Welcome back to Fraudology.

Every once in a while I come across a report that makes me stop what I was planning to talk about because it's just that important. This is one of those weeks.

Matt Vega recently released his quarterly fraud report 2026, and after reading it, I knew we needed to break it down together. Not because it's predicting what might happen next year. Because every attack covered in this report is already happening.

One of the biggest themes running through the report is that fraud is simply moving faster than fraud teams are. AI is making sophisticated attacks cheaper, easier to launch, and much harder to detect. Criminals no longer need deep technical skills when they can rent the tools they need through fraud as a service marketplaces.

So what does that actually look like?

In this episode, I walk through several of the newest fraud tactics already showing up in the wild, including malware hidden behind fake unsubscribe links, banking malware that can piggyback on a customer's trusted device, and session hijacking techniques that make account takeover fraud incredibly difficult to detect using traditional fraud detection models.

At first glance, many of these attacks look legitimate. That's exactly the problem.

We also talk about why fraud teams can't rely on individual trust signals like device intelligence, IP reputation, or even behavioral analytics by themselves anymore. Criminals have learned how to blend into legitimate customer behavior, which means our approach to fraud detection and fraud prevention has to evolve too.

This is where things get interesting.

One of my biggest takeaways from Matt's report is that the answer isn't one new tool or one new model. It's layering better fraud intelligence, sharing information across consortium networks, and understanding the broader cybercrime trends happening outside your own organization. Because by the time a new attack reaches your queue, there's a good chance another company has already seen it.

I also spend a few minutes sharing an update on the Merchant Fraud Alliance conference, including our new AI bootcamp that's focused on practical ways fraud teams can start using AI in fraud prevention today. Not because AI replaces fraud analysts, but because it helps good teams move faster.

If you work in merchant fraud, banking fraud, online fraud, or e-commerce fraud, this is one of those episodes that will help you recognize the patterns before they become your next incident.

What you'll hear in this episode:

  • Why Matt Vega's quarterly fraud report 2026 is one of the most valuable fraud intelligence resources released this year.
  • How AI is accelerating modern cybercrime and making sophisticated attacks accessible through fraud-as-a-service platforms.
  • A breakdown of several emerging fraud tactics already targeting merchants and financial institutions.
  • How unsubscribe phishing campaigns are being used to install malware and keyloggers.
  • Why banking malware is becoming increasingly effective at bypassing traditional fraud controls.
  • How session hijacking enables criminals to perform account takeover fraud from trusted customer devices.
  • Why device intelligence, IP reputation, and behavioral analytics all need to be evaluated together instead of independently.
  • How fraud intelligence sharing and consortium data help organizations identify emerging threats faster.
  • An update on the Merchant Fraud Alliance conference and its new AI in fraud prevention bootcamp.


You should listen to this episode if you:

  • Lead fraud, risk, or trust & safety teams.
  • Manage fraud prevention for an ecommerce merchant, fintech, bank, or payments company.
  • Want to stay ahead of the latest cybercrime trends instead of reacting after attacks become widespread.
  • Are evaluating how AI is changing both fraud prevention and AI fraud.
  • Build or manage fraud detection models.
  • Investigate account takeover, synthetic identity, or online fraud.
  • Want practical fraud prevention best practices instead of theoretical discussions.
  • Rely on device intelligence, IP reputation, or behavioral analytics as part of your fraud strategy.


Podden och tillhörande omslagsbild på den här sidan tillhör Karisse Hendrick. Innehållet i podden är skapat av Karisse Hendrick och inte av, eller tillsammans med, Poddtoppen.