Online payment with computer and credit card

Banks Unite to Fight Financial Fraud with a Common Language

By Catherine Trifiletti

MITRE’s Center for Threat-Informed Defense brought leading financial institutions together to create the MITRE Fight Fraud Framework™, a common language that helps fraud and cyber teams connect signals, understand adversary behavior, and strengthen defenses.

Fraud costs banks billions of dollars annually. In 2024, losses reached a record $13.7 billion. Beyond the financial toll, institutions devote significant resources to keep up with increasingly bold and creative cybercriminals.

One recent con involved scammers spoofing Chase Bank's phone number to convince unknowing victims their accounts had been compromised. The scheme was so polished that even a New York Times journalist who covers fraud nearly fell for it.

To combat these types of attacks, banks rely on both cyber and fraud defense teams. Each brings a different perspective: cyber teams focus on the technical indicators of compromise and attack, while fraud teams focus on the financial impacts and transaction patterns associated with fraudulent activity. As a result, the teams use different methods and language in their communications about fraud.

Fragmented incident responses leave organizations struggling to connect signals, understand fraud behavior, and prioritize defenses.

“It's like putting a baseball player onto the soccer pitch,” says Suneel Sundar, head of research at MITRE's Center for Threat-Informed Defense (CTID). “Both are great athletes, but they're playing different sports.”

A Solution for the Community, By the Community

CTID is a research and development consortium whose mission is to bring together industry to advance threat-informed cyber defense globally.

Members of the group, including Citi, JPMorganChase, and Lloyds Banking Group, recognized the need for a resource that would benefit their own operations and the broader financial services community.

“It’s important for teams not to work in silos, but rather to bridge the gaps and combine the skill sets of both domains so that we can tackle financial fraud together,” says Denise Tan, Security and Crisis Management at Citi.

Developing a framework that competing financial institutions could trust required leadership from an organization without commercial interests to lift up the industry. “As a nonprofit working in the public interest, this effort fit perfectly in MITRE’s wheelhouse,” says Sundar. “There’s trust that MITRE will treat the data honestly and assurance that we’re experts in creating rigorous and usable frameworks compatible with MITRE ATT&CK®.”

The collaboration resulted in the MITRE Fight Fraud Framework™ (F3), published earlier this year. Modeled after ATT&CK, F3 defines a common language for fraud analysts and cyber defenders by organizing real-world data inputs from members into tactics and techniques. The free, publicly available framework enables organizations to consistently analyze attacks, share information, and strengthen their defenses.

Indexing Each Action in a Real-World Attack

Scam diagram

In the phone number spoofing scam, once criminals gain a target’s trust, they carry out a series of carefully orchestrated actions that ultimately persuade the victim to transfer money through Zelle.

F3 catalogs each step as a technique, giving fraud and cyber teams a shared language that can be understood across institutions. Learning how the scammers behave helps organizations spot the attack and better plan how to stop it.

“By leveraging this framework, fraud and cyber teams can map what they know about a trend, identify what is not yet known, direct the next steps for their investigation and pursue mitigation efforts across the relevant groups,” says Dan Stiving, head of cybercrime and fraud intelligence at JPMorganChase.

Like ATT&CK, F3 is a living framework that continues to evolve as new tactics and techniques emerge. The methodology and detailed mappings are freely available through CTID, giving organizations of all sizes the tools to strengthen fraud defenses, model adversary behavior, and validate controls against threats.

Expanding the Model’s Impact

Although F3 was designed for financial services, its methodology can be applied across industries. Input from organizations such as the Aviation Information Sharing and Analysis Center (Aviation ISAC), an active CTID member, helped shape the framework and demonstrated its potential to address fraud challenges beyond banking.

The next phase of the research, scheduled for publication this fall, will identify the data sources adversaries use and define mitigations institutions can enact to prevent fraud. The goal is for defenders to move from a reactive to a more proactive approach.

CTID’s effort underscores MITRE's commitment to advancing threat-informed defense through collaboration for the public good. For participating organizations, F3’s value extends beyond strengthening their own defenses. By contributing to a shared framework, they're helping improve resilience across the entire financial services community.

“You get the benefit of driving the change,” says Heath Montembeault, global head of applied cyber threat research at JPMorganChase. “But also, there's this sense of wellbeing that you’re providing something to the community, free of charge.”