Go back

Inside the AI Fraud Surge with Frank McKenna & Matt Vega

83m 41s

Inside the AI Fraud Surge with Frank McKenna & Matt Vega

The transcription discusses the introduction of Sardine in the Fridology podcast and the excitement around it. The conversation delves into the utilization of AI in fraud prevention and detection, focusing on the dual roles of AI in both attacking and defending against fraud. Various examples of AI usage in committing fraud are highlighted, including deep fakes, business email compromise attacks, and website scams. The text also touches on specific instances of AI exploitation for fraud, like using stolen credit cards based on geolocation, matching spend patterns, exploiting chargebacks, and employing password spraying techniques. The discussion underscores the evolving and sophisticated nature of AI-driven fraud tactics, emphasizing the challenges they pose for traditional fraud detection methods.

Transcription

15149 Words, 80393 Characters

Fridology is now presented by Sardine, and I couldn't be more excited. You'll get to meet their Founder Soups, and some of the team later this quarter. And you'll hear a bit more about why they've caught the attention of some of the smartest fraud leaders I know, throughout crypto, fintech, financial services, and e-commerce. Thanks again to Sardine for supporting this episode of Fridology, I hope you enjoy it. Welcome to Fridology Podcast, where we dive into the science and study of online fraud from the perspective of an e-commerce fraud fighter. I'm Karees Hendrick. Welcome back to the Fridology Podcast. Well, today's going to be an all-star episode. I have asked both Frank McKenna of Frank on Fraud, and also co-founder of Point Prodictive, and Matt Vega, who is Chief of Staffs, the CEO of Sardine, to join me on the podcast. And I should also say about Matt, he's been on the podcast before as different things, because he's been in the industry for so long, when he was a practitioner in crypto, and NFTs, as well as he's been an e-commerce for a long time, and on the banking side of fraud. So these two are heavy hitters in the industry, as far as the knowledge that they have. And what I really wanted to talk about today was AI. We hear the buzz word is crazy, everybody's using it, but what does it mean? And I think when we talk about AI, there's two buckets for fraud. There's the AI that is coming towards us, that is attacking us, that we need to be aware of. What are they, what are they, the bad actors doing, and how are they using AI to attack us? And then flipping it, and how are we using AI in fraud prevention to catch them? And this may turn into a two-parter, I'm not sure. I just know that I have a long list of questions for them, and I'll chime in where I can too. So we'll dive in, but welcome to you both. Thank you so much for taking time to join me on the podcast. Thanks for having us. We appreciate it. Yeah, this is a, I've been looking forward to this for a while, so. Like a lot of times here. Me too, the three of us love to nerd out about fraud. And I think, you know, I've, I have had long phone calls with both of you just nerding out on fraud. That is an interesting. Matt and I famously used to talk into our phones to die. Yeah, that is happening. Just like talk about fraud to somebody else. That's true. That's a very true statement. And Frank and I are, you know, we've worked on the fraud predictions for the new year, for the last few years. And Frank's been a regular guest on the podcast, and everybody knows we love to nerd out about fraud too. So I think having both of you, it's going to be really fun. It'll be a good one. Yeah, thanks for joining us as well, Frank. I appreciate it. Yeah, this is a good topic we have too. This is going to be fun. Well, and there's a lot, there's a lot to dive into. So I'm just going to start like, because if we don't start, we'll just start babbling about other stuff and then we won't get to the questions. All good. Let's dive in. So I think the first question and maybe the biggest question is, how is AI being used to commit fraud? Specifically in ways that impact, you know, online merchants e-commerce as well as online banks. And I'll stop there and I'll, you know, Frank, you and I had talked a little bit about on the last time you were joining me. You know, we talked about the AI deep fake tipping point and just how many he fakes are being used. How else are fraudsters attacking online merchants and online banks using AI? Yeah, I mean, I think we were talking before the podcast about good AI and bad AI. And the funny thing is if I was to make a list of all of the use cases for bad AI like the scammers and fraudsters and how they're using it. And then all of the good uses of AI, I think right now, because it's kind of an it's impency that it would slur a lot more to the attacking with AI. And I think the reason for that is because the amount of money that these people can make by using AI to help them scam is in the billions and billions of dollars. And a lot of companies on the good side haven't really figured out how to monetize it or to get the productivity gains or the efficiency gains. So it's really right now, we're at a point where there's just a lot of use cases and what have we seen, right? So one of the big ones that we talked about obviously was the deep pakes. You know, a year ago, decreased when we did our predictions. It was a feeling like, oh, this AI hype is way overblown. There's not much fraud happening, right? It's all theoretical and we were like, well, I think 2025 is going to be the year where it's not hypothetical anymore. Deep fakes was like the number one thing and it surprised me the types of defects, right? All of this pig butchering now is being supported by fake, deep fake videos where the victims are interacting with, you know, people that aren't real. BEC attacks, so looking at these business email compromise attacks where the CEOs getting instructions to an employee to send a wiretress or those are happening with deep fake zoom calls even. So you're seeing a lot on the deep fake front, you're saying a lot on the bots that are sending out automated text messages. So think about those text messages you get every single day like, hey, let's meet up for coffee from an unknown number, you know, 99% of those right now are created with AI coming out of these sim forms somewhere in the somewhere in the world right now. These are everywhere. So there's a lot of those messages you're getting now are deep fakes and scams. We talked about websites, right? One of the big scams we saw this year was people creating in the auto industry, which is where I spend a lot of my time. People propping fake dealer websites to sell cars that don't exist and do wire transfer prod and these are just proliferating everywhere they're impersonating car dealerships. We see deep fake data sniper scams, right? This is another prediction we had last year, so it's like these scammers are stealing data from data breaches and creating these hyper realistic scams, which say something like, hey, Frank, notice that you're, you know, so security number appeared on a website that is, you know, whatever, something questionable. And we don't want to have to go to your address at, you know, 123 B Street. And by the way, here's a picture of your house. And one recent example I saw, here's a picture of your car. This one sent to me, but it was on Reddit. Here's a picture of your car with your license plate in front of a strip club. And if you don't anybody get this picture, pay us, you know, these types of things. There's just literally every week something new or deepakes are attacking us essentially as you said, Greece. And so I could go on and on example after example. They're thinking of new and creative ways. And we're going to see a thousand more next year. I completely agree with that. In fact, speaking of new examples, literally this weekend, I was doing some threat intelligence on the dark web. And I came across a ring that specialized in using AI for exploits. And the basically four that were really interesting that they were using as one, they had taken something called a CBE, which is basically a public vulnerability report in the cyber security space. And what these reports do, you can find them on cve.org, for example. And basically whenever there is a security researcher or even like hacker one, for example, in the hacker bounty programs, when they find a technology vulnerability, a software vulnerability, etc. They will create a basically a report on that so that other companies know to basically plug the whole what they were doing is basically they have trained their own model using cve's. And they're using an agent agent to go capture the cve extract the logic out of it. Right. So what is the how is it in this vulnerability. Then that agent pushes it to a large language model to then write the code basically from the prompt of that agent to write the code of the exploit and then use it in real time. So they've now basically are using what this in the cyber security professionals in particular, they create these cve reports to protect the industry and community and the fosters are actually using the reports to protect the industry right back against them. So that is interesting. So what they're, what they're kind of hoping for is these are exploits that we can really capitalize on before people plug them. That's exactly right because the vast majority of companies are not plugging the holes. They will eventually right and they definitely well if there's a pressure being applied. But you know, like the Microsoft, so the world plug the holes immediately like very quickly they have huge teams that are dedicated to finding these vulnerabilities, right. But your average even billion dollar company, you'd be surprised it can take three, six months, 12 months before some of the especially if they're minor vulnerabilities where that like they haven't been utilized yet, right. So they almost consider it as like a very low risk because the fact that the chance of it being exploited is near none. Well, like some of these some of these vulnerabilities are like very complex, right. It takes like a true cyber security software engineering expert to utilize them, but with the power of AI people with a little bit of knowledge are now able to utilize these really advanced attack vectors. That's super interesting because I can get some of those blogs that give you the plugs every weekend. That's like 20 or 30 new ones a week. But so this was a telegram channel that was published things in dark web. Yeah, this isn't a dark web. It's a it's a it's a what was really funny is they were using AI to write in Russian, but like it was very very clear that they weren't Russian. So like yeah, so they they they were like probably they may even been Americans for all I know, right. But it was like very clear that the language that they were using was like being written by AI because they were trying to hide their identity, etc. So they were like communicating using using AI language conversion, which was even extra funny. And so that was one of them. The other the other three that were also I would think just as fascinating is one of the big controls that you see in the industry is when you have a stolen credential login. Let's just say username password credential and then you have a separate stolen credit card. Let's just say that account doesn't have any payment information on it, right. But you want to use that stolen credit card. So what they're doing is they're using AI to match the stolen credit card details to the highest probability of success of the account, I'll give you an example. Oh wow. Let's just say Frank has let's just pretend like Frank has an Instacard account, whatever they name the company door dash, whatever. And that his account was somehow compromised somehow, right. Let's just say it's fishing or whatever maybe, but Frank doesn't have any type of payment details on it. Well, let's just say let's pretend like Frank is located in downtown New York. Okay. Well, if you want to increase the chance of success of now using stolen cards on Frank's account, you want credit cards that also have payment history or billing addresses in the same region or or geolocation or even zip code as Frank, right. And so what's really interesting is even with the credit card system like ABS, et cetera, you don't pass the name anyway. So you can just make a mouse and it'll still get a better. So what they're doing is they're increasing their chance of success on these attack vectors by matching really high probability cards that are from that exact location or very close to that exact location. They're taking it once that further and they're looking at Frank's spend pattern in that account. So if Frank normally buys from staples, they will use a stolen card that's from his exact area and then their purchases that they're going to steal will be at staples, for example. So it kind of matches a similar spend pattern, but it's different items. So like same store location, for example, because when you look at the anomaly detections, most companies, they're looking at like impossible travel, right. You're looking at like, okay, well, the card is from California, but Frank is in New York. Frank just transacted an hour ago in New York. So there's no way he's in California. That's an impossible travel. Right. So like call it geofencing. And then the other, the other anomaly alert that most people use is that they're looking for a anomaly spend, right. They're a high dollar transaction at a new store that the individual has never transacted at. That's a red flag. So you can actually with this matching logic can get through some of those traditional controls, which is really interesting. And then the other two, one that Frank actually just hit on, which was really interesting, was around basically charge back abuse. And so what they're doing is they're using AI to file charge backs. And I'll give you a perfect example. We did this in a test and it worked, which was a little bit freaky. But basically, let's just pretend like you have a delivery from Amazon. I'll just use this isn't the case, but let's just say you buy electronic device at Amazon. You can take a picture of it and you could just use a chat GPT to say like make the screen look like it's cracked. And then you file a dispute and you say it was damaged on delivery. And so they're doing that a lot now, which is interesting, especially on the like interestingly, they're doing it on lower dollar items because a lot of the companies won't won't review the returns of low dollar items. So in some cases, it's too expensive to even cover the return costs. So they're starting to exploit that now, which was really interesting. And then the last one that I saw that was really interesting is called password spread. And what they're doing is just like with brute force attacks where you have a login credential. You would hit that that same login credential. Let's just say 5,000 times with a bunch of different password combinations until you get it right. Most companies out there can can detect that they can steer large spike in volume and traffic right they can see brute force. You can see credential stuffing. What they're doing is password spring. So what they'll do is using this model that they created is they plug in 100 different companies. And they have known known users, but not the login credentials for them. So they have let's just say emails that are associated with these companies. And then what they do is they do three password attempts per login and they rotate company to company each time. So what ends up happening is you can scale that to millions of password attempts, but you're only actually hitting one login three times and then moving on. And so and you're also not going boom, boom, boom, back to back login, login, login, login, because the company can see that. So the by the time they rotate across 100 different companies and come back, you now have a time delay from the first attempt to the second attempt and they're rotating their IP addresses. So you know, I'm sure they're probably using a proxy or something similar. So now you have it's not happening at the same time. It's not high volume. So your velocity checks won't check. It won't work. Right. It's a different session now because a lot of times it'll be in the same session. It's now no longer a session, but you're actually fully exiting the site. So like the cloud flare of the world will not be able to see it now, especially if you're bouncing from off of cloud flare, which is like totally doable. And it's very effective. So like when I was just watching them do this, they got into something like 198 accounts and this was like over two or three minutes, just like rotating through spraying three attempts, because if you do that at scale over millions of attempts, right, you're going to get a lot of. So that was a wild and we're talking about they were doing it at companies that I know have best in class security controls. Two of them in particular, like have world class controls. So that's pretty scary, because that's getting through a lot of the traditional anomaly detection, velocity tank checks, right. And then most companies have throttling in place to mitigate these types of force attacks, right. And this throttling does not work in this case. Right it. When you feature that starting recently introduced to their products, we is called the anomaly to rule product. If your system suddenly experiences a huge spike in risky activity, starting is machine learning will suggest a new rule to detect it. If you're creating the rule, you can decide what to do with the transactions or accounts that triggered this new rule. Some of your options include putting the system in shadow mode to gather the data, but not actually take action on these accounts. Or you can send them a manual review or automatically cancel them. This feature is so needed because often the time between spotting activity and finding the right rule to trigger can take some time, especially if you're relying on traditional legacy rules and data analysis to manually create new rules. In this case, you can go from experiencing high risk activity to making a rule and acting upon it within hours instead of days or weeks. For more information about this feature or any of the other products within Sardine, go to www.sardine.ai to read more information or to request a one-on-one product. That's amazing. You just dropped four megazine, those articles, or it's like a shocking article. The two that really concern me is using it in an automated way to scale up subversion of people's fraud detection, so that's right. But the event worse is using data breaches, using AI, to really narrow down to a person, kind of like we talked last year, creased the data typing and then pieced together to become you essentially make your credit card profile. They've assumed your credit card profile, which fooling like the Falcons and the other transaction system. It's a way of deepfaking you, almost digitally, in a way, in your thought of. Yeah, it's like a deepfake without actually needing to deepfake you. It's like you're deepfaking you via the data without actually having to deepfake you as an individual. They look at your pattern because those transactions, a lot of them monitoring systems are successful because they profile your spend pattern. They profile where you shop profile, those things are now available in data breaches and they mimic it. Well, I'm just going to break just what if they do an account takeover as Matt said, they have access to your account history with that app or that merchant, right? So they're able to see or if they log into your email, they can see all the past emails that you got from that, you know, that merchant, right? Door dash, if it's Instacart, if it's Uber, if it's, I mean, it could be any, it could be Target, Walmart, it could be anybody. They can look at your spend patterns and go, okay, so they usually spend about $200 every three weeks. I'm just going to set up a lot to come in every three weeks and spend a 200 bucks on this car, you know, and they're not going to, the bank isn't going to catch it. Or when you know, here's what's worse, I'll have to dispute it in the bank because this is you. Yeah, please go to staples. Correct. I was about, I was off to say that too. It really screws over merchants on the charge factory resentment side because a lot of times you're looking at is the address, you know, is the billing and shipping similar or the same. And, you know, did it get ABS? Why? Well, if the zip code is the same, then it's going to get some ABS. Why? And now you're able to say, no, this is the card holder that made this purchase when it may not be because. Imagine buying the same item that you've already purchased. So let's just say you put an iPhone like seven months ago. Right. And they go in and they use a similar trick, but they buy the same item again. Now it's like, oh, so like the attacker just happened to buy the same exact item and they happen to be in your zip code and they happen to buy it at the staples that you bought it at. Yeah. Right. That's the problem. Right. People people are going to be hurting. And then by the way, if the attacker needs dispute evidence, I'll just use AI to fake fake some disputed and then met it anyway. Right. Archbacks or refund fraud too because you don't even have to contact your bank, you can contact the merchant directly and say, you know, the screen was cracked or, you know, I got two left shoes or whatever it is that you asked AI to, you know, come up with a picture of they can very easily do that. That's a good one. Two laps shoes in the box. Yeah. Those are things that people claim for refund fraud. They'll buy two pairs of shoes and then they'll take a picture of just the two left feet and say, I got two left shoes in this box. So you need to give me my money back. Yeah. But don't you do that anymore? And you just take a picture with BT and say, that's it. Make it two left shoes. Exactly. That's what I was thinking. I would be easy to do. Yeah. It's wild. And like, I would say like the all the stuff that Frank talked about, especially that stuff is worries me the most on the scam side. Like every day people are going to be far more impacted than businesses are, I think on those, I think they're going to still businesses are in banks are still getting impacted by deep fakes on IDV, on selfie checks, etc. But I think that every day people, the civilian population is going to get get a lot worse, like to the tune of potentially trillions in the future on on these types of scams, because, you know, you're normal grammar and and, you know, even communication styles or like there's no longer a bunch of red flags. Like there used to be. Right. Like if I get a text message that uses the word deer, like I immediately like, all right, they're scamming me. Right. But like all that all that is is gone now. Whereas these attack factors, the things that worry me the most in AI is actually a gentick AI, because they're able to scale it like so much faster and more aggressively than ever before. That dropping just picked up on that two weeks ago, right. The Chinese nation state actors were using agents to do cyber attacks. That's right. It's a huge problem. So you can like even like so here's a perfect example, even bin attacks right or, you know, some of these let's just call it like a numeration attacks right. You can imagine being able to do that at like 10,000% increase in volume speed and rotating. And so you're able to like, you know, what would before it would take a human to write a script basically to initiate the attack. Now you could scale that 10X right. You could do it at half the time faster and you could be more clever by rotating, for example. And then they're also using now AI to with the Lune algorithm. So the Lune algorithm is just about to say that it would probably be easy enough to integrate Lune algorithm in case they're only testing. They're only testing card numbers that are accurate that would pass the Lune algorithm. How would you now I'm very curious about that. What is that what are they doing there? So the Lune algorithm basically the algorithm that there's a few but Lune is the big one. It's the algorithm that basically allows financial institutions to recreate pants. So you're recreating the full credit card details, right. You can kind of work backwards and have a pretty high degree of success by using your own Lune algorithm to recreate new cards. So you could basically say using this particular logic, right, or let's just say this type of information, recreate me 10,000 cards using the same algorithm. And there's going to be a good percentage of those that other Lune algorithms have also replicated and are live in the field. So you can for example, like. Card testing, wake up actual cards that are active, right. You're like you're working backwards, right from it. And so with the AI enhancement, you can increase the accuracy of that and the scale. Do you guys remember maybe you know, but there used to be a little thing you would download to your software. It was like the 1995 was called credit master. And it was basically you'd type in a card number and it would use the Lune algorithm to generate a thousand. Yeah, yeah, yeah. So this is kind of like the credit. Well, yeah, and already fraudsters have figured out the individual bins and how they create new card numbers. So essentially, you know, they can get a list of dead cards, right, like cards that have all been canceled because of fraud. And those are still valuable to them because if they're AMX, if they're discover, if they're, you know, certain, certain issue issuers within V semester card, they can say, OK, I know which Lune algorithm this bank uses. And you can use AI to determine which which algorithm they use, you know, how are they generating because all you need is the old card and one new card, that's all you need. Like, I mean, for instance, my debit card, when I get a new one issued, the only thing that changes is the last four digits because they have my bank account number in the middle. I mean, the first six digits are my bank and then the middle is my account number and the last four digits is the only thing that changes. So if you can figure out, OK, that bank only changes the next four, then you can have a dead card list and figure out what's the next card number. You know, going to be done and you come across victims that say, you know, my credit card keeps getting stolen and I don't go to any websites, I haven't even used it yet. Like, I hadn't even gotten it out of the envelope yet and my new card number was stolen and it's like, well, that's because they figured out the Lune algorithm and they figured out what that next card number was going to be and they hit that before you even got the card in mail. Right. You can do that for several cards in a row. Yep, that's right. So it's wild. Yeah, we're just in the, and by the way, like next month, there's probably going to be 10 more new attack factors, right? Like, these are, I think that's the, that's the part is like their ability to create new attack vectors and like, pen test them is like easier than ever before. Right. And so before you needed to be pretty sophisticated software engineer, now you could be a 16 year old kid in your mom's basement and like start executing on these attacks. And I think that to me is where the danger of AI comes in. What's really interesting is the regulators are like pretty concerned about this. So like we, I've had the pleasure of like speaking with the House Intelligence Committee on this and their house fund services and they're like, they're very concerned about like, how do we, how do we implement the current administration's policy on like, pretty aggressive AI adoption while putting in guardrails and like, how do we enforce those guardrails, which is very hard to do because it's, it's almost impossible without a regulatory body and audit, et cetera. Right. And then the other thing is like the liability shift is insane. Right. Who holds liability at the end of the day on these on, especially in the agenda commerce school and in agente agents. There's a user is it the person that built the model if the model fails and they purchased the wrong item is at the merchant because they didn't challenge it effectively. My solution is actually roll back to 3DS 1.0 and 2FA step up every single agente agent. So let's just say an agent comes in and tries to buy which is saying iPhone on Apple, right. If you use 3DS 1.0, that was the old, that was the old model that would always step up. So it would basically call your bank, get the phone number linked to the bank and then push a 2FA to your phone number saying, do you authorize this transaction? Yeah. Are you passing the liability instead of to the issue where I would pass it to the customer because the customer is actually saying, yes, I authorized this transaction. Yeah. Issues used to do it too is issuers a lot of times if the customer authenticated that they allowed this transaction to go through and then later claim they didn't allow it without any robust evidence that then you're going to take liability on it. Oh, sorry, Frank, I about to have a guest come on the podcast in the next couple of weeks or be very beginning of the new year to talk about that because they've really been studying the liability of agente commerce on card payments and, you know, in all of the different scenarios that can go wrong, like you mentioned, it's it's crazy to think about. But the more you move ahead, the more you go back, which is like the government, one of their responses to stopping fraud and this is like a legitimate proposal is have everybody go to the post office to confirm their identity. Yeah, I'd like to merge it. If you have a problem with your bank, they go, oh, go to the post office and they'll verify your passport. Can you imagine like you're going back to the dark ages. It's wild. I think honestly what it comes down to is the scale. So like I had I spoke with, by the way, like probably the best government organization I've ever spoken with was called the DFPI. It's California is like basically their their innovation and financial services agency. They are like proactively reaching out to the industry for guidance and education and training to like stay ahead of the curve. So I was very impressed with them. But like the problem comes down to like the scale of this is so large that like how do you implement as a government, a policy that impacts hundreds of millions of people or billions or trillions of transactions. Right. So you start looking at really, I mean, first off, by the way, like the EU, in my opinion, did a phenomenal job on PST, right, all PST, et cetera, PST 3, like the like that's probably the right approach in some cases. But the US is behind the curve. We also as Americans, like do not like paying for things. We don't like friction. We're all, you know, kind of pretty stubborn on this stuff. And so I don't know if it's going to get over. And most most regulators will not die on that hill. Right. So that's the other challenge is a lot of them are not willing to like take the bullet and jeopardize their career. Yeah. So they're not willing to like really fight for these regulatory changes. Yes. So one more thing going back to how fraudsters are using AI that was one other example that I wanted you to cover. Matt, and that was website phishing attacks and how quickly fraudsters are duplicating websites of legitimate e-commerce companies. And, you know, using that those duplicated websites to gather PII and gather information from new victims. And those impersonation scams, you know, impersonating a legitimate business and scamming, you know, customers where they think they ordered a product, but it never comes or things like that. Or their credit card gets stolen and they only made a purchase at your website, you know, those type of things is really bad for the brand. And I understand that you've, you've watched fraudsters be able to recreate these and duplicate these websites in minutes where it used to take hours or days. Yep. Yep. Exactly. In fact, Frank and I were just talking about this before as you know that both Frank and I have done this attack vector as testing right to see how in from a research perspective. And I can give you a perfect example. So recently a Canadian bank reached out to one of our co-founders and said, hey, like this was a C-suite executive. And he said, I want to scare my other C-suite executives of like what the AI attack vectors are. Basically, give me a free, you know, give me a free test of like scare me. Yeah. And so what we did is basically we used a replication model that basically we went in, you just take screenshots of the website, the login portals, anything that you want to replicate, right. And you just simply use some of these tools out there won't give the exact one that we use, but it's it's highly effective. And you drop those screenshots in, you prompt it to replicate it, and then you tell it what you want to do. So for example, I want the login portal to function, I want to whatever it may be. And basically it'll recreate that, you know, let's just say 60 seconds on average, it'll recreate a fully functioning website. In many cases, it's an exact match. In some cases, it's a partial match and then you just do one or two more prompts to basically fine tune it. And then what they're doing is they're doing a couple things, one, they're buying like traditionally, they're buying a similar URL, right. And then so let's just pretend like it's this particular Canadian bank, and then I would put Vancouver dot CA, right, let's just as an example, right. So I buy that that URL for let's just say, I think it was $11 a year, and then you use you go live with that website, all right. So now the website is live. And then what you do is what's what's really fun is you use AI to basically beat out search engine optimization or, or even AEO, which is the AI search engine optimization, right. So you're using AI to kind of hack their own optimization, and you can actually beat the real bank in the search results very easily now. So before you would have to buy the link, yeah, I sponsored links and you would just beat them out by paying for the ad. And so you would be the first one to show up as a link with like Google, you'll see recently, they've actually removed some of their sponsored links and they're moving into more of an AEO type model. And, but you can still beat them. So we actually beat them in real time. We beat them in the search results. And then when you go to our fraudulent site, what was happening is when you would go to log in, you could do two things. You could do a man in the middle attack where we would funnel that credential to the real bank. And then basically, so like the real user name and password, even if they saw it as a new device. And we would just ask for that to a day on the first right. So they would now give us their to a day, which means we now have fully authenticated access to their account and we push them to the real site so they re log in. So now they don't know we're actually in their account and we're fully authenticated. So that's one way to do it. The other way is you simply fail. But when you fail it, you're capturing a lot of details like the device location, the altitude, the screen, the battery, the health, the IP address, right. You're capturing all of this data on top of the user name and password so that you can emulate it very with a very high degree of precision. And a lot of the new device emulators that are out there, you can you can emulate a lot of pretty unique details about the device. So you can try to match that person with a high degree of accuracy using the same device that they were using the same operating system, the same language, etc. You ask, now you fail. That's it. That's it for depressing. Every time we talk to Matt, I'm just filled with hope and optimism. I mean, the good news is is that we know about it and all of us are working very hard to prevent it. To build technology to defend against it. So that's the, you know, the downside is that these new attack vectors are always evolving. And now they're evolving faster than ever before. The good news is the technology to prevent or mitigate or respond to them is also evolving faster than this. Yes. Well, let's talk a little bit about that. So what kind of fraud signals no longer work. I love to depend on so many and which ones just don't work anymore. I have some ideas, but I would love Frank's opinion on this. I'm just curious. What does it don't work? I mean, for that, you know, having a rule in a system that all the time, right? It's got some this zip code and this IP range of that type of like very static rule sent that's based upon a particular fraud pattern is is not working anymore. It kind of used to work for a month or two, but now it's probably then a couple of days. It's almost interesting that when you were talking is almost all fraud and scams are now cyber attacks right there. A lot more less like the more cyber they're more instant they're changing just like cyber attacks always have so you have to almost look at all fraud and scams as being extremely dynamic. That's right. Yeah, I agree with him completely. I think a lot of the static stuff that we used to use doesn't work. I think a lot of the geofencing technology it works for for low sophistication stuff the more high sophistication stuff can pierce that stuff. You can and the other challenges is of course like you know the VPNs and proxies the world's like they're just so widespread that those signals are not as effective anymore. But the good news is is you can pierce a lot of those which is interesting so like we have some technologies so we just pierce them and we can actually get the true true geolocation. I think that a lot of the device signals are no longer as viable as they used to be with some of the new emulators that are going on. I think the real challenge is the real concern that the industry has right now is on the agentex side because the fact that you're separating the attacker from the actual act. You have agentex agents for example that are doing the fraud for you right they're actually doing the shopping and using the stolen credit card during checkout. You no longer actually are able to capture the same intelligence that you would before or look or or behavior. We behavior is still a very powerful indicator today. Or it is even using AI attack vectors or even agentex attack vectors they still have the behavior right they still click in a certain location on the page they still move at a certain speed they still type at a certain speed. So even though even though in some cases the behavior of the user is separated the behavior of the agent is just as important. And there's some interesting things that are happening on the master card and visa side of the house with pass boarding agents right to where you basically have to get yeah so what they're working on at a high level what they're working on is basically in order to transact on their network as an agent you have to be basically passported on via tokenization. And so you're an authenticated agent so the agent is almost like you know KYA yeah right and so they're they're basically pre vetting the agents and they're basically they have pre approved authenticated agents on the network and those are the only agents that are going to be allowed to court report transact. At a high level that's kind of some of the projects that they're working on that's very interesting. And then that kind of helps de rescue a little bit because now you have at least trusted agents the problem is humans are humans and so like humans are still going to exploit those agents and like it becomes a whole different kind of muddy area when you have an authenticated agent that's being used for fraud. Right you think mad do you think like the normal person like me or you use is AI agents to do their shopping for them or is it just all straight. I have a very unusual opinion of this that's probably going to even piss off my boss but I'm going to say it anyways and my opinion is I think agenda commerce is not going to be anywhere near successful as people think it is I would bet my career that even hold me to this that it. They're not going to see a rapid increase in purchases and growth of their maybe because of a genetic and the reason for it is it will definitely potentially increase the user experience because it'll allow you to do more but you're not going to buy more or buy things that you work going to buy just because you now have an agent to do the work for you. Well maybe you know right but like give me a break I mean by the way do you trust the agent to make those purchases like you're going to go on a case and you want them to do it for you good luck. It's like you're interested but the other part of it is about that always gets me the agent says you know when I'm shopping I'm like you know if I go to a site I'm looking at it gone I've never heard of this one before yeah the sweater is like 19 dollars. It's you know I can tell it's probably going to come from China it's going to be really. The agents are not going to know that they're going to be buying you a bunch of junk that's right and you're actually able to get your money back it's like. Well it'll lead to a lot of charge but hacks. Well and you know I actually I agree with you on that Matt as far as I don't think it's going to be I think it's a lot of hype. I think it's you know something that a lot of people at frog conferences are having fun talking about right now. But I do see some use cases actually in travel and tick event ticketing especially. All ready. The agent AI has been used kind of for years on the broker side of around for a long time it's been around for a very right that's like people don't realize it. A gentick has been around for a long time. We just called them sneaker bots of course yeah of course right it's the same similar. We just called them something else yeah yeah but in the ticketing space I don't know if I agree and the reason why I don't agree. I think I agree with I think I know what you're getting at and I actually agree with the use case for sure where I think like the ticket masters of the world are just going to have a field day. Because you're going to have like much more sophisticated bots come in and buy up an entire conference for example. And then sell it on the secondary marketplaces which is already a problem for a lot of them right. So like you have to have find this like dichotomy between like allowing the good agents to make the purchases but blocking the bad agents and like good luck doing that by the way because it's going to be insane. And by the way like how do you manage third party agents that are just transacting through the user portal so like that you can't defend against. So you can defend against agents that are pre authenticated and authorized on a particular platform or service. What you can't defend against is me using an agent as a customer and just using your public facing website to transact right. It doesn't matter if that's on the visa or mastercard network or not because they're just going to be operating as a human in that case right. And so did luck trying to defend against that and now you don't have by the way the device same device signals etc right. And it's like we're and by the way like what are you going to do you know block the IP address of like you know chat GPT. It's easier said than done. That's the concern that we have. Yeah. I just mean like from a from a consumer adoption perspective. Oh yeah I do think that in ticketing and travel we'll see that because you know hey if I could set it up so that you know when tickets go on sale at 3 a.m. And you're up for a concert I want to see you know in Lisbon next year which may or may not be hypothetical. You know if I can set up an agent to buy those tickets at you know 3 a.m. I time when they go live and I can tell them you know which which area I want to take a price you know all those things and then they just is set up and go buy it that's perfect. I was trying to find the right flights to the right you know to the right place or that type of thing or the right flight prices. But the ebay case is actually better to me. The ebay case is exactly right is like you you you snipe right so you just have agents run through on the items that you want. Yes. They learn like 7 milliseconds before the. Yes. Right because you can just train them with a very high level of accuracy right so like that is an interesting use case however the agent is not going to cause you to buy more in my opinion. Yeah no I think what's interesting. It's a little mess up that's the problem is that like you know if if consumers all adopted and go okay I would just want agents to buy for me. I'd much rather tell them what to buy than me actually go to the website and put it in my cart and check out which I don't really know if that's true for like traditional hotel. Explain to the agent what to buy. Exactly you have to explain to the agent what to buy when how where you know where to ship it where to do it what to you you're giving them your credit card number. You don't necessarily know you know if this a agent is legit you know and you're just giving them your credit card number. I mean there's a lot of things there that I don't think it's going to be adopted by the typical consumer hotel. But I do see it in ticketing and travel a gambling is another one that I see it in is what I could see it being used in. But last second of the game or you know whatever they're doing you know getting that bet in. I think that the regulators will kill that quickly. I think that like you start getting into gambling or regulatory regulated. Well yeah because at that point you're now using technology to game it it's like starts falling. That's true that's true yeah. But by the way I'll guarantee you you're right that people are going to use it for that. Yeah for that they already are. Yes I agree that I don't think agent commerce is going to be used for this whole new wave of commerce and all these new sales that you know. Some e-commerce you know experts are predicting what I do think it's going to open up a lot of mistakes a lot of customer you know. Customer service problems a lot of charge back issues a lot of refund fraud issues. I think it's going to open up all of that and that's where the liability gets really sticky. But on the balance like just everything. It just seems the more AI use cases come about it's always slanted to the fraud like yeah your fraudsters are going to love it. Yep and maybe just a segment of consumers are going to love it and it's always the fraud that is seems to be the major winners a lot of use cases for you. I would say in fact probably probably like 75 to 80% of the use cases I see now are all fraud related. Even the speed of things like the automation pieces like you know all the enhancement where like it does increase the value in your day to day lives it can like make your life better. It can make fraudsters 10x more effective. Yes and so like how do you regulate against that? Well how do you just on the if you look at a macro level all the money that's being plowed into AI for open AI Microsoft Amazon if you look at the call the magnificent seven right. The seven that are allowing all the money and it's causing the stock market to be artificially inflated if you take those seven. Out of the stock market it's barely moving we're barely growing we're climbing all of our money as an economy and as. Into AI and like 97 the use cases are for for on it's like. And there's all sorts of circular type of you know investment or inventive ideas of you are supporting companies that are going to buy their product and open it. There's a lot at stake with AI that isn't going to pan out very well. I'm more I'm cautiously optimistic I think that like if we use the tools effectively and stay as far ahead as possible we can. Most of it but I can tell you that like fraud is going to keep I mean like Warren Buffett said fraud is going to be the biggest industry of all time that's really a recent recent statement. I think that's a that's very interesting because he's extremely smart but he has to be get further along you see just have true that it's a tall. Yeah and so that's my concern as I just think that we're we're we have lowered the bar of entry as to be a fraudster lower than ever in human history in my opinion using new AI and automation techniques and I double agree with with what Frank said is that AI or excuse me fraud is transitioning into more of like a cyber fraud world. Versus cyber security type attacks versus traditional human based attack vectors that's just far more scalable faster and more money to be made. So how should fraud and risk teams evolve now that fraud is scaling with AI I mean how can we keep up with it how can we you know be able to identify I know that you said behavior is a really good indicator. But what are some other things that fron risk teams can do to try to identify these things and stop them. Frank you want to you want to take a first stab at it well yeah I'll take a stab and I'm sure you got a lot of ideas not that they I think the. Companies need to give their fraud staff access to the same types of tools that that for that the criminals have right they don't hold them back from using the I because. Fraudsters using it and not to get the same types of agents and the same types of technology and the same types of AI is going to put them at a disadvantage I think a lot of especially think about banks right they're very very conservative but they in order to survive they're going to have to break out of that they're going to have to start investing in letting the fraud people have. Access to really advanced tools that are dynamic that are going to be able to help counter some of these types of things we're saying on the on the attack side. I cannot agree more I think that that is probably that is incredibly well said you really have to go from a defensive to offensive posture. And and that's really what it like I can tell you I know a head of fraud a director fraud that was fired for. Downloading and using telegram to try to keep track of new attack vectors that were targeting them because like they didn't want him on telegram right. Yes that's right so the like stuff like that to me is wild like yeah you're basically you know you handcuffed your fraud prevention team and then help them to a standard as if they were using those same tools to like you know compete against them so the what I would say is you need to be a very highly proficient user of AI. To be a data scientist but you need to be very comfortable in an AI world start playing start using these tools start messing with agentic start using like the gems on Gemini that you can create your own agents for basically. You can start like start playing with n8n for example there's a lot of like really good like early entry tools that you don't have to be a data scientist a lot of it is drag and drop or English you know it's a standard text prompts. I would start staying ahead of like prompt injections are very interesting because you can get ahead some of the really fun ones are like the emoji prompt injections if you're familiar with these were basically what they're doing is they a lot of a lot of companies especially the big ones like the open the open a eyes of the world. They have a lot of guard rails to prevent you from abusing their models for for for you know what the problems first games are yeah you can hide around them by basically let's take an emoji and then you hide your prompt into the emoji and you paste the emoji into it. And the guard rails don't fire the same as they would and so you can get the models to do things like there was a big one a big model i'm not going to say the name using a certain type of emoji prompt injection you could get it to tell you every company that has prompted it for a business case and the data that they prompted. So those are examples of like these are things that you want to as a fraud fighter be aware of and you want to understand like you need to be proactive the other thing I would add which really actually is double tapping on what Frank said is like if you don't have a threat intelligence program you're really behind the curve and what I mean by threat intelligence program could be as simple as you. Spending your Saturdays going out into the wild and seeing what's going on going like you know Frank is always posting about crazy stuff happening on telegram of all sorts of you it could be small ranks but that's where a lot of these new technologies and attack vector start is in these bubbles of a few friends on the internet and then it starts exploding. I would actually go out and buy the fraud books on like how to defraud people as they sell them they're like fifty fifty bucks you can learn how they're actually doing it right and like learn to be a fraudster I would definitely start learning on how to how to utilize the dark web more effectively get into these forums most most of the most effective ones that I've used like there's a couple fraudsters that are friends that act as fraudsters that really you have to like actually integrate into those societies right. The best thing you could do is once you're in there you can honey pot them yeah and that's where we learn the most intel at sardine is I'll go in as a fraudster and I will actually feed them information to actually have them start using their exploits on a particular like target for example right but we're sitting there waiting for them to do it and watching everything that they're doing so that we can learn what attack vectors they're using how they're getting an extra up. So we have a whole on-ramp product it's a crypto related product that we use almost exclusively to learn really unique attack vectors on of course it's a totally legitimate product it's it's highly effective but are the where it adds the most value is actually learning really advanced attack vectors by honey potting attackers and so I think just teams need to be much more offensive now than ever before in order to stay ahead of the curb is like you know like you're like you know really you should be at emulating what Frank is doing and it's he's constantly out looking for new things and looking for new attack vectors and looking for like all of these kind of new new hot off the press right like roll and lice if you can beat frank to the knowledge to where every time Frank posts on frank on fraud you already knew about it you're probably in a pretty good place. It's in me the tip I would that would be amazing yeah New York's interesting that is that usually like this places I get the information are like in a Reddit post victim is like hey I just got scammed for this and then like two days later somebody else says I just got scammed and I remember all of that and all of a sudden then it's on tiktok and then it's on YouTube and then all of a sudden it's this huge scam and then it's in the new york times like three months later it's those little tiny things on reddit on telegram on instagram of tiktok those are the next broad percent that are happening right now having somebody. It's especially if your big organization we can have a dedicated person you're going to save so much money through that person's work really. 100% and that's where the proactive comes in right and that's where these big companies do it that's the big you know world class players the Facebook's the Google's the microsoft they absolutely have a threat intelligence program and it's very effective. I can't afford it in house or you don't know how to support it in house because you don't want to have the tour browser and you're on your network or whatever. You want to get a program once but that's not real yeah. There are third parties that you can hire to you know do some of the more sophisticated things to learn those threats but I have learned so much the way Frank has is just by having telegram on my phone and if I have a merchant reach out to me and say and we're getting hit by this new phone. I can't figure out how they're doing it. The first thing I'll do is search that company's name in telegram and a lot of times I'll see exactly how they're getting. Oh okay so the merchant told me they're seeing this. I'm looking in telegram and seeing how they're doing it. Okay we can put those two things together and figure out how we can identify them. I can tell you that the vast smudge I would say over 90% of every attack vector of every exploit is able you can find it on the open web. You don't need to go into the dark web. The vast majority of it is open web. In fact that's why open source intelligence is so powerful. There's a reason why the NSA CIA, DIA have open source intelligence programs that are massive because it is highly effective. Just like Frank alluded to when you have a little tiny blurb where all of a sudden a new attack vector comes out because someone says hey I got scammed this way and I've never seen this before. Frank hasn't seen it before and now we're screwed right now we got my pulse at something's wrong when I see Frank Frank post something that I haven't heard it before. Then I know we got a problem so that's the place that I would start is think of it like even learn open source intelligence techniques you can there's a lot like online learning that you can do. There is. We have to be more proactive in our industry now more than ever before. Matt do you have seen like some post on this our team like you guys have you guys use agents to right are you guys are you exploring that like I'm just curious how do you what's example of how an agent can help like a fraud analyst or like a. AML totally you really took the question out of my mouth right I love yeah I want to see what is what's working yeah that's exactly where I wanted to go. There's two pieces one it's very effective in the threat intelligence space to be able to get like basically for scraping purposes into alert on unusual activity so we have like threat intelligence that we offer now as well but more importantly on the agenda side automating repetitive tasks especially in alerting so I'll give you a perfect example like a really good one that we're developing and continuing to develop is a star narrative agent right where you're taking information that already exists within your compliance portal and basically converting that into a full star narrative that's ready to submit. And where we find success is providing the capability and we have multiple agents right and so you can do from alerting cues to clearing alerts to writing star narratives there's a lot of different use cases even in like you can you can we build agents very rapidly so we were very lucky in the fact that we have an AI machine learning engineering team that's dedicated just to this so that's the only reason why I would say like we have a little bit of an advantage here because like where it soups our CEO definitely has this mentality he definitely does not follow the move fast and break things but he does move in the move fast and try things. And so oops is willing to take bets that others are not and he's willing to try things knowing that it might not work but we're going to learn something really interesting by doing it. And so I would say the two really effective places that we've seen a genetic where it's actually scaling effectively is one where it's human in the loop where basically we are automating the heavy lifting of the user but the the analyst is still doing making the final decision. So in places like that were even if the agent fails and it's pretty rare but even if the agent were to fail for some reason you still have human eyes on it from a regulatory standpoint right and so like for example those are narratives right that should be human in the loop in most cases but there's there's companies that are willing to take the bet and say hey. Even though this works 98% of the time right that's still probably better than the human the analyst doing it right and by the way we're able to do it faster and at scale so we're actually producing more we're giving the government for example more information and better information than we were before then with humans were doing. So there's like this kind of interesting delineation happening in the industry between the human and the loop versus full automation and it really comes to like regulatory flexibility on it and clearing SARS is like the one that's like really sketchy and I say sketch like the regulators don't love that one. So using AI to not send information to them that's when they start getting twitchy right but if you're using AI to help provide better information to them thing that they're more open to so again it's like really we spend a lot of time thinking about like how do we solve the right problems with the right solution and I think that this is. And you can you can even like play with our agents you can go on our website we have tons but I think the key is is that we're really trying to we also like custom build our agents that's the other reason why we've been successful is we we have the ability to basically call it refit the agent to help solve a particular use case out of particular company and that's very very effective and it's also like it's they're basically simple feature flags. So companies can turn them on and off very effectively and very easily without impacting a whole like API integration build right and so that approach that we've been really really lucky on and I think the final piece that I call it which we talked about is MIT did a study on on AI use and agentic use in the fintech space and especially you know just industry wide and they found that something like 90% of all projects fail. And what's really interesting about the study I mean there's some some gaps in the study that they can that like you know the technologist talk about but in general what we find is the CEOs of companies are saying you know you well use AI to their team right like they are forcing AI automation in their team is they're hoping to. You know drive efficiency they're hoping to lean out but what we're seeing as an as an industry is we're seeing two things happen one AI is being used to solve the wrong problem right so there's problems that are that they're trying to use AI to solution which is not the right problem for AI the other thing is or seeing is AI is not really replacing jobs like people think they what's happening is the employees are becoming more productive but they're not they don't trust AI yet to the point where they would replace the employee. So I think that that's really interesting to and so the if you can provide agents and agentic agents for example to 10X the performance of your team that's very very valuable that's kind of the angle that we're taking. That's great so there's some positive help yeah the combination I think it's a combination of using agent to AI in the right way to identify fraud and you know be able to augment fraud teams so maybe you don't have to grow them as quickly you know by number of had count that type of thing but there's also using AI. So well not to say I but you know sophisticated models and behavior biometrics and even device intelligence using those two together to look at those patterns like you mentioned before you know even agents have patterns right everybody has patterns on how where they collect how they do things what you know where they keep their battery life at like you know the language on the browser the size of the screen how they're holding the phone like all those things you could identify. Everything from simulators to you know to AI agents doing these things because you're using that behavior biometrics you know to really look at the behavior. And so I I'm a big believer in doubling down on behavior biometrics even more than agent AI. But I know that you know being able to augment human you know capabilities with more techniques and and more technology is the way of the future in my husband works for. I don't even know fortune 100 fortune 50 company and it's a big one and he is a product manager and he's been implementing AI in all the processes that they do from a product perspective and you know a lot he was saying the other day that he thinks in five years there there will be no more human developers. That's really interesting I don't think that there will be no human developers but I think it'll be much more software engineer specializing in QA versus versus actually writing the code I think like we're already pretty close to that surprising. Yeah yeah like there's a very powerful and they're very effective and a lot of them you know so I think like QA is going to be interesting. But for companies that are building like QA agents right so it could automate that out but like I still don't believe I'm not a huge believer in this like futurist model of like no humans like Elon Musk recently said like a work will be optional in the future I don't know by that. Now I'm not going to bet against Elon Musk because I know that that doesn't work out well but I just don't buy it yet because I do know that humans still like I think at the subconscious level we don't trust artificial intelligence. And I think even the more should we if they're going to continue to look you know they're only as good as the data they train on. And they're only as good as the people they prompt them or give them information. It's Frank talked about yeah like the agents are not you know these models. I don't even remember if we were talking off screen or not but basically what Frank was talking about is that you can have two people doing the exact same task and if one of them is very good at working with agents and one of them is not. Then their outcome is going to be completely different. And there's by the way there's human biases that play into those right and there's all sorts of problems and if there's biases that play into these models. And again that's like the big push with open AI that everyone was freaking out about is like it's his data science team that's like building these models and making like human decisions on what they should not share right. So it's it's really an interesting problem in the fraud space luckily it's a little bit more simple as crazy as that sounds. It's like more focus on automation more focused on increasing efficiency the ability to capture it but we I can tell you right now 100% AI is being used against AI. We are legit world today where we have we currently actively have AI agents and models running at sardine that are combating other AI agents and models like I see it every day. So we are literally in a world today where AI is being fought and defended against AI which is wild I never thought in my career I would see it but we're seeing it today. And to your point. Carries about the model the you know there's the agent but then there's like the machine learning classic in the class and it's like deep learning. You know Google just came out with they call it nested learning which they they are backing and they're going to say that is actually second to be the LLM this is going to be the foundation for continually learning. Models on behavior so all of these Falcon type products are like the underlying scores can use this new AI that's. Not just a single mode but a series of many little optimized models that are all self contained learning on their specialty and then you get this one super score so can look at things like the IP address and the speed and all of these different things and each model can focus on one thing and. You have this like super model that can basically be like an all knowing model and not necessarily like an agent right so I. It's wild I read that and it was fascinating the other thing that's like always always as funny as when I'm in conversations is AI has been around for a long time and the reason why it has been around for a long time is machine learning is in the AI bucket it is considered AI by almost every data scientist. If you get out of the weeds it's not AI it's machine learning but if you were to draw the AI framework machine learning is very clearly in the middle of that so like these technologies have just been adopting and evolving but like the consumer facing version of it is what's new right like before it would be really really rare for someone on the weekend to like prompt a machine learning model that's not going to happen right but in the business world we've been using these techniques and technologies for many years. Frank I mean even back then we were talking about that back in the even the teens you know yeah yeah you know 2020's even 2017 you guys were already you know leading lead. Well 1997 when I moved to San Diego as repair agency software the first commercially viable. A machine learning our AI application in history was 1997 and it was. Taken from the military it was desert storm technology that was. You would examine satellite imagery in the desert and it would find the patterns in the desert where it looked like a take so instead of like. Taken claims out trying to figure out where to bomb the reason satellite imagery and just using missiles to hit these tanks with AI that was back in desert storm and. That became the basis for credit card fraud detection so instead of targeting tanks they use the added target the rare instances of fraud. You know what's so interesting about I didn't know that story and I need to buy you a beer one day and actually that story more because that's fascinating the other one that was fascinating is some one of the. Engineers in Israel that worked on you know what is it you know the iron dome basically was an engineer that worked on basically increasingly accuracy of the missiles to be able to shoot down another missile like that targeting algorithm that he developed is now he's now trying to build to target anomalous activity. You know about prevention space he's more of a researcher now but it's interesting how this like that transition between. It's happening more than people think surprising even in the cyber world a lot of a lot of a lot of the cyber attacks that you see initiated from the intelligence communities or the military. Frank that technology that evolved from the military to card fraud detection was that Falcon that's Falcon you know it was it was built by in UCSD are you from San Diego map by the way. UCSD is the mecca for basically machine learning neural networks and it was Robert Hecknellson he was professor there in the 90 80s and 90s and he started to work with the military like during the summer and he created this algorithm to help him in desert storm and then after that he was like oh I want to monetize this and he started agency software heck Nelson computing. And then he sold it to all the banks and now 70% of the banks use that still you know 30 years later there's all built from out of San Diego. Yeah they are legitimately the mecca they are the pinnacle it's like surprise me I don't think there is known for like everyone thinks of the Stanford's of the world but you know UC San Diego is like world class on. Yeah still around today yeah absolutely cool. Well as we begin to wrap this up like I said we'll probably you know try to do a part to in January to talk more about this because I anticipate getting at least a handful of notes from listeners asking questions about this stuff. And then also Matt and putting on spot that I would love to do a webinar with you in January where you're showing some of these things and able to actually share your screen. It's not something you can do on the technology that we record the podcast on but we can do it for the webinar and where you're actually doing demonstrations of these things I think that would be really powerful. But as we wind down from this conversation do you have any last thoughts or words of encouragement right we're towards the end of the year everybody's kind of feeling beat up. And then here we are telling them that you know 90% of all of you know AI interactions are going to be fraud or whatever we said. You know what any words of hope or just encouragement or or maybe just you know last words on this conversation. You take the first one free. You know what I'm always a big you know I'm fearful of AI but nobody believes it more than me like I just love it. And so I guess what I would say is if you want to your mind to be blown is get a subscription for $20 a month. Let's say choose chat TpT cloud or Gemini any one of them buy it and try their deep research tool. You want to know something just try it but in a prompt like give me the history of synthetic identity and and plot it out year over year. Ask it to bunch of stuff and then five minutes later you're going to have the most magnificent history sitting in front of you that you can learn from. I guess I would say is I would encourage people to use AI and start essentially be in fraud because it'll open up your eyes to the potential of how to use it. So that would be my advice I think my last. Yeah you stole my thunder there because I. The exact same thing is like we're in a world now where there's going to be directors of fraud AI agents versus fraud ambulance. And that's happening faster than people think in fact there's a bank in particular that just is about to hire their very first director. It's a director level position where their entire role is going to be monitoring the performance of agent agents. Wow. And so we're in that world that's absolutely going to be adopting so the more comfortable you get at using these technologies the better. And it'll really future proof yourself from an ROI perspective because if you're a very competent user of AI and you're very comfortable working within that technology you'll be able to drive much higher value for your company. Which again is going to future proof you against the risk of of job loss from AI. Wow. You know that's all you have a do you have a gem in on do you have have you do you say I me personally or no you do you you Matt do you say you heavily heavily. We we use it not only do we use it as a business very heavily but I use it through I'm a purpose well I like complexity quite a bit. I really like I think originally I didn't like Google now I love Gemini they've really come a long way. The one that I actually fall in love with is it's called open router and open router there's it's like normally it's an API like Elon Musk tweets about them sometimes. But you can go in and create an account and it lets you almost AB test multiple model simultaneously which is cool you can go in and like prompt and actually like run it against different models and like determine kind of what model you should use for the outcome that you're looking for. And so that's been kind of fun so I've been kind of like trying to you know if it's broad related you know is there a particular model I tend to lean into more complexity or or or Gemini in particular but you know there's all sort of if it's like general knowledge information I found that the chat gbt's of the world are pretty strong the one that's insanely good but like no one in the US really like wants to admit it is the AI model from. Alibaba those ones are wild but like you know do you you know anyways I won't get into it but you know that's right you use the model and they're giving the US a run for their money. Wow done yeah what's going on do you use it crease not a ton no I'm weird about technology even though I've been in the tech world for you know 2025 years in my day to day life. I'm I'm still you know asking questions to Google I'm not I'm not you in chat gbt are you are using a I then that's true that's true yes so I mean through Google and yeah but not like specifically and I think there yeah I think part of it is I don't want to train anything right like. Just use your own data to train their money yeah yeah but that's silly because I know I already I'm they're doing it anyways yeah exactly and I mean yeah and there's a story I can tell another date about how I recently learned that someone used AI to. Five of my podcasts and AI to create a persona and created a company that just got a million dollars invested in them. Wait your persona was used to yes what where is this I that I'll have to share it another time not on the podcast baby but I just learned that and I don't even know what to do with that information use some you need some money to that. As you know say I think you're entitled to 50% of the yeah you know aren't you enough the person that was bragging about it didn't think that I was entitled to anything and yeah I was like because because my podcast is open source and because I you know I provided the information that I provided in the podcast specific to charge box. And that's a little bit there that's tough that's a tough one if they're if they're using the idea but then I I went through exactly how to do it. Okay so there's one call around and they fed it into it and they fed it into AI and created a persona built a tool around that and now they've got heavy investments and are working with some top companies. I don't know anything no no they're not using my voice or anything like that no but they're but they do internally call it crease. I don't even know who that yeah but no I just it blew my mind when that was told to me I I literally said I don't know how I feel about that yeah my husband felt very protective of me and not so happy about it more than even I did. That's an odd one but yeah yeah so you know I think you know so obviously AI is I'm training AI whether I want to or not is what with the point of me bringing up that story. But yeah I just I'm kind of a lot I when it comes to stuff in my own personal life but I do you know I do learn about the things that are capable and what what is what is capable and I try to stay on top of that if you know what's what's possible with AI. I just don't play around with it myself. Well you're going to be well pay attention in the next couple of months because I think Google and the Googles of the world are going to have like an existential crisis is what's happening is that transition to that AI like when you do Google searches you were talking about the click through rate has dropped exponentially. Oh I bet you're seeing everyone's just reading the summary. That's right and so you monetize that if they're not clicking through which was their whole business model originally. Well that's why they say AI is killing the internet which today. 100% yeah so now that's why they're moving to a to a genetic browsers right to try to start start monetizing against them. And those I hate by the way those are not good yet you know I create we block them at at our company employees are not allowed to use them. Yeah those what it's taken from you. It's insane. Yeah it's insane. Yeah so that's so that's too early technology that's something I wouldn't touch. Well not surprisingly we went over the hour mark and I know that nobody's going to mind that whatsoever. I just appreciate both of your time and sharing of information so freely and my mind I think my brain grows a size every time I talk to each of you. So getting the talk to both of you at once is pretty awesome and we'll have to do it again if we can find time on the calendar where it works. But just thanks to you guys so much and I will include links to your LinkedIn profiles in the show notes. If people want to get a hold of you directly. If anyone isn't subscribed to Frank's newsletter you're crazy. But Frank on fraud newsletter is where I get a lot of my fraud news. And obviously Matt is a very good source of information as well. I'm a Frank on fraud subscriber myself so I'm a big fan so I completely agree with that but you really appreciate you both. Thanks for having us on. Yeah this. It was. Well thanks so much you guys I'll talk to you soon. Sounds good. Thank you again to Sardine for sponsoring this episode of Fraudology. And for supporting information sharing and collaboration across the fraud batter ecosystem. You can learn more about the team and their mission at Sardine via the link in today's episode description.

Podcast Summary

Key Points:

  1. Introduction of Sardine in Fridology podcast.
  2. Discussion on AI in fraud prevention and detection.
  3. Examples of AI usage in committing fraud such as deep fakes, business email compromise, and website scams.

Summary:

The transcription discusses the introduction of Sardine in the Fridology podcast and the excitement around it. The conversation delves into the utilization of AI in fraud prevention and detection, focusing on the dual roles of AI in both attacking and defending against fraud. Various examples of AI usage in committing fraud are highlighted, including deep fakes, business email compromise attacks, and website scams.

The text also touches on specific instances of AI exploitation for fraud, like using stolen credit cards based on geolocation, matching spend patterns, exploiting chargebacks, and employing password spraying techniques. The discussion underscores the evolving and sophisticated nature of AI-driven fraud tactics, emphasizing the challenges they pose for traditional fraud detection methods.

FAQs

AI is being used by fraudsters in various ways, such as creating deep fake videos, sending automated text messages, impersonating businesses on websites, and using data sniper scams.

Fraudsters are using AI to exploit vulnerabilities by creating exploits from CVE reports, matching stolen credit card details to accounts, filing chargebacks using AI-generated claims, and performing password spraying attacks across multiple companies.

Fraudsters are using AI to bypass traditional security controls by matching high probability credit cards to accounts, mimicking spend patterns for fraudulent transactions, and rotating password attempts across multiple companies to avoid detection.

Sardine introduced an anomaly rule product that uses machine learning to suggest new rules for detecting high-risk activities, allowing for quick action within hours instead of days or weeks.

Fraudsters are using AI to analyze data breaches and account takeovers to mimic individuals' spending patterns, account history, and emails, enabling them to conduct fraudulent transactions that evade detection.

Some AI-driven fraud tactics include creating deep fake videos, sending automated text messages, impersonating businesses on websites, and using data sniper scams to deceive individuals and organizations.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.