SardineCon SF/2026

Learn More
Fraudology

Relatório trimestral de fraudes 2026: combatendo as fraudes de hoje enquanto nos preparamos para os esquemas de amanhã

41 min

Bem-vindo de volta ao Fraudology.

De vez em quando, me deparo com um relatório que me faz parar tudo o que eu tinha planejado falar, porque é realmente muito importante. Esta é uma dessas semanas.

Matt Vega lançou recentemente seu relatório trimestral de fraudes de 2026 e, depois de lê-lo, eu soube que precisávamos analisá-lo juntos. Não porque ele esteja prevendo o que pode acontecer no ano que vem, mas porque todos os ataques abordados nesse relatório já estão acontecendo.

Um dos principais temas que permeiam o relatório é que a fraude está simplesmente avançando mais rápido do que as equipes de combate à fraude. A IA está tornando ataques sofisticados mais baratos, mais fáceis de executar e muito mais difíceis de detectar. Os criminosos já não precisam de grandes conhecimentos técnicos quando podem alugar as ferramentas de que precisam em marketplaces de fraude como serviço.

Então, como isso realmente se parece?

Neste episódio, apresento várias das táticas de fraude mais recentes que já estão aparecendo por aí, incluindo malware escondido atrás de falsos links de cancelamento de inscrição, malware bancário que consegue se aproveitar do dispositivo confiável do cliente e técnicas de sequestro de sessão que tornam a tomada de conta extremamente difícil de detectar usando modelos tradicionais de detecção de fraude.

À primeira vista, muitos desses ataques parecem legítimos. E esse é exatamente o problema.

Também falamos sobre por que as equipes de fraude não podem mais depender apenas de sinais de confiança isolados, como inteligência de dispositivo, reputação de IP ou mesmo análises comportamentais. Os criminosos aprenderam a se misturar ao comportamento legítimo dos clientes, o que significa que nossa abordagem à detecção e à prevenção de fraudes também precisa evoluir.

É aqui que as coisas ficam interessantes.

Uma das principais lições que tirei do relatório do Matt é que a resposta não é uma nova ferramenta ou um novo modelo. É combinar uma inteligência de fraude mais avançada, compartilhar informações entre redes de consórcios e entender as tendências mais amplas do cibercrime que estão acontecendo fora da sua própria organização. Porque, quando um novo ataque chega à sua fila, é bem provável que outra empresa já tenha se deparado com ele.

Também passo alguns minutos compartilhando uma atualização sobre a conferência da Merchant Fraud Alliance, incluindo nosso novo bootcamp de IA, que é focado em maneiras práticas de as equipes de fraude começarem a usar IA na prevenção de fraudes hoje. Não porque a IA substitua os analistas de fraude, mas porque ajuda boas equipes a se moverem mais rápido.

Se você trabalha com fraude de comerciantes, fraude bancária, fraude online ou fraude em comércio eletrônico, este é um daqueles episódios que vai ajudar você a reconhecer os padrões antes que eles se tornem o seu próximo incidente.

O que você vai ouvir neste episódio:

  • Por que o relatório trimestral de fraude de 2026 de Matt Vega é um dos recursos de inteligência contra fraudes mais valiosos lançados neste ano.
  • Como a IA está acelerando o cibercrime moderno e tornando ataques sofisticados acessíveis por meio de plataformas de fraude como serviço.
  • Uma análise de várias táticas de fraude emergentes que já estão mirando comerciantes e instituições financeiras.
  • Como campanhas de phishing de cancelamento de inscrição estão sendo usadas para instalar malware e keyloggers.
  • Por que o malware bancário está se tornando cada vez mais eficaz em contornar os controles tradicionais de fraude.
  • Como o sequestro de sessão permite que criminosos realizem fraudes de tomada de conta a partir de dispositivos confiáveis dos clientes.
  • Por que a inteligência de dispositivo, a reputação de IP e a análise comportamental precisam ser avaliadas em conjunto, e não de forma independente.
  • Como o compartilhamento de inteligência contra fraudes e os dados de consórcios ajudam as organizações a identificar ameaças emergentes mais rapidamente.
  • Uma atualização sobre a conferência da Merchant Fraud Alliance e seu novo bootcamp de IA em prevenção a fraudes.

Você deve ouvir este episódio se você:

  • Lidera equipes de fraude, risco ou confiança e segurança.
  • Gerencie a prevenção de fraude para um comerciante de comércio eletrônico, fintech, banco ou empresa de pagamentos.
  • Quer se manter à frente das últimas tendências em crimes cibernéticos em vez de reagir apenas depois que os ataques se tornarem generalizados.
  • Estão avaliando como a IA está mudando tanto a prevenção de fraudes quanto as fraudes com IA.
  • Criar ou gerenciar modelos de detecção de fraude.
  • Investigue sequestro de contas, identidade sintética ou fraude online.
  • Quer práticas recomendadas práticas de prevenção a fraudes em vez de discussões teóricas.
  • Conte com inteligência de dispositivo, reputação de IP ou análise comportamental como parte da sua estratégia de prevenção a fraudes.
Notas do episódio

Relatório trimestral de fraudes de Matt Vega 2026

Se você já ouviu o podcast antes, sabe que sempre valorizei a forma como o Matt aborda a inteligência de fraude. Ele passa o tempo dele olhando para onde a maioria de nós não consegue. Monitorando comunidades criminosas, acompanhando técnicas emergentes e conectando padrões muito antes de se tornarem ataques comuns. Essa perspectiva é importante porque a fraude não chega com um comunicado à imprensa. Ela começa silenciosamente, se espalha rapidamente e, quando a maioria das organizações a reconhece, os criminosos já passaram para a próxima tática.

O relatório reforça uma realidade crescente: fraudadores já não precisam de conhecimentos técnicos avançados para lançar ataques sofisticados. Ferramentas baseadas em IA, malware alugado e plataformas de fraude como serviço reduziram drasticamente a barreira de entrada, permitindo que criminosos ampliem seus ataques mais rapidamente do que nunca.

O relatório não está cheio de previsões ou cenários hipotéticos. Estas são técnicas ativas que já estão sendo usadas hoje contra instituições financeiras, comerciantes e credores. O valor não está apenas em saber que elas existem, mas em entender como funcionam para que você possa reconhecê-las antes que se tornem o seu próximo incidente.

Três técnicas de fraude emergentes

Vamos analisar três ataques que realmente chamaram a minha atenção.

  • Campanhas de phishing de cancelamento de inscrição geradas por IA que instalam malware keylogger.
  • Malware bancário que disfarça atividades fraudulentas ao direcionar transações por meio de dispositivos legítimos de clientes.
  • Ataques de sequestro de sessão que permitem que criminosos assumam o controle de contas sem acionar muitos dos sinais tradicionais de detecção de fraude.

Muitos dos sinais em que tradicionalmente confiamos, como inteligência de dispositivo, reputação de IP do histórico de sessão e consistência comportamental, podem todos parecer normais.

E é por isso que esses ataques merecem atenção.

A detecção de fraudes moderna exige múltiplas camadas de inteligência trabalhando em conjunto

Um grande tema presente no relatório do Matt é algo sobre o qual venho falando neste podcast há anos. Não existe um único sinal que vá salvar você. Os invasores continuam encontrando maneiras de imitar o comportamento legítimo dos clientes. Os criminosos estão cada vez mais encontrando formas de transformar nossos sinais de confiança mais fortes em fraquezas. Eles estão sequestrando sessões confiáveis, usando dispositivos legítimos emprestados e utilizando IA para automatizar ataques em um ritmo que as empresas individualmente simplesmente não conseguem acompanhar.

Os programas mais eficazes de prevenção a fraudes não dependem de um único modelo ou de uma única regra. Eles combinam múltiplas fontes de inteligência, validam continuamente os sinais de confiança e analisam o contexto mais amplo em vez de tomar decisões com base em um único indicador.

Conferência da Merchant Fraud Alliance

Uma atualização rápida sobre algo que me deixa extremamente empolgado. A Merchant Fraud Alliance Conference, que acontecerá em outubro em Chicago, terá uma sessão pela qual estou especialmente ansioso.

Nosso AI Boot Camp não será mais uma conversa sobre se a IA é importante ou não. Nós já sabemos que é. Em vez disso, vamos focar em algo muito mais prático: como as equipes de fraude podem usar IA em seu trabalho do dia a dia.

Vamos abordar prompts reais, fluxos de trabalho reais, dashboards, relatórios, investigações e maneiras práticas de profissionais de fraude usarem IA para se tornarem mais eficazes.

Não para substituir a expertise, mas para ampliá-la. Essa abordagem reflete toda a filosofia por trás da Merchant Fraud Alliance.

Tudo na programação é pensado para ajudar os profissionais de fraude a saírem com ideias que possam aplicar imediatamente quando voltarem ao trabalho. E, sinceramente, esse é exatamente o tipo de conferência que eu gostaria que tivesse existido anos atrás.

Principais pontos
  • O relatório trimestral de fraudes de 2026 foca em ataques reais que já estão afetando as organizações hoje, e não em previsões futuras.
  • A IA está tornando os ataques de fraude sofisticados mais rápidos, baratos e acessíveis.
  • Fraude como serviço continua a acelerar o crescimento do crime cibernético organizado.
  • Malware bancário e sequestro de sessão exploram cada vez mais dispositivos confiáveis dos clientes para contornar a detecção tradicional de fraudes.
  • A fraude por tomada de conta está se tornando mais difícil de identificar usando apenas sinais individuais de confiança.
  • Modelos robustos de detecção de fraude combinam análise comportamental, inteligência de dispositivos, dados de consórcio e inteligência contra fraudes.
  • Compartilhar inteligência sobre fraudes entre organizações ajuda a identificar novos padrões de ataque mais cedo.
  • As equipes de prevenção a fraudes devem monitorar continuamente as novas tendências do cibercrime para aprimorar a detecção e a resposta.
Conclusão final

As ferramentas que os criminosos utilizam continuam a evoluir, e muitos dos sinais em que confiamos há anos estão se tornando mais fáceis de manipular. Isso não significa que esses sinais tenham perdido o seu valor. Significa que eles funcionam melhor como parte de uma estratégia de prevenção a fraudes em camadas, em vez de serem usados como indicadores isolados.

Para os profissionais de combate à fraude, manter-se informado está se tornando tão importante quanto aprimorar a detecção. Relatórios como este nos ajudam a reconhecer novos padrões de ataque antes que se tornem generalizados, dando-nos a oportunidade de nos adaptar em vez de simplesmente reagir.

Porque, no fim das contas, o objetivo não é apenas detectar as fraudes de hoje. É se preparar para as de amanhã.

Conecte-se com Karisse Hendrick | LinkedIn

Apresentadora do podcast Fraudology

Especialista premiado em ciberfraude

Consultor de Prevenção de Fraudes em Comércio Eletrônico

Consultor de startups, palestrante principal e

Consultor para varejistas da Fortune 500

Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:05
Welcome back to the Fraudology Podcast. Well, for those of you that are listening, everything sounds the same. For those of you that found me on YouTube, I'm gonna be honest, this is a little weird. I had my first episode on YouTube last week with Mark Portius, and that was easier because I've done webinars before, I've worked with other people before. It was just a conversation with a friend, right? And it just happened to be on camera. But now I'm talking by myself to myself, and I can see myself doing it, and that's a little strange. So bear with me. For those of you on YouTube, please bear with me for the next couple of weeks. We're still figuring out lighting and position of the camera and all of those things to try to make this easier for you to watch. I've been hearing for years from people who have wanted to watch or listen on YouTube and I've put it off long enough. And thanks to the encouragement of the team at Sardine Media, I they made it happen. Really, they did 95% of the work to make sure that this happened. And if you haven't checked out the new Fraudology website yet, which will be in the show notes, as well as I posted about it last week on LinkedIn, definitely take check it out. We've got every single episode. So all four hundred I guess today is four hundred and thirteen. So all four hundred and thirteen episodes where you can look, you can find the transcript, you can find a summary, you can find takeaways, there's you know links to connect with the speakers on LinkedIn. It's really cool and really amazing that they were able to do all of that. So make sure that you check that out, especially. You know, of course I want you to listen, but if there's a week where you're like, I can't listen, but the topic looks good. I'd love to know what it was about. Go check out the summary. It's, you know, just a couple paragraphs, and then there's some bullet points afterwards for takeaways and things like that. So that's my plug for this new platform and all of that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
02:21
Again, I'm just so grateful to the Sardine team for going above and beyond what a sponsor does to make all of this look even more professional than I think that it is. Anyway, so before I dive into going over, so today I'm gonna go over part of a quarterly report that our good friend Matt Vega just put together and released and published. Matt, as if you've heard him on the podcast before, he really has his ear to the ground when it comes to dark web stuff. So not that cyber criminals really operate on the dark web anymore, but what I mean by that is, you know, the people that he understands what the criminals are doing and it's often the tactics that we don't know about yet, those hardcore sophisticated cybercrime tactics that we haven't we don't have a name for yet or we haven't identified in our systems yet. Those are the things that Matt really specializes in because of his background, with the military and then with a certain agency with three letters that I'm not allowed to say publicly. As well as, you know, his time at Sardine, Matt is now at point predictive working closely with Frank McKenna. Which what a powerhouse duo that is. So Matt put this together for Point Predictive and it's really the top ten fraud tactics in cybercrime that we don't know about yet that we need to. And he's got it broken down by banking, you know, credit and lending, you know, who the targets are. And we're gonna go over the ones in cyber fraud. There's I think three. Three in the cyber fraud section. So that's what we're gonna do for today's episode. But first I just want to give a little bit of an insight into what's going on for the Merchant Fraud Alliance. I haven't talked about it in a couple weeks.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
04:30
Mostly because I've been heads down working on the agenda. It's unorganized, but I currently have two large foam boards to the left of me with post-it notes of all the sessions that we're having, all the educational sessions that we're having. And it's now my job to assign speakers to each each session. And that's really what I've been head down working on that for the last few weeks. So, haven't been talking about it, but one of the things I wanted to highlight was actually, you know, the conference is October 6th and 7th in Chicago. But on October 5th, what we're kind of calling day zero, we're having a boot camp. And that boot camp is for you know, merchants only. It'll be for about 50 merchants. There's an e-commerce merchant that has an office in The Willis Tower, where we're having the conference on Tuesday and Wednesday. And they have graciously offered us the a large conference room to do this boot camp so that the rest of our team can set up for the conference for Tuesday and for Wednesday. But anyway, it'll be at the Willis Tower and AI boot camp can be so general, but you know what we came about was when we were talking with the ambassadors and figuring out what they think merchants need to know and what they, what they wanted to learn and what they wanted their teams to learn more about. We identified utilizing AI to fight fraud. There's some e-commerce companies that have mandated across their company that all employees must be utilizing AI, you know, whether it's Claude or it's Copilot or Chat GPT, that they need to be utilizing often the enterprise solution. They need to be utilizing it for 25% of their job or more. There are other e-commerce companies that have set up a kind of a working group to review any company that claims that they do AI.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
06:45
To verify that they actually are using AI and that they're not just saying that because it's a buzzword. So different companies are handling it different ways. But what it comes down to is there's also this piece where we're watching colleagues of ours in the industry lose their jobs, either to the fact that their employer thinks that they can be replaced by AI. You know, they haven't been yet, but they think they can, or they're you know, in the US, they're outsourcing to overseas. We're watching that happen and I think a lot of fraud people are saying, well, I need to get with the times so that I don't lose my job. And that's not to say that the people that were laid off if they you know had implement integrated AI into their job for 25% of the time or whatever, that they wouldn't have been. But there's a lot of people who want to utilize AI in fighting fraud, whether that's running reports, creating dashboards, identifying new fraud vectors, all of those different things, you know, new data sets, upgrading their machine learning to be AI internally, just all of those things. But they don't really know where to get started. And so there's two merchants that are gonna be leading this. I'm not gonna announce who they are yet, but they work for very large companies. And one of them specifically has been training their team over the last year to use AI and really to do more faster and to catch more fraud. And the goal of this boot camp is that you walk away with a takeaway. With prompts to use, with you know, the outline of a dashboard. Just with a greater understanding of how to use AI to fight fraud. And that's what those three hours on Monday is going to be dedicated to. So I want, I really, I can't stress enough how critical all of these sessions are to help you do your job better. That is our hundred that is our main goal, and we're knocking it out of the park with these topics and with these speakers, guys. It's pretty impressive.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
09:04
I'm very humbled at the people who have graciously accepted my offer to be part of this conference in the content piece. Some of them refuse to go to other conferences, so you can't see them anywhere else, but they're choosing to take risk on this first year. And I hope that you do too as an attendee because you're gonna have a lot of FOMO the first week of October if you don't. I can tell you that. But yeah, so we are limiting entry to the people who sign up and who first, so it's first come, first serve for that boot camp. We're getting close to capacity, but that's why I wanted to share about it today. If you do register at Merchant Fraud Alliance dot com, you can email me or message me afterwards or include it in your registration that you want to be part of the boot camp. I think there's a part that you can check for that. If you want a discount you for a ticket, message me on LinkedIn. I've got a handful of 50% off discounts that I'd love to hand out to Fraudology listeners. And just a reminder that we're not selling vendor tickets. We are only sending selling tickets to merchants. There will be vendors at the conference, but they're sponsors of the conference. And that sold out months ago. So we only have 15 companies that are vendors that will be attending. That's I think the way it shakes out, it'll be about 47 vendors and the rest will be merchants. And our hope is to have, you know, four or five merchants to every one vendor. So that it's easier to identify your peers and that you can have really good conversations with the solution providers that are there. Rather than feeling like you're a continual target. So for those of you who want to come to the conference, just a reminder that you do have to be working for a merchant or have most recently worked for a merchant if you're laid off.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:13
Okay, that was probably a lot longer than I meant for it to be. I hope my editor kind of like makes that a little more succinct. He's very good at that. Sometimes I ramble and he's, he's good at kind of tightening it up a little bit. But I could honestly talk about the content for MFA for a long time because I'm just so proud of it. And I think I'm proud of it because it came from merchants. Instead of putting out a call for speakers and saying, “What do you want to speak about in six months?” We asked our audience. We asked merchants, the people that will either be there or their peers will be there, and said, “What do you want to learn about?” What do you need to learn about? And that's how we built the agenda. So I'm proud of it. And that's why I'm rambling. All right, let's talk about Matt Vega's report. It is lengthy. I will say that. It is in-depth and lengthy. So you definitely will want to download it yourself or I think, you know, the first page you can read without anything. And then at least for me when I got to the actual report after the executive summary, it just asked for my name address or not my address, my email address. So my name, my email address and the company I worked for. I think that that's just so that the next quarter that Matt releases it, he can email it to you. He's not gonna sell the data or try to sell anything to you. I will make sure that there is a link to this report in the show notes. But it's also on the Point Predictive blog. Like I said, Matt joined Frank about a month and a half ago, I think. He love the way he did it at Sardine. I think he was there for four years and did a lot to really build it up and make it a you know, great and really relevant. But he wanted a new challenge and Frank was looking to kinda focus more on his Frank on Fraud duties than having a full time job at Point Predictive and work on Frank on Fraud. So it was a win-win. I had the pleasure of giving Matt a raving recommendation when Frank called me about it. So it's their dynamic duo and just having the time of their life geeking out every day on fraud. But anyway, this report I'm gonna read a little bit of what Matt says because it just gives context to why he did it. The kind of the title is Fraud is Officially Faster than Fraud Fighters. I would agree with that. And that is a very stressful statement. He goes on to say the trend that continues to worry me is the speed of innovation and collaboration of the attackers. As fraud fighters, it is more important than ever before to share what we're seeing, pass along our lessons learned, stay on the front lines of fraud threat intelligence, and lean into data consortium models for herd immunity. Attack on one protects all.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
14:35
I am now releasing this free quarterly fraud intelligence report to help my fellow fraud fighters and industry professionals stay aware of the ever evolving threats that we face. I spend hundreds of hours a week, or a quarter, diving into the deepest corners of the dark web, infiltrating rings and monitoring threat actors to understand the new exploits they are proposing, the ones they're working on and deploying against the industry. The most common theme this quarter: the people attacking your institution are no longer advanced cybersecurity black hats, engineers, or skilled fraudsters. They are a new generation of threat actors who combine the lack of extradition treaties with AI and rent a fraud tool. Providers, I call it fraud as a service, but same thing, rent a fraud tool providers to attack financial institutions and businesses with little to no recourse. Camera injection kits that defeat document checks, now sell for the price of a movie streaming plan. Banking Trojans are custom built to silence a specific bank's fraud prevention alerts before the money moves. And two-thirds of the flagship fraud AI models you hear about across the industry have been flipped into scams aimed at people trying to research or stop them. Nothing in this report is a forecast. All 12 vectors are active techniques we tracked from early dark web chatter. Into active or scaling attacks over the last quarter. Some will have already hit your queue this quarter, and you probably will never know. Others are going to hit your system in the coming months, following the traditional path of least friction. Every one of them is cheaper, exponentially faster, and far more advanced than the version you defended against last year.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
16:36
Wow, Matt, let's invite you to a dinner party. But it's all so true. And this is stuff that I talk about on a regular basis. I was asked to present at a top internet 50 company, I think, like very well known brand, last week, and really just to help them understand what they're not seeing and what they don't know and kind of that bigger picture of fraud. As I explained to them, they're the experts of the fraud that happens under their roof, so to speak. But it's helpful to understand what it looks like everywhere because, you know, you may not understand the other half of that fraud vector. There might be pieces of it that if you understood them, you could fight them better. It also is good because you're not going to be receiving every single fraud vector. And so what your peers are seeing, if you're not seeing it yet, you will soon. So when I was talking to this merchant, and it was a group of about 30 or 40 people from their risk team, they have a very large risk team because they have a lot of fraud, just like most large, well-known companies do. I do know of a few very large companies that have very lean teams, but their numbers kind of speak for themselves. They're hanging on by a thread. Not that always throwing bodies at the problem is the right way, but in this case, I think they see a lot of ROI on that. So I'm just backing up what Matt said. The biggest thing that I said was that they no longer need to have, you know, PhDs in computer science or, you know, be a skilled hacker, or even understand the ins and outs of your flow the way that fraudsters of you know previous years have. They'll study every single part of your flow, they'll figure out how to you know exploit a vulnerability and these days you don't need that anymore every piece of the puzzle to commit fraud against specific companies is out there for sale. And it's not expensive.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
18:55
You can get tutorials, you know, whether that's in book form or video form or a one-on-one coach, so to speak. You can get a fraud coach to teach you how to do fraud. You know, this fraud as a service thing, I remember really calling it out when I started to see it for refund fraud because I thought, man, if this starts happening for payment fraud, it's gonna be difficult to catch because you know it's no longer one guy trying to figure out all the ins and outs of several companies. It's several companies trying to figure out or you know, several small fraud fraudulent companies, figuring out the vulnerabilities of one company at a time. Matt goes on to say advanced threats and fraud vectors can do and hide from one financial institution, lender, dealership, merchant, or business. They cannot hide from a shared knowledge network like the lenders on Point Predictives Data Consortium. Where an attack on one triggers the fraud immune response that protects everyone. Once they attack one, the network learns, adapts, and builds up on that herd immunity. Improving detection and prevention with each subsequent attack just like your immune system. One of the reasons why Matt and I get along so well is because we both love analogies. Every attack vector in this report survives by staying nearly invisible to any single institution or business, making these exploits extremely difficult to detect without sharing networks and consortium models. A seasoned synthetic looks prime in one portfolio, but that same file in front of the full network of lenders and the community of enhanced data sharing pierces the network to show its true risk.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:47
As you read, ask yourself whether you would be able to detect or stop them in your own systems and controls. Industry collaboration, knowledge sharing, and shared data networks are more critical than ever before, and we are always happy to help provide guidance or show you how Point Predictive's data consortium models are leading the way for lenders across the industry. So, I of course, you know, need to talk about the company that he represents. Point Predictive is really good at helping dealerships, car dealerships identify synthetic ID. And a big part of that is their consortium model. A lot of times someone who steals a car from one dealership is gonna go steal a car from another dealership. They're gonna use, you know, fake documentation and fake bank account, you know balances and you know fake job pay stubs and everything else, and they're gonna go to different dealerships. So that's why he's talking about, you know, if you a fight a hit against one is is against all, right? We'll all find out about it if you use a data consortium. So they're all, you know, some are better than others. But I definitely recommend with at least one of your fraud vendors, that you do take advantage of the data consortium. There can be challenges. And I've been vocal about that over the years, but I agree with Matt that that is one tool that should be in your, in your fraud fighting toolkit.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
22:25
So there's twelve vectors. I'm gonna go through the ones that are impacting cyber fraud. I’m going to go through the ones that are impacting cyber fraud. We talk about the first trend in cyber fraud. He says it’s hiding in plain sight. And that is the annoyance to unsubscribe attack. And I didn’t know about this either. So that’s why I love to, you know, do this kind of research. And why I wanted to share it with you guys. I might have Matt back on the podcast in the coming months, but he was just on a couple well a month or two ago, right before he left Sardine, and I didn't wanna ask him again so soon, so we can learn from him this way. Attackers found a use for your annoyance. They flood you with the same email until you reach for the unsubscribe link, and that link is the attack. This is kind of scary. Anyone whose email address appears on the dark web list, which is more than ninety-five percent of all emails globally, are the key targets in this.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
23:30
So this was first detected by Point Predictive in June of 2026. So just last month. Criminals use AI to build high quality clones of I'm gonna start over there. Criminals use AI to build high quality clones of real company email campaigns. Then spam you with them many times a day from a lookalike address. The links are safe, real products, real sales. Real promotions. Click a product image and you land on the real website. Nothing bad happens. So it's not similar to Starkiller, like we talked about a few months ago. Then after the 21st identical marketing email that day, you click unsubscribe. That link carries a hidden malware redirect that drops a keylogger onto your device, capturing everything you type. Passwords, credit card numbers. Addresses, banking details. It's on his radar because it rides on legitimate campaigns and real URLs, and it uses annoyance as the method. Irritated people forget to check the unsubscribe link. That combination, because the emails look fine. They're legit. So why would you check the unsubscribe link? That combination is giving this attack the highest success rate we have seen in years because it hides in plain sight. Ninety five percent of all email addresses globally sit on a dark web list and that is the targeting.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
24:58
Signals to watch. A rapid or daily jump in marketing volume from a brand that rarely emails you. Copy the unsubscribed URL before clicking. A random string is the tell. So it would just be a lot of alphanumeric characters dot net or dot com. If you don't know how to copy a URL without clicking it, you just simply right click or you hover over the hyperlink. I don't know if we still call it that in 2026, but you hover over the link to unsubscribe. And sometimes you have to right click depending on your software, and then it will show you what the URL is that you'll be directed to if you click the button. So if it's a random string of alpha numeric characters. You know it's not for the merchant that they're, you know, trying to be or the bank that they're trying to be. Legitimate looking campaigns. So also look out for legitimate looking campaigns from addresses that do not match post marketing. So, you know, take a look at the email address that traditionally sends you emails, you know, marketing emails, and then take a look at the email address that sent you this one and determine if it's accurate or not. I've never thought about, you know, utilizing the unsubscribed link as the way to get malware onto your system with a keylogger. But it doesn't surprise me and I think it's really good to be aware of. The next one.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
26:39
Is Trickmo. Turns victim phones into clean exit nodes. Same real device, same IP, same city. Every signal your model trust checks out and a fraudster's behind all of it. That is very similar to the Starkiller product that we talked about on the podcast about a month, or a month and a half ago. Maybe it was two months now, but I was really worried when I found out about that because it was, you know, had a lot of potential danger. It looks like something similar is out there too. So the key targets are banks, credit unions, lenders, e-commerce, and exchanges that lean on device or IP as a key trust signal. As I think we all know, there's not just one key trust signal anymore, right? It's the combination that makes the difference. So what is it? A Trickmo variant, first tracked by Threat Fabric. And sold as malware as a service, re-engineers a banking trojan into a managed foothold. A built-in SOX5 proxy turns the infected phone into a network exit node. I'm saying N O D E node. That gives the fraudster the ability to route their own session through the victim's actual device and IP address. IP reputation and geolocation signals come back clean. In plain terms, the fraudster's activity flows through the actual card holder's real phone and your system reads it is safe.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
28:19
But it's on their radar because this attacks the fraud detection layer itself. The transaction originates from the customer's trusted device, network, and geography, which is exactly what many models, rules, and score risk scores use to lower the risk on a login and its activity. So by being able to glob on to the consumer's session and device and everything else, that looks legitimate. A lot of times these types of attacks are happening after another purchase. So what you'll have is customers calling your customer service and saying, “Hey, I made purchase one for $60. I didn't make not make purchase number two for $600.” There's no way I didn't make it, it's fraud. So customer service contacts the fraud department, they look it up to see if, you know, they missed something. And as Matt says in this report, everything that we hold, you know, is a weighted advantage you know, can be used against us. And so if we're using device and session and all of those in geography, you know, geo geography on IP, like geographic locations, then that can be used against us if the fraudster can just piggyback on the first transaction. This attacks the fraud detection layer itself. The transaction regenates from the customer's trusted device, network, and geography. Which is exactly why many models, rules, and risk scores use to lower the risk on a login and its activity. Think I might have read that twice. Sorry guys.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
30:07
Trick mode doesn't beat your fraud model. It dresses the fraudster in the victim's clothes. That's why invisible, when that's only visible when you're looking across a network or consortium, not inside a single portfolio, said Bill Hall, who is CTO and chief of staff. I don't know if that's for Point Predictive or not, but give him a shout out for his quote. Signals to watch. So, you know, you can't just cancel every transaction that has a safe device and a good IP address because there wouldn't be a company anymore. So instead the signals to watch are trusted device and IP paired with brand new behavioral metrics. Impossible spy simultaneous sessions from one identity or device. So maybe they make the per, two purchases at once on the same device and same session. That would be odd. Residential proxy or exit node indicators on a consumer line. And then another way to identify this is internal network recognizance coming from a consumer device. So if you're seeing any of those things across your network, or like I said, if you're having customers contact customer service to say, wait, transaction one was right, transaction two was not, or I logged into my account to change my address, and after I logged out, they then change the payee information to send me the check for people staying at my house on like a hosted, you know, travel site, for example. Those would be some indicators as well that you're getting hit with this.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
31:59
The Puppet Master malware that waits. All of this malware just creeps me out. Like it's just there's so much of it and it's really powerful, that it really worries me. And I think it should worry you as well. And I think knowing it's half the battle, when you know that these attacks are possible. You can then be able to diagnose it so much faster, once it's attacking your company. But also it makes you very relevant to other departments within your company where you can say, hey, there's a problem here. These, this is not a case of a customer making one purchase and then making a much larger purchase the next day or the same day. They haven't even gotten their products yet. So why would they know that they were happy and they wanted to order more? So anyway, those are all of the reasons why I think this is really important to talk about and also to just remember that malware can be scary. Here's the last one the puppet master malware that waits. This is a tricky one. The fraud operator waits and strikes mid session inside the real username's genuine activity, like a puppet master.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
33:20
The key targets are banks, credit unions, and online banking customers. So not as much e-commerce companies, but if you're in online banking or I would imagine crypto as well, this is important. So described in Barracuda's June 2026 analysis, this banking malware does not auto-fire. Disguised as a browser or security update, it lets a human operator watch a live banking session and pick the exact moment to act. Capture the session or take over midstream like a puppet master working a toy puppet. Because takeover happens inside the customer's own normal session, the fraud blends into their real behavior patterns and device signals. Detection gets very hard. Why it's on their radar? Bot and behavioral models are tuned for machine speed and or out-of-pattern actions. A human striking mid-session from inside the real user's activity generates almost none of those tells. So because they could identify account takeover when they weren't on the same session, they weren't on the same device or IP or anything else, it's really difficult. So unfortunately fraudsters are trying to bypass those. A human striking mid-session from inside the real user's activity generates almost none of these tells. It looks like the victim because in every tran technical sense it's the victim's session.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
34:54
So it's gonna you know, it's gonna look like friendly fraud, so to speak, or, you know, first party fraud, but it's not. So they do provide a call out between human-driven and so it says human-driven is an operator watching live and picks time the picks the moment that no machine speed tells. Mid-session, the attack lands inside genuine logged in activity, not the log E. Signals to watch for, high value actions right before, right after a software security update. Because the software security update would be the download of the malware. Session hijack indicators with no new device event or signal. So you've seen two checkouts on one account, an hour apart, and the local time is very, very late. And you know, all those other signals that you can combine, you should be combining to be able to identify this. Session hijack indicators with no new device event or signal, subtle mid-session shifts in cadence or navigation behavior, and a legitimate login followed by out-of-character movement in the same session. So those are things that you can look for to identify this. There is one more about international ghost tapping on the global remote contactless fraud that we talked about a little bit before Christmas. I think that we are the holiday season in November. I think that I have not done a good job of educating consumers or retailers with physical stores on this tactic. But it's important to be educated. So the very short answer I would say on this issue, that's impacting card not present merchants and remember they're on the hook for their own chargebacks. So they want to not be on the list, right? They don't want to have those they don't want to have any more. Inner but anyway.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
37:10
It's important just to know that contactless fraud can happen and you can get chargebacks from it. I have yet to hear from one of the merchants I reached out a few weeks ago. To see what happened when they called their acquirer and said, look, this was a ghost app. This was not true fraud. We need to go after these people. And in this case they knew exactly who they were because they had surveillance cameras from in store, they had their information. So that they could get loyalty points. But it's not always gonna be the case. So now that I've thoroughly depressed you, I do think it's so important though to be up on these tactics so that when someone in your company comes to you and is like, this is really weird. This doesn't make a lot of sense. You can recall something that you heard on the podcast or a webinar I do or a private presentation and be like, hey, is this affecting me? Like, am I not am I the problem, but is this something I should be concerned about? What are those signs? You know, can you look through my reporting and identify it? That type of thing. So I really want to thank Matt for putting this together. I had other fraud articles that I was gonna read this week. But then I saw this come out and I was like, no, we definitely have to dive into this. Because Matt always knows he's like three steps ahead of where a lot of us are with or a lot of, you know, online companies and banks are with the software that's able to detect that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
38:57
This helps you be able to detect them early. And really that's what it's all about is being able to be aware of them so that you can find them early. I want to, again, like I said, thank Matt for putting this together, knowing this stuff can help us stop them faster. It also shows a lot of patterns around how they're using AI, how they're using our own systems against us. The things that we have come, become reliant on, can no longer be relied on. And I think that the other big takeaway from all of this is how important it is to look from a 10,000 foot view. Not just look at the device, not just look at the session details, not just look at the behavior, but look at all of it together. And then also bring in your consortium data with the fraud provider that you use that for. Bring it, you know, you need we've been saying it for years, but you need to have layers. Because just one piece of this isn't gonna catch it. And as soon as they can identify that this works on your system, they're gonna go full court press and really hit you hard. So we don't want that. That's why we talk about it early. All right, everyone, I am gonna be done for the week. I really appreciate you listening to the podcast, all of your support. Thank you for watching on YouTube. Like I said, my I'm gonna try to have the back of my little shelf back here be a little more lit. I swear I'm not in a cave. I'm on the second floor of my house. But because I'm lighting my face, I guess the rest of it looks dark. I don't know. I don't know a lot about lighting and stuff like that, but I have awesome people around me that are helping me pick out the right equipment, which will just take time. But let me know what you hope that we talk about next. Let me know who you want to see on YouTube. Go check out that website that Sardine created if you just want a summary of an episode. If there was an episode that you really enjoyed that you wanted to share with your team. It might be easier to find it on the web when you can search the transcripts for keywords. There's just a lot of good things happening with Fraudology, and it's because you guys listen and you support it.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
41:15
So I really appreciate that. All right. I'm gonna look forward to speaking with you more next week. And next week will be a guest episode. So I won't have to stare at myself while talking for forty five minutes. Thanks so much for watching and for listening. Bye.