
Sign up to save your podcasts
Or


Welcome back to Fraudology.
AI is here, and it’s making every kind of fraud we already know cheaper, faster, and harder to catch. We are going to walk through a handful of stories that show exactly how AI enabled fraud is showing up right now. From card testing at scale to one very messy fraud story.
That story is Polymarket, and I spend some real time on it. It’s rare that we get this much visibility into a company’s actual fraud details. A Wall Street Journal investigation lays out the stolen debit cards linked to thousands of new accounts and a fraudulent deposit rate that hit 80%. I also get into AI-generated deepfake delivery orders, a bank coalition’s new warning about agentic commerce fraud, and a warning about AI voice cloning scams.
We aren’t eliminating fraud, we never can, but we can get the information to be as fast or slightly faster than the fraudsters.
What you’ll hear in this episode:I'm joined today by Sudhir Lanka, Associate Director of Fraud Strategy at GrubHub. Sudhir's team doesn't just cover GrubHub anymore. His scope recently expanded to include Wonder, GrubHub's new parent company, and Blue Apron, which means he's thinking about food delivery fraud across three genuinely different business models at once, and I wanted to dig into how that actually changes his approach.
We get into what makes a three-sided marketplace uniquely exposed to fraud, since GrubHub has to protect diners, restaurants, and drivers all at the same time, and a gap in protection on any one side eventually breaks trust for everyone else. Sudhir walks through the primary fraud vectors his team deals with, account takeover, payment fraud, refund abuse, and promo abuse, and gives some of the most specific, real-world detail I've heard on this podcast about how each one actually plays out, down to the exact excuses customers give to get a refund they're not owed.
What you'll hear in this episode:Welcome back to Fraudology.
This is a solo episode, and I’ve got two stories for you this week. I wanted to follow-up on the ID scan breach that Frank McKenna and I discussed last week. Where things stand now, whether we should still be worried, and what the driver’s license data breach means for KYC fraud prevention going forward.
And then I wanted to get into one of the biggest fraud stories this week. This one is brand new and I wanted to get it to you as soon as possible. A government email phishing scam hit Revolute using what appeared to be a legitimate .gov email domain. The request was fulfilled. Customer data was released. And it did not require a breach of Revolute at all. It required a spoofed email that looked real enough to pass.
I have been talking to my fraud threat intelligence sources about this, including someone with a background at one of the three-letter government agencies. What he told me changed how I’m thinking about this incident entirely. We are going to get into all of it.
This is a fraud news episode, and I’m going to keep it tight today. Let’s dive in.
What you’ll hear in this episode:Welcome back to Fraudology.
I’m joined this week by Frank McKenna of Frank on Fraud and Point Predictive, because this was one that I needed a second brain to process it all with me.
I was heads-down working on the Merchant Fraud Alliance agenda when my phone would not stop buzzing. It was a group chat with the people I trust to tell me when the big deals are happening versus just internet noise. And this time, it was a big deal. Brian Krebs had uncovered a dark web portal selling real driver’s licenses. Front, back, barcode, and all. For the price of about a hundred dollars each. That’s roughly 60% of the entire US population sitting in a database that almost anyone could buy.
The rest of this episode is really two stories that are more connected than you realize once you start looking deeper. The data breach itself is only half of the story. The other half is understanding the vendor working behind the scenes of a huge number of household-name businesses, handling their identity verification. That’s what makes this breach so much bigger than it looks on the surface. Then we shift to the scam that has been on my mind since Frank first flagged it last year. Digital arrest is a form of psychological captivity scam that’s now officially made the leap from India to the United States, with real victims and real seven-figure losses to prove it.
Buckle up, because the way to start fighting this is to know what we are up against.
What you’ll hear in this episode:Welcome back to Fraudology.
It’s just me for this episode, but I’ve got two stories to dig into. They are genuinely important for anyone dealing with chargeback disputes. Whether you’re on the merchant side or the banking side.
The first is Uber and the nearly billion dollars in fines for automated account deactivation. The second story is the story that I really want to unpack. Hims and Hers blowing past their chargeback threshold on their weight loss subscription business.
It’s rare that this stuff becomes public, and I think there’s a lot merchants can learn from it. I know a lot of companies leaning on AI right now to cancel buyer or seller accounts. We will walk through the math on chargeback fee per dispute, what’s actually driving these disputes, and what I’d tell these businesses if they were my client.
What you’ll hear:Welcome back to Fraudology.
Since I’ve been back from SardineCon, I’ve thought about how much faster and cheaper AI is making fraud. That thread runs through basically everything I’m covering today. I’m digging into a new report from Inscribe showing a 4X increase in AI generated documents. I’ll walk through the difference between a document that’s built entirely by AI and one that’s a real document with AI alterations. Because they are not the same problem.
Then we will go deep on a digital arrest scam, and this is the one I really want you to sit with. Frank McKenna has been predicting digital arrests would hit the US for almost a year. I found a first person account from a woman who got a call claiming to be from her local sheriff’s department. What happened to her over the next several hours is genuinely hard to listen to. I think this is one every fraud fighter needs to be able to explain to the people in their own life who aren’t in this industry.
Along the way, I’m covering a case out of Spain where a man was arrested for using deepfakes to get past identify verification checks, a new report on Grok deepfakes, and a study out of UMass on zombie credit cards. Which is a real NFC fraud loophole. It’s a lot but stick with me.
What you’ll hear:Welcome back to Fraudology.
I have to tell you I’m genuinely excited about this one. Today’s guest was highly recommended by Matt Vega, someone whose opinion I trust completely in this industry. By the time we finally hit record, we’d already been talking for 45 minutes off air. That’s a pretty good sign this episode is going to deliver.
Cy Khormaee spent years at Google, building out what eventually became the company’s user protection platform and the technology that now runs quietly in the background protecting billions of devices worldwide from phishing and malware. He took that experience and eventually founded Aegis.AI, and he just got back from Black Hat, which means he is walking into this conversation with a front-row view of exactly where adversarial AI is heading next.
What I wasn’t fully prepared for was how far he was willing to take the demonstration. Cy didn’t just tell me adversarial AI is a growing thread, he showed me, live. Using nothing more than ChatGPT and information freely available online. It’s the kind of moment that changes how you think about a threat you thought you already understood.
We cover a lot of ground in this one. And if you work in fraud, trust and safety, or security in any capacity, this is one you’ll want to sit with.
What you’ll hear in this episode:Welcome back to Fraudology.
Today's a solo episode built around a study that puts a real number on something fraud leaders have been debating for years: does organizational convergence for fraud actually move the needle on performance, or is it just an org chart trend?
For years, we've all benchmarked ourselves the same way. Approval rate here, chargeback rate there, maybe a manual review rate if we're being thorough. But the problem I've seen play out in company after company is this: optimize your approval rate, and your chargeback rate quietly creeps up. Optimize your chargeback rate by blocking more, and your approval rate takes the hit. You're never seeing the whole picture, just one lever moving at the expense of the other.
The Precise Yes metric is the headline finding from a new Liminal and Accertify study, but the study itself is much bigger than one metric. It surveyed 250 senior fraud, security, and risk leaders across five industry verticals specifically to test the thesis of organizational convergence for fraud and cybersecurity. I walk through what the data says, what forms of convergence actually improve fraud performance, and which ones don't move the needle at all.
This is a data-heavy episode, and I mean that as a compliment to the study. If you've ever needed a fraud KPI for CFO reporting that actually captures the full tradeoff between approvals and fraud loss, this is the one to bring back to your team.
What you'll hear in this episode:Welcome back to Fraudology.
This week I’m joined by Dave G., who spent years investigating money laundering, wire fraud, and scams before moving into e-commerce and, eventually, directly into crypto. Dave was on the ground floor of Bitcoin back when the white paper first came out, and he brings a rare vantage point on stablecoin fraud risk as someone who has watched a payment technology evolve from a niche curiosity into the backbone of a real conversation about agentic commerce.
We start with a story that sets the tone for the whole conversation. It demonstrates how unpredictable this space has always been, and how easily it is to miss where the real value and the real risk end up landing. From there, we get into the heart of what a stablecoin actually is, and why stablecoin unit economics change the payment fraud conversation entirely. They function less like a new currency and more like an infrastructure upgrade.
That capability sounds abstract until you follow it to its logical endpoint; agentic e-commerce. Everyone wants to talk about AI agents buying jackets, concert tickets, or collectibles, the high-consideration, emotionally driven purchases people actually enjoy shopping for. But Dave argues the real volume, and the real fraud exposure, is going to show up in the boring stuff. Bread, milk, and eggs. The things nobody wants to spend time discovering, just delivered. And when those transactions are worth pennies instead of dollars, low-dollar transaction fraud stops looking like a nuisance and starts looking like a scalable business model for criminals willing to take a cent at a time instead of hundreds of dollars at once.
That shift exposes a chargeback liability gap that already has real victims. A reminder that new payment technology fraud adoption always follows the same pattern: whatever gets built, someone tries to exploit before the guardrails exist.
What you'll hear in this episode:In this episode, I'm sitting down with Tal Yeshanov. Someone I've known for a very long time in this industry, and one of the sharpest risk leaders I know. Tal's path into fraud started almost by accident at Google and YouTube. Then took her through building fraud programs at Eventbrite, before its IPO, and Uber during its earliest hockey-stick growth years. Tal has spent her career building holistic fraud detection systems from scratch, in industries where there was no playbook to follow.
For years, fraud teams operated off a snapshot. Device at checkout. IP at checkout. Did the payment information match? Tal walks through why that single-moment view is no longer enough. And why the shift toward an orchestration platform, one that pulls in customer journey risk signals from the moment a user lands on your site rather than just the moment they transact, is where modern fraud programs are actually headed.
The deeper theme of this episode is what happens when you stop treating fraud detection as a scoring exercise, and start treating it as a full picture. Tal shares a personal story about a rule she built early in her career that was, on paper, flawless. It caught the exact triangulation fraud pattern it was designed for. It also caught a company executive, because his girlfriend used his credit card in a different city. That's false positive reduction in fraud detection in its most human form, and it's a direct argument for upstream fraud prevention data collection: pulling in more signals earlier in the journey instead of adding more rules at the transaction point.
What you'll hear in this episode:From the publisher's feed

38,717 Listeners

1,963 Listeners

2,180 Listeners

9,616 Listeners

1,639 Listeners

1,028 Listeners

1,260 Listeners

56,447 Listeners

3,979 Listeners

1,092 Listeners

314 Listeners

27,762 Listeners

933 Listeners

6,068 Listeners

5,391 Listeners

14 Listeners

25 Listeners

3 Listeners

6 Listeners

9 Listeners

22 Listeners

4 Listeners