#94 - How fraudsters (accidentally) find your gaps

"Fraud teams traditionally were in silos. I'm sure the finance team knew the chip and pin changes were coming in 2015. But nobody told the fraud team, because it was always the one left in a silo."

Dajana G., a veteran fraud leader of 25 years, dropped this nugget on the latest TSFS episode (out now!) and reminded me of how fraud usually succeeds.

Is the silo itself the problem? Not necessarily.

The problem is that successful attacks never target silos. They target the gaps between them.

Why? Because no one is watching.

And when you finally realize you’re under a fraud attack, there are too many stakeholders to manage.

No one owns it, so everyone owns it.

The Sedan principle

In May 1940, Germany didn't break France at its strongest point. It didn't break it at its weakest point either.

It broke through at Sedan - the seam between the Maginot Line and the neighboring sector, the Belgian border.

The French command assumed the Ardennes forest was impassable, so it seemed like the natural boundary between their armies. Three Panzer divisions came through anyway.

Why choose the most difficult terrain? Because no one owned it. 

Side note: if you want to read more “fun facts” about the parallels between military doctrine and fraud strategy, I got you covered.

You might think, “hold up, Chen! Fraudsters don’t run intelligence operations on your org chart!” And you’ll be right about it too.

Fraudsters don't know your identity team doesn't talk to your payments team, and they don't know your data science team ships a model nobody in FraudOps ends up using. 

They can't target your org seams on purpose, because they have no visibility into where your seams even are.

But here’s the thing - they don’t have to either.

Fraudsters just need to try repeatedly until something works. Then scale and exploit the gap they found.

And while that initial success might be “accidental”, odds are that it reflects a real gap in your system.

Does it change anything for you, the defender, whether the gap got found on purpose or by chance?

It doesn't.

An accidental discovery bleeds you exactly as fast as a deliberate one, and sophistication was never the variable here. Ownership was.

Hunting for system gaps

I've written about this exact problem more times than I originally thought - always as a one-off, never named as the same pattern. That’s why Dajana’s remark made something click.

Here are a couple of examples of where to look for system gaps:

Identity vs. payment teams:Your KYC team owns the signup, your payments team owns the transaction. Each one sees half the customer's journey, and each one assumes the other one caught it.

Fraud DS vs. Analytics vs. Ops: Similarly to the above, but cut across skillset and tasks rather than domain. Which of these teams owns the fraud rate? 

Side note: Here’s a good example - data science trains a model, Ops applies it in rules, and neither one is explicitly on the hook forwhether the model actually gets used.

Finance vs. Fraud: The fraud team optimizes fraud rate, finance is watching approval rate, and nobody agreed in advance on what "good" looks like. Misalignment then breeds indecision, slow reactions, and finger-pointing.

Vendor vs. in-house monitoring:Your vendor is absolutely watching their performance internally. Whether they expose that to you is a separate question, and your own team is usually watching whether the vendor is up, not whether it's right.

Every one of these gaps looks different on the surface. 

But all of them share the same pattern: two teams, two dashboards, and nobody whose job is to own the space in between.

Mind the gap

So how do you actually close a gap like that? 

Let’s take the model utilization gap I mentioned above as an example.

In my team, I introduced a new KPI - Model Participation Rate: the percentage of decisions genuinely driven by the model, and not just any rule.

I also named an owner for this metric, my VP of AI, who ran both data science and fraud operations.

And believe it or not, once you track a metric and assign an owner to it - you start optimizing it.

Now, I get it: sometimes visibility is easier to establish than ownership. Let’s face it, these org gaps are many times the result of internal politics.

And politics are rarely solved with a dashboard.

But a dashboard (or a report, or a deck) is a way to expose that gap to senior leadership. And senior leadership awareness does solve politics.

From time to time.

The bottom line

Sophisticated, AI-powered fraud isn’t a threat in and of itself. It’s about it being able to identify system gaps at scale, and at speed.

But the threat is not new. It was always there.

Found on purpose or found by accident, the exposure is identical.

Name the owner, share the metric, and the gap stops being invisible.

To you at least.

Dajana and I spent a good chunk of the episode on exactly where fraud teams sit in the org chart today versus ten years ago, and why collaboration might be the most underrated basic in the entire industry. Go give it a listen, it was a fun one.

Where's the unowned gap in your organization right now? Hit reply, I'd genuinely like to know.

In the meantime, that’s all for this week.

See you next Saturday.


P.S. If you feel like you're running out of time and need some expert advice with getting your fraud strategy on track, here's how I can help you:

Free Discovery Call - Unsure where to start or have a specific need? Schedule a 15-min call with me to assess if and how I can be of value.
​Schedule a Discovery Call Now »

Consultation Call - Need expert advice on fraud? Meet with me for a 1-hour consultation call to gain the clarity you need. Guaranteed.
​Book a Consultation Call Now »

Fraud Strategy Action Plan - Is your Fintech struggling with balancing fraud prevention and growth? Are you thinking about adding new fraud vendors or even offering your own fraud product? Sign up for this 2-week program to get your tailored, high-ROI fraud strategy action plan so that you know exactly what to do next.
Sign-up Now »

 

Enjoyed this and want to read more? Sign up to my newsletter to get fresh, practical insights weekly!

<
Next
Next

#93 - The two things fraudsters can't hide