This website uses cookies

Read our Privacy policy and Terms of use for more information.

Hello Fraud Fighters!

This week a Miami rental-car scheme shows exactly how straw buyers beat auto lenders using nothing more than a calendar. Meanwhile, a $5.2 billion identity player just bought its way into agentic fraud investigations, researchers figured out how to bring a dead Visa card back to life at the checkout counter, and Visa and Mastercard joined two dozen companies trying to agree on how AI agents should be allowed to spend your money.

Let's get into it…

Nick

Big Story: Gone in 60 Seconds

In August 2020, 25 year old Cesar Cespedes, walked into a Miami CarMax and financed a $49,000 Mercedes. Within a day, the keys went to Alejandro Soto, who ran a Turo-based luxury rental business called Venom Luxury Rentals. Over the next two weeks, Cespedes financed a Maserati, two Camaros, and a Land Rover the same way, using fabricated employment records that listed him as a $8,800-a-month manager at a company he'd never worked for. Then he brought in his sister, his father, and a friend to do the same thing.

That was the start of a straw-buyer bust-out ring that federal trial testimony unsealed this year and was recently reported in detail by fraud guru Frank McKenna. It shows the ring financed roughly 90 vehicles through 16 straw buyers for about $3.6 million, generating close to $600,000 in Turo rental revenue before the loans collapsed. The Florida Office of Financial Regulation corroborates the same numbers, and Soto was ultimately sentenced to 99 months in federal prison.

The methodology exploited two blind spots at once. First, a new auto loan doesn't show up on a credit report for roughly 30 days, so the crew bought every car in a single straw buyer's name inside that window, before any lender could see the last purchase. Second, lenders don't check with each other in real time, so spreading applications across different banks meant no single lender ever saw the full pattern. An unscrupulous finance manager, handled the rest: fake W-2s, fabricated employers who'd answer verification-of-employment calls, and "ghost" down payments that were listed on contracts but never actually paid, making thin loans look properly collateralized on paper.

This isn't an isolated case. Miami-Dade's auto fraud task force separately arrested 21 people this year in a strikingly similar scheme: 100 fraudulently financed vehicles worth $5.5 million, straw buyers, fake paperwork, cars stripped of liens and re-VINed. The county sheriff put the exploit in almost the same terms Soto's crew used: a single straw buyer can purchase up to 20 vehicles in a week before anything registers on a credit report.

So what for operators: if your fraud model treats "clean credit report" as confirmation of capacity to repay rather than a snapshot with a 30-day blind spot, a crew that understands the lag can walk through it with real, unaltered credit files. Velocity monitoring across dealer networks and faster loan-reporting cycles matter more here than better identity verification at the point of sale — the borrowers in this case were who they said they were.

Quick Hit #1: Socure Hits $5.2B, Buys Its Way Into Agentic Fraud Investigations

Socure announced a $156 million strategic growth investment this week that values the identity and risk platform at $5.2 billion, led by Summit Partners with Goldman Sachs Alternatives, Wells Fargo, and Docusign also participating. Bundled into the raise: the acquisition of Fravity, an agentic platform built to automate fraud, risk, and compliance case investigations, which Socure is folding into its RiskOS decisioning engine as "RiskOS_Agents." Terms of the acquisition weren't disclosed, though Crunchbase reports Socure has now raised over $742 million since 2012.

What I think of when I hear “Agent”

The underlying business numbers are notable: $364 million in annual recurring revenue, up 63% year-over-year, with 133% net dollar retention and logo churn of just 0.01% across more than 3,000 customers. Socure is pitching the deal against data from Liminal showing U.S. organizations spend roughly $100 billion a year on fraud, compliance, and risk operations, with 53% of banks taking at least an hour to review a single alert. Fravity claims its existing deployments have cut cost per case by 80% and false positive rates by up to 70%.

For fraud teams evaluating vendors, this is the clearest signal yet that "agentic AI for case investigation" is consolidating into the big identity platforms rather than staying a standalone category: expect RFPs to start asking incumbents what their agentic roadmap looks like, not just their match rates.

Quick Hit #2: The Zombie Card

Researchers at UMass Amherst presented findings at USENIX Security 2026 showing that expired Visa contactless cards aren't actually dead — they can be "revived" to make real purchases. The exploit works because a card's expiration date is checked by the payment terminal as a plaintext policy field, not cryptographically signed as part of the card's core security data. Using two off-the-shelf smartphones running NFC relay software, the team intercepted a card's data, altered the expiration date in transit, and completed live purchases at retail and grocery terminals with no knowledge of the card's actual replacement expiration date required, since any future date satisfies the check.

“CAAARDS…”

Testing across major card networks found the flaw was specific to Visa's implementation: Mastercard, American Express, and Discover all rejected the tampered date because those networks tie expiration to a cryptographic signature that breaks when altered. The researchers disclosed the issue to Visa and affected banks in May and again in December 2025; as of the paper's publication, no CVE has been assigned and no advisory issued by Visa, EMVCo, or any of the five major US banks tested. For card issuers, "shred your expired cards" is a real mitigation for consumers, but it doesn't fix the underlying gap — the expiration check belongs in the card's signed data, not the terminal's plaintext read, and until Visa closes that gap, discarded intact cards are a live payment instrument.

Quick Hit #3: Visa and Mastercard Join Rain's Agentic Payments Alliance

Stablecoin infrastructure company Rain launched the Agentic Payments Alliance on August 18, pulling together 26 founding members that notably include both Visa and Mastercard alongside Circle, Solana, Fiserv, Chainalysis, and Remitly. The coalition's stated purpose is to define the infrastructure agentic commerce still lacks: how AI agents get authorized to transact, how fraud gets detected in agent-initiated purchases, and how loyalty and rewards travel with an agent rather than a human cardholder. Rain cites McKinsey projections of $3–5 trillion in global agentic commerce by 2030 as the scale driving the urgency.

Rain co-founder and CEO Farooq Malik framed the alliance as an attempt to get ahead of fragmentation: "No single company should get to decide how agents transact on someone's behalf... we initiated the Agentic Payments Alliance to put all of these parties in the same room, and to do it now, while the category is still taking shape."

Notably, fraud detection standards for agent-initiated transactions are explicitly listed as one of the undefined pieces the alliance intends to build, meaning the rules for who's liable when an agent gets tricked into an unauthorized purchase are still being written. Fraud and risk teams at any institution touching agentic commerce should treat this as the moment to have input, not the moment to wait for a finished standard to react to.

This Week in Fraud is a publication for fintech operators, fraud teams, and risk professionals. Have a tip or story? Reply to this email or drop Nick Holland [email protected] a note directly.

Reply

Avatar

or to participate

KEEP READING


VIEW MORE