SCRASemper Clarus Risk Insights
Demo — one typology of 35

A First Principles Fraud Taxonomy

What one record looks like, end to end.

Fraud terminology is descriptive but imprecise. It blurs the channel with the method — “vishing” tells you a phone was involved, not what the fraudster did. You cannot build a control against a category that shifts underneath you.

So this taxonomy starts from what has to be true for a fraud to succeed: two methods, the typologies that realise them, and the reusable techniques that compose those. Below is one typology in full — everything a single record carries.

The typology

Business Email Compromise - Advanced
ATOAPPCorporate
The executive's real email is taken over (ATO) and used over time to send wire requests that finance authorizes (APP).
Cross-method: this one spans ATO + APP. Taking over a mailbox (ATO) is what makes the authorised payment (APP) possible — method is a property of the step, not a label on the whole fraud.
Worked example. A fraudster phishes the CEO's email password, takes over the account, and over a month sends wire requests matching the CEO's style; finance authorizes $2M.

Attack chain — 3 techniques · click any step for its detection signals and controls

1Spear PhishingSocial Engineering DeceptionAccessdetail ▾
Targeted, researched messages impersonating a trusted party to a specific individual.

Detection signals

  • Unusual request from a seemingly known sender
  • Lures referencing real projects, deals, or colleagues
  • Reply-to address differs from the From address

Countermeasures / controls

  • Targeted training for finance/executive staff
  • Out-of-band verification of unusual requests
  • Attachment sandboxing
  • External-sender banners
2Email Account TakeoverTechnical CompromiseAccessdetail ▾
Full control of a mailbox, often with hidden forwarding or filtering rules.

Detection signals

  • New inbox forwarding or filter rules
  • Logins from a new geography
  • Sent items the user did not send

Countermeasures / controls

  • MFA on email accounts
  • Alert on mailbox-rule changes
  • Impossible-travel detection
3Wire-Authorization Process AbuseLegitimate Process AbuseExecutiondetail ▾
Exploiting legitimate authority and approval flows to push wire transfers.

Detection signals

  • Authority used to override controls
  • Rushed approvals
  • Dual control bypassed

Countermeasures / controls

  • Enforce dual approval
  • Payment thresholds requiring extra sign-off
  • Out-of-band confirmation of beneficiaries

Defender’s view — every control across this chain

  • Targeted training for finance/executive staff
  • Out-of-band verification of unusual requests
  • Attachment sandboxing
  • External-sender banners
  • MFA on email accounts
  • Alert on mailbox-rule changes
  • Impossible-travel detection
  • Enforce dual approval
  • Payment thresholds requiring extra sign-off
  • Out-of-band confirmation of beneficiaries

That was one record.

The library holds the rest — each technique carrying its own detection signals and controls, and mapped to every typology that uses it.

34more typologies
43more techniques
31precursor links
5technique categories
4kill-chain stages

Want to see the whole thing?

Tell me a little about what you are working on and I will get back to you.

Semper Clarus Risk Advisors · Richard A. Hamilton, Jr.