Try a short exercise with your last serious fraud case. Draw the attack as the attacker ran it, stage by stage, and next to each stage write which of your teams could have seen it. Not which team caught it — which team’s telemetry contained it at all.

For a typical phishing-to-fraud campaign, the answers come easily at first. The attacker registers a look-alike domain, sets up hosting and a certificate: your cyber team can see this — domain monitoring, certificate transparency, brand protection. Mass SMS and email lures go out to customers: cyber again, at least partially, through abuse reports and detection feeds. Skip ahead: the attacker logs in with stolen credentials and works around 2FA — your fraud team can see this, a new device, an unusual session. Funds move: fraud sees the damage.

The stage we skipped is credential theft — the victim typing their password into the fake page, the data silently captured. Cyber has stopped watching: no corporate perimeter was touched. Fraud has not started watching: there is no session yet, no transaction. When we draw this journey for banks as five boxes, the label above the middle box reads, simply: nobody sees. The precise moment your customer is compromised is the moment your defence, as organised today, is structurally blind.

The chain against the org chart. Cyber and fraud each see their stages — and the middle belongs to no one, until Threat Intelligence gives the SOC eyes on stolen credentials.

The chain against the org chart. Cyber and fraud each see their stages — and the middle belongs to no one, until Threat Intelligence gives the SOC eyes on stolen credentials.

Here is the insight this article exists to deliver: that blind spot is positional, not technological. It is not a model deficiency, a tuning problem, or a data-science gap, and no amount of investment in transaction-layer tools will remove it — for the same reason a ground-floor window cannot see the horizon. Transaction monitoring, rules engines, device fingerprinting, consortium data built on confirmed losses: all of it observes the final stage of a multi-week operation from a fixed position at the end of the chain. From that position, the campaign’s first three weeks — domains registered, kits deployed, credentials harvested, mule accounts patiently seasoned — do not exist. Every campaign is met for the first time at the moment of loss, and the detection rules are written after the losses start.

The position also explains why modern scams slip through. In authorised-push-payment fraud the transaction is technically legitimate — right customer, right device, freely authorised — so a transaction-layer control has almost nothing to refuse. Catching the manipulation requires signals from elsewhere on the chain: the scam call in progress, the remote-access tool on the device, the intelligence that this customer’s segment is being targeted this week. Position, again.

What does the positional blind spot cost in practice? A documented case. At an Indonesian financial institution, Group-IB’s fraud protection team identified more than 1,100 fraud attempts in which AI-generated deepfake faces were used to defeat digital KYC for loan applications — one instance of a technique whose potential losses in Indonesia alone are estimated at USD 138.5 million. Walk the scheme against the org chart and it is a cyber operation until its final step: biometric data and credentials obtained through malware, remote-access trojans, and dark-web markets; emulators and virtual-camera software injecting the synthetic face into verification; then account opening, a loan request, cash-out. Only the last step touched the fraud team’s telemetry.

So the response ran the way siloed responses run. Fraud, cyber, and threat intelligence worked their separate lanes, communicating by email, tickets, and ad-hoc calls; the attackers’ tooling sat with reverse engineers in the cyberthreat intelligence team while the fraud side tuned rules on transactions. The campaign’s own telemetry shows the shape of the failure. Detection came on day 25. First containment on day 31; full containment on day 39. Between detection and containment, USD 6.58 million in damage accumulated across the campaign’s peak — while more than 200 analyst hours, roughly USD 30,000 of expert time, went into manually connecting what the organisation, collectively, already knew. And mean time to remediate is recorded, honestly, as infinite: a fraud scheme is not a vulnerability you patch. It can only be contained — faster, or slower.

The deepfake campaign's damage curve: detection on day 25 (MTTD), containment between days 31 and 39 (MTTC1–2), USD 6.58 million in damage across the peak — and MTTR effectively infinite.

The deepfake campaign’s damage curve: detection on day 25 (MTTD), containment between days 31 and 39 (MTTC1–2), USD 6.58 million in damage across the peak — and MTTR effectively infinite.

When the same class of scheme is run through a fused workflow — intelligence spotting the tooling in dark-web channels, an AI engine mapping it to a fraud scenario and proposing the detection rule, a fusion analyst reviewing and approving deployment — containment is up to ten times faster, and the next variant arrives at a defence that already knows its family. The 25 days were spent discovering what the operation was. A fused defence starts from knowing.

The fix, like the problem, is positional: put an observer at every stage of the chain and connect them. Upstream, intelligence watches infrastructure being built and credentials being traded. Midstream, session defence watches the moment of takeover. Downstream, network signals watch the money’s destination. None of this requires merging departments tomorrow. It requires deciding that the chain, not the org chart, defines what must be watched.

Do this week. Run the exercise this article opened with. Take one recent fraud case, draw the attacker’s chain, and write next to each stage which team’s telemetry contained it. Every stage with no name beside it is your integration backlog — and the first item on the agenda of a joint cyber-fraud review, if you do not yet have one, is that drawing.

One Adversary is a five-part series on Cyber-Fraud Fusion. Each article stands alone; the full 90-day playbook is in part 5.