414 episodes
- Welcome back to Fraudology.
Since I’ve been back from SardineCon, I’ve thought about how much faster and cheaper AI is making fraud. That thread runs through basically everything I’m covering today. I’m digging into a new report from Inscribe showing a 4X increase in AI generated documents. I’ll walk through the difference between a document that’s built entirely by AI and one that’s a real document with AI alterations. Because they are not the same problem.
Then we will go deep on a digital arrest scam, and this is the one I really want you to sit with. Frank McKenna has been predicting digital arrests would hit the US for almost a year. I found a first person account from a woman who got a call claiming to be from her local sheriff’s department. What happened to her over the next several hours is genuinely hard to listen to. I think this is one every fraud fighter needs to be able to explain to the people in their own life who aren’t in this industry.
Along the way, I’m covering a case out of Spain where a man was arrested for using deepfakes to get past identify verification checks, a new report on Grok deepfakes, and a study out of UMass on zombie credit cards. Which is a real NFC fraud loophole. It’s a lot but stick with me.
What you’ll hear:
A quick recap of SardineCon 2026 and why AI was the theme of nearly every conversation I had there
Inscribe's new fraud report showing a 4X increase in AI generated documents, and why bank statement fraud, fake invoices, and fake pay stubs make up more than half of what they're catching
The difference between AI generated documents and AI altered ones, and why the altered ones are actually harder to catch
How synthetic identity fraud and first party fraud both show up in lending fraud, even when the person applying is real
A case out of Spain where deepfakes almost got a man through identity verification, until a one second glitch gave him away
A new report on Grok deepfakes and what it means that one platform is tied to the majority of tracked incidents
A UMass study on zombie credit cards and the NFC fraud loophole that can bring expired cards back to life
The full, first person story of a digital arrest scam, including the jury duty scam call, someone impersonating law enforcement, a bond scam demand, and a PayPal fraud payment that couldn't be undone
You should listen to this episode if you:
Want to understand what a digital arrest scam actually sounds like from the inside
Are in lending, underwriting, or KYC and need to know how bank statement fraud and fake pay stubs are evolving
Want to know the real difference between synthetic identity fraud and first party fraud
Have family members who don’t work in fraud and need a real example to help them recognize a jury duty scam or someone impersonating law enforcement
Are tracking deepfakes and want to know where Grok deepfakes fit into the bigger picture
Process card not present or in person transactions and haven't heard about the zombie credit card loophole yet - Welcome back to Fraudology.
I have to tell you I’m genuinely excited about this one. Today’s guest was highly recommended by Matt Vega, someone whose opinion I trust completely in this industry. By the time we finally hit record, we’d already been talking for 45 minutes off air. That’s a pretty good sign this episode is going to deliver.
Cy Khormaee spent years at Google, building out what eventually became the company’s user protection platform and the technology that now runs quietly in the background protecting billions of devices worldwide from phishing and malware. He took that experience and eventually founded Aegis.AI, and he just got back from Black Hat, which means he is walking into this conversation with a front-row view of exactly where adversarial AI is heading next.
What I wasn’t fully prepared for was how far he was willing to take the demonstration. Cy didn’t just tell me adversarial AI is a growing thread, he showed me, live. Using nothing more than ChatGPT and information freely available online. It’s the kind of moment that changes how you think about a threat you thought you already understood.
We cover a lot of ground in this one. And if you work in fraud, trust and safety, or security in any capacity, this is one you’ll want to sit with.
What you’ll hear in this episode:
Cy's path from Google's user protection platform, home of reCAPTCHA and Safe Browsing, to founding Aegis.AI, and how credential stuffing defense evolved into a hundred-million-dollar business.
A live ChatGPT phishing demo where Cy used open source intelligence to research himself and generate a convincing, contextualized phishing email and matching fake conference website in minutes.
Why AI phishing attacks have moved from theoretical to fully operational, with real-world state actor phishing tactics now automatable at near-zero cost.
The staggering AI phishing email bypass rate statistics: over 50% of emails now slip past existing security email filter bypass controls.
Why AI red team fraud thinking, treating AI as a gardener to nurture rather than a carpenter to micromanage, changes how fraud and security teams should actually deploy these tools.
How the real Robinhood phishing attack shows why login fraud detection signals and upstream fraud detection AI matter more than ever.
Why fraud and cybersecurity convergence isn't optional anymore, and how fraud data sharing across teams closes gaps that adversaries are actively exploiting.
How automated sandboxing fraud detection can catch attacks before a user ever clicks, and why carding attack prevention and account takeover detection increasingly rely on the same signals as cybersecurity teams.
You should listen to this episode if you:
Work in fraud, trust and safety, or security and want to understand how adversarial AI is changing social engineering and phishing attacks.
Are responsible for account takeover detection, credential stuffing detection, or synthetic identity risk at a bank, fintech, or merchant.
Assumed business email compromise had been mostly solved and need a reality check.
Are evaluating AI fraud investigation automation tools and want a clearer sense of what can realistically be automated today.
Are trying to build the case internally for fraud and cybersecurity convergence and fraud data sharing across teams. - Welcome back to Fraudology.
Today's a solo episode built around a study that puts a real number on something fraud leaders have been debating for years: does organizational convergence for fraud actually move the needle on performance, or is it just an org chart trend?
For years, we've all benchmarked ourselves the same way. Approval rate here, chargeback rate there, maybe a manual review rate if we're being thorough. But the problem I've seen play out in company after company is this: optimize your approval rate, and your chargeback rate quietly creeps up. Optimize your chargeback rate by blocking more, and your approval rate takes the hit. You're never seeing the whole picture, just one lever moving at the expense of the other.
The Precise Yes metric is the headline finding from a new Liminal and Accertify study, but the study itself is much bigger than one metric. It surveyed 250 senior fraud, security, and risk leaders across five industry verticals specifically to test the thesis of organizational convergence for fraud and cybersecurity. I walk through what the data says, what forms of convergence actually improve fraud performance, and which ones don't move the needle at all.
This is a data-heavy episode, and I mean that as a compliment to the study. If you've ever needed a fraud KPI for CFO reporting that actually captures the full tradeoff between approvals and fraud loss, this is the one to bring back to your team.
What you'll hear in this episode:
How the Precise Yes metric is calculated, and why approval rate vs chargeback rate alone can hide the real story of your fraud program
Why organizational convergence for fraud and cybersecurity is being driven by operational necessity, not executive mandates, and what that means for how teams are actually changing
Why login has become the new fraud control point, with account takeover, credential stuffing, and bot attacks all converging at that stage
Why 63.6% of organizations still cannot distinguish a cyber attack from a fraud attack in real time, and what that costs them operationally
How CISO fraud ownership is showing up earlier in the vendor decision process, and why board level fraud reporting is becoming a real governance topic
Why partial integration is the highest-performing model for organizational convergence for fraud, and why pushing to full structural integration can actually erode the domain expertise that makes teams effective
Why sharing just two or more use cases between fraud and cyber teams is the real performance tipping point, delivering a 1.5x improvement in fraud performance scores
Why separate budgets between fraud and cyber teams actually outperform unified ones, contradicting one of the most common assumptions about convergence
How fraud metrics by industry vertical vary, including why ecommerce and retail lead the pack while marketplaces lag significantly behind
What the study found on agentic commerce fraud controls and synthetic identity fraud in ecommerce specifically
Who should listen:
Fraud leaders looking for a fraud KPI for CFO reporting that captures the real tradeoff between approvals and fraud loss.
Anyone building a business case for fraud and cybersecurity convergence and needing real data to support it.
CISOs and security leaders increasingly involved in fraud tool evaluation and vendor decisions.
Fraud teams trying to figure out where to start with shared fraud and cyber use cases without a full reorg.
Ecommerce and marketplace fraud professionals wanting an ecommerce fraud benchmarking study to compare their own performance against.
Anyone responsible for board level fraud reporting or making the case for fraud visibility at the executive level. Stablecoin fraud risk, agentic commerce, and the chargeback liability gap nobody has solved
06/08/2026 | 46 mins.Welcome back to Fraudology.
This week I’m joined by Dave G., who spent years investigating money laundering, wire fraud, and scams before moving into e-commerce and, eventually, directly into crypto. Dave was on the ground floor of Bitcoin back when the white paper first came out, and he brings a rare vantage point on stablecoin fraud risk as someone who has watched a payment technology evolve from a niche curiosity into the backbone of a real conversation about agentic commerce.
We start with a story that sets the tone for the whole conversation. It demonstrates how unpredictable this space has always been, and how easily it is to miss where the real value and the real risk end up landing. From there, we get into the heart of what a stablecoin actually is, and why stablecoin unit economics change the payment fraud conversation entirely. They function less like a new currency and more like an infrastructure upgrade.
That capability sounds abstract until you follow it to its logical endpoint; agentic e-commerce. Everyone wants to talk about AI agents buying jackets, concert tickets, or collectibles, the high-consideration, emotionally driven purchases people actually enjoy shopping for. But Dave argues the real volume, and the real fraud exposure, is going to show up in the boring stuff. Bread, milk, and eggs. The things nobody wants to spend time discovering, just delivered. And when those transactions are worth pennies instead of dollars, low-dollar transaction fraud stops looking like a nuisance and starts looking like a scalable business model for criminals willing to take a cent at a time instead of hundreds of dollars at once.
That shift exposes a chargeback liability gap that already has real victims. A reminder that new payment technology fraud adoption always follows the same pattern: whatever gets built, someone tries to exploit before the guardrails exist.
What you'll hear in this episode:
How Dave went from investigating money laundering and wire fraud to working directly in crypto, and the story of accidentally giving away roughly $1.5 million in Bitcoin at industry conferences.
Why stablecoin fraud risk needs to be understood separately from Bitcoin fraud history, and how stablecoins function more like an infrastructure upgrade than a new currency.
How stablecoin unit economics make micropayment fraud economics viable at a scale traditional card and ACH rails were never built to support.
Why the agentic e-commerce conversation has it backwards, focusing on high-consideration purchases like jackets and concert tickets instead of the low-dollar transaction fraud risk hiding in everyday purchases like bread, milk, and eggs.
A real chargeback liability example where a cardholder admitted an AI agent made the purchase, and the merchant still had no compelling evidence chargeback rules to fight it.
Why device-based identity verification is a weaker foundation than the industry treats it as, and an early look at an emerging protocol for verifying AI agent identities.
How consortium fraud data sharing can create real, sometimes irreversible fraud blacklist consortium risk when a label gets attached to the wrong entity.
A subscription chargebacks story involving an antivirus company that charged customers for software that did nothing at all.
Why every new payment technology, from ACH to stablecoins, follows the same pattern: fraud arrives before the guardrails do.
You should listen to this episode if you:
Work in payments, fraud risk, or chargeback management and want to understand where stablecoin fraud risk and agentic commerce actually intersect.
Are responsible for card network relationships or dispute strategy and want to understand the chargeback liability gap in agent-initiated purchases.
Are evaluating identity verification strategies and want a real critique of device-based identity as a long-term solution.
Participate in a fraud consortium and want to better understand the risk and responsibility that comes with labeling data.
Are trying to get ahead of new payment technology fraud adoption instead of reacting to it after losses show up.
Want a grounded, practitioner-level conversation about crypto fraud and payment fraud that goes beyond the hype cycle.From snapshot to journey: Holistic fraud detection in the age of AI, with Tal Yeshanov
30/07/2026 | 52 mins.In this episode, I'm sitting down with Tal Yeshanov. Someone I've known for a very long time in this industry, and one of the sharpest risk leaders I know. Tal's path into fraud started almost by accident at Google and YouTube. Then took her through building fraud programs at Eventbrite, before its IPO, and Uber during its earliest hockey-stick growth years. Tal has spent her career building holistic fraud detection systems from scratch, in industries where there was no playbook to follow.
For years, fraud teams operated off a snapshot. Device at checkout. IP at checkout. Did the payment information match? Tal walks through why that single-moment view is no longer enough. And why the shift toward an orchestration platform, one that pulls in customer journey risk signals from the moment a user lands on your site rather than just the moment they transact, is where modern fraud programs are actually headed.
The deeper theme of this episode is what happens when you stop treating fraud detection as a scoring exercise, and start treating it as a full picture. Tal shares a personal story about a rule she built early in her career that was, on paper, flawless. It caught the exact triangulation fraud pattern it was designed for. It also caught a company executive, because his girlfriend used his credit card in a different city. That's false positive reduction in fraud detection in its most human form, and it's a direct argument for upstream fraud prevention data collection: pulling in more signals earlier in the journey instead of adding more rules at the transaction point.
What you'll hear in this episode:
How Tal moved from Google and YouTube into building fraud programs at Eventbrite and Uber with no existing playbook to follow.
Why holistic fraud detection means tracking customer journey risk signals from first visit to transaction, not just a snapshot at checkout.
How an orchestration platform unifies device, IP, email, and behavioral data that used to live in separate point solutions.
A real story about false positive reduction in fraud detection, including a rule that was technically perfect and still failed a legitimate customer.
How the same holistic approach extends to account takeover detection, including typing cadence, autofill behavior, and device history.
Why domain expertise vs AI in fraud isn't a competition, and how agentic AI is being used right now to query databases, support customer service teams, and triage escalations.
A candid conversation about AI replacing fraud jobs, including a real example of a company that prematurely laid off its fraud leadership.
Why fraud team tribal knowledge doesn't transfer to an AI model, and what companies risk losing when it walks out the door.
Tal's fraud leadership philosophy, built on transparency and empathy, and why it creates teams that stay in touch for years.
The ongoing industry shift from risk team vs fraud team naming, and why more companies are choosing the broader term.
You should listen to this episode if you:
Work in fraud detection, risk operations, account security, or trust and safety.
Are evaluating an orchestration platform or trying to move your fraud program beyond point-in-time scoring.
Want a practical, non-hypothetical look at where agentic AI actually fits in fraud operations today.
Are a fraud leader worried about AI replacing fraud jobs on your team, or trying to make the case for why domain expertise still matters.
Care about fraud leadership philosophy and want to build a team that stays loyal and stays sharp.
More Business podcasts
Trending Business podcasts
About Fraudology Podcast with Karisse Hendrick
If you work in online fraud prevention, chances are you've caught the "bug". The bug that makes you passionate about identifying & preventing cybercriminals from getting away with stealing from your company, or your client's companies. Most people who have made cyber-fraud their career have the perfect balance of analytical and social skills, a strong sense of justice and the curiosity that will drive you to go down every path of information until you "crack the case".
Just like sociology is the study of social behavior, and psychology is the study of human behavior, Fraudology is the science and study of fraud.
On the Fraudology podcast, long-time online fraud expert, Karisse Hendrick will dive into all areas of Fraudology from the perspective of a fraud-fighter. With guests ranging from former cybercriminals to fraud-fighters at Fortune 500 companies to law enforcement and others, you will no doubt be entertained, while learning a lot about fraud & other forms of abuse prevention!
Subscribe to be alerted when a new episode is out and please rate & review where you can, to help others find this new & unique podcast!
Podcast websiteListen to Fraudology Podcast with Karisse Hendrick, The Other Hand and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Fraudology Podcast with Karisse Hendrick
Scan code,
download the app,
start listening.
download the app,
start listening.




























