Hello Fraud Fighters!
This week: a White House staffer got caught betting on his own boss's speeches, fake Guardian and BBC articles are selling crypto scams, and it turns out most fraudulent selfies are still embarrassingly low-effort — not the deepfake apocalypse the vendor decks promise. Plus new data on where fraud losses actually cluster, in payments and in the air.
Let's get started...
Nick
Big Story: The Prediction Market Insider Trading Problem
Kalshi's own surveillance system caught something a human compliance team almost certainly wouldn't have: a pattern of "off" trades on its Mentions markets, the contracts where users bet on which specific words or phrases a public figure will say in a speech. According to CBS News, a Kalshi spokesperson said the company investigated the trader's activity after its surveillance systems detected trades that didn't adhere to typical buying and selling patterns.
That trader has since been identified by multiple outlets, including Axios and CNBC, as Gabriel Perez, Trump's teleprompter operator since 2016, someone with literal advance access to the text of the speeches being bet on. Perez made more than $100,000 on the trades; Kalshi froze roughly $90,000 of it before he could withdraw, and referred the activity to the Commodity Futures Trading Commission after its surveillance team flagged the anomaly and market makers separately raised it through the platform's whistleblower channels. Perez has been cooperating, and the CFTC is reportedly negotiating a settlement that would require him to disgorge profits. Federal prosecutors in Manhattan declined to open a criminal case.
Strip out the political noise and there's a genuinely useful fraud-ops story here. Prediction markets are one of the fastest-growing product categories in fintech right now, and they sit in an unusual spot: real-money wagering on real-world events, built by exchanges that had to stand up market-surveillance infrastructure from scratch, faster than most of their compliance functions could mature around it.
So what for operators: if your fraud program is still tuned primarily to transaction size and velocity, this is a good prompt to ask what "doesn't fit the pattern" actually means for your product. Insider-information exploitation, first-party fraud, and account-takeover-that-looks-like-the-real-owner all share the same tell: the individual transaction looks fine, and the anomaly only shows up at the pattern level. As prediction markets, embedded trading products, and other real-money-on-real-events categories keep expanding, expect this exact failure mode to show up well outside of politics.
SPONSORED

Every time a legitimate customer abandons your onboarding flow, you're leaving money on the table. Too much friction kills conversions. Too little opens the door to fraud. You shouldn't have to choose. This Buyer's Guide from Jumio breaks down how modern identity solutions use dynamic friction to fast-track good customers while stopping bad actors in their tracks. Whether you're a growth leader trying to hit acquisition targets or a risk manager protecting your platform, this guide shows you how to optimize for both — without compromise.
Quick Hit #1: Scammers are cloning trusted news sites to sell fake crypto platforms

Fraudsters are building convincing clones of Guardian and BBC pages, populating them with fabricated stories, and using them to funnel readers into bogus investment platforms. The latest version, reported by the Guardian, fabricates a story about billionaire Jim Ratcliffe storming out of a BBC interview and quietly making money through a "secret" trading platform. Full Fact's fact-check found the fake image still carried Google's SynthID watermark, giving away the AI tooling used to make it.
This isn't new as a tactic. financial campaigner Martin Lewis and broadcaster Sir David Attenborough have both been used as bait in near-identical schemes, but the production quality has jumped. The clones now replicate layout, typography, and even named journalists' bylines and headshots closely enough that spotting the fake requires checking the URL, not the page. Kraken, whose branding has also been impersonated in some of these clone sites, says any site guaranteeing returns and using its name should be treated as fraudulent outright.
Quick Hit #2: Persona's 27 million fraudulent selfies say the AI panic is a little ahead of the data

Persona analyzed 27 million fraudulent selfie submissions and found AI-generated content in roughly one in four of them, real, but not the dominant mode. The bulk of attacks are still low-effort presentation attacks (photo of a photo, basic virtual camera setups), which account for over 80% of injection attempts. Attackers were nearly three times more likely to inject video of a real person than to generate a synthetic one.
Persona's read, via product architect Coco Tang: high-quality AI selfies and injection attacks show up when fraudsters are chasing high-value targets specifically; the mass-market version of this attack is bot-driven, high-volume, low-sophistication "fraud slop". Worth remembering the next time a vendor pitch leads with deepfakes, the actual attack surface most teams are dealing with day to day is still fairly unglamorous.
Quick Hit #3: Fraud is getting quieter and more expensive at the same time
Sift's Q2 2026 benchmarks, drawn from its global data network, show attack volume falling across most metrics: account takeover attempts down 7% quarter over quarter, manual review rates down 13.5%, while fraudulent chargebacks jumped 75.6% QoQ and 80% year over year. The read: attackers are moving off stolen-card volume plays and onto established accounts with real purchase history and trusted payment methods, where compromised transactions pass every standard signal because they are the same customer, same device, same behavior. The dispute doesn't surface for weeks.
Vertical divergence is the sharper data point for this audience: finance and fintech held attack rates flat at 2.4% with 2FA adoption climbing to 11.5% (up from 9.2% a year ago), while Internet/Software subscription businesses saw payment fraud attack rates jump 39% QoQ as attackers exploit stored-credential compromise for recurring billing theft. Sift's other finding worth sitting with: only 28% of consumers who experience fraudulent charges keep using the platform without hesitation afterward — 27% leave permanently.
Quick Hit #4: Airline booking fraud has a geography problem
Accertify's Q2 2026 Global Air Travel Fraud Report tracks prevented fraud rates (bookings denied for a fraud reason before travel) across 537 departure cities worldwide, and the geographic concentration this quarter is stark. The global average was 0.29%, but Middle East and Africa's regional average more than doubled quarter-over-quarter, from 0.95% to 2.03%, the only region to worsen year-over-year. Cairo posted the single largest move in the report: its fraud rate nearly quintupled in one quarter, from 1.43% to 6.57%, catapulting it from 15th-highest in the world to first. The four highest-fraud departure cities on the planet right now (Cairo, Accra, Tunis, Casablanca) are all in North and West Africa.
The contrast is the useful part for operators elsewhere. US departure cities averaged 0.07% and Australia/Pacific 0.08%, both down year-over-year, which Accertify attributes to the layered, mature prevention practices already standard in those markets.
Note: flagging the methodology plainly… these are prevented fraud rates, not realized losses, so a high number shows where fraud-prevention teams are working hardest at the point of booking, not necessarily where the money actually got out the door.
This Week in Fraud is a publication for fintech operators, fraud teams, and risk professionals. Have a tip or story? Reply to this email or drop Nick Holland [email protected] a note directly.


