Hello Fraud Fighters!
This week, six major banks asked who pays when an AI shopping agent buys the wrong thing, and the honest answer is that nobody has a clue. Also: North Korea (allegedly, but very probably) drained $388 million from Bitget without touching a private key, Microsoft dismantled a phishing service that used AI to pick its victims, a credit union alleged fraudsters are phoning Fiserv's help desk to unlock stolen cards, and the UK closed nearly a quarter million mule accounts and the problem is still there. Oh my.
Let's get into it.
Nick
Big Story: It’s 10pm. Do you know what your AI agent is buying?
On Sept. 22, six banks (ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING, and NatWest) published Building Trust in Agentic Commerce, a principles paper that starts from a question with no settled answer: when an AI agent buys the wrong thing, who pays? Reuters reported the group's warning that agents could raise the risk of scams, fraud, and privacy breaches, and noted that British retailer John Lewis has seen searches originating from AI agents climb from 0.3% to 2.5% in a year, meaning autonomous shoppers are arriving before the rules are.
The banks lay out a spectrum. At one end, an agent searches and a human checks out. At the other, it picks and buys off a single instruction and the customer never sees the final choice. And the further along you go, the murkier the disputes get. Issuers and acquirers may lack real-time access to the agent's identity, the merchant of record, the customer's intent, and the purchase details. Customers don't know whom to call when an agent overspends or falls for a scam, and merchants fear chargebacks over decisions they never controlled.
The proposed fix is voluntary. Providers should keep evidence of the customer's instruction, the authentication, the agent's decision, and the outcome, including any warnings or interventions. Customers should be able to see and manage the authority they've delegated. Liability should follow wherever the error or risk entered the transaction. The paper also names some positively Black Mirror-esque scenarios: agents keying card numbers into unfamiliar websites, agents favoring payment methods with weaker protections, and criminals impersonating or compromising agents and merchants.
FIDO Alliance CEO Andrew Shikiar, interviewed by Payments Dive, is working the same gap from the standards side. His answer is "know your agent": tie every agent action back to a verified human, and track an agent's breadcrumbs (where it has been, what it has bought, what services it has touched). Shikiar doesn't expect agentic commerce at scale for years because chargebacks and liability for a rogue agent are unresolved, and when he cited McKinsey's $3 trillion-by-2030 projection, he said the industry isn't there yet.

Given the magnitude of industry weight behind making “agentic” happen, it seems more than a little reckless that the potentially gargantuan fraud problem is trailing rollout of agents in commercial transactions.
Fraud incoming in 3…2…1…
Who moved the needle in fintech this year?
We’re recognizing the top leaders across Startups, Big Companies, Founders, VCs, and Social Good at our year-end Fintech Formal on Dec. 11 in New York. Judging is 100% independent—TWIF doesn't vote.
Quick Hit #1: North Korea (probably) drains $388 million from Bitget without stealing a key
Bitget says a theft on Sept. 24 involved no stolen private keys. CEO Gracy Chen said the attacker compromised a critical backend system in the wallet infrastructure, used it to spoof transaction data, and triggered Bitget's own authorization process to move funds out of hot and warm wallets. The payouts looked legitimate from the inside. Cold wallets were untouched, and Bitget says its $464 million User Protection Fund covers the loss. The exchange first put the damage at $351.6 million and raised it to $387.5 million after a fuller accounting.
Bitget cites IP addresses linked to VPN services associated with a North Korean hacking group, and Elliptic adds on-chain links to laundering addresses from last year's Bybit heist. TRM Labs sees the same wallet overlaps and points to the TraderTraitor group, though it hasn't definitively attributed the theft. By Elliptic's count, suspected North Korean thefts this year now top $1 billion. The attribution will keep analysts busy, but the method carries the lesson for everyone else: an authorization layer accepted spoofed data, so any custody review that ends at "the keys are safe" has stopped a step early.
Quick Hit #2: Microsoft takes down a phishing service that used AI to choose its victims
Microsoft's Digital Crimes Unit and partners including Cloudflare, Coinbase, OpenAI, SpyCloud, and TRM Labs disrupted EvilTokens, a phishing-as-a-service platform that compromised more than 12,000 inboxes across 10,000-plus organizations since February. Victims were tricked into entering a code on Microsoft's real sign-in page (device-code phishing), which gave the attacker an authenticated session. An AI chatbot then read the mailbox to find wire-transfer threads, the people who move money, and trusted contacts worth impersonating. The service sold through Telegram for a $1,500 sign-up fee and $500 a month, with dashboards and customer support included. Microsoft seized 50 sites and disabled 150-plus domains, and London's Met Police arrested two men on Sept. 11.
The takedown is a dent. SpyCloud's recaptured data shows the ten most active customers accounted for 60% of unique victims, and Dark Reading reports SpyCloud expects those operators to move to rival kits. BleepingComputer notes clones such as APToken already exist. Microsoft's Digital Crimes Unit advises assuming that once an inbox is compromised, criminals can understand its contents within minutes. Disabling the device-code flow where you don't need it closes the entry point, and payment-change and vendor-onboarding controls need to hold up against a request that arrives from a real, trusted mailbox.
Quick Hit #3: Fraudsters are phoning Fiserv's help desk to unlock stolen cards
FiCare Federal Credit Union told a federal court last week that fraudsters are calling the cardholder-services line Fiserv runs for card-fraud blocks, passing verification, and talking agents into turning stolen cards back on. According to CU Daily's review of the emergency motion, at least 18 fraudulent transactions hit FiCare cardholders in August after blocks were lifted. FiCare's declaration lists five other credit unions with similar reports, secondhand from an email listserv and unconfirmed by those institutions or Fiserv. FiCare alleges the center verifies callers with knowledge-based questions (an SSN plus card-face details like the expiration date) and no multifactor step, so a thief holding the card and a breach-sourced SSN already has most of the answers. It also alleges fraudsters flooded cardholders with texts so real fraud alerts went unnoticed.

These are FiCare's allegations, and no court has ruled. Fiserv told American Banker it has invested heavily in fighting fraud and will respond through the legal process. The call center runs on a separate platform from the online-banking account takeovers at the heart of FiCare's original suit, one of several brought by a coalition of credit unions against the processor. FiCare has asked for a ruling by Sept. 29 on faster discovery; otherwise Fiserv's responses aren't due until Oct. 19.
Quick Hit #4: The UK closed 238,396 mule accounts in 2025, and the growth is flattening
The FCA's multi-firm review found firms closed 238,396 suspected mule accounts in 2025, up from 233,269 in 2024 and 184,935 in 2023. Closures rose 26% in 2024 and about 2% last year, and the regulator cautioned that increases may partly reflect customer growth and better detection rather than a larger mule population. The NCA estimates more than £100 billion a year is laundered through the UK or UK corporate structures. Fraud proceeds were typically cashed out after moving through two to five mule accounts, most often at the second, and some accounts were used repeatedly, which points to organized networks.
The age data will make a few risk models uncomfortable. According to FinTech Global's coverage, people aged 26 to 39 account for the most closures (91,073), but 40-to-49-year-olds are growing fastest, from 25,760 to 37,274. Personal accounts made up roughly 92% of closures across the three years.
This Week in Fraud is a publication for fintech operators, fraud teams, and risk professionals. Have a tip or story? Reply to this email or drop Nick Holland [email protected] a note directly.



