All eyes are on AI, and it’s reshaping both innovation and risk. Organizations are making significant investments in cybersecurity to get ahead of the growing wave of AI-driven fraud. As consumer-facing AI agents increasingly mediate digital interactions, long-trusted signals—like device fingerprints, keystrokes, and behavioral patterns—are losing their reliability. What once looked like a “clean” session can now be fully controlled by an agent, masking malicious intent and exposing enterprises to threats ranging from account takeover to policy abuse.
Staying ahead requires more than traditional fraud defenses or incremental tuning. Organizations must embrace approaches that can infer intent in real time, deliver explainable risk decisions, and adapt seamlessly to new attack vectors—without adding friction to the customer experience. By aligning with next-generation FRIP capabilities, leaders can ensure their investments not only defend against today’s attacks but also build resilience and digital trust for the agent era.
John Tolbert, Director of Research and Lead Analyst at KuppingerCole Analysts will share insights from the 2025 Leadership Compass on FRIP platforms. He will cover major market shifts, the growing use of AI in scams and the rising importance of governance. John will also outline which FRIP capabilities leaders should prioritize to stay prepared for the AI agent era.
David Mahdi, Chief Identity Officer at Transmit Security will focus on how enterprises can practically rethink their fraud playbooks in the era of agentic AI. He will discuss the shortcomings of traditional rule-based and bot-focused models, why predictive AI is becoming essential, and how leaders can build detection strategies that adapt continuously to evolving threats. David will also share real-world examples of how Fortune 500 organizations are adopting AI-first fraud strategies powered by Predictive AI to protect digital trust at scale.
Who must attend:
This webinar is tailored for fraud and security professionals, IT leaders and risk managers seeking to understand the impact of AI agents on fraud prevention.
Good morning, good afternoon. Welcome to our webinar today. I'm John Tolbert, Director of Cybersecurity Research here at KuppingerCole Analysts, and today I'm joined by David Mahdi, who's the Chief Identity Officer at Transmit.
Hello, David. Hello.
Hi, John. Hello, everyone. Thanks for having us today.
Well, today we're going to talk about The New Face of Cybercrime and Fraud and how AI agents are going to be rewriting digital trust and risk. So a little bit of logistics info up front. Everybody's muted centrally. There's no need to try to mute or unmute yourself. We're going to do a couple of poll questions, and we'll take a look at the results as we go, and there'll be a Q&A session at the end, and you can enter your questions in the control panel at any time.
This is sort of a fireside chat plus presentation format, so we're going to save some time at the end for a technical discussion, and then we are recording this, and both the recording and the slides will be available in just a few days. So I will start off talking about the fraud landscape, Fraud Reduction Intelligence Platform, show the results from our recent leadership compasses on what we call FRIP, Fraud Reduction Intelligence Platforms, two different editions for finance and e-commerce.
Then we'll turn it over to David to talk about agentic AI and gen AI and how it's impacting fraud and fraud prevention. Then we'll have that chat, and we'll take questions at the end. So we thought we'd start right up front with our first poll question, sort of get the pulse of what you feel about what's gen AI going to do to fraud prevention technologies. Do you think it's going to force major changes to what you already have in place? Do you think, yes, it's going to force some changes, but they might be minor?
You can say no, we think what we have already is resistant against gen AI-assisted fraud, or it's fair to say, you know, we're not really sure. We need to do some gap analysis on that. So feel free to ponder that and enter your answer when you're ready. We'll just keep going. So first up, let's look at the fraud landscape. I think it's always good to refresh the numbers, see what the current statistics are. It is a huge problem. I pulled some numbers of the NASDAQ Verifim report, $3.1 trillion in illicit fund movement.
Now that includes fraud, you know, $103.6 billion in fraud losses, but it also includes things like terrorist financing, money laundering, drug trafficking, organized crime, but you can see that it's an absolutely staggering amount, including almost $60 billion in money that's moved by money mules. We'll go through all of these, but you can certainly look at them in more detail later.
But, you know, I think it's worth calling out, too, that I think for many years, our perception of fraud is that it tends to affect elderly more than younger people, maybe because they're not as familiar with technology. But some recent studies show that people are reporting losing more money to fraud more often than older people. But of course, when an older person loses money, they tend to lose more because they probably have more in savings. So the age demographics of those who are targeted and those who are losing money has shifted considerably over the last few years.
That means everybody has to be extra vigilant. Some more numbers. 99% of organizations say that they've experienced account takeover attempts, with almost two-thirds of those being successful. Half organizations will report that they've seen account opening fraud attempts, including using fake documents. We'll get into that in a bit more detail later. But you can see investment scams are up. Fake tech support calls are up. And interestingly, on the AI side, face swapping is up over 700% in the last year.
So I thought I'd go into a little more detail on a couple of the most common types of fraud that we have to deal with. The first is ATO fraud, account takeover fraud. The idea there is to get access, at least temporarily, to existing accounts, often financial, but not limited to that by any means. Fraudsters will go after anything that can be converted into currency. So that means almost all industries are targeted. Think about loyalty programs, frequent flyer miles. Anything that somebody can then turn around and get money out of is a target of fraudsters and cybercriminals.
Account opening fraud, goal here is to create fake accounts based on real people's data. And that can be used for major financial fraud, money laundering, or trying to get people to essentially serve as mules to move money around for them. This too can be very devastating for individuals. Large amounts of money can be um attributed to them and they wind up in a great deal of debt or lose a lot of money. Synthetic fraud, another type of account opening fraud. This is to create fake accounts, you know, with plausible but not necessarily real data.
The pictures down below I created at thispersondoesnotexist.com. So you can see it's easy to make pictures of people that aren't real but look real and then fraudsters could use that to, you know, try to enroll and get accounts.
Again, this is often used for financial fraud. You know, sometimes in these cases they start small. Maybe they apply for a credit card at a store, a department store, a hardware store, and then they will make small purchases, pay them off, sort of build credibility on the credit card, and then once it gets to a sufficient size they will, you know, charge a lot of money to it and then walk away. And then again, you know, almost all industries can be targeted here and as you can see by the use of the photos, Gen AI can be a real enabler for synthetic fraud.
The fraud perpetration methods or what are the techniques that they use? Well, for ATO, phishing, vishing, smishing, you know, I think we all get hit with several messages a day that might look like smishing. It's become so prevalent trying to get access to your accounts. Brute force password guessing still works. There are compromised credentials on the dark web from data breaches.
The cyber criminals will use that information in credential stuffing attacks, hoping that, as is often the case, a lot of users reuse the same passwords between sites so they can do credential stuffing attacks and hope to get access to other accounts. They can send you to a fake website to try to harvest your credentials. And then there's always malware.
You know, if you can get access to a device in one way or another, then you get access to usernames, passwords, or other credentials. Session hijacking has become a real problem too.
You know, a lot of websites will have very long-lived cookies or tokens. These are actually also for sale in some cases and that's been used to perpetrate some pretty major attacks over the last couple of years. Lastly on this one, you know, I think it's worth pointing out malicious QR codes in public places. A real problem, particularly parking lots and places like that, just a way to try to redirect and steal credentials. So for account opening fraud, where do they get the information?
Well, you may wonder why cyber criminals have gone after, let's say, school records or healthcare records with such ferocity. It's because the stuff has information, you know, address information, name information, past addresses, social security numbers, other identifiers, and all this can be used to help build an account that looks like you. And then they can also use, you know, AI-powered image generators to create a fake image, maybe use one that looks like themselves, and then get access to your assets. For synthetic ID, again, we see a lot of use of AI, generative AI.
You know, they can use generative AI to create things like fake bank statements, fake utility bills that are often needed to demonstrate that a person's lived in a particular address for a while. The big cyber criminal operations might use mobile farms or virtual phone emulators so that they can receive calls or SMSs to verify account creation. So lots of different methods involved in the different kinds of fraud. And this is just scratching the surface with the different types of fraud that are out there. Many of you may have heard about this story from last year.
There was a British engineering firm, a case where a scammer was able to impersonate the company's CFO using video and audio and order a financial employee to, in the end, wind up transferring about $25 million to several different bank accounts. Unfortunately, it was only discovered after that employee called up headquarters and said, should I have done this? But the problem here is it's not difficult at all, and it's probably only going to get easier for fraudsters to create very realistic video and audio and then be able to insert that into, let's say, a video conference stream.
So out-of-band checks for authorization are coming back. So with that, let's talk for a few minutes about the six major detection and mitigation techniques for reducing fraud. First up is identity verification.
Here, we want to raise the identity assurance level. This is something that, of course, you do at the time of onboarding, but in many cases, you have to periodically re-verify. This helps banks with anti-money laundering regulatory compliance, know your customers, sanctions, screening.
I mean, every day, it seems like we hear about more sanctions and banks. Well, really, nobody should want to do business with a person or entity on the sanctions list. So it becomes very difficult to keep up with that, and fortunately, there are third-party services that can help with this if it's not built into your fraud reduction solution. Then we have credential intelligence. This is more or less asking the question, has this user ID been used somewhere else recently for fraud?
It sure would be great to know about that and pass that information, let's say, amongst the customers of a particular service, if not more widely in industry. You can also get a lot of useful risk information out of devices. Devices have identifiers.
Of course, they all have IP addresses. You can look at device and IP reputation. There are curated sources for that. You can look at the characteristics of the device itself, what operating system, what patch level. Does it have some sort of anti-malware installed, or can you find signs of a malware infection? User behavioral analysis. This is looking at, let's say, where transactions originate, location-wise, network-wise. History of transactions. This is incredibly valuable.
You can build a profile, figure out whether or not what the current context of the transaction is would be something that you would expect the user to do. Is it a similar purchase that's been made before? Is it coming from a similar location? Is this very, very different from anything else the user's tried to transact in the past?
If so, you might want to raise the risk flag. We also have behavioral biometrics. This is how we interact with our devices. If you're typing on a computer, how you use your mouse, or if you're using a phone, how you hold the phone, how do you press on the screen, gyroscope. All this information can be used to build a very good profile of individual users and how they interact. So much so that really good behavioral biometrics can actually distinguish between two different users on the same device. That also plays into bot detection.
It's very important to have bot detection and bot management because so much of the traffic online is driven by bots. Not all bots are bad.
I mean, we hear the word bot, we think they're bad, but a lot of business on the web actually occurs through bots. But of course, there are bots that you wouldn't want your site to interact with. They could be credential stuffing bots, inventory hoarding bots. We'll talk about that a bit more in a few minutes, but you need to be able to provide choices to customers and figure out, okay, if this is a good bot, I may want to allow it to go ahead and do something, or I may want to challenge it, I may want to throttle it, or I might just want to block it altogether.
That's what bot management allows you to do. So let's talk now about the leadership compasses that we recently published. These are our comparative reports. I recently did one on finance and e-commerce. I'll describe the differences. Previously, I had done just one report, you know, combining everything, but I see that the fields are diverging sufficiently that it's certainly worth breaking into at least two different reports. The use cases can be very different.
So for finance, obviously, I focused on use cases that involve banks, credit unions, credit card issuers, fintechs, savings and investment houses, things like that. The differences here are a real emphasis on AML KYC and that name and watchlist screening as part of identity verification, and having identity verification built in is certainly advantageous if you're a bank and you're going out to look for a new fraud prevention provider. But they also need to be able to detect things like card not present, fraud, authorized push payment fraud, buy now, pay later.
They need to be able to detect mule accounts and scams. Scams have just, you know, been a big issue in the last couple of years, and being able to alert the bank and the user about a scam in progress and stop it is extremely valuable. With e-commerce, here we're focusing on what is it that online merchants or service providers or media outlets need, and it turns out can be somewhat different.
Of course, they need to be able to detect credit card fraud, but policy abuse is something else that they're concerned about more so than banks. There might be abuse of like guest checkout policies or return policies or discount and loyalty programs. It also needs more sophisticated bot management because there are lots of different kinds of bot attacks that happen against, let's say, an online retailer. Inventory checking, inventory hoarding, account creation, ticket scalping.
You know, this is just a tiny subset of all the different kinds of bot-generated fraud that online businesses face every day. So, these are the technical evaluation criteria I used. There's some overlap between the two, but identity verification, very important for finance, still important for e-commerce, but maybe a bit less so.
Credential intelligence, user behavioral analysis, device intelligence, behavioral biometrics, bot detection, name watch list screening, and then the last one is interpretation of how I see the analyst, the fraud analyst, user interface, the policy builder, and the dashboards. And how that differs on e-commerce, here I'm focusing a little bit more on bot detection management and the policy abuse detection.
So, let's take a look at the results briefly. So, for e-commerce, you'll see we have a pretty good range of distribution where all the different vendor products fall. You see Transmit Security, who's with us today, definitely a leader in e-commerce. Fraud prevention. And then on the finance side, a somewhat different set of companies in many cases. Some companies specialize in e-commerce fraud prevention, others specialize in financial fraud prevention, and there are some that address both sets of use cases very well.
And you see Transmit here, again, and the overall leader for Fripp for Finance. So, with that, I would like to remind you to submit your questions. And just before I turn it over to David, let's take a look at the results for the first poll. More than half say, yes, major changes will be needed. I think that's very realistic.
So, David, over to you. Excellent.
Thank you, John. Thanks for going over that, and thanks to the audience as well for doing that poll. We do have one more coming up shortly.
Yeah, all right. Let's dig in.
So, I think I'm going to cover, I'm going to continue the conversation that John started. Obviously, the theme being around online fraud detection, prevention, you name it. But really, when you think about it, it's like these identity-based threats, because we know that over 80% of all attacks nowadays, whether you look at CrowdStrike, Verizon Data Breach Report, research coming from Krupp and Jekyll, and many others, we know that they're going after identity, and we're going to unpack that.
But first, we're going to start with the obvious, and that is we all know that AI adoption has accelerated tremendously. Having been a veteran in this space for over 20 years in cybersecurity and identity, and background of being a hacker and tinkerer, for that, I've never seen any technology move this fast personally, as well as when I put on my previous analyst hat.
What we're trying to show here is really how we've crossed the chasm, and we've got press releases that were shown here from Visa, MasterCard, PayPal, talking about agentic AI, and this notion of know-your-customer really now combining as a hybrid, as know-your-agent, because David will have an agent. And then we also see in the top right that the AI browser war has begun. And in fact, yesterday, OpenAI released their Atlas browser. And so effectively, it's a Chromium-based browser, but your experience now is the LLM itself, chat GPT, is built into the browser itself, right?
We've got Sam Altman on the bottom talking about fraud with AI, but first on the AI browser, when you think about OpenAI, they would want to own that full client digital experience, and so now you can have that. And one of the things I'm going to state here is that what Apple did for biometrics with Touch ID, they brought that to the masses.
Today, we know that many of us that are in technology, we can go into chat GPT or Perplexity or Gemini and we can build agents, right? But that's something that you actually have to do. You have to look into it. It's not difficult, and you can actually get the LLM to help you, but the agent tech now is built into the browser. I downloaded Atlas yesterday and I had it very quickly, within 10 minutes of me downloading it. I had it finding flights for me because I have to book a trip in a couple of weeks.
It found flights, found good prices, found the times, and it also was able to tell me what connections I should take based on probability of delay, cancellations, and also even upgradeability as well. So the point is that these AI browsers are going to bring agentic technology to the masses. And one thing I do not want the audience to forget as we move ahead here with the content is simply that it is going to change what user behavior looks like. It's going to change how we deal with fraud detection online. Everyone's going to look like a bot. Everyone's behavior is going to be very different.
I sat there and watched the agent go through the airline's website for me. That's not me as a human.
So John, let's go to the next slide and start unpacking this. So I kind of alluded to this. We've got the standard browser and what we see here on the right side is the AI browser. Effectively, it's your LLM built in with agentic technology. It will ask you, you know, hey, would you like me to go into agent mode and go and maybe find these flights? And also you can say do it in a log out state or log in state, right? And that's just 1.0 of these AI browsers. So effectively, it can get the answers for you. It can get the information for you, but it can take actions and personalize the results.
When we look at that compared to what we've been used to with the standard browser, very different. You open it up. We have a search bar. You search. You have to go through the results. You have to go in through it.
Sure, you could have written scripts in the past, you know, Python scripts or anything to kind of go through websites and rip through things. But today, like I said, these browsers are going to bring agentic technology to the masses, and we're only in the first phase. I was at the Fido Authenticate event last week, talked to a lot of e-commerce providers, financial institutions, and other retailers, and all of us agreed that the consumer digital experience is going to change. And if you don't believe me on AI browsers, it doesn't really matter if you do or not.
Google's rapidly embedding Gemini into Chrome, Edge with Copilot, now with Atlas being released in the wild, and this is day two to the public, and we have a comment as well from Perplexity. So the AI browser wars have begun, and all of your users are going to start to change their behavior. Go to the next slide, John. So we know that the perfect storm is here, right? So some of the things that John was talking about from fraud stats to deep fakes and so on, on the left side what you see here is generative AI.
So we know that for the past couple years, attackers have ramped up and amplified their capabilities with Gen AI. Specifically, what we see, and it's hard to say, oh, did they use Gen AI? But it's very likely they have. They can use tools like EvilGPT, WormGPT, and so on to help them with reconnaissance, right? Help me target this organization, you know, let me know what top employees that work there, who's in their IT group, do they have any compromised humans, machines, and so forth. So they can use it for mining, they can use it for their attack planning and campaign planning, right?
They can also use it for phishing, right? I think Icelandic banks didn't used to suffer phishing attacks because Icelandic, there's not many people who speak and read Icelandic, but now with these tools, they're able to craft phishing campaigns in any language and they can spin it up very quickly. So what we've seen there is increase of volume, velocity, meaning they can do these campaigns faster, and variety, so they can switch them out much, much quicker. But John covered the notion of deep fakes and so on, synthetic IDs, and that's amping up tremendously.
So we have that on one side, and that has been really attacking, you know, the human world, if you will, right? KYC, right? It's breaking KYC in some ways, but I think some of our legacy tech can handle some of it, but we have to do that, but there's still some major gaps there. But that is just only going to be amplified on the right-hand side here with agentic AI. Now with your users, absolutely going to be empowered with AI browsers, is it them or is it their agent that's coming to your site? Is it a good agent or a bad agent? Did someone compromise John or David's agent?
Those are all the questions you're going to have to ask, and if you don't, I think it's going to become very clear that this next era of the digital experience, which is AI interacting with your digital services and digital channels, if you don't, you are going to be at a disadvantage. So we've got to get ahead of this quite rapidly, and what you see below is we've got a white paper that we'll have a QR code at the end, which talks about 50% of the consumers are starting to become very comfortable with this and that's increasing rapidly.
Again, Atlas came out yesterday. We're seeing that 2000% growth in this traffic shift coming from Gen AI itself, so people might ask the LLM and it might give them links. Now it's embedded in the browser, that's just going to be even greater, and each AI agent session can be weaponized instantly. We'll cover that slightly, so if we can go to the next slide John.
All right, so what we're going to do here is we're going to take a look at the current situation that we have, and really in this kind of four panes, I'm going to start in the top left. Device fingerprinting, something that we still should leverage, but is much more applicable to the old world and slightly current world of what we're looking at, right? So that's like understanding your users through the devices they use.
Okay, that's great. What happens if they're using a agent now? Where is that agent? Is it on their device or is it coming from the cloud, right? So they're going to be these workloads, right? These ephemeral agents that are going to have different device IDs every time, right? So the sessions are going to reset, memory is going to be lost, all these blacklists that we might have are going to start to fail, because they're going to just go super, super fast, and then the risk of sharing agent traffic is going to start to cluster.
So all these things might look the same, and or they might look totally different. So we're effectively, we're calling out the fact that it's going to be blind, device fingerprinting is going to be blind to many of these agents, we're going to take a different approach there. Now we go to the right hand side on the top, behavioral biometrics certainly are going to become ineffective. The entire industry of behavioral biometrics, right? And John knows, you know, my previous background of being an analyst, right?
I had a front row seat to all the tech and the practitioners and investors in the space, amazing technology to understand the behavior of a user, because that's how a lot of the ransomware attacks when I interviewed lots of clients, they caught it. But when behavior changes, and now we have agent functionality coming in, it really starts to change things.
So again, you can see in the bullets here loss of human cues, bots, faking randomness, we'll get more on bots in a moment. And some of the other rules really just having to because, again, if it's not David on that, that that airline website, and it's an agent doing it, what is that going to look like? How are they going to score me? How are they going to change my user behavior? It's not me anymore, they're going to have to have a separate profile as my legitimate agent.
Now, if we go to the bottom left hand side, we got bot detection, the industry has absolutely leveraged bot detection. But now this is going to be a double edged sword in the sense that what everything is going to start to look like a bot. And when everything starts to look like a bot, absolutely 100% bot detection is going to have some problems. So we're saying it's going to start to have an identity crisis, right? In that good bots are going to start to get blocked, right? Bad bots are going to start to look human. And it actually, you know, I can't demo it today.
But I've played around with making bad bots. And it's not that difficult to bad agents, right? Or if you compromise my agent platform, whether it's through my browser, and you're acting like me, how do you decipher whether it's David legitimately behind that agent, or it's a bad actor, changing his behavior slightly over time. So we've got a lot of all these things that are going to change. And then the last one on the bottom right hand side is anomaly and the anomaly detection and rule based systems are going to start to fail, right?
Because things like velocity checks, agent masks, right, again, all of these bleed into each other. But frankly, the new fraud vectors, it's the fact that the volume and the velocity is going to be ramped up quite dramatically. So we can go to the next slide. That's a great segue. It's going to be fraud at machine speed, which it means going to be lightning fast, it's going to be relentless. The economy of scale for the attackers, the cost for them to attack you is already today, it's extremely cheap. So for them, they can fail fast, adapt, and they can move on and they can do it quite rapidly.
Orchestrating between accounts and channels, it's going to become much easier than it is today. And it already isn't difficult for them. Scalable abuse. This is the thing when we talk to a lot of practitioners, whether they're in telcos or other industries, they say that's the biggest thing they've seen. The biggest game changer is they can scale the attacks at a much greater rate, which it's a numbers game for them. And so that means that they can go after these. And John mentioned some of these other areas and why he has two research notes focused on FRIP.
We think about promotions and loyalty as well. There's a lot of fraud going on there. Synthetic identity farming, that's going to ramp up absolutely. And then these invisible patterns, blending fraudulent and legitimate actions seamlessly.
And again, the dynamic of human and agent is going to complicate how we deal with fraud prevention in this new world. So we absolutely need to review how we tackle these things because they're going to change.
So John, let's go to the next one. So this is where we're going to fade. We're not going to say, hey, let's just focus on panicking here. We're going to start to talk about how we need to get into the notion of there's gen AI, but we need to get into predictive AI as a way to take some of the models that we understand today, but move to a point where we can extrapolate and understand the intent of the user. And the way to think of it is when John logs in, he typically has five pathways and we can assign probabilities to those.
We're going to talk about that in a moment, but John, if we can go to the next slide. I'm going to hit you with another poll.
And again, we'll give you some time and we'll go over these towards the next section here. So what impact do you believe AI browsers will have on consumer behavior and fraud in your business? We talked about those up front.
One, AI browsers will significantly change how customers interact and alter fraud patterns. Two, medium AI browsers will have moderate influence on customer interactions and fraud.
Three, low AI browsers will have minimal effect. Or four, no effect.
Or five, unknown. So we can go ahead and give you folks some time to answer that as we press ahead. So reflect on that. And if you're new to AI browsers, that's totally fine. That's a part of the point we're trying to make here today. But if you're not, yeah, absolutely go ahead and download Atlas if you can. Take a look at it because that's a glimpse of what we're going to be dealing with. So everyone says when they do AI, you know, there's multiple things, right? Multiple areas.
But what we're going to really focus on here is this notion of predictive AI, where it's like anomaly detection, you know, rule-fed machine learning, reactive, static models, high false positives. This is the old world of what we're doing with fraud. And predictive AI is aiming on these bullets to try to mitigate them, right? To turn the dial back so we can deal with false positives. We can deal with these models and we can get out of the notion of being reactive because you can imagine fraud at machine speed.
If we were reactive to it, it's going to be very difficult to have human analysts try to react to everything and create a thousand cases every five minutes. That's just not scalable, not possible. I think we know that today. So let's move to the next slide, John. So in this session, we've got our white papers toward the end, which kind of define predictive AI more in detail, talk about all of those. So at the end of the webinar, if you want to go more into this, absolutely, just take a look at those and we can always talk about doing follow-ups.
But these panes here just kind of show, or panels, I should say, show why it's the future, right? So we're evolving the technology as Gen AI evolves.
Gen AI is, think of it as a core engine that we can use to analyze the data and go from there. But the idea is when we go to the next pane that's on the top, right, it's focused on predicting outcomes and intent. So when we think about when David logs in, typically he has five or six pathways. What's the probability of each one? What's his typical intent, right? We can do that from a human perspective. But now if we identify his agent that could move at lightning speed, machine speed, we can do the same thing for his agent. Once we identify the agent, we can then have those predictions.
Now, if it goes off into a new area, we can say that's entirely new. Maybe we need to do something to elevate trust, which is where we can orchestrate in maybe a passkey that he might use as a human, or get the human to review the transaction, or have the agent do something in and of itself to prove its intent and its authenticity, and so on and so forth, right? So the idea, though, as there's these flows, we're learning through feedback on large data sets, right?
So it's feeding back in, and it's learning more and more about David, his agent, those interactions between the two, and moving in where we're leveraging the data to make those predictions. So what that does now, if we go to the second row, is that it doesn't rely on these rules, right, which we know the attackers now can very easily, let's say grok, if you will, pun intended, where they can actually understand what those rules are just through brute force of finding it. We see this with things like Scattered Spider, when they do reconnaissance, they learn your call scripts.
In the same way, they just almost like penetration test your environments, and they can come back and have a pretty good idea of what your rules are. So they attack your rules. So that's why we don't, we cannot be totally reliant on these rules anymore because of this, and because of agents, really. We can't assume that a human is behind the transaction anymore. And we can't just assume because the human is not behind it, that it's illegitimate.
That's, again, the case, especially with AI browsers, that there will be absolutely a ton of legitimate bots out there now, and we can't block them, right. And the idea is now that we're learning when you look at the next one, is that it's going to get better over time and not worse. And that's something that you think you've got to spend countless hours training and remodeling as a new threat comes out. The idea is that as those patterns change, the system with predictive AI is changing along with it.
Less false positives, less resources required, really outcomes we're going for here, and try to be future-proof, as we said, because we're constantly learning. If there's new tools, tactics, and procedures that attackers are using, the idea is that you're monitoring these things and you're predicting. And even though we may not know the true nature of it, we can see that this is not what David normally does. So we're going to go back and do some kind of verification on him, and go back to those principles John talked about.
All right, move to the next one. I'll just speed up here a little bit, because I definitely want to get into the fireside chat. So I'll wrap up here, John. You go to the next slide.
So, and then there's a notion of pre- and post-detection, right. So I'll hit this one pretty quickly. So when we think about the notion of real-time detection, right, go through a catalog of the network, the account changes, authentication events, all of this kind of telemetry we can get through all these events, right, feeding that in to even what we see with post-detection on the specific user and or an aggregate across the user base, and even pulling in some other kind of consortium data and so on and so forth.
Having the two flow together to reinforce each other, again, it puts us in a better position to be able to deal with rapid fraud campaigns that will change at machine speed, and that's really what we're trying to go here. So again, blending the two worlds of pre and post, not doing total reliance on pre or total reliance on post, combining the two together to make it much, much more powerful going forward.
All right, let's go to the next one. All right, so when we take a few steps back now, I mentioned at the start of my session that everything's about identity now, right, and I think the market finally, and it's something, you know, I've been saying for decades now that identity is where it has to start. If we don't know who and what it is, how do we know how to protect it? How do we know if we should let it in? Everything should start with identity, right? Identity for security is the whole point.
So when we look on the right-hand side, it really, we have to consider any actor now, a human, an agent, a bot, right? They could be good, they could be bad. We got to look for all those. And when we go through all of those, these are really the outcomes we want to achieve. And what we see from a transmit security perspective happening in the market is this very rough Venn diagram of you've got fraud prevention or FRIP right at the top, and it's overlapping with identity verification. John had that in the success criteria of what Kubernetico looks for in these platforms.
And we also see customer identity coming in as well, because you don't have the lens of identity. How do you have the telemetry to truly be able to block them, understand their intent? So these worlds are rapidly coming together. And what we see is identity orchestration is the glue that's pulling them all together, because it allows you to stitch those channels together. And we see this on the left-hand side across from Kubernetico and many others.
These are the core capabilities that you need to start to look for when you're running a customer identity security program, it should start to include fraud, right? I could go off in a whole other range here, but let's go off to the next slide. And we're going to get into the Farsight chat in a moment here. And so this is exactly what we've done at transmit security.
We've been seeing this convergence or fusion, if you will, of these areas, since the inception of the company where transmit started with orchestration, and built up the capabilities in this Venn diagram, because it's just like, there's no way to prevent any of this fraud without linking, stitching these things together. So let's go to the next one, John. So the last poll question was, what impact do you believe AI browsers will have on consumer behavior and fraud in your business? And very interestingly, people are still voting. I'd say roughly 50% say it's going to have a significant impact.
25% say a medium impact. No one believes that it will have no impact or only a small amount of an impact. So these are probably very realistic answers.
Yeah, yeah, I like that. And folks, I think, you know, we're still all learning here together. But I think I'm very happy to hear that, because I've had a lot of conversations around this, and a lot of people have been surprised.
And again, in all fairness, it's moving very quickly. But I think we can kind of see the leaves here very clearly. If you look at the trajectory of just open AI itself, and we use that as a loose model now with it being in the browsers, it's just going to be in front of all of us. And it's undeniable.
But yeah, let's get into this. So John, I'll kick these questions off to you. And we can kind of kick off the chat. And we can go from there.
So John, how will cyber resilience influence FRIP projects going forward? I guess the first question you have to think about, let's say you're a bank, you know, and you're using an external FRIP service, what happens when it goes down? Do you fail open, fail closed? Who makes that decision?
You know, I think you have to believe that your third party intelligence services are very important decisioning mechanisms. So maybe you start thinking about how do you build resilience into that?
You know, if you think of a FRIP platform as one that, you know, provides a lot of basic capabilities on its own, but then also receives information from let's say, IP, IP and device reputation, information with what if those constituents goes down? Should you have backup services? Should you have multiple services that you know, can handle each of the different components of FRIP? And then I guess you could think about if let's say your API to your FRIP service provider for whatever reason goes down, maybe there's a cloud service outage or something like that.
Is there any way you can sort of fall back to using cached information like device reputation? Are you keeping a copy of that locally? Do you have your own credential intelligence that you can use?
And again, thinking about cloud service outages, maybe you should think about using multiple regions or a FRIP service provider that really is multi-cloud and can demonstrate that and think about that at RFP time when you're trying to pick a FRIP service provider. Are they multi-cloud? Do they have some sort of active, active failover capability? And can they show that to you so that you can be assured that in the event of some sort of outage, you will be less effective at the very least? What do you think?
Yeah, yeah, John, I think those are all good points, especially in light of what happened to AWS this past week and CrowdStrike last year and even some of the breaches that, you know, gave had, you know, Okta had some downtime. We've started to see clients in North America ask about cyber resilience. And then certainly in Europe with the EU Dora, which was passed in January, I think now is starting to put teeth behind these outages. And the more we depend on these digital services, the more we're going to just simply because there's a rush to the cloud, which brings so many benefits.
But it also introduces problems that, you know, we were not fully used to or aware of. And so I think when it comes to authentication and fraud and FRIP platforms, you said it from the outright, I mean, you know, you can't feel open. And what EU Dora is kind of saying is you can't feel closed either. So you got to have other pathways to ensure business continuity.
I think from a, from a transfer security perspective, we see it as being active, active, being able to operate in multiple clouds, because again, knock on wood, but the likelihood of, you know, all three major cloud providers going down at the same time, is it a zero probability? No. Right? Is it a high probability? No. Right. So but is it something that could mitigate downtime for you? For sure. If you can go active, active. But let's pop over to maybe the next ones. I know we want to be able to take some questions from the audience. I did see a good one in the chat.
So we'll get through some of these ones. So John, what impact will cyber and identity threats have on fraud and FRIP? And what are the implications for FRIP offerings?
Oh, well, let's focus on what we've already addressed. I mean, obviously, fraudsters have been using Gen AI for better phishing text, you know, generating those images, being able to infer information about individuals so that you can create other realistic information to go sign up for an account, those, you know, fake utility bills and bank statements I mentioned.
But, you know, I think going forward, you know, particularly thinking about the use of AI, you will have things like automated transaction execution, man in the prompt attacks, credential harvesting overlays. I mean, we've already seen this. It's really, I think it's going to have a pretty significant, it's a force multiplier for the cyber criminals.
But, you know, there's also opportunities that it'll present for fraud reduction, Intel platform vendors who can be able to detect these new kinds of attacks and these, you know, high scale attacks to that may be completely different from what we've seen before. Yeah, John, I think that's, yeah, I agree. And I think when you look at the capabilities of what you evaluated with the Fripp platforms, right, you had identity verification is kind of the first one, right, bringing that identity context into it.
And then the Venn diagram that I, you know, followed up the transmit section with, you know, just kind of showing that these areas are starting to come together. And when you link that back to the predictive AI, it all needs that data pre and post, right, of the user and users to understand better context of what's going on, the intent, right? So if you're blind to identity, which I'll just make a, just a general comment.
I mean, when you look at the, in the workforce, the endpoint detection platforms, they've been blind on identity forever, which is why we see your CrowdStrike, Sophos the other day talked about their new ITDR service, right? So we see them going, oh, wait a minute, if 80% of the breaches are identity related across workforce, customer and partner identities, we've got to kind of like start to pull that context in. So I think, you know, I think we're going to start to see that happen more and more.
All right, let's move to the next one. So again, I want to give us time to kind of get to the audience questions. So I think we have one more fireside chat question. What are the key Gen-AI trends shaping fraud and FRIP, John, in 2026? So I guess this is saying like, get to your crystal ball of what you see, is Gen-AI going to change what you're going to be looking for when you go through the next research cycle with FRIP?
Well, I guess we'll start with the negative first. I think we will, we're already seeing that scams are outpacing ATOs. So ATO is something that we've been talking about for quite a few years. It's been a concern, but now scams with the possibility of losing huge amounts of money are definitely something that should be top of mind, particularly for those in any area of the finance industry. Smishing attacks are just off the charts, authorized push payments.
You know, this is particularly sinister because for a fraud reduction intel platform, how do you, you know, infer the intent of the individual? Because you have an authorized push payment, you know, maybe you get a mobile app, you get a pop-up, do you want to authorize this payment?
Well, if that individual has been scammed or persuaded to do something that they shouldn't do, there are some technical capabilities that can help alert the bank, which then can help alert the customer slash almost victim. I think those kinds of technologies really have to come to the fore to be able to help stop scams and authorize push payments. On the positive side, I think there are lots of good things that Gen AI can help with, with regard to fraud prevention.
I mean, we've been using machine learning-based detection models for many, many years, and that is really the only way to determine fraud at scale. But as you've said, David, that's going to get a lot harder. So I think there needs to be more emphasis on refining ML-based detection models. But Gen AI, you know, is already in some cases, not all vendors do this yet, but some do use it for helping to create executive-level reports, take raw information, put it into a form that's, you know, easily consumable.
And then, you know, the fraud analyst workbenches, having the ability to do natural language queries directly from the mid-level fraud analysts, being able to simply ask questions about, you know, tell me about this IP address, or does this transaction look legitimate? Show me the signs that it may look illegitimate. And that will hopefully save a lot of time and prevent fraud.
Yeah, I think I'll just make a quick comment on this before we transition over to kind of the Q&A. But yeah, once again, I agree with you, John, there.
I mean, I think if I were to just look at Transmit and other providers in the industry, I mean, I think that one of the first areas was looking at how we could use this to give a step function increase to the fraud analysts that are using these platforms, right? Help them go through the, find the needle in the haystack much quicker. And some feedback that we got from the market too, is that a lot of folks were like, you know, other players in the space were focusing a lot on pre, which is good. We're trying to mitigate as much as possible, but at the expense of not doing a lot of post.
And so that was one of the reasons why we showed that pre and post slide to say that like, you know, post detection is really important to see that, you know, because stuff will get through. That's inevitable. We know that, right? And if it gets through, we can use these tools to help us, again, pun intended, grok the results. And then that other step change would be like, you know, being able to pull something out to bring it to a business leader to say, Hey, you know, we need to tackle this.
So, so yeah, actually, I forgot there's one more question and let's hit this one quick and John, I'll just let you answer this one. And then let's, let's, let's kind of get to wrap up. So Fripp capabilities, what should they be looking for 2026 and beyond? I would say tighter integration with your CIM signals flow in both directions, better deep fake protection, which is going to require a far more sophisticated identity verification. I think we need to start planning for how do you add a human in the loop authorization for high value transactions and suspicious transactions.
And then we really, really need to figure out how to discern human from AI agents, and then figure out what the authorization scheme is to deal with that. Any thoughts on your side? Yeah.
I mean, I, I think it was definitely a question more for you and say, you know, as lead analysts in this space, right, what you're looking for there. So I think that's, that's, that's really good.
Let, let me just hit this quick and then let's get into some of the, the, the takeaways we want to leave the audience with, but we'll tackle the questions. So John, I'll, I'll just take this rapidly. So I think what we're seeing for the general recommendations, we wrap all this up is organization plan for your agentic AI roadmap. I'm sure many of you have that, but I think what we're going to recommend here is that, you know, AI agents coming via the AI browser, that's going to be, you know, maybe the Trojan horse to get AI agents into the market.
And I think, you know, organizations that aren't, you know, going to make their websites ready, their fraud systems or identity security systems ready, I think are, are, you know, they're going to have to get prepared. Identify your defense gaps today. So we've got some white papers, which will help you with that as well as leveraging Coup and Dracul's research on that. And then develop an AI strategy. I think we are recommending predictive AI.
You know, we look at stuff as fraud experts. We see that that's the best way to go pulling in all those signals pre and post to be able to give you those kind of predictive pathways and then end-to-end visibility, right? Having that single view of the user of the agent of both of them. So you can, you can adapt and leveraging orchestration as the glue and operationalizing continuous learning as we go forward.
All right, let's go. I think John, we've got a couple takeaways here for the audience. Let's go. Let's do the takeaways here.
So yeah, you take this one and I'll, I'll, I'll take the next one. Well, let's, let's take the questions that we've got here. There's quite a few questions. I don't think we'll have time to get through all of them, but let's look at the first one. With the rising AI generated fraud events, it becomes natural need to use agentic AI and AI to identify and prevent AI frauds. Is there any platform already matured in the market which can work as agentic AI to manage AI fraud? So I think there are a number of different platforms.
I guess my suggestion would be take a look at the research that we've recently published, and we will be integrating in more specific research on AI agents and other NHIs and how identity systems should handle them. Let's see, we've got maybe time for one more. Do you have anything else to add, David?
No, I mean, I, I, I think that's, that's accurate. It's still moving quite rapidly. And I think you just want to be mindful of the providers that are leaning too heavily on when they say gen AI, what do they actually mean? Because I think there's still that definition soup and conflict. Not everyone means the same thing. So I think unfortunately, we're just going to have to, you know, probably have those discussions and look at your core capabilities that you need.
So again, the recommendations that we highlight, go through, go through that in your environments, and then kind of start to map that towards what some of these providers are offering. And certainly what we have here up on the screen, and John, thanks for putting that up, you know, transmit, we can go through that with you folks as well. So you can kind of click here as like a little kind of engagement session we can have to discuss about that in particular across identity and fraud.
But yeah, John, I see a lot of really good questions. So let's try and at least nail one or two if we can.
Yeah, we've got one minute. So let's do the next one. What do internal audit risk control departments need to adjust to help ensure predictive models are working appropriately? What do these areas need to change in order to help a business deter AI fraudulent actions? Do you want to take that and wrap up on it?
Yeah, I mean, I think the first thing is, is if you if you, we've got to be able to like detect and discover, right. So we have to be able to first handle these agents coming to our digital services, right. And if we can't determine if we can't decipher between like a human and the agent, right, because some of the cases might look very similar. And some of the and there might be, you know, you can go in with these browsers and actually stop the agent as it's going through, say, click on a website for you, because you can you can actually click manual takeover, right.
So what happens if the agent did partway through and whatever. So I guess my point here being, we've got to be able to detect them got to be able to understand it across the life cycle. And then from there, you can then have your determination based on your risk, your login, we have to do X, Y, Z, if they're going to trend, if they're not in a logged in state, and they're going to transfer x sum of money or greater, we have to do some kind of step up, right. So having the flows between between the two. So it's a standard exercise to just do like, a snapshot of where you're at today.
And then doing a gap analysis, anticipating the agentic actors coming in across the life cycle, what implications or ramifications that has to your people process and technology. Again, it's very, very apt, John, that we've got this QR code here, because that's something that, you know, if there's if there's specific actions, that's something that I think, well, that's what we're doing with transmit today, we're engaging with a lot of clients, and at least, you know, offering a North Star of where to point stuff to leaving flexibility for just we know that this space is rapidly changing. Okay.
Well, thanks, everybody, for joining us for taking the poll questions and hope you enjoyed the session. And thank you to David and transmit for being here as well today also. Thank you.
Okay, have a good rest of your day.
See All Locations
See All Locations