Transcript
AI is making investment. Scams have actually increased by over 1,800%. Now involve AI tools like DeepBait. A lot of that is because it's never been easier to commit fraud. Today, our guest is Mason Wilder. He's research director at the Association of Certified Fraud Examiners. He's going to unpack how it's never been easier to commit fraud and why chasing the shiny external threat is leaving the back door wide open. It's totally understandable to really get focused on and worried about the headlines you see on a day-to-day basis about different breaches and scams and deepfakes. All these same tools that we're talking about that are available for external fraud are also available to your employees. Is the biggest risk the AI outside of your company, or in fact the employees inside using the same tools? The fact is that internal fraud is just simply an aspect of human nature. I'm Ash Hunt, and this is The Watchtower. Mason, great to have you with us. Really excited to get into this conversation. It's cyber-adjacent, but I think incredibly relevant to the intersection of everything the industry is dealing with. Security, AI, and most importantly, what we're here to talk about today, fraud. Maybe just for our listeners, you can give us a bit of background on you, yourself and your career. I know you've had a load of super interesting experiences that are going to be pertinent to our discussion today. Yeah, absolutely. And before I get into that, thanks again for the invite. Really cool to be here, and I'm looking forward to the conversation. So yeah, Mason Wilder, Research Director at the ACFE. And my career has kind of been divided in half at this point over 20 years. The first 10 years were in physical security risk assessment for international business travel. I started off working 12-hour overnight shifts in a security operations center, looking for plane crashes and bombs and earthquakes and things like that to alert our customers and their travelers. Worked my way up through that organization to provide intelligence analysis, support for a lot of different physical security operations and crisis response things. And somewhere in there, got my private investigator's license and started doing due diligence and background investigations. And then transitioned over to the ACFE, where I've been almost a decade working in the research department, where a lot of my responsibilities have involved monitoring and tracking developments and emerging risks and making sure that our membership is aware of the implications of these developments for the anti-fraud profession, specifically prevention, detection, and investigation of all types of fraud. And so just even within that 10 years, I've seen a lot of evolution of the fraud landscape. And as you alluded to earlier, I think we're at a point now where there's never been more fraud than there is today. There's never been more types of fraud than there is today. And a lot of that is because it's never been easier to commit fraud than it is today. So that's a brief overview and happy to get into it. Yeah, I think that's a great segue into sort of where I wanted to start, which is I think there's a general perception because of the technology advancements that fraud has become more voluminous, more complex, more sophisticated. Maybe just walk us through some of the key themes of where you've seen fraud change, particularly maybe in the last couple of years with the advent of some of the new technologies we're dealing with. Yeah, absolutely. I think it's a combination of pretty pertinent factors going back to, you know, even all the way back to the launch of Bitcoin and cryptocurrency and digital assets and those kind of fueling the dark web fraud markets. You know, and those two things together serve to be really accelerating factors for external fraud. And that kind of information sharing and ease of illicit transactions really, I think, is a big part of the explosion of fraud that we've seen. And then, you know, the advent of AI tools, starting with generative adversarial networks and then adding on large language models, I think it's just been like pouring diesel on a burning fire. And now we've all got to figure out how to keep those flames at bay or try and do our best to extinguish those flames. Right. And I know that you and the organization that you work for have recently surveyed anti-fraud teams, particularly looking at the preparedness against AI-powered fraud. Maybe just walk us through some of the stats and some of the findings that you've found. Yeah, absolutely. So we launched the fourth edition of an anti-fraud technology benchmarking report in collaboration with SAS, where we will ask about how anti-fraud professionals and their organizations are using technology in fraud prevention and detection. So this one, we added some more content to the survey to ask about how fraudsters are using AI and the types of schemes that are becoming more prevalent and expected to continue becoming more prevalent. And one of the questions we asked was, how prepared do you feel your organization is to combat AI-enhanced fraud? And it was a scale of one to five, with one being not at all prepared, which we had 17% of our respondents said not at all prepared. And then five at the high end was completely prepared. And we only had 6% say they were completely prepared. And you back it up one to four on the five scale rating, and there was an extra 1% there. So a total of 7% of our respondents that felt more than moderately prepared, which, you know, I think is a pretty significant indicator of how fraud teams are feeling about this risk landscape. Right. And I've always found, I mean, from all the work that I've done, particularly in Fortune 500 banking, for example, there's always been a pretty established, I say, culture, funding, and almost a maturity to fraud as a discipline, particularly when I compare it maybe against cyber, which is, I think, in some organizations perceived as a newer discipline, even though that's probably kind of false perception. But I often thought that cyber fraud, things like AML, they were all ultimately dealing with the same type of problem, right? Which was that there was some form of loss exposure to the organization should these things not be tackled. Do you, for me, that gap between those teams still exists. Do you feel that's true from the observations you and your organization sees when you're dealing with particular research? Or is it actually that some of these teams are beginning to coalesce and deal with the problems, say, I guess, more centrally? There's certainly historically been, those have been siloed departments and they kind of sit side by side under the overall enterprise risk management framework. However, I think you're right. There have been just silos. Now, I think we're starting to see some progress in kind of breaking down those walls and understanding that there's a lot of overlap between those three different departments or functions. And even I think some of the language that you see being used is starting to reflect that more to where people are kind of collectively referring to these three risk channels as financial crime. And I think that's very positive. And we're starting to see some positive indicators in terms of organizations getting those functions working together more cohesively and collaborating more and sharing more information. And I think that's a really important thing for organizations to take a look at doing for this current landscape. And there's going to be a certain amount of inertia that has to be overcome because many organizations, change is difficult. And when you have to rethink three entire functions and how they interact and work with one another, that can be kind of daunting. And a lot of people can be a little bit resistant to change. And, you know, combine that with how scary these threats are made out to be. Then, you know, I think that's a big reason why some of the progress has been a little bit slow, but I'm optimistic. Well, maybe that's a great place for us to pick up because the fear factor, I think, is something that's become particularly prevalent to the discussions and the intersection between many of the cyber threats that we deal with, but also a lot of the routine and increasingly sophisticated fraud that you've alluded to. Maybe let's touch on some of the topics like deep fakes, particularly business email compromise. That was something I used to deal with day in, day out as a CISO. I even ended up being a design partner on a product to try and fix it because it was such an issue. But I think this sort of began emerging, let's say, sort of seven, seven, eight years ago. Maybe just walk us through a bit of the timeline of the evolution of deep fakes in particular and how you've seen the sort of growth of that threat in that period of time. Yeah, absolutely. This is something that I kind of picked up on and started talking about back in 2018. I had just seen some research coming out of the University of Washington where they were the ones that first debuted some of the generative adversarial networks with video manipulation. And so it started off, you'd have to have one actual real video or audio clip or some piece of media that then you would kind of combine with another rather than just generating things out of whole cloth. I think the very first video was Barack Obama. They took a video of him giving one address as president and then combined it with audio from a totally separate address that he had given and made his mouth match the audio of the second. And that was, you know, blowing everybody's minds. And then, you know, where it started to first be deployed in a fraud context was with business email compromise schemes, just like you mentioned. And those, the very first ones were audio only. So it would be like a voicemail that showed up in somebody's inbox that was an audiophile impersonating like a CFO or a CEO. And it was just one single media format being manipulated. And I think it was the summer of 2018 where an insurer publicly released information about three cases that their clients had suffered losses to kind of raise the alarm a bit. And then it's just kind of been a snowball rolling downhill ever since then. And it evolved into, you know, then all of a sudden you can combine totally new generated audio and video. And then you can do all that in a format that appears as though it's live on a video call or a chat. And then you have the large language models get introduced and, you know, people are using those to create really convincing social engineering scripts that reduce the presence of any of the kind of red flags or telltale signs or like even a bad accent or bad broken English, misspelled words. And so all of these things combine over time to make these social engineering attacks really effective and, you know, really difficult for somebody that hasn't had any training or awareness about these schemes to be able to recognize and exercise their professional skepticism. And now with where AI is today, these people that spent time developing their tactics using these technologies now have these automation capabilities, not only to just scale up these attacks, especially like the digital injection attacks for bypassing know your customer protocols, but then also being able to vibe code versions of it that are adaptive. And, you know, when the behavioral analytics that organizations have in place start to pick up on the cues, the attackers are already modifying and adjusting and customizing these automated attacks. And so, I mean, that snowball is just still rolling downhill, picking up steam. Yeah, I want to pull on that thread a bit more, Mason, because I think you mentioned something interesting, which is ultimately the sophistication of the attacks now have outstripped our human ability to ultimately detect them without the aid of much more advanced technical control. I remember, I mean, I was a CISO only 15, 16 months ago, and I recall at the time service desk being hit routinely by phishing, smishing attacks, all of which were getting increasingly advanced. And ultimately, even I wouldn't be able to detect changes like to a Cyrillic A right in an email now, and all the kind of nuanced approaches that SLMs, LLMs are being leveraged far more effectively now by attackers to execute those attacks successfully. So if an organization, obviously most budgets are always constrained, it's kind of looking at one key place to spend on technical control against some of the threats that you've spoken about, where should they start? Maybe something in like the identity space, but maybe just give our listeners a bit of a view of where you think they're going to get best bang for buck. Yeah, I think if you only had one place to put your money for technical controls against these kind of risks, it's got to be identity verification systems, because all of these common across all of these emerging risks is the kind of unauthorized access and bypassing technical controls. And so identity verification systems that, and they have to be kind of multimodal or multilayered and be looking at multiple signals all at once, not just one single signal, like facial recognition or voice recognition, but also looking at like device IDs, IP addresses, behavioral analytics, and doing some pretty sophisticated risk scoring and red flags too, and doing it live and automating, but also kind of continuously updating and looking for more signals to add into that mix, because that's what the attackers are doing as well. They're adapting and customizing. But I think that certainly for the near term, identity verification systems with multiple layers are where I would recommend, especially an organization that has a lot of like customers logging in or, you know, account creation or customer accounts with financial information in them. That's where I would put the resources. Yeah, I think you, again, are highlighting some of the, I think, future areas of focus, particularly in the target operating model, probably better forward, but definitely for security as well. And actually, I think generally for technical engineering within the organization, which is context engineering, like to your point. I think lots of the controls that we've built historically, in fact, almost all of them are pretty binary and they're built on very sort of Boolean logic of if this, then that, between one-to-one systems. And to your point, right, if you're actually really going to tackle a lot of this, you're gonna have to be pooling in data and signal intelligence from multiple disparate sources in order to build a picture to then execute the decision. And for me, this is now getting into the heart of something that I know we discussed a bit earlier before the show, but I think is probably one of the most exciting spaces of innovation occurring within technology at the moment, which is not looking at the inbound, external-driven adversarial activity, but actually internal insider threats. And for me, this is one of the areas where context engineering and the type of technical controls around identity, data, and others begin to, again, coalesce and can really drive meaningful change in this. So maybe just give us a bit of a view on some of what you've seen that's actually going on inside the organization and not just sort of external sort of focused. Yeah, I mean, I think it's totally understandable for people tasked with the overall fraud prevention and detection and fraud risk management at an organization to really get focused on and worried about these external threats and the kind of shiny objects and all the headlines you see on a day-to-day basis about different breaches and scams and deep fakes and all of those things. But the fact is that internal fraud is just simply an aspect of human nature. And there's nothing that you can do to eliminate that risk. It's just a part of human behavior. People are going to feel pressure and have motivations to commit fraud against their employers and they're gonna have reasons and rationalizations available to them to justify doing it. And really all these same tools that we're talking about that are available for external fraud actors and schemes and organized crime and things like that are also available to your employees. And so is the information sharing that's available, whether it's dark web, Telegram channels, Discord servers, even Facebook groups that share information and you can purchase fraud guides and things that will tell you exactly step-by-step how to commit these schemes. And you have access to all the data you need available. So from an internal fraud perspective, you can very easily create a convincing synthetic business presence to carry out and then use generative AI to create a very convincing invoice to carry out a billing scheme. It's very easy to doctor receipts to carry out expense reimbursement frauds, forge documentation that can be linked to all different types of common internal fraud schemes that have been around forever and that will continue to be around forever. And so I really urge people to not get too focused on the external fraud schemes that you lose focus on your internal fraud because like I said, it's just simply an aspect of human nature and that risk will always persist. There's no way to totally eliminate it. I think that's a generally, it's a message that I've been beating the drum for in security in that arena for the entirety of my career. Ever since I got into risk modeling, you begin to realize most of the loss exposure is generated in not only internally, but actually through very menial intent or in actually many cases just accidentally and process error almost allows it to happen. And that brings me on to a point I would love to get your thoughts on, which is the sort of degree to which you see genuinely significant intent over a contract period of time where an internal adversary is generally planning to commit fraud within the organization versus actually it's pretty opportunistic. It's a bit of a pushing at an open door and the controls are probably failing and employees probably just think, I can, if I can get away with this, I will do. What do they say when they're caught? It's a little bit tough to say. I think it's a mixture of both. There are some people that are just psychologically wired to look for opportunities to exploit and have fewer moral qualms about dealing from their employer. I think one factor there that's not really working in our favor is a lot of times an employee's attitude towards their employer is a big rationalization in their decision to commit fraud. And you think about people, there are a lot of people around the world that are not doing great in this economy and feeling financial stress from increasing prices. And then their leadership tells them, hey, we're gonna have this AI bot shadow you and learn how to do your job and then eventually cut you loose. Those are the kind of worries or stresses that are gonna push people over the edge to commit fraud. But a lot of times it just starts small. It's somebody that maybe has a medical emergency or racks up a lot of credit card debt because of some extenuating circumstances and they think they're looking anywhere they can to get some relief. And so they find one little vulnerability that they think they can exploit. They get away with it as far as they know. And then they almost never stop. The fraudsters, the internal fraudsters, once they've had a little bit of success, they think, oh, well, yeah, I paid off that debt or I addressed that need, but hey, I'm still here. Didn't get caught. What else might be available to me? So a lot of times you see over time, frauds not only grow in terms of the losses mounting, but they also, a fraudster will start, maybe they did the expense reimbursement fraud first, but then realized, hey, these controls didn't quite work. Maybe I can set up a fake company. Maybe I can put a fake employee, a ghost employee on the payroll and they start looking for other ways. And then generally speaking, they don't stop committing fraud until they're caught and suffer significant consequences for it. It's just, there are some very interesting kind of psychological axioms of fraud when it comes to internal fraud that are part of what makes it such a persistent and ever-growing risk. Right, and I think it's, or maybe it's the way we've designed our controls, but certainly the state of technology controls writ large today don't seem to be particularly well-equipped to be tackling, to your point, some of those consistent psychological qualities that seem to persist in this arena. And often it's actually tip-offs and other notifications that lead to the identification of this. I think your research found something like 43% of occupational fraud is detected through tips. So why is it that the people are still able to see things that our technology controls are missing? And what can we be doing about the technology controls, either filling gaps, reconfiguring existing controls to actually replace most of those, what in many cases must just be goodwill, good fortune that those individuals are tipping the organization off and actually almost configure full detection inherently in the systems that we run our organizations with. You know, a lot of technical controls are really well-programmed or well thought out, you know, but the problem is there's always a human element, especially when it comes to like authorization. And it can be, you know, a lot of times we see internal fraudsters are somebody that is well-liked by everybody in the organization and trusted and has been there a long time. And so people just give them the benefit of the doubt or, you know, there's there, but a lot of times the element that gets exploited is some human element of authorization or oversight that is easily circumvented with just, you know, basic human elements like trust or somebody walks away from their computer or, you know, their password is easy to guess and you can just bypass some of these controls. So I think one potential solution that organizations should consider is adding extra layers of authorization for access to sensitive information or especially outgoing payments or, you know, modifications of systems that control the outgoing funds. Because a lot of times there's just one single point of failure. And if you're able to get access to one person's authorization mechanism or just convince that one person, then all you have to do is get past that one layer. But, you know, I know that certainly in the cybersecurity world the term multi-factor authentication is very common and has been around for a long time and is employed as part of a lot of different controls. But I think multi-factor authorizations, especially when it comes to large payments or significant modifications of critical, you know, organization system, especially financial logs and payment authorizations and things like that is one way that organizations could look to kind of enhance their scam or scam detection or scheme fraud detection platforms and capabilities. But I do think that that always needs to be paired with good fraud awareness training for your employees and not just basic off the shelf, once a year check a box training. But the more you can kind of customize it and give specific training to the high risk departments that's related to, you know, the internal as well as the external red flags and behavioral indicators of fraud. You referred to our report to the nations with the statistic about tips being the most common detection mechanism which has been the case for every single one of those reports that we've put out over 30 years by a wide margin. So, you know, you have to include good awareness education because if you're doing it right, you're turning every single one of your employees into an anti-fraud control. And so telling them how to recognize the signs of the fraud risks that are most pertinent to that industry or that organization or that department, and then also making sure they know what to do if they see those signs and have, you can't just have one channel for reporting suspicious activity anymore. It can't just be a hotline. You've got to meet your employees where they are. And across several generations, you're going to have some people that want to just pick up the phone. You're going to have some people that want to send an email. You're going to have some people that are going to be more inclined to use like a web-based reporting mechanism. And also I think it's important going back to that same study, about 55% of those tips come from employees but about a third come from a combination of customers and vendors. So your awareness and education about the reporting mechanisms and how to detect signs of fraud. Also, if you're sharing that with your vendors and customers as well, you're going to increase the likelihood that you get valuable tips from all potential sources and really cover your bases. So there's really no one way to perfectly address fraud risks. It's got to be a combination of things. So the technical controls, there are opportunities there, but it has to be paired with also education to turn, to address some of the human elements and human behavioral vulnerabilities that often get exploited in the circumvention of controls in internal fraud. So I think the focus on behavior change, process, re-architecture to constrain the catalysts of fraud, I think in the organization is absolutely sound. I maybe want to stress test, maybe challenge is too strong a word, stress test one of your thoughts around the technology control piece, because that seems to be all well and good in terms of the educational narrative for human to human fraud, i.e. human using systems to commit fraud for themselves. We're now going to be environments where we've got ratios of agents, thousand to one to the human, and particularly, A to A activity, agent to agent activity. And it's already foreseeable, if not evidential, that these agents will have the capacity, and I use this word in quotation marks, will to commit fraud as a by-product of achieving an objective and their use of tokens to achieve an objective, because they're mission-centric entities, right? Identities, at least. And so when you're ever dealing with non-determinism, it's arguable that fraud can be a by-product, like I said, of achieving an overall task, even if it's not intentful to commit the fraud as the end goal. In my head, the only way we're ever going to solve that is simply because of the high-velocity runtime activity is the future of insider threat management insider threat management with context engineering at its core, a sort of advanced with context engineering. form of circumstantial DLP that's going to be able to, to your point, really feed into and extricate all the intelligence from the authentication channels, the authorization channels, the identity profiles, all the data transfer channels. What are your thoughts on sort of A2A activity and the future that might have for different types of fraudulent activity? Yeah, that's, I mean, you bring up a good point and certainly, you know, you're much more technologically sophisticated and I'm sure much more familiar with the bleeding edge of things like AI engineering. So, but I do think, you know, there's an element in there that you talked about committing fraud as part of another objective, you know, and that it's just kind of a byproduct of trying to get from, you know, point A to point B in any way possible and very adaptive and very smart agents looking for and identifying opportunities to do that. And so, you know, then I do think, yeah, there is something to that risk as well as some of the promise, you know, we get, we hear all these stories about like Mythos or these, you know, models that get released and freak everybody out. And while I will take one moment to pause here and say that I think there's a certain incentive to the companies releasing stories like that, you know, that's like AI is so powerful, it might take down the whole world. You better get in now as an investor, you know, so I think there's some, a little bit of hyperbole or hype there, but at the same time, you know, there's going to be similar models that are continuously being used and built into the development process to kind of try and catch some of that stuff before it happens. And so, yeah, you know, it's just, it's an arms race in a certain amount of cat and mouse game that's generally the detection is going to be on you playing catch up a lot of times, but I think with some of the power here and also investing in, you know, threat intelligence kind of function that involves some pin testing and playing in sandboxes to see, to really think like a fraudster and okay, if I was going to attack this system or try and, you know, manipulate or circumvent some controls, how would I do it? And you kind of work that into the development with some of the AI tools available in a defense capacity. And, you know, I think there's some cause for optimism that at the same time that these threats are evolving and getting more difficult to manage, we do have some tools available to us to confront that reality and catch up pretty quick, if not try and get ahead, if you're really being intentional about it and devoting resources into doing just that. Yeah. I think this is one of the most interesting spaces for innovation, particularly on the technology control side. And, you know, I didn't even pay you to say that very nice compliment about me being more technology advanced, but I shall absolutely screen record that and keep that for future reference. That's not the highest bar to clear. Yeah. Well, I mean, the reality is, you know, most of our listeners are highly technologically advanced and all engaged in trying to deal with this issue from one angle or another. And like I said, I think the innovations that I'm seeing in the identity sector and in the data sector are, you know, maybe from a slightly different starting point or a different angle, all gearing up to try and solve this problem. And I totally share your skepticism around particularly some of the larger labs and organizations that are releasing these models. You know, to me, it seems one very convenient on the timing when they release these research results, particularly of AI breaking guardrails, et cetera, when it's going to be pretty well known that would have happened many, many times prior in internal testing. They just haven't disclosed it beforehand. And I think that has, to your point, ramifications in terms of the motivations, particularly for investors, but also for, I think, you know, technologists and organizations that are trying to keep pace with this and in this kind of arms race. I just want to maybe focus on one final question. And it's just sort of dawned on me as we've had this discussion, Mason, which has been great, by the way. Thank you so much for sharing your insights. But this last piece is really important, which is liability. So I guess ultimately the day-to-day consumer acknowledges to a degree that there'll be a byproduct of fraud always. And obviously, the organization is always going to be doing as much as it can, but the sophistication of threat actors, both in physical reality, as well as it is, you know, sort of digital adversaries that organizations face are always going to be there. Do you see liability changing, getting more severe? Are there any regulatory pressures and levers against organizations to be dealing with this in a more heavy-handed manner than they have been? So to get a bit more action and progress with some of these things, or is it just the case that this is acknowledged as a routine byproduct of running a business? Yeah, it depends on what part of the world we're talking about. You know, here in the U.S. where I am, I would not say that there's a significant increase in regulatory stress related to liability against organizations, but other places in the world, I think there is. And, you know, I think there's some very interesting kind of initiatives starting in some different countries specifically. I think, you know, Singapore in particular, I'm aware of some updated regulations that would shift liability for losses related to scams from, you know, the victims whose bank accounts were compromised or who transferred out the money or something to the banks that allowed that transaction to occur and didn't, you know, have controls in place to detect that kind of activity and block it. Telecommunications companies that are being used to communicate with these victims that aren't, you know, flagging these things or doing enough on their side to prevent them. Or social media companies, similarly, that are a channel, a delivery mechanism for a lot of the communications that lead to consumer-facing scams. And so I think that, you know, I find those initiatives kind of refreshing and potentially encouraging because I think the only way to really make a big dent in this onslaught of fraud is to shift some of that liability. But, you know, if there's conflicting and competing regulatory regimes worldwide, not sure, you know, how that'll play out on a broader scale. And if they're, I mean, just like we've seen with like cryptocurrency money laundering, as long as there are a couple of jurisdictions that are just going to look the other way and have their hands off, then, you know, efforts in other places are going to fall a little short or not make as much of a dent in the overall ecosystem. But, you know, like I try and stay optimistic about this and look for little signs to be encouraged about. And I think there are some, if you don't mind, I'll tie a couple threads together here. Just a very quick story. You know, I was doing a presentation for one of the ACFE chapters talking about deep fakes and generative AI and the fraud implications. And as I was discussing technical controls, you know, this is a couple of years ago at a time to where the like deep fake detection is relatively nascent. And, you know, but still like a lot of false positives or, you know, there's testing that comes out and says, well, it, you know, there were a lot of false positives or it missed all these other things. It's only about 75% accurate. And we were dealing with fraud on an industrial scale. Fraudsters are going to take one in four odds. But anyway, so I'm talking about the, the, to be a little skeptical of the technical controls and not necessarily think that somebody is going to come in and just say, you know, save your organization and solve your deep fake problem. And you can just press play and walk away. And a woman came up to me after, after the talk and was like, oh, I enjoyed your talk. And I was like, oh, well, so, you know, where do you work? What do you do? I'm not going to say the name of the company, but she was like, oh, we do deep fake detection. And I was like, oh boy, here we go. You know, like she's going to be very upset with me here, but I wanted to, I'll hear you out, tell me. And, you know, she was like, I'd actually like to invite you to get on a call with some of our engineers so we can show you some of what we're working on. And, you know, it really opened my eyes and made me feel encouraged. And this is where I started kind of focusing in that, on that multi-layer detection tools that don't just look at one signal, but combine a bunch of different signals, not just from your organization, but also from a broader, that's one of the benefits of getting like a good external provider for solutions like this is because you're not limiting to yourself, to your own organization's data, but also what that, you know, vendor solutions provider, provider, all their other clients, you know, that, that company can use data and signals from all those other clients that they have. And you can benefit from that instead of just being limited to, you know, what, what data you have available to, to, you know, your functions at your organization. So, you know, that, that little story, I think is, is something that hopefully people can get a little bit encouraged about because having seen behind the curtains at one or two places, there are some really cool things and really impressive things that companies are doing. Now I still would encourage you to not necessarily think that there's some solution out there that's going to allow you to just click a button and not have to worry about fraud anymore. That's everything evolves too much and, and changes too quickly. Your fraud risk management program, and especially the detection and prevention has to be like a living creature that you're continuously training and working with and adjusting. There's, you know, gone are the days when you can just say like, Oh, this, this control makes a lot of sense. It's going to be really effective. Let's just do that. And then, you know, we'll come back to it in a year or two. So I just wanted that, that story kind of occurred to me as we were talking and figured I'd throw that in there to kind of put a bow on it. I love it. That's a great story. And I think you, you made a great point as well. We didn't really have like maybe future discussion, right? But I think we could have gone into, or even had a second conversation all around the, the supply chain aspect of fraud, particularly cross border to your point. And, you know, I was thinking in my head, it's very similar to things like climate policy, where there's an asymmetric effort to is very similar in that aspect in terms of cross border activity. And particularly, I think if you're a commercial organization, actually how much broader influence you can have being one part of that broader supply chain. And I know groups like FS Isaac and others take a lot of interest alongside of what I imagine, you know, all of the work you do with the association of certified fraud examiners to, to try and identify those more risky regions or risky geographical regions. And on the flip side of that, it is great to see, you know, I used to report into ask the monetary authority of Singapore, and that there are countries that are taking a more heavy handed and concerted approach to addressing this through regulatory levers. So yeah, that plus the innovations in market, it is good to see that we're heading in the right direction. And I want to just say on behalf of all of our listeners, like we're extremely grateful for you coming on, it's great to have an adjacent perspective to some of these challenges, you know, rather than just from the cybersecurity angle. And I think a lot of what I observe working, you know, and also venture capital and product around the, the innovations in context, intelligence, and things like that do offer up, hopefully, some really viable solutions to address this on mass going forward. Yeah, just one last thing there, then I appreciate the thought there. And yeah, to add on to that, one of the things that I've learned in the decade at the ACFE, where we have members from all different kinds of backgrounds. But the greatest thing about working in the anti fraud profession is that everybody feels like they're on the same team. And so breaking down these silos and helping people from these different disciplines and functions understand that we are all on the same team, and we can all help each other out. And there's a lot of benefits of working together, I think is another, you know, cause for for some optimism on from my end, but thank you so much for the opportunity to be here. And I really enjoyed the discussion. I hope to have a chance to have another one someday. But if not, you know, I'm sure that you're going to keep on doing good work and having good conversations and being part of a rising tide that lifts all boats because we're all in this mess together. Yeah, I think the topic of fraud is going to definitely reappear and look forward to picking up the discussion in the near future. Mason, just very briefly for our listeners that might want to reach out and I think definitely engage with some of the research that your organization has been conducting. What's the best way they can reach you? Yeah, LinkedIn is, is probably the easiest place. There aren't too many Mason Wilders out there. And the ones that are out there don't usually have CFE after their on LinkedIn. And so, and you find me there and visit the acfe.com webpage and go to the resources. on LinkedIn. You can find me there and visit the acfe.com webpage and go to the resources to look at some of our research reports that I've worked on and reach out with any and all fraud related questions you've got for me. I'd love to help you out if I can. Thanks again for the invitation. I really enjoyed the discussion. I think it's an important discussion and I hope to see you again and work with you again in the future. 100%. Thanks ever so much, Mason. It's been great speaking with you and thank you again to all our listeners. I'm Ash Hunt. This has been The Watchtower.