Invisible signals
Featured Article

Silent exploits: Detecting transactional blind spots that slip past controls

By Sunny Banerjee, CFE
Written by: Sunny Banerjee, CFE
Date: July 1, 2026
Read Time: 17 mins
Please sign in to save this to your favorites.

Bad actors evade detection and scale attacks by exploiting overlooked transactional patterns that automated alert systems don’t always recognize. Here’s how to thwart these attacks and elevate anti-fraud defenses with a framework to identify early warning signs and coordinate cross-functional responses.

In early 2025, a fraudster posing as a contractor with Portland, Oregon’s, Water Bureau executed a sophisticated scheme that quietly redirected more than $6.7 million in public funds from the city’s coffers to a fraudulent account. The imposter convinced a city employee to change the bank account information in the vendor file and direct the payment to an out-of-state bank account controlled by the fraudulent contractor. 

The city didn’t register the error until its bank, Wells Fargo, alerted it to the strange transaction. Despite established controls, the fraudster’s attack exposed a critical transactional blind spot that allowed the faux transfer to proceed without triggering internal alarms. 

While authorities were able to recover the funds through civil forfeiture, the case underscores the vulnerability of organizations — even well resourced ones — to subtle breakdowns in verification, workflow oversight and formal controls that manage vendor payment information. Payment detail changes, such as updating a bank account, adding a new beneficiary or modifying payout routing, are some of the riskiest points for account takeover, business email compromise and insider manipulation. Portland’s incident serves as a vivid example of how hidden weaknesses within transactional processes can be exploited and the pressing need for fraud detection systems to be proactive.

Rather than merely stealing credentials to run unauthorized transactions and cash out quickly, fraudsters have become much more strategic with their methods of attack. This article explores an emerging fraud typology where bad actors exploit overlooked transactional patterns with penny transactions, business and vendor email compromise, account takeover and chargeback loops to evade detection and scale attacks. Drawing from real-world cases, I offer practical solutions and a signal detection framework to help fraud teams identify early warning signs and coordinate cross-functional responses to elevate their fraud prevention measures from reactive defense to proactive strategy.

Invisible signals

The illusion of immunity: Why AI alone isn’t enough  

While artificial intelligence (AI) provides hefty assistance to fraud detection by enabling real-time analytics, behavioral modeling and predictive scoring, these detection methods aren’t infallible. Fraudsters have adapted quickly by exploiting blind spots in rule engines and machine-learning models.     

Fraudsters slip past automated scrutiny by looking for areas where a system lacks visibility, correlation and control. They’ll repeatedly exploit these weaknesses, creating a pattern of recurring behaviors that, with the right awareness and human oversight, can be detected. While automated systems might not flag a series of rapidly occurring small transactions, for instance, a model with a more advanced detection framework will identify this pattern as a possible indicator of fraud. The system then alerts the person overseeing the process that there’s a control, workflow or data‑visibility gap that exists somewhere in the life cycle of a transaction.

As AI grows more sophisticated, so do fraudsters’ tactics to outmaneuver it, making human oversight, contextual intelligence and continual model refinement critical. Here’s a deeper look at the most damaging fraud schemes that often evade detection.

Penny transactions: The Trojan horse of testing

In penny transaction fraud schemes, fraudsters test active accounts by making tiny transactions — often just a few cents — with stolen payment cards or compromised bank account credentials to determine whether a payment method will be authorized before attempting a large purchase or withdrawal. They intentionally use microtransactions to evade risk thresholds without drawing customers’ attention, allowing them to make much larger fraudulent transactions later and bypass fraud reviews. 

For example, a global e-commerce platform might experience a sudden spike in $0.01–$0.05 authorizations coming from the same device cluster (a group of devices that appear unrelated individually but share enough technical or behavioral similarities that they can be linked to the same fraudster, fraud ring or fraud farm). This clustering reveals coordinated fraud activity that would be invisible when looking at a single device in isolation. Fraudsters may use automated scripts to run hundreds of microcharges across thousands of stolen cards. Each successful penny transaction confirms that a card is valid and not reported stolen so that it can be used for larger transactions. Within hours, fraudsters can use the same validated cards at other merchants to make high-value purchases, buy gift cards and commit digital goods fraud — all because the initial penny tests go undetected. 

This type of fraudulent pattern can be detected by correlating velocity signals (the rate and frequency of an occurrence over a period of time), device fingerprints and cross‑merchant intelligence. Fraud data consortiums, or industry‑wide networks where multiple merchants, banks or fintechs contribute fraud data and receive aggregated intelligence in return, are the primary way to obtain cross-merchant intelligence. Once a pattern is identified, a platform can block device access and implement stronger authentication measures to stop future attacks.

Invisible signals

Targeted data breaches via business and vendor email compromise

In business email compromise (BEC) schemes, criminals impersonate a trusted party, such as an executive or employee, electronically to trick an organization into sending money or sensitive information to an unauthorized account. In vendor email compromise (VEC) schemes, scammers impersonate trusted vendors. They use stolen credentials to access email accounts, enabling invoice manipulation, vendor impersonation and fund redirection. 

BEC and VEC are social engineering schemes that bypass technical controls by exploiting trust, communication patterns and internal processes rather than hacking systems. In many cases, the domains and transactions appear legitimate. For example, in a VEC scheme, a fraudulent vendor’s seemingly small request to change an account number might appear to be a routine vendor payment exchange that fails to trigger an automated alert.

In December 2021, a Paris‑based real estate firm’s chief financial officer (CFO) received what appeared to be legitimate emails from a well‑known accounting firm’s lawyer. The fraudster, who was part of a criminal network, gained the CFO’s trust by pretending to be a consultant and requested a series of large wire transfers tied to a supposedly confidential acquisition. 

Because the emails looked authentic and referenced real business activities, the CFO approved multiple transfers, sending more than 30 million euros to accounts controlled by a fraud ring. By the time the victim organization realized the request was fraudulent, the funds had already moved through multiple international accounts, making recovery extremely difficult. This case illustrates the typical BEC progression: The attacker compromises or spoofs an email account, builds rapport with a targeted employee and then issues a high‑stakes request timed to appear routine. 

Account takeover: Beyond the login

Modern account takeover (ATO) attacks involve mimicking the ways in which people behave online to access accounts and fool systems into thinking nothing unusual is occurring. In device emulation, a fraudster makes their computer or phone look like someone else’s device. Session hijacking occurs when a fraudster slips into someone else’s online account while that person is still logged in so that they don’t need credentials and can bypass authentication protocols. Once inside the account, fraudsters exploit stored payment methods and reroute communications, all while blending into historical profiles or mimicking a legitimate customer’s past patterns.

During an account takeover, a fraudster’s skilled imitation of a legitimate user suppresses anomaly scores and avoids triggering controls. They replicate familiar login patterns, follow the customer’s typical navigation flow, and pace their clicks and actions to match human‑like behavioral biometrics. They also mirror the user’s regular transaction actions, such as reviewing account information or adding a new payee. By imitating what the real customer normally does, fraudsters create the illusion of a routine session, making the takeover significantly harder for detection systems to identify.

Invisible signals

The 2021 OCBC Bank attack in Singapore is emblematic of an ATO. In this case, more than 790 customers had their accounts drained after receiving SMS messages spoofing the bank’s sender identification. Victims were directed to a fake login page that looked identical to the bank’s site, where attackers harvested credentials and then used them to access accounts, intercept multifactor authentication codes and initiate unauthorized transfers.

Account takeover schemes typically follow this structure:

  • Credential harvesting: Fraudsters steal login information through phishing, malware, data breaches or credential stuffing tools. In the OCBC case, SMS phishing led victims to a cloned banking site where they entered their usernames and passwords unknowingly into the fake site.
  • Account access and multifactor authentication (MFA) bypass: Once attackers obtain credentials, they log in, usually from a new device or location, and attempt to bypass MFA. Modern phishing kits can capture MFA codes in real time or use reverse-proxy techniques to relay credentials directly into the legitimate site. This was seen in the Chase Bank phishing attacks and phishing kit schemes in 2022, where cloned login pages captured both passwords and MFA tokens.
  • Reconnaissance inside the account: After gaining access, fraudsters quietly explore the account to review balances, check recent activity, identify linked cards or payment methods, and add new payees or modify contact details. This helps fraudsters plan the fastest path to cashing out without triggering alerts.
  • Cashout attempt: Once attackers establish control, they move quickly to initiate wire transfers, purchase digital goods or gift cards, move funds to mule accounts, and charge devices or services to the victim’s account.

Exploiting operational gaps with chargeback loops

In chargeback loop schemes, also known as digital shoplifting or friendly fraud, fraudsters orchestrate cycles of purchases and disputes across platforms. They exploit lenient refund policies and fragmented merchant data to drain funds while evading consolidated detection. It’s a type of fraud that impacts both financial institutions and their clients in terms of financial exposure, operational overload and reputational damage.

Amazon filed a lawsuit against an alleged fraud ring that stole millions in fraudulent refunds. The defendants bribed seven Amazon employees to authorize fictitious refunds for expensive items including laptops and car tires that were never actually returned. The group was part of a larger organized operation that defrauded retailers and advertised their fraudulent refund services on social media.

In a classic chargeback loop, the fraudster repeats the same dispute tactic across multiple accounts, exploiting gaps in identity verification and merchant evidence.

Invisible signals

From detection to design

To counter these silent exploits, fraud fighters must evolve from model-centric thinking to using a dynamic pattern-centric strategy powered by consortium data. Model‑centric and dynamic‑pattern detection are both fraud systems that rely on machine learning models to identify risk based on evolving behaviors rather than fixed rules. In a model‑centric approach, the model becomes the primary decision-maker; it learns what normal activity looks like and flags deviations without needing constant manual updates. 

However, attackers continually change their tactics, shifting channels and adapting to new controls.  Dynamic pattern‑centric systems can recognize these shifting, fast‑moving patterns by analyzing subtle changes in velocity, device behavior, transaction flow or customer activity, even when the fraud method is new. In practice, this means the system can detect emerging threats, such as a new style of card testing or an account takeover sequence, faster than traditional rules would’ve caught them. This strategy enables organizations to keep defenses aligned with the constantly changing nature of fraud.

Narrative intelligence

Instead of presenting raw metrics or isolated events, narrative intelligence connects the dots and shows what’s happening, why it matters and what action is needed. It transforms scattered information into a coherent storyline that reveals risk patterns, emerging threats and strategic implications. In a fraud prevention context, it means taking technical signals, data points and operational insights and turning them into a narrative that leaders, investigators and cross functional teams can easily grasp. The narrative should be in the form of a business case that’s easy to understand and clearly dictates issues such as emerging fraud trends, the kind of fraud losses associated with those trends, why the organization is facing the issue and a proposed solution. This aligns teams across the organization and allows them to make decisions faster to implement efficient and effective fraud prevention and detection controls.

Cross-channel visibility

Integrating signals across payments, authentication, customer profiles and channels allows organizations to detect fraud patterns that tend to remain hidden in isolation. For example, a new device login followed by a password reset may seem routine, and a high‑value wire transfer to a new beneficiary might also appear legitimate on its own. But when these events occur together, especially from an unfamiliar IP address and from a customer who rarely sends wires, the combined signals reveal a strong likelihood of account takeover. 

As a hypothetical example, a U.S. bank’s fraud screening systems might notice a customer logging in from a foreign IP address with no prior history. The customer resets their password and immediately attempts a wire transfer to an overseas account. None of these actions would individually trigger an alert, but an integrated signal view would expose a fraud pattern, allowing the bank to hold the transfer and confirm whether the customer had been compromised. This kind of cross‑signal intelligence enables early detection and prevents losses before they occur.

Model tuning with strategic feedback

To refine machine learning and AI models, fraud strategists must feed overlooked patterns back into training pipelines to keep systems relevant and adapt to all possibilities of fraud detection. Fraud detection models should be dynamic and able to correlate relevant consortium-level data to arrive at parameters that make their screening capabilities more efficient. For example, while addressing penny transaction fraud, instead of having control at an individual transaction level, the model should look at transactions over a few days and set the screening threshold to be at the same level. This would block fraudsters from bypassing screening with below-threshold penny transactions.

Visual frameworks for executive alignment

Heat maps, flow diagrams and attack trees can be used to translate complex risks into actionable priorities. From a fraud-screening-model perspective, attack trees are structured threat‑analysis diagrams used to map how an attacker could compromise a system or a process. This is a visual depiction that can help with understanding the risk and potential impact due to a control gap or vulnerability. Visuals accelerate buy-in and response, which can help obtain executive and leadership approvals for new approaches towards fraud screening and controls. Financial organizations and marketplace platforms need to embed anti-fraud thinking directly into their product designs and policy frameworks and make it key to their foundations. 

Invisible signals

Collaborative intelligence

Fraud analysts, data scientists and business leaders must share vigilance against fraud attacks. This means collaborating on strategies, reviewing patterns and challenging assumptions. Shared intelligence concerning fraud trends and payee trustworthiness can make a significant difference in fraud screening by reducing false positives and flagging more true frauds.

Customer awareness

Financial institutions should consider customers as critical stakeholders. Informing and educating customers about practical courses of action that can reduce fraud threats can keep them safe against financial fraud schemes. Prioritizing customers’ awareness of evolving fraud tactics and trends, teaching them how to avoid social engineering, recognizing red flags that signal potential schemes and reporting suspected fraud immediately can help increase chances of recovering any losses.

Some best practices for informing customers include:

  1. Deliver continual, bite‑sized education. People absorb and retain fraud prevention guidance best when it’s delivered frequently and in small, actionable formats, rather than through infrequent, dense communications. Ongoing education is essential to keep customers aware of emerging threats and reinforcing safe behaviors. Examples include a monthly “Fraud Alert” newsletter, short in‑app banners explaining new scams and 30‑second videos on red flags based on real examples of current fraud attempts.
  2. Teach customers to recognize social engineering red flags, such as urgent requests for money, credentials or verification, or even unexpected calls claiming to be from the bank with pressure to act immediately.
  3. Use multichannel alerts to communicate new fraud trends quickly. It’s essential to keep people up to date on emerging threats and ensure they understand proper protocols and responses. Effective channels for this kind of alert include SMS alerts for high‑risk scams and email advisories.

Technology and strategy-driven defenses

As fraud examiners, we can help our organizations develop advanced techniques that will elevate detection from a reactive activity to a preventive one.

Dynamic risk scoring

Evaluate every transaction using:

  • Behavioral signals: Velocity, device changes, login anomalies, and interrelated monetary and nonmonetary activities.
  • Historical context: Account age, past transaction patterns.
  • External intelligence: Fraud markers, consortium data. Fraud examiners access consortium data through industry‑wide data‑sharing networks that pool fraud signals, confirmed cases and behavioral patterns from multiple financial institutions, fintechs, merchants, and product and service providers. These networks allow organizations to see fraud attempts happening at other institutions so they can recognize emerging fraud typologies before they occur at their own organizations. Consortium data is typically accessed through fraud detection service and product vendors, industry associations, payment networks and specialized data‑sharing platforms.
  • Adaptive machine learning models: These models are like fraud detectors that get smarter every day. They watch how customers normally behave, notice when something looks unusual and then update themselves based on new information. When fraudsters change their tactics, these models change too, without needing someone to rewrite the screening rules manually. In fraud detection, this means the model can spot new types of suspicious behavior, such as unusual login patterns, strange transaction sequences or sudden changes in account activity, even if it hasn’t seen that pattern before.

Risk scores trigger actions like auto-decline, step-up authentication or manual review.

Velocity checks

When fraud teams review velocity, they’re looking for how fast something is happening and whether that speed is normal or suspicious. Across different parts of the platform, abnormal velocity often signals automation, credential testing or coordinated fraud attempts.

  • Transaction velocity: Fraudsters often run dozens or hundreds of microtransactions to test stolen cards or exploit system weaknesses. Transaction velocity measures how many transactions are happening within a short time window. When checking this, you should look for:
    - A sudden spike in small or identical transactions.
    - Multiple failed or declined transactions in rapid succession.
    - High frequency attempts from the same card, account or merchant.
    - Unusual bursts of activity outside normal customer behavior.
    - Patterns consistent with card testing or bot driven checkout attempts.
  • IP and device velocity: Bots, credential‑stuffing tools and fraud farms rely on high‑speed, automated requests from the same device clusters. Fraud farms are large‑scale, organized operations where fraudsters use hundreds or even thousands of devices or human workers to commit digital fraud on an industrial scale. They’re essentially “factories of fraud,” designed to mass‑produce fraudulent activity across platforms. IP and device velocity measure how often the same IP address or device interacts with a platform. You should look for:
    - One IP hitting login or checkout endpoints repeatedly.
    - A single device attempting to access many accounts.
    - High‑volume activity from VPNs, proxies or data centers.
    - Rapid switching between devices or IPs for the same user.
    - Multiple accounts sharing the same device fingerprint.
  • Account creation and access velocity: Synthetic identity rings, account takeover attempts and bot‑generated accounts all show abnormal speed and repetition. Account creation and access velocity measure how quickly new accounts are created or accessed. You should look for:
    - Many new accounts created from the same IP, device or email domain.
    - Rapid‑fire login attempts across multiple accounts.
    - A burst of password resets or MFA challenges.
    - Newly created accounts immediately performing high‑risk actions.
    - Multiple access attempts from unusual geolocations.

Behavioral fingerprinting

You can build behavioral profiles based on how clients behave both in monetary and non-monetary transactions, rather than authentication factors such as passwords and PINs. This helps detect bot-like behavior, anomalies and reused traits across synthetic identities through machine learning.

For example, a botnet tests hundreds of cards with identical mouse paths and typing speed. This type of behavior should be flagged, even with small transaction amounts. A member of the fraud investigation team can then analyze it to determine whether it’s fraudulent activity and log the behavior accordingly.

Smart API security and rate limiting

You can prevent abuse of platform endpoints by throttling suspicious activity and enforcing authentication layers.

An application programming interface (API) is simply a bridge that lets two different software systems talk to each other. It’s how apps share information and work together behind the scenes, like when your banking app pulls your account balance or when a website lets you log in using your email provider.

Abuse of platform endpoints often begins when fraudsters bombard login, payment or account‑update APIs with rapid, automated requests designed to test stolen credentials, validate cards or manipulate account settings. To counter this, platforms rely on two core defenses: throttling and enforcement controls. Throttling limits how frequently a user, device or IP address can interact with a specific endpoint, slowing down suspicious high‑velocity behavior that typically signals automation or probing. Once abnormal activity is detected, enforcement mechanisms step in, such as step‑up authentication, temporary account locks, IP blocking or transaction holds, to stop the activity from escalating into actual fraud. Together, throttling and enforcement transform vulnerable endpoints into controlled gateways, making it significantly harder for attackers to exploit system blind spots or scale their attacks unnoticed.

This type of endpoint abuse illustrates a broader challenge. Most of the fraud attacks I’ve witnessed didn’t begin with a high value transaction, but rather with subtle, easily overlooked behaviors that fall below traditional detection thresholds. These early warning signs — small profile edits, rapid fire API calls, penny-testing attempts or repeated authentication resets — rarely trigger alarms on their own. When they’re viewed together, they reveal the early architecture of a coordinated attack. 

Invisible signals

Early signal detection framework

In transactional fraud schemes, fraudsters perform a series of subtle, low visibility actions that slip past traditional controls. An early signal detection framework addresses this challenge by combining three layers of intelligence — signal clusters, cross functional triggers and escalation paths — to identify concealed threats before they materialize into losses.

Signal clusters form the foundation of the framework. Rather than evaluating events in isolation, the framework enables a fraud team to group small, low risk behaviors, such as password resets, device changes, penny transactions or profile edits, into meaningful patterns. When these signals occur together within a short time window or across related accounts, they reveal early indicators of account takeover, synthetic identity buildup, vendor payment manipulation or chargeback abuse.

Once a cluster is detected, cross functional triggers ensure that the right teams see the right signals at the right time. Because fraud often spans multiple systems, these triggers direct emerging risks to the appropriate owners. This breaks down operational silos and creates shared visibility across fraud, security, payments and operations.

Finally, escalation paths translate early warnings into coordinated action. Each cluster type is tied to predefined responses such as step up authentication, transaction holds, vendor callback verification or manual review, which ensures consistency and speed. These paths prevent early signals from being ignored or handled inconsistently, strengthening the organization’s ability to intervene before financial loss occurs.

By recognizing early behavioral patterns, routing them intelligently and responding with structured escalation, an early signal detection framework helps organizations detect transactional blind spots and stay ahead of increasingly sophisticated fraud strategies. Since my team implemented a platform with this kind of framework, we’ve seen fewer false positives and enhanced fraud detection across our payment-processing teams, investigation teams and shareholders. Fraud analysts can easily adapt this framework, which can be implemented by leadership and bridges data science with strategic oversight.

By clustering low risk signals, guiding them to the right operational teams and enforcing structured escalation paths, organizations can surface hidden patterns long before they evolve into financial loss. In other words, an early signal detection framework transforms scattered anomalies into actionable intelligence, closing the transactional blind spots that fraudsters rely on.

A unified defense ecosystem

Preventing financial institutions from attacks requires behavioral and contextual intelligence, as well as the ability to adapt rather than merely adhere to static rules. Fraud prevention isn’t a solo sport, and cross-functional collaboration is essential.

Effective fraud prevention hinges on organizations making a fundamental shift from isolated efforts to collaborative defense. Because fraudsters operate strategically across boundaries, financial institutions must foster a unified ecosystem that includes leadership, fraud teams, auditors, regulators, solution providers and informed customers. By incorporating fraud controls as intuitive, behavior-driven practices rather than mere compliance tasks, organizations can transform fraud screening into a proactive, collective habit that empowers all stakeholders to detect and disrupt threats more effectively.

Sunny Banerjee, CFE, is a senior product manager/VP of Enterprise Fraud at First Citizens Bank. Contact her at mimi.bannerjee@gmail.com.

Begin Your Free 30-Day Trial

Unlock full access to Fraud Magazine and explore in-depth articles on the latest trends in fraud prevention and detection.