Fraud map

Fraud goes by many names

Know only one part of it and you defend only one part. Once you have the whole picture in front of you, you can decide where effort pays off and which gap you leave open on purpose. This map is that picture.

AI changes the game

Not because new kinds of fraud necessarily appear, but because fraud pays off far more readily than it used to.

Fraud has always been a calculation: effort per attempt against expected return. When an attack only paid off for large amounts, small targets were left alone. That calculation no longer exists. Once the next attempt costs almost nothing, every target and every amount is worth it. What shifts along with it:

Scale

One scam, a hundred targets

A scam used to be tried out on one company and then laboriously transferred to the next. Today it runs against hundreds at the same time, evaluates the responses and adjusts itself.

Speed

No window left

Scouting, testing, creating identities, opening accounts: what used to run over weeks and leave traces along the way now happens in a single pass. The opportunities to step in are closing.

Who attacks

Fraud as a service

Tools are sold, with support and a success guarantee. Anyone who wants to attack needs neither technical skill nor language skills nor a network, only money. The number of possible offenders has grown many times over.

Recognisability

The old signs are falling away

Clumsy language was only the most obvious one. A familiar voice, a known face in a video call, a professional appearance, a proper ID document: none of it is proof any more.

Defence

What still holds

Controls that rely on a human finding something plausible are losing their value. Controls that rely on behaviour, on linking across channels and on hard rules are gaining.

Consequence

Overview beats single measures

When everything is attacked at once, securing one spot particularly well helps little. What counts is knowing the whole field and knowing which gap you leave open deliberately.

What precedes the damage

Every case of fraud is preceded by preparation, often weeks or months earlier and with a clear division of labour. The damage is the end of a chain, not its beginning.

Data sourcing Breaches, phishing, malware
Scouting Harvesting data, observing how things work
Infrastructure Fake shops, hosting, obfuscation
Channels Phishing campaigns, invented pretexts
Testing Running through credentials and card numbers
Automation Bots, scripts, attacks at scale
Trade Reselling the results of the preparation
Handover Execution and the money leaving

Every one of these fields is an opportunity to step in. Look only at the damage and you have let all of them pass. That is precisely why looking at the whole beats looking at the single case: how I go about it →

Categories

Ordered by who attacks and how the damage arises, not by the channel it comes in through. That is the distinction that matters: the same scam turns up in the web shop, in the app and in the store. Defence therefore has to start at the scam, not at the channel.

The colour of a card says which discipline is responsible: violet for fraud prevention, green for payments, burgundy for anti-financial crime. Navy carries whatever sits across all of them.

A Identity, access & platform abuse

  • Account takeover
  • Synthetic identities
  • Identity theft at onboarding
  • Account farming & account renting
  • Deepfake & document forgery
  • Fraud as a service
  • SIM swapping
  • Session hijacking & man in the browser
  • API abuse
  • Scalping & inventory hoarding
  • Ban evasion & multi-accounting
  • and much more

B Payment & transaction fraud

  • Card-not-present fraud
  • Card-present fraud at the POS
  • Triangulation fraud
  • Authorised push payment scam
  • SEPA & R-transaction fraud
  • Business email compromise
  • Instant payment fraud (A2A)
  • Crypto investment on-ramp
  • Gift card & prepaid fraud
  • Digital wallet fraud
  • and much more

C First-Party Fraud

  • Deliberate first-party fraud
  • Unintentional “family fraud”
  • Refund, policy & promo abuse
  • Collusion
  • Service abuse in delivery
  • Loyalty & voucher abuse
  • Creator & affiliate abuse
  • Chargeback fraud
  • Subscription & free trial abuse
  • and much more

D Affiliate & ad fraud

  • Click fraud
  • Impression fraud
  • Attribution fraud
  • and much more

E Claims, supply chain & physical fraud

  • Insurance claims & application fraud
  • Cargo theft using identity fraud
  • Shipping & postal fraud
  • Merchant onboarding fraud & fake shops
  • and much more

F Scams & social engineering

  • Romance & investment scams
  • Pig butchering
  • Phishing, smishing & vishing
  • Tech support & authority scams
  • Purchase & marketplace scams
  • Telecommunications toll fraud
  • and much more

G Money laundering & AML

  • Money mules
  • Mule networks & account farms
  • Transaction laundering
  • Structuring (smurfing)
  • Layering through payment service providers
  • Crypto on- and off-ramps
  • Trade-based money laundering
  • Third-party payer constellations
  • Sanctions and embargo evasion
  • and much more

In detail further down →

H Insider & HR fraud

  • Warehouse fraud & internal theft
  • Invoice factoring & trade finance fraud
  • Procurement & supplier fraud
  • Payroll fraud
  • Recruitment fraud & insider placement
  • and much more

Two things sit across this order and cannot be filed under it: the question of what happens to the proceeds, and organised gangs that work several categories at once.

Money laundering belongs on the same map

Not as a neighbouring topic, but as part of the same event. Fraud produces money that has to go somewhere, and that is exactly where the fraud team's remit ends in most companies.

Both areas see the same accounts, the same payments and often the same people, only at different points in time and out of different systems. Fail to bring those views together and you check the same anomaly twice and still miss it: the fraud team sees one suspicious payment, anti-money-laundering sees an unremarkable amount. Only together does the pattern appear.

That is why money laundering is not tucked into a chapter at the edge here, but sits in the middle of the map. Look only at fraud and you see half the picture.

Mules and account farms

  • Fake job offers, where the helper usually ends up a suspect
  • Unwitting mules (“just lend me your account for a moment”)
  • Knowing mules working on commission
  • Bought and rented accounts
  • Account farms built on synthetic identities
  • Chained accounts and forwarding networks
  • Romance and investment fraud as a source of mules
  • and much more

Placement and layering

  • Structuring below reporting thresholds
  • Layering across several payment service providers
  • Instant payments as an accelerator
  • Prepaid cards and vouchers
  • Crypto on- and off-ramps
  • Wallet hopping between providers
  • Cash-intensive business models
  • and much more

Abuse of legitimate channels

  • Transaction laundering through someone else's merchant account
  • Sham sales on marketplaces
  • Trade-based money laundering via invoices
  • Over- and under-invoicing
  • Third-party payer and triangular constellations
  • Refunds as a payout channel
  • Digital goods and licences as carriers of value
  • and much more

Industry-specific routes

  • Gaming: chip dumping and coordinated losing
  • Gaming: routing money through bonuses and stakes
  • Lottery: buying up wins and fake winners
  • Marketplace: seller accounts as a conduit
  • Insurance: staged claims as a payout
  • Property and high-value goods purchases
  • Sanctions and embargo evasion via intermediaries
  • and much more

Where exactly the line between fraud and money laundering runs is of no interest to offenders. Inside companies it is usually a departmental boundary. Closing that gap is the job of anti-financial crime.

Industries

The same order, a different weighting: what hurts most in a marketplace business is irrelevant for an insurer, and the other way round. Every business model has its own fraud profile.

  • Marketplaces & platforms
  • B2B trade
  • Delivery & quick commerce
  • Mobility, taxi & ride hailing
  • Omnichannel & physical retail
  • Logistics, warehousing & post
  • Banking & neobanks
  • Insurance
  • Travel, OTA & experiences
  • HR & recruitment
  • Streaming & digital content
  • Ticketing & travel passes
  • Booking platforms
  • Digital goods, licences & in-game items
  • SaaS, cloud & platform services
  • iGaming, esports & lottery
  • Lending & credit
  • Telecommunications
  • Crypto exchanges & on/off ramps
  • Quick service restaurants & food ordering

On top of that come cross-cutting topics that belong to no single industry: dispute handling as the bridge between payment and refund, the fraud profile of alternative payment methods from BNPL to account-to-account, omnichannel fraud at the seams between channels, and loss prevention as a discipline in its own right.

Grown out of practice

This map was not designed at a desk. It grew out of reality: out of cases that actually crossed the table, out of patterns that only became visible the second or third time round, and out of conversations with people who see the same things every day.

And it stays up to date. Every new scam, every case, every talk where someone in the audience adds something writes another piece of it. It will never be finished, and that is not a shortcoming but the point: an overview of something that keeps changing must not stand still itself. What is here is today's state, not next year's.

In practice that means: we do not have to start from zero. For most cases the framework already exists. What remains is the work on your specific situation.

From the map to your own threat portfolio

Behind every category lie worked-out profiles, variants and cases, and behind every industry its own picture of the threats. You do not have to get your head around all of it. That is what I am here for: I take you through the parts that actually affect you and leave the rest alone.

Because only a fraction of it matters for you anyway, and that fraction is the real question: which of these patterns hit your business, your channels, your customers? Where are you exposed today, and which of it is even worth an offender's while?

Out of that I build your own threat portfolio: the threats that genuinely count for you, ranked by importance and related to your own processes. Plus the solution that fits, matched to your systems, your organisation and your budget, not taken from a catalogue.

Your variant is not listed, or you want to know how it plays out in your case? Just ask.

It is about you, from the first conversation

Of course I make a living from engagements. That is exactly why I will also tell you when you do not need one. Getting started costs nothing and commits you to nothing.

You talk

What is on your mind, where does it hurt, what have you already tried? A phone call is usually enough to begin with. If it needs more, we take more time.

I place it

Often it is possible to name what is really going on during the conversation itself. You get an honest assessment, including when I am not the right person.

You decide

Only then comes a proposal: modular, tailored to your goals and your budget. Only what is actually needed.

And that is how it stays. During an engagement too, the work follows your situation and not a standard procedure. You decide how deep we go and when we stop.

Pick a free slot →

Which of these patterns are hitting you right now?

Tell me briefly what you are seeing. Often a first conversation is enough to work out what is really going on.

Arrange an intro call