Episodios

  • AI at Scale: The New Frontier of Identity Theft and Biometric Fraud
    Apr 14 2026

    In this episode of Fraudology, Karisse Hendrick welcomes back Ron Zayas, CEO of Ironwall, to discuss the terrifying ways Artificial Intelligence is industrializing fraud. While we often think of AI as a tool for automation, Zayas explains that its true danger lies in its ability to apply human-like logic to stolen data at an unprecedented scale.

    The conversation dives deep into the mechanics of modern account takeovers, explaining how AI can "guess" password variations by identifying personal patterns across multiple data breaches. We also explore the hidden risks of biometric security, from the vulnerabilities of centralized facial recognition databases to the high error rates of AI models when identifying people of color.

    Key topics covered in this episode include:

    • Fraud at Scale: How AI moves beyond simple automation to recognize patterns in your passwords and digital behavior to breach accounts across the web.
    • The Biometric Trap: Why storing your facial recognition or fingerprint data with a bank or organization is a permanent risk, and why local storage on your device is the only safe alternative.
    • Biometric Bias and Mistakes: The reality of high error rates in facial recognition for people of color and the harrowing story of a woman arrested for a crime in a state she had never visited due to an AI mismatch.
    • Breaking the Connection: Practical steps to remove your personal information from data brokers and why you should treat your mobile number with the same secrecy as your Social Security number.
    • The Metadata Threat: How a simple photo of your house or the Grand Canyon can leak your exact IP address and physical location to bad actors through hidden metadata.

    Más Menos
    37 m
  • Inside the Scam Compounds: Erin West’s Cambodian Debrief & the Fight for Accountability
    Apr 7 2026

    In this episode of Fraudology, Karisse Hendrick welcomes back Erin West, prosecutor and founder of Operation Shamrock, for an urgent update on the global "scamdemic" of pig butchering. Erin shares firsthand accounts from her recent investigative trip to Cambodia, providing a chilling look at the industrialized nature of transnational organized crime and the massive scale of the scam compounds operating in the region.

    The conversation explores the recent waves of accountability, including the historic U.S. indictment of Cambodian/Chinese kingpin Chen Ji and the subsequent $15 billion forfeiture—a move that has sent ripples of fear through the industry. Erin details the "Super Bowl effect" she witnessed in Sihanoukville, where compounds appeared shuttered for show while operations continued behind locked metal doors and shuttered windows.

    We also explore the "hot topics" dominating the fraud landscape today:

    • The GDP of Fraud: How the scam industry now accounts for an estimated 40% to 60% of Cambodia’s GDP, making total eradication a complex economic and humanitarian challenge.
    • Industrialized Deception: Why these compounds resemble corporate training rooms—complete with cubbies for personal phones and strict "fine" schedules for victims—proving this is a highly systemized global industry.
    • The Liability Lever: A look at how platforms like Meta successfully block scam ads in Australia where they face financial liability, while failing to do so in regions where "teeth" in the law are missing.
    • Building the Coalition: How Erin’s crypto-coalition has grown to 2,400 members, bridging the gap between local law enforcement and federal agencies to ensure victims are no longer turned away.

    Additionally, Erin dives into the heartbreaking reality of the "generation's worth of wealth" being stolen from Western countries to fund "mint-colored Rolls Royces" and garish displays of luxury in Phnom Penh. We conclude with a call to action for fraud professionals to "Train the Trainer," using Operation Shamrock’s resources to educate their own communities and break the echo chamber.

    Más Menos
    48 m
  • The 430% Surge: FTC Statistics & Meta’s Historic Fraud Liability
    Mar 31 2026

    In this episode of Fraudology, Karisse Hendrick provides a comprehensive debrief following the Merchant Risk Council (MRC) Vegas conference. Karisse shares her highlights and lowlights from one of the industry's biggest events, cutting through the conference hype to provide practical insights for fraud and payments professionals.

    The conversation explores the evolving mechanics of Agentic AI in commerce, detailing how tools like Sardine are now identifying AI agents by monitoring "invisible" behaviors, such as fields being filled without mouse movement. Karisse provides an inside look at why OpenAI recently shelved its "instant checkout" feature, moving away from being a merchant of record to avoid the liability of chargebacks and complex transaction enablement.

    We also explore the "hot topics" dominating the fraud landscape today:

    • The VAMP Threshold "Cliff": How Visa is drastically reducing high-risk merchant ratios from 220 basis points to 150 basis points this April, potentially catching many enterprise merchants off guard.
    • The Complexity of Agentic Chargebacks: Real-world examples of "authorized" AI purchases where merchants are losing disputes because card brands like Visa do not yet have established "compelling evidence" protocols for AI agents.
    • The Human Element vs. AI: Why senior fraud leadership cannot be replaced by LLMs, as the critical "domain expertise" required to manage sophisticated fraud is not found in open-source data.

    Additionally, Karisse dives into the latest FTC fraud statistics, revealing a staggering 430% increase in fraud since 2020. We break down the $375 million jury verdict against Meta in New Mexico, a historic win for child safety that challenges the long-standing "Section 230" liability shield. Finally, we examine a Reuters study uncovering how Meta's ability to block scam ads depends almost entirely on the financial liability they face in specific countries.

    Más Menos
    37 m
  • Beyond the Hype: Agentic AI, VAMP Ratios, and Post-MRC Realities
    Mar 24 2026

    In this episode of Fraudology, host Karisse Hendrick provides a comprehensive debrief following the Merchant Risk Council (MRC) Vegas conference. Karisse shares her highlights and lowlights from one of the industry's biggest events, cutting through the conference hype to provide practical insights for fraud and payments professionals.

    The conversation explores the evolving mechanics of Agentic AI in commerce, detailing how tools like Sardine are now identifying AI agents by monitoring "invisible" behaviors, such as fields being filled without mouse movement. Karisse provides an inside look at why OpenAI recently shelved its "instant checkout" feature, moving away from being a merchant of record to avoid the liability of chargebacks and complex transaction enablement.

    We also explore the "hot topics" dominating the fraud landscape today:

    1. The VAMP Threshold "Cliff": How Visa is drastically reducing high-risk merchant ratios from 220 basis points to 150 basis points this April, potentially catching many enterprise merchants off guard.
    2. The Complexity of Agentic Chargebacks: Real-world examples of "authorized" AI purchases where merchants are losing disputes because card brands like Visa do not yet have established "compelling evidence" protocols for AI agents.
    3. The Human Element vs. AI: Why senior fraud leadership cannot be replaced by LLMs, as the critical "domain expertise" required to manage sophisticated fraud is not found in open-source data.

    Más Menos
    51 m
  • Navigating the Rise of Starkiller and the Future of Session Hijacking with Frank McKenna
    Mar 17 2026

    In this episode of Fraudology, host Karisse Hendrick is joined by Frank McKenna, Chief Fraud Strategist at PointPredictive and the mind behind Frank on Fraud. Frank shares his latest deep dive into Starkiller, a sophisticated new phishing-as-a-service (PaaS) platform that emerged following the takedown of Tycoon 2FA.

    The conversation explores the terrifying mechanics of Attacker-in-the-Middle (AITM) attacks, where fraudsters use "headless browsers" to mirror legitimate login sessions in real-time. Frank provides an inside look at how this tool allows criminals to capture not just credentials, but also two-factor authentication (2FA) codes and session cookies, enabling them to maintain access even after a user logs out.

    We also explore the "hot topics" dominating the fraud landscape today:

    1. ATO Without a Login Event: How marketplaces are seeing "good" users perform legitimate actions, only to have their payout information changed moments later within the same session.
    2. The Democratization of Fraud: The professionalization of phishing kits on Telegram, which offer Netflix-style subscriptions and user-friendly dashboards for as little as $300 to $500 a month.
    3. Detection Challenges: Why traditional device intelligence and cybersecurity tools struggle to flag these attacks because the victim is interacting with the real merchant website, not a clone.

    Más Menos
    34 m
  • Navigating Global Advocacy and the Future of Fraud Education with Keith Briscoe
    Mar 10 2026

    In this episode of Fraudology, Karisse Hendrick is joined by Keith Briscoe, VP of Education and Advocacy at the Merchant Risk Council (MRC). Keith shares his journey from marketing commodity transaction software in the late '90s to falling in love with the high-value world of fraud intelligence at Ethoca.

    The conversation dives deep into the MRC's critical role in global advocacy, highlighting how they foster balanced dialogues between merchants, issuers, and card networks to create sustainable change. Keith provides an inside look at the recent evolution of Visa’s Acquirer Monitoring Program (VAMP) and the collaborative effort to make its thresholds and calculations more equitable for merchants.

    We also explore the "hot topics" dominating the industry today:

    1. Agentic Commerce: How AI-driven shopping agents are redefining liability and the "intention" behind a purchase.
    2. Professional Certification: The growth of the CPFPP (Certified Payments and Fraud Prevention Professional) program and its role in standardizing expertise for the next generation of fraud fighters.
    3. Event Innovation: A preview of the MRC’s new "Lightning Talks" in Las Vegas—bite-sized, high-impact sessions designed for a new generation of learners.

    Más Menos
    49 m
  • 5-Minute Phishing: How AI is Revolutionizing Scams and Morphing Attacks
    Mar 3 2026

    In this episode of the Fraudology podcast, Karisse Hendrick is joined by Matt Vega, Chief Fraud Strategist at Sardine, to explore how artificial intelligence has fundamentally altered the threat landscape for financial institutions and online retailers.

    First, Matt reveals the alarming ease with which AI can now be used to orchestrate phishing campaigns. Using advanced tools like Vercel’s v0, Matt demonstrates how he can clone a legitimate website—complete with branding, functional images, and login flows—in less than five minutes. He explains how attackers use these replicas to execute sophisticated "man-in-the-middle" attacks, tricking victims into handing over two-factor authentication (2FA) codes to gain fully authenticated access to accounts.

    Later in the episode, Matt and Karisse dive into the rise of "polymorphic" AI attacks. These autonomous agents are capable of adapting their behavior in real-time to bypass bot detection and security thresholds as soon as they are implemented. Matt also discusses "dust trailing," a tactic where fraudsters spread large volumes of small transactions across hundreds of platforms to make traditional human investigation cost-prohibitive.

    In this episode, we discuss:

    1. The 5-Minute Phish: How AI models use simple screenshots and prompts to create pixel-perfect clones of banks and government agencies.
    2. Polymorphic Attacks: The emergence of autonomous AI agents that instantly adapt to security controls, making traditional bot mitigation obsolete.
    3. The Power of Basics: Why "low-tech" solutions like card-to-name matching and behavioral biometrics remain the most effective tools against high-tech fraud.
    4. Threat Intelligence: Best practices for proactive defense, including beacon technology, "hidden watermarks," and strategic domain acquisition.
    5. Upcoming Events: Details on meeting Matt and the Sardine team at the upcoming MRC conference in Las Vegas.

    Más Menos
    39 m
  • Two Victims, One Session: Unmasking the New Age of Account Takeovers & Agentic AI
    Feb 24 2026

    Fraudology is presented by Sardine. Request a 1:1 product demo at sardine.ai

    In this solo episode, Karisse Hendrick checks in from a hotel room in San Diego at the Merchant Advisory Group (MAG) conference to share urgent intelligence from the front lines of e-commerce fraud before the full chaos of conference season begins.

    First, Karisse explores two sophisticated new fraud trends that are leaving even seasoned investigators scratching their heads. She breaks down the rise of the "Two-Victim ATO," a unique spin on account takeover where fraudsters leverage the "legacy" and trust of an active account to bypass security, only to hit it with a completely different person's stolen credit card. Then, she dives into a high-tech trend hitting digital gift card retailers: Malware-driven session hijacking. Karisse discusses how fraudsters "piggyback" on a legitimate customer's active session and device to commit a second, high-value theft—making it nearly impossible for traditional fraud systems to flag as a separate entity.


    Later in the episode, Karisse discusses the "scary" new frontier of Agentic AI. She shares insights from recent tests by major retailers showing that autonomous shopping bots are beginning to make purchases that are currently indistinguishable from human behavior, creating a massive "Know Your Agent" (KYA) challenge for the industry.


    In this episode, we discuss:

    1. The Two-Victim ATO: Why fraudsters are adding new payment methods to active, high-history accounts instead of just using cards on file.
    2. Session Hijacking & Malware: How bad actors are using VPNs and malware to "replay" or continue a legitimate customer's session to buy high-value gift cards.
    3. Agentic AI & KYA: The difficulty in identifying AI-initiated transactions and why current device ID technology can't tell the difference between a human and a bot.
    4. Upcoming Events: Details on the Merchant Advisory Group, and the first annual Merchant Fraud Alliance Conference in Chicago this October.


    Fraudology is hosted by Karisse Hendrick, a fraud fighter with decades of experience advising hundreds of the biggest ecommerce companies in the world on fraud, chargebacks, and other forms of abuse impacting a company's bottom line.

    Connect with her on LinkedIn

    She brings her experience, expertise, and extensive network of experts to this podcast weekly, on Tuesdays.

    Más Menos
    18 m