top of page



Cyber Resilience in Financial Services: DORA, OSA and the Operational Risk Frontier of 2026
Cyber security has graduated from a technology discipline to a board-level operational resilience requirement. The European Union's Digital Operational Resilience Act became fully applicable in January 2025, and is now in its first full year of supervisory enforcement; the UK's Operational Resilience framework is approaching its 2025 transition deadline; and the United States is finalising rules under the SEC, OCC, and FFIEC that align increasingly closely with the European m

TrustSphere Network
Jun 255 min read


Chargeback Inflation: First-Party Misuse, Friendly Fraud and the Battle for Card-Not-Present Integrity
Chargeback volumes have entered a structural growth phase. Card-not-present commerce now accounts for the majority of card payment value in most developed markets, and the share of chargebacks classified as first-party misuse — where the genuine cardholder disputes a transaction they themselves authorised — has risen to a level that materially distorts the economics of e-commerce, subscription, and digital-services merchants.

TrustSphere Network
Jun 255 min read


The Software Supply Chain Problem: Why Cyber Resilience in Banking Now Reaches Every Vendor
The cyber posture of a Tier 1 bank is increasingly only as strong as the weakest third-party SaaS vendor in its delivery chain. Concentration risk in cloud, identity, and observability tooling has turned into one of the most material — and least managed — operational risks in financial services.

TrustSphere Network
Jun 254 min read


Agentic Account Takeover: When the AI Buying Agent Itself Becomes the Compromised Endpoint in 2026
The agentic-commerce conversation through 2025 and into 2026 has focused almost entirely on what happens when an AI agent transacts honestly on a u...

TrustSphere Network
Jun 245 min read


Q-Day on the Horizon: Why Payment Infrastructure Has to Move on Post-Quantum Cryptography Now
The quantum-computing community has stopped arguing about whether a cryptographically relevant quantum computer is possible and has moved on to arguing about when. Conservative estimates put cryptanalytically useful quantum capability at the early 2030s. Less conservative ones put it sooner. Either way, the half-life of payment messages, card cryptograms and TLS-protected session keys means the harvest-now-decrypt-later attack model already applies to any sensitive material m

TrustSphere Network
Jun 114 min read


The Synthetic Brokerage: How AI-Generated Trading Platforms Have Industrialised Pig-Butchering Investment Scams in 2026
The 2024–2025 wave of relationship-led investment scams — the so-called "pig-butchering" typology — was built on a labour-intensive playbook: a lon...

TrustSphere Network
Jun 45 min read


The End of the Periodic Review: How Perpetual KYC Has Become the 2026 Default for Customer Due Diligence
The periodic customer review — the calendar-driven exercise in which a financial institution refreshes KYC and risk data on a low, medium or high c...

TrustSphere Network
Jun 15 min read


Inside VAMP: How Visa's Acquirer Monitoring Programme Has Quietly Rewired Chargeback Economics in 2026
The 2025 rollout of the Visa Acquirer Monitoring Programme — VAMP — was treated initially as a tidying-up exercise that consolidated the old Visa D...

TrustSphere Network
May 315 min read


Mule Networks Under New Pressure: Why Telcos and Social Platforms Are Now in the Anti-Fraud Frontline
The first quarter of 2026 has cemented something fraud teams have argued for years — that money mules are recruited, not born. Recent PSR and HM Treasury consultation papers, alongside live enforcement under the Online Safety Act, have moved the conversation from "make banks find the mules" to "make recruitment platforms stop creating them in the first place." Ofcom's late-2025 priority direction on illegal financial harms, combined with the FCA's January 2026 Dear CEO letter

TrustSphere Network
May 314 min read


Calling the Help Desk: How Scattered-Spider-Style Social Engineering Became the 2026 Account-Takeover Vector Banks Underestimated
The Scattered Spider playbook — confidently calling a help desk, impersonating an internal employee or a high-value customer, and talking the agent...

TrustSphere Network
May 305 min read


The Predictive AML Stack: From Reactive SAR Filing to Anticipatory Detection
Anti-money-laundering programmes have spent two decades filing suspicious activity reports about transactions that have already moved. The next generation of AML platforms is being designed around a fundamentally different premise — predicting the typology before the payment leaves the bank, and intervening with the same evidentiary rigour required for a SAR.

TrustSphere Network
May 284 min read


First-Party Misuse: The Quiet Chargeback Epidemic Eating Merchant Margins
First-party misuse, often described as friendly fraud, has become the largest single category of card-not-present chargebacks for many merchants. Unlike third-party fraud, where a stranger uses stolen credentials, first-party misuse is committed by the legitimate cardholder who later disputes a transaction they authorised. The result is a slow, structural drain on merchant margins that traditional fraud controls cannot detect.

TrustSphere Network
May 273 min read


Network Tokens and Issuer Fraud Operations: How Tokenisation Is Quietly Rewriting Card Risk Models
Network tokenisation has crossed the threshold from optional optimisation to default infrastructure for card payments. With network tokens now provisioned automatically across major issuer portfolios in the UK, EU and US, fraud teams that built their detection logic around primary account numbers are discovering that the signals they relied on for years no longer behave the way they did. Risk models, dispute workflows, and step-up rules all need recalibration — quietly, but q

TrustSphere Network
May 193 min read


TrustSphere Vendor Spotlight: Quantexa — Contextual Decision Intelligence for Financial Crime
Quantexa has established itself as one of the most influential financial crime technology vendors of the past decade. Its contextual decision intelligence platform is used by some of the world's largest banks, government agencies and insurance groups, and it anchors a category that combines entity resolution, network analytics and machine learning at enterprise scale. In this Vendor Spotlight, we examine what Quantexa actually does, where it adds distinctive value, and the co

TrustSphere Network
May 173 min read


When Scammers Get Smart: How Generative AI Is Industrialising Voice, Video and Identity Fraud
Generative AI has moved from novelty to weapons-grade in less than three years. Voice cloning that requires fewer than fifteen seconds of source audio, deepfake video that survives liveness checks, and large-language-model-generated phishing prose that is grammatically flawless in any language have collectively dismantled the heuristic defences on which most consumer fraud detection has historically relied.

TrustSphere Network
May 145 min read


Chargebacks at the Tipping Point: First-Party Misuse and the End of Frictionless Refunds
Chargeback volumes are climbing again across card-not-present commerce, and the dominant driver is no longer organised criminal fraud but first-party misuse — customers disputing legitimate purchases for convenience or buyer's remorse. The frictionless refund era is ending; the next phase will reward institutions that can tell genuine fraud, friendly fraud, and merchant error apart at speed.

TrustSphere Network
May 143 min read


Synthetic Identities at Industrial Scale: How Generative AI Is Manufacturing Fake Customers
Synthetic identity fraud has crossed the threshold from niche typology to systemic risk in 2026. Generative AI has industrialised every step of the synthetic identity supply chain — from inventing plausible biographies to producing photorealistic ID documents and animated liveness footage — and the cost of producing a 'good' synthetic now sits well below the value of a single approved retail credit line.

TrustSphere Network
May 144 min read


Compelling Evidence 3.0 One Year On: How Issuer-Acquirer Liability Is Re-Rebalancing in Card Disputes
Visa Compelling Evidence 3.0 was the most consequential change to the card-not-present dispute regime in a decade. A year on, the rebalancing of issuer and acquirer liability is producing a clear pattern of winners and losers — and quietly reshaping how merchants, processors and banks invest in dispute defence.

TrustSphere Network
May 144 min read


Deepfake CEO Fraud Goes Industrial: When Treasury Calls Become Synthetic
The 2024 Hong Kong incident, in which a finance employee was tricked into wiring USD 25 million after a fully synthetic video conference with what appeared to be the CFO and several senior colleagues, was treated at the time as a cautionary one-off. Two years later it looks more like an opening shot. Generative AI has industrialised the production cost of executive impersonation, and treasury and accounts-payable functions are now squarely in the crosshairs. Regulators have n

TrustSphere Network
May 134 min read


Chargeback Inflation: Why First-Party Misuse Is Reshaping the Card Issuer Loss Curve
Chargeback volumes have outpaced card spend growth for three consecutive years, and what was once treated as a back-office dispute workflow is now a strategic loss line for issuers and merchants. The growth is no longer driven by classical card-not-present fraud — it is being driven by first-party misuse, where the legitimate cardholder disputes a transaction they recognise. This shift is forcing a fundamental rethink of evidence, liability and dispute economics.

TrustSphere Network
May 133 min read
bottom of page
