r/FraudPrevention

Huge fraudulent payment to PayPal

I logged into my online banking app to check my account as I do every two days and my heart stopped—2/3 of my money was missing. I looked through transactions and two days ago, a massive (like multiple thousands of dollars) debit went to a “PayPal purchase.” I obviously didn’t make that purchase and I do not have a PayPal account affiliated with that bank account. Called my bank immediately—all they could do was tell me that the payment was made through “online banking” and that they would file a claim. They have 45 days to review the claim—during which, I wouldn’t get any of that money back. The bank froze that account and I had to open a new account where I transferred what is left of my money to.

I filed a police report. I’m trying to file a claim with PayPal which so far has been impossible to do because the payment was not made through a PayPal account.

I asked my bank how this could happen—this amount of money being debited without any sort of approval. They said it could happen if someone had my bank account number, routing number and address.

I find this terrifying. I may not be able to pay my bills and I may not see this money again. Has anyone experienced anything similar?

I’ve changed all passwords, etc

reddit.com
▲ 6 r/FraudPrevention+1 crossposts

When your "customer" is an agent, most of our fraud defense quietly stops working. What replaces it?

I spent about eight years inside credit card authorization. eCommerce and not POS. Something about agentic checkout has been bothering me and I want to know whether anyone here has a better answer than I do.

Take the controls we actually run. Device fingerprinting. Behavioral biometrics, meaning mouse movement, typing cadence, how long someone sits on the CVV field (which always gets me and I have to yell out to my kids to give this to me quick). Velocity rules. 3DS step-up. One-time passcodes to a phone. Risk models trained on how real people move through a checkout.

Every one of those infers that a human is present and behaving normally. None of them verifies that the purchase was wanted.

That held for thirty years because a human was always eventually there. Even card-not-present, someone typed the number. Presence was a decent proxy for intent, so nobody had to separate the two.

Agentic checkout removes the human on purpose. The signals then go one of two ways. Some disappear, because there is no mouse movement and no hesitation to measure. The rest get emulated, and emulated cleanly, because an agent produces consistent timing and a stable device signature every single run. A model trained to catch the anomalous human has nothing to catch when there is no human and no anomaly. A compromised agent looks the same as a working one.

I have been calling this the presence assumption. Authenticating the human, treated as though it authorized the transaction.

What I cannot resolve is what carries the decision once presence is gone. Options I keep seeing, and my problem with each:

  • Agent identity and attestation. Tells you which agent is calling. Says nothing about whether this purchase sits inside what the person asked for.
  • Merchant-side allowlists. Do not travel, and agents shop across merchants.
  • Spend caps at the card. Blunt, and they do not survive an agent splitting a purchase.
  • Post-hoc dispute. Fine on cards. Useless when the action does not reverse.

Real question, not rhetorical. For anyone running fraud ops or building on the agent payment rails, what are you planning to lean on is the absence of presence? Is anyone checking the transaction against the mandate the human actually granted, and does that hold up operationally? This becomes a huge liability in itself. I am sure there are solutions out there, at least in parts. Please illuminate.

reddit.com
u/usually_guilty99 — 1 day ago

BoA Visa Debit/Credit Hacked 4 Times Due to Consumer to Merchant Data Exchange

Last year, my Bank of America Visa Debit/Credit card account was used for restaurant delivery purchases four times by DoorDash hackers. The restaurant locations were in three different states.I have never had a DoorDash account. Each time I discovered the transaction in my account, I reported the transaction as unauthorized and followed up with a phone call to BoA customer service, consumer security. Each time BoA insisted I cancel that card and have them reissue it. Each unauthorized transaction happened within a month to six weeks of the issuing of the new card with new account #. The first time it happened I wanted a root cause and was told I would have to contact DoorDash. DoorDash could not provide me any information as I did not have a DoorDash account.The second time it happened, the Bank volunteered it could block "DoorDash" from charging any of my accounts. Third time, they insisted somehow my smartphone security must be breached. That time, I noticed that the merchant name on the transaction line was "DD" not "DoorDash" which I learned from the rep was an allowed data exchange shortname. BoA replied that they would also block DD. The fourth time it happened about 3 weeks after that card had been reissued and received! This time I escalated to the highest consumer security rep. Not sure how high as this person didn't seem to have much more knowledge than the others. I was very angry, asking how the bank could allow this to continue to happen and if they could they investigate the actual hackers and have them arrested. They said they don't get involved with investigations and that I should file a report with my local police. Since these crimes occurred in other states, I asked if that would be the FBI's purview. No answer. I learned from this rep that she really didn't know, as far as she knew the bank has never pursued criminal legal action in cases like mine. I threatened to close all of my accounts and transfer funds to another bank and got further escalated to a security manager. Finally, this rep speculated it could be a systemic issue. She told me every time a credit or debit card is reissued by the Bank and Visa, the account data and the new card's number is automatically transmitted to all partner merchants, which I assume could be any business that accepts Visa cards. I believe this to be true because one app allowed me to continue making purchases without updating my new debit/credit information--Starbucks. I also mention Starbucks because the DoorDash hacks started shortly after I signed up for the Bank's Starbucks new customer promotion. I have no means of proving my speculation of where this data leak is occurring but it feels more than coincidental. Here's the kicker. I worked for Bank of America for 5 & 1/2 years as a contractor. Quarterly, I had to take their mandatory cyber and infosec security education with exam certification, including regulatory, consumer and data protections, anti-fraud, etc. PPI sections include the bank's absolute adherence to never disclosing or sharing the consumer/customer's personal or financial data without the consumer's complete notification and authorization. I did try to take my complaints up with other bank security departments, I had two emails for reporting. But, the response I got was to continue working with the consumer security people. Anyway, I am not sure whether this auto transferring of PPI and card data to merchants is done by all banks and all credit card companies. Has anyone else experienced this type of unauthorized account use? Does anyone know which banking regulatory agency I should share these incidences with? Whether it caused my hacks or not, any auto sharing of consumer personal and financial data should be banned and better protections are required.

reddit.com
u/CAZelda — 1 day ago
▲ 3 r/FraudPrevention+1 crossposts

Robbed of over $1,000

Close to $1,100 in fraudulent charges were made online from our debit card back in May. I called Bank of America who assured me they would get this taken care of, and then issued me a temporary credit for the amount taken. They stated I didn't need to do anything else. Today they reversed that credit, and took the money back. After I called they're fraud department and spoke to someone who barely spoke English, I was told that my claim was refused and that I had been sent a letter on August 3rd stating that they would take the money back on August 18th. First of all I never got the letter, second of all WTF lol. These were 100% fraudulent charges, but they said they couldn't prove that, so end of story. The moral of the story is, and I've heard this before and wish I had heeded the advice, Bank Of America is shady AF and should be avoided at all costs.

reddit.com
u/stlcraig1984 — 2 days ago
▲ 2 r/FraudPrevention+1 crossposts

Help with fraudulent charge case

OK. Here's the whole story.

In late April of this year someone charged almost $7000 at Home Depot on my wife's credit card. We immediately reported it as a fraudulent transaction.

BofA closed the account and issued a new card. They then reversed the decision saying it was a PIN transaction and the CVV was used.

We have filed a police report. We have talked to Home Depot. We have gone into the Bank of America branch. We have provided proof that my wife was not physically at the Home Depot at that time (she's a therapist and was with a client and can prove it.)

We have done everything humanly possible to prove that this was not a charge that we made but we are still on the hook.

Has anyone encountered something like this and been able to resolve it?

We are at our wit's end!

Thanks in advance for any help!

reddit.com
u/heavyjpdx — 2 days ago
▲ 649 r/FraudPrevention+3 crossposts

Rebco Ventures Private Limited, Pune

This is Ravi Lal, He is the CEO of a company named Rebco India (Pune) which allegedly works on investment projects and real estate. The company has no lending license. He hasn’t paid salaries since last 3 months or so, and is asking employees to resign just to get rid of them. I am posting this on behalf of everyone who worked there so that other youngsters don’t get their lives ruined there. And this is the image of the CEO. This guy had done 3-4 scam earlier, he even bought bouncers today for protection. Even today he asked us to resign and not take legal action. We will file a legal complaint soon but I personally don’t want individuals to ruin there lives here if it ever comes to that. If anyone has connections who can help, media or politically, please let us know🤍

u/StatusLengthiness634 — 4 days ago

Hi. I got a job offer. Before i even started they sent me this. Couldn't it be more obvious its a scam?

Watch out people stay safe.

u/Fit_Tumbleweed2787 — 3 days ago

How do I remove any public connection to my father after cutting him off?

I recently made the decision to go no contact with my father after learning about / dealing with his criminal history. I don't want to go into all the details but it's serious enough that I don't want to be associated with him anymore, publicly or privately. I have changed my name last year and I need to know how can I get my old name removed from existing online?

reddit.com
u/Agreeable_Song_5495 — 3 days ago
▲ 4 r/FraudPrevention+3 crossposts

Help stop fraud on Wisconsin public funds—bring back private enforcement

Wisconsin used to let citizens help catch fraud against public programs. That power got taken away, and now only government agencies handle it. The problem? They're stretched thin, and fraud keeps slipping through the cracks.

I started a petition to restore private qui tam actions—basically giving citizens a legal tool to report false claims on public money (starting with medical assistance). If someone wins, they'd get a percentage of what's recovered, plus costs and fees. The government gets first crack at the case, and there are safeguards to prevent junk lawsuits.

It's not about creating chaos. It's a controlled, incentive-based way to recover taxpayer money without relying entirely on overworked agencies. Public funds belong to the public—shouldn't we have a way to help protect them?

If this resonates with you, would you consider signing and sharing? Anyone else think Wisconsin should give people this kind of tool to fight fraud on public programs?

c.org
u/UNSC_117 — 4 days ago
▲ 89 r/FraudPrevention+2 crossposts

Warning about Privacy.com and my experience

Hello,

I wanted to warn everyone and share my experience with Privacy.com

A lot of Reddit posts claim you can use it to generate throwaway credit card numbers. I intended to use it to get a free trial and prevent being auto billed by a sketchy company. The website claims it is free up to 12 cards and that it will not run your credit. I signed up for an account and had to provide all personal data that is typically required in a credit card application such as a social security number and address. I did email and phone verification and added a debit card. They ran a transaction on the card and I had to verify the amount. After all those hoops, it said there was 1 more step before I could use the service.

I had to consent to applying for a “charge card” AKA a credit card through Patriot Bank.

They described this as “boring legal stuff” and I am glad I did not scroll past and click Accept. Cannot believe how deceptive they were and that I was foolish enough to give them so much verified personal data. Don’t be a sucker like me. Stay away!

reddit.com
u/TexasCivil — 4 days ago

Crime: why steal a sim card?

The other day, my locker at the gym was entered, my clothes searched and wallet stolen. The perp also took time to open my mobile phone simcard tray and remove the simcard, replacing the SD card tray before returning the phone to my locker.

Why?

I can understand stealing my wallet as several attempts to make purchases using my cards were made, but blocked by the bank. But why go to the bother of removing a simcard rather than just taking the phone?

Any amateur detectives want to enter the chat?

reddit.com
u/No_Feedback_7772 — 4 days ago
▲ 4 r/FraudPrevention+2 crossposts

How do professional services firm (CPAs, Lawyers, Pvt Equity etc.) deal with tampering fraud

Public accountants and Law firms issue sensitive, high-stakes documents to their clients, that then get passed on to other users such as lenders.

Does it concern you, as a CPA for example, that someone (client or a third party) can use basic pdf editing software to change some numbers on the statements and use them for lending purposes? A lot of mortgage fraud happens on fraudulent documents. You would probably avoid any liability, but it can cause reputational damage and unnecessary headache.

Would you pay for a solution that helps prevent this tampering?

reddit.com
u/gilygilyapa — 3 days ago
▲ 2 r/FraudPrevention+2 crossposts

Someone is using my personal details to submit malicious enquiries

Hi all,

Location: UK

I have had someone use my details last month (name, email, post code and email address) to make a bunch of enquiries for “breast augmentation” and “vaginal tightening”. (Never heard of either in my life to be honest).

Long story short, I made an excel file to collate all the evidence of when the calls, texts and emails started rushing in trying to chase up the enquiries but I had to explain to all it wasn’t me and my details were compromised. It feels like a targeted and intentional attack. Why? I’m not sure as I’ve never done this to anyone and am not arguing or at war with anyone in my life currently. I put it down to an insecure, jealous person who just wanted to ruin my day. I did file a fraud report (that’s what I was directed to after following the police helpline automated machine). The case was closed down the day after.

Recently, over this weekend I’ve now had more enquiries submitted using my details again but for laser this time and some plastic surgeon places.

I’m going to add to my excel doc (even tho I couldn’t upload this on the fraud website), submit another report but majority of these places said they can’t reveal or find location of where the enquiry was made because that requires a police investigation.

Can someone please kindly advise what I should do in this situation? I’m starting to doubt people close to me but I also don’t want to emotionally stress myself out like that.

reddit.com
u/Secret-Pie3306 — 3 days ago
▲ 2 r/FraudPrevention+1 crossposts

transaction agent building

I am building an AI agent for transactions which performs actions like approve / hold or question / stop, so I want feedback on:
If a transaction looks suspicious but there isn’t enough evidence to call it fraud, what should an automated system do?
A) Approve it
B) Hold it and collect more evidence
C) Stop it
D) Send it to a human
E) Something else — explain

reddit.com
u/rahulk448 — 3 days ago
▲ 194 r/FraudPrevention+2 crossposts

[US] is someone trying to steal the deed to my home?

A few months ago I got mail for a real bank account at my single family home address with some random person's name...I’ve lived here for 3 years and this wasn’t the name of the previous owner. It was also just paging off minimum card balances for 3 major credit cards. Weird.

It gets much worse. On a hunch I just did a reverse address lookup for my home in the white pages and that SAME random person’s name is listed there as the owner. Of my home. There are no unit numbers. I’ve never heard of this person and now I’m kinda freaking out. What scam might this be and how can I stop it? I reported the account to the fraud department at the bank when I got the notice but the reverse white page result makes me fear they’re trying to steal the title to my house or something?

reddit.com
u/superjew1492 — 6 days ago

Anyone else notice financial breaches since governor turned over voter lists?

In the past few months, I have had 5 unauthorized transactions on 4 different accounts. I had my computer examined for viruses/malware and nothing came up. I NEVER use two of these cards online, I don’t use 1 of them for anything other than automated payments, and keep them in protective sleeves. I’ve never had this happen before – but I live in a state where the governor turned over our voter lists with apparently personally identifying information. It may just be a coincidence, but I’m wondering if anyone else has had the same experience? I just can’t think of anything else that has changed.

reddit.com
u/Relevant_Tone950 — 4 days ago
▲ 6 r/FraudPrevention+3 crossposts

WARNING: Check your Boost Protect / Likewize iPhone replacement for "Non-Genuine" parts + Record Discrepancies

I’ve paid $63/month for Boost Protect/AppleCare coverage for over two years. When I received a replacement device, an official Apple Diagnostic / Settings check confirmed it contained non-genuine, unauthenticated internal display components. When I escalated this to Corporate, they submitted conflicting dates to regulators and retroactively altered my account portal logs. I'm organizing a collective petition for the FCC and OAG to have our consumer protection agencies actually assist help with citizens consumer complaints. I brought this up to Boost Corporate Escalations, instead of replacing the hardware with genuine components, they focused on closing the administrative dispute: Submitted conflicting dates to federal oversight agencies regarding when account credits were allegedly issued/ Retroactive Portal Changes: Modified my online billing history months after the fact to retroactively insert a $63 credit card payment line item that never appeared on my original February 2026 account statement.

u/Illustrious-Mood2139 — 3 days ago
▲ 3 r/FraudPrevention+3 crossposts

Administrative Systemic Billing Fraud & Database Manipulation

My exhausting situation has been actively ongoing for 29 months, originating from initial interactions in October 2025. Throughout this period, Boost Mobile has engaged in continuous corporate misconduct: charging full price for a premium product while forcing me to carry an unauthenticated device, manipulating my payment history to block transparency, and fabricating transaction ledgers.

Since October 2025, I have been in contact with Boost Escalation Managers regarding my dissatisfaction with a local retail storefront. The store sold me Boost AppleCare insurance coverage but overcharged me for repairs involving unauthorized, non-genuine parts. Boost Mobile escalation manager requested proof of my purchase date and insurance coverage, claiming she could only see 10 months of payments. I provided documentation proving the device was purchased on March 18, 2024, and that I had paid for insurance for 20 months leading up to October 27, 2025. Upon receiving this proof, the manager blocked my email address and ceased communication.

u/Illustrious-Mood2139 — 3 days ago