Virtual Event: Threat Detection & Incident Response Summit - Watch Now
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Fraud & Identity Theft

MITRE Releases Fight Fraud Framework

The document provides a behavior-based model of the tactics and techniques employed by fraudsters.

MITRE

The non-profit MITRE Corporation on Thursday released a new framework to help organizations fight fraudsters. 

MITRE’s Fight Fraud Framework (MITRE F3) is a curated knowledge base that provides a behavior-based model of the tactics, techniques, and procedures (TTPs) fraudsters employ, informed by real-world attacks.

“These incidents involve the intentional use of deceptive or illegal practices to fraudulently obtain money, assets, or information from individuals or institutions, and include actions carried out over cyber channels,” MITRE says.

The framework offers a common structure and taxonomy describing cyber fraud incidents and is meant to enable stronger collaboration on fraud detection, prevention, and response.

The analyst-developed knowledge base was designed as a structured, transparent, and operationally relevant resource that is globally accessible, open, and free for use.

MITRE F3 details behaviors that are not included in the ATT&CK framework by introducing two fraud-specific tactics.

Advertisement. Scroll to continue reading.

These include positioning, which includes the post-compromise actions aimed at collecting and manipulating data and preparing follow-up execution, and monetization, which involves the activities threat actors perform to convert the compromised assets into usable value.

“These additions capture the uniqueness of fraud where success depends on moving and extracting value, not just gaining access. By capturing those stages, F3 allows defenders to trace fraud activity from initial compromise through financial impact,” MITRE notes.

The framework also changes the definition of tactics that already exist in ATT&CK, such as reconnaissance, resource development, initial access, defense evasion, and execution.

MITRE Fight Fraud Framework (F3)

“This structure creates a shared language that allows cyber and fraud defenders to enumerate the material events in a fraud incident, connect cyber activity to financial outcomes, and align detection, prevention, and response strategies,” MITRE explains.

In addition to launching a website for the framework, MITRE published a visual representation of the described tactics, along with details on the F3 design principles and methodology, and information on how it can be used.

Additional resources are available in a GitHub repository that also provides details on how interested parties can get involved with the project.

Related: MITRE Launches New Security Framework for Embedded Systems

Related: MITRE Releases 2025 List of Top 25 Most Dangerous Software Vulnerabilities

Related: MITRE Unveils ATT&CK v18 With Updates to Detections, Mobile, ICS

Related: MITRE Unveils AADAPT Framework to Tackle Cryptocurrency Threats

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Joe Chen has become Chief Technology Officer at Trellix.

Usercentrics has named Pawan Hegde as COO and Elena Ignatova as CPTO.

SecureAuth has named Mark van Oppen as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.