Lessons from a fraudster

Lessons from a fraudster

I don’t admire fraudsters.?

But I do respect their persistence.?

You have to give credit where it’s due.?

Fraudsters are a creative bunch.?

They’re adaptive.?

They’re clever.?

And they’re willing to put up with high levels of tedium and repetition if they know they’ll get a profit out of it.?

So, what can we learn from the average fraudster’s attitude toward their craft??

It’s important for us not to underestimate our opponents.?


We have to acknowledge that fraudsters, as a group, have serious skills.?

Some might dismiss fraudsters as lowlifes or common criminals.?

But if they were really just unskilled nobodies, the issue of fraud would’ve been solved ages ago.?

The simple truth is that fraudsters are talented.?

They’re good at what they do, and they’re only getting better.?

When we find one way to stop them, they find ways to get back in.?


Fraudsters are also not as lazy as you might think.?

Even with some automation in place, it takes a lot of patience to:

  • Create hundreds of accounts on a single platform.
  • Run dozens of instances of one app using an app cloner, and send phishing messages on all of them.?
  • Configure an emulator and run dozens of app instances on dozens of emulated phones, carrying out multiple fraud schemes at once.?

Tedium isn’t an obstacle for fraudsters if there’s money to be made.

They’ll automate what they can and grind through what they can’t.?


Lastly, fraudsters are persistent.?

When they find out one vulnerability has been patched, they go looking for others.?

They test what they find. They think about the problem. They research.

And then they get to work stealing money from platforms and their users.?

Whenever fraud prevention technology catches up with them, they just find new workarounds.

So let’s recap what we’ve learned.

Fraudsters are:

  • Skilled at committing fraud
  • Willing to invest lots of time and effort
  • Ready to adapt and persist when fraud prevention catches up?

What can we learn from this as fraud fighters??

Fraudsters have some pretty impressive traits. But so do fraud fighters.?

They’re skilled at committing fraud? We’re skilled at stopping it.?

They’re willing to invest time and effort into fraud schemes? We invest time and effort, on an industry-wide scale, into fighting them.?

They adapt quickly when fraud prevention advances? We’re developing innovative solutions that cut them off at the root and stop the Whac-a-Mole antics for good.?

It’s important not to underestimate our opponent.?

But we shouldn’t underestimate ourselves, either.?

We’ve got all the skills of the average fraudster and more—it’s just a matter of putting them to use.?

Renan N.

Security Operations Center | Cyber Threat Intelligence | Manager

8 个月

Excellent, totally agree ????

要查看或添加评论,请登录

André F.的更多文章

  • Introducing the Incognia Frontline Report: Gig Economy Edition

    Introducing the Incognia Frontline Report: Gig Economy Edition

    It’s a wild time in the gig economy fraud space. Fraud is draining millions from gig economy platforms.

    1 条评论
  • ELF: The Persistent Signal Fraudsters Can’t Erase

    ELF: The Persistent Signal Fraudsters Can’t Erase

    Let’s acknowledge the obvious: Fraudsters don’t typically stop after a single infraction. They often commit as many…

    1 条评论
  • Continuous verification should actually be continuous

    Continuous verification should actually be continuous

    Continuous verification should actually be continuous. It sounds pretty straightforward, but many companies don’t treat…

  • Fraud prevention needs a collaboration power-up

    Fraud prevention needs a collaboration power-up

    Many platforms deal with their fraud problems in isolation. They’re not collaborating with other platforms to better…

    2 条评论
  • Don't fight fraud with your offline brain

    Don't fight fraud with your offline brain

    Why do many companies default to selfies for user verification?” When I got this question recently, it helped me…

    5 条评论
  • Just let them commit fraud

    Just let them commit fraud

    Predicting whether a user will commit fraud can be really tough. You may be better off just letting them do it.

    1 条评论
  • Fraudster Intel: How they find vulnerabilities to exploit

    Fraudster Intel: How they find vulnerabilities to exploit

    How do fraudsters find their exploit points? Looking to forums and chat groups tells us—they test. To help you picture…

    4 条评论
  • More data isn’t always better

    More data isn’t always better

    In fraud prevention, the problem is usually not a lack of data. We have so many signals available to us, they’re coming…

    1 条评论
  • Closing the fraud prevention time gap

    Closing the fraud prevention time gap

    What’s the “time gap” in the world of fraud prevention? It’s the time between the emergence of a new threat and the…

    7 条评论
  • 3 strategies for elevating fraud prevention internally

    3 strategies for elevating fraud prevention internally

    You understand the value of your fraud prevention team’s work. But how do you get others in your company to recognize…

社区洞察

其他会员也浏览了