SOLUTION 05 · For fraud teams in banking, fintech and e-commerce

The chargeback is the symptom. Where did the data come from?

Consumer fraud is a manufacturing process with a supply chain: material is stolen, refined into kits, tested by checkers, and cashed out through recruited mules. Every stage of it advertises. Your fraud team sees the last one.

01Why it keeps happening

The four places the current answer runs out

You measure the loss, not the cause

Chargeback rates and fraud losses are lagging indicators of a leak that happened weeks earlier, in a place your fraud stack has no visibility into. You are tuning thresholds against a symptom.

Credential stuffing looks like traffic

A checker run from a distributed proxy pool is a slow rise in failed logins. Distinguishing it from a bad release requires knowing that credentials for your domain are circulating, which is knowable, though not from your logs.

The mule is recruited in public

Drop recruitment for your country's banks runs openly in Telegram channels, weeks before the cashout it enables. Nobody on your team reads them, and the ones that matter are not in English.

Fraud and security do not share a source

The same stealer log that compromises an employee compromises ten thousand customers. It lands in one team's tooling and never reaches the other's, because the two bought different products.

02How it got here

How fraud industrialized

The customer-facing symptom moved from the card to the account to the session. The controls at each layer were designed against the previous one.

THREAT EVOLUTION

EACH ERA STACKED ON THE LAST

  1. 2012-2017

    The card dump

    Stolen card numbers, sold in bulk, burned quickly. The bank's answer was velocity rules and reissuance, and on the whole it worked.

  2. 2018-2023

    Identity as inventory

    Fullz, meaning the whole person rather than the card, enable application fraud and account recovery. Drop networks recruit mules openly, in "work" channels, at national scale.

  3. YOU ARE HERE

    2024-2026

    The account is the product

    Checkers validate stolen credentials against your login in bulk; OTP bots talk the code out of the customer; the session is resold intact. The fraudster no longer needs the card, because they have the customer.

  4. Next

    Synthetic customers at scale

    Assembled identities with real documents, real histories and no real person behind them, onboarded patiently and cashed out later. The fraud is not a transaction any more; it is an account you approved.

03What we do about it

Six plays, and the window each one runs in

Every play names the module that does the work. Nothing here is a capability we describe without shipping.

Customer credentials, from the primary source

The same pipeline that surfaces employee exposure surfaces customer exposure: primary stealer records with victim-machine context, not a recycled combolist that inflates the number and moves nothing.

SHERLOG

See the checker run being planned

Chatter about your login endpoint, your OTP flow or your app's API is a leading indicator of a stuffing campaign. It is discussed before it is executed, and when it names you, the post is in the corpus and your name is what finds it.

DRAGNET

Follow the money, not the advert

Bulk sales of accounts, fullz and access to your platform are negotiated over Jabber, and those rooms are indexed full-text. Nothing flags a thread as escrowed for you; reading one that is tells you the transaction is real, which is the difference between chatter and a scheduled attack.

JABBERNAUT

Volume goods moved to Telegram

Combolists, log drops and checked-account batches push to subscriber lists on Telegram rather than sitting in a forum thread. That corpus is indexed full-text as its own body, so where the advertisement ran and where the goods actually shipped are both searchable. They are separate corpora and separate queries; the point is that neither half is invisible.

TELEPATHY

Watch drop recruitment for your market

Drop and mule recruitment runs in the same channel corpus, weeks before the cashout it enables, and it names the banks and the countries the pressure is aimed at. That signal belongs to your fraud team as much as to your SOC.

TELEPATHY

The crew coordinates where the forum can't see

The checker run, the mule split, the drop schedule: that planning happens in invite-only Discord servers a researcher cannot casually read. Indexed alongside the rest of the corpus, so the coordination is readable at all. Reconciling it with the advertisement is still your analyst's job; the alternative is not having the coordination.

GUILDWIRE
04In practice

Two weeks before the fraud spike

Day 0

A cloud-of-logs channel ships its daily batch. Four thousand of the records carry credentials for your consumer platform: customers, not staff.

Day 1

Your fraud team's standing query returns them, with combolist records excluded by the filter, so the number is the one worth acting on: four thousand primary records, not a recycled million.

Day 4

A forum thread offers "checked" accounts on your platform. The seller's sample matches your record set, which tells you the checker run already happened and against which cohort.

Day 6

You force a reset on the exposed cohort and step up authentication for it alone. The buyer receives a list of dead accounts and posts a complaint, which is the closest thing to a thank-you note this market produces.

05What changes

The move, stated plainly

No customer logos and no invented percentages: we have not deployed long enough to have honest ones. What we can state is what the workflow becomes.

Fraud is measured after the loss

The exposed cohort is known before it is monetized, and can be stepped up on its own

Every customer gets a blanket password reset

The four thousand who actually leaked get one, and nobody else is annoyed

Fraud and security buy separate feeds

One pipeline, one API, two teams reading the record that concerns them

Questions

Fraud & abuse, honestly answered

Your competitors will learn about the leak from the invoice.

Learn about it from the log batch.

NDA-friendly briefings · global coverage · no slideware