Skip to main content
2.4M Attacks in One Month: What ChangedFraud Detection Analytics
4 min readFor Fraud Risk Managers

2.4M Attacks in One Month: What Changed

August's fraud data reveals a structural shift in how attacks reach your checkout. The numbers matter less than what they signal: fraud rings now operate with industrial-scale automation, and your detection layer probably wasn't built for this.

What the Data Shows

Forter's network tracked 2.4 million fraud attempts in August, with 84% traced to coordinated fraud rings. This isn't a surge in opportunistic fraud, it's organized crime applying software engineering discipline to account takeover and identity manipulation.

Three findings stand out:

3,300 large fraud rings detected across the network. These aren't lone actors testing stolen cards. They're structured operations that hit multiple merchants, learn from each attempt, and refine their approach. The Chrome Soles ring alone attempted $71,561.71 in fraudulent footwear purchases across 333 transactions, using bots calibrated to mimic human browsing speeds. They concentrated IP activity in two metro areas but routed 54% of shipments to California, a mismatch your fraud rules should have caught if you're correlating shipping and billing geography.

Desktop carries 54% of detected fraud despite lower traffic. Mobile's biometric authentication creates friction that fraudsters avoid. Your fraud team should measure risk by channel, not just transaction volume. If you're staffing fraud review queues based on traffic distribution, you're under-resourced on desktop.

Sophisticated account takeover patterns rose 12%. Package rerouting used to require social engineering, calling carriers, tricking support agents, manually setting up forwarding accounts. AI tools now automate the entire workflow. Fraudsters run credential stuffing attacks with tools like OpenBullet or Sentry MBA, loaded with custom configs that scrape loyalty point balances directly from your API responses. High-value accounts get prioritized for immediate redemption; zero-balance accounts get sold in bulk.

What This Means for Your Team

Your fraud prevention layer was designed for a different threat model. If you're still relying on velocity rules, device fingerprinting, and static risk scores, you're measuring the wrong variables.

Fraud rings operate like software teams now. They A/B test checkout flows, use proxies to mask location, and train bots to browse at human speeds. The Chrome Soles ring used 0-day accounts (created the same day as the transaction attempt) and stuck to Microsoft OS with Chrome browsers, a consistency pattern that should have triggered alerts, but only if your detection system correlates user-agent strings with account age and shipping mismatches.

Identity manipulation is easier than it's ever been. Reputation takeover increased 18% year-over-year. AI agents scrape open-source data, social profiles, public records, data breach dumps, and assemble convincing synthetic identities. Your KYC checks won't catch this if you're only verifying that an identity exists, not that the person transacting matches the behavioral profile of that identity.

If you run a loyalty program, you're 3.5 times more likely to be targeted, according to Arkose Labs. Fraudsters sort accounts by points balance and elite tier status, then prioritize high-value accounts for redemption or resale. Your loyalty members have predictable behaviors, login cadence, preferred redemption patterns, typical transaction sizes. Use that data. A sudden login from a new device, followed by a points redemption that doesn't match historical behavior, should trigger MFA or manual review.

Action Items by Priority

1. Correlate shipping and billing geography in real time. The Chrome Soles ring routed half their shipments to California while concentrating IP activity in the Northeast and Canada. That's a detectable pattern if your fraud rules compare billing address, shipping address, and IP geolocation. Flag transactions where all three don't align within a reasonable radius.

2. Measure fraud by channel, not traffic. Desktop accounts for 54% of detected fraud. Allocate fraud review resources accordingly. If your team reviews mobile and desktop transactions at the same rate, you're missing desktop attacks.

3. Build behavioral profiles for loyalty accounts. Track login frequency, redemption patterns, and transaction history for program members. When an account deviates, new device, unusual redemption, off-hours login, require step-up authentication. Don't rely on passwords alone.

4. Join a fraud intelligence network. The 3,300 rings detected in August hit multiple merchants. If a ring attacks one network member, every other member should inherit that intelligence. Forter's network model does this; if you're operating in isolation, you're learning about rings only after they've hit you.

5. Review your return abuse controls. Beauty merchants saw a 25% year-over-year increase in return fraud, driven by AI-altered images that manipulate refund workflows. Personalize return privileges based on customer lifetime value and fraud history. Some customers shouldn't get returns at all; others should face restrictions on high-risk products or peak fraud periods.

6. Audit your API responses for data leakage. Credential stuffing tools scrape loyalty balances and account details directly from HTTP responses. Review what data your login API returns. If you're sending point balances or account tier information in the authentication response, you're handing fraudsters a sorting mechanism.

PCI DSS requirements

By understanding these evolving threats and adjusting your strategies, your team can better protect against sophisticated fraud rings.

You Might Also Like