Fraudology Podcast with Karisse Hendrick

If you work in online fraud prevention, chances are you've caught the "bug". The bug that makes you passionate about identifying & preventing cybercriminals from getting away with stealing from your company, or your client's companies. Most people who have made cyber-fraud their career have the perfect balance of analytical and social skills, a strong sense of justice and the curiosity that will drive you to go down every path of information until you "crack the case". Just like sociology is the study of social behavior, and psychology is the study of human behavior, Fraudology is the science and study of fraud. On the Fraudology podcast, long-time online fraud expert, Karisse Hendrick will dive into all areas of Fraudology from the perspective of a fraud-fighter. With guests ranging from former cybercriminals to fraud-fighters at Fortune 500 companies to law enforcement and others, you will no doubt be entertained, while learning a lot about fraud & other forms of abuse prevention! Subscribe to be alerted when a new episode is out and please rate & review where you can, to help others find this new & unique podcast!

  1. 2d ago

    Lending Fraud: When the Perfect Applicant Is the Red Flag

    Welcome back to Fraudology. Welcome back to Fraudology. I'm Karisse Hendrick, and this week I'm talking with someone who has become a regular guest on the show. Matt Vega has joined me across six years and several different employers. He's now the Chief Fraud Strategist at Point Predictive, where he works with Frank McKenna on lending fraud, and his move into that world gave me a good reason to ask what looks different from where he sits. Lending fraud rarely looks like the fraud most merchants picture. Plenty of losses start with an applicant who stretched the truth about income or cleaned up a credit report through repeated disputes, and those cases sit right next to organized attacks. Matt explains how credit washing fraud and income misrepresentation blur the line between abuse and fraud. He also shows how lending consortium fraud data lets a lender see patterns that a single credit report never will. Then we get to the part I think deserves the most attention. A super prime synthetic identity can now be assembled quickly, and on paper it can outperform a real customer. Whether you work in lending, fintech, or ecommerce, you'll leave with a clearer sense of where your defenses actually hold up. What you'll hear in this episode:How lending consortium fraud data works, and why one lender's loss can protect an entire network from the same attackHow credit washing fraud and credit bureau dispute abuse can turn a 580 score into a 790 for a short window, and why lenders sometimes miss itWhy income misrepresentation and bust out fraud lending sit on a spectrum between friendly first party abuse and deliberate attacksHow a super prime synthetic identity can be built in roughly 90 days using an authorized user fraud scheme and buy now pay later fraudWhy a perfect credit profile can be the red flag, and what fraud network intelligence lending teams can see that a credit report cannotHow jailbroken LLM fraud tools, dark web fraud tools, and a dark web identity marketplace make it easier to produce identities, identity document fraud lending, and matching cardsWhy AVS CVV fraud limitations and PSP fraud tool limitations show up as high declines, false positives, and chargebacksHow good user behavior mapping makes anomalies easier to spot, and how polymorphic fraud attacks and device farms try to imitate real human behaviorHow behavioral biometrics lending fraud controls, friction strategy fraud prevention, and fraud stack vendor evaluation fit together, including why a design partnership fraud tech opportunity can be worth saying yes to You should listen to this episode if you:Work in lending, auto finance, or fintech and want a current look at lending fraud beyond the standard synthetic identity playbookAre responsible for fraud tech stack strategy and want a practical way to think about proven vendors versus newer technologyAre a merchant relying on a PSP fraud tool and wondering why your declines and your chargebacks are both highNeed language to explain friction decisions to executives and growth teams using data they already care aboutWant to understand why a fraud consortium lending network matters when attackers are using AI to adapt quickly

    Lending Fraud: When the Perfect Applicant Is the Red Flag
  2. Oct 1

    AI Enabled Fraud: When Growth Comes Before Guardrails

    Welcome back to Fraudology. AI is here, and it’s making every kind of fraud we already know cheaper, faster, and harder to catch. We are going to walk through a handful of stories that show exactly how AI enabled fraud is showing up right now. From card testing at scale to one very messy fraud story. That story is Polymarket, and I spend some real time on it. It’s rare that we get this much visibility into a company’s actual fraud details. A Wall Street Journal investigation lays out the stolen debit cards linked to thousands of new accounts and a fraudulent deposit rate that hit 80%. I also get into AI-generated deepfake delivery orders, a bank coalition’s new warning about agentic commerce fraud, and a warning about AI voice cloning scams. We aren’t eliminating fraud, we never can, but we can get the information to be as fast or slightly faster than the fraudsters. What you’ll hear in this episode:Why AI-enabled BIN attack fraud and card testing are up over 75% according to at least one fraud vendor, and how fraudsters are now optimizing payment authorization the same way legitimate payment teams doA full breakdown of the Polymarket fraud scandal, including the prediction market fraud risk baked into its business model and the leadership decisions that made things worseWhy Polymarket scrapped its same-source withdrawal rule to speed up payouts, and how that decision opened the door to real money laundering prevention failuresA serious account takeover fraud exploit where a new account created with someone's stolen SSN could inherit their existing balance and linked cards, no password neededWhy compliance staffing fraud programs need people with actual prevention experience, not just investigators brought in after the factHow growth at all costs fraud risk plays out when a CEO's response to an 80% fraud rate is reportedly "just keep growing and pay a fine"A new bank coalition report on agentic commerce fraud, and why AI shopping agent chargeback liability still has no real framework under current Visa and Mastercard rulesAn AI-generated fake delivery order used to attempt a retail theft at Walmart, and a Georgia police chief's warningWhat a real chargeback monitoring program actually looks like from the inside, and why Polymarket landing a fraud vendor like Riskified says a lot about how serious this problem became You should listen to this episode if you:Work in payments, card fraud, or retail fraud prevention and want a grounded look at how AI is scaling attacks you already knowAre building or evaluating a chargeback monitoring program and want a real, public example of what happens when fraud rates spiralCare about prediction market fraud risk or are watching the regulatory and legal fallout at companies like PolymarketAre responsible for compliance staffing fraud programs and want language for why prevention expertise matters as much as investigative expertiseAre tracking agentic commerce fraud and want to understand the AI shopping agent chargeback liability gap that still hasn't been solvedWant practical, real-world examples of AI-generated fake delivery orders and AI phishing scams to bring back to your own fraud team

    AI Enabled Fraud: When Growth Comes Before Guardrails
  3. Sep 24

    Food Delivery Fraud: From Diner to Doorstep

    I'm joined today by Sudhir Lanka, Associate Director of Fraud Strategy at GrubHub. Sudhir's team doesn't just cover GrubHub anymore. His scope recently expanded to include Wonder, GrubHub's new parent company, and Blue Apron, which means he's thinking about food delivery fraud across three genuinely different business models at once, and I wanted to dig into how that actually changes his approach. We get into what makes a three-sided marketplace uniquely exposed to fraud, since GrubHub has to protect diners, restaurants, and drivers all at the same time, and a gap in protection on any one side eventually breaks trust for everyone else. Sudhir walks through the primary fraud vectors his team deals with, account takeover, payment fraud, refund abuse, and promo abuse, and gives some of the most specific, real-world detail I've heard on this podcast about how each one actually plays out, down to the exact excuses customers give to get a refund they're not owed. What you'll hear in this episode:How Sudhir's career path through JP Morgan Chase, Discover, and GrubHub shaped his approach to fraud strategy at each stage of scaleWhy GrubHub, Wonder, and Blue Apron each carry different food delivery fraud risks despite serving the same underlying missionThe three primary fraud vectors GrubHub tracks, account takeover, payment fraud, and refund and promo abuse, and how they show up differently across business linesA detailed walkthrough of restaurant account takeover, including how a compromised owner's email can lead to a redirected ACH payout and an expensive double payment for GrubHubReal examples of driver and diner collusion, including self-delivery loops and a surprising exploit tied to minimum wage laws in cities like Seattle and CaliforniaWhy refund abuse and first party fraud can't be predicted at the time of transaction, and Sudhir's framework for placing controls at the actual point of irreversibility insteadHow layered fraud controls work across account creation, checkout, and post-order stages, including multifactor authentication, 3DS authentication, CVV validation, and delivery PIN verificationThe difference between soft friction and hard friction, and why Sudhir intentionally reserves harder friction for a very small percentage of customersWhy Sudhir sees fraud strategy as fundamentally pro-growth, not anti-growth, and how protecting trust across the marketplace translates directly into revenue You should listen to this episode if you:Work in fraud strategy at a marketplace, food delivery, or platform business balancing multiple user typesAre dealing with refund abuse, promo abuse, or first party fraud and want a real framework for controlling it without over-relying on predictionWant to understand restaurant account takeover and payment redirection fraud from the platform's side, not just the consumer sideAre building or refining layered fraud controls and want concrete examples of where soft friction versus hard friction actually belongsNeed language to make the case internally that fraud strategy is pro-growth, not a blocker to it

    Food Delivery Fraud: From Diner to Doorstep
  4. Sep 17

    A Government Email Phishing Scam and the ID Scan Breach Update

    Welcome back to Fraudology. This is a solo episode, and I’ve got two stories for you this week. I wanted to follow-up on the ID scan breach that Frank McKenna and I discussed last week. Where things stand now, whether we should still be worried, and what the driver’s license data breach means for KYC fraud prevention going forward. And then I wanted to get into one of the biggest fraud stories this week. This one is brand new and I wanted to get it to you as soon as possible. A government email phishing scam hit Revolute using what appeared to be a legitimate .gov email domain. The request was fulfilled. Customer data was released. And it did not require a breach of Revolute at all. It required a spoofed email that looked real enough to pass. I have been talking to my fraud threat intelligence sources about this, including someone with a background at one of the three-letter government agencies. What he told me changed how I’m thinking about this incident entirely. We are going to get into all of it. This is a fraud news episode, and I’m going to keep it tight today. Let’s dive in. What you’ll hear in this episode:The ID scan data breach update. Where the 153 million driver’s license database stands now, why the FBI takedown matters, and whether we should still be treating this as an active threat.Why the ID scan breach was so dangerous for KYC fraud and identity document fraud detection. And why most verification companies would not have caught it.What supply chain data breach risk looks like in practice and the vendor contract language every financial institution should have in place.The Revolute government request fraud incident explained. What data was released, what a fraudster can do with it, and why it could be used for identity theft and espionage.Why a .gov email domain is harder to spoof than it sounds, what a CAC card is and why it matters for government email security, and what my fraud threat intelligence source actually thinks happened.The three most likely explanations for this government email phishing scam. Including the foreign adversary fraud angle that changes the whole picture.How to prevent government email phishing at your financial institution, email authentication tools, two factor authentication for sensitive inbox access, and training the team that handles government information requests.Why this kind of email domain spooking fraud is going to be attempted again, and what neobank fraud prevention teams specifically need to have in place. You should listen to this episode if you:Work in fraud, compliance, or risk at a bank, neobank, or financial institution and want to understand what the Revolute incident actually means for your team.Are responsible for financial institution phishing prevention and want practical recommendations you can bring back this week.Want to understand how government impersonation fraud works and why a .gov email does not guarantee legitimacy.Are evaluating your vendor contracts for supply chain data breach liability language and want a framework for what to include.Work in KYC fraud prevention and want to understand why the ID scan data breach was uniquely dangerous for identity document verification.Follow fraud news and want a practitioner's read on what actually happened with Revolute, not just the viral LinkedIn version.

    A Government Email Phishing Scam and the ID Scan Breach Update
  5. Sep 10

    Impersonation Scams: When an ID Isn’t Proof

    Welcome back to Fraudology. I’m joined this week by Frank McKenna of Frank on Fraud and Point Predictive, because this was one that I needed a second brain to process it all with me. I was heads-down working on the Merchant Fraud Alliance agenda when my phone would not stop buzzing. It was a group chat with the people I trust to tell me when the big deals are happening versus just internet noise. And this time, it was a big deal. Brian Krebs had uncovered a dark web portal selling real driver’s licenses. Front, back, barcode, and all. For the price of about a hundred dollars each. That’s roughly 60% of the entire US population sitting in a database that almost anyone could buy. The rest of this episode is really two stories that are more connected than you realize once you start looking deeper. The data breach itself is only half of the story. The other half is understanding the vendor working behind the scenes of a huge number of household-name businesses, handling their identity verification. That’s what makes this breach so much bigger than it looks on the surface. Then we shift to the scam that has been on my mind since Frank first flagged it last year. Digital arrest is a form of psychological captivity scam that’s now officially made the leap from India to the United States, with real victims and real seven-figure losses to prove it. Buckle up, because the way to start fighting this is to know what we are up against. What you’ll hear in this episode:How a supply chain breach at an identity verification vendor exposed 153 million physical driver’s licenses, and why that’s different from a typical retail data breach.Why forged identification cards used to be the thing fraud detection software looked for, and why that entire approach breaks down when the ID being used is real.How AI deepfake drivers license techniques let someone swap their face onto a real, stolen license and pass a liveness check.What digital arrest actually is, and why I was wrong to assume it would stay contained.Real case studies of US victims, including a woman held under surveillance for two months and who lost $4.2 million.How digital arrest has evolved into homegrown versions, including police impersonation and FBI impersonation calls, plus jury duty bail scams.The scam compounds and pig butchering scam infrastructure in Cambodia that’s now being repurposed for new scam types.Why some of the jury duty and bail scam calls are reportedly coming from contraband cell phones inside US prisons. You should listen to this episode if you:Are working in identity verification, KYC, or fraud prevention and need to think what “the ID is real” actually proves.Are a fraud and risk professional at a bank who may be the first to see a victim of digital arrest scams withdrawing large sums under duress.Someone who wants to understand how a breach at one vendor can quietly expose customers of dozens of major, recognizable brands.Are part of a consumer-facing team and may need to train frontline staff to recognize a customer who’s on the phone with a scammer while standing at the counter.

    Impersonation Scams: When an ID Isn’t Proof
  6. Sep 3

    When AI Cancels Your Account: 966 Million Reasons to Get Chargeback Disputes Right

    Welcome back to Fraudology. It’s just me for this episode, but I’ve got two stories to dig into. They are genuinely important for anyone dealing with chargeback disputes. Whether you’re on the merchant side or the banking side. The first is Uber and the nearly billion dollars in fines for automated account deactivation. The second story is the story that I really want to unpack. Hims and Hers blowing past their chargeback threshold on their weight loss subscription business. It’s rare that this stuff becomes public, and I think there’s a lot merchants can learn from it. I know a lot of companies leaning on AI right now to cancel buyer or seller accounts. We will walk through the math on chargeback fee per dispute, what’s actually driving these disputes, and what I’d tell these businesses if they were my client. What you’ll hear:Why Uber's near-billion-dollar GDPR fine over automated account deactivation AI should matter to any company using AI to cancel buyer or seller accounts, not just ride-share platforms.How Visa's acquirer monitoring program actually works, including the chargeback threshold merchants need to stay under and the real dollar cost once they don't.A full breakdown of the Hims and Hers chargeback situation, including the FTC lawsuit, Restore Online Shoppers Confidence Act violations, and real customer complaints pulled from public FOIA records.How I'd approach chargeback root cause analysis if this were a client, from subscription billing practices to refund policy gaps.Real examples of merchants using generative AI chargeback response tools, including one who took their chargeback win rate strategies from a 40% to 65% win rate.Why dispute monitoring program penalties go far beyond the per-chargeback fee, and how they can affect your relationship with your payment processor.How to calculate the true cost of a chargeback, including fees, fines, operational costs, and the merchant reputation and chargebacks damage that doesn't show up on a balance sheet.A reminder that subscription chargebacks are almost always a symptom, not the actual disease, and what usually causes them. You should listen to this episode if you:Are a merchant, especially recurring or subscription-based businesses, currently on or worried about landing on Visa's acquirer monitoring program.Are a fraud, risk, or payments professionals who want a practitioner's breakdown of what actually drives chargeback disputes.Are using or considering AI to automate account decisions, cancellations, or chargeback responses.Are a banking professional curious about the ecommerce and merchant side of dispute management.Are a business leader weighing whether an aggressive subscription or cancellation policy is actually saving money, or just deferring a bigger cost.

    When AI Cancels Your Account: 966 Million Reasons to Get Chargeback Disputes Right
  7. Aug 27

    Fraud News: AI Document Fraud, Zombie Credit Cards, and a Digital Arrest Scam

    Welcome back to Fraudology. Since I’ve been back from SardineCon, I’ve thought about how much faster and cheaper AI is making fraud. That thread runs through basically everything I’m covering today. I’m digging into a new report from Inscribe showing a 4X increase in AI generated documents. I’ll walk through the difference between a document that’s built entirely by AI and one that’s a real document with AI alterations. Because they are not the same problem. Then we will go deep on a digital arrest scam, and this is the one I really want you to sit with. Frank McKenna has been predicting digital arrests would hit the US for almost a year. I found a first person account from a woman who got a call claiming to be from her local sheriff’s department. What happened to her over the next several hours is genuinely hard to listen to. I think this is one every fraud fighter needs to be able to explain to the people in their own life who aren’t in this industry. Along the way, I’m covering a case out of Spain where a man was arrested for using deepfakes to get past identify verification checks, a new report on Grok deepfakes, and a study out of UMass on zombie credit cards. Which is a real NFC fraud loophole. It’s a lot but stick with me. What you’ll hear:A quick recap of SardineCon 2026 and why AI was the theme of nearly every conversation I had thereInscribe's new fraud report showing a 4X increase in AI generated documents, and why bank statement fraud, fake invoices, and fake pay stubs make up more than half of what they're catchingThe difference between AI generated documents and AI altered ones, and why the altered ones are actually harder to catchHow synthetic identity fraud and first party fraud both show up in lending fraud, even when the person applying is realA case out of Spain where deepfakes almost got a man through identity verification, until a one second glitch gave him awayA new report on Grok deepfakes and what it means that one platform is tied to the majority of tracked incidentsA UMass study on zombie credit cards and the NFC fraud loophole that can bring expired cards back to lifeThe full, first person story of a digital arrest scam, including the jury duty scam call, someone impersonating law enforcement, a bond scam demand, and a PayPal fraud payment that couldn't be undone You should listen to this episode if you:Want to understand what a digital arrest scam actually sounds like from the insideAre in lending, underwriting, or KYC and need to know how bank statement fraud and fake pay stubs are evolvingWant to know the real difference between synthetic identity fraud and first party fraudHave family members who don’t work in fraud and need a real example to help them recognize a jury duty scam or someone impersonating law enforcementAre tracking deepfakes and want to know where Grok deepfakes fit into the bigger pictureProcess card not present or in person transactions and haven't heard about the zombie credit card loophole yet

    Fraud News: AI Document Fraud, Zombie Credit Cards, and a Digital Arrest Scam
  8. Aug 20

    The One-Shot Phishing Attack

    Welcome back to Fraudology. I have to tell you I’m genuinely excited about this one. Today’s guest was highly recommended by Matt Vega, someone whose opinion I trust completely in this industry. By the time we finally hit record, we’d already been talking for 45 minutes off air. That’s a pretty good sign this episode is going to deliver. Cy Khormaee spent years at Google, building out what eventually became the company’s user protection platform and the technology that now runs quietly in the background protecting billions of devices worldwide from phishing and malware. He took that experience and eventually founded Aegis.AI, and he just got back from Black Hat, which means he is walking into this conversation with a front-row view of exactly where adversarial AI is heading next. What I wasn’t fully prepared for was how far he was willing to take the demonstration. Cy didn’t just tell me adversarial AI is a growing thread, he showed me, live. Using nothing more than ChatGPT and information freely available online. It’s the kind of moment that changes how you think about a threat you thought you already understood. We cover a lot of ground in this one. And if you work in fraud, trust and safety, or security in any capacity, this is one you’ll want to sit with. What you’ll hear in this episode:Cy's path from Google's user protection platform, home of reCAPTCHA and Safe Browsing, to founding Aegis.AI, and how credential stuffing defense evolved into a hundred-million-dollar business.A live ChatGPT phishing demo where Cy used open source intelligence to research himself and generate a convincing, contextualized phishing email and matching fake conference website in minutes.Why AI phishing attacks have moved from theoretical to fully operational, with real-world state actor phishing tactics now automatable at near-zero cost.The staggering AI phishing email bypass rate statistics: over 50% of emails now slip past existing security email filter bypass controls.Why AI red team fraud thinking, treating AI as a gardener to nurture rather than a carpenter to micromanage, changes how fraud and security teams should actually deploy these tools.How the real Robinhood phishing attack shows why login fraud detection signals and upstream fraud detection AI matter more than ever.Why fraud and cybersecurity convergence isn't optional anymore, and how fraud data sharing across teams closes gaps that adversaries are actively exploiting.How automated sandboxing fraud detection can catch attacks before a user ever clicks, and why carding attack prevention and account takeover detection increasingly rely on the same signals as cybersecurity teams. You should listen to this episode if you:Work in fraud, trust and safety, or security and want to understand how adversarial AI is changing social engineering and phishing attacks.Are responsible for account takeover detection, credential stuffing detection, or synthetic identity risk at a bank, fintech, or merchant.Assumed business email compromise had been mostly solved and need a reality check.Are evaluating AI fraud investigation automation tools and want a clearer sense of what can realistically be automated today.Are trying to build the case internally for fraud and cybersecurity convergence and fraud data sharing across teams.

    The One-Shot Phishing Attack
4.8
out of 5
39 Ratings

About

If you work in online fraud prevention, chances are you've caught the "bug". The bug that makes you passionate about identifying & preventing cybercriminals from getting away with stealing from your company, or your client's companies. Most people who have made cyber-fraud their career have the perfect balance of analytical and social skills, a strong sense of justice and the curiosity that will drive you to go down every path of information until you "crack the case". Just like sociology is the study of social behavior, and psychology is the study of human behavior, Fraudology is the science and study of fraud. On the Fraudology podcast, long-time online fraud expert, Karisse Hendrick will dive into all areas of Fraudology from the perspective of a fraud-fighter. With guests ranging from former cybercriminals to fraud-fighters at Fortune 500 companies to law enforcement and others, you will no doubt be entertained, while learning a lot about fraud & other forms of abuse prevention! Subscribe to be alerted when a new episode is out and please rate & review where you can, to help others find this new & unique podcast!

More From Rolled Up Network

You Might Also Like