Fang Yu has spent her career tracking the same pattern across very different threats, worms, spam, account abuse, and now financial fraud: malicious behavior is adaptive. Attackers study whatever control sits in front of them and change the variables it depends on, identities, devices, timing, transaction paths. As Co-Founder and Chief Product Officer of DataVisor, that lesson shapes a conviction she thinks much of the financial industry still hasn't internalized: verifying someone's identity at onboarding tells you almost nothing about whether that same account will still be trustworthy six months later.
A legitimate customer can be recruited or coerced into a mule network long after KYC clears them, which is why Yu argues the real question isn't whether an account looks bad in isolation, but what it reveals as part of a larger pattern. In this conversation, she explains how unsupervised machine learning finds fraud rings that have no labeled examples to train against, by spotting accounts that look clean individually but share devices, IP infrastructure, or synchronized activity, why rules alone are always reactive, and why she believes effective fraud prevention now means detecting threats that have never been seen before, not just refining defenses against the last one.
The consistent lesson is that malicious behavior is adaptive. Whether it is spam, worms, account abuse, or financial fraud, attackers study the controls in front of them and change the variables that controls rely on—identities, devices, timing, transaction paths, and behavior. That is why defending against fraud cannot be a one-time classification exercise. You need to understand how activity changes over time and how seemingly separate events connect.
Fraud is increasingly organized to look legitimate at the individual-account level. The relevant question is often not “does this account look bad?” but “what does this account reveal when viewed as part of a larger pattern?”
The hard part is not inventing another model. It is operationalizing intelligence: turning raw transaction, device, identity, and behavioral signals into a decision quickly enough to matter.
That requires a production data foundation that can compute custom aggregated signals in real time, connect related events, and apply multiple detection methods together. Rules are useful for explicit policy logic; supervised models improve known-pattern detection; and unsupervised learning surfaces coordinated or emerging behavior. The output must be explainable and usable in the decision flow, not a score that arrives after the loss has occurred.
KYC verifies an identity at a point in time. It does not guarantee that the identity will remain trustworthy, that the account will not be taken over, or that a legitimate customer will not later be recruited or coerced into a mule network.
The risk changes after onboarding. Institutions need to watch for behavioral shifts: an unfamiliar device, a new payee, sudden changes to profile information, unusual login sequences, or funds moving in a way that is inconsistent with the account’s history. Identity is an important signal, but it is the beginning of a risk relationship—not the end of one.
Unsupervised learning starts from the premise that the first version of a fraud ring will not come with labels. Instead of asking whether one account matches a known fraud profile, it looks for groups of accounts whose behaviors, devices, identifiers, transaction paths, or timing are unusually connected.
For example, accounts may appear clean individually but share device characteristics, rotate through the same IP infrastructure, make similar test transactions, or activate in a synchronized sequence. Those links reveal the operating pattern of a network. Investigators can then assess the cluster, rather than reviewing every isolated alert without context.
Rules are essential. They are transparent, fast, and effective for known risks and policy requirements. But they are inherently reactive: someone must first recognize a pattern, write the rule, tune it, and keep tuning it as the attack changes.
Adaptive machine intelligence extends that defense. It can identify behavior that no one has yet written a rule for, find correlations across large populations, and help teams test and refine strategies as fraud evolves. The right model is not rules versus AI; it is a layered system where each method does what it is best at.
Effective monitoring continuously updates risk based on what an account does—not just what it presented at onboarding. Operationally, that means unifying signals across login, device, profile, transaction, beneficiary, and network activity; recalculating risk as events occur; and routing material changes to the right automated action or investigator.
Many organizations under-invest in the data and workflow needed to make that continuous view practical. They have strong point controls at onboarding or payment authorization, but limited ability to connect signals across the customer lifecycle, analyze networks, or feed investigation outcomes back into detection strategies.
AI is making fraud more scalable, coordinated, and changeable. Defenses built only to recognize yesterday’s attack patterns will always be late.
Fraud prevention has to become more adaptive: detect anomalies and relationships as they emerge, combine real-time signals with network intelligence, and give teams a governed way to test and deploy new strategies quickly. Good AI must fight bad AI—but with human accountability, clear controls, and enough speed to stop a threat before it becomes a known loss pattern.