
#56: VAMP Updates, Tinder's Face Check Works, PSPs Caught in Global Fraud Ring
The ecosystem is shifting – from stricter enforcement and smarter verification to fraud rings exploiting the very rails meant to stop them. This week , we look at Visa’s surprise fines catching merchants off guard, Tinder’s biometric rollout cutting fraud exposure in half, and a massive PSP-assisted scam ring that defrauded millions.
Let’s get into it.
NATE'S TAKE - NOVEMBER 11, 2025
Top Three This Week
- Visa’s New Rules Are Already Costing Merchants
- Tinder’s Face Check Shows Biometric Verification Can Work
- Payment Providers Caught in the Middle of Global Fraud Ring
1. Visa’s New Rules Are Already Costing Merchants

Some merchants are learning the hard way that Visa’s Acquirer Monitoring Program (VAMP) is more aggressive than expected.
Cyberfraud expert Karisse Hendrick shared on LinkedIn that Visa is already issuing fines to enterprise merchants whose TC40 and chargeback ratios exceed 2.2%, including activity from before the grace period officially ended. The fines are $8 each, and that applies to everyTC40 and chargeback over the threshold, regardless of sub-code.
Worse, some acquirers and PSPs are passing along those fines to merchants even if they’re over just 0.7%, resulting in merchants throttling approvals just to stay under the limit. The economic impact is hard to measure, but the ripple effects are real. Merchants who aren’t prepared to operate with extreme chargeback discipline may soon find themselves choosing between risk and revenue again.
2. Tinder’s Face Check Shows Biometric Verification Can Work

In an industry long plagued by fake profiles and romance scams, Tinder says its new biometric Face Check feature has driven a 60% reduction in exposure to bad actors. The feature, which uses a live video selfie to verify identity and detect duplicate faces across accounts, is now mandatory in select markets and expanding across the U.S.
That shift from optional to required identity verification marks a significant pivot in platform safety. With engagement down and trust under pressure, Match Group is signaling that real-world safety measures now need to show real-world results.
As fraudsters evolve, platforms that don't adapt their onboarding processes—and make trust part of the core experience—will fall behind.
3. Payment Providers Caught in the Middle of Global Fraud Ring

Germany arrested 18 people last week after uncovering a massive fraud and laundering network tied to fake subscription services and compromised payment providers. The scheme hit 193 countries, stole over 4.3 million credit cards, and defrauded victims of nearly $350 million.
Among the 44 suspects are six former employees of major German PSPs. Authorities say these insiders helped process fraudulent charges for phony dating sites, making this a rare but powerful example of how fraud doesn’t just exploit payment infrastructure, it can infiltrate it. As the Financial Intelligence Unit put it: “What initially looked like small debits turned out to be a global business model with professional structures.”
For fraud teams, this case is a reminder that detection can’t stop at the edges of your own system. When legitimate rails are abused at scale, collaboration and cross-border intelligence sharing become table stakes.
===
That’s all for this week! For more insights, follow us on LinkedIn or X, and if you want to learn more about what we do, visit www.specprotected.com.
Ready to get started with Spec?
Nate Kharrl, CEO and co-founder at Spec, has built leading solutions for application security and fraud challenges since the early days of the cloud era. Drawing from his cyber experience at Akamai, ThreatMetrix, and eBay, Nate helped found Spec to focus on the needs of businesses operating in a landscape of increasing AI risks. Under Nate’s leadership, Spec grew from its mid-pandemic founding to raise $30M in venture-backed funding to build solutions used by Fortune 500 companies transacting billions in online commerce. Spec’s service offerings today include protective measures for websites and APIs that specialize in defending against attacks designed to bypass bot defenses and risk assessment platforms.



