Adopting the Analyst Mindset: Uncovering Fraud Through Curiosity and Action

Layne Hanson (Threat Analyst)

SAINTCON 2025 · Day 1 · Main Track 1

Overview

Layne Hanson, a cybersecurity threat analyst and officer at Labs, delivered a compelling talk at SAINTCON detailing her journey from feeling lost in her career to successfully mitigating significant financial fraud. The presentation, titled "Adopting the Analyst Mindset: Uncovering Fraud Through Curiosity and Action," chronicles Hanson's proactive approach to identifying and disrupting a sophisticated fraud operation that targeted her employer, a major contact lens retailer. Over a four-month period, her efforts led to the prevention of over $64,000 in fraudulent losses, with the potential for even greater savings as her program matured.

Watch on YouTube

Visual summary for Adopting the Analyst Mindset: Uncovering Fraud Through Curiosity and Action by Layne Hanson
Visual summary for Adopting the Analyst Mindset: Uncovering Fraud Through Curiosity and Action by Layne Hanson

Key moments

  1. 0:00 Introduction: Mitigating $64k Fraud Story
  2. 2:18 Defining the Analyst Mindset: Curiosity and Action
  3. 3:07 The Pervasive Impact of Business Fraud
  4. 6:00 Initial Observations: Key Fraud Patterns and Tactics
  5. 7:07 How existing fraud prevention controls were bypassed
  6. 7:56 Iterative Cycle for Fraud Detection and Tuning
  7. 9:00 The Urgency: A Race Against Time for Mitigation

Adopting the Analyst Mindset: Uncovering Fraud Through Curiosity and Action

Speakers: Layne Hanson (Threat Analyst)

Conference: SAINTCON

YouTube: https://www.youtube.com/watch?v=3mMgGG5go7s

Overview

Layne Hanson, a cybersecurity threat analyst and officer at Labs, delivered a compelling talk at SAINTCON detailing her journey from feeling lost in her career to successfully mitigating significant financial fraud. The presentation, titled "Adopting the Analyst Mindset: Uncovering Fraud Through Curiosity and Action," chronicles Hanson's proactive approach to identifying and disrupting a sophisticated fraud operation that targeted her employer, a major contact lens retailer. Over a four-month period, her efforts led to the prevention of over $64,000 in fraudulent losses, with the potential for even greater savings as her program matured.

The core of Hanson's talk emphasizes the importance of the analyst mindset – an approach characterized by curiosity, creativity, and a hands-on engagement with data. She illustrates how this iterative, hypothesis-driven methodology allowed her to transform a passion project into a critical business function, ultimately shaping her career trajectory and providing her with invaluable, transferable skills in data analysis, stakeholder communication, and incident response. This article delves into the methodologies, technical challenges, and strategic insights shared by Hanson, offering a blueprint for organizations facing similar threats.

Hanson's story is a powerful testament to the impact a dedicated individual can have within an organization, even when operating with limited resources. Her ability to identify patterns, develop custom detection logic, and implement effective countermeasures against evolving fraud tactics highlights the critical role of human intelligence and analytical rigor in modern cybersecurity. The talk serves as an inspiration for aspiring and seasoned security professionals alike, demonstrating that significant contributions can arise from a curious mind willing to take action.

Background

▶ Watch: Introduction: Mitigating $64k Fraud Story (0:00)

To understand the context of the fraud, Hanson first established the regulatory landscape surrounding contact lenses. Despite being a common consumer product, contact lenses are classified as a medical device by the FDA, necessitating a valid prescription from an eye care physician or general practitioner for purchase in the United States. While national regulations are stringent, international rules vary significantly; for instance, Japan restricts purchases to a two-month supply, with excess quantities disposed of by customs. Internally, Hanson's employer had a policy to contact doctors for prescription verification, with orders shipping in "good faith" if no response was received within 24 hours. This regulatory framework, intended for patient safety, inadvertently created vulnerabilities for exploitation.

Hanson defines the analyst mindset as akin to the scientific method: forming an educated guess (hypothesis), designing an experiment to test it, and observing the results. More broadly, she characterizes it as lead-driven context-based discovery and action, emphasizing curiosity, creativity with data, and a hands-on approach to understanding how systems and behaviors work. This mindset was crucial because, as Hanson asserts, "where there's business, there is fraud." She cited a 2020 survey by S&P Global (451 Research) which found that 41% of 263 respondents considered fraud a significant concern impacting their business. Key impacts included a high negative effect on customer experience, damage to brand and reputation, and an adverse impact on authorization rates – the fees charged by payment networks like Visa and Mastercard when a merchant experiences numerous payment disputes or chargebacks. Hanson's initial involvement stemmed from her role as a customer service supervisor, where she observed these issues firsthand and, due to a lack of dedicated headcount, took on the problem as a "passion project."

Key Findings

▶ Watch: The Pervasive Impact of Business Fraud (3:07)

Hanson's initial observations provided the foundational clues for her investigation. She noted an abnormally high rate of payment disputes where, paradoxically, the ordered product did arrive at the customer's address. Further investigation revealed the widespread use of mail forwarding services, suggesting that orders were not going to legitimate residential addresses but to intermediary businesses before being rerouted. The fraudsters also employed fake identities and relied heavily on fraudulent prescriptions, which Hanson noted were surprisingly easy to create, often just a Word document with a faked signature, exploiting the system's reliance on "face value" verification.

Gaining visibility was her first challenge, which she approached as an iterative cycle. This involved slow parsing of event data, flagging events that met certain detection criteria, reviewing them, taking action (e.g., cancelling an order), and then tuning her alerts based on whether the flag was a true or false positive. This continuous feedback loop allowed her to refine her internal intelligence. A significant hurdle was the business's core goal: rapid order fulfillment. With orders shipping out within 24 hours due to the company's large inventory, Hanson was in a race against time, often unable to review and act on detections before products were already shipped.

To overcome the lack of pre-existing fraud detection infrastructure, Hanson had to get creative with data sources. She leveraged the company's Splunk instance, adapting existing developer queries to extract relevant information. She also implemented a daily keyword scan of account notes, looking for terms indicating fraud or chargebacks, which then flagged accounts for her review and fed into her closed intelligence loop. Recognizing a pattern of failed transactions, she added signals based on high rates of payment add failures, inferring the use of stolen credit cards that had either been canceled or blocked by banks. Her query reuse extended to exposing account to address relationships, allowing her to build intelligence by linking frequently used addresses to multiple accounts. Finally, she created a session ID and account linkage dashboard to aid in investigations, providing a way to connect disparate fraudulent activities.

These efforts began to unlock distinct behavioral patterns. Fraudsters were engaging in typo squatting evasion with drop shipping addresses, adding subtle alterations (e.g., "3" instead of "E", extra spaces) to known fraudulent addresses to bypass blocklists. The company's fast shipping was actively exploited, creating a narrow window for intervention. High card add failures often led to fraud locks, where the system would deny even valid card attempts after numerous failures. The obfuscation of digital identity was common, with widespread VPN usage and IP rotation. Other observed behaviors included abnormal and frequent site refreshes to check order status, multi-account creation (requiring creation of multiple email addresses), and a particularly cunning tactic: strategic use of the online customer service feature to update an order's shipping address to a known fraudulent one after the order was initially placed with a legitimate-looking address, effectively bypassing Hanson's early detection logic that focused only on the initial order details.

Technical Deep Dive

▶ Watch: Initial Observations: Key Fraud Patterns and Tactics (6:00)

Hanson's technical investigation was rooted in leveraging existing data infrastructure and creatively manipulating it to reveal hidden patterns. Her primary tool for data aggregation and analysis was Splunk. She began by examining existing queries developed by engineers, understanding their outputs, and then adapting them to her specific fraud detection needs. This iterative process of query reuse and tuning allowed her to extract data points relevant to account activities, order statuses, and payment attempts.

A crucial custom detection mechanism involved parsing account notes for specific keywords. Fraudsters, or internal customer service agents interacting with them, might leave notes that, when scanned daily, could trigger an alert. This keyword scan provided a proactive signal for potential fraud or confirmed chargebacks, feeding directly into her closed intelligence loop.

Recognizing that stolen credit cards were a likely vector, Hanson implemented signals to detect high rates of payment add failures. Multiple failed attempts to add a credit card to an account indicated either a compromised card that had been canceled, or a bank's fraud detection system actively blocking the transaction. This insight allowed her to flag accounts even before a successful fraudulent purchase.

To understand the network of fraud, Hanson developed methods to expose account to address relationships. By plugging in a suspicious address, she could identify all associated accounts and past orders, building a historical context of its usage. Similarly, she created a session ID and account linkage dashboard. A session ID, a unique identifier for a user's interaction with the website, allowed her to "fingerprint" fraudsters. Even with IP rotation and VPN usage, persistent session IDs could link multiple seemingly disparate accounts back to a single actor or group, providing invaluable evidence for behavioral grouping.

The behavioral analysis led to the identification of two distinct Known Fraudulent Actor (KFA) entities, which Hanson internally designated KFA1 (01) and KFA2 (02).

KFA1 (01) Characteristics and Tactics:

  • Aliases: Primarily used Eastern Asian aliases.
  • Networks: Operated predominantly from Eastern Asian and Australian networks, suggesting a geographical origin or pivot points in those regions.
  • Digital Obfuscation: Employed IP rotation session reuse. This meant they would frequently change their external IP address (likely via VPNs), but maintained the same underlying session ID by logging in and out of multiple accounts, allowing Hanson to track their activities across different accounts.
  • Order Strategy: Engaged in low value order spam, placing numerous small orders designed to fly under the radar of typical high-value fraud detections.
  • Customer Service Interaction: Uniquely, KFA1 interacted with customer service, even expressing frustration when their fraudulent activities were detected. This provided additional behavioral data points.
  • Disruption Difficulty: Easier to disrupt due to the ability to track their persistent session IDs.

KFA2 (02) Characteristics and Tactics:

  • Aliases: Used a significant number of Slavic aliases, indicating a different cultural background.
  • Networks: Primarily utilized American and Canadian networks, making their geographical origin harder to pinpoint initially.
  • Digital Obfuscation: Also used IP rotation with high refresh rates, but unlike KFA1, they did not exhibit observable session reuse, making traditional session-based fingerprinting more challenging. They were constantly refreshing their connection and possibly creating new sessions.
  • Order Strategy: Characterized by placing very high value orders, which paradoxically triggered detections more frequently but were harder to stop due to the rapid shipping times. Hanson described them as "brave."
  • Prescription Forgery: Hanson dubbed them "fraud prescription mailers." They exploited online services designed for prescription renewal to generate seemingly legitimate, yet fake, prescriptions for random product information, effectively bypassing the prescription verification step with documents that appeared valid.
  • Disruption Difficulty: Harder to disrupt due to their speed and lack of session reuse, combined with the absence of a dedicated fraud response program beyond Hanson's individual efforts.

A particularly insidious technical evasion involved typo squatting evasion for shipping addresses. Fraudsters would slightly alter known fraudulent addresses (e.g., "123 Main St" becoming "123 Main Str" or "123 Mian St"). The company's shipping system, however, was designed to be resilient, with shippers often correcting labels to ensure delivery, inadvertently aiding the fraudsters. This highlighted a gap in detection logic that needed to be addressed. The exploitation of the online customer service feature was another sophisticated maneuver: placing an order with a benign address, then contacting customer service to update the shipping address to a fraudulent one after the initial fraud detection window. This bypassed early detection rules that only scanned the address at the point of order placement.

Demo / Proof of Concept

▶ Watch: Iterative Cycle for Fraud Detection and Tuning (7:56)

This technical article is based on a conference talk that primarily detailed a real-world case study and the speaker's investigative process. As such, there was no live technical demonstration or proof of concept of a specific tool or exploit during the presentation. Instead, Layne Hanson effectively "demonstrated" her methodologies and findings through a comprehensive narrative of her analytical journey, illustrating how she identified patterns, built detection logic, and implemented countermeasures within her organization's existing systems. The efficacy of her approach was proven by the tangible result of mitigating $64,000 in fraud.

Defensive Implications

▶ Watch: The Urgency: A Race Against Time for Mitigation (9:00)

Hanson's efforts yielded several critical defensive strategies that organizations can adopt to combat similar fraud operations. These implications span technical controls, operational adjustments, and human factors:

  1. Evolving Address Blocklists and Wildcard Queries: Recognizing that fraudsters used typo squatting evasion, Hanson moved beyond static address blocklists. She developed wildcard queries based on known constants within addresses, such as specific street numbers or zip codes. For example, if a fraudulent address always contained "4242" as the residence number or a particular zip code, her detection logic would flag any address matching that pattern. While this initially led to some false positives, continuous tuning improved accuracy significantly. This adaptive approach is crucial as fraudsters constantly modify their details.
  1. Package Recall: For orders already shipped within the United States, Hanson implemented a package recall process. She would send requests to shipping carriers like UPS to intercept and return packages before they reached the fraudulent destination. This directly prevented the loss of product, even if the initial detection was delayed.
  1. Account Lockouts and Order Holds: Implementing system-level account lockout mechanisms for accounts exhibiting suspicious behavior (e.g., numerous failed payment attempts, multi-account creation) was a direct countermeasure. Additionally, placing holds on orders flagged as potentially fraudulent bought critical time for manual review and verification before products left the warehouse.
  1. Temporary Net Blocks with OSINT: To combat VPN usage and IP rotation, Hanson engaged in session monitoring. When a suspicious IP address was identified, she would use open source intelligence (OSINT) to determine if it belonged to a known VPN provider, identify its ASN (Autonomous System Number), and then implement temporary net blocks on the associated IP ranges. While fraudsters could refresh their connection to obtain a new IP, this forced them to connect to an entirely different VPN server, increasing their operational cost and making their activities more difficult.
  1. Enhanced Session Monitoring: Beyond IP addresses, the ability to track and link session IDs to multiple accounts proved invaluable, especially for KFA1. This kind of deep session monitoring allows for more accurate fingerprinting of actors, even when they attempt to obfuscate their network presence.
  1. Security Awareness Training: Recognizing that front-line employees are often the first point of contact with fraudsters, Hanson initiated security awareness training for both call center representatives and shipping teams. She educated them on the specific behaviors exhibited by fraudsters (e.g., multi-account creation, specific types of address changes via chat, signs of customer frustration when caught). This empowered employees to identify suspicious activity and escalate it to her team, effectively extending her detection capabilities across the organization.
  1. Advocacy for Resources and Collaboration: Hanson's journey underscored the importance of business advocation. By quantifying her impact ($64,000 mitigated), she was able to secure access to additional resources, such as deeper Splunk access and collaboration with developers for more sophisticated queries. This highlights that demonstrating tangible value is key to gaining organizational support for security initiatives.

In essence, the defensive strategy was an iterative process of continuous learning, adaptation, and refinement. As fraudsters evolved their tactics (e.g., shifting from initial order address fraud to post-placement address updates via customer service), Hanson's detection logic and countermeasures also had to evolve. This constant feedback loop between observation, detection, action, and tuning is fundamental to building a resilient fraud prevention program.

Key Takeaways

  • Embrace the Analyst Mindset: Cultivate curiosity, creativity, and a hands-on, hypothesis-driven approach to problem-solving, even for challenges outside a traditional job description.
  • Fraud is Inevitable and Adaptable: Businesses must recognize that fraud is a constant threat that will evolve its tactics. Proactive and continuous monitoring, rather than static defenses, is essential.
  • Visibility Unlocks Behavior: Gaining deep visibility into data sources and user behavior patterns is critical for identifying and understanding sophisticated fraud operations.
  • Iterative Learning is Key: Security is an iterative process of failure and success. Learn from false positives, tune detections, and continuously build internal intelligence.
  • Collaborate and Communicate: Effectively communicate the value of security initiatives with stakeholders, using quantifiable results to advocate for necessary resources and organizational support.
  • Empower Front-Line Defenders: Educate and train customer service and operational teams to recognize and escalate suspicious activities, extending the organization's defensive perimeter.

About the Speaker(s)

Layne Hanson, who also goes by the online handle "Spooks," is a cybersecurity threat analyst. She is an officer on Labs, a local hackers nonprofit organization based in Salt Lake. Her career journey, as highlighted in this talk, demonstrates a strong passion for security and a proactive approach to problem-solving. Prior to her role as a threat analyst, Hanson worked as a customer service supervisor, a position that provided her with firsthand exposure to the fraud problems she later dedicated herself to mitigating. Her experience showcases how curiosity and self-driven initiative can lead to significant career progression and impactful contributions in the security field.

All talks from SAINTCON 2025