Hello Fraud Fighters!
This week, Anthropic published its latest threat intelligence report, and buried in the case studies is a blueprint for exactly how criminals are using AI to beat KYC at scale: proxies, antidetect browsers, and a reverse-proxy trick that lets a real verification session get hijacked mid-flow. Meanwhile, Revolut got played by a fake government email, crypto platforms keep losing billions despite passing their audits, and three separate governments moved against AI-driven scams in the same two weeks. It’s been spicy out there!
Let's get into it.
Nick
Big Story: AI vendors are now fighting fraud on two fronts
For the past two months, the AI industry's fraud problem has mostly been a story about the labs themselves. On July 21, OpenAI disclosed that a model it was testing broke out of a sandboxed evaluation environment and hacked its way into Hugging Face's production infrastructure while trying to cheat on a benchmark. Nine days later, Anthropic said its own review of 141,006 evaluation runs had turned up three similar incidents, involving Claude Opus 4.7, Claude Mythos 5, and an internal research model, all of which reached the open internet through a misconfigured third-party test environment and touched real production systems. Two of the three victims hadn't noticed.
By August 27, more than 100 companies (OpenAI, Anthropic and Google among them) had signed a letter calling for a joint cybersecurity consortium, warning that the window to prepare defenses against AI-driven attacks is closing fast.
“Do I look like I’m going to go rogue and destroy humanity?” LLMs, probably.
The most recent Anthropic threat report is the part of the story that actually belongs in a fraud newsletter. It covers disrupted operations from December 2025 through August 2026, and two case studies land squarely on our beat. The first: a "fraud account factory," where an operator provisioned residential proxies and antidetect browser profiles, then ran bots through exchange and marketplace signup flows using commercial CAPTCHA-solving services and automated identity verification to defeat onboarding, banking verified, legitimate-looking accounts for later use. The second, nastier one: a "KYC interception cloak." Victims got routed to lookalike verification domains that reverse-proxied the real KYC flow, so the person on the other end completed a genuine identity check while the operator captured the verified session and documents from the middle of the connection. The victim's KYC actually passed. The account just didn't end up in their hands.
There's a third thread worth flagging for anyone buying agentic AI tools for fraud or compliance work: the AI supply chain itself is now a target. Anthropic documented a group running a fraudulent "cheap Claude access" reseller; customers thought they were getting discounted access to Claude, but their traffic was silently proxied to a different model while the reseller's own client software harvested their real Anthropic credentials for resale. Stolen AI API keys and session tokens are being treated by criminal groups as three things at once: loot to sell, free compute to run attacks on, and cover, since the activity gets attributed to whoever's key it is.
None of this is abstract for fraud teams. If you're evaluating or already running agentic AI for KYC, transaction monitoring, or case investigation, the questions worth asking your vendor now go beyond detection accuracy: how is API access authenticated and rotated, and what happens if a session token is stolen? And on the KYC side specifically: a "passed" verification event needs to prove the session wasn't relayed, not just that the person on camera was real. Verified doesn't mean it hasn’t been intercepted anymore.
Quick Hit #1: Revolut got hit by the fraud signal it wasn't using
Revolut confirmed last week that a scammer using a legitimate government email domain tricked the company into handing over customer data including passports, driver's licenses, verification selfies, and transaction histories for what it's calling a "limited number" of customers. Revolut says systems and funds weren't touched, and it's notified regulators, law enforcement, and the impersonated agency. TechCrunch first reported the incident after obtaining Revolut's own customer notification.
The timing is almost too neat: PYMNTS Intelligence published research the same week surveying 150 senior executives at companies with heavy payment flows, and found 69% have secure access to customer bank account data but only 49% actually use those connections to generate real-time fraud alerts, a 20-point gap between having the signal and acting on it. Whether or not that gap applies to how Revolut vetted the request that hit it, the broader point holds: most institutions are sitting on more fraud-relevant data than they're using operationally, and the fastest fix on the table right now isn't a new tool, it's turning on what's already connected.
Quick Hit #2: Crypto keeps getting hacked, audits or no audits
CoinGecko's State of Crypto Security Report, covered by CNBC this week, puts crypto platform losses to hacks and theft at $3.6 billion over the last 18 months. The uncomfortable number inside that figure: 88.4% of the stolen capital came from platforms that had completed independent security audits before they were compromised. Only about 11% of the 245 documented incidents involved an actual smart contract flaw, the rest hit external infrastructure, unaudited code updates, and governance mechanisms.
Medieval Hackers at work
The report's window closes before some of the past two weeks' bigger incidents, including the $320 million hack on Bitcoin's Liquid Network (reported as a "white hat" operation, though $47 million of it stayed with the attackers) and a breach of Coldcard hardware wallet customers that's now cost more than $115 million. For fraud and risk teams evaluating crypto counterparties, a clean audit report on the smart contract layer is table stakes, not a security guarantee — the infrastructure and deployment pipeline around the contract is where most of this money is actually leaving.
Quick Hit #3: Three governments, one target, same two weeks
Thailand, South Korea, and Visa's Singapore operation all moved against AI-driven fraud within days of each other this month. The Bank of Thailand rolled out a sector-wide framework effective September 10, binding banks, e-payment operators, and more than 2,000 money changers to heightened diligence on large cash and gold transactions, alongside a "Bangkok Blueprint" it's co-developing with the IMF and World Bank as a template for other countries. South Korea's Ministry of Science and ICT is drafting a national AI-crime strategy after deepfake case numbers went from 168 in 2023 to 1,300 last year. And Visa unveiled its Singapore Security Roadmap 2026 and Beyond, expanding tokenization and passkey adoption in response to a shift toward AI-assisted, authorized payment scams.
Three separate authorities, three different tools, a central bank framework, a national policing strategy, a network security roadmap converging on the same problem in the same fortnight. That’s how you solve a fraud problem.
Quick Hit #4: Biometrics had a rough couple of weeks
Germany's federal cybersecurity agency, BSI, warned this month that AI combined with a 3D printer can reproduce a usable fingerprint from nothing more than a photo of someone's hand. Unlike a password, a fingerprint can't be reissued once it's compromised. Obvs.
At the same time, Biometric Update's Deepfake Detection Market Report is pointing the industry toward continuous, session-long verification instead of a single check at login — IngenID's updated Twilio connector now re-verifies a caller's voice throughout an entire call rather than just at pickup, and JPMorgan and Accenture are pushing banks toward layered defenses covering the full window between when a payment is initiated and when it executes. Two different biometric modalities, two different warnings, the same conclusion: a single verification moment isn't a security control anymore.
This Week in Fraud is a publication for fintech operators, fraud teams, and risk professionals. Have a tip or story? Reply to this email or drop Nick Holland [email protected] a note directly.


