Stripe upgrades FT3 to agentic fraud framework with Team Cymru

Stripe's FT3 2.0 turns a public fraud taxonomy into an agentic operating layer, with Team Cymru backing its practitioner-led distribution model.

A bright modern office space features a curved white desk with blue LED strip lighting, supporting three monitors on black articulated arms displaying dark-themed data visualizations, with large windows and blurred glass partition walls in

Stripe and threat-intelligence firm Team Cymru have jointly released FT3 2.0, the second generation of Stripe's Fraud Tools, Tactics and Techniques framework, repositioning what began as an open-source taxonomy into a living, agentic operating layer for fraud and security practitioners. The move marks a deliberate shift in both technical ambition and distribution philosophy, with implications that extend well beyond payment fraud into the broader architecture of AI-assisted cyber defence.

FT3 was originally authored by Stripe's Attacker Engineering team in 2024 and publicly released in 2025 as a machine-readable common language for mapping fraud adversary behaviour across the full attack lifecycle, spanning payments, network infrastructure and hosting environments. Version 2.0 expands that foundation to cover more than 200 techniques, each paired with data sources, analytics, detections, mitigations and agentic profiles.

From taxonomy to operational layer

The most significant technical addition is Acheron, an agentic reasoning system built into the framework alongside an MCP (Model Context Protocol) server operating over a knowledge graph. Together, these components allow both human practitioners and AI agents to query, reason over and operationalise fraud intelligence within existing security workflows, rather than treating the taxonomy as a static reference document.

"A taxonomy is useful until the work starts," said Vincent Passaro, Head of Attacker Engineering at Stripe. "FT3 2.0 is designed for what comes next: connecting observed behavior to telemetry, analytics, detections and controls, and making those relationships usable by both practitioners and agents."

The distribution model has also changed in a meaningful way. Rather than a public GitHub release, FT3 2.0 will be made available at no cost through trusted, practitioner-led communities, a deliberate response to lessons from the first year of FT3 1.0. Stripe found that the most substantive intelligence contributions came not from open pull requests but from established professional relationships and closed communities. The original framework remains publicly accessible on GitHub.

The convergence angle: agentic AI meets financial infrastructure defence

For cross-sector strategists, the FT3 2.0 announcement sits at the intersection of two accelerating trends. The first is the industrialisation of agentic AI: the incorporation of Acheron and MCP-based querying into a fraud framework signals that financial infrastructure operators are now building AI agents into their security operations centres, not merely their customer-facing products. Stripe processes over $1.9 trillion in payments annually, equivalent to roughly 1.6% of global GDP, making its internal threat frameworks consequential at a macroeconomic scale.

The second trend is the growing tension between open-source intelligence sharing and trust-gated practitioner networks. The shift away from a public repository reflects a broader debate in cybersecurity: open standards accelerate adoption but may dilute the quality of intelligence contributed. FT3 2.0's community-reciprocity model is closer to closed threat-sharing consortia such as the Financial Services Information Sharing and Analysis Center (FS-ISAC) than to conventional open-source projects, and its uptake will test whether that model can sustain the validation and iteration that open repositories historically provide.

For capital allocators watching the cybersecurity and fintech space, the collaboration also highlights the strategic value of infrastructure intelligence firms such as Team Cymru, which contributes global network telemetry and practitioner community infrastructure to the project. As agentic AI tools proliferate across financial services, the firms that sit at the telemetry and threat-intelligence layer, rather than the application layer, may accumulate durable competitive advantage. Investors in AI-native security tooling should note that the real bottleneck is increasingly access to high-quality, practitioner-validated intelligence, not model capability.

Whether FT3 2.0's gated distribution model attracts the breadth of contribution needed to keep its 200-plus techniques current will be the framework's first genuine test. The next indicator to watch is adoption velocity within the practitioner communities Stripe and Team Cymru are cultivating, and whether other major payment processors move to build or back comparable agentic fraud-intelligence layers of their own.