After Bots — a new book by our founder on classifying AI agents. Now available

Get Your Free Copy
← Video Library
/
RSAC 2026
/
Making Fraud Unprofitable
8:46
RSAC 2026

Making Fraud Unprofitable: Frank Teruel on Fraud Deterrence at RSAC 2026

If you make fraud unprofitable, it goes away. If you don't, you make it inevitable.

8:46
March 25, 2026
Moscone Center, San Francisco, CA

Fraud has evolved from simple bots into a fusion of volumetric attacks, agentic AI, and human fraud farms. Arkose Labs COO Frank Teruel breaks down why making fraud economically unprofitable, not just harder to commit, is the only strategy that actually works.

FT
Frank Teruel
COO, Arkose Labs

Frank Teruel serves as Chief Operating Officer of Arkose Labs, leading the company's mission to make fraud economically unprofitable for attackers across every major consumer-facing industry.

Key Takeaways
0:59

How do we create a platform that allows us to identify, challenge, inform, mitigate and ultimately break the model, the business model of the adversary? The reality is, if you make fraud unprofitable, it goes away. If you don't, you make it inevitable.

3:19

That is a very interesting fraud because what happens is the bots get the numbers through aggregators. It's also called international revenue sharing fraud because the carriers in some cases collude with the bad guys, the bad guys split the revenue.

5:09

The way we share data is that mitigation is shared immediately with that bank. No attribution, no customer data, but you're able to stop the attack because you saw that attack migrate across industry.

7:31

It's not a matter of if, it's a matter of when it's gonna hit you. As I said, 90 some odd percent of respondents believe in the next 12 months they'll be hit with an agentic attack. And of that 90%, a small portion feel prepared.

Full Transcript
FT
The New Identity Problem
0:04

We had to explain what bots were back in the day, and that there are good bots and bad bots. It's the same kind of world, just 10 times, maybe 100 times, more complex, accelerated, more sophisticated. If you and I had met 10 years ago, I would have said all that ever matters online is: is Frank really Frank, and is Frank behaving normally in the context of this transaction? Today it's: is Frank really Frank, is this an authorized agent of Frank, and are these two entities behaving in a way that's normal or anomalous? The problem of identity as it relates to the bot world, and agentic in particular, is incredibly more complicated. It's not just a binary human or not, and/or good or not. There's a lot of nuance in there too.

FT
Arkose's Mission: Making Fraud Unprofitable
0:41

I'm the chief operating officer. Arkose Labs is really focused on the idea of fraud deterrence in this new world of a fusion between volumetric bot-driven attacks, agentic agents, human fraud farms, and slow and low human attacks. How do we create a platform that allows us to identify, challenge, inform, mitigate, and ultimately break the business model of the adversary? The reality is, if you make fraud unprofitable, it goes away. If you don't, you make it inevitable. It's the issue of our heritage in bot migrating to a much broader security perspective as it relates to the important flows — new account registrations, logins — those really critical flows for our customers. We represent today the world's largest consumer-facing brands, across every industry: the big banks, the social companies, the two-way marketplaces, the big rideshare companies, technology. That gives us a purview of identity that's very unique, because we get to see these identities across the entirety of the industry, and that helps us inform that mission of making fraud unprofitable.

FT
How Fraud Became an Industry
2:27

The urgency around that became much easier at scale for bots to do their thing, because now they were being enabled through these crime-as-a-service platforms. The minute it became a business, those platforms had an imperative for continued product-market fit — they had to sell something that works. So they became multi-billion-dollar businesses, and the innovation started to flow. The last piece that was missing was how do they communicate — Discord, Telegram, the social channels. Now you had everything you needed to do fraud at scale. If you look at the last maybe five years, that's been the big evolution: the acceleration of fraud at scale using these platforms.

FT
The Three Biggest Attacks We've Seen
3:08

Let me give you the three biggest kinds of attacks we've seen in the last year. SMS toll fraud: you go to register for an account, enter your number, they send you a code, and you use that code to complete your onboarding. That is a very interesting fraud because the bots get the numbers through aggregators — it's also called international revenue sharing fraud, because the carriers in some cases collude with the bad guys and split the revenue. You get into a flow and start signing up for accounts en masse. Say it's your favorite rideshare company — you start pounding this thing, and the minute it hits submit, that toll has run. That money goes back through the provider, all the way back to the carrier, and ultimately to the person that provisioned the numbers. That is billions of dollars a year, and it's all around account registration. What's interesting about that one is it never gets to the security people, because they never come back — they don't try to take over the account, they simply cash out and go. Fake account registrations are also really big right now — you can watch these things register for accounts that sit dormant, everything from pig-butchering scams, where I register with a dating site, sit on the account, slowly develop a reputation, and ultimately use that to defraud someone who thinks they're in a relationship, all the way to linking loyalty programs.

FT
Federated Threat Intelligence Across Industries
4:33

Imagine I'm a bank, and all I see is the bank stuff — I may identify a bad customer in banking, but I don't know anything else about that individual or entity. What we get to do, because we're across multiple industries and the entire digital journey — technology companies, shared marketplace companies, gaming companies, travel companies — is see a consumer across this entire view of the industry. So a threat develops somewhere, say in gaming — one of our big gaming companies sees an attack, real fraud in there. That's the Petri dish for that stuff. The threat develops there, you write a mitigation for it, and that same threat manifests itself at a bank a day or two later. The way we share data is that mitigation is shared immediately with that bank — no attribution, no customer data — but you're able to stop the attack because you saw it migrate across industry. So sharing that data becomes hypercritical, and not just the data, but also the risk associated with the transaction: why did we mark it as risky, what was it about that transaction across device, session, and behavior. We see a threat, we write a challenge to it — we call them telltales — a global mitigation. That threat now works its way to a bank, a rideshare company, a travel company, or a ticketing company, and you can apply that same mitigation to it in real time. That's really the value of having federated threat intelligence, because you get ahead of the attacks.

FT
Advice for CISOs
6:00

Two things I would say to CISOs. Number one, start with the fact that today they understand they're unprepared — 75% of the people we just surveyed don't know how to do attribution, they don't know whether it's a bot or a human, they don't know what to do. So first, look at those high-value flows that are likely to be affected: who's registering for accounts, what are they doing in those accounts. Then realize, across all these use cases, how do we share data to understand what's happening, and work with somebody who can identify risk up front and help you mitigate it, not just tell you about it. What are the signals? Are sellables going through the roof with no associated increase in new customer base, or a spike in transaction abandonment where something's clearly going on? Look at volumes of accounts created, and accounts being linked — who's involved in those decisions, and who are you relying on to trust that the linkage is legitimate? You've got to look at the entire surface and ask where those areas could be exploited in real time, and find vendors that are in the fight with this thing — it's not a matter of if, it's a matter of when it's going to hit you. Ninety-some-odd percent of respondents believe they'll be hit with an agentic attack in the next 12 months, and of that 90%, only a small portion feel prepared. So create fusion — we were talking to a bank recently that created internal fusion teams, which they define as data-sharing organizations. If you're a CISO and someone says we're launching this campaign for new registrations, ask how, does it involve SMS, who's paying the bill. Start identifying those signals in advance, and recognize that agentic is here, it's learning, it's getting better. You've got to partner — if your important workflows aren't agentic-proof today, you're already behind. The CISO needs to work alongside the AppSec team, and fraud and loss prevention. Partner with companies that have the data and the platform approach, that are willing to step in and help you mitigate, not just inform you, and create that fusion — federated data from the outside, internal data sharing — so that within the organization, nothing falls through the cracks.

Up next
Want to talk through your agentic traffic policy?
Our team can walk through how intent-based detection applies to your specific fraud vectors.
Talk to Arkose Labs