MerchantGo Intelligence Platform

Industry Update IU-005

Payment Fraud Is Becoming an Industrialized Business.

AI, reusable criminal tooling and organized fraud services are allowing attackers to operate with greater speed, scale and consistency.

TopicsPayment Fraud · Card Fraud
Reading Time6 Min Read
PublishedAugust 2026

What changed

The direction described in Mastercard's coverage of the Recorded Future 2026 payment-fraud report is one of standardization rather than novelty. Card testing, account takeover, synthetic identity and fake merchant activity are long-established techniques. What has changed is that an attacker no longer needs to build the components.

Compromised credential and card data is sourced. Automated testing infrastructure is rented. Synthetic identity documents and supporting content are generated. Storefronts, hosting and descriptor infrastructure are provisioned. Cash-out and laundering are contracted to specialists. Each element is a service, and the services compose.

Mastercard has also published analysis on the role of AI in payment-fraud prevention, including survey findings on institutional adoption and savings. Those figures come from research commissioned by a network with a commercial position in the space; they are informative about direction and should be attributed accordingly rather than presented as neutral benchmarking.

Why it matters

Reusability changes the economics on the attacker's side of the equation. When each attack required bespoke setup, defensive friction was expensive to overcome and marginal targets were not worth pursuing. When capability is modular, the cost of attempting an additional target approaches the cost of configuration — which means smaller merchants, narrower windows and lower-value targets all become economically viable.

It also changes the shape of what defenders observe. A single transaction from an industrialized operation looks ordinary because it was designed to. The abnormality exists at the level of the pattern: the shared device fingerprint across unrelated accounts, the BIN sequence tested across four merchants in eleven minutes, the twelve identities that share a fragment of address history, the storefront that has existed for nine days.

This is the structural weakness of isolated transaction scoring. A model evaluating one payment in isolation is being asked to detect a property that only exists across events. It will produce defensible individual decisions and miss the operation entirely.

Fraud is scaling because criminal capability is becoming reusable. Defences built around isolated events will struggle against connected operating models.

Who is affected

  • Card-not-present merchants. Enumeration and card testing target checkout endpoints indiscriminately; low ticket value does not confer protection.
  • Issuers. Testing traffic and synthetic-identity applications arrive at volume and are individually unremarkable.
  • Acquirers and payment facilitators. Fake merchant activity and rapid onboarding abuse are direct portfolio exposures.
  • Fraud operations teams. Case-by-case review scales linearly against an adversary that does not.

MerchantGo analysis

The correct response to industrialized attack is not simply better models. It is a change in the unit of analysis. Programs that hold their ground treat the entity — device, identity cluster, network, merchant, beneficiary — as the object being scored, with individual transactions as evidence contributing to that assessment rather than as the assessment itself.

That has concrete architectural consequences. Linkage data must be retained and queryable across sessions and accounts. Velocity has to be measured across dimensions the attacker does not control cheaply, not just per-card or per-IP. And decisions have to be revisitable: an account that looked clean at signup and links to a confirmed ring three days later should trigger reassessment, not remain approved because the original decision was made correctly.

AI belongs in this picture, but with a precise role. It is genuinely effective at surfacing linkage and behavioural pattern at a scale humans cannot process. It is not a substitute for a defined strategy, clean data or governance — a point worth restating because vendor positioning frequently implies otherwise, and because the same generative capability is available to the other side.

The organizational implication is cross-functional intelligence. Fraud, payments, security, onboarding and disputes typically each hold one fragment of the same operation. Industrialized attackers exploit the seams between those functions, and in many organizations no one is looking at the seams. A standing forum with shared entity-level data does more for detection than another model iteration.

None of this means transaction scoring is obsolete. It means transaction scoring is the last layer, not the whole architecture, and treating it as the whole architecture is why defences that perform well on individual decisions can still lose to a coordinated operation.

What leaders should do now

  1. 01Score entities, not just transactions. Make the device, identity cluster, merchant or beneficiary the unit of assessment, with transactions as contributing evidence.
  2. 02Retain and query linkage data. Cross-session, cross-account linkage is the primary detection surface for coordinated activity. It cannot be reconstructed after the fact.
  3. 03Build multi-dimensional velocity controls. Measure velocity across attributes attackers cannot rotate cheaply, and specifically instrument card-testing and enumeration patterns at checkout.
  4. 04Make decisions revisitable. Approved accounts and merchants should be reassessed when new linkage evidence appears, not locked in by the original decision.
  5. 05Share intelligence across functions. Fraud, payments, security, onboarding and disputes each hold part of the picture. Establish a standing forum with shared entity data.
  6. 06Attribute vendor and network research carefully. Commissioned research is useful for direction. It is not neutral benchmarking, and should not be used to set internal targets.

Key Takeaways

What to carry into your next leadership discussion.

  • 01Criminal capability is becoming modular — sourced, rented and composed rather than built per attack.
  • 02Reusability lowers the marginal cost of attacking additional targets, extending exposure to smaller merchants and narrower windows.
  • 03Industrialized activity is abnormal at the pattern level and ordinary at the transaction level.
  • 04Entity-level scoring, retained linkage data and revisitable decisions matter more than incremental model tuning.
  • 05Network-commissioned AI research indicates direction; it should be attributed, not treated as independent benchmarking.
MB

Author

Michel Bertrand

Founder & Principal Consultant, MerchantGo

Enterprise Fraud · Payments · Decision Intelligence

Share this Industry Update

About MerchantGo

Want to know what this means for your portfolio?

MerchantGo helps fraud, payment and risk leaders translate industry developments into control decisions, reporting changes and remediation plans that hold up in front of executives, acquirers and regulators.