The Psychology of a Fraud Enabler: AI Re-Equipped an Old Adversary, It Did Not Create a New One


KasadaIQ built a model for the decision behind the tooling — the Fraud Enabler Diamond — and applied it to a live adversary community. AI moved opportunity and capability. Motivation and rationalization have not moved in 70 years.

KasadaIQ

The Psychology of a Fraud Enabler: AI Re-Equipped an Old Adversary, It Did Not Create a New One

Cybersecurity gets treated as a technology problem. The attacks are technical, the defenses are technical and the vendor language is technical. Every attack, though, starts with a person deciding to act. This quarter KasadaIQ built a model for that decision and applied it to a live adversary community, to see what AI is actually changing about the people behind the tooling.

The model is the Fraud Enabler Diamond. It adapts more than 70 years of fraud research, starting with Donald Cressey's 1953 study of why people commit fraud, into a frame for a different kind of actor: the external operator who does not commit the fraud but builds and sells the capability that lets others do it. Their relationship to the victim is commercial supply rather than betrayed trust, so the classic models needed reframing. The Diamond has four elements: motivation, opportunity, capability, and rationalization.

The Fraud Enabler Diamond: motivation, opportunity, capability, and rationalization

Motivation is the set of forces that make selling capability worth the risk: economic pressure, lifestyle costs, status, and ego. Across both cohorts KasadaIQ observed, one established over years and one arriving with AI in 2026, this looked the same. Operators describe services that pay their rent and more, and frame legitimate six-figure tech jobs as not worth their time.

Opportunity is the structural conditions that let an operator work without consequence: a widening attack surface, weak security on targets, structured deniability, and favorable legal conditions. This is where AI is genuinely changing the picture. The attack surface has expanded with enterprise adoption of agentic AI, and the community's 2026 engagement concentrated heavily on AI, anti-bot techniques, and monetization.

Capability is what the operator brings to act on that opportunity: skill, tooling, and the network behind it. This is the second element AI moved, and it is where the two cohorts diverge most. The established cohort runs on deep technical skill built through long practice and high-trust networks. The emerging cohort produces high output through LLM-assisted development, wider but shallower community reach, and tooling aimed straight at the seam where AI meets verification.

Rationalization is the publicly available set of arguments an operator uses to reconcile the work with their self-image: grey-zone framing, no direct link to victims, an us-versus-them stance toward defenders, and the absence of KYC treated as a feature of the trade rather than a choice. Like motivation, this held steady. One cohort keeps its disclaimer architecture quiet inside trusted channels; the other builds it in public behind commercial frontage. The underlying argument is identical.

Line the four elements up and the pattern is clear. AI moved opportunity and capability. Motivation and rationalization did not move, and they have not moved in 70 years. The operator entering the market today is recognizable as the same kind of person Cressey described in 1953, with faster tooling and a wider surface to work.

That is the practical value of the Diamond. Defenders who calibrate to a cohort's capability will miss the next cohort, because capability is the element that keeps turning over. Defenders who calibrate to the motivation and rationalization shared across both will keep pace.

Download the report: Access the report

Defeats threats 
not your customers

Start deploying today