Breaking the Chain: Inside the Fight Against Modern Cyber Fraud

Cyber-enabled fraud cost Americans nearly $21 billion in 2025, according to the FBI. This session examines the Fraud Kill Chain and the new MITRE Cyber Fraud Framework and challenges the misconception that cyberfraud requires sophistication or insider access. It shows how exposed APIs, weak authentication, and targeted phishing create real attack surfaces, and how API monitoring, device fingerprinting, threat intelligence, and AI can help detect, disrupt, and break the fraud kill chain.


In this presentation, we will walk through the following key areas:

Fraud Kill Chain and MITRE F3 Fraud Framework Overview
A high-level walkthrough of the Fraud Kill Chain and MITRE F3 framework, establishing a shared vocabulary for how modern fraud operations are planned, staged, and executed. This framework helps practitioners map controls and identify gaps across the fraud lifecycle.

Cyber Intelligence & Dark Web Monitoring
Real-world examples of how threat actors leverage the underground ecosystem to enable fraud, including session reuse attacks, SCATTERED SPIDER-style social engineering, bot-driven credential abuse, and darkweb-collected tokens. We will cover how intelligence can provide early indicators and actionable context for defense.

Detection & Response Opportunities
Practical examples of where cybersecurity controls can disrupt the chain, covering data exposure through public APIs, call center impersonation exploiting authentication weaknesses, targeted phishing campaigns, and infostealer malware leading to wire fraud. Attendees will see how to align existing security controls to cyberfraud-specific use cases.

AI Implications
How generative AI is lowering the barrier for fraudsters across each stage of the kill chain, and how defenders can adapt

Jonathan Gonzalez

Jonathan Gonzalez graduated from the University of Texas at San Antonio with a major in Cybersecurity and Information Systems and a minor in Digital Forensics in 2020. During his collegiate career he worked in Application Security, Security Operations and Vulnerability Management before doing Digital Forensics and Incident Response (DFIR) at Crowdstrike. He is now an Assistant Vice President (AVP) of Cyber Threat Intelligence at Synchrony Financial, where he works to build and test enterprise defenses for key stakeholders. Currently, he is a graduate student studying Global Security Studies at Johns Hopkins University, deepening his understanding of the intersection between cybersecurity and global security. Outside of his professional and academic pursuits,

Gloria Haight

Gloria Haight is a VP of Incident Response at Synchrony, with over a decade of experience across CrowdStrike, Western Union, and Secureworks. She specializes in threat hunting, incident response, and security operations, holding CISSP, GCFA, GCIA, GWAPT, and GDAT certifications. Her work at the intersection of cyber and fraud drives her focus on investigation strategies that go beyond traditional security silos.