Transform Risk Into Opportunity

Offering solutions that combine human expertise and AI to reduce friction, surface insights, and drive growth.

Request a Consultation Fraud & Abuse Trade Compliance & Due Diligence

Global leaders trust FiveBy Solutions to turn complexity into opportunity with adaptive solutions that combine AI and human expertise to overcome regulatory, operational, and cultural barriers—and accelerate growth.

Explore Our Core Expertise

Dive deeper into how FiveBy transforms complexity into growth opportunities through specialized expertise in critical areas.

Fraud & Abuse

Combat evolving threats with FiveBy’s comprehensive fraud and abuse solutions. We combine advanced AI with human intelligence to identify suspicious activities, implement strategic challenges, and protect your business from financial losses and reputational damage.

Learn More

Trade Compliance & Due Diligence

Navigate global markets with confidence. Our experts ensure adherence to complex international trade laws, sanctions, and customs regulations. We provide thorough due diligence to mitigate risks and foster secure, compliant cross-border transactions for sustained growth.

Learn More

Tips From Our Experts

Beyond the Meter : AI Consumption Fraud

Nobody broke in, but your AI bill went up. That's AI compute fraud. See where the loss hides, who absorbs it, and how to stop it.

Expand

Catching AI compute fraud before it blows through your forecast, without blocking the users you want to keep.

Your AI compute budget started as a forecast, a clean line you could plan and price against. Lately that line keeps breaking: costs spike above plan with no launch or traffic win to explain them, and every unit of it looks like ordinary usage. The opportunity now is knowing who (or what) is really driving those spikes, so you can catch abuse early, protect your margin, and keep scaling, instead of shutting the tap or writing the overage off after the fact.

The meter shows how much, not who

AI compute is billed like a utility: you pay for what flows through the line, metered by the token, the call, or the GPU-hour. That meter is precise about one thing and blind to another. It records exactly how much was consumed, and nothing about who consumed it or whether anyone authorized the spend. Usage is trusted by default, because charging for consumption is the whole business model. So the abuse arrives looking like demand, clears the meter, and lands in the same totals as your best customers. The question the meter cannot answer is the one that now matters most: who, or what, is really behind the usage.

The door holds. The bill climbs.

Here is what that looks like in practice. A company launches a free generative-AI tool to break into a new market. Signups climb overnight, which is the point. Then the fraud team notices the shape of the usage: accounts arriving in bursts, from generated email addresses, dozens at a time, each one draining its free credits within minutes to mass-produce images. The traffic is not a person trying the product. It is bots harvesting it, using the launch to build a training library for a model of their own. No system was breached. No invoice went unpaid. Every account signed in cleanly and used exactly what it was offered.

That was one company, and it is not the exception, at any size. The headline version makes the news: in 2026, Canva moved to shut down a ‘seat cycling’ scheme that spun up trial accounts to harvest and resell its AI image credits. The everyday version is quieter, and just as costly: a developer pushes an API key to a public repository, or a poisoned open-source package lifts the keys out of a team’s pipeline, and the first anyone hears of it is a five-figure inference bill.

Access controls are not what failed here. The front door was locked: keys, OAuth, rate limits, all in place. The problem is that valid access is exactly what gets taken, and it gets taken in more than one way. Attackers spin up fake accounts by the dozen to farm free trials and promotional credits, cycling through a fresh allotment with every new signup.

They take over legitimate, paying accounts and burn through the credits your customers already bought, so the loss lands on your best users before it lands on you. And they buy valid access outright, from credentials that leaked into public code, got phished, or were sold on marketplaces built for it. Once a valid key or a believable account is loose, the meter bills whoever holds it, human or machine.

Stolen keys running models on someone else’s bill are now common enough to have a name, LLMjacking; in a March 2026 research note, the Cloud Security Alliance documents a single compromise running to roughly $46,000 a day in stolen inference.

The methods and the motives keep changing, from reselling stolen access to powering other attacks, but they share one trait: each looks legitimate on the way in, so the bill climbs until someone catches it.

Where the loss lands

The direct overage is only the visible part. Underneath it, compute fraud spreads into the work and the numbers your team already owns. It burns quota you provisioned for paying customers, so real users hit limits and service degrades. When the credits being drained belong to a paying customer, that customer feels the fraud first, and the refund, the dispute, and the lost trust land on you next. It pulls a lean trust and fraud team into credential-rotation fire drills and incident response instead of the roadmap. It sets the false-positive trap: tighten the rules too far and you block the good users and the conversion you are measured on. And it quietly corrupts the metrics you forecast from, so the next plan inherits the noise.

Weak or missing credentials were the top way into cloud environments, tied to 47 percent of intrusions in a recent period, according to Google Cloud Threat Horizons research, and that same open door is what turns your compute into someone else’s free resource.

What actually stops it

By the time the cost is climbing, the login is not the problem. The credential is valid, the account cleared every check at the door, and on its own it looks like a customer. What gives the fraud away is the pattern across accounts: the same devices, the same infrastructure, the same behaviors and relationships surfacing again and again. So the way to stop it is to stop judging accounts one at a time and start triangulating the actual entity behind the activity, connecting the signals a single account hides and recognizing the shape of an operation already running inside your system. This is a different discipline from authentication. Login and MFA verify a credential at the door; catching compute fraud means identifying the entity doing the damage once it is already inside, with enough confidence to act on the call and defend it to a customer, an auditor, or your leadership. It takes pattern recognition and judgment at scale, applied continuously as the tactics change, which is usually what a lean team lacks.

By the time the cost is climbing, the login is not the problem. The credential is valid, the account cleared every check at the door, and on its own it looks like a customer. What gives the fraud away is the pattern across accounts: the same devices, the same infrastructure, the same behaviors and relationships surfacing again and again. So the way to stop it is to stop judging accounts one at a time and start triangulating the actual entity behind the activity, connecting the signals a single account hides and recognizing the shape of an operation already running inside your system.

This is a different discipline from authentication. Login and MFA verify a credential at the door; catching compute fraud means identifying the entity doing the damage once it is already inside, with enough confidence to act on the call and defend it to a customer, an auditor, or your leadership. It takes pattern recognition and judgment at scale, applied continuously as the tactics change, which is usually what a lean team lacks.

Where to start

That is where FiveBy comes in. We pair Entity Intelligence and pattern recognition with experienced fraud practitioners who triangulate the actual entity behind the damage and handle the fraud already inside your system, alongside your team. The outcome is fewer bad accounts, protected margin, and a compute line you can forecast again, without new headcount or a heavy lift. Start with one capability, prove it against your own traffic, and expand as it earns its place. If your forecast keeps breaking and the usage all looks legitimate, let us scope a pilot: one capability, with the proof and the numbers you can take to finance.

Limit your risk, not your business.


Sources

Beyond the Login : Stopping Account Takeover

Catching account takeover after the login, without adding friction for the users you want to keep.

Expand
Catching account takeover after the login — without adding friction for the users you want to keep.
You’ve already locked the front door. The opportunity now is to extend that same confidence past the login, all the way to the session itself, so you catch abuse early, act with confidence, and protect revenue instead of chasing losses after the fact.

The Fight Has Moved Past the Login

MFA did its job at the door, and it belongs there. The next move is to carry that protection to where the fight actually happens now: the authenticated session. Get it right and you keep good users flowing while quietly closing the gap fraud has moved into. Because that’s exactly where organized fraud has gone. Attackers wait for a real user to sign in, then take over the authenticated session, and there are many ways to get one: malware that lifts cookies off the device, phishing kits that sit in the middle of a real login, malicious browser extensions, and more. The method matters less than the result. What they end up with is a live, logged-in session in someone else’s hands, with no password stolen and no MFA prompt to answer. To the user, it surfaces as charges they never made or a payout that never arrives; to your team, it’s one more dispute in the queue that looked completely legitimate on the way in. This is a large and growing pattern. Microsoft records roughly 600 million identity attacks a day, and more than 99% of them target passwords, which is exactly why sophisticated actors have industrialized the next step: taking over the session once a real user is already in. And the cost keeps climbing. The FBI’s Internet Crime Complaint Center reported more than $16 billion in cybercrime losses in 2024, up 33% in a single year. For a trust and fraud team, the question isn’t whether you’ll see this. It’s how you catch it early, act with confidence, and show the call was right.

The Friction Paradox: Why Your Strongest Signal Now Points at Good Users

Conversion depends on a frictionless experience, so your platform runs on long-lived session tokens that keep users signed in across web and mobile. A session token is simply the credential your platform issues at login to keep someone signed in, so whoever holds a live token is treated as that user, no password required. That’s the right call for the business, and it’s also the opening fraud takes. Once a session is taken over, the attacker inherits your user’s trusted status instantly. No password. No MFA challenge. And this isn’t limited to free or trial accounts. Every logged-in account runs on a session, and the higher the account’s value, the more attractive the takeover. That now includes AI sessions themselves: a stolen seat to a paid generative-AI tool or enterprise AI assistant is exactly the kind of high-value session attackers want. To your automated checks, the request looks like it’s coming from the customer. Which is the hard part you already live with: the strongest signal you have (a valid, authenticated session) is now the fraudster’s best disguise. To your defenses, the attacker looks exactly like the customer. The opportunity is telling them apart in real time, while still letting good users through.

The Blast Radius: Beyond a Single Account Takeover

When token fraud lands on a multi-sided platform, it doesn’t stay one account takeover, and it doesn’t stay one team’s problem. Because every hijacked session looks legitimate, the abuse routes straight into the work your team already owns: review queues, disputes, and payout investigations that grow faster than you can staff.
  • On the demand side · BuyersHijacked sessions ride one-click checkout, drain stored loyalty value, and push fraudulent transactions before the real user notices. Each one comes back as a chargeback to represent and a “was this really fraud?” review. Every rule you tighten to catch it also risks blocking a real buyer, so the queue and the tuning burden climb together.
  • On the supply side · Merchants & sellersA compromised seller account is never a single fix. It’s a high-touch investigation every time: payout holds, banking-change and re-verification, support escalations, counterfeit-listing cleanup. Multiply that across accounts and it’s caseload your headcount can’t scale to.
  • For streaming, content & creator platformsAt scale, operators harvest sessions and run them as farms of “trusted” accounts: reselling premium access, botting views and engagement, and laundering funds through subscriptions, tips, and in-app currency, while hijacked creator sessions get payouts diverted and channels taken over. Because every token looks like a real viewer or creator, the abuse buries itself in legitimate traffic and corrupts the very analytics your models and analysts rely on.
None of this is exotic. It’s volume, and volume is the problem: the loss is real, but so is the operational drag, and both land on a team that can’t hire its way out. That’s the case to take upstairs: not just fraud caught, but caseload contained.

Defend the Journey, Not Just the Gate

If your fraud program stops at the login window, everything downstream is exposed, and you’re left reconciling losses instead of preventing them.
In a world of automated fraud, a valid token can’t be taken at face value.
The opportunity is to close that gap with continuous, automated validation of every session that monitors the whole journey and acts in real time, without the friction that pushes good users away, and without standing up a program you don’t have the headcount to run. FiveBy pairs that automation with experienced practitioners who operate it alongside your team, so signals become decisions instead of another dashboard to watch. You can start with one capability and expand as you see results. None of this replaces MFA. It extends that protection to the session. Three moves make it work:
  1. Contextual and behavioral signal analysisAI reads the whole journey continuously. Does the way this session moves, navigates, and transacts break from the user’s own baseline? The point isn’t more signals. It’s signals that resolve into a decision.
  2. Device and network intelligenceTie each session to the device and network it began on. When a live token suddenly appears on a new device, from an impossible location, or behind a mismatched fingerprint, that’s a clean, explainable reason to step it up or shut it down, one you can put in front of anyone.
  3. Operational calibration, operated with youModels and playbooks tuned continuously against your real traffic (by automation and by FiveBy practitioners working alongside your team), so you clear good users and hold a high-fidelity trigger on genuine abuse. That’s the difference between “we have signals” and “we made the right call, and here’s why.”
A static perimeter can’t hold when trust can be copied. Real protection means evaluating trust continuously across the whole lifecycle, and being able to show, signal by signal, why each call was right. Handle it well and the session fraudsters try to exploit becomes an asset: fewer false positives, less loss, and confident, defensible decisions you can stand behind, with finance and with leadership.

Scope a Pilot

How confident are you that the sessions you trust today are still the users you onboarded? At FiveBy, we help trust and fraud teams make confident, defensible decisions about the sessions they trust, combining experienced practitioners, intelligence, and AI-powered technology to catch abuse tools alone miss, and operating it alongside your team without disrupting the customer journey or adding headcount. Let’s scope a pilot: start with one capability, with the proof and the numbers you can take to finance.

Limit your risk, not your business.


Sources

  1. Microsoft, 2024 Microsoft Digital Defense Report. com/security/security-insider
  2. FBI Internet Crime Complaint Center (IC3), 2024 Internet Crime Report. gov/AnnualReport

Fraudsters Are Building Businesses. Most Organizations Are Still Investigating Incidents.

Fraudsters Are Building Businesses. Most Organizations Are Still Investigating Incidents.

Expand
Short answer. Organized fraud now operates like a business: specialized groups acquire, monetize, and resell access at scale, while most companies still investigate incidents one at a time. The teams pulling ahead stop treating each alert as a separate problem and start identifying the whole entity behind the activity, early enough to act. In one FiveBy analysis of 300,000 accounts already flagged for fraud, 94% would have fallen into the highest-risk band at account creation, before the loss occurred.
For years, fraud has been treated as a series of isolated incidents. A fraudulent transaction, a compromised account, a chargeback, a fake user, or a policy violation triggers an investigation, gets routed to the right team, and is eventually closed. The assumption underneath is that every incident is a discrete problem that can be resolved on its own. That assumption is breaking down.

Why are fraud incidents no longer isolated?

Because the actors behind them are organized. Most companies now face coordinated operations, not lone bad actors, and one group’s activity surfaces separately to security, fraud, and Trust & Safety. What looks like unrelated incidents is often one entity seen from different angles. Each event looks manageable on its own. Together, they describe one entity operating across the platform. That is the core idea behind entity intelligence: the risk lives in the whole entity behind the account, not in any single signal it trips.

What does “the account is the inventory” mean?

It means a compromised account is not the prize but stock to be sold. One group steals it, another supplies the infrastructure, a third monetizes it, and it may be resold to thousands of buyers. The account is inventory in a larger operation.
“The account is not the business. It is the inventory.”

Which businesses are most exposed to this kind of fraud?

Any business where accounts carry value: creator platforms, marketplaces, gaming, subscription services, loyalty programs, and fintechs. Attackers are not after access itself but after assets they can monetize, rent, resell, or transfer. Wherever value exists, organized actors find a way to reach it.

If everyone has more data, why is fraud still winning?

Because the problem is context, not data. Security, fraud, Trust & Safety, and operations each see one symptom of the same activity, and no team owns connecting them. You can flag every alert and still not know who is behind it. More data is not the answer. Better context, resolved into a single entity, usually is. 94%. In one FiveBy analysis of 300,000 accounts already flagged for fraud, 94% would have fallen into the highest-risk band at account creation, before the loss occurred.

What separates the fraud programs that pull ahead?

They turn understanding into decisions they can defend. The programs that win are not the ones catching the most incidents but the ones that recognize the entity and business model behind the activity and act early, before the loss lands. If you lead one of those programs, the shift is from reacting to events to recognizing the entity driving them, and deciding with enough confidence to act before the chargeback or payout occurs.

How does FiveBy help?

FiveBy is a risk-intelligence partner. We pair practitioners who have built fraud programs for more than fifteen years with purpose-built technology that resolves entities and maps their connections, so you can see the whole entity behind an account and decide with confidence. Handled this way, the goal stops being damage control. When you can see the whole entity, you can tell a trusted new customer from an organized threat at signup, approve more of the good with less hesitation, and defend every call you make. That is the difference between limiting your business to limit risk and limiting the risk so the business can grow. The future of fraud prevention will not belong to the organizations that investigate the most incidents. It will belong to the ones that understand the businesses behind them, and turn that understanding into confident, sustainable growth.

Frequently asked questions

What is entity intelligence?

Entity intelligence evaluates the whole entity behind an account, its identity, relationships, and behavior over time, rather than scoring isolated signals. It classifies entities by risk and explains why, so teams can make faster, defensible decisions about trust, fraud, and payments.

Why treat fraud as organized rather than as isolated incidents?

Because most abuse now involves multiple specialized actors who acquire, monetize, and resell access. Investigating incidents one at a time misses the connections between them. Identifying the shared entity behind the activity reveals the larger operation and where the real risk sits.

Which industries are most affected by account-based fraud?

Any business where accounts hold value: creator platforms, online marketplaces, gaming, subscription services, loyalty programs, membership organizations, and fintechs. In each, attackers pursue assets they can monetize, rent, resell, or transfer, not access for its own sake.

Can fraud be caught before the loss happens?

Often, yes. In one FiveBy analysis of 300,000 accounts already flagged for fraud, 94% would have fallen into the highest-risk band at account creation. Recognizing the entity early lets teams act before a chargeback or payout occurs.

What is a risk-intelligence partner?

A risk-intelligence partner combines experienced practitioners with purpose-built technology to help a company understand the entities behind its accounts and act on them. FiveBy works alongside a team’s existing tools and infrastructure rather than replacing them.

When Decisions Break… After the Fraud Alert

Most risk programs don’t fail from lack of signal, they fail after the alert fires. Learn how calibration creates consistent decisions and stabilizes outcomes.

Expand
Would two investigators make the same decision on the same fraud alert?
For many mature risk programs, the most significant challenge isn’t a lack of signal. Most organizations have spent years investing in sophisticated infrastructure, including complex scoring models, device and identity data, and diverse vendor platforms. On “paper”, the system appears robust: alerts fire, cases flow into manual review queues, and escalation paths are clearly defined.
Yet, outcomes eventually stall. Despite having experienced teams and cutting-edge technology, the same case types keep resurfacing, escalation rates increase, and reviewers often disagree on identical case profiles.
When results become inconsistent, the issue is rarely a failure of detection; it is a failure of what happens after the alert fires.

The Hidden Breakdown: The Handoff to Judgment

A breakdown occurs when the tech stack identifies a mid-risk score or a set of mixed signals and hands the case off to human judgment. This is where divergence begins. Without explicit, shared criteria, “defensible” decisions (decisions that can be explained in isolation) quickly become “inconsistent” ones across the broader team. In practice, we see this systemic breakdown manifest in four specific ways:

Thresholds That Age Quietly: A score that meant “review” six months ago may no longer be relevant. As attacker behavior changes and legitimate customer patterns shift, static thresholds lead to a gradual increase in false positives or overlooked losses. The system behaves as configured, but the configuration no longer matches the environment.

Escalation Without Shared Criteria: When two reviewers look at the same case and reach different conclusions, the problem isn’t their experience, it’s the lack of explicit criteria. If one reviewer blocks based on velocity while another approves based on account age, the outcome depends on the individual rather than the policy.

Automation Beyond Its Original Scope: Rules are often introduced to reduce volume, but eventually, nuanced cases start being auto handled by systems that were never intended for that level of complexity. Reviewers lose visibility, and the system begins running outside its original strategic intent.

Business Misalignment: Tools are often set with general assumptions that fail to account for a specific company’s risk tolerance or revenue sensitivity. The tool may perform “correctly” according to its code, but its impact on the business is misaligned.

Micro-Case Study #1: The Consistency Gap

Consider a marketplace that saw rising refund volumes and customer complaints, yet no single fraud alert was firing consistently. The team had plenty of data, but because each event looked “normal” in isolation, no detection was triggered.

Inside the review queue, the problem was compounded by subjectivity. Reviewers regularly disagreed on mid-risk cases: one would weight account history while another focused on transaction velocity. Both were “correct” in their reasoning, but the inconsistency meant that the same type of fraud was being approved by one person and blocked by another. Once decision rules were made explicit and tested against past cases, escalation dropped significantly and outcomes stabilized. No new signals were added; the team simply aligned their interpretation of the signals they already had.

Micro-Case Study #2: The Static Threshold Trap

In another instance, a mature risk team relied on a score threshold that had been highly effective at launch. However, as attackers adapted, the threshold “aged” quietly. The stack remained the same, but the behavior of the attackers became more subtle. Because the thresholds weren’t recalibrated based on current behavior, review queues grew uncontrollably and false positives spiked. The solution wasn’t a new tool; it was recalibrating the judgment calls within the existing stack.

The “More Signal” Fallacy

When outcomes stall, the instinctive reaction is to add more signal, more rules, more models, and more data points. However, if the interpretation of the current data is inconsistent, adding more data only increases the debate. More alerts increase volume, and more signals increase escalation. You end up with more activity, but not more consistency.

Calibration: Moving Beyond the Framework

To change outcomes, decisions must be made consistently under the same conditions, a process we call Calibration. This isn’t a theoretical policy rewrite; it is an operational discipline that involves working inside live workflows to:

  • Identify exactly where decisions diverge between reviewers.
  • Define how specific signals should be weighted in different contexts.
  • Revisit thresholds based on current, observed behavior rather than historical assumptions.
  • Clarify the precise boundaries where automation should stop and human review should begin.

At FiveBy, we focus on making the work repeatable. We move the criteria out of people’s heads and into documented, tested investigation workflows and escalation playbooks.

The Results of a Calibrated Program

Within weeks of shifting focus toward decision consistency, organizations see tangible improvements:

  • Repeated case types stop resurfacing in the queue.
  • Escalation rates drop as reviewers gain confidence in the criteria.
  • Decisions become faster and are no longer dependent on which individual handles the case.

The system becomes predictable because the interpretation is shared. You aren’t just reacting to alerts; you are managing a system with intentionality.

The Diagnostic Question

If you want to know if your program is struggling with this breakdown, stop looking at your detection dashboards for a moment and ask one question:

“Would two different reviewers make the same decision on the same case today?”

If you can’t answer with a definitive “yes,” that is exactly where your work needs to begin.

Know Your End-User: Supply Chain Diversion Poses Rising Legal Risk

Know Your End-User: Supply Chain Diversion Poses Rising Legal Risk

Expand
A new lawsuit filed by Ukrainian civilians in U.S. courts illustrates a growing and often misunderstood risk for U.S. technology companies: you can face severe legal and reputational consequences even when you believe you’ve done everything right. In this case, plaintiffs allege that U.S.-made microchips were diverted, without the manufacturers’ knowledge, to the Russian military and used in missile and drone attacks on Ukraine. The lawsuit is a timely demonstration that exposure doesn’t depend on intent or direct involvement. Civil actions, alongside government penalties, are becoming a powerful tool for holding companies accountable for gaps in supply chain oversight. As diversion risks increase, so does the need for rigorous due diligence and end‑user verification at every step of the supply chain. Below, we break down the case to help companies understand how these risks emerge and what practical steps can reduce the likelihood of facing similar litigation.

Background

In December 2025, Ukrainian civilians filed suit against U.S.-based technology companies Intel Corp., Advanced Micro Devices Inc. (AMD), Texas Instruments Inc., and their distributor, Mouser Electronics. The lawsuits, brought by Watts Law Firm LLP in cooperation with BakerHostetler LLP in a Texas court, allege that the companies negligently allowed their microchips to be diverted to Russia, where they were incorporated into missiles and drones used against civilian infrastructure. As of early December 2025, 20 plaintiffs are represented by the law firms with each lawsuit seeking more than $1 million in reparations. As of this writing, the defendants have not yet responded to the claims, making it too early to assess the likelihood of success. The companies named in the suit maintain that they comply with U.S. export controls and sanctions and do not directly supply products to Russia and other sanctioned jurisdictions, signaling that they intend to contest the allegations rather than pursue early settlement. Regardless of the eventual outcome, the litigation itself carries significant financial, operational, and reputational costs. The case underscores a critical reality: supply chain diversion can create legal exposure even for companies that believe they are fully compliant.

Export Controls and Due Diligence Negligence at Fault for Diversion

The lawsuit makes four main claims against the defendants:
  1. Negligence. The plaintiffs claim these companies failed to adequately design and enforce export control systems. They argue that the defendants neglected to perform due diligence on high-risk customers, ignored government warnings about product diversion risks, and continued sales to risky transshipment hubs and intermediaries with ties to diversion activities. This negligence allegedly enabled the Russian military to obtain and use the companies’ microchips in weapons systems used against Ukrainian civilians.
  2. Negligence per se. The plaintiffs assert that these companies violated US export control laws, sanctions, and executive orders aimed at preventing sensitive technology from reaching hostile actors. The plaintiffs argue that these violations on their own constitute negligence.
  3. Gross negligence. The plaintiffs allege that these companies were aware of the high diversion risks from public reports and government warnings. Though aware, the companies continued sales, fully understanding the potential harm.
  4. Wrongful death and survival claims. The plaintiffs, who are families of victims killed in missile and drone attacks, claim these US companies’ negligence directly caused victims’ deaths. Plaintiffs seek compensation for mental anguish, loss of companionship, and other damages under Texas law. Survival claims also seek damages for physical pain, medical expenses, and funeral costs.

Challenges and Risks

Companies with insufficient supply chain compliance face significant reputational risks. Consumers, investors, and other stakeholders are placing increasing pressure on businesses to act ethically and in alignment with international norms. In addition to legal settlements, reputational damage could decrease companies’ long-term market value. Relying on supply chain partners without rigorous internal controls or incentives to comply with export regulations presents another risk. Examples include partners with low transparency and insufficient secondary sales tracking exposing companies to liability. Companies can decrease these risks with comprehensive diversion controls and supply chain monitoring processes.

Best Practices and Recommendations

Ultimately, companies are legally responsible for sanctions compliance whether or not they are actively managing it. To mitigate the risk of diversion-related lawsuits along with sanctions and export controls enforcement, US tech companies need to take a proactive due diligence approach. A proactive due diligence approach is particularly critical when dealing with potential dual-use or military end-user products. The proactive due diligence approach differs from a reactive approach, which only addresses issues when suspicious transactions arise. A proactive approach includes an ongoing system of checks and audits tracking end-use and end-users of all products. This proactive approach should also include monitoring the whole supply chain, including secondary distributors and end customers.

Key best practices include:

Enhanced Due Diligence Procedures. Conduct comprehensive background checks on all partners, including secondary distributors. Require detailed, verified end-user certificates before agreeing to transactions. This practice supports US export controls compliance and lowers the risk of diversion to sanctioned countries like Russia.

Regular Auditing and Compliance Reviews. Establish internal compliance teams that regularly review the entire supply chain, not just direct sales channels. Checks should include tracing products from manufacturers to end users to ensure that no diversion occurs at any point.

Engage Legal and Regulatory Experts. Partner with external legal advisors to stay informed on export controls and sanctions developments. Keeping up with and adapting to ever-changing international trade laws is key to avoiding legal violations.

Supply Chain Monitoring Tools. Leverage cutting-edge software solutions that track products through every stage of the supply chain. Technologies like blockchain can provide immutable records of transactions, improving transparency and accountability.

Conclusion

At FiveBy, we have the expertise and specialized professionals to help companies navigate the complex compliance challenges surrounding export controls and sanctions, particularly with military end-use technology. We understand the growing risks of civil lawsuits, as highlighted by recent cases against US technology firms and are equipped to assist businesses in mitigating these threats. FiveBy’s Risk Intelligence Team works with industry-leading tech companies to conduct thorough due diligence, implement effective diversion checks, and verify supply chains. We support our clients by proactively finding ways to safeguard their operations, reduce legal risk exposure, and provide reputational protection from product misuse and international conflict.

Let’s Talk

Contact us to learn how we can help you stay compliant, protect your reputation, and build a culture of integrity across borders.

Testimonials

What Our Clients Are Saying

“FiveBy has been our trusted partner for over 5 years, supporting us with sanctions due diligence and investigations. Over the years, we have developed a relationship rooted in mutual respect and shared culture that prioritizes a personalized approach to our unique internal challenges and processes.”

Keep Current and Thrive

At FiveBy, we believe staying informed on the latest trends is essential to optimizing revenue growth. Our News & Advisories page delivers expert analysis, updates, and guidance across fraud, financial crime, sanctions, and compliance.

From regulations to emerging threats, we break down what matters so you can make smarter decisions, reduce risk, and unlock opportunities. Whether you’re a risk leader, compliance officer, or fraud strategist, our insights help you anticipate change and act with confidence.