Dual citizenship, single focus
Read Time: 16 mins
Written By:
Tim Harvey, CFE
In early 2025, a fraudster posing as a contractor with Portland, Oregon’s, Water Bureau executed a sophisticated scheme that quietly redirected more than $6.7 million in public funds from the city’s coffers to a fraudulent account. The imposter convinced a city employee to change the bank account information in the vendor file and direct the payment to an out-of-state bank account controlled by the fraudulent contractor.
The city didn’t register the error until its bank, Wells Fargo, alerted it to the strange transaction. Despite established controls, the fraudster’s attack exposed a critical transactional blind spot that allowed the faux transfer to proceed without triggering internal alarms.
While authorities were able to recover the funds through civil forfeiture, the case underscores the vulnerability of organizations — even well resourced ones — to subtle breakdowns in verification, workflow oversight and formal controls that manage vendor payment information. Payment detail changes, such as updating a bank account, adding a new beneficiary or modifying payout routing, are some of the riskiest points for account takeover, business email compromise and insider manipulation. Portland’s incident serves as a vivid example of how hidden weaknesses within transactional processes can be exploited and the pressing need for fraud detection systems to be proactive.
Rather than merely stealing credentials to run unauthorized transactions and cash out quickly, fraudsters have become much more strategic with their methods of attack. This article explores an emerging fraud typology where bad actors exploit overlooked transactional patterns with penny transactions, business and vendor email compromise, account takeover and chargeback loops to evade detection and scale attacks. Drawing from real-world cases, I offer practical solutions and a signal detection framework to help fraud teams identify early warning signs and coordinate cross-functional responses to elevate their fraud prevention measures from reactive defense to proactive strategy.
While artificial intelligence (AI) provides hefty assistance to fraud detection by enabling real-time analytics, behavioral modeling and predictive scoring, these detection methods aren’t infallible. Fraudsters have adapted quickly by exploiting blind spots in rule engines and machine-learning models.
Fraudsters slip past automated scrutiny by looking for areas where a system lacks visibility, correlation and control. They’ll repeatedly exploit these weaknesses, creating a pattern of recurring behaviors that, with the right awareness and human oversight, can be detected. While automated systems might not flag a series of rapidly occurring small transactions, for instance, a model with a more advanced detection framework will identify this pattern as a possible indicator of fraud. The system then alerts the person overseeing the process that there’s a control, workflow or data‑visibility gap that exists somewhere in the life cycle of a transaction.
As AI grows more sophisticated, so do fraudsters’ tactics to outmaneuver it, making human oversight, contextual intelligence and continual model refinement critical. Here’s a deeper look at the most damaging fraud schemes that often evade detection.
In penny transaction fraud schemes, fraudsters test active accounts by making tiny transactions — often just a few cents — with stolen payment cards or compromised bank account credentials to determine whether a payment method will be authorized before attempting a large purchase or withdrawal. They intentionally use microtransactions to evade risk thresholds without drawing customers’ attention, allowing them to make much larger fraudulent transactions later and bypass fraud reviews.
For example, a global e-commerce platform might experience a sudden spike in $0.01–$0.05 authorizations coming from the same device cluster (a group of devices that appear unrelated individually but share enough technical or behavioral similarities that they can be linked to the same fraudster, fraud ring or fraud farm). This clustering reveals coordinated fraud activity that would be invisible when looking at a single device in isolation. Fraudsters may use automated scripts to run hundreds of microcharges across thousands of stolen cards. Each successful penny transaction confirms that a card is valid and not reported stolen so that it can be used for larger transactions. Within hours, fraudsters can use the same validated cards at other merchants to make high-value purchases, buy gift cards and commit digital goods fraud — all because the initial penny tests go undetected.
This type of fraudulent pattern can be detected by correlating velocity signals (the rate and frequency of an occurrence over a period of time), device fingerprints and cross‑merchant intelligence. Fraud data consortiums, or industry‑wide networks where multiple merchants, banks or fintechs contribute fraud data and receive aggregated intelligence in return, are the primary way to obtain cross-merchant intelligence. Once a pattern is identified, a platform can block device access and implement stronger authentication measures to stop future attacks.
In business email compromise (BEC) schemes, criminals impersonate a trusted party, such as an executive or employee, electronically to trick an organization into sending money or sensitive information to an unauthorized account. In vendor email compromise (VEC) schemes, scammers impersonate trusted vendors. They use stolen credentials to access email accounts, enabling invoice manipulation, vendor impersonation and fund redirection.
BEC and VEC are social engineering schemes that bypass technical controls by exploiting trust, communication patterns and internal processes rather than hacking systems. In many cases, the domains and transactions appear legitimate. For example, in a VEC scheme, a fraudulent vendor’s seemingly small request to change an account number might appear to be a routine vendor payment exchange that fails to trigger an automated alert.
In December 2021, a Paris‑based real estate firm’s chief financial officer (CFO) received what appeared to be legitimate emails from a well‑known accounting firm’s lawyer. The fraudster, who was part of a criminal network, gained the CFO’s trust by pretending to be a consultant and requested a series of large wire transfers tied to a supposedly confidential acquisition.
Because the emails looked authentic and referenced real business activities, the CFO approved multiple transfers, sending more than 30 million euros to accounts controlled by a fraud ring. By the time the victim organization realized the request was fraudulent, the funds had already moved through multiple international accounts, making recovery extremely difficult. This case illustrates the typical BEC progression: The attacker compromises or spoofs an email account, builds rapport with a targeted employee and then issues a high‑stakes request timed to appear routine.
Modern account takeover (ATO) attacks involve mimicking the ways in which people behave online to access accounts and fool systems into thinking nothing unusual is occurring. In device emulation, a fraudster makes their computer or phone look like someone else’s device. Session hijacking occurs when a fraudster slips into someone else’s online account while that person is still logged in so that they don’t need credentials and can bypass authentication protocols. Once inside the account, fraudsters exploit stored payment methods and reroute communications, all while blending into historical profiles or mimicking a legitimate customer’s past patterns.
During an account takeover, a fraudster’s skilled imitation of a legitimate user suppresses anomaly scores and avoids triggering controls. They replicate familiar login patterns, follow the customer’s typical navigation flow, and pace their clicks and actions to match human‑like behavioral biometrics. They also mirror the user’s regular transaction actions, such as reviewing account information or adding a new payee. By imitating what the real customer normally does, fraudsters create the illusion of a routine session, making the takeover significantly harder for detection systems to identify.
The 2021 OCBC Bank attack in Singapore is emblematic of an ATO. In this case, more than 790 customers had their accounts drained after receiving SMS messages spoofing the bank’s sender identification. Victims were directed to a fake login page that looked identical to the bank’s site, where attackers harvested credentials and then used them to access accounts, intercept multifactor authentication codes and initiate unauthorized transfers.
Account takeover schemes typically follow this structure:
In chargeback loop schemes, also known as digital shoplifting or friendly fraud, fraudsters orchestrate cycles of purchases and disputes across platforms. They exploit lenient refund policies and fragmented merchant data to drain funds while evading consolidated detection. It’s a type of fraud that impacts both financial institutions and their clients in terms of financial exposure, operational overload and reputational damage.
Amazon filed a lawsuit against an alleged fraud ring that stole millions in fraudulent refunds. The defendants bribed seven Amazon employees to authorize fictitious refunds for expensive items including laptops and car tires that were never actually returned. The group was part of a larger organized operation that defrauded retailers and advertised their fraudulent refund services on social media.
In a classic chargeback loop, the fraudster repeats the same dispute tactic across multiple accounts, exploiting gaps in identity verification and merchant evidence.
To counter these silent exploits, fraud fighters must evolve from model-centric thinking to using a dynamic pattern-centric strategy powered by consortium data. Model‑centric and dynamic‑pattern detection are both fraud systems that rely on machine learning models to identify risk based on evolving behaviors rather than fixed rules. In a model‑centric approach, the model becomes the primary decision-maker; it learns what normal activity looks like and flags deviations without needing constant manual updates.
However, attackers continually change their tactics, shifting channels and adapting to new controls. Dynamic pattern‑centric systems can recognize these shifting, fast‑moving patterns by analyzing subtle changes in velocity, device behavior, transaction flow or customer activity, even when the fraud method is new. In practice, this means the system can detect emerging threats, such as a new style of card testing or an account takeover sequence, faster than traditional rules would’ve caught them. This strategy enables organizations to keep defenses aligned with the constantly changing nature of fraud.
Instead of presenting raw metrics or isolated events, narrative intelligence connects the dots and shows what’s happening, why it matters and what action is needed. It transforms scattered information into a coherent storyline that reveals risk patterns, emerging threats and strategic implications. In a fraud prevention context, it means taking technical signals, data points and operational insights and turning them into a narrative that leaders, investigators and cross functional teams can easily grasp. The narrative should be in the form of a business case that’s easy to understand and clearly dictates issues such as emerging fraud trends, the kind of fraud losses associated with those trends, why the organization is facing the issue and a proposed solution. This aligns teams across the organization and allows them to make decisions faster to implement efficient and effective fraud prevention and detection controls.
Integrating signals across payments, authentication, customer profiles and channels allows organizations to detect fraud patterns that tend to remain hidden in isolation. For example, a new device login followed by a password reset may seem routine, and a high‑value wire transfer to a new beneficiary might also appear legitimate on its own. But when these events occur together, especially from an unfamiliar IP address and from a customer who rarely sends wires, the combined signals reveal a strong likelihood of account takeover.
As a hypothetical example, a U.S. bank’s fraud screening systems might notice a customer logging in from a foreign IP address with no prior history. The customer resets their password and immediately attempts a wire transfer to an overseas account. None of these actions would individually trigger an alert, but an integrated signal view would expose a fraud pattern, allowing the bank to hold the transfer and confirm whether the customer had been compromised. This kind of cross‑signal intelligence enables early detection and prevents losses before they occur.
To refine machine learning and AI models, fraud strategists must feed overlooked patterns back into training pipelines to keep systems relevant and adapt to all possibilities of fraud detection. Fraud detection models should be dynamic and able to correlate relevant consortium-level data to arrive at parameters that make their screening capabilities more efficient. For example, while addressing penny transaction fraud, instead of having control at an individual transaction level, the model should look at transactions over a few days and set the screening threshold to be at the same level. This would block fraudsters from bypassing screening with below-threshold penny transactions.
Heat maps, flow diagrams and attack trees can be used to translate complex risks into actionable priorities. From a fraud-screening-model perspective, attack trees are structured threat‑analysis diagrams used to map how an attacker could compromise a system or a process. This is a visual depiction that can help with understanding the risk and potential impact due to a control gap or vulnerability. Visuals accelerate buy-in and response, which can help obtain executive and leadership approvals for new approaches towards fraud screening and controls. Financial organizations and marketplace platforms need to embed anti-fraud thinking directly into their product designs and policy frameworks and make it key to their foundations.
Fraud analysts, data scientists and business leaders must share vigilance against fraud attacks. This means collaborating on strategies, reviewing patterns and challenging assumptions. Shared intelligence concerning fraud trends and payee trustworthiness can make a significant difference in fraud screening by reducing false positives and flagging more true frauds.
Financial institutions should consider customers as critical stakeholders. Informing and educating customers about practical courses of action that can reduce fraud threats can keep them safe against financial fraud schemes. Prioritizing customers’ awareness of evolving fraud tactics and trends, teaching them how to avoid social engineering, recognizing red flags that signal potential schemes and reporting suspected fraud immediately can help increase chances of recovering any losses.
Some best practices for informing customers include:
As fraud examiners, we can help our organizations develop advanced techniques that will elevate detection from a reactive activity to a preventive one.
Evaluate every transaction using:
Risk scores trigger actions like auto-decline, step-up authentication or manual review.
When fraud teams review velocity, they’re looking for how fast something is happening and whether that speed is normal or suspicious. Across different parts of the platform, abnormal velocity often signals automation, credential testing or coordinated fraud attempts.
You can build behavioral profiles based on how clients behave both in monetary and non-monetary transactions, rather than authentication factors such as passwords and PINs. This helps detect bot-like behavior, anomalies and reused traits across synthetic identities through machine learning.
For example, a botnet tests hundreds of cards with identical mouse paths and typing speed. This type of behavior should be flagged, even with small transaction amounts. A member of the fraud investigation team can then analyze it to determine whether it’s fraudulent activity and log the behavior accordingly.
You can prevent abuse of platform endpoints by throttling suspicious activity and enforcing authentication layers.
An application programming interface (API) is simply a bridge that lets two different software systems talk to each other. It’s how apps share information and work together behind the scenes, like when your banking app pulls your account balance or when a website lets you log in using your email provider.
Abuse of platform endpoints often begins when fraudsters bombard login, payment or account‑update APIs with rapid, automated requests designed to test stolen credentials, validate cards or manipulate account settings. To counter this, platforms rely on two core defenses: throttling and enforcement controls. Throttling limits how frequently a user, device or IP address can interact with a specific endpoint, slowing down suspicious high‑velocity behavior that typically signals automation or probing. Once abnormal activity is detected, enforcement mechanisms step in, such as step‑up authentication, temporary account locks, IP blocking or transaction holds, to stop the activity from escalating into actual fraud. Together, throttling and enforcement transform vulnerable endpoints into controlled gateways, making it significantly harder for attackers to exploit system blind spots or scale their attacks unnoticed.
This type of endpoint abuse illustrates a broader challenge. Most of the fraud attacks I’ve witnessed didn’t begin with a high value transaction, but rather with subtle, easily overlooked behaviors that fall below traditional detection thresholds. These early warning signs — small profile edits, rapid fire API calls, penny-testing attempts or repeated authentication resets — rarely trigger alarms on their own. When they’re viewed together, they reveal the early architecture of a coordinated attack.
In transactional fraud schemes, fraudsters perform a series of subtle, low visibility actions that slip past traditional controls. An early signal detection framework addresses this challenge by combining three layers of intelligence — signal clusters, cross functional triggers and escalation paths — to identify concealed threats before they materialize into losses.
Signal clusters form the foundation of the framework. Rather than evaluating events in isolation, the framework enables a fraud team to group small, low risk behaviors, such as password resets, device changes, penny transactions or profile edits, into meaningful patterns. When these signals occur together within a short time window or across related accounts, they reveal early indicators of account takeover, synthetic identity buildup, vendor payment manipulation or chargeback abuse.
Once a cluster is detected, cross functional triggers ensure that the right teams see the right signals at the right time. Because fraud often spans multiple systems, these triggers direct emerging risks to the appropriate owners. This breaks down operational silos and creates shared visibility across fraud, security, payments and operations.
Finally, escalation paths translate early warnings into coordinated action. Each cluster type is tied to predefined responses such as step up authentication, transaction holds, vendor callback verification or manual review, which ensures consistency and speed. These paths prevent early signals from being ignored or handled inconsistently, strengthening the organization’s ability to intervene before financial loss occurs.
By recognizing early behavioral patterns, routing them intelligently and responding with structured escalation, an early signal detection framework helps organizations detect transactional blind spots and stay ahead of increasingly sophisticated fraud strategies. Since my team implemented a platform with this kind of framework, we’ve seen fewer false positives and enhanced fraud detection across our payment-processing teams, investigation teams and shareholders. Fraud analysts can easily adapt this framework, which can be implemented by leadership and bridges data science with strategic oversight.
By clustering low risk signals, guiding them to the right operational teams and enforcing structured escalation paths, organizations can surface hidden patterns long before they evolve into financial loss. In other words, an early signal detection framework transforms scattered anomalies into actionable intelligence, closing the transactional blind spots that fraudsters rely on.
Preventing financial institutions from attacks requires behavioral and contextual intelligence, as well as the ability to adapt rather than merely adhere to static rules. Fraud prevention isn’t a solo sport, and cross-functional collaboration is essential.
Effective fraud prevention hinges on organizations making a fundamental shift from isolated efforts to collaborative defense. Because fraudsters operate strategically across boundaries, financial institutions must foster a unified ecosystem that includes leadership, fraud teams, auditors, regulators, solution providers and informed customers. By incorporating fraud controls as intuitive, behavior-driven practices rather than mere compliance tasks, organizations can transform fraud screening into a proactive, collective habit that empowers all stakeholders to detect and disrupt threats more effectively.
Sunny Banerjee, CFE, is a senior product manager/VP of Enterprise Fraud at First Citizens Bank. Contact her at mimi.bannerjee@gmail.com.
Unlock full access to Fraud Magazine and explore in-depth articles on the latest trends in fraud prevention and detection.
Read Time: 16 mins
Written By:
Tim Harvey, CFE
read time: 10 mins
Written By:
Douglas M. Watson
Read Time: 7 mins
Written By:
David G. Banks, CFE, CIA
Read Time: 16 mins
Written By:
Tim Harvey, CFE
read time: 10 mins
Written By:
Douglas M. Watson
Read Time: 7 mins
Written By:
David G. Banks, CFE, CIA