惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
WordPress大学
WordPress大学
月光博客
月光博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
大猫的无限游戏
大猫的无限游戏
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 聂微东
Apple Machine Learning Research
Apple Machine Learning Research
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
雷峰网
雷峰网
小众软件
小众软件
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 叶小钗
美团技术团队
宝玉的分享
宝玉的分享
Hugging Face - Blog
Hugging Face - Blog
阮一峰的网络日志
阮一峰的网络日志
A
About on SuperTechFans
Jina AI
Jina AI
D
Docker
Last Week in AI
Last Week in AI
MongoDB | Blog
MongoDB | Blog
Stack Overflow Blog
Stack Overflow Blog
Microsoft Azure Blog
Microsoft Azure Blog

Help Net Security

Your work apps are quietly handing 19 data points to someone ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security
MITRE releases a shared fraud-cyber framework built from ...
Mirko Zorz · 2026-04-13 · via Help Net Security

Financial fraud losses in the United States reached $16.6 billion in 2024, up from $4.2 billion in 2020. Behind those numbers is a structural problem: the teams responsible for stopping fraud, fraud investigators and cybersecurity analysts, have historically operated separately, using different tools, different terminology, and different mental models of how attacks unfold.

The MITRE Fight Fraud Framework, known as F3, is a behavior-based model designed to give both teams a common structure for describing, detecting, and disrupting fraud campaigns.

MITRE Fight Fraud Framework

A model built from observed fraud behavior

F3 organizes fraudster behavior into tactics and techniques drawn from real-world incidents. The tactics cover the full attack lifecycle: Reconnaissance, Resource Development, Initial Access, Defense Evasion, Positioning, Execution, and Monetization.

Two of those tactics, Positioning and Monetization, do not appear in MITRE ATT&CK, the established framework for cyberattack behavior. Positioning covers the adversary’s actions in a selected environment after gaining access, including collecting data or preparing for execution. Monetization covers converting stolen assets into usable funds or value. These additions reflect the financial end goal that distinguishes fraud from other cyberattacks.

Where a tactic or technique already exists in ATT&CK, F3 uses it directly with definitions modified for fraud-specific outcomes. Fraud-specific techniques that fall outside ATT&CK receive F1XXX-series designations to maintain compatibility with the broader ATT&CK schema.

What sets F3 apart from rule-based detection

Organizations currently rely on rule-based fraud detection systems that apply predefined conditions to transaction data and trigger decisions to approve, decline, or flag activity. F3 operates at a different level.

Speaking to Help Net Security, the MITRE CTID Research Team described the distinction: “F3 is a behavior-based model that maps how fraud occurs. It codifies fraud actors’ tactics and techniques across the full lifecycle, based on real-world incidents. In essence, F3 answers: ‘What is the adversary trying to achieve at this stage, and how do they typically do it?’ By doing so, it enables organizations to understand and describe complete fraud campaigns rather than isolated suspicious events.”

The team notes that F3 can inform and improve rule design by grounding detection logic in observed fraud behaviors and attack sequences. F3 itself does not score transactions or make enforcement decisions. Rules, heuristics, or machine learning models remain necessary to determine whether to allow, block, or escalate activity.

Bringing fraud and cyber teams together

The MITRE Fight Fraud Framework gives fraud analysts a way to describe incidents using consistent behaviors, gives cyber teams a structure for detecting and validating adversary techniques, and gives security leaders a basis for assessing risk tied to how fraud actually unfolds.

The MITRE CTID Research Team outlines a practical path for organizations starting to use the framework: “Integrate fraud and cybersecurity teams. Bring fraud investigators and cyber analysts together through shared workflows, collaboration, and joint analysis to strengthen detection and response capabilities. Document incidents and trends using MITRE F3. Use the MITRE F3 framework to standardize how fraud scenarios, techniques, and patterns are recorded. Map F3 techniques to data sources. Align documented F3 techniques with your organization’s data sources to better identify and monitor adversary behaviors.”

Design principles behind F3

Four principles guided the framework’s construction. Institutions must be able to observe the effects of a technique during the fraud incident. Every incident in F3 includes at least one digital or technological method, such as phishing, malware, or unauthorized access. Techniques describe the behavior of the adversary, focusing on distinct, observable actions rather than on entities or tools. Behaviors that appear in multiple concrete forms are captured as sub-techniques to keep the framework at a consistent level of abstraction.

These principles tie F3 to observable fraud behavior and keep it applicable to cyber threat intelligence, detection engineering, and security control design.

A living framework

F3 is designed to be updated continuously as new fraud schemes emerge and adversaries adapt their techniques. MITRE plans to add data sources for detecting fraudster techniques and recommended mitigations as the framework grows. Organizations can review the framework, suggest edits, prioritize future content, and contribute new techniques or refinements at the F3 website.