SardineCon SF/2026

Learn More
The Saturday Fraud Strategist

O que a AdTech me ensinou sobre fraude financeira, com Gilit Saporta

Neste episódio de The Saturday Fraud Strategist, converso com Gilit Saporta sobre ad tech em fraudes financeiras, o que parece algo bem de nicho até você perceber que isso envolve malware, tráfego falso, detecção de bots, abuso do consumidor, fraude em publicidade e muitos sistemas que fingem silenciosamente que já têm tudo isso sob controle.

A fraude em ad tech não é apenas “alguém clicou em um anúncio falso”. Isso até seria quase simples. O que estamos realmente falando é de todo um ecossistema em que fraudadores monetizam tráfego, sequestram dispositivos, manipulam o investimento em publicidade e, às vezes, envolvem pessoas comuns nessa bagunça sem que elas sequer percebam que isso aconteceu.

Gilit traz quase duas décadas de experiência no combate a fraudes em serviços financeiros, cripto, comércio eletrônico e publicidade digital, o que torna a conversa prática bem rapidamente. Analisamos o que torna a ad tech em fraudes financeiras diferente da fraude tradicional, onde a detecção de fraude está melhorando e onde os sistemas ainda desmoronam porque falta contexto.

E, sinceramente, é essa parte que continua aparecendo.

Você pode ter prevenção de fraudes com IA. Você pode ter detecção de fraudes automatizada. Você pode ter painéis que parecem muito impressionantes em uma reunião de diretoria. Mas se o sistema não consegue diferenciar entre um padrão estranho porém legítimo e um sinal real de fraude, então você tem um problema. Talvez um problema muito caro.

O que você vai ouvir neste episódio:

  • Uma explicação passo a passo de como funciona a fraude em tecnologia de anúncios e por que ela não se comporta como a fraude financeira tradicional
  • Uma análise prática do que a detecção de fraudes moderna está acertando e onde ainda enfrenta dificuldades
  • Por que instituições, plataformas e equipes de tecnologia precisam parar de tratar a gestão de risco de fraude como o trabalho de limpeza de outra pessoa
  • Uma conversa sobre o combate a fraudes com IA, automação, responsabilização e o desconfortável abismo entre velocidade e julgamento
  • Como os consumidores são envolvidos em sequestro de dispositivos, malware, golpes, aplicativos falsos e ecossistemas de publicidade fraudulenta
  • Por que uma melhor prevenção de fraudes financeiras depende do contexto, e não apenas de modelos maiores ou alertas mais rápidos
  • Uma discussão sobre a colaboração entre equipes de fraude, equipes de confiança e segurança, pesquisadores, reguladores e as organizações que detêm todos os dados úteis

Quem deve ouvir:

  • Profissionais de fraude e líderes de instituições financeiras
  • Equipes de risco, conformidade e cibersegurança
  • Profissionais de IA, aprendizado de máquina e análise de fraude
  • Equipes de confiança e segurança
  • Líderes em tecnologia de anúncios, comércio eletrônico e plataformas digitais
  • Reguladores, consultores de políticas e defensores do setor
  • Qualquer pessoa que esteja tentando entender por que a fraude continua encontrando brechas entre os sistemas

Este episódio é para pessoas que se importam com estratégias de prevenção a fraudes que vão além da versão de comunicado à imprensa. Detecção é importante. Conformidade é importante. Mas você precisa se perguntar: estamos realmente prevenindo danos ou só ficando melhores em rotulá-los depois que acontecem?

Notas do episódio

A tecnologia de anúncios em fraudes financeiras se tornou um terreno muito conveniente para golpistas. Há dinheiro circulando por sistemas de publicidade complexos, tráfego que pode ser falsificado ou manipulado, dispositivos que podem ser sequestrados e consumidores que muitas vezes nem fazem ideia de que fizeram parte da operação.

Isso já é confuso.

Agora adicione IA, automação, bots, aplicativos falsos, malware e redes de publicidade que não foram exatamente criadas para oferecer total transparência, e tudo isso começa a parecer menos um simples problema de fraude e mais um problema de ecossistema.

A Gilit e eu conversamos sobre como as organizações estão usando detecção de fraude com IA, detecção de bots, análises avançadas de fraude e compartilhamento de inteligência para melhorar a prevenção. E, para ser justo, parte disso é um progresso real. Não estou aqui apenas para reclamar ao microfone. Na maior parte do tempo.

Mas ainda existem grandes lacunas.

Os sistemas de IA podem agir rapidamente, mas também podem tirar conclusões precipitadas. Eles conseguem detectar padrões, mas nem sempre entendem por que esses padrões são importantes. Eles podem sinalizar anomalias, mas, sem fluxos de trabalho sólidos de investigação de fraude e sem o julgamento humano, você pode acabar apenas com uma confusão muito confiante.

Também abordamos a diferença entre automação maliciosa, automação legítima e automação desperdiçadora. Essa distinção é mais importante do que as pessoas imaginam. Se todo bot for tratado da mesma forma, ou se todo comportamento estranho for tratado como fraude, as equipes criam ruído. Se ignorarem completamente o problema da automação, os fraudadores recebem um convite e tanto.

Não pega bem.

O impacto sobre o consumidor é uma parte fundamental desta conversa. Sequestro de dispositivos, malware, aplicativos fraudulentos, publicidade baseada em golpes e ecossistemas enganosos frequentemente atingem pessoas que nunca imaginaram se tornar vítimas. E, quando isso acontece, a vergonha e o constrangimento podem impedi-las de denunciar.

Por trás do tráfego de bots, instalações falsas, cliques automatizados e padrões suspeitos, geralmente há uma pessoa em algum lugar que foi explorada, manipulada ou silenciosamente prejudicada por um sistema que não identificou o problema a tempo.

Também falamos sobre o próximo Fraud Fighters AI Playbook e sobre como a adoção responsável de IA realmente deveria ser para as equipes de fraude. Não a versão brilhante. A versão operacional. A versão em que as equipes precisam pensar em governança, qualidade dos dados, responsabilização, tecnologia de prevenção a fraudes, fluxos de trabalho de investigação e se suas ferramentas estão ajudando as pessoas a tomar melhores decisões ou apenas gerando mais alertas para triagem.

Principais aprendizados
  • A conscientização ajuda, mas não é o mesmo que prevenção.
  • A detecção de fraudes precisa de tecnologia, contexto e julgamento humano atuando em conjunto.
  • O combate à fraude com uso de IA só é eficaz quando é apoiado por estruturas de investigação robustas.
  • A tecnologia de anúncios em fraudes financeiras gera riscos em fraudes de publicidade, abuso de identidade, malware, proteção ao consumidor e serviços financeiros.
  • As organizações precisam de maneiras melhores de separar a automação maliciosa da automação legítima ou simplesmente desperdiçadora.
  • A detecção de fraude em anúncios não pode depender apenas de alertas mais rápidos. Ela precisa de melhor contexto, melhores dados e melhor discernimento operacional.
  • As equipes de fraude, de confiança e segurança, os pesquisadores, os reguladores e as plataformas precisam colaborar de forma mais direta.
  • O custo humano da fraude não deve ser tratado como algo secundário.

A questão mais importante é se as organizações estão criando sistemas que realmente reduzem os danos ou apenas sistemas que explicam os danos depois que eles já aconteceram.

A alternativa é aceitar sistemas fragmentados, responsabilidade fraca e ecossistemas de fraude que continuam a crescer mais rápido do que as defesas ao seu redor.

Esse não é um bom plano.

Para se aprofundar, obtenha seu exemplar de The Fraud Fighter’s AI Playbook de Gilit Saporta, Chen Zamir e Shoshana Maraney na O’Reilly: https://www.oreilly.com/library/view/the-fraud-fighters/9798341660359/

Ainda não está pronto para encerrar a conversa sobre o meu e, espero, também o seu assunto favorito? Assine a newsletter Saturday Fraud Strategist.

Episode transcript
Chen Zamir
Chen Zamir
00:02
All right. Welcome back, everybody, for another episode of The Saturday Fraud Strategist. And with me today, a very special guest, one that has so much experience in the field of fraud, fraud prevention, and one of the most experienced fraud fighters that I've got to meet throughout my career. I also had the privilege in the last year to be her co-author, writing our upcoming book. We'll talk about it a bit later. Gilit Saporta, it's such a pleasure to have you on the show.
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
00:37
It's such a pleasure to be here, Chen. Thank you so much for inviting me. We just realized that you and I go way back, to the point that you still have me saved with my maiden name on your contact list. That's so cool.
Chen Zamir
Chen Zamir
00:51
Yeah, I met Gilit on my first day doing fraud prevention. Well, likely the first day. So that means that we know each other for nearly 17 years now. It's a bit scary to say that, but yeah. Gilit, you've been around, and I'm sure that a lot of the listeners who are listening right now know you either personally, through a conference, or through a podcast. Can you share a bit about who you are and tell us a bit about your career so far, just so we're all on equal ground?
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
01:36
So yeah, I've been around, and I was one of the lucky ones to be part of the early days of e-commerce and e-commerce financial crime. Our first opportunity to work together, you and I, was with the reincarnation of my first student job, doing some manual review of credit card payments, mostly for people who were paying for VPN services. Even the ones who were doing so without a stolen credit card back then were probably buying the services to do something nefarious or naughty later on.
Chen Zamir
Chen Zamir
02:30
Not to watch the newest Netflix release.
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
02:33
Who knows, who knows? No, Netflix was still a service for shipping DVDs to your home back then. That's how old we are. Do you realize that? So yeah, it was a fun ride and an amazing opportunity to learn about how diverse and creative the human mind can be when it comes to both fraudulent manipulations and just bizarre behaviors that are not fraudulent online. I think that, in a nutshell, characterizes what I do and what I love doing throughout my career. I moved from financial fraud, where you and I met, with PayPal. After nearly a decade with Fraud Sciences, which got acquired by PayPal, I moved into e-commerce with Forter, where I got to be part of the fairly early days of that amazing company. Then I moved into cryptocurrency fraud with Simplex, which got acquired by Nuvei. During the first COVID lockdown in 2020, I moved into DoubleVerify, where I work today as VP of Product for our wonderful Fraud Lab. That gave me the chance to experience both the most sophisticated, targeted version of crypto fraud, where you're targeting one victim in a very spear-phishing kind of way, all the way to bot attacks with DoubleVerify, where we identify massive volumes of events with anomalies in order to help uncover fraud attacks.
Chen Zamir
Chen Zamir
06:26
Yeah, that's amazing. The reason why I was so keen to have you on the show is because you've had such a fascinating journey. When I look at it, I see three things. First, you've spent almost two decades on cutting-edge teams, building cutting-edge technologies. And it's not just one team. You've seen several problems from several different angles over a very extended period of time, always on the forefront, dealing with frontier problems and frontier solutions. Second, you've transitioned from financial fraud and e-commerce fraud into ad tech fraud, which is a space I don't know much about. And third, and this is probably the main reason why I wanted to have you on the show, you've had roles that involved training. That positioned you in a place where you had to think about abstractions, methodologies, and the theory behind fraud and fraud prevention. I thought, who better to talk to about fraud in general, and the differences between financial fraud prevention and ad tech fraud, than Gilit? So I'm super excited to dive into it. Let me start with the first thing that came to mind. I'm not even sure I know what ad tech fraud is. I can imagine, but I can also imagine there are several major typologies. Maybe I know some of them, maybe I don't. Can we start by discussing that and how it's different from financial fraud?
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
09:06
Yeah, for sure. I think you and I both share this passion for abstraction, methodologies, and training. It's a great way to help teams and the industry think about the next potential attack and threat we should be looking out for. In ad tech, we define fraud as any kind of manipulation that's out there to monetize and drain the advertising budgets of brands. The largest brands in the world are our clients today, which means I get the fun and very stressful experience of having to explain fraud attacks to brands like Disney and many others. There's a huge sensitivity not just to the financial impact, but also to brand reputation, brand suitability, and brand safety. What does it mean for a large organization to be perceived as monetizing fraud? Or supporting fraud? Or allowing children to be exposed to content they shouldn't be exposed to because some manipulation in the advertising pipeline led them there? We see that all the time. The classic example I provide when I explain what I do is how advertising fuels our digital lives. If you look at the mobile device we all have next to us, there is a lot of technology running both in ways we see and under the hood. Once I became more aware of it through our Fraud Lab, I realized that almost every device has some app running code that may be generating ad calls, whether you see them or not. My dad experienced this all the time. No matter how often I told him not to click suspicious links, he would install all sorts of junk apps. Flashlight apps, for example, even though the phone already has a flashlight. A few days later he'd notice the device heating up, the battery draining quickly, or his data plan disappearing. It was malware producing invisible ads that brands were paying for. That's one example of an ad tech fraud typology. A device hijacking attack. Someone is tricked into installing malware. Advertisers pay substantial amounts to run ads on that device around the clock, and nobody is aware of it. These are the kinds of operations I feel proud about uncovering at scale and helping the industry address, especially when there's a human victim involved. Part of my passion for education, and I think yours as well, comes from the fact that we've seen so many fraud attacks that are technically sophisticated but could have been prevented through public awareness. People shouldn't feel ashamed of being victims. My dad often noticed something was wrong, but he felt embarrassed. We see that in romance scams, ransomware, and countless other fraud schemes. We need to remove the shame element so we can all be safer.
Chen Zamir
Chen Zamir
15:46
It's interesting because I expected you to talk about affiliate fraud and things like that. What I didn't expect was how much ad tech fraud resembles scams. There are elements of social engineering, cybersecurity, malware, and classical fraud prevention because ultimately someone needs to monetize and move the money. That's super interesting. Going back to 2020 and your move into DoubleVerify, I'd assume you came in with a tremendous amount of experience compared to many team members, even if not in the ad tech domain itself. What parts of your experience translated directly into your new role? What frameworks or processes were you able to lift from financial fraud and apply on day one?
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
17:54
That's such a great question. First, I was completely overwhelmed by the volume of data and expertise I needed to absorb. Even six years later, I'm still amazed by the researchers here. Their understanding, creativity, and mindset are incredible. It felt like walking into Hogwarts, and I definitely wasn't the wizard in that scenario. The first thing we heavily invested in was collaboration, both within the Fraud Lab and across the broader organization. Fraud fighters naturally gravitate toward each other. That's one reason fraud meetups are so enjoyable. We love sharing analytical riddles and discussing attacks. But if you're talking to sales, commercial teams, or even engineering teams, you can quickly lose people. It's important to connect fraud prevention to human outcomes, like my dad's hijacked phone, but also to business outcomes. What's the financial impact? What does this do to the bottom line? Should you accept more risk to gain more scale? That need for cross-organizational collaboration became a major focus. In fact, Shoshana and I, who is also our co-author on the upcoming book, created a video series on FraudLab.com about translating fraud fighter language into business language that executives can understand.
Chen Zamir
Chen Zamir
21:49
And you think that's easier in financial services because the connection to the bottom line is more obvious?
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
22:01
Yes. It's easier when you're in a risk organization that directly measures chargebacks, clawbacks, and financial losses. It's harder when you're in product organizations or ecosystems where scale and bot attacks create more indirect impacts. The second thing that transferred directly was the good story, bad story approach. Whenever we see an anomaly, we ask: What's the most plausible legitimate explanation? And what's the most plausible fraudulent explanation? The ability to ask why is something we still practice every day. In fact, it's one of the biggest challenges for AI agents. Our AI systems tend to jump to conclusions. If they see a traffic spike at 3:00 a.m., they immediately say, "Bot attack." A human analyst would ask, "What if Taylor Swift tickets just went on sale and everyone hit the site at once?" The challenge is teaching AI to consistently generate reasonable human explanations before concluding fraud. You need to hold both possibilities simultaneously.
Chen Zamir
Chen Zamir
26:18
I completely agree. LLMs are incredibly quick to find conspiratorial explanations. I want to double-click on the good story, bad story approach. You're describing it in the context of individual cases, but you work in a Fraud Lab. You're not investigating one case at a time. How does that framework translate into scalable, analytical work?
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
27:48
Great question. Our Fraud Lab is somewhat unique because we've automated a lot of the operational work. That allows us to focus on edge-case analytics. You still need automation to process huge volumes of traffic. Whether that's rule engines, machine learning, or AI systems, something has to filter the majority of activity. But I don't believe in one model to rule them all. The attacks targeting senior citizens are different from those targeting gamers, which are different from attacks targeting sports audiences. The patterns vary dramatically. That's why I love the good story, bad story approach. Take a TV generating ads 24 hours a day. One story is that it's a bot attack. Another story is that it's a legitimate display at an airport showing sports programming around the clock. Both explanations fit the data. You need systems capable of distinguishing between them. You can't just say, "24-hour traffic equals fraud." That won't work.
Chen Zamir
Chen Zamir
33:50
How do you actually do that at scale?
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
34:35
That's exactly why we need excellent people building these systems. We're like kids in a candy store right now. The challenge isn't access to AI. It's orchestration. We've found success with specialized skills. For example, we have an investigate skill trained to tell good and bad stories. That skill feeds into a detect skill that looks for anomalies and compares them against the outputs of the investigate skill. It's like building with LEGO pieces. You create smaller components and connect them together. One of the motivations behind our book was to show fraud fighters that they can now mix and match capabilities much more easily than before. Even if you're moving from fintech into ad tech, AI can help accelerate the learning process.
Chen Zamir
Chen Zamir
37:59
That's fascinating. We spent years talking about these theories, and suddenly we have tools that can operationalize them. Going back to your first weeks at DoubleVerify, what surprised you? What felt truly novel?
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
39:08
I was surprised by the murkiness of the industry. Ad tech is a B2B ecosystem where everyone knows everyone. That was very different from fintech, where many adversaries were anonymous criminals or organized crime groups. In ad tech, you sometimes have companies operating in gray areas. They're not necessarily criminals, but they're serving ads in ways that provide little or no value to advertisers. The industry relies heavily on trust and transparency. That led me to appreciate collaboration in ways I hadn't expected. I never imagined I'd spend part of my job working directly with other fraud labs, such as Roku's, to bring down device hijacking schemes together. That level of cooperation surprised me. It also required learning about legal considerations, business sensitivities, and collaboration across organizations.
Chen Zamir
Chen Zamir
43:34
I don't think I've ever heard of two private companies collaborating to bring down a fraud ring in financial services. How does that work?
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
44:14
The regulator plays a major role. The Media Rating Council and organizations like TAG, the Trustworthy Accountability Group, invest heavily in collaboration and education. The goal is to maintain trust in the ecosystem and support a free internet supported by advertising. These groups provide resources, events, and frameworks that help the industry work together. Ad tech is younger than fintech, but in terms of collaboration, I think it's actually more mature.
Chen Zamir
Chen Zamir
46:37
That's amazing. If you returned to financial services tomorrow, what lesson would you bring from ad tech?
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
48:06
One major lesson is that bot does not automatically mean fraud. Bots can be shopping assistants, agents, and other forms of automation working on behalf of humans. The challenge is distinguishing malicious bots from legitimate bots. That's something ad tech has spent years refining. We've tried to share many of those ideas in the book.
Chen Zamir
Chen Zamir
50:20
Can you give an example?
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
50:57
It becomes almost philosophical. Intent is difficult to measure. We often focus on impact instead. For example, websites today are constantly scraped by bots. Sometimes those bots belong to major AI companies collecting data to train models. Sometimes they're projects built by students. The intent isn't necessarily malicious. But the impact can still be costly. I know of a large e-commerce website that has been scraped continuously for years. It may have started as a school project someone forgot to turn off. But it's still consuming resources and generating costs. That's where I think we all need to become more responsible. Not all bots are malicious, but some are wasteful. And AI has dramatically increased the scale of that problem.
Chen Zamir
Chen Zamir
55:02
That's really interesting. It sounds like we now have a new category that's neither good nor bad, just careless or wasteful.
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
55:48
Exactly. And the challenge is scale. One example we discuss in the book involves AI-generated content farms. Some are promoting dropshipping schemes. Others are more dangerous and lead users toward ransomware or other scams. The sophistication isn't always impressive. What's impressive is the volume. That's the challenge we need to solve as an industry.
Chen Zamir
Chen Zamir
59:36
I'm glad you brought up the book. We started writing it about a year ago, and everything has changed since then. The technology, the attacks, the defenses, our understanding of the space. If we started writing it again today, it would be a different book. What made you want to take on such a challenging project?
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
61:00
Terrible FOMO. That's the honest answer. Fortunately, O'Reilly has allowed us to keep updating and refining the content until the very last minute. It's daunting to write about a topic moving this quickly. What helped was that you constantly brought us back to frameworks and methodology. I kept showing up with new attacks every week saying, "Put this in the book." You kept saying, "Let's generalize." That balance helped create something more durable. My hope is that readers walk away feeling more confident discussing AI and fraud, regardless of their starting point.
Chen Zamir
Chen Zamir
65:19
I'm curious to see how quickly it ages. One question I ask all guests is this: Leaders know they need to adopt AI. They're being pushed to do it. Where should they start?
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
67:13
If your organization is encouraging AI adoption, start by understanding what technology is already integrated into your enterprise environment. What systems already have access to your data? What tools are approved? Our team experimented with everything early on. That was fun, but we also built a lot of things that weren't scalable. Eventually, we rebuilt many of them into workflows where AI could participate across the entire process. From documenting findings in Jira, to accessing data sources, to routing insights to the right business stakeholders. That level of automation requires maturity. A year ago, most organizations didn't have that infrastructure. Today, many do. The key is starting with your existing ecosystem.
Chen Zamir
Chen Zamir
71:19
That's such a good point. Many organizations still think AI is magic. They assume it's plug-and-play. But like any data-driven technology, it depends on the quality and accessibility of your data.
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
71:51
And it will lie to your face shamelessly. It will confidently generate information that isn't there. You have to be very careful.
Chen Zamir
Chen Zamir
72:06
Exactly. Gilit, this has been so much fun. Let me summarize some of the key takeaways. Fraud teams often struggle to connect their work directly to business outcomes, even though that connection is critical. We discussed the good story, bad story approach and how AI finally gives us tools to scale that way of thinking. We talked about the importance of granularity rather than trying to build one model that does everything. We discussed how bot detection is no longer about identifying all bots as bad, but rather distinguishing between good, bad, and sometimes simply wasteful automation. And finally, we talked about AI adoption and the importance of getting your data in order before expecting meaningful results.
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
74:01
Yeah. It's an inherent challenge. If you're doing a great job in fraud prevention, you're often invisible. It's a bit like parenting teenagers. If everything is working, nobody notices.
Chen Zamir
Chen Zamir
74:16
That's a great description of the catch-22. Gilit, thank you so much for joining me. The Fraud Fighters AI Playbook is either out now or coming very soon. You may still be able to get a free copy from O'Reilly. The link is below. Thank you again for joining me today.
A smiling woman with long brown hair wears a blue-green top.
Gilit Saporta
79:48
Thank you.
Chen Zamir
Chen Zamir
79:50
All the best, and I'll see you all next Saturday.