PayPal's Blake Butler on Finding Fraud Signals in Uncleaned Data
JAN 29, 202642 MIN
PayPal's Blake Butler on Finding Fraud Signals in Uncleaned Data
JAN 29, 202642 MIN
Description
<p><a href="https://www.paypal.com/us/home"><u>PayPal</u></a>'s fraud team catches credential stuffing before money moves by watching business intelligence signals that most organizations overlook: explosive traffic growth to legacy endpoints, mismatched phone numbers against account creation locales, and anomalies hidden in raw uncleaned data. <a href="https://www.linkedin.com/in/blakebulterpaypalinfosec/"><u>Blake Butler</u></a>, Senior Manager & Head of Fraud Threat Intelligence, applies infrastructure analysis techniques from offensive security to fraud investigations. This fills the gap most organizations face: anti-fraud teams understand scam mechanics but lack technical depth, whereas infosec practitioners know infrastructure but not how criminals monetize accounts at scale.</p><p>Blake breaks down how phishing kits now bypass MFA through real-time automation. His detection philosophy: counting and explosive growth patterns beat machine learning for uncovering fraud. Data scientists clean away the signal. </p><p><strong>Topics discussed:</strong></p><ul><li><p>Applying offensive security infrastructure analysis methods to fraud threat intelligence investigations</p></li><li><p>Detecting credential stuffing and account takeover campaigns through anomalies in account creation regions, phone number locales, and explosive traffic growth</p></li><li><p>Understanding how modern phishing kits automate real-time OTP theft by integrating directly into legitimate platform APIs during password resets</p></li><li><p>Tracking massive fraud operations emerging from China and South America through business intelligence signals</p></li><li><p>Identifying fraud indicators in uncleaned data: extra spaces, unrenderable characters, and AI-generated webshop metadata artifacts</p></li><li><p>Building security communities to enable monthly collaboration with local practitioners on emerging threats and tool development</p></li><li><p>Bridging the critical talent gap between anti-fraud teams lacking technical infrastructure skills and infosec practitioners without fraud monetization expertise</p></li><li><p>Evaluating phishing-as-a-service platforms and encrypted communication tools that lower barriers to entry for criminal actors</p></li></ul><p><strong>Key Takeaways: </strong></p><ul><li><p>Monitor explosive traffic growth patterns to legacy endpoints and unusual account creation regions to detect credential stuffing.</p></li><li><p>Analyze raw uncleaned data for fraud signals including extra spaces, unrenderable characters, and metadata artifacts.</p></li><li><p>Apply infrastructure analysis techniques to fraud investigations to identify phishing domains and criminal tooling.</p></li><li><p>Track mismatches between phone number locales and account creation regions as indicators of automated account generation.</p></li><li><p>Investigate anomalies in business intelligence metrics through simple counting before deploying MLMs to uncover emerging fraud trends.</p></li><li><p>Build fraud threat intelligence teams that combine offensive security backgrounds with fraud monetization expertise to fill the critical industry talent gap.</p></li><li><p>Attend security community meetups to collaborate with local practitioners on emerging threats between annual conferences.</p></li><li><p>Implement MFA while recognizing that advanced phishing kits now automate real-time OTP theft through direct platform API integration.</p></li><li><p>Hire candidates with infosec infrastructure knowledge who understand how criminal actors use tooling to automate credential stuffing and account monetization operations.</p></li></ul><p><strong>Listen to more episodes: </strong></p><p><a href="https://podcasts.apple.com/us/podcast/future-of-threat-intelligence/id1631947902"><u>Apple</u></a> </p><p><a href="https://open.spotify.com/show/0671lFjPIgX6k2jYRrWrf4?si=c728ebaa3cb44095"><u>Spotify </u></a></p><p><a href="https://www.youtube.com/playlist?list=PL6DKwSSbBu7uAbek0EyOYNBiVXVbYIc7_"><u>YouTube</u></a></p><p><a href="https://www.team-cymru.com/podcast"><u>Website</u></a><br></p>