
Fraudology Podcast with Karisse Hendrick · 2026-06-30 · 39 min
Key moments - from our scoring
Substance score
48 / 100
Five dimensions, 20 points each
The Visa-OpenAI partnership announced in June 2024 marks a watershed moment for agentic commerce - where AI agents autonomously complete purchases on behalf of users. While presented as secure and seamless, the infrastructure creates dangerous blind spots for merchants. Hendrick identifies three critical vulnerabilities: merchants currently have no way to identify whether a transaction was initiated by an AI agent (no merchant-side detection tools exist yet beyond Sardine and one other vendor); the Visa chargeback liability framework hasn't been updated to reflect agent-initiated transactions, meaning merchants absorb all losses when agents make mistakes or purchase wrong items; and merchants cannot dispute these chargebacks through compelling evidence 3.0 standards since the cardholder is one-removed from the actual purchase decision. Most immediately dangerous: AI agents trained to find the lowest prices will be targeted by sophisticated phishing sites offering counterfeit goods. Fraudsters can now clone functional e-commerce websites complete with payment processing, and agents will route traffic and payment data to these fakes. Without new liability rules shifting responsibility to OpenAI and other agentic platforms, or mandatory payment tokenization and agent identification at the Visa rails level, merchants face astronomical losses from chargebacks they cannot prevent or challenge.
Visa and OpenAI are integrating Visa's payment rails into ChatGPT experiences, allowing AI agents to initiate transactions directly. Merchants receive payment through standard Visa infrastructure, but there are no new fraud monitoring capabilities, liability frameworks, or chargeback representment tools specific to agent-initiated transactions.
Currently, merchants bear 100% of the liability under existing card-not-present chargeback rules. There are no special provisions in Visa's framework to shift liability to OpenAI or other agentic platforms, even when the agent alone caused the error (wrong item, wrong quantity, developer mistake).
Merchants currently have no way to identify agentic transactions in real-time payment flows. Only Sardine and one other vendor can detect agent-initiated orders post-transaction; Visa provides no merchant-side detection tools or special transaction indicators for AI-initiated purchases.
AI agents are programmed to hunt for the lowest prices, making them targets for cloned phishing websites offering counterfeit goods or stealing payment data. Fraudsters can now create fully functional duplicate e-commerce sites with working checkouts, and agents will automatically route traffic and cardholder information to these fakes.
VAMP (Visa Account Management Program) fines merchants $8 per TC 40 per chargeback once the ratio exceeds 1.5% in a month - with no grace period. A spike in agentic chargebacks merchants cannot prevent or dispute can immediately trigger these fines.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers several genuinely useful operational insights - VAMP's immediate fine structure, TC40 attribution by descriptor rather than MID, and the chargeback representment gap for agentic transactions - that practitioners would not find in mainstream coverage. However, roughly a quarter of the runtime is conference promotion, a Sardine ad, and filler anecdotes, pulling the density down significantly.
VAMP is not cheap. And there's no, there's no trial month. There's no safety month. That used to be that you had two to three months before the VFMPs or VDMPs would charge fines. That doesn't happen anymore. There's now it's the first month that you go over that 1.5%, you occur $8 per TC, 40 and per chargeback.
TC 40s are based on the descriptor, not the merchant ID. So if this fake company selling $20 Nikes created a website called Nike123 chances are the real Nike would get the TC 40s for those.
The connection between agentic AI's price-optimisation behaviour and its susceptibility to phishing/clone sites - and the downstream VAMP consequence for innocent legitimate merchants - is a specific and non-obvious chain of reasoning. However, the bulk of the episode is reporting on an announced partnership and reading a Guardian article aloud, limiting how much original thinking is actually present.
agents will be trained to look for the best price...those phishing websites are known for giving the best prices ever
my hope in asterisk is is that visa and OpenAI rework the liability for these circumstances to require the agentic platform OpenAI in this case to take financial liability for agent mistakes
This is a solo episode; the host is a practitioner-level fraud consultant who runs the Merchant Fraud Alliance and clearly has real industry relationships (Visa contacts, Sardine CEO access), but she is not an operator who has run fraud at enterprise scale, and there is no guest to evaluate on seniority or relevance.
I got a one on one demo from Supes, actually, uh, the CEO of Sardine while at a conference this spring on exactly how they can detect an AI agent.
I have been in touch with my contact at Visa, uh, who said, you know, this is such a new thing. They don't know if this has been considered yet, but that they were going to do their best to run it up the flagpole
There are useful concrete specifics - the $8-per-TC40 VAMP fine, the 1.5% threshold, the 10-day acquirer notification window, Sardine named as a detection tool, and Matt Vega cloning a MasterCard site in five minutes - but the lone merchant case study is vague ('pretty big dollar transaction') and several claims about scale of future harm are asserted without data.
first month that you go over that 1.5%, you occur $8 per TC, 40 and per chargeback
he cloned MasterCard's website right in front of me as we were talking and recording the podcast, uh, he did it in about five minutes
As a solo monologue there is no interviewer craft to evaluate - no questions, no follow-ups, and no productive challenge. The host organises her argument coherently and does call out her own speculative limits, but the format inherently precludes the conversational dynamics this dimension rewards, and there is notable rambling and self-promotion diluting focus.
I'm going to go ahead and read the LinkedIn post that I wrote about it to start, uh, just because I think I did a pretty good job of summarizing this.
My grandmother used to say if I ever said something wasn't fair, she would say, you know, the fair only comes once a year, meaning that nothing's fair and the county fair is the only thing that exists.
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of Fraudology, Karisse Hendrick provides a comprehensive debrief following the massive shifts in the world of artificial intelligence and digital fraud. Karisse shares her highlights and lowlights from navigating the industry's rapid evolution, cutting through the future-looking hype to provide practical insights for fraud and payments professionals. The conversation explores the evolving mechanics of Agentic AI in commerce, detailing how partnerships like the new Visa and OpenAI infrastructure are designed to make AI commerce a reality. Karisse provides an inside look at why OpenAI previously shelved its original agentic project to avoid becoming a merchant of record, shifting away from full structural ownership due to complex liability rules and low initial adoption. We also explore the "hot topics" dominating the fraud landscape today: The VAMP Threshold "Cliff": How Visa’s monitoring programs offer no "trial" or "safety" months anymore, immediately penalizing merchants the first month they cross thresholds with instant fines and fees per chargeback and TC40.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Welcome to Fraudology Podcast, where we dive
Speaker B: into the science and study of online fraud from the perspective of an E commerce fraud fighter. I'm Carice Hendrick.
Speaker A: Welcome back to the Fraudology Podcast. This will be another solo episode. I think if you've been listening along in chronological order, you can guess that I've been kind of doing every other, uh, one with a guest and one on my own today. There's a topic that I want to dive into, and that is AI, um, agentic commerce specifically. So, uh, purchases made by AI agents in the online world. And if you work for a bank and you're like, this is for merchants, hold tight because this will impact you as well. And if you're from a card brand, please listen because we need your help. Before that, I'm just going to do a reminder that the Merchant Fraud alliance first inaugural conference. So I guess that's a double, double meaning there. So, inaugural conference is October 6th and 7th in Chicago. We have some pretty, uh, optimistic goals for how many people are going to come, but we also have some really killer ambassadors that have from companies such as Booking and Best Buy and Walmart and Google and so many more that I can think of that have stepped up to be part of the planning committee and the board essentially and have also pledged to come to the conference. So, uh, we have a great group of people that are coming already. They'll also. A lot of them will be speaking as well. We just met for a second time this past week, going through all the topics and starting to address some of the speakers. And we have, you know, someone from PlayStation, someone from Booking talking about how they're integrating AI into, uh, fighting fraud and training their analysts to utilize AI in different ways, whether it's for data analytics, reporting dashboards, things like that. We have someone from Best Buy talking about working cross functionally with other departments. She literally is the best person, I think, that could speak to this topic. A, uh, good friend of the podcast, Holly Sandberg, is going to be talking about creating an executive score chart or scorecard for your executives and really explaining what managing up and really quantifying fraud for them in ways that they understand. I had a chance to see her speak on this topic at the Assertify user conference last month, and it was really good. So those are just off the top of my head, a few of the sessions I can think of that you'll want to be there for. We're also doing an AI bootcamp on October 5, the day before the conference starts. And that's only open to people that register. You know, it's in the order you register. Uh, we're going to have about 50 slots, so I know that there's a few more spaces open. So make sure that you register soon. And if you're listening to this before July 1st, tickets are only 4.95 for merchants. We aren't selling vendor tickets. Uh, we have a select number of sponsor companies that are attending, but we won't be selling vendor tickets. This is for merchants only. Okay, that's enough of a plug for my conference. But that is literally all that I'm like breathing and doing right now. So I had to give a little bit of an update. Uh, I want people to show up. I want it to be as good of an experience as it can be for everyone. Uh, if you have known me at all. I try to make sure that everyone gets their time and their money's worth of anything that I work on. And this podcast is a good example. It's free and I still give out a lot of information. So, you know, just assume that the conference will be even better than a podcast episode. All right, I really am going to turn to agentic commerce now. I've, you know, I've had Robbie McDermott on the podcast talking about liability for agentic commerce. I've talked a little bit about it here and there, but I've kind of shied away from it for a few reasons. One is there was a conference in the spring that really focused a lot on agentic commerce, but there wasn't any news. It was all kind of pontification and future forward looking. And you know, the feedback I heard from almost everyone I talked to about it was there was no, there were no takeaways, uh, because we just aren't there yet. Then we saw OpenAI scrap their project. And I think, I think I made mention of that on the podcast on a solo episode a few weeks ago where they scrapped their project for, I can't remember what they called it, but it was, uh, where they had AI agents finish a purchase. So they were going to be the merchant of record. And I think they realized that liability rules as well as other issues. They didn't want to get involved, so, uh, they scrapped that project. I think also adoption was really low. So all of those things combined. I haven't really talked about it because I haven't felt like there's been a lot to say. I haven't known if it's actually going to be a thing. Yes, it's been talked about a lot, but it, you know is going to be adopted by more than 5% of consumers. Uh, those have been my open questions. But then an announcement came out about two weeks ago that made me think, okay, this is probably happening. Um, I'm going to go ahead and read the LinkedIn post that I wrote about it to start, uh, just because I think I did a pretty good job of summarizing this. Last week it was announced that Visa and OpenAI are partnering to build infrastructure designed to make AI commerce secure, scalable and seamless. That's in quotations. Those are their words in this statement. Visa also said that Visa's payment capabilities will be integrated into OpenAI experiences, giving developers and merchants a streamlined way to accept Visa payments initiated by AI agents. They also said Visa will deliver the underlying global network payment tokenization authorization, agent identification and fraud monitoring infrastructure to support secure and trusted AI initiated transactions. So I'll stop there from my post and just say that, you know, the fraud monitoring isn't necessarily from the merchant perspective, it's just the general fraud monitoring that Visa does. Um, you know, looking for card testing, that type of thing. Um, also on the issuer side, their fraud monitoring, I, it doesn't say that Visa is doing anything new as far as fraud monitoring. So I wouldn't take that statement to mean, oh, they're going to do fraud monitoring on agentic transactions so I don't have to. I would not at all read in that into it. So now that Visa and OpenAI, who is behind ChatGPT, are partnering with each other. That's a lot of power. That's a lot of brand power, but also just a lot of. They're lending the visa rails to OpenAI transactions, to transactions that are initiated in ChatGPT. So some of the use cases would be if I wanted to book the best flight for, for the cheapest price. Uh, but I didn't wanna search all of the online travel agency sites, I didn't wanna use Google. And maybe I had a little time, so maybe I had a week. I could create a prompt in ChatGPT to ask it to create an agent to look for the best airline price from Seattle, Washington to San Francisco, California. And uh, you know, you can set as many parameters as you want, right? Like I want my departure time to be after 10am, I want my arrival time to be before 9pm I want, you know, a window seat, I want an aisle seat. But a lot of people aren't going to do all of those qualifiers. You can, but they may not. So, you know, that opens it up to a lot of issues. Right? What if my, you know, and then my final prompt for that would be, you know, find the best rate in the next week and book it on my behalf. Here's my card information. Here's, you know, my TSA pre check number or whatever you need to do, just do it for me. Others would be around, you know, sale prices. The best, you know, best deal on a sweater or a pair of shoes, or what if there's a drop coming of new sneakers. Uh, it's kind of similar to a bot, but it's different where you're directing an agent to do it for you rather than a bot, so it can adapt more. There's a lot of issues that I see with this and we're going to talk about another issue, uh, after I talk about this first one. But from a chargeback perspective, this was really scary to me because, uh, at the end of the day, the Visa infrastructure does not support agentia commerce chargebacks. There's no process for them, there's no verbiage for them. There's nothing. There are chargebacks that are going through right now, uh, to merchants that are very obviously, you know, were initiated by an agent. Either the, you know, cardholder says so in their statement or the merchant can tell it was created by an agent and not a person. There's no guidance for. So the merchant is getting those chargebacks. The liability is working the way it always has where it's. If it's card not present, it's on the merchant. There's no additional liability. You know, hey, if it's, if the agent makes a mistake or it books something that the cardholder didn't want it to, or it orders 20 items instead of two, all of those different scenarios, there's no, uh, additional guidance for where liability goes. So it falls on the merchant. And I'll read what I wrote in my LinkedIn post and then I'll go a little bit further about this too. So I said there are two things I want to highlight about this announcement from the merchant perspective. Number one, and this is a little, you know, a little bit what I just said. But there are no stated changes to the chargeback liability framework for CMP transactions. This most likely means that when mistakes are made, like an agent orders the wrong thing or too much of one thing, these cardholder disputes will fall to the merchant to repay to the consumer. Even if there was nothing a merchant could have done to know it was a mistake or prevent it at the time of a transaction. The reason I said that Is the whole point of the CMP liability rules has been, well, merchants should be able to detect fraudulent transactions before they occur, so therefore they have the liability in this case. It's similar to what we call friendly fraud. Right. If the cardholder, uh, information validates, and it looks like the cardholder initiated the transaction, and the cardholder was involved in the transaction, they initiated the agent, that type of thing, it still falls on the merchant. Even though there was nothing, aside of having superpowers or a psychic on hand, there's nothing they could have done to say, oh, that one order is going to come back as a chargeback, or, you know, the cardholder told the agent to buy two, not 20. So we should cancel 18 of these. There's nothing a merchant can do. However, they're still liable. So I said we also need to consider that more chargebacks for merchants equals a higher risk for vamp infractions. This could mean more fines, fees, and issues with acquirers that are outside the scope of prevention for C P merchants. So with vamp, uh, which man did we have a good webinar with anoush at? Ah, Visa for mfa. It was a couple weeks ago. I think it's available still through about fraud. I actually haven't asked PJ or Ronald about that, but it was recorded. I know that it was so good. And we're actually going to have a second one in August because there were just. There was so much engagement from the audience that we didn't get through everything that we needed to or wanted to, um, or that the merchants had asked us to. Anyway, that's a side note about vamp, but, you know, vamp is real and your acquirers are now managing your risk. And the more chargebacks you have, the higher risk for vamp infractions. Vamp is not cheap. And there's no, there's no trial month. There's no safety month. That used to be that you had two to three months before the VFMPs or VDMPs would charge fines. That doesn't happen anymore. There's now it's the first month that you go over that 1.5%, you occur $8 per TC, 40 and per chargeback. And that adds up real quick. So there's, you know, there's no wiggle room. There's no safety time. It's just instant. So it is something to be considered. Uh, but then I put my take and I said my hope in asterisk is is that visa and OpenAI rework the liability for these circumstances to require the agentic platform OpenAI in this case to take financial liability for agent mistakes. Do I know that that is extremely optimistic and probably not likely. Yeah, I do, but I at least need to call it out. I felt the need to call it out and say, hey, merchants shouldn't be responsible for agentic mistakes. What if it's a mistake on the developer side? You know, there's nothing a merchant could have done to stop that, but yet now they have to pay back the transaction. Doesn't make a lot of sense. Um, doesn't seem fair, which, I mean, the chargeback system has never been fair. My grandmother used to say if I ever said something wasn't fair, she would say, you know, the fair only comes once a year, meaning that nothing's fair and the county fair is the only thing that exists. I know the chargeback system isn't fair, but we're opening a new channel. I just saw a good presentation from a startup recently where they talked about, you know, we have the E Commerce channel or the web channel, we have the mobile channel and now we're going to have the agentic channel. And the agentic channel should go through a different flow because it doesn't, you know, recognize the website in HTML format the way that human eyes do. And you know, they often will hallucinate where a button is or it will, you know, order the wrong thing because they think that button's over here or it just. Agents can't navigate websites the way that humans can. And so there needs to be a more agent friendly site where maybe humans can't understand it, but agents will know exactly what to do and where to go. Um, I thought it was an interesting take because then also your fraud and risk decisions would be different as well if you are able to parse out the Agentix transactions into their own bucket and look at the data on those. So, yeah, that is something to, you know, consider. Right now we don't have an agentic channel. There is a company trying to build one right now. Visa doesn't have any way for merchants to identify in the payment flow that a transaction was initiated by an agent. Maybe that will change once their partnership with OpenAI goes through, but right now they don't. Uh, I only know of a, maybe two vendors on the merchant side that are really able to identify agentic orders. Most of the merchants using legacy tools, if not all of them, have no way of, you know, they've done so many tests, transactions on every different agentic site and then, you know, looked on the back end for any identifiers of what you Know how they can tell that an order was placed through ChatGPT and timing doesn't matter anymore because these agentic platforms are trying to mimic consumer behavior so the transactions are approved so they aren't moving fast. Otherwise they get caught up in bot detection. Uh, there's no device difference. They're using real device IDs and uh, emulators. There's no way right now to identify it. Unless you have maybe one of two tools that are still pretty new. Yes, Sardine is one of them. I got a one on one demo from Supes, actually, uh, the CEO of Sardine while at a conference this spring on exactly how they can detect an AI agent. And it was really fascinating. But I know of another company that is able to do that as well. But my whole point being right now there's no way to tell if it was an agentic transaction on the merchant side. And there's no additional liability shift for merchants when errors occur or when fraud occurs or anything like that. And that needs to be looked at. My other concern, and this is, this kind of, this goes hand in hand, right? Because if you don't know that an agentic transaction is coming in, you can't do anything to stop it or prevent it. There are currently no provisions for chargeback representment by a merchant. When an agent initiates a transaction on behalf of a cardholder, a cardholder can change their mind, claim fraud, or state that the wrong item was purchased. And there is no way for merchants to dispute these claims or reverse the debited funds. Merchants are currently receiving these chargebacks and are automatically losing them. Once OpenAI and visa partner up, these losses will skyrocket. My take before this partnership goes live is that it's imperative that Visa and MasterCard as well. But right now it's about Visa. At least give merchants an opportunity to prove that these purchases were not fraudulent and that the cardholder authorized their agent to make this purchase. If changes aren't made to the liability structure of CMP transactions and to the ability for merchants to dispute chargebacks, the financial losses will be astronomical. So m, yeah, that's some big news. But you know, if you have a Visa rep that you work with, bring this up to them, ask them what they're doing about it. I have been in touch with my contact at Visa, uh, who said, you know, this is such a new thing. They don't know if this has been considered yet, but that they were going to do their best to run it up the flagpole for consideration. I don't know if there will be any motivation to change these things, if there's not a little pressure. So, um, you know, be aware that this is the case. I already know of one merchant that lost a pretty big dollar transaction. Uh, when the cardholder said I directed my agent to the purchase, but I changed my mind. That was in the cardholder documentation of the chargeback. The merchant highlighted that along with their terms of service and you know, all the other things that were required for that specific chargeback reason code. And they were given an automatic decline because this is agentic commerce and there's. It didn't fulfill the compelling evidence 3.0 requirements. You know, an agentic transaction may not even fulfill the C2.0 requirements, uh, because the cardholder technically wasn't involved, but they directed it. So the cardholder is one removed from the transaction now, which makes it difficult.
Speaker B: This episode is brought to you by Sardine. One of the things I enjoy about working closely with Sardine is the ability to learn more about identifying and preventing fraud and scams. For instance, I've learned that the best way for a bank or fintech to detect a scam is to look at the the five seconds before a transaction. Most fraud and AML controls focus on the transaction itself. But it's those things immediately before it that help you stop scams. That's in the pre auth signals. That's why user, device and behavior are so crucial. In those five seconds you can identify if another user is driving that device from a remote desktop access. Or you can learn that the phone making a transaction is upside down and not not actually in use. You can also identify the behavior of the person behind the device and what their true intentions are. It's those little details that all add up. For more information about this or any of the other products within Sardine, go to www.sardine.AI to read more information or to request a one on one product account.
Speaker A: So I'd love to know your thoughts. Um, other than, oh crap, um,
Speaker B: if
Speaker A: you're on the banking side, the issuer side, be aware of this. I would love for you to not forward these on to merchants when you see mention of an agent. But obviously I know you have cardholders to appease and everything else. Um, that's why I really do think that the agentic platform should have liability on these transactions, especially for errors. But I don't know how they would be able to do that because obviously OpenAI and any other agentic platform is going to lobby to keep playability the way it is. So that is something to be aware of. As we start talking about agentic AI, those are two concerns and two things that I think we all need to be aware of. There is no liability shift for merchants. It's always on them, and there's no way for them to win those transactions because there's no provisions in the chargeback documentation about a Gentex transaction. Obviously, agentic commerce is moving very quickly. There wasn't even a lot to report in March, you know, so now there is right now in June. We're like, oh, okay, Visa and ChatGPT are gonna, you know, join forces. That sounds big. MasterCard has made a similar announcement, but not with a large. It's not in partnership. It's like their own thing. Uh, and I mentioned a few weeks ago another solo podcast that amex has said that if a cardholder uses their agents and their Rails for a transaction, that the cardholder won't be liable for that. They don't say that it won't be turned on to the merchant. They just say that there's consumer protections on those transactions. So I don't know if they're planning to take the hit or pass those on, but, you know, the ball is moving already, is what I'm trying to say. So along that note, another issue that I see for agentic commerce, and this was something I thought of kind of right away when I started wrapping my head around what agent ecommerce is, is that agents will be trained to look for the best price or they'll be, you know, trained to look for the best location or the best timing or, you know, whatever it is. If it's for concert tickets, it's the, uh, you know, the best seating, it's the best, you know, whatever those things are, they're trained to look for those. But I would say the majority of them are looking for a deal. There are a lot of fishing websites out there, especially because of AI, because it's so easy. Matt Vega, um, on the podcast a month or two ago, talking about how easy it is to clone a website, he cloned MasterCard's website right in front of me as we were talking and recording the podcast, uh, he did it in about five minutes. And he was able to harvest people's information off of that. So had he made that website go live, had he, you know, attached it to Google SEO or other search engine optimization for other browsers, he could advertise and people could think, oh, that's MasterCard's website. I have no problem putting in all of my information, but Then later down the line, their identity is stolen or their credit card is used. So, you know, it's easy to make fake websites. We know that fraudsters love to create fake websites and replicate merchants. So duplicate their websites. So say, I'm not going to pick on one particular company, but like Merchant A, for whatever reason, sorry, I couldn't come up with like a, uh, creative name that wasn't real. Merchant A has, you know, sells furniture and they have, you know, proprietary photographs of all their furniture on their website. They have, you know, it's, it's their website and then it allows consumers to interact with it, to put things in their cart, to visit their cart, to, you know, then check out. Fraudsters can now duplicate not only the. They used to be able to duplicate the pictures they would copy and paste, they would scrape the websites, et cetera. But now they can make those functional. They can say, hey, make it possible for a cardholder to order this item and purchase this item. And then chances are they're harvesting credit card numbers and the person that, you know, placed the order never gets the item. Or if they do, it's something that's really fake. It's not the real item that they thought they were ordering. Well, with agentic commerce, those agents are looking for the best deal possible. Those phishing websites are known for giving the best prices ever. I think we've all seen, you know, especially around drops or holidays, uh, big purchase times. I'm sure we've all seen Facebook ads or Instagram ads for $20 Nikes or, you know, $50 airline tickets or whatever it is. You just have to click their website. Well, chances are that website isn't real. And it's going to look like it's coming from Costco or United Airlines, or it's going to look like it's coming from Nike themselves, but it's not. So what's going to happen is a lot of those agents are going to choose the lowest price, which is going to go to a fake website. A fake website that now has actions, that can now collect credit cards, that can sometimes, in some cases process credit cards. That's going to cause a lot of fraud. It's going to cause a lot of issues. The types of issues it'll cause are at your call center, uh, you'll see more calls with people saying, hey, I ordered this item on your website, but it never came, or I got a pair of fake Nikes instead of real ones or whatever it is that is going to cause, you know, going to take time for your customer service to research it because there won't be an order on file for that cardholder and the cardholder will be really confused because they're very certain that they made the purchase on your website. The other issue it has is for TC 40s. Uh, TC 40s are based on the descriptor, not the merchant ID. So if this fake company selling $20 Nikes created a website called Nike123 chances are the real Nike would get the TC 40s for those. And that adds up to their vamp very quickly. They would get the TC 40s and the chargebacks for those. Now Visa does allow a 10 day window between the time that your acquirer is notified that you're on the vamp list. So it's a ticking clock from when your acquirer was notified, not from when you were notified. But they allow 10 days of grace for you to pull all the reporting and say oh, 430 of these were not for us, they were for a fraudulent descriptor. Um, um, or maybe it's, you know, 2,000 of these were for a fraudulent descriptor. It's Nike 1, 2, 3, not Nike.com sorry to Nike that I'm picking on them. It was just the easiest example I could think of. It happens to every large retailer. So I'm, no one is immune from this. So you know, when the cardholder realizes that they made an place, uh, an order with a fake website, they're going to issue a TC40 because they want their money back. And unfortunately if you don't have the time to manually go through all of the TC or if your acquirer doesn't provide it to you because I know some of you are still in that boat. You can't see the printout or the, you know, the data that says this is not for us, this is for a different company that added on letters after our company name. And uh, you know, it might be Nike Daily sale. It doesn't have to be a number, it can be all kinds of things. But as long as it starts with Nike, they're gonna put it under Nike's, you know, account. And so it is important to dedicate some time when you get, if you are put on vamp to look at those TC 40s and verify that they are coming for your website. But I really believe that as agentic commerce continues to grow, this is going to become a major problem because agents don't have a way of deciphering a legitimate website from a fake one. So they're just looking, if they're just looking at price, they're going to go for the $20 Nikes, either because they were stolen and that's still profit for the fraudster, or more likely, you're not going to get those shoes ever. Uh, but your credit card is going to be stolen down the road or you were charged for those items if the fraudster was able to get a merchant account. And then that means chargebacks. So it's not going on your mid. It's not going on your, you know, you, you won't be responsible for that chargeback amount. That's the good news. But for vamp counts, those will be applied and the only way to take them out is to. Very quickly, when you're notified that you're on vamp, look through every single CC40 or search for it. Uh, maybe you can use ChatGPT for this. Actually, you know, look for any descriptor that isn't yours and make sure they subtract those from the total. Um, however, it is challenging because acquirers are sitting on these notices. They're not always providing them to the merchant within just a couple days. So it is important to talk to your acquirer and say, hey, if I get on the vamp list and if you're going to find me, how quickly do you notify merchants of that? I need to be notified within two to three business days of when you're notified because I need to be able to highlight these transactions for Visa that shouldn't be under our name. Um, so that's my big overview. But I found an article that talks about this too. And, you know, this has been kind of my. So what I just talked about was kind of my take on it and, like, what I thought would happen. And this, uh, article from the Guardian actually, um, says that I'm right. And like I always say, when it comes to fraud, I don't like to be right necessarily. I don't like to be called the fraud psychic. It's just, you know, those of us that have been fraud for a long time, we know the cause and effect of it and we know, you know, what's going to happen if you change something upstream and how it's going to impact the downstream. So this article is titled Cloned Sites, which is just what I was talking about. The shopping scams that led ChatGPT to fake stores, or that lead, sorry, that lead ChatGPT to fake stores. Buyers are ripped off, assuming online stores were genuine, because they are recommended by an AI tool. You want to buy a new bag and you ask ChatGPT for help, you Always liked Russell and Bromley. So you asked ChatGPT what is popular there at the moment. The AI assistant gives you a crossbody shoulder casual, informal options with the prices listed beside them. You click through from the sources to what looks like the official Russell and Bromley site and buy your new bag, which is conveniently on sale. The item will never arrive, however, you have handed money over to a scammer and your bank details have been harvested through an elaborate fraud where fake sites are created to look convincingly like real retailers. Ask Silver, a scam checking service, says clone sites have been showing up in search results on ChatGPT. The ones it has seen are rip offs off of Russell and Bromley and furniture retailer Dunalin. This, uh, must be in the UK because those are brands I'm not familiar with. Anna Jones of Ask Silver says in this instance it looks like scammers are taking advantage of the fact that Russell and Bromley went into administration in January of 2026 and was absorbed by Next. So there is no longer an official Russell and Bromley website, but potential customers will likely still be searching for it. Louise Baxter, the head of scams team at National Trading Standards, said people should not assume a website is genuine just because it is recommended by an AI tool. And that's the same for uh, browser Internet browsers as well, uh, when they come back with results. You can't assume that all of those websites are real either. Consumers are increasingly turning to AI tools to ask for advice and recommendations, but criminals are adapting just as quickly. The fact that scam websites can appear in AI generated results is worrying and a stark reminder that fraudsters will exploit any new technology that helps them reach potential victims. She said. The Ask Silver research asked chatgpt a general question. What are the popular Russell and Bromley purses and bags? The results include details and prices of different bags, trends and what bag was good for what occasion. Among the sources for the answer were two fraudulent Russell and Bromley sites. These sites look credible. In one case, there are huge discounts, up to 80% offered on a bag. In reality, it is likely that if you buy something fraudsters will make off with your money. The cloned website will often have a similar address to one that you may expect a legitimate store to have. Ask Silver identified the Russell Bromley official and Russell Bromley London, Russell Bromley Online UK and Russell Dash and Dash Bromley as ah, some of the names of the fake sites. The legitimate Russell and Bromley store sits within the next website. So there isn't actually a Russell and Bromley website anymore dedicated to them. What you can do when shopping online, watch out for clone sites by looking at their address. Legitimate UK sites will often use co.ukor.com in the US it would be you know.com um or maybe.co.us sometimes uh, and be aware of extra words in the title such as official or deals. Fraudulent sites will often only take payment by bank transfer which is an immediate red flag and have large discounts on them. Uh, so large fees on them. Go directly to retailers websites when you can rather than following the sources. That's my big suggestion. A spokesperson for Dunelm said we encourage our customers to only engage with our official website www.dunelm.com or via the official Dunelm M app. He said that when the retailer became aware of a fraudulent site it worked hard to ensure its removal as soon as possible. If you find that you have handed over your financial details, reported to bank and report fraud, that's in the uk there's not really a place to report fraud here in the US like that. Next which brought Russell and Bromley in January, said that it was aware of the situation and had been working to have the sites closed down. A spokesperson for ChatGPT said it had removed the fraudulent websites from its search index. Users of the AI tool can report sites that violate its policies through this form that requires consumers to notice that it's fake and that's, you know, the onus shouldn't be on them in my opinion. Uh, this article and its headline were amended on 12 June to remove the suggestion made by a Silver that the large language model powering ChatGPT may have been poisoned. This is a specific term that applies to the manipulation of AI training data rather than AI simply providing false research results and that is it. So basically the website said what I was saying but uh, just a little bit more because you know we're aware of the vamp program and having receiving those TC 40s from those fake sites can be really detrimental uh and can add up and then you can be fined for them. Uh but also the impact on your customer service is, is big. You know they're expecting their item and they are mad at you. They're not mad at some scammer. Uh, they want their money back. Well they can't get it back from you. It's going to be a lot of headaches. So if I were a fraud leader now for an enterprise E commerce I would first notify customer service that this may be happening and explain what's happening. You know that there are most likely scam websites out there, you know that are depicting and look very legitimate to be your website. You know, let them know that's happening. Contact your IT department to have them try to take it down through the DNS servers. That can take a little time, but they can, you know, do what they can there. And then the other thing is, you know, really encourage your consumers as much as you can through messaging and other, you know, maybe creative ways. You know, maybe you meet them on social media, maybe you meet them, you know, you meet them where they are.
Speaker B: Right.
Speaker A: So it's important to educate your consumers that they need to be going to your official website. The challenge is going to be that ChatGPT and other, you know, large language models are going to keep directing their consumers to the lowest price. It would be very good if they had the same type of thing that Google put in place when they had this problem, uh, which is a registry for the legitimate websites and not allowing the fake websites to do much. But the combination of being able to clone a website along with these large language models looking for the best deals tells me that this is going to be a real big problem for E commerce merchants in the next few months and ongoing years. Um, again you won't receive a chargeback for them because it'll be on a different mid if they did charge their card. Uh, but you will receive customer service complaints and you will most likely receive TC 40s that you don't deserve. So those are just two of the things from agent of Commerce that are impacting E commerce fraud today or that will impact E commerce. I would love to hear from you if you feel like I'm missing anything, uh, or if you have any questions or comments about the two topics that I shared today, that's it. That's really all that I wanted to talk about today. We might take a break next week for the US holiday of uh, the 4th of July. I have not decided yet, but that's a possibility. So if you don't see a new episode next week, that's why and then the next episode's gonna be with a really good guest. You're not gonna wanna miss it. We're gonna talk places and market volatility and how market volatility impacts marketplaces in their fraud and abuse. Uh, it'll be really interesting. I, we've already had a pre call and I had a lot of fun geeking out and uh, it's someone that's a friend of mine that I think you guys will all enjoy learning from and hearing from too. So you have that to look forward to. Either next week or the week after. I hope that you are enjoying a great summer if you are in the Northern Hemisphere. And. And, uh, I will look forward to speaking with you more next week.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.