Council Post: Merchants Deserve More From The Fraud Tools They're Paying For
Wayne Hamilton is CEO and co-founder of pmtbox, a payments and risk platform built to get ahead of fraud instead of reacting to it.

getty
Payment card fraud reached $33.41 billion in 2024, with projections hitting $41 billion by 2030, according to the Nilson Report.
That threat is accelerating. The Merchant Risk Council’s 2026 fraud report found that 63% of merchants are exploring or implementing agentic AI payments, payments an AI agent initiates on a customer’s behalf, even as 62% report rising first-party misuse.
Tools built for a slower threat are running out of runway. Nearly every payment processor sells a fraud tool, and nearly every one of them markets it as solved. It often isn’t. Merchants sign up, fraud slips through anyway, and the vendor walks away clean. The merchant pays. Funds get held in reserve, accounts get flagged, and in the worst cases, the account gets shut down entirely, with no explanation of what went wrong or why the tool failed. When fraud gets through, the vendor takes no responsibility. The merchant does, financially and reputationally. Systems keep stacking, and merchants are afraid to rip any out.
Here’s where I think most fraud tools fall short today, and what merchants should ask before signing the next contract:
Fragmented Workflows And Distributed Accountability Are Self-Defeating
Fraud tools today sit as a separate layer bolted onto a merchant account, a shopping cart solution or a payment gateway, acting as a single gatekeeper at checkout with little data sharing between systems, so merchants end up cobbling that data together themselves. Single-purpose tools for chargeback recovery or identity verification often operate in isolation, blind to the broader transaction context.
For example, according to the Merchant Risk Council’s report linked above, the average merchant runs 3.9 payment gateways and 3.2 acquiring banks, each with its own fraud signals that don’t talk to each other.
Fragmentation creates a second problem. Someone has to correctly label the outcomes, fraud or false alarm and feed that back into the systems. That takes real integration work and ongoing human review most merchants don’t expect. Get it wrong, and the system trains on bad information and gets worse over time.
Narrowly focused vendors, each handling one piece of the problem with no stake in the outcome, create the blind spots for the merchants that thieves feast on.
Models Are Trained To Predict Noise Rather Than Signal
Any fraud model separates good outcomes from bad ones. Focus on the bad ones, and predictors keep multiplying, needing constant updates as fraud evolves. Focus on the good ones instead, and the model stays simple enough to understand, not a black box. When black boxes fail, you pay twice: once for the tool and once for the team fixing misses.
This matters most when the thing you’re trying to predict is human behavior. While self-driving cars learn from static obstacles, fraud models must navigate environments where every variable is actively attempting to deceive the system.
You can see the same principle in the strongest AI systems being built today. They’re trained on huge amounts of data but deliberately constrained to avoid overfitting to noise. Many commercial fraud tools lean on this older approach, chasing bad patterns instead of modeling good ones. That’s a big part of why so many turn into expensive black boxes that never live up to their promise.
Merchants evaluating a fraud vendor should ask directly whether the model is built to recognize legitimate customer behavior or is mainly trying to catch known bad patterns; the second approach tends to fall a step behind whatever fraudsters try next.
A Surprising Amount Of This Runs On Very Old Infrastructure
Much of the back-end infrastructure behind U.S. card payments has been in place for decades, and most fraud tools run on top of that same aging backbone regardless of who sells them. Merchants can’t wait for that backbone to modernize, so the real question is how much a provider actually does with the data those old systems already produce. Two providers plugged into the same aging infrastructure can pull very different signals out of it, depending on how much of that data they actually use.
Ask a fraud vendor directly what they’re doing with the data their infrastructure already hands them, and how much of it is going unused.
Buying The Software Doesn’t Mean The Work Is Done
Bringing on a fraud tool forces merchants to become experts: configuring rules, interpreting flags and managing software sold as “plug-and-play.” The same Merchant Risk Council report found 56% of merchants expect spending on fraud tools to increase over the next two years, and 48% expect spending on staff to increase.
When a provider hands over a dashboard and a rulebook and calls it a solution, the work of preventing fraud has shifted onto the business least equipped to carry it.
AI Is Moving Faster Than Most Fraud Tools Can Keep Up With
AI helps bad actors test stolen credentials, generate synthetic identities and probe for weaknesses faster than today’s fraud teams can match.
Captcha once felt like a reasonable checkpoint. On its own, it’s now an increasingly weak signal against fraud that’s being generated and adapted by AI in real time.
Merchants evaluating a fraud vendor should ask what’s changed in their model or approach over the past year to account for AI-driven attacks.
Questions Worth Asking Before You Sign
Ask these questions before you sign the next contract. A vague answer to any of them is your answer.
1. Does your fraud tool read from our actual payment and transaction data, or does it operate separately from it?
2. Is your model built to recognize what legitimate customer behavior looks like, or is it mainly trying to catch known bad patterns?
3. If fraud gets through, what happens to our account, and who’s responsible?
4. How much ongoing configuration and management will our team realistically need to take on?
5. What have you changed this year to keep pace with AI-driven fraud?
Fraud tools aren’t worthless, but too many merchants discover their limitations the hard way. Ask these questions before you are the one holding the bag.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?