Fraud has not been solved.It has been redistributed.
- Sean Murphy

- Jun 9
- 4 min read

An interview with Julien Gabillet, by Sean Murphy
A consumer receives a package, takes a quick photo, and asks a generative AI model to add a tear or a scuff mark. The doctored image then travels to the issuing bank with a refund request attached. The product is fine. The customer keeps both the goods and the money. According to Julien Gabillet, Lead Risk Director at Visa Europe for France, Belgium and Luxembourg, this kind of first-party fraud now represents around a fifth of fraudulent disputes globally, rising to 30 per cent for high-volume online merchants, and it is the cleanest illustration of where the industry's risk problem is heading.
For most of Visa's six decades in Europe, the company's fraud strategy has been an arms race against criminals trying to break the technology. Tokenisation, biometric authentication, 3D Secure, the various iterations of Click to Pay and Visa
Payment Passkeys: each was designed to take a layer of vulnerability out of the payment itself. The results, Gabillet argues, speak for themselves. Over the past three years, card fraud in Europe has fallen by 24 percent on Visa's network, with around 60 percent of e-commerce now running on tokenised credentials. The company says it has put over 11 billion dollars into security and resilience over the past five years.
What the numbers do not capture is the shift in where the criminals have gone. The fraud is moving from technology fraud to social fraud, Gabillet says, and the consequences are different. When a card was compromised, the loss was limited by what was on the card. When a human is compromised, the losses can run into thousands of euros at a time, and the damage can extend beyond the financial. Victims of romance scams, fake-merchant scams, and so-called bank-impostor schemes often hide what happened from their families and their banks, which can make pattern detection harder and recovery slower.
AI can reshape every stage of this new fraud economy. Before the payment, generative tools allow criminals to assemble synthetic identities, stitching together fragments of personal data, social media exposure, and phishing yields into convincing profiles that can be sold on or used directly. During the payment, AI can produce fake storefronts that mimic legitimate brands, offering deeply discounted goods that require only a small shipping fee. Card credentials captured at that point may sit unused for months before being exploited through recurring billing that consumers struggle to spot. After the payment, the doctored-package trick illustrates how the same tools that protect transactions can be turned against the merchant.
The fraud is not only changing in character, it is changing rails. The 24 percent drop on card fraud has been mirrored by a steady migration of criminal activity towards account-to-account transfers, which in many European markets still lack the embedded fraud controls and reimbursement frameworks that card schemes have spent decades building. The banks themselves bear part of the blame having historically run their card and account-to-account fraud teams as separate silos with separate tools and separate dashboards. That separation is no longer sustainable when the criminal sitting on the other end of the screen sees one consumer, not two product lines.
To respond, Visa has been steering its capabilities towards what Gabillet calls a fight between AI and AI. The Visa Advanced Authorization score, long used to assess card transactions in real time, now sits alongside newer models built for emerging attack patterns. One example is the score designed to detect enumeration attacks, the brute-force technique fraudsters use to discover valid card credentials. In late 2024, Visa acquired Cambridge based firm Featurespace, whose AI fraud detection is structured around user behaviour rather than transaction patterns. Crucially, it runs across card payments, account-to-account transfers, login events and even KYC checks at account opening, building a single view of risk across what a customer is actually doing rather than what payment rail they happen to be using.
The third plan is cooperation, and this is where Gabillet sounds most insistent. Visa Scam Disruption, launched in 2024, pools intelligence from across the network and has so far dismantled around 25,000 scam-selling operations representing more than $1 billion globally, including €220 million in Europe. Regulators also promote data sharing: France's new bank-to-bank fraud-data-sharing platform, live since May, will connect with FRIDA, the new European fraud-data-sharing hub which is expected to launch in 2028. Success is limited, he stresses, without the consumer at the table alongside banks, merchants, schemes, acquirers and payment service providers.
Despite the industry’s best efforts, fraud has not been solved, It has just been redistributed. The bank card itself is now one of the safer places a euro can sit, but the human holding it is more exposed than ever, and the next frontier of payments, agentic commerce, will introduce a fresh set of questions about who, or what, is authorising a transaction in the first place. Gabillet puts it plainly, the same technologies that secured the payment, he says, can now help secure the identity behind it. The fight has simply moved upstream.
.png)


