SardineCon SF/2026

Learn More
Fraudology

Monitoramento de Comerciantes Fraudulentos da Mastercard e o Problema de Alucinação da IA

Imagem para o episódio nº 405 do podcast "Fraud/ol/ogy", com a participação da convidada Dra. Nicola Harding e de Karisse Hendrick, mostradas em duas fotos de rosto.

Bem-vindo de volta ao Fraudology.

Estou falando com você de uma work-cation à beira-mar na Flórida para este episódio, logo após o Accertify Global Customer Summit. E sim, o cenário estava lindo.

Neste episódio, conto com a participação da Dra. Nicola Harding para falar sobre duas coisas que podem parecer separadas à primeira vista: alucinações de IA em fraudes e o novo programa de monitoramento de comerciantes de golpes da Mastercard.

Quando você olha mais de perto, percebe que eles estão ligados pelo mesmo problema maior.

As equipes de prevenção a fraudes estão sendo pressionadas a tomar decisões mais rápidas e complexas em ambientes onde os sinais aparecem cada vez mais cedo, a responsabilidade está mudando e as ferramentas que usamos para interpretar o risco nem sempre são tão confiáveis quanto parecem.

Isso é importante.

Por um lado, temos LLMs sendo usadas em gestão de risco, pesquisa de fraude e tomada de decisões operacionais. E, como discutimos neste episódio, isso se torna rapidamente arriscado quando a IA começa a produzir respostas confiantes a partir de informações incompletas ou de código aberto. Especialmente em fraudes, onde o conhecimento mais útil costuma ser proprietário por um motivo.

Por outro lado, o programa de monitoramento de comerciantes envolvidos em golpes da Mastercard cria uma estrutura muito mais rigorosa para identificar e investigar estabelecimentos que possam estar ligados a fraudes. Os novos limites, o monitoramento de reembolsos e estornos e o prazo de 72 horas para investigação de comerciantes exercem uma pressão real sobre os lojistas, credenciadores e equipes de pagamentos.

Então, este episódio é realmente sobre responsabilidade.

Quem é responsável pela decisão?

Quem valida o sinal?

Quem entende o contexto?

E o que acontece quando um modelo ou um programa de comércio é tratado como se pudesse funcionar sem a devida expertise humana ao seu redor?

O que você vai ouvir neste episódio:

  • O que o programa de monitoramento de comerciantes fraudulentos da Mastercard significa para comerciantes e adquirentes
  • Por que o painel de comerciantes de golpes da Mastercard é importante para as equipes de prevenção a fraudes em e-commerce
  • Como o monitoramento de reembolsos e estornos pode afetar as análises de risco de novos comerciantes
  • Por que o prazo de 72 horas para investigação do comerciante gera urgência operacional
  • Como alucinações de IA em fraudes podem distorcer a análise de risco e a tomada de decisões
  • Por que as alucinações de LLM são especialmente arriscadas quando o conhecimento sobre fraude é proprietário
  • Por que as equipes de fraude e de cibersegurança precisam quebrar silos à medida que os sinais surgem mais cedo no caminho de ataque

Você deve ouvir este episódio se você:

  • Trabalha em operações de fraude, risco de comerciantes, pagamentos ou fraude em comércio eletrônico
  • São responsáveis pelos limites de chargeback da Mastercard ou por fluxos de trabalho de investigação de comerciantes envolvidos em golpes
  • Precisam entender como o programa de monitoramento de comerciantes fraudulentos da Mastercard pode afetar sua equipe
  • Estão avaliando LLMs na gestão de risco de fraude ou em pesquisas sobre fraudes geradas por IA
  • Se importam com expertise em domínio, alinhamento entre fraude e cibersegurança e prontidão operacional

Se você gostou deste episódio, não deixe de assinar e avaliar o podcast no iTunes, Spotify, YouTube ou em qualquer plataforma onde você ouça podcasts. Isso ajuda muito a divulgar o programa.

Notas do episódio e principais aprendizados

Este episódio está na interseção de dois problemas de fraude muito diferentes, mas muito importantes.

O primeiro é o risco de alucinação de IA. Não aquele tipo engraçado em que um chatbot inventa algo inofensivo e todo mundo segue em frente. Quero dizer o tipo em que uma ferramenta de IA produz uma análise de fraude, citação, recomendação ou interpretação de risco confiante, mas que não está realmente baseada na realidade.

Isso é um problema.

As equipes de fraude não operam em um mundo onde todas as informações úteis são públicas. Grande parte da melhor inteligência contra fraudes está em sistemas internos, regras proprietárias, investigações, padrões de chargeback, históricos de comerciantes, dados de segurança cibernética e experiência operacional. Portanto, quando um LLM tenta raciocinar apenas com dados de código aberto, ele pode deixar de captar exatamente o contexto que mais importa.

O segundo problema é o programa de monitoramento de comerciantes envolvidos em golpes da Mastercard, que coloca mais pressão sobre os lojistas e adquirentes para identificar, investigar e agir rapidamente em relação a atividades de comerciantes ligadas a golpes. Isso não é apenas uma atualização de política. É uma questão de prontidão operacional.

E é aí que os dois temas se conectam.

As equipes de fraude estão sendo pressionadas a agir mais rápido enquanto os sinais de risco se tornam mais complexos. Isso significa que as empresas que se sairão bem aqui não serão aquelas que confiam cegamente em cada dashboard, em cada resultado de modelo ou em cada métrica superficial.

Serão aquelas que compreendem os sinais, validam os dados e trazem a expertise de domínio certa para a decisão.

Por que o monitoramento de comerciantes de golpes da Mastercard muda a pressão sobre os adquirentes

O programa de monitoramento de comerciantes envolvidos em golpes da Mastercard foi desenvolvido para identificar estabelecimentos que possam estar ligados a fraudes, atividades enganosas ou práticas de venda prejudiciais. Isso significa que o foco não está apenas na fraude tradicional em transações sem cartão presente. O foco é o comportamento do comerciante, os padrões de reembolso, os chargebacks, as reclamações de emissores, o desempenho de autorizações e se o comerciante aparenta estar criando risco para a rede.

Para os adquirentes, isso muda a postura.

Não basta esperar até que o dano seja evidente. Os adquirentes precisam ser capazes de investigar rapidamente, entender os sinais de risco dos comerciantes e decidir se um comerciante é legítimo ou precisa ser encerrado.

Esse é um tipo de pressão muito diferente.

  • O monitoramento de comerciantes fraudulentos pela Mastercard aumenta a necessidade de uma análise de risco de comerciantes mais rápida
  • Os adquirentes podem precisar de fluxos de trabalho mais robustos para investigar comerciantes envolvidos em golpes
  • As equipes de risco de comerciantes devem monitorar em conjunto os padrões de reembolsos, estornos e autorizações
  • A janela de 72 horas para investigação do comerciante torna a prontidão operacional fundamental

Por que o monitoramento de reembolsos e estornos é importante para novos comerciantes

Uma das partes mais importantes deste programa é a forma como ele analisa reembolsos e estornos em conjunto para contas de comerciantes mais recentes.

Comerciantes fraudulentos nem sempre aparecem por meio de um único sinal claro. Às vezes, o padrão é uma combinação de reclamações, reembolsos, estornos, baixo desempenho de autorização e um comportamento que parece apenas legítimo o suficiente para continuar operando.

À primeira vista, um reembolso pode parecer atendimento ao cliente.

Mas, quando você aprofunda a análise, os reembolsos também podem ser um sinal de que algo mais está acontecendo. Especialmente quando vêm acompanhados de reclamações, atividade de estornos ou mudanças repentinas nas taxas de aprovação.

Para as equipes de fraude, a conclusão é simples: não analisem esses sinais de forma isolada.

  • O monitoramento de reembolsos e estornos pode revelar padrões de golpes mais cedo
  • Novas contas de comerciantes podem precisar de uma análise mais rigorosa durante os primeiros seis meses
  • Os limites de fraude da Mastercard criam um incentivo ainda maior para monitorar o risco de forma contínua
  • As equipes de prevenção a fraudes em comércio eletrônico devem relacionar o comportamento dos comerciantes aos sinais de reclamações dos clientes

Por que alucinações de IA são perigosas na gestão de risco de fraude

Alucinações de IA em fraudes são arriscadas porque podem gerar confiança onde deveria haver cautela.

Um modelo pode resumir. Pode redigir. Pode organizar informações. Pode até ajudar as equipes a trabalhar mais rápido.

Mas se os dados de origem estiverem incompletos, incorretos ou faltando o contexto proprietário do qual as equipes de fraude dependem, o resultado pode se deteriorar muito rapidamente.

É aqui que a expertise em domínio faz diferença. Um profissional de fraude pode olhar para uma declaração refinada gerada por IA e perguntar: “Espera, isso realmente faz sentido?” Um modelo nem sempre sabe quando está atuando fora da sua área.

E, na gestão de risco de fraude, essa distinção é importante.

  • Alucinações de LLM podem distorcer a análise de fraude e as recomendações operacionais
  • Ferramentas de IA de código aberto podem deixar passar padrões de fraude proprietários
  • A experiência de domínio ajuda as equipes a validar se um resultado de IA é utilizável
  • A IA deve apoiar as operações de combate à fraude, não substituir o julgamento humano

Por que os silos de fraude e cibersegurança estão se tornando uma responsabilidade maior

Um dos principais temas que surgiram no Accertify Global Customer Summit foi que os sinais de fraude estão se deslocando para o topo do funil.

Isso significa que os primeiros sinais de risco podem não aparecer mais na própria transação. Eles podem surgir antes, por meio de atividade de conta, comportamento do dispositivo, phishing, malware, uso indevido de credenciais ou outros sinais de cibersegurança.

Portanto, se as equipes de fraude e de cibersegurança ainda estiverem atuando em áreas separadas, isso cria uma lacuna.

E os criminosos costumam gostar dessas brechas.

As equipes de prevenção a fraudes precisam ter visibilidade dos sinais que ocorrem antes do pagamento. As equipes de segurança cibernética precisam entender como esses sinais acabam se transformando em fraude de comércio eletrônico, fraude de pagamento, risco para o comerciante ou estornos.

Quanto mais conectadas essas equipes estiverem, mais cedo elas conseguirão perceber o padrão.

  • Os silos entre fraude e cibersegurança dificultam a detecção precoce de riscos
  • Sinais no topo do funil podem ajudar as equipes a entender a fraude antes da transação
  • A prevenção de fraudes em pagamentos funciona melhor quando as equipes compartilham contexto
  • A visibilidade multifuncional ajuda a reduzir pontos cegos nas operações de fraude

Por que a expertise de domínio ainda precisa ancorar a decisão

Este episódio volta sempre ao mesmo ponto: as ferramentas são úteis, mas é a experiência que ainda transforma informação em discernimento.

Isso se aplica a alucinações de IA. Aplica-se ao monitoramento de comerciantes fraudulentos da Mastercard. Aplica-se ao risco do comerciante. Aplica-se ao alinhamento entre fraude e cibersegurança.

Um painel pode sinalizar um limite.

Um modelo pode resumir um padrão.

Um relatório pode identificar um risco.

Mas ainda é preciso que alguém entenda o que isso significa.

É aí que os profissionais experientes em fraude são mais importantes. Eles sabem quando um padrão de comerciante parece errado. Eles sabem quando um limite de política precisa de suporte operacional. Eles sabem quando uma resposta de IA soa boa demais para ser verdade. Eles sabem quando diferentes sinais apontam para o mesmo problema subjacente.

O custo de errar nisso não é apenas um relatório ruim ou um fluxo de trabalho confuso. Pode significar prejuízos, responsabilidade legal, encerramento de contas de comerciantes, redes de golpes não detectadas ou decisões tomadas com base em informações que nunca foram devidamente validadas.

Conclusão final

O programa de monitoramento de comerciantes de golpes da Mastercard é mais um lembrete de que a prevenção a fraudes está se tornando mais conectada, mais sensível ao tempo e mais exigente do ponto de vista operacional.

Ao mesmo tempo, as alucinações de IA lembram que informação mais rápida nem sempre é informação melhor.

Portanto, a verdadeira lição não é apenas “preste atenção aos limites” ou “tenha cuidado com a IA.”

É isto: as equipes de fraude precisam de um contexto mais sólido.

Contexto em todo o risco do comerciante.

Contexto em fraude e cibersegurança.

Contexto em reembolsos, estornos, reclamações e comportamento de autorização.

Contexto entre os resultados de IA e o conhecimento proprietário que os modelos não possuem automaticamente.

Porque, em fraudes, as ferramentas podem ajudar você a enxergar mais.

Conecte-se com Karisse Hendrick | LinkedIn

  • Apresentadora do podcast Fraudology
  • Especialista premiado em ciberfraude
  • Consultor de Prevenção de Fraudes em Comércio Eletrônico
  • Consultor de startups, palestrante principal e
  • Consultor para comerciantes da Fortune 500

Guests

Dra. Nicola Harding
Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:02
Welcome to Fraudology Podcast, where we dive into the science and study of online fraud from the perspective of an ecommerce fraud fighter. I'm Karisse Hendrick. Welcome to this week's episode of the Fraudology Podcast. Well, if my background or microphone sound even just a little bit different, that's because I am not in my home office this week. When I ran into a merchant at a recent event I was at, which I will talk about in a minute, she joked with me that she never knows where in the world I am because either on the podcast or she's part of one of my biweekly merchant groups, often I have new backgrounds. I've been traveling a lot this year since February.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:45
I spent two weeks in Maui with my husband, which was just absolutely magical, and then I went to the MAG Conference in San Diego. A few weeks later, I went to MRC in Vegas. A few weeks after that, I went to Fraud Fight Club in North Carolina. And then after North Carolina, I went straight to San Francisco to see family friends and spend some time with them, and then back home. And then a few weeks after that, I flew into Tampa, but stayed in Saint Petersburg for the Accertify Customer Summit. So that's where I've been this week. I decided to make it a work vacation and, you know, was at the conference for three days, and then myself and a very good fraud friend who was also at the conference, we decided to stay a few extra days, rented an Airbnb on the beach with a private pool. I really don't want to leave. And it's just, it's been perfect weather. I think that's pretty, you know, pretty common for Florida, but it's a long flight back to Washington State. So I didn't want to just come for three days and then go back.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
01:51
Plus, you know, if you can do it, it's fun. And, you know, she and I have traveled a fair amount together over the years, so we split the house well and just do our own thing sometimes and then hang out and talk fraud other times. I'm sure if anyone staying at the condos next to us, there's like a condo building on either side of this house, they're probably really sick of hearing us talking about fraud, but that's okay. Anyway, today I wanted to talk about a few things. So one was I was going to give a little bit of a recap from the Accertify Customer Summit. I was very grateful that they allowed me to come and asked me to come, especially because that is a rarity. Usually it's strictly for customers. So there's a few things that I got out of it that I wanted to share, and there were also a few things I got out of it that I can't share yet, but will once I'm told I can.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
02:45
I'm also going to share with you a LinkedIn post about fraud and ChatGPT that kind of proves the point that both Holly and I were making on our previous episode just about data sources and things like that, and AI hallucinations and all of that, that I think could be really helpful if you are being told that you have to use an LLM for part of your job. I know there's a couple companies, they've been told they must be using an LLM, you know, a ChatGPT, a Claude, that's whatever it is for 25% of their job by X date. You'll want to probably share this story with your bosses if that's the case. So I will share that. And then we'll talk. The main topic I wanted to talk about is Mastercard's new scam program. If you're on LinkedIn at all, and if you're on fraud LinkedIn at all, you've probably seen a couple of posts about it over the last few weeks. It's kind of Mastercard's version of VAMP. It's very different, but it has similar goals. So I'll go through that program, and it has some pretty significant repercussions if you are included in that and if your metric gets you above a threshold.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
03:56
So I think it's important to be aware of if you are an ecommerce merchant, and even if you aren't, I think it's good to be aware of what the card brands are doing and what they're requiring of ecommerce merchants. So this is today's agenda. Diving into the Accertify Global Customer Summit, it was a great opportunity to network with about 150 people that work for merchant companies, merchant fraud fighters. If you're not familiar with companies that work with Accertify, I don't know which ones are public and which ones aren't. So I'm not going to name any, but I'm going to say they are primarily the largest brands in retail, in travel, in airlines, in some restaurants, a lot of different areas. But I would say 80% of their clients are household names. And Accertify is probably the longest running fraud tool out there.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
04:52
I remember when their very first sales rep came and pitched it to me when I worked for a startup in Seattle in probably 2009, right around there in 2008, 2009, something like that. And at the time I was impressed that they were building something like that, but it was very similar to what I had built with our dev team at the time for what we needed for our business model. So we didn't go with it, but it was impressive and it has since grown immensely since then. I was curious to know what was new for Accertify and got to learn a lot about that, as well as got to network with existing fraud friends and met several new ones. And my hope is that a lot of them will join us at the Merchant Fraud Alliance in October. That would be a lot, a lot of fun. I hope every merchant joins us at the Merchant Fraud Alliance in October. But I specifically, you know, one of the reasons I went to this event was to get the word out a little bit more. So it was a great opportunity for that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:54
They had a lot of networking opportunities, a lot of fun mixed in with sessions. And, you know, some on the big stage, some in breakouts, some were trainings, some were trainings on their new products, some were topics that people really care about in this industry and that, you know, they wanted to learn more about. Of course, AI was a topic of conversation. The theme of the event was how cybersecurity and fraud are better together, really talking about how fraud signals are moving up funnel. They're not just at point of checkout anymore. So there's a lot of fraud signals, especially for account protection, whether that's new account protection or account takeover protection, that type of thing, that live up funnel. And therefore, you need to make friends with your cybersecurity team. And they released a proprietary survey that they had commissioned that had a lot of really great benchmarking metrics that I've never seen published before, especially around cross-functional organizations working together. And they correlated that with their customers' fraud statistics. So like approval rate, chargeback rate, fraud rate, etcetera, to really demonstrate that there is, at least, a correlation, if not a causation, between cybersecurity and fraud working together and, you know, good outcomes in fraud metrics.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:22
So that's probably, I'm not saying anything specific, but that's probably all I can say for now. I did ask permission to share some of the statistics, and they said I absolutely can once the study is published, which will probably be in June. So you can look forward to that episode. I was really impressed with the questions they asked and the answers that came out of them. There's some good strategic direction, not only for this topic of fraud and cybersecurity working together, but for other things that we've all been asking for for a long time on the merchant side. So I think that will be something to look forward to. One of the breakout sessions that I attended was done by, you know, one of my favorite recent guests, Holly Sandberg. She did a terrific session on providing metrics with counterbalances to executives and senior leadership. She created a really great template for an executive scorecard and, you know, which metrics you should be measuring and then which metrics kind of counter those metrics and keep them honest.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
08:24
For instance, you can't just look at your fraud rate and say, woohoo, we're catching all the fraud without looking at your approval rate too. And you may be catching all the fraud, but your approval rate might be, you know, in the gutter and you're not approving enough orders. So you need to have both of those metrics to balance things out. That's just one example of the metrics that she shared. I thought it was a really good session and I asked her to please present it in a little bit of a different way with a different title and with a little different information, a few more specifics at MFA. So if you're looking for another reason to go to Merchant Fraud Alliance, that session is going to be fire. And I haven't told Holly this yet, but I want it on the big stage. I don't want it in one of the smaller breakout sessions because I think it's that good. And I think it's something that everybody needs to learn and wants to learn.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
09:17
I think communication with cross-functional teams as well as communicating with leadership are two things that we, on a whole, don't do well. And a lot of us recognize that and want to be informed by people who are doing it well. And Holly definitely is. So she'll be the perfect person to present on that. And if she wants a co-presenter, I will get her one, but she doesn't need one. Okay, well now I wanted to read this post from Nicola Harding. I found it really fascinating. It kind of made me laugh. It was the first thing I read one morning this week and I just, I kind of laughed to myself. And then my friend that was with me, I was like, what's so funny? And I read the post and, you know, as only fraud nerds would get it, she got it.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
10:06
So here's the post from Nicola and then I'll share some of my thoughts. EY. So like that EY, one of the top four biggest consultancies in the world, just published and then quietly pulled a 44-page cybersecurity report on fraud in loyalty schemes, all because it was riddled with AI hallucinations, fabricated citations and footnotes pointing to pages that don't exist, including a McKinsey report referred to throughout, a reference throughout that simply does not exist anywhere. So they were citing this McKinsey report of data, and that McKinsey report doesn't exist. This was not caught by EY's own review process, but by an external AI detection firm. As a criminologist, Nicola Harding, if you don't know her, has her doctorate. She's Dr. Nicola Harding and has her doctorate in criminology. I've gotten to see her speak in person and she is a wealth of knowledge on fraud.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:07
So as a criminologist who is an expert in this area, I can tell you that loyalty card fraud absolutely exists and it matters. The problem is that research like this doesn't just embarrass the firm that published it. It poisons the well. Hallucinated data gets picked up by other researchers, surfaces in AI search results, and corrupts the broader evidence base that practitioners, policymakers, and prosecutors rely on. That's not a minor quality control failure, it actually does serious harm to a field. AI is not the villain here. You wouldn't argue an accountant shouldn't use a calculator, but you would expect that accountant to be trained, accredited, and exercising professional judgment, not outsourcing the thinking to the tool and skipping the part where they check the workings.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:53
Research requires human judgment acquired through years of training, selecting appropriate methodology, reviewing the literature, understanding not just whether a source exists, but what the findings mean within the broader body of knowledge on a topic. That cannot be automated, and it shouldn't be. Research doesn't just need to be done, it needs to be presented within context by experts that understand the data in great detail and can defend the research and its implications. Fraud and financial crime prevention is an area where the stakes of getting it wrong are high. It is also increasingly an area where even the largest firms appear to believe they can blog expertise rather than invest in it. They cannot, and cases like this show exactly why.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
12:41
So there was an article, FT Times or yeah, the Financial Times that exposed this, but I really liked Dr. Nicola Harding's perspective on this and her take on this. My comment to her was, I was wondering when this would happen. AI is incapable of saying it doesn't know something, so it hallucinates. There's also the point, and if you've listened to this podcast in the last month or two, you know what point I'm about to make, that its data sources are open sources. And most of the real knowledge in fraud is either internal within companies or stored within the minds of fraud fighters. It's purposeful to keep what little advantage we have away from the criminals. And then I asked as a side note, did anyone copy or download this study before it was pulled? I'd love to read it, mostly for pure entertainment value.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
13:30
And she said, oh, all good points. And then she said, I have not. I don't have it, but I wonder if it's around. Shall we ask ChatGPT? Unfortunately, some of those points that may have been hallucinated in EY's study may now be in ChatGPT. So that if somebody, you know, asked ChatGPT about loyalty fraud, they may cite this EY study that was all based on AI hallucinations. That's part of the problem. The other part of the problem is this, not, you know, to have true expertise on a topic like loyalty fraud, you can't trust open source information. It's going to be all generalized. They're not going to be talking about the tools that you can specifically use to prevent loyalty fraud or even how hard it's impacting companies because a lot of impacted companies won't publicly say how much loyalty fraud is impacting them.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
14:19
So loyalty fraud is one of those that's kind of like account takeover fraud where it doesn't really have a metric. The metric you'll get, you know, you'll know it's happening when customer service is getting the calls of saying, you know, my air miles have been drained or my hotel points have been drained, or, you know, someone cashed in this voucher that I had because of how many times I've shopped with you, those type of things. And so they don't have the clear feedback loop that card fraud, traditional card fraud has with chargebacks. So there's a lot of nuances there that AI just doesn't have access to and doesn't know. So they'll make it up. And I did find it funny that one of the top four, you know, consulting firms that writes these big research papers obviously used AI to write it and didn't have a professional in the fraud industry read over it to verify that it was accurate. That is something I would have been happy to do had they asked, but now instead it's pretty embarrassing for them.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
15:20
But I think that this is a good article to share or posting to share with leadership if they are asking you to rely on LLMs to do research, as well as if they're thinking about using LLMs to replace somebody in strategy or someone in operations and fraud leadership. They cannot just ask ChatGPT a question and get the right answer. Just like with that example I've given earlier about, you know, what's pizza fraud? What's, you know, this kind of fraud? What's that kind of fraud? When Frank, we kind of did that in a group text I was a part of and then others did it too, ChatGPT was just making up different types of fraud that kind of made sense for pizza, right? I think one of them was pizza fraud is when someone goes into a pizzeria and steals a pizza. That's not, that's not fraud and that's theft.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
16:11
There were other examples as well that I can't remember, but there's no such thing as pizza fraud. But it couldn't say that. It was incapable of saying that. So instead, it made something up. How do you know if AI is making something up or not? You have an expert employed in your company who knows to spot BS and not, or at least knows who to ask. If they don't know, they can ask someone else in the fraud industry and say, does this sound right? You have to have someone with expertise and knowledge. You can't just rely on open source information for our industry. Maybe for others, but not for our industry. So that was the story. Like I said, I thought it was pretty funny, but also telling about the future that we are walking into or running into at this point.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
18:07
All right, let's talk about Mastercard's Scam Merchant Program, shall we? So Mastercard's new Scam Merchant monitoring is going to go into effect July 24th of 2026. They just announced it a few weeks ago. Its purpose is to find scam merchants. What they mean by scam merchants are merchants that are scamming consumers. The ones that pop up with a, you know, new merchant ID and they're offering free trials or they're shipping things like, or they're not shipping things at all, or they're promising something that they don't deliver on. Or, you know, they're promising something large and you get something small, or they're promising something, you know, that works and you get something that's broken. Those type of companies. Scam merchants. And so the way that Mastercard thinks that they can find them is by looking at a few key criteria. And they kind of have a multi-trigger framework is what they're calling it. But any one of these conditions can initiate a required investigation.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
19:10
So one of the more straightforward triggers is a breakdown in authorization performance. If a merchant's approval rate drops sharply over a short period, for example, a decline of 50 percentage points or falling below the 30% overall, that alone can put them into scope. The measurement window is tight. Acquirers are given a minimum of a 72-hour period or actually, oh no, this is different. This is not the acquirers. This is the measurement window for approvals falling quickly, a minimum 72-hour period with at least 25 transactions. So when any one of these triggers is, or one of these conditions is triggered, it'll initiate a required investigation with your acquirer. The acquirer has 72 hours to investigate and either provide Mastercard with an explanation on why this merchant is not scamming and not illegitimate. They have to provide a legitimate reason for that condition to be triggered, or they need to terminate that merchant and no longer allow them to accept Mastercards.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:18
And by the way, you can't just accept Visa without Mastercard. So if you're shut down for Mastercard, you also can't accept Visa. That merchant would only be allowed to accept Amex or Discover or maybe PayPal, which would greatly cripple online businesses. I'm reading from a post by Rick Lynch, who's been in the chargeback space for a long time. He goes on to say, there is also a direct escalation path from Mastercard itself. If a merchant is the subject of a Global Rules Investigation Program, or GRIP letter, that independently triggers the requirement to investigate. For newer merchants, defined as those with less than six months of processing history, there's an additional layer of sensitivity tied to issuer behavior and early performance signals. In those cases, just two different issuers reporting scam-related transactions under the manipulation of cardholder fraud classification is enough to initiate the process.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
21:16
So if you're a new merchant under six months and two issuers report that their cardholders have claimed that they were manipulated in some way, that's enough to initiate the investigative process within 72 hours. That can result in terminating your ability to accept Mastercard. The same applies if two issuers initiate chargebacks that reference scams or similar behavior. That's going to be more complicated because there are cardholders that claim that a merchant scammed them and they really didn't, right? So that's something to watch out for. Then there's a 5% threshold, and it sits specifically in this category. If a newer merchant, so I think within six months, sees more than 5% of its transactions result in refunds and chargebacks over a 30-day rolling period and has processed at least 500 transactions, that condition alone can trigger monitoring. So outside of that early life window, those issuer count and 5% thresholds are not explicitly defined as triggers in the same way. So I think that's important to know.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
22:26
But if you have a new merchant account and the combination of refunds and chargebacks equal more than 5% of your total volume of sales, you could be at risk for having your account activity investigated by your acquirer and possibly shut down. I think it's really interesting that they are combining refunds and chargebacks together. I understand why, but at the same time, Mastercard owns Ethoca, and when merchants enroll in Ethoca, they're enrolling in alerts that can allow them to issue refunds to avoid chargebacks. So they're kind of saying that for these purposes alone, but still for these purposes, Ethoca's not going to help you. It's going to hurt you. It's not going to, it's just, well, maybe it's not going to hurt you, but it's not going to help you because it's going to increase your refund amount. Additionally, there are some merchants that issue a lot of charge, or a lot of refunds because they have a lot of returns, right? A lot of retailers have a lot of legitimate returns that could look fishy to this, you know, program. You could be, you know, under monitoring. Granted, it is if you have, you know, at least 500 transactions, but I think in a 30-day rolling period. But I think most people on the merchant side that are listening to this podcast would very much blow that out of the water. So I think this applies to everyone.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
23:52
What they're not saying right now is if this applies to merchants that are older than six months. I don't know the answer to that. I have seen some people say it does. I have seen some people say it doesn't. I have heard other people say, well, they're rolling it out for the first six months, you know, of a merchant's lifetime now. But they're going to see how it goes and they're going to start tracking this metric more. And now that they can track this metric, if they see a high number of enterprise merchants, for example, that have a combined rate of refunds plus chargebacks divided by sales for that 30-day rolling period, it's not a calendar 30 day, it's a 30-day rolling period, that, you know, there could be repercussions. Right now, it hasn't been said one way or another, but I do think it's, you know, it's worth being aware of.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
24:41
Beyond performance and issuer-driven signals, third-party and network alerts can also initiate the process. If a merchant is flagged by a merchant monitoring service provider or through Mastercard's own monitoring programs, that alone can be sufficient. Once any of these conditions are met, the timeline is clear. The acquirer or payment facilitator has 72 hours to initiate an investigation, and if the merchant is confirmed to be conducting scam activity, they are required to block that merchant from processing Mastercard transactions. Separate from the trigger events themselves, Mastercard is reinforcing expectations around ongoing monitoring. Acquirers are expected to continuously evaluate transaction patterns, refund and chargeback activity, fraud indicators, and behavior that doesn't align with the merchant's stated business model. So if you say that you are a hotel but then you're only processing $20 transactions, that's going to look weird, or, you know, those type of things.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
25:48
There is also an expectation to review Mastercard's fraud and loss database on a daily basis for new signals. I think that's more for the acquirer than the merchant. Taken together, this is not a single metric program. It's a system with multiple entry points where performance changes, network escalation, issuer activity, and third-party alerts can all independently set the process in motion. So again, that's starting July 24th of 2026. I think most companies that are listening to this now on the ecommerce side have had their MIDs for way longer than six months. But I think it's important to be aware that Mastercard is tracking this data. This is new math that we don't usually do, right? Similar to VAMP, we don't usually do the exact math that they require for VAMP.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
26:38
We hadn't up until this time combined TC40s with chargeback numbers and then divided those by the number of sales. That was a new metric for us to start computing. Now there's a new metric to compute for Mastercard risk, and that is refunds plus chargebacks divided by sales, number of sales, the number of refunds plus number of chargebacks divided by number of sales. I think it's important to know that that's how things are being measured because you want to stay underneath those thresholds. And again, that threshold is 5%. I would hope that you would want to stay under that threshold for lots of reasons, specifically revenue. But at the same time, like I said, there are multiple reasons why merchants refund orders and some of them are very legitimate. I think that this could also impact subscription merchants who will often refund the last month of a transaction because they know that the cardholder can issue a chargeback.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
27:42
So, you know, technically the issuer, or the cardholder, can issue a chargeback for the last three months. So they'd rather give an appeasement refund of one month and then tell them, no, you can't get a refund at all, and then they go to their bank and find out they can charge back three months. So subscription merchants, high-risk merchants, some retailers, I think maybe over 500 basis points, I don't know, you know, it might be over that 5%. It's important to, you know, be aware of. All right, that is it for me today. That was kind of a shorter episode, just around 30 minutes or so. And it's not just because I want to get back to floating in the pool, I promise. But that was really, those are really the three things I wanted to update you on. I am expecting to have a guest for next week's episode. Also, Fraudology is coming to YouTube soon. This is kind of against my will, but it's been strongly encouraged by several people and as well as by my sponsor that I branch out to YouTube. So why not now?
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
28:49
So that will be happening in the next few weeks. Don't forget to look into the Merchant Fraud Alliance October 6th and 7th in Chicago. You're not going to want to miss it. Otherwise you're going to have significant FOMO. I promise. I am putting a lot of time and effort into sourcing the best speakers and, you know, representing the best companies. And by having those people in a room, those are conversations you get to have as well. And there will be the ability in the app to set up meetings with people. You can also set up your own schedule for meetings. There's just all kinds of cool features. So it's a great way to meet new people and see familiar faces as well.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
29:29
So with that, I'm going to talk to you more next week, but I hope that you are having a great day and I'll talk to you soon.