MITRE Fight Fraud Framework: How F3 Extends ATT&CK Into Financial Fraud

SHARE

Loading the Elevenlabs Text to Speech AudioNative Player...

In April 2026, MITRE’s Center for Threat-Informed Defense (CTID) released the MITRE Fight Fraud Framework (F3), a behavior-based knowledge base of tactics and techniques used by financial fraud actors. Built on the same structural logic as MITRE ATT&CK, F3 extends that logic into territory ATT&CK was not designed to cover: the mechanics by which compromised access is converted into financial loss.

F3 is the product of a collaboration between MITRE and a group of financial services, retail, and security organizations, including JPMorganChase, Citigroup, Lloyds Banking Group, Standard Chartered, FS-ISAC, A-ISAC, RH-ISAC, CrowdStrike, Marsh, the National Retail Federation, and Verizon Business, and is openly accessible at no cost. If you want to inspect the framework artifacts directly, you can consult the project’s GitHub repository.

This article is for those familiar with MITRE’s existing frameworks who want a technical view of what F3 introduces, how it differs from ATT&CK, and how it can be integrated into existing detection and response workflows.

What Is the MITRE Fight Fraud Framework?

The Fight Fraud Framework is a curated, behavior-based knowledge base of tactics, techniques, and procedures (TTPs) used by financial fraud actors. In MITRE’s description, it is derived from real-world observations of cyber fraud incidents, so it references existing cyber techniques and includes both fraud-specific behaviors and references to existing ATT&CK techniques where those techniques apply to financial fraud.

What F3 solves is a modeling gap. ATT&CK is effective for describing adversary behavior in compromise-centric scenarios, but fraud investigations often need to explain something more specific: how access, information, or process control is turned into fraudulent action and, ultimately, financial gain. Fraud is not only about intrusion, but also about preparation, orchestration, and value extraction. In that sense, F3 helps describe deceptive or illegal practices that emerge after technical access has already been obtained. F3 is therefore useful not as a replacement for ATT&CK, but as a complementary model.

MITRE and CTID describe the new framework as providing fraud analysts with a consistent vocabulary for describing incidents, giving cyber teams a common structure for fraud detection and validating the techniques that precede fraud outcomes, and giving security leaders a basis for assessing risk in terms of how fraud actually unfolds.

The framework’s scope is cross-sector. While its initial contributor base is weighted toward financial services, MITRE identifies banking, fintech, e-commerce, insurance, and telecommunications among the sectors where cyber-enabled fraud is most intense.

MITRE F3 vs. ATT&CK: Key Structural Differences

F3 will look familiar to teams that already use ATT&CK. It organizes behavior into tactics and techniques and retains ATT&CK references where those remain relevant to fraud scenarios. That makes it easier to adopt without changing the basic analytical model teams already use.

The main difference is scope. ATT&CK Enterprise is built to describe intrusion activity across fourteen tactics, from Reconnaissance through Impact. F3 is narrower. Its current matrix includes seven tactics and focuses on the part of the lifecycle where access is used to enable fraud after the initial compromise.

That difference becomes clearer when the two tactic sets are viewed side by side:

MITRE F3 vs. ATT&CK comparison table


In practice, this makes F3 more useful for fraud investigations. In many cases, the main question is not only how an attacker got in, but how that access was used to manipulate data, influence business processes, or prepare fraudulent transactions. F3 treats those fraud-related actions as behaviors that can be modeled directly, rather than leaving fraud as a downstream consequence of compromise.

The clearest examples are Positioning and Monetization. These tactics do not exist as top-level ATT&CK tactics, and they show most clearly how F3 extends ATT&CK into financial fraud. They also make F3 more useful as a behavior-based model for analyzing how threat actors move from access to fraud execution.

Positioning: Fraud Preparation After Compromise

Positioning covers the actions a fraud actor takes after gaining access but before executing the fraudulent transaction. This includes collecting data, manipulating information within the compromised environment, and preparing the conditions required for execution.

In ATT&CK terms, this stage overlaps with parts of Discovery and Collection. In fraud scenarios, however, these activities are rarely incidental; they are often the longest and most consequential phase.

For example, a call-center-initiated account takeover is modeled as spanning multiple tactics, with Positioning captured through techniques such as account linking and the submission of loan requests against the compromised account. F3 treats this preparation as its own named tactic rather than as a byproduct of other stages, making it easier to describe known fraud TTPs in a structured way.

Monetization: Converting Access Into Value

Monetization covers the activities a fraud actor performs to convert compromised assets into usable funds or value. This is the stage ATT&CK explicitly does not model. In ATT&CK, the chain generally ends with Impact — the adversary’s effect on a system. F3 continues past that point, into the steps required to turn impact into financial gain.

Depending on the specific techniques cataloged, monetization behaviors can include account takeover, crypto transfer, fake invoices, unauthorized payments, resale of stolen credentials and others. Without a dedicated tactic for this stage, fraud defenders had no shared way to describe or detect the behaviors that turn compromise into loss.

Practical Applications: How to Start Using F3

The most practical way to use F3 is alongside ATT&CK, not instead of it. ATT&CK can describe the intrusion path, while F3 can describe the fraud path that follows.

This is especially useful in incidents where teams need to explain not only how access was gained, but how that access was used to prepare and execute fraud. In that sense, F3 helps connect technical compromise to financial outcome and can strengthen both fraud prevention and investigative analysis.

A good starting point is incident mapping. Teams can use ATT&CK to identify the techniques involved in compromise, then use F3 to map the fraud-specific behaviors that follow, especially in the Positioning and Monetization stages.

F3 can also help detection teams identify coverage gaps. If a team already detects access, execution, or evasion, the next question is whether it can also detect signs of fraud preparation or attempts to cash out. That makes the framework relevant not only to fraud detection, but also to broader cyber threat intelligence efforts focused on financially motivated activity.

For teams that already work with ATT&CK, the best way to start using F3 is to apply it to a small number of recent fraud cases. That makes it possible to test where the framework adds analytical value without changing existing workflows all at once.

Conclusion

Fight Fraud Framework does not replace MITRE ATT&CK; it extends its logic into territory ATT&CK was never designed to cover. By modeling Positioning and Monetization as first-class tactics, and by reusing ATT&CK techniques where they apply, it gives cyber and fraud teams their first shared behavioral taxonomy for financial impact. The framework is open, evolving, and best understood as a reference that will deepen as contributors add data sources and mitigations over time.

FAQ

What is the MITRE Fight Fraud Framework (F3)?The MITRE Fight Fraud Framework, or F3, is a behavior-based knowledge base of tactics, techniques, and procedures for analyzing cyber-enabled fraud and connecting observations across prevention, detection, and response.

What is the difference between F3 and ATT&CK?The main difference is scope. ATT&CK models intrusion-oriented adversary behavior across the enterprise attack lifecycle, while F3 focuses on the fraud lifecycle that follows, including fraud-specific stages such as Positioning and Monetization.

Is F3 part of MITRE ATT&CK?No. F3 is a separate MITRE knowledge base, but it is designed to work alongside ATT&CK and reuses ATT&CK references where they are relevant to fraud scenarios.

Which sectors does F3 affect?F3 is relevant anywhere cyber-enabled fraud is a material risk, but it’s especially relevant to sectors such as banking, fintech, retail, insurance, and telecommunications.

Is F3 free?Yes. MITRE states that the knowledge base is globally accessible, open, and available at no charge to any person or organization.

About the author

Picture of Joana Coelho

Joana Coelho

Joana is a creative and dedicated content writer. After her Master’s in Translation and Linguistic Services, she combined her passion for languages with her experience in copywriting to write about technology and, more specifically, cybersecurity.

RELATED POSTS

Ready to take your security
to the next level?

We are! Let’s discuss how we can work together to create strong defenses against real-life cyber threats.

Stay informed, stay secure

Subscribe to our monthly newsletter

Get notified about new articles, industry insights and cybersecurity news