Stripe's ML flywheel cuts successful card-testing fraud attacks by 80%
Stripe built a machine learning-based system to detect and block card testing fraud, applying ML models at three levels of abstraction: overall prevalence estimation, identifying where attacks are occurring, and scoring individual transactions. A rapid data-labeling, retraining and redeployment pipeline, built on Stripe's Shepherd feature-engineering platform (developed with Airbnb) and the Flyte ML orchestration platform, lets the team react to new attack patterns within hours. The system is augmented by a large transformer model trained on billions of global transactions that generates embeddings used across card-testing detection use cases. Successful card-testing attacks on Stripe declined by 80% over two years even as Stripe's payment volume grew past $1 trillion.
Overview
Stripe built a machine learning-based system to detect and block card testing fraud, applying ML models at three levels of abstraction: overall prevalence estimation, identifying where attacks are occurring, and scoring individual transactions. A rapid data-labeling, retraining and redeployment pipeline, built on Stripe's Shepherd feature-engineering platform (developed with Airbnb) and the Flyte ML orchestration platform, lets the team react to new attack patterns within hours. The system is augmented by a large transformer model trained on billions of global transactions that generates embeddings used across card-testing detection use cases. Successful card-testing attacks on Stripe declined by 80% over two years even as Stripe's payment volume grew past $1 trillion.
The challenge
Card testing is one of the most significant fraud threats to Stripe, its users, and the broader financial ecosystem, and one of the most challenging to detect and block, because it blends in easily with legitimate traffic and bad actors are constantly changing their tactics. Unlike disputes or declines, card testing doesn't yield explicit labels that can be used to train models or evaluate prevalence or performance.
The solution
Stripe built an ML-based flywheel that applies models at three levels of abstraction — estimating overall card-testing prevalence, identifying where attacks are occurring, and scoring individual transactions — to dynamically set block thresholds. Labels are derived by consolidating intelligence on new attack vectors, automating discovery of hidden patterns from weaker signals, and manual expert review. New features are engineered on Stripe's Shepherd feature-engineering platform, built through a partnership with Airbnb, and tested and redeployed via the Flyte ML orchestration platform, including blue-green tests between old and new models. The flywheel is augmented by a large transformer model trained on billions of global transactions that generates embeddings used across multiple card-testing detection use cases.
Reported business value
Successful card-testing attacks on Stripe declined by 80% over the last two years, even as Stripe's payment volume expanded to over $1 trillion.
Sources
Open any source and check the claim yourself — that is the point of the register.
This record was researched and written with AI assistance, and its claims were checked against the sources above. (EU AI Act art. 50 transparency notice.)
Other financial services entries in the register.
Navy Federal Transforms Service With AI
Navy Federal Credit Union is reshaping banking for military members by unifying data and leveraging generative and agentic AI on the Databricks Data + AI Platform. By embracing AI-augmented workflows and upskilling teams, Navy Federal delivers customized services while streamlining productivity through responsible change management and data readiness.
Banking Innovator bunq Supports Growth, Strengthens Security Using AWS
bunq, a Dutch neobank with over 11 million users across Europe, uses Amazon Bedrock for several generative AI use cases including summarizing new user data with large language models, removing the need for agents to process onboarding documents manually. Using Amazon Bedrock, bunq tripled user support process efficiency while maintaining over 90 percent accuracy. Sensitive data stays within bunq's AWS virtual private cloud, supporting GDPR and PCI DSS compliance alongside tools such as AWS CloudHSM, AWS Security Hub and AWS KMS.
TBC Bank Operationalizes Trusted Data with Lakebase
TBC Bank, the largest banking group in the Caucasus region, built a Lakehouse on Databricks and adopted Lakebase and Databricks Apps to move from on-premises SQL Server instances and month-long reporting cycles to self-service analytics and AI-driven applications, including a web-based AI chatbot and AutoML-based credit risk scoring. Credit risk model deployment fell from 14 weeks to two days, and more than 600 users regularly query governed data through Genie.
Worldline enables real-time insights for smarter merchant decisions with Databricks
European payment processor Worldline consolidated data from multiple acquisitions onto a Databricks medallion architecture with Delta Lake and Unity Catalog to unify over 50 billion annual transactions, reducing infrastructure costs by €200,000 per month, lifting team productivity 40%, and increasing scheme reporting speed 93%.
Was this helpful?
Your feedback helps us improve our use case database
