Fraud Strategy
The Dumbest Control in the Room
Fraud controls are built to answer one question: is this really you? In a scam, it really is your customer, willingly wiring his savings to a crook. When authentication works perfectly and still fails, what saves him is the dumbest control in the room, one that watches the money, not the story.
Most of fraud fighting is spotting the stranger who put on your customer's coat.
Someone steals a card, or takes over an account, and the whole job is telling the impostor from the real person. That turns out to be a solvable problem, because the real customer is quietly on your side. He logs in from the same phone he always uses. He types the way he always types. When you send him a one-time code, he's the one holding the number. The fraudster has to fake all of that, and faking it is hard. So you can build controls that are precise, a scalpel rather than a club, because the honest customer keeps handing you evidence that he's honest.
Scams break that arrangement completely.
In a scam, nobody stole anything. The customer is the customer. He is sitting at his own kitchen table, on his own phone, logged in the way he always logs in. And he is being talked, step by patient step, into sending his money to a crook he has never met. The romance he believes is real. The investment he's sure is going to the moon. The nice man from "the bank" who called to say his account is under attack and he must move his savings somewhere safe, right now.
Here's the uncomfortable part for anyone who builds fraud controls. Every clever check you own is designed to ask, "Is this really you?" In a scam, the answer is yes. It really is him. He'll pass your device check, because it's his device. He'll pass your one-time code, because he's holding the phone and he'll read the number out to the crook if you make him. Ask him to confirm he wasn't coached, and he'll confirm it, because he doesn't believe he was. You cannot authenticate your way out of a problem where the authentication is working perfectly.
So the precise tools go quiet, and you're left needing something blunter.
What still works is anything the crook can't coach away. A scammer can rewrite the story your customer tells you. He cannot rewrite the size of the check. He can teach the victim to answer every question just so, but he can't make ten thousand pounds look like nine hundred. The amount is the amount. The beneficiary is new or it isn't. The account was opened last Tuesday or it's twenty years old. These are structural facts, and they don't care what script the crook is running this week.
That's the whole case for a threat-agnostic control: a plain monetary threshold, a limit on how fast money can leave, a hard look at any first payment to a brand-new payee. It doesn't need to know whether the story is romance or crypto or a fake fraud-department call. It watches the money, not the tale. Scam scripts change every few weeks; a threshold on a first-time transfer to a stranger doesn't need to keep up with the fashions.
And yes, a control like that means protecting customers from themselves. That's an odd sentence to write. Everywhere else in the business you're taught the customer is right and friction is the enemy. Here the friction is the point. The delay your customer resents, whether it's a held payment, a phone call, or a twenty-four-hour cooling-off, is very often the thing that saves his retirement. He'll be annoyed. He may tell you, firmly, that he knows exactly what he's doing. So does the friend at the bar who's sure he's fine to drive. The kindest thing you can do is take the keys, and take the small helping of resentment that comes with it.
There's a second reason to like a blunt control, and it's one that Warren Buffett and Charlie Munger have spent their lives pointing at, though never about fraud.
If your rule is perfectly knowable, someone will learn it and hug the line. Say every payment over five thousand pounds gets a call. The crook does arithmetic too. Now your victim sends three payments of four thousand nine hundred, and your clever line has taught the enemy exactly where to stand. The cure is a little randomness. Sometimes a modest payment gets held for no reason the outside world can see. Some slice of traffic gets a human's eyes regardless of what the score said. You give up a fixed line, and in exchange the crook loses his map of your defenses.
Munger likes to solve problems backwards, asking how the other fellow is going to beat you and then refusing to make it easy. Buffett's whole habit is a margin of safety: don't stand at the exact edge of what's prudent, because you'll misjudge the edge sooner or later. A dose of unpredictability in your controls is that same instinct wearing work clothes. Be a little harder to model than the crook expects, and you stop being a mark.
The last thing I'd say is the one people skip.
The blunt control isn't only a net. It's a sensor. Every scam it stops is a real case that walked straight past your smart, targeted models and got caught by the dumb one at the door. That is a gift. It's a labeled example of a loss you would otherwise have eaten, and it's telling you exactly where your precise controls are blind. Study what the threshold catches. Find the pattern. Then go teach your sharper tools to catch it earlier, with less friction for the honest customer who just wanted to pay his builder.
Do that faithfully, and the two controls trade favors forever. The blunt one keeps the floor from falling out while your clever ones are still learning. The clever ones slowly take over the easy cases, so the blunt one only has to bother people when something is genuinely strange. The dumbest control in the room ends up being the one that trained all the others.
It rarely gets the credit. Most things that quietly do their job don't.
Co-founder
Georgi
