Buyer liars, AI fraudsters & lost revenue with Galit Shani-Michel

Fraud is evolving, and merchants can’t afford to fight it alone. In this episode of Payments Unfiltered, our host, Theo Spyrides, speaks with Galit Shani-Michel, VP of Payments at Forter, to discuss the rise of AI-powered fraud, the growing threat of friendly fraud, and why false declines cost businesses more than they realize. They also discuss why traditional fraud rules no longer work, how merchants can leverage data-sharing networks, and the real impact of 3DS on fraud prevention and conversion rates.

Theo Spyrides

Host of Payments Unfiltered

Galit Shani-Michel

VP of Payments @ Forter

Read transcript

Theo Spyrides: Let's jump straight into the conversation. To kick off, I thought we could start with a very high-level question: what does payment fraud mean to you?

Galit Shani-Michel: I started my career many years ago, almost 20, doing fraud. In the beginning you always think fraud is about stopping fraudsters. 20 years ago it was mainly about stolen cards and people stealing databases. Very fast you realize it's about more than that. It's about all the good people you mistakenly think are fraudsters and start to stop, and a lot of times these are your best consumers trying to purchase for very high amounts. That's when you realize it's not just about the fraudsters. Yes, you have to keep them out, but it's about the good customers, and you don't want to harm them or make their life difficult. This is where it really connects to payments, because these good consumers deserve a good experience, and you don't want issuers declining them or PSPs turning on 3DS because they think they're risky. Everything comes down to fraud.

TS: So if everything's about fraud, there are different types, first-party fraud and third-party fraud. Could you give us your view on the difference between them? I know we've previously discussed the term "friendly fraud." Could you do an intro into those topics, and what should merchants be thinking about when they consider these two types of fraud?

GSM: Sure. First-party fraud, often called friendly fraud (or "own PM," using your own payment method), is when someone uses their own card, buys something, then contacts their bank claiming they didn't do it. The other kind is real fraud, someone else used my card without my knowledge, and I never made that purchase.

TS: So how should merchants be reasoning about those two types of fraud, and what levers do they have to mitigate the costs?

GSM: Let's start with real fraud. Someone comes to a website claiming to be you and will do everything to look like you, same IP, same behavior. The challenge is realizing they aren't who they say they are, or that they're using a payment method that doesn't belong to them. This is getting harder because AI makes it very accessible to create a fake identity, and a lot of data is available on the dark web. Almost 20 years ago, when I managed fraud, we created rules. My team would review flagged transactions and I'd keep writing rules like "IP and BIN don't match" or "country plus high amount." But you always create the rule after the fraud happens, and meanwhile good people get blocked, like travelers using a card not from their home country. Today it's even harder because fraudsters can use AI to understand and walk around your rules. Most of the industry is moving to AI and machine learning, and the key is really understanding identity, not just what someone does, but who they are.

TS: With real fraud, would you say AI is the biggest change you've seen in the last 10 to 15 years, both in the sophistication of fraudsters and in your capabilities to combat it?

GSM: Yes, both. AI is making the technology better for merchants and fraud prevention companies, but also better for fraudsters, so you need to stay ahead of the game. The other factor is that data is far more accessible today. It's much easier to purchase card databases or personal details on the dark web than it used to be.

TS: So AI and easy data access give fraudsters powerful tools, but merchants need to build their own AI, hire data analysts, and build huge datasets. Is it even possible for a merchant to combat this wave of AI-powered fraud on their own, and is it just incredibly more expensive than the old hard-coded rule approach?

GSM: It's much more expensive, and more complicated, which brings up a third trend: data sharing. How do you fight fraud together? A good consumer might be new to your site but not new online, they bought elsewhere yesterday. The power of good fraud prevention companies is in their network: if a company knows 90%+ of the population in a country, most people coming through you aren't unknown to them. You can't fight fraud alone anymore, and most merchants I talk to realize that.

TS: So a community approach isn't a nice-to-have anymore, it's becoming a requirement. You're part of the MRC, a community that helps merchants think about risk. Could you share what the MRC is and how it helps merchants leverage this community approach?

GSM: The MRC is the Merchant Risk Council, a community around payments and fraud. It does three things. First, connections and ecosystem: merchants meet through conferences, Slack, WhatsApp, and community calls (payment, fraud, issuer calls) where you can get insight into what others are seeing, like new fraud programs from Visa or the 8-digit BIN change. Second, education: webinars, conferences, and sessions, because you have to keep learning in this fast-moving industry. Third, advocacy: for example, with PSD3 or Japan's regulation (which initially wanted 3DS on every transaction with no exemptions), the MRC advocates for merchants with regulators who don't always understand merchant needs, then publishes guidance on what the regulation means. The community itself is amazing, so many experts, and sometimes one coffee with someone becomes a resource you call on later.

TS: Awesome, don't fight fraud alone, and the MRC is a great community. You mentioned 3DS. What role do you see 3DS having in fraud prevention?

GSM: Great question. First, it's not really a fraud tool. The heart of 3DS is that it shifts liability to the bank from the merchant. If there's a 3DS transaction and the cardholder disputes it, the bank, not the merchant, bears the loss (with some exceptions like gambling). A lot of merchants thought this meant they didn't need fraud tools anymore, but that's wrong: if you send a lot of fraud through 3DS, the chargebacks still count toward your fraud-to-sales ratio, which can put you into card network programs, cost you fines, or even your merchant account. It also hurts your auth rate. There's also a misconception that success should be 100% for good consumers. It's not. I recently showed a UK merchant that sending every transaction through 3DS cost them 5% in bottom-line revenue. My mom is a great example, she's 71, and by the time she finds her phone, finds the SMS, and goes back to the website, she often times out and just gives up, a lost, legitimate sale. SMS delivery issues while traveling cause similar problems.

TS: So that's the bearish case on 3DS. Is there a bullish side, where it brings real value?

GSM: Yes, two things. First, regulation sometimes requires it (PSD2, upcoming Japan and other country regulations), and some issuers have low auth rates without it. But the most important use is on your borderline traffic, not the clear fraud (which should just be declined) but that 2 to 3% you're unsure about. Sending that borderline traffic to 3DS, instead of declining it outright, lets good customers pass through authentication while catching fraud that does slip through, which stays a small, manageable number.

TS: You mentioned Japan, are you seeing 3DS adoption increasing globally? It's traditionally been European-heavy, now Japan and some interest in Brazil. But in the US, challenge-based 3DS doesn't have great auth rates. Do you think 3DS popularity will grow globally, and what regional differences do you see in combating payment fraud?

GSM: I think 3DS is growing. Europe always leads in payments and the US lags a bit. Japan is adopting it, Australia has plans (though delayed), and countries in APAC like Indonesia, plus India, are leaning toward it more. I hope the technology gets easier, apps and biometrics instead of SMS, which will make 3DS a better experience than hunting for an SMS. In the US, consumers aren't used to the challenge flow and often won't cooperate, even legitimate ones. But about 65% of US 3DS traffic is frictionless, meaning the consumer doesn't have to do anything; authentication happens in the background. So maybe we can move to friendly fraud, real consumers who buy something then claim they didn't. Sometimes it's genuine confusion (like a kid using a parent's card), but sometimes it's just lying, "buyer liars," as we call them. They're a huge, growing problem because normal fraud tools can't catch someone who genuinely made the purchase and then lies about it later. And you can't just ban everyone who's ever disputed a charge, since sometimes the dispute is legitimate. There are two good ways to deal with this. One is applying frictionless 3DS, especially in the US, when banks are willing to authenticate; this can shift up to 40 to 45% of liability to the bank. When I call my bank about an undisputed 3DS transaction, they push back harder on my claim because they know they'll eat the loss, which means far fewer successful chargebacks. We've seen merchants cut friendly-fraud chargebacks by 50% this way, without hurting conversion, which matters a lot to travel and OTA merchants especially. The second solution is having a strong dispute system, proving to the bank that the person actually received and is lying about the purchase. Get that right and you'll recover the money. One more thing: fraudsters and liars will find any open window. If chargebacks get harder for them, they'll shift to other abuse, like false "item not received" claims, returning stones instead of the actual product, and so on. So you need to protect the entire flow, from registration to login to checkout to post-purchase, not just the checkout itself. Many merchants are strong at checkout fraud but weak at post-purchase abuse, and that's where they lose money. This is a trend we're increasingly seeing.

TS: Amazing, "bye, liars," I've never heard that before and I'm 100% going to use it again. Galit, that's all we have time for today. Thank you so much for sharing all your insights, it's been great speaking with you.

GSM: Thank you.

Meeting with the best in the business

Primer puts you in control of how money moves across the business. With our unified infrastructure you can orchestrate every flow, reduce friction, and capture more revenue everywhere.

Revolut Bank
Revolut Bank
Revolut Bank
Revolut Bank
Revolut Bank
Revolut Bank
Revolut Bank

Latest episodes

Episode
15

July 23, 2026

The next era of payments: AI, data & the end of the “black box”

Featuring:

Theo Spyrides

&

Gabriel Le Roux

In this episode of Payments Unfiltered, Theo Spyrides sits down with our co-founder and CEO Gabriel Le Roux to discuss where payments are heading next, why AI in payments is more about context than prompts, and what payments intelligence actually looks like in practice for merchants.

Episode
14

June 15, 2026

Everything merchants need to know about chargebacks with Chargeblast’s Qi Cao

Featuring:

Theo Spyrides

&

Qi Cao

Most merchants think hitting their chargeback target means they're safe. Spoiler alert: they're not. In this episode of Payments Unfiltered, Theo Spyrides speaks with Qi Cao, co-founder and CEO of Chargeblast, to unpack chargebacks, what the Visa Acquiring Monitoring Program (VAMP) actually means for merchants, and why the merchants who manage disputes best are the ones who've already fixed their business model.

Episode
13

April 30, 2026

What is really takes to build and run a PSP at global scale with Worldpay’s James Fry

Featuring:

Theo Spyrides

&

James Fry

This is Part 2 of our conversation with James Fry, Head of Enterprise Product at Worldpay (now part of Global Payments). Most people know what a PSP does. Far fewer know what it actually takes to build and run one. In this episode of Payments Unfiltered, Theo Spyrides, VP of Product at Primer, and James pull back the curtain. James also shares how he thinks about structuring product teams inside a large payments organization and his advice for anyone building payment technology today.

Episode
12

March 19, 2026

From commodity to competitive advantage with James Fry at Worldpay

Featuring:

Theo Spyrides

&

James Fry

In this episode of Payments Unfiltered, Theo Spyrides, Head of Product at Primer, sits down with James Fry, Head of Enterprise Product at Worldpay (now part of Global Payments), to explore how merchants have evolved their approach to payments, and what that means for the payment providers supporting them. James also shares his perspective on two of the biggest trends reshaping the space: stablecoins as an additional payments rail for global merchants, and agentic commerce as a new channel that will require the industry to solve for trusted agents, fragmented protocols, and a whole new model of intent verification.

Episode
11

February 19, 2026

The shifts reshaping enterprise payments with Citi’s Will Artingstall

Featuring:

Theo Spyrides

&

Will Artingstall

In this episode of Payments Unfiltered, Theo Spyrides, Head of Product at Primer, is joined by Will Artingstall, Global Head of Digital Asset Payments and ecommerce Services at Citi. Will shares how Citi is working more closely with enterprise merchants as payment flows become more complex and new rails begin to emerge. They discuss how large organizations are approaching these changes in practice, and what it means for how payments are designed and managed.

Episode
10

January 21, 2026

How AI shoppers are forcing merchants to rethink fraud with Riskified’s Jeff Otto

Featuring:

Theo Spyrides

&

Jeff Otto

In this episode of Payments Unfiltered, Theo Spyrides, Head of Product at Primer, sits down with Jeff Otto, CMO at Riskified, to explore what happens when software starts acting on behalf of customers and what that means for risk, fraud, and merchant exposure. They discuss how agentic commerce changes who initiates a transaction, how trust is established, and why introducing an agent into the flow raises new questions around risk ownership and liability.

Episode
9

September 24, 2025

The business of play with Xsolla’s Berkley Egenes

Featuring:

Theo Spyrides

&

Berkley Egenes

Payments aren’t just infrastructure in gaming, they’re critical to the industry’s growth. From local wallets and currencies to mobile browser checkout, the way players pay now decides how studios scale. In this episode of Payments Unfiltered, Berkley Egenes, Chief Marketing & Growth Officer at Xsolla, joins host Theo Spyrides to outline a practical playbook for global game monetization.

Episode
8

July 31, 2025

Why low fraud isn’t always a win, with Galit Shani-Michel of Forter

Featuring:

Theo Spyrides

&

Galit Shani-Michel

Low fraud and chargeback rates? Great. But what if it’s costing you customers? In this episode of Payments Unfiltered, host Theo Spyrides is joined once again by Galit Shani-Michel, VP of Emerging Products at Forter, to explore the hidden risks of a “zero fraud” mindset. From KPI misalignment to false declines and friction-filled 3DS flows, Galit explains how well-meaning fraud strategies can quietly damage conversion, customer experience, and long-term growth.

Episode
7

April 16, 2025

Merchants, money & the mechanics behind the scenes with Natasha de Teran

Featuring:

Theo Spyrides

&

Natasha de Teran

In this episode of Payments Unfiltered, Theo Spyrides speaks with Natasha de Teran, author of The Payoff and former Head of Corporate Affairs at SWIFT, about the hidden complexity behind everyday transactions. Together, they unpack the frictions built into today’s payment rails, the rising role of regulators, and whether CBDCs and account-to-account payments are viable challengers to cards. Natasha brings a rare blend of policy insight and hands-on merchant experience to the conversation, questioning what’s changing in payments and who those changes are actually for.

Subscribe and never miss an episode

The next move is yours

Want to join the podcast