The chargeback is the symptom. Where did the data come from?
Consumer fraud is a manufacturing process with a supply chain: material is stolen, refined into kits, tested by checkers, and cashed out through recruited mules. Every stage of it advertises. Your fraud team sees the last one.
The four places the current answer runs out
You measure the loss, not the cause
Chargeback rates and fraud losses are lagging indicators of a leak that happened weeks earlier, in a place your fraud stack has no visibility into. You are tuning thresholds against a symptom.
Credential stuffing looks like traffic
A checker run from a distributed proxy pool is a slow rise in failed logins. Distinguishing it from a bad release requires knowing that credentials for your domain are circulating, which is knowable, though not from your logs.
The mule is recruited in public
Drop recruitment for your country's banks runs openly in Telegram channels, weeks before the cashout it enables. Nobody on your team reads them, and the ones that matter are not in English.
Fraud and security do not share a source
The same stealer log that compromises an employee compromises ten thousand customers. It lands in one team's tooling and never reaches the other's, because the two bought different products.
How fraud industrialized
The customer-facing symptom moved from the card to the account to the session. The controls at each layer were designed against the previous one.
THREAT EVOLUTION
EACH ERA STACKED ON THE LAST
2012-2017
The card dump
Stolen card numbers, sold in bulk, burned quickly. The bank's answer was velocity rules and reissuance, and on the whole it worked.
2018-2023
Identity as inventory
Fullz, meaning the whole person rather than the card, enable application fraud and account recovery. Drop networks recruit mules openly, in "work" channels, at national scale.
YOU ARE HERE
2024-2026
The account is the product
Checkers validate stolen credentials against your login in bulk; OTP bots talk the code out of the customer; the session is resold intact. The fraudster no longer needs the card, because they have the customer.
Next
Synthetic customers at scale
Assembled identities with real documents, real histories and no real person behind them, onboarded patiently and cashed out later. The fraud is not a transaction any more; it is an account you approved.
Six plays, and the window each one runs in
Every play names the module that does the work. Nothing here is a capability we describe without shipping.
Customer credentials, from the primary source
The same pipeline that surfaces employee exposure surfaces customer exposure: primary stealer records with victim-machine context, not a recycled combolist that inflates the number and moves nothing.
SHERLOGSee the checker run being planned
Chatter about your login endpoint, your OTP flow or your app's API is a leading indicator of a stuffing campaign. It is discussed before it is executed, and when it names you, the post is in the corpus and your name is what finds it.
DRAGNETFollow the money, not the advert
Bulk sales of accounts, fullz and access to your platform are negotiated over Jabber, and those rooms are indexed full-text. Nothing flags a thread as escrowed for you; reading one that is tells you the transaction is real, which is the difference between chatter and a scheduled attack.
JABBERNAUTVolume goods moved to Telegram
Combolists, log drops and checked-account batches push to subscriber lists on Telegram rather than sitting in a forum thread. That corpus is indexed full-text as its own body, so where the advertisement ran and where the goods actually shipped are both searchable. They are separate corpora and separate queries; the point is that neither half is invisible.
TELEPATHYWatch drop recruitment for your market
Drop and mule recruitment runs in the same channel corpus, weeks before the cashout it enables, and it names the banks and the countries the pressure is aimed at. That signal belongs to your fraud team as much as to your SOC.
TELEPATHYThe crew coordinates where the forum can't see
The checker run, the mule split, the drop schedule: that planning happens in invite-only Discord servers a researcher cannot casually read. Indexed alongside the rest of the corpus, so the coordination is readable at all. Reconciling it with the advertisement is still your analyst's job; the alternative is not having the coordination.
GUILDWIRETwo weeks before the fraud spike
A cloud-of-logs channel ships its daily batch. Four thousand of the records carry credentials for your consumer platform: customers, not staff.
Your fraud team's standing query returns them, with combolist records excluded by the filter, so the number is the one worth acting on: four thousand primary records, not a recycled million.
A forum thread offers "checked" accounts on your platform. The seller's sample matches your record set, which tells you the checker run already happened and against which cohort.
You force a reset on the exposed cohort and step up authentication for it alone. The buyer receives a list of dead accounts and posts a complaint, which is the closest thing to a thank-you note this market produces.
The move, stated plainly
No customer logos and no invented percentages: we have not deployed long enough to have honest ones. What we can state is what the workflow becomes.
Fraud is measured after the loss
The exposed cohort is known before it is monetized, and can be stepped up on its own
Every customer gets a blanket password reset
The four thousand who actually leaked get one, and nobody else is annoyed
Fraud and security buy separate feeds
One pipeline, one API, two teams reading the record that concerns them
Fraud & abuse, honestly answered
The other four
Credential exposure
We do not stop the login. We hold the record that would have made it work, and you can search it today.
Ransomware early warning
The ransom note is the last message in the thread. We read the earlier ones.
Vulnerability triage
Your backlog is sorted by severity. The attacker's is sorted by price.
Brand & executive exposure
Your executives are discussed in channels they cannot open, in languages your feed does not read.
Your competitors will learn about the leak from the invoice.
Learn about it from the log batch.
NDA-friendly briefings · global coverage · no slideware