank about a month and a half ago, I think. He love the way he did it at Sardine. I think he was there for four years and did a lot to really build it up and make it a you know, great and really relevant. But he wanted a new challenge and Frank was looking to kinda focus more on his Frank on Fraud duties than having a full time job at Point Predictive and work on Frank on Fraud. So it was a win-win. I had the pleasure of giving Matt a raving recommendation when Frank called me about it. So it's their dynamic duo and just having the time of their life geeking out every day on fraud. But anyway, this report I'm gonna read a little bit of what Matt says because it just gives context to why he did it. The kind of the title is Fraud is Officially Faster than Fraud Fighters. I would agree with that. And that is a very stressful statement. He goes on to say the trend that continues to worry me is the speed of innovation and collaboration of the attackers. As fraud fighters, it is more important than ever before to share what we're seeing, pass along our lessons learned, stay on the front lines of fraud threat intelligence, and lean into data consortium models for herd immunity. Attack on one protects all.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
14:35
I am now releasing this free quarterly fraud intelligence report to help my fellow fraud fighters and industry professionals stay aware of the ever evolving threats that we face. I spend hundreds of hours a week, or a quarter, diving into the deepest corners of the dark web, infiltrating rings and monitoring threat actors to understand the new exploits they are proposing, the ones they're working on and deploying against the industry. The most common theme this quarter: the people attacking your institution are no longer advanced cybersecurity black hats, engineers, or skilled fraudsters. They are a new generation of threat actors who combine the lack of extradition treaties with AI and rent a fraud tool. Providers, I call it fraud as a service, but same thing, rent a fraud tool providers to attack financial institutions and businesses with little to no recourse. Camera injection kits that defeat document checks, now sell for the price of a movie streaming plan. Banking Trojans are custom built to silence a specific bank's fraud prevention alerts before the money moves. And two-thirds of the flagship fraud AI models you hear about across the industry have been flipped into scams aimed at people trying to research or stop them. Nothing in this report is a forecast. All 12 vectors are active techniques we tracked from early dark web chatter. Into active or scaling attacks over the last quarter. Some will have already hit your queue this quarter, and you probably will never know. Others are going to hit your system in the coming months, following the traditional path of least friction. Every one of them is cheaper, exponentially faster, and far more advanced than the version you defended against last year.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
16:36
Wow, Matt, let's invite you to a dinner party. But it's all so true. And this is stuff that I talk about on a regular basis. I was asked to present at a top internet 50 company, I think, like very well known brand, last week, and really just to help them understand what they're not seeing and what they don't know and kind of that bigger picture of fraud. As I explained to them, they're the experts of the fraud that happens under their roof, so to speak. But it's helpful to understand what it looks like everywhere because, you know, you may not understand the other half of that fraud vector. There might be pieces of it that if you understood them, you could fight them better. It also is good because you're not going to be receiving every single fraud vector. And so what your peers are seeing, if you're not seeing it yet, you will soon. So when I was talking to this merchant, and it was a group of about 30 or 40 people from their risk team, they have a very large risk team because they have a lot of fraud, just like most large, well-known companies do. I do know of a few very large companies that have very lean teams, but their numbers kind of speak for themselves. They're hanging on by a thread. Not that always throwing bodies at the problem is the right way, but in this case, I think they see a lot of ROI on that. So I'm just backing up what Matt said. The biggest thing that I said was that they no longer need to have, you know, PhDs in computer science or, you know, be a skilled hacker, or even understand the ins and outs of your flow the way that fraudsters of you know previous years have. They'll study every single part of your flow, they'll figure out how to you know exploit a vulnerability and these days you don't need that anymore every piece of the puzzle to commit fraud against specific companies is out there for sale. And it's not expensive.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
18:55
You can get tutorials, you know, whether that's in book form or video form or a one-on-one coach, so to speak. You can get a fraud coach to teach you how to do fraud. You know, this fraud as a service thing, I remember really calling it out when I started to see it for refund fraud because I thought, man, if this starts happening for payment fraud, it's gonna be difficult to catch because you know it's no longer one guy trying to figure out all the ins and outs of several companies. It's several companies trying to figure out or you know, several small fraud fraudulent companies, figuring out the vulnerabilities of one company at a time. Matt goes on to say advanced threats and fraud vectors can do and hide from one financial institution, lender, dealership, merchant, or business. They cannot hide from a shared knowledge network like the lenders on Point Predictives Data Consortium. Where an attack on one triggers the fraud immune response that protects everyone. Once they attack one, the network learns, adapts, and builds up on that herd immunity. Improving detection and prevention with each subsequent attack just like your immune system. One of the reasons why Matt and I get along so well is because we both love analogies. Every attack vector in this report survives by staying nearly invisible to any single institution or business, making these exploits extremely difficult to detect without sharing networks and consortium models. A seasoned synthetic looks prime in one portfolio, but that same file in front of the full network of lenders and the community of enhanced data sharing pierces the network to show its true risk.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:47
As you read, ask yourself whether you would be able to detect or stop them in your own systems and controls. Industry collaboration, knowledge sharing, and shared data networks are more critical than ever before, and we are always happy to help provide guidance or show you how Point Predictive's data consortium models are leading the way for lenders across the industry. So, I of course, you know, need to talk about the company that he represents. Point Predictive is really good at helping dealerships, car dealerships identify synthetic ID. And a big part of that is their consortium model. A lot of times someone who steals a car from one dealership is gonna go steal a car from another dealership. They're gonna use, you know, fake documentation and fake bank account, you know balances and you know fake job pay stubs and everything else, and they're gonna go to different dealerships. So that's why he's talking about, you know, if you a fight a hit against one is is against all, right? We'll all find out about it if you use a data consortium. So they're all, you know, some are better than others. But I definitely recommend with at least one of your fraud vendors, that you do take advantage of the data consortium. There can be challenges. And I've been vocal about that over the years, but I agree with Matt that that is one tool that should be in your, in your fraud fighting toolkit.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
22:25
So there's twelve vectors. I'm gonna go through the ones that are impacting cyber fraud. I’m going to go through the ones that are impacting cyber fraud. We talk about the first trend in cyber fraud. He says it’s hiding in plain sight. And that is the annoyance to unsubscribe attack. And I didn’t know about this either. So that’s why I love to, you know, do this kind of research. And why I wanted to share it with you guys. I might have Matt back on the podcast in the coming months, but he was just on a couple well a month or two ago, right before he left Sardine, and I didn't wanna ask him again so soon, so we can learn from him this way. Attackers found a use for your annoyance. They flood you with the same email until you reach for the unsubscribe link, and that link is the attack. This is kind of scary. Anyone whose email address appears on the dark web list, which is more than ninety-five percent of all emails globally, are the key targets in this.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
23:30
So this was first detected by Point Predictive in June of 2026. So just last month. Criminals use AI to build high quality clones of I'm gonna start over there. Criminals use AI to build high quality clones of real company email campaigns. Then spam you with them many times a day from a lookalike address. The links are safe, real products, real sales. Real promotions. Click a product image and you land on the real website. Nothing bad happens. So it's not similar to Starkiller, like we talked about a few months ago. Then after the 21st identical marketing email that day, you click unsubscribe. That link carries a hidden malware redirect that drops a keylogger onto your device, capturing everything you type. Passwords, credit card numbers. Addresses, banking details. It's on his radar because it rides on legitimate campaigns and real URLs, and it uses annoyance as the method. Irritated people forget to check the unsubscribe link. That combination, because the emails look fine. They're legit. So why would you check the unsubscribe link? That combination is giving this attack the highest success rate we have seen in years because it hides in plain sight. Ninety five percent of all email addresses globally sit on a dark web list and that is the targeting.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
24:58
Signals to watch. A rapid or daily jump in marketing volume from a brand that rarely emails you. Copy the unsubscribed URL before clicking. A random string is the tell. So it would just be a lot of alphanumeric characters dot net or dot com. If you don't know how to copy a URL without clicking it, you just simply right click or you hover over the hyperlink. I don't know if we still call it that in 2026, but you hover over the link to unsubscribe. And sometimes you have to right click depending on your software, and then it will show you what the URL is that you'll be directed to if you click the button. So if it's a random string of alpha numeric characters. You know it's not for the merchant that they're, you know, trying to be or the bank that they're trying to be. Legitimate looking campaigns. So also look out for legitimate looking campaigns from addresses that do not match post marketing. So, you know, take a look at the email address that traditionally sends you emails, you know, marketing emails, and then take a look at the email address that sent you this one and determine if it's accurate or not. I've never thought about, you know, utilizing the unsubscribed link as the way to get malware onto your system with a keylogger. But it doesn't surprise me and I think it's really good to be aware of. The next one.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
26:39
Is Trickmo. Turns victim phones into clean exit nodes. Same real device, same IP, same city. Every signal your model trust checks out and a fraudster's behind all of it. That is very similar to the Starkiller product that we talked about on the podcast about a month, or a month and a half ago. Maybe it was two months now, but I was really worried when I found out about that because it was, you know, had a lot of potential danger. It looks like something similar is out there too. So the key targets are banks, credit unions, lenders, e-commerce, and exchanges that lean on device or IP as a key trust signal. As I think we all know, there's not just one key trust signal anymore, right? It's the combination that makes the difference. So what is it? A Trickmo variant, first tracked by Threat Fabric. And sold as malware as a service, re-engineers a banking trojan into a managed foothold. A built-in SOX5 proxy turns the infected phone into a network exit node. I'm saying N O D E node. That gives the fraudster the ability to route their own session through the victim's actual device and IP address. IP reputation and geolocation signals come back clean. In plain terms, the fraudster's activity flows through the actual card holder's real phone and your system reads it is safe.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
28:19
But it's on their radar because this attacks the fraud detection layer itself. The transaction originates from the customer's trusted device, network, and geography, which is exactly what many models, rules, and score risk scores use to lower the risk on a login and its activity. So by being able to glob on to the consumer's session and device and everything else, that looks legitimate. A lot of times these types of attacks are happening after another purchase. So what you'll have is customers calling your customer service and saying, “Hey, I made purchase one for $60. I didn't make not make purchase number two for $600.” There's no way I didn't make it, it's fraud. So customer service contacts the fraud department, they look it up to see if, you know, they missed something. And as Matt says in this report, everything that we hold, you know, is a weighted advantage you know, can be used against us. And so if we're using device and session and all of those in geography, you know, geo geography on IP, like geographic locations, then that can be used against us if the fraudster can just piggyback on the first transaction. This attacks the fraud detection layer itself. The transaction regenates from the customer's trusted device, network, and geography. Which is exactly why many models, rules, and risk scores use to lower the risk on a login and its activity. Think I might have read that twice. Sorry guys.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
30:07
Trick mode doesn't beat your fraud model. It dresses the fraudster in the victim's clothes. That's why invisible, when that's only visible when you're looking across a network or consortium, not inside a single portfolio, said Bill Hall, who is CTO and chief of staff. I don't know if that's for Point Predictive or not, but give him a shout out for his quote. Signals to watch. So, you know, you can't just cancel every transaction that has a safe device and a good IP address because there wouldn't be a company anymore. So instead the signals to watch are trusted device and IP paired with brand new behavioral metrics. Impossible spy simultaneous sessions from one identity or device. So maybe they make the per, two purchases at once on the same device and same session. That would be odd. Residential proxy or exit node indicators on a consumer line. And then another way to identify this is internal network recognizance coming from a consumer device. So if you're seeing any of those things across your network, or like I said, if you're having customers contact customer service to say, wait, transaction one was right, transaction two was not, or I logged into my account to change my address, and after I logged out, they then change the payee information to send me the check for people staying at my house on like a hosted, you know, travel site, for example. Those would be some indicators as well that you're getting hit with this.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
31:59
The Puppet Master malware that waits. All of this malware just creeps me out. Like it's just there's so much of it and it's really powerful, that it really worries me. And I think it should worry you as well. And I think knowing it's half the battle, when you know that these attacks are possible. You can then be able to diagnose it so much faster, once it's attacking your company. But also it makes you very relevant to other departments within your company where you can say, hey, there's a problem here. These, this is not a case of a customer making one purchase and then making a much larger purchase the next day or the same day. They haven't even gotten their products yet. So why would they know that they were happy and they wanted to order more? So anyway, those are all of the reasons why I think this is really important to talk about and also to just remember that malware can be scary. Here's the last one the puppet master malware that waits. This is a tricky one. The fraud operator waits and strikes mid session inside the real username's genuine activity, like a puppet master.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
33:20
The key targets are banks, credit unions, and online banking customers. So not as much e-commerce companies, but if you're in online banking or I would imagine crypto as well, this is important. So described in Barracuda's June 2026 analysis, this banking malware does not auto-fire. Disguised as a browser or security update, it lets a human operator watch a live banking session and pick the exact moment to act. Capture the session or take over midstream like a puppet master working a toy puppet. Because takeover happens inside the customer's own normal session, the fraud blends into their real behavior patterns and device signals. Detection gets very hard. Why it's on their radar? Bot and behavioral models are tuned for machine speed and or out-of-pattern actions. A human striking mid-session from inside the real user's activity generates almost none of those tells. So because they could identify account takeover when they weren't on the same session, they weren't on the same device or IP or anything else, it's really difficult. So unfortunately fraudsters are trying to bypass those. A human striking mid-session from inside the real user's activity generates almost none of these tells. It looks like the victim because in every tran technical sense it's the victim's session.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
34:54
So it's gonna you know, it's gonna look like friendly fraud, so to speak, or, you know, first party fraud, but it's not. So they do provide a call out between human-driven and so it says human-driven is an operator watching live and picks time the picks the moment that no machine speed tells. Mid-session, the attack lands inside genuine logged in activity, not the log E. Signals to watch for, high value actions right before, right after a software security update. Because the software security update would be the download of the malware. Session hijack indicators with no new device event or signal. So you've seen two checkouts on one account, an hour apart, and the local time is very, very late. And you know, all those other signals that you can combine, you should be combining to be able to identify this. Session hijack indicators with no new device event or signal, subtle mid-session shifts in cadence or navigation behavior, and a legitimate login followed by out-of-character movement in the same session. So those are things that you can look for to identify this. There is one more about international ghost tapping on the global remote contactless fraud that we talked about a little bit before Christmas. I think that we are the holiday season in November. I think that I have not done a good job of educating consumers or retailers with physical stores on this tactic. But it's important to be educated. So the very short answer I would say on this issue, that's impacting card not present merchants and remember they're on the hook for their own chargebacks. So they want to not be on the list, right? They don't want to have those they don't want to have any more. Inner but anyway.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
37:10
It's important just to know that contactless fraud can happen and you can get chargebacks from it. I have yet to hear from one of the merchants I reached out a few weeks ago. To see what happened when they called their acquirer and said, look, this was a ghost app. This was not true fraud. We need to go after these people. And in this case they knew exactly who they were because they had surveillance cameras from in store, they had their information. So that they could get loyalty points. But it's not always gonna be the case. So now that I've thoroughly depressed you, I do think it's so important though to be up on these tactics so that when someone in your company comes to you and is like, this is really weird. This doesn't make a lot of sense. You can recall something that you heard on the podcast or a webinar I do or a private presentation and be like, hey, is this affecting me? Like, am I not am I the problem, but is this something I should be concerned about? What are those signs? You know, can you look through my reporting and identify it? That type of thing. So I really want to thank Matt for putting this together. I had other fraud articles that I was gonna read this week. But then I saw this come out and I was like, no, we definitely have to dive into this. Because Matt always knows he's like three steps ahead of where a lot of us are with or a lot of, you know, online companies and banks are with the software that's able to detect that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
38:57
This helps you be able to detect them early. And really that's what it's all about is being able to be aware of them so that you can find them early. I want to, again, like I said, thank Matt for putting this together, knowing this stuff can help us stop them faster. It also shows a lot of patterns around how they're using AI, how they're using our own systems against us. The things that we have come, become reliant on, can no longer be relied on. And I think that the other big takeaway from all of this is how important it is to look from a 10,000 foot view. Not just look at the device, not just look at the session details, not just look at the behavior, but look at all of it together. And then also bring in your consortium data with the fraud provider that you use that for. Bring it, you know, you need we've been saying it for years, but you need to have layers. Because just one piece of this isn't gonna catch it. And as soon as they can identify that this works on your system, they're gonna go full court press and really hit you hard. So we don't want that. That's why we talk about it early. All right, everyone, I am gonna be done for the week. I really appreciate you listening to the podcast, all of your support. Thank you for watching on YouTube. Like I said, my I'm gonna try to have the back of my little shelf back here be a little more lit. I swear I'm not in a cave. I'm on the second floor of my house. But because I'm lighting my face, I guess the rest of it looks dark. I don't know. I don't know a lot about lighting and stuff like that, but I have awesome people around me that are helping me pick out the right equipment, which will just take time. But let me know what you hope that we talk about next. Let me know who you want to see on YouTube. Go check out that website that Sardine created if you just want a summary of an episode. If there was an episode that you really enjoyed that you wanted to share with your team. It might be easier to find it on the web when you can search the transcripts for keywords. There's just a lot of good things happening with Fraudology, and it's because you guys listen and you support it.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
41:15
So I really appreciate that. All right. I'm gonna look forward to speaking with you more next week. And next week will be a guest episode. So I won't have to stare at myself while talking for forty five minutes. Thanks so much for watching and for listening. Bye.