MITRE Fight Fraud Framework (F3): What It Is and Why It Matters

Social Engineering
·
Summarize with:
MITRE Fight Fraud Framework (F3) overview

The MITRE Fight Fraud Framework (F3) is a structured, analyst-built knowledge base of tactics, techniques, and sub-techniques used by fraud actors in cyber-based financial fraud incidents. Released in April 2026 by MITRE's Center for Threat-Informed Defense, it gives fraud and cybersecurity teams a common language to describe, detect, and prevent financial fraud.

Key takeaways

  • F3 is the first ATT&CK-aligned knowledge base focused specifically on cyber-based financial fraud.
  • It was developed by MITRE's Center for Threat-Informed Defense with contributions from JPMorganChase, FS-ISAC, Lloyds Banking Group, CrowdStrike, and others.
  • F3 covers 7 tactics and dozens of techniques and sub-techniques, with social engineering and phishing prominently featured.
  • It is designed for fraud-fusion teams, bridging cybersecurity, fraud, and AML functions with shared terminology.
  • For security awareness training programs targeting financial services, F3 provides the most current and precise taxonomy of attack techniques employees need to recognize.

The problem F3 solves is not technical: it is organizational. Banks, fintechs, and payment processors routinely split fraud prevention responsibilities across cybersecurity, fraud analysis, anti-money laundering (AML), and compliance teams. Each uses different terminology and different frameworks. A cyber incident that looks like a social engineering attack to the SOC looks like an account takeover to the fraud team and a suspicious transaction to AML. Without a shared taxonomy, these teams struggle to coordinate; and attackers exploit the gaps.

According to the 2026 NASDAQ Global Financial Crime Report, financial fraud losses were estimated at $579 billion in 2025. The latest FBI IC3 Report put losses impacting Americans alone at $17.6 billion. F3 exists to reduce this figure by enabling the "shift left" that fraud teams have been calling for: detecting and disrupting attacks before they reach the monetization phase.

What does F3 cover, and how is it structured?

F3 is a behavioral model. Like MITRE ATT&CK, it structures adversary behavior into three layers:

  • Tactics: the fraud actor's goal at each stage (e.g., Reconnaissance, Initial Access)
  • Techniques: how the actor achieves that goal (e.g., Phishing for Information)
  • Sub-techniques: specific implementations (e.g., Vishing, Quishing)

What are the 7 F3 tactics?

Tactic What the fraud actor is trying to do
Reconnaissance Gather information to plan future fraud operations
Resource Development Acquire infrastructure, accounts, or capabilities to support attacks
Initial Access Gain a foothold in a target environment or account
Defense Evasion Avoid detection during the operation
Positioning Collect data, manipulate accounts, or prepare for execution
Execution Run malicious code or initiate fraudulent transactions
Monetization Convert stolen assets into funds under the attacker's control

Not every tactic appears in every fraud incident. An attacker who purchases access (Access Acquisition) may skip Reconnaissance and jump directly to Initial Access.

Which F3 techniques are most relevant to social engineering?

Phishing for Information, Impersonation, Phone Number Spoofing, MFA Takeover, and Account Takeover are the techniques most directly addressed by security awareness training. They represent the human-facing attack surface that no technical control eliminates on its own.

How is F3 different from MITRE ATT&CK?

F3 is built on the methodology of ATT&CK: same design philosophy, same empirical grounding in real-world incidents, same technique/sub-technique structure. But the two frameworks cover fundamentally different problem spaces.

Dimension MITRE ATT&CK MITRE F3
Primary scope Cyber intrusions (IT/OT systems) Cyber-based financial fraud incidents
Primary actor Nation-state, cybercriminal groups Fraud actors (often financially motivated)
Target IT infrastructure, data Financial accounts, transactions, funds
Outcome Data breach, ransomware, espionage Fraudulent transfers, account takeover, identity theft
End goal Compromise, persistence, disruption Monetization
Primary user SOC analysts, threat intelligence Fraud-fusion teams, AML, compliance, SOC

The key distinction is the monetization tactic, which does not exist in ATT&CK. F3 extends the attack lifecycle to capture how stolen data and access are converted into financial gain; the step that matters most to fraud prevention teams.

F3 also includes new content for behaviors with no ATT&CK equivalent, while referencing and refining existing ATT&CK techniques where they apply directly to financial fraud (e.g., credential stuffing, session cookie theft, adversary-in-the-middle).

The two frameworks are complementary, not competing. A financial institution's SOC can use ATT&CK to describe the technical intrusion and F3 to describe the fraud lifecycle that follows.

Why does F3 matter specifically for financial services?

Financial institutions are the initial release focus of F3; and for good reason. They operate under the most demanding fraud environment of any sector: regulated transaction monitoring, AML obligations, KYC requirements, and direct exposure to account takeover, wire fraud, and payment manipulation.

The techniques most prevalent in financial fraud (vishing, phone number spoofing, MFA fatigue, and impersonation) are all prominently mapped in F3. This makes F3 the most directly applicable framework for:

  • Designing simulation programs aligned to real attack paths, not hypothetical scenarios
  • Training contact center agents on the specific techniques used to bypass their identity verification processes
  • Reporting fraud incidents using a consistent taxonomy that fraud, cyber, and compliance teams all understand
  • Gap analysis: mapping existing controls to F3 techniques to identify which attack paths have no coverage

The foreword to the F3 methodology document (contributed by the Head of Cybercrime and Fraud Intelligence at JPMorganChase) frames the challenge clearly: what starts as an isolated social engineering attempt can snowball into a large-scale fraud attack within hours when teams lack a common language to coordinate their response.

How do you turn F3 into a testing program?

Gap analysis against F3 usually produces the same finding: the technical techniques have control coverage and the human-facing ones have training coverage, which is not the same thing. A control can be evidenced. A training completion cannot.

The five social engineering techniques above map cleanly onto simulation types, which is what makes F3 unusually practical for a security awareness program:

F3 technique How it is tested Population to target first
Phishing for Information Email and QR code simulation All staff, then finance
Impersonation Vishing simulation with a caller profile Contact center, help desk
Phone Number Spoofing Vishing simulation with spoofed caller ID Treasury, operations
MFA Takeover Adversary-in-the-middle phishing simulation Privileged and admin users
Account Takeover Help desk reset-request simulation IT support, service desk

Running these produces the evidence a gap analysis actually needs: susceptibility and reporting rates per technique, per population, over time. That is also the form of evidence expected under DORA in the EU and under FFIEC guidance in the US, where ICT risk awareness has to be demonstrated rather than asserted.

Other resources for Financial Services CISOs:

🎭 Deepfake Fraud in Financial Services: What CISOs Need to Do Now →

📋 Why Basic Phishing Training Won't Stop AI Social Engineering →

☎️ AI Vishing: Why Finance Teams Are the New Front Line →

📞 Hedge Funds Targeted by Vishing: Citadel, Two Sigma and Point72 →

Explore each F3 technique in depth

The Arsen Team has produced dedicated resources for each of the social engineering-relevant F3 techniques covered in the initial release. Each resource includes the technique's F3 tactic classification, a practical explanation of how it works in financial fraud scenarios, key takeaways, and a FAQ section.

Explore them below:



Frequently Asked Questions

The MITRE Fight Fraud Framework (F3) is a knowledge base of tactics, techniques, and sub-techniques used by fraud actors in cyber-based financial fraud. It was built by MITRE's Center for Threat-Informed Defense, with significant contributions from JPMorganChase, FS-ISAC, Lloyds Banking Group, CrowdStrike, Marsh, and other financial sector organizations. It was publicly released in April 2026.

ATT&CK covers cyber intrusions broadly; IT and OT environments, nation-state and criminal actors, data breaches and ransomware. F3 focuses specifically on cyber-based financial fraud: the techniques fraud actors use to obtain money, assets, or information from individuals and banking institutions. F3 adds a Monetization tactic not present in ATT&CK and covers fraud-specific techniques like phone number spoofing, account takeover, and MFA fatigue.

Directly. F3 maps the specific techniques (phishing, vishing, impersonation, MFA fatigue, phone spoofing) that employees in financial services encounter most. Building simulation and training programs around F3 techniques ensures training addresses real, documented attack paths rather than generic awareness.

The live F3 Matrix is available at ctid.mitre.org/fraud. The full design principles and methodology document was released by MITRE in April 2026 and is publicly available.

Not directly, since F3 is a threat taxonomy rather than a regulatory framework. It is useful as the bridge between them: mapping your controls and your training coverage to F3 techniques gives you a defensible, evidence-based answer to the ICT risk awareness obligations in DORA and to FFIEC expectations on social engineering.


Map F3 techniques to what your people actually face

A gap analysis tells you which techniques have no coverage. A simulation tells you which ones your staff fall for. Test impersonation, phone spoofing and MFA takeover against your contact center, treasury and help desk teams with vishing simulation, or see our work with financial services.



Can your team spot a vishing attack?

Test them and find your blind spots before attackers do.

Don't miss an article

No spam, ever. We'll never share your email address and you can opt out at any time.

Next article

Why Vishing Has Become the Main Cyber Threat, And What to Do About It

Why Vishing Has Become the Main Cyber Threat, And What to Do About It

Vishing has overtaken email phishing as the go-to attack vector for threat actors in 2025. Google and Mandiant's...