One scam, a hundred targets
A scam used to be tried out on one company and then laboriously transferred to the next. Today it runs against hundreds at the same time, evaluates the responses and adjusts itself.
Fraud map
Know only one part of it and you defend only one part. Once you have the whole picture in front of you, you can decide where effort pays off and which gap you leave open on purpose. This map is that picture.
Not because new kinds of fraud necessarily appear, but because fraud pays off far more readily than it used to.
Fraud has always been a calculation: effort per attempt against expected return. When an attack only paid off for large amounts, small targets were left alone. That calculation no longer exists. Once the next attempt costs almost nothing, every target and every amount is worth it. What shifts along with it:
A scam used to be tried out on one company and then laboriously transferred to the next. Today it runs against hundreds at the same time, evaluates the responses and adjusts itself.
Scouting, testing, creating identities, opening accounts: what used to run over weeks and leave traces along the way now happens in a single pass. The opportunities to step in are closing.
Tools are sold, with support and a success guarantee. Anyone who wants to attack needs neither technical skill nor language skills nor a network, only money. The number of possible offenders has grown many times over.
Clumsy language was only the most obvious one. A familiar voice, a known face in a video call, a professional appearance, a proper ID document: none of it is proof any more.
Controls that rely on a human finding something plausible are losing their value. Controls that rely on behaviour, on linking across channels and on hard rules are gaining.
When everything is attacked at once, securing one spot particularly well helps little. What counts is knowing the whole field and knowing which gap you leave open deliberately.
Every case of fraud is preceded by preparation, often weeks or months earlier and with a clear division of labour. The damage is the end of a chain, not its beginning.
Every one of these fields is an opportunity to step in. Look only at the damage and you have let all of them pass. That is precisely why looking at the whole beats looking at the single case: how I go about it →
Ordered by who attacks and how the damage arises, not by the channel it comes in through. That is the distinction that matters: the same scam turns up in the web shop, in the app and in the store. Defence therefore has to start at the scam, not at the channel.
The colour of a card says which discipline is responsible: violet for fraud prevention, green for payments, burgundy for anti-financial crime. Navy carries whatever sits across all of them.
Two things sit across this order and cannot be filed under it: the question of what happens to the proceeds, and organised gangs that work several categories at once.
Not as a neighbouring topic, but as part of the same event. Fraud produces money that has to go somewhere, and that is exactly where the fraud team's remit ends in most companies.
Both areas see the same accounts, the same payments and often the same people, only at different points in time and out of different systems. Fail to bring those views together and you check the same anomaly twice and still miss it: the fraud team sees one suspicious payment, anti-money-laundering sees an unremarkable amount. Only together does the pattern appear.
That is why money laundering is not tucked into a chapter at the edge here, but sits in the middle of the map. Look only at fraud and you see half the picture.
Where exactly the line between fraud and money laundering runs is of no interest to offenders. Inside companies it is usually a departmental boundary. Closing that gap is the job of anti-financial crime.
The same order, a different weighting: what hurts most in a marketplace business is irrelevant for an insurer, and the other way round. Every business model has its own fraud profile.
On top of that come cross-cutting topics that belong to no single industry: dispute handling as the bridge between payment and refund, the fraud profile of alternative payment methods from BNPL to account-to-account, omnichannel fraud at the seams between channels, and loss prevention as a discipline in its own right.
This map was not designed at a desk. It grew out of reality: out of cases that actually crossed the table, out of patterns that only became visible the second or third time round, and out of conversations with people who see the same things every day.
And it stays up to date. Every new scam, every case, every talk where someone in the audience adds something writes another piece of it. It will never be finished, and that is not a shortcoming but the point: an overview of something that keeps changing must not stand still itself. What is here is today's state, not next year's.
In practice that means: we do not have to start from zero. For most cases the framework already exists. What remains is the work on your specific situation.
Behind every category lie worked-out profiles, variants and cases, and behind every industry its own picture of the threats. You do not have to get your head around all of it. That is what I am here for: I take you through the parts that actually affect you and leave the rest alone.
Because only a fraction of it matters for you anyway, and that fraction is the real question: which of these patterns hit your business, your channels, your customers? Where are you exposed today, and which of it is even worth an offender's while?
Out of that I build your own threat portfolio: the threats that genuinely count for you, ranked by importance and related to your own processes. Plus the solution that fits, matched to your systems, your organisation and your budget, not taken from a catalogue.
Your variant is not listed, or you want to know how it plays out in your case? Just ask.
Of course I make a living from engagements. That is exactly why I will also tell you when you do not need one. Getting started costs nothing and commits you to nothing.
What is on your mind, where does it hurt, what have you already tried? A phone call is usually enough to begin with. If it needs more, we take more time.
Often it is possible to name what is really going on during the conversation itself. You get an honest assessment, including when I am not the right person.
Only then comes a proposal: modular, tailored to your goals and your budget. Only what is actually needed.
And that is how it stays. During an engagement too, the work follows your situation and not a standard procedure. You decide how deep we go and when we stop.
Tell me briefly what you are seeing. Often a first conversation is enough to work out what is really going on.
Arrange an intro call