iGaming fraud has surged 64% year-over-year, with advanced bonus abuse and account takeovers slashing more than 15% of operators’ hard-earned revenue. From fake identities to complex multi-accounting and rotating devices/IPs, it is getting harder to track bonus abuse, opening the door to more fraud further down the player journey. And with growing pressure to ensure responsible gambling, the stakes have never been higher for iGaming Operators to evolve beyond traditional approaches to ensuring profitable growth.
Watch this on-demand panel discussion that deep dives into the challenges of balancing business growth with regulatory demands. Hear from industry leaders as they break down actionable strategies for protecting both your players and platform, helping you meet responsible gambling requirements while confidently growing revenue.
You’ll also learn:
- 5 ways to address the new generation of bonus abuse, account takeovers, and self-exemption fraud
- How to make the most of the iGaming ecosystem to strengthen identity protection and player protection
- The new approach to player journey mapping that boosts fraud prevention and improves conversion rates
- How to leverage industry risk intelligence and AI to uncover behavioral insights and address complex fraud tactics
- Practical case studies showcasing how leading iGaming operators are addressing these issues today.
Watch the On-Demand Webinar
Video Transcript
0:00
Good afternoon and welcome to our latest SBC webinar, accelerating profitable
0:05
play, preventing bonus abuse whilst ensuring responsible gambling. A really
0:11
really important subject today. We’re going to yeah, we’re going to tackle it
0:14
head on and uh yeah, do our best to to provide some really important insights
0:19
into the industry and yeah, we have uh we we have a really good panel to do it
0:24
as well, a decorated panel bringing lots of different perspectives from all
0:28
corners of the industry. So any questions that you have, please feel
0:32
free to uh to get them in and we will endeavor to get them answered. Uh but
0:37
yeah, let’s get right into it because we’ve uh we’ve got so much to tackle
0:40
today. So uh let’s uh introduce our panel. I will uh let them introduce
0:44
themselves. They can they can certainly do that better than me. And uh yeah,
0:48
start from the top. Uh Britney, how how are you?
0:51
>> I’m okay. Good. I get to go first. So I am Britney Allen. I’m a senior trust and
0:57
safety architect at Sift. I’ve been working in fraud prevention and trust
1:01
and safety for about 15 years at companies like Epsi and Airbnb.
1:07
Um I will pass it on to Stephanie.
1:11
>> Hi. Uh pleasure to join. Thank you for the opportunity. Um Stephanie Tren. I uh
1:17
worked at SIFT and my goal uh is to align I gaming use cases with
1:24
innovation. And so spend a lot of time deep diving into the fascinating and
1:28
nuance world of of I gaming.
1:31
>> Brilliant. And uh Vladislav.
1:34
>> Hello everyone. I’m glad to be here. Um Vlad, you can call me Vlad for short.
1:39
I’m currently um group head of bonus abuse and gaming fraud for Evoke. Um I
1:44
have over 12 years of experience specializing in various aspects of uh
1:49
fraud prevention and uh management in the online gambling industry. Background
1:55
um includes expertise in chargeback prevention, cyber security fraud
1:59
operations and of course bonus abuse and gaming fraud prevention.
2:05
Passing the ball to uh Stephen.
2:09
>> Yeah. Uh Steve Armstrong. Um I’m the founder and director of FRL compliance
2:14
solutions. Previously um group MLRO at both hills and betway. Previous to that
2:20
lots of experience in risk compliance in payments and in the finance space.
2:26
>> Amazing. And Mia last but certainly not least.
2:30
>> Hey everyone, I’m Maria Abella. I am lead compliance governance at Baton
2:34
Group for the past five years where we basically establish governance
2:38
frameworks for the entire group. So we manage policies and procedures which we
2:42
then disseminate to the rest of the business to ensure a cohesive approach
2:46
to our processes. Fantastic. And uh I guess we had quite a
2:51
collaborative approach to the introductions there. You’ll pass the
2:54
baton on and really fits the theme of this panel because I think uh that’s
2:59
what we’re going to highlight is that a collaborative approach when tackling
3:02
fraud is of the utmost importance. But to kick us off, um, yeah, I guess, uh,
3:09
there are so many things to kind of go into and so many aspects of this to kind
3:14
of break down as an industry, but what can we do as an industry to ensure that
3:19
uh, we work smarter and not necessarily harder, work in a more efficient way
3:24
when it comes to tackling bonus abuse and fraud. Um, Vlad, if you kick us off
3:30
there, if that’s okay.
3:32
>> Yeah, definitely. Maybe the most trivial things at first like we need to have
3:36
good internal collaboration between different different uh analytical and
3:41
operational teams to ensure that proper controls are set and abuse is mitigated
3:47
uh as soon as possible. Uh of course be aware of uh any new trends that are
3:52
arising. uh have the particular uh let’s say products in place to be
3:58
able to uh uh to prevent encounter the fraudsters at
4:04
best levels that that this can can be done. I will leave some of my colleagues
4:11
also to uh add few things so I won’t take the whole spotlight on me. very
4:17
graceful and uh Stephen I know you obviously in your various roles you kind
4:21
of had to be ahead of the trends right that’s uh yeah it’s so so crucial
4:26
>> no is it’s it’s very crucial I think that um there’s lots of different
4:30
aspects of this and the collaboration and working smarter starts right from um
4:36
you know stuff like good data um good knowledge of of of what you’re actually
4:41
looking at and I think that that the data is the key here there’s there’s
4:44
lots of places that um may have the right address, you might have the right
4:48
approach, but if they’re not looking at the right data or got the right data,
4:50
then it’s all going to fall fall over come the end of it. So for me, that
4:54
collaborative bit is, you know, you’ve got pool teams, you’ve got risk teams,
4:57
you got AMLs, compliance teams, but if they’re not all looking at data, then
5:01
actually they’re not going to be able to to to work smart. Um, so for me, yeah,
5:05
that’s that’s definitely the starting point.
5:08
>> Yeah. Yeah. And uh Stephanie, I know you uh you believe a lot in data. From from
5:12
the conversations we’ve had, you kind of believe a lot in uh not just having a
5:16
lot of data, but uh you know, getting a holistic view of data and being able to
5:20
utilize it in the correct way.
5:23
>> Yeah. And I like that Vlad and both Steve kind of started on a practical
5:26
approach. I think as companies grow and and expand uh uh what you see is that
5:32
there’s a lot of data collected in being in different pieces and um the through
5:38
line um is really this concept of how can you not only think about data
5:44
holistically but operationally how do you align that and mapping that
5:49
specifically to the customer journey. um it’s a big task but but the there’s more
5:55
data accessible than ever before and it’s a blessing and a curse because what
6:00
do you do with that and how do you keep that clean? Um I think it’s a tactical
6:05
um strategy that that needs to be instilled in in the culture moving
6:10
forward if it hasn’t been already.
6:13
>> Yeah. No, Britney, I’ll let you kind of piggyback off that point.
6:17
>> Yeah. I I think I’ll both piggyback off of it and then pivot ever so slightly
6:21
because there’s some things that had come up in my mind as as others were
6:24
speaking and I I think one great call out for working smarter and not harder
6:30
is just to make sure that as an organization and as a fraud prevention
6:34
unit you’ve decided what your level of risk tolerance is for your business and
6:40
so you have that baseline because everything will build off of that the
6:45
goals that you’re looking to reach the metrics that you need to hit to report
6:48
up within your organization. They all fall back on just how much uh potential
6:54
loss can we let through, how much of an appetite do we have for potentially
6:58
turning away some legitimate customers as we, you know, make our decisions on
7:03
how our approach to, in this case preventing bonus abuse will work. But if
7:08
you don’t know what that overall risk tolerance level is that you have to sort
7:13
of play within, then you might just think, well, let’s try to stop
7:17
everything. Let’s try to fix it all. Let’s try to be, you know, on top of
7:20
let’s put um hours and hours and hours of effort into a little piece or an
7:25
initiative that’ll only move you up a couple of basis points in a metric
7:30
that’s not that important anyway. So, that’s one way that I really want
7:34
everyone to make sure they still see the forest for the trees, so to speak. Um,
7:38
it’s great to do the deep dives into data like what Stephanie mentioned. Just
7:42
know why you’re looking at it and what you’re trying to accomplish.
7:45
>> Okay, that’s really interesting. If I could uh just follow up there like what
7:48
will be some of the uh the the kind of metrics the variables that dictate in
7:53
terms of how much of a risk factor you know an operator will will be not happy
7:57
to lose but will be kind of okay to yeah lose.
8:02
>> So I don’t want to take all of the answers. I’m going to follow Vlad’s lead
8:06
and just say one thing and then pass it on. But I mean, in a highly competitive
8:11
industry with a lot of options, monthly active users and return customers, your
8:17
ability to not have somebody, let’s say, if they’ve just heard about your brand
8:21
because you’re doing an advertising push on bonuses and you how you have an
8:25
affiliate program spun up, you don’t want to have those people become super
8:29
frustrated, not even get to interact one time with your product, and then bounce
8:33
for a competitor. So, I would throw that one out to start, but then I’ll I’ll be
8:37
quiet for a minute. And it makes a it makes a lot of sense. And Miria, I’m
8:41
going to come come to you now just to kind of yeah reflect on working smarter
8:44
and not harder and also some of the the points that have been made already.
8:49
>> Yes. Uh one of the first and important points was that there is this need for
8:53
cross departmental collaboration and knowledge sharing and we see that comes
8:57
also with training your workforce on multiple areas of compliance all the
9:01
horizontal areas so that they are aware of the importance of everything from AML
9:06
from RG from fraud detection and risk. The entire workforce has to understand
9:11
how these come together to one end goal. Um so training your workforce on all on
9:17
all areas of compliance not just a legal requirement but it helps you to
9:21
establish a good uh pediment for for your employees to be able to um work
9:27
more efficiently. Yeah, that’s a definitely a really
9:31
important point and uh yeah, Stephanie uh I know you agree right that it’s
9:36
really crucial that the silos are broken down and that teams kind of work
9:39
together and uh yeah share data as well when it comes to tackling fraud.
9:44
>> Yeah, and I’m going to try to tie some of the themes that that all together in
9:48
terms of KPIs uh data and silos. What we often see kind of going down
9:54
operationally um is sometimes the payment teams, the fraud teams, the
9:58
compliance teams in larger operations um sometimes act in silos and then
10:04
compliance may sit across all top and then there’s KPIs right and they may
10:08
differ and so where is the risk tolerance across the company to
10:13
understand uh at what points of the customer journey um that risk tolerance
10:18
is and then creating a deep feedback loop between all three departments. And
10:24
it could be as simple as making sure that there are weekly meetings. Um, but
10:28
what what I when I think about KPIs and data in some in some perspective, making
10:35
sure that there is a clear KPI at every point of the touch point, but also that
10:41
everyone has in some way, shape or form the same KPI and enough communication
10:46
and insights to understand. Let’s say you’re in a high growth market, you’re
10:50
dipping into Africa, you may talk to Vlad and say, you know what, just kind
10:54
of open the gates a little bit. But that kind of KPI has to follow through, but
10:59
also be commun communicated to the compliance team to understand how that
11:04
impacts compliance in the same manner. Um and so KPIs alignment, customer
11:11
journey alignment, data mapping, but the communication between the internal teams
11:16
and then I will add an um um a caveat to that. At SBC, we had a panel that had a
11:22
lot of different vendors and one of the takeaways is that the vendors in and of
11:27
themselves have a lot of data about your players.
11:31
>> Yeah. um they have processes and technologies and it’s as simple as
11:35
making sure that you communicate with them to extrapolate how much data they
11:39
may have so that can give you a little bit more flexibility when you do want to
11:43
fine-tune that risk tolerance across the journey.
11:47
>> Okay. Uh yeah, a couple of points there to touch on and I’m I’m going to kind of
11:52
tap into Steven Vlad in a sec, but first Stephanie, when you talk about those
11:56
vendors, uh do do you mean like we we need a a bit more maybe support from the
12:00
the financial sector, the the the data from the financial sector,
12:04
>> the financial sector, the KYC sector, all you know, you can go to an exciting
12:10
event like the SBC and the ISIS and what you do see is just it can be
12:15
overwhelming even if you do not want to use them. I highly suggest understanding
12:19
where they are pushing the envelope on insights to understand what you can
12:24
glean from them um and doing your due diligence and not only just staying on
12:29
top of fraud trends but seeing how innovation is giving you more more
12:33
insights to even kind of slightly adjust your strategy whether it be compliance
12:37
because now you know that data is out there and or if you don’t want to how
12:42
can you glean it internally.
12:44
>> Okay. Yeah, that’s uh really interesting and we’ve already had a couple of
12:47
questions in, but first I want to kind of draw back to something else you said
12:51
and uh yeah, when it when it comes to kind of aligning those KPIs and uh
12:56
breaking down the silos, you know, internal meetings, just making sure
13:00
everybody’s working on as as a team. Steve, obviously that’s very uh you
13:04
know, it’s kind of easy to say that, but in pract practicality at a large
13:07
operator, how how challenging is that?
13:11
>> Yeah, look, it’s very challenging. I think that um it comes back to
13:13
education. I think um I’m always a firm believer if you’ve educated the right
13:18
people on the process um educated them on the outputs and actually it makes it
13:23
a lot easier. Certainly in large operators you could have you could have
13:27
20 30 40 50 people looking at the same set of data and because there’s been no
13:32
education behind it then what actually happens is it just creates mass
13:35
confusion and then you’ll have commercial against compliance when
13:38
actually generally most of the time you’re both working for the same thing.
13:41
someone’s just said it slightly differently. Um, and when you bring in
13:44
wider groups, when you’ve got maybe international departments and stuff, you
13:48
know, there’s a word that that that someone in the UK might use that someone
13:50
in Mort might describe it slightly different. And actually, again, it just
13:53
creates mass confusion. So for me, you know, one of the big things when when I
13:57
was in the operators was um was actually taking that time out to um you know, if
14:04
I was running with a set of KPIs to do with AML, for example, you know, have I
14:08
gone in before the big meeting when you’ve got 50 people reading a debt,
14:12
have you actually spent time with them individuals to educate them on what it
14:16
means, why it’s there, and actually the benefit to them because a lot of the
14:20
time there is a benefit that that actually can be used in in other pieces.
14:23
So yeah, massive on the education piece for me.
14:26
>> And uh Mia, I’ll I’ll bring you in there. What challenges do do you guys
14:30
face when it comes to uh breaking down those barriers, you know, making sure
14:34
that uh you know, companies uh that you know internally you’re aligned on uh
14:38
yeah just KPIs and data sharing. Yes, going on to what Steven is saying,
14:44
it’s education and it’s also documentation of the policies and
14:48
procedures and in fact obviously every market will have its own compliance
14:53
requirements but what we try to do is take learnings from each market and as
14:57
much as possible apply uh a streamlined approach across markets so it makes it
15:03
easier for the rest of the business for the other teams who are working um uh
15:08
working on this to to understand the the the what procedures they have to follow.
15:13
So definitely the documentation of requirements um across the business is
15:19
one important thing for everyone to understand um what steps to take.
15:24
>> Okay. And I guess you can uh Mir you can learn lessons from various markets as
15:29
you yeah you kind of become more more global and uh move into different
15:33
markets.
15:36
>> Correct. I mean we see some markets where the regulators are issuing more
15:40
and more information on what they expect, what controls and and the the
15:44
level of controls they expect. Um which would make sense to apply for other
15:49
markets. So we sort of uh see what makes sense what’s what’s what’s good for the
15:55
business but what’s also good for the protection of the player at the end of
15:59
the day and try to apply it um across.
16:04
>> Okay. Yeah. And Vlad, I’ll uh bring bring you in there on on that one as
16:08
well. Um yeah, obviously bringing the operator perspective on kind of
16:11
practical challenges when it comes to breaking down the silos.
16:15
>> Yeah, ultimately what I just wanted to add to what Stephanie uh said is
16:19
eventually that we also need really good communication with the commercial teams
16:23
in order to um be able to manage their expectations with new promotions and be
16:29
able to prepare in advance to what may happen. um also uh monitor different uh
16:36
KPIs like second time deposits, third time deposits because it’s very often
16:41
that we can be challenged because we see decrease in FTDs. However, it’s not
16:46
necessarily something that is uh related to uh decrease of good customers. So
16:53
essentially there should be multiple KPIs that should be monitored and
16:57
compared to ensure that the uh proper um um like proper end information is taken
17:06
in consideration if I can say so. But yeah for regarding what Mariah said I
17:14
would say that uh at least for me it will be very essential that compliance
17:19
guide us to towards the policy that they create and then we need to align with uh
17:24
within our processes to ensure not only the operational processes but the
17:29
strategies and the products that we implement are meeting the regulatory and
17:34
of course compliance um expectations. So yeah, definitely it’s something that we
17:40
need to do in order not to work in silos, but um I’m not saying mainly this
17:45
needs to come from compliance, but it’s very essential that we receive those
17:49
guidelines from them.
17:51
>> Yeah. And Britney, you were nodding as Vlad gave his answer there.
17:55
>> Uh I was I was nodding through multiple parts of it. I’ I’d like to go back to
17:59
the the data that he pointed to and just share a little bit about some of what I
18:05
do within my work. So I run a deep and dark web investigations team and we in
18:12
addition to just trying to stay on top of fraud trends and you know learning
18:16
more about how fraudsters commit fraud we’ll see patterns in how they adjust
18:20
their behavior based on what merchants are doing and we have seen the I guess
18:27
length of time that they would age an account really really increase um to the
18:32
point where beyond the research that we do I actually had spoken to a i gaming
18:38
company earlier in the year that told me that their average age of accounts that
18:44
are used for fraud on their platform is about one year. So fraudsters have the
18:48
patience to sign up one year ago in 2023 to be able to use that account today and
18:55
over the course of that year they’ve perhaps done 10 euros in deposits a
18:59
couple of times a week. They’ve done normal looking activity. Maybe they’ve
19:03
bet on something but cashed out before the end of a game. They’ve taken little
19:06
steps that make them look like a a new participant and that is something that
19:12
the fraudsters are quite ready to do because for them it’s an entire business
19:16
that they are able to spin up. And so when I hear of people looking at, you
19:21
know, some unreliable data points, like just looking at, let’s say for credit
19:25
cards, the bin and last four, but not also looking at behavioral patterns and
19:30
not also looking at the actual full picture of what that account is up to,
19:35
then that makes me a little bit more concerned, makes me worry more about
19:39
being able to identify this. And you know, again to touch on what we’ve
19:42
talked about, not just fraud, but all the way up to those who are maybe
19:46
chronically abusing policy, because also each year that line between what we
19:52
would can just consider abusive behavior and fraudulent behavior does continue to
19:56
blur as fraudsters realize they can monetize things that we only considered
20:01
abuse and our policies haven’t quite caught up with them yet.
20:04
>> Okay. And I would like to double click into that as as we work uh a lot with
20:08
operators to understand their behavior patterns. And it’s interesting that Vlad
20:12
had talked about uh deposit timing. Um I don’t envy your job at all or Steve um
20:19
or Maria it’s it’s um in one hand I I think about it often as a cat and mouse
20:25
game and tying it back to the operator silos. Why is that important in terms of
20:31
that plus data plus KPIs is that um you’re never going to be able to cast m
20:36
the mouse. They’re going to multiply and they’re going to look like good mice.
20:40
And how quickly can you adjust will be dependent upon in large part a human
20:48
operation, right? like how quickly can Vlad talk to Mariah because compliance
20:52
is changing and how deep and how quickly can you spot trends because you know
20:58
they to Britney’s point for 3 months they might have an attack plan of okay
21:04
we’re going to have this velocity we’re going to do these first deposits and
21:08
Vlad will catch them and then in three months six months they might change it
21:13
and how do you know and how quickly can you move and moving one step above data
21:20
to behavior is really where I think the key is, but it is extremely amorphous,
21:27
right, in some ways. Um, especially in this industry and and so going all the
21:32
way back to that, I do not envy your job, but it is fascinating.
21:37
>> Thank you.
21:39
>> Well, maybe just to add to that, sorry to interrupt your job, but yeah,
21:42
ultimately I was about to say that it’s a constant game of cat and mouse. So
21:47
basically it’s all about hitting the frosters that bad so they can just move
21:52
to somewhere else for some time until you meet them again. And just also I
21:57
wanted to comment on what Britney mentioned actually is that um um another
22:02
smart adaptation that we see the frosters are doing is they are also
22:05
creating a different different online accounts on uh Facebook um let’s say
22:10
different other platforms in order to try to bypass the the checks that we are
22:16
doing and etc. So, it’s yeah, it’s very uh turbulent and you need to be able to
22:23
adapt to all those changes really quickly.
22:26
>> Yeah. And they’re not only creating those accounts, but they’re also, you
22:30
know, committing account account takeover and taking over valid accounts
22:34
that have histories that they then don’t have to bother setting up. And sorry to
22:37
interrupt you there, Joe, but I just wanted to share uh you just where we
22:41
took a last look at some email accounts from a popular email provider that were
22:45
for sale and they had very reasonably priced ones going all the way back to
22:50
being created in 2006, at least for this listing. So that would give a lot of
22:54
history and a lot of validity to that uh email if you were only looking at that
22:59
single data point. Yeah, I guess it really just underlines
23:03
the importance of uh keeping up with trends and ensuring that you’re
23:07
flexible, right? Uh yeah, Mir, I’ll bring you in there just to kind of
23:11
follow up what what the guy said.
23:16
>> Um yes, and also brings on the point of having strong verification controls. So
23:23
as soon as there is a uh anomalous activity something which which
23:29
might raise a red flag there needs to be specific tools which are raising these
23:34
flag to to the right people and then you have policies in place which set when
23:40
monitoring when verification has to kick in um to be able to understand who is
23:46
the is the person you are dealing with is it the same as the the who is
23:50
declaring to be the account holder. which is difficult to do at the front
23:56
end for promo and bonus abuse, right? Because there really isn’t.
24:00
>> We go again to the like to this circle where we see like the stolen identities
24:06
usage and um ensuring that we are verifying the players without creating
24:12
uh friction on the other hand. So in line,
24:19
>> sorry.
24:20
>> Oh, no, no. I I just had a bro I love fraud stories are my favorite. They’re
24:24
just so so interesting. One of the ones around
24:28
promo abuse and I think the throughine um uh around understanding behaviors is
24:33
one of the uh I gaming customers um had noticed promo bonus abuse. Long long
24:40
long long story short, it turned out um that there was like two or three
24:44
fraudsters that were going through their little town, a little town in Eastern
24:49
Europe and collecting IDs from the local villagers and they were passing KYC.
24:54
Um, and then with now, you know, responsible gaming and compliance, like,
24:58
uh, you know, how do you how do you track that and how quickly can you track
25:03
that and what are the compliance implications of someone complaining
25:06
that, you know, their ID was stolen or used for this account? So, um, again, do
25:11
not envy your guys’ job, but it is fascinating.
25:15
>> It’s a Yeah, almost impossible to keep up with that. It’s so challenging,
25:20
right? But Stephen, I’ll bring you in for one of the questions that we we’ve
25:22
had here from uh our audience. Um yeah, just to bring it back and really
25:27
simplify it. What are some of the critical signals that experts should
25:32
check for promo abuse? Um, but there’s I mean it’s not just
25:38
promo abuse I guess and this goes you know when you talk about promo abuse it
25:42
links in with what you’re looking at around responsible gambling around KYC
25:47
signals that aren’t just going to define one element. You know you’re not you’re
25:52
not setting up a matrix of controls that’s just looking for promo anymore.
25:56
It’s almost like a there’s so many different touch points. So when you
26:00
think about, you know, fooled and and promo, you know, we’re looking at um
26:05
triggers in KYC, you know, have they passed automate automatic verification,
26:09
for example, or, you know, has that failed and then they’re asking for
26:12
documents. For me, that’s that’s always generally sometimes a big sign because,
26:17
you know, if if you’ve got enough of a presence online, certainly when you talk
26:21
about the UK, for example, you know, you’re generally going to pass a uh you
26:25
know, I won’t name them all because they’ll get free uh they’ll get free uh
26:30
marking, but you know, a different verification tool, you know, that that
26:33
actually enables you to to to not have to send in documents. That that’s an
26:37
early sign. You know, what devices are they on? Is it um you know is their IP
26:41
address same as as as 10 other um accounts that you potentially cloned? Um
26:46
is the email link to other customers? Is the phone number linked to other
26:50
customers? Um is there multiple customers at the same address all in the
26:54
same age range? You know, there’s so many different different trigger points
26:58
that don’t just set you up for bonus abuse. He actually gives you the
27:01
knowledge of a customer. And I think that’s really really key is is whenever
27:05
I’ve sat in regulatory audits or in front of a regulator um there’s always
27:09
this assumption that that and that happens at at the end point. Well
27:14
actually you know when you’re talking about a control suite it’s from the
27:17
moment that customer signs up because they are capturing data from their
27:21
device. you’re catching data that they’re inputting and it may seem that
27:25
you know it’s not important but but all of that data builds a profile of a
27:29
customer that then enables you to trigger different elements of it and you
27:32
know there’s been lots of times you know um over the years where you potentially
27:36
looking at at one thing and thinking okay this is a you know this could be
27:39
abuse but actually it links into you know actually no this is an individual
27:43
who’s got a problem and actually he’s he’s you know signing up multiple
27:47
accounts under mult names because he’s just trying to get a bet on. So all of
27:50
these sort of interlink but um but yeah for me it’s you know start point is the
27:55
moment that customer logs in or registers you know we’re tracking that
27:59
data a bit etc. So yeah many different elements to it.
28:04
>> Steph I know you’re a a big believer in the through line between you know as
28:08
much as they’re very very different the the through line between promo abuse and
28:13
responsible gambling that Steven mentioned there. Yeah. To give give you
28:17
the floor to talk on that. Yeah. Um, and I’ll try and give a a a kind of a story
28:22
around sometimes complex and basic risk signals
28:27
with combinations uh can go through the player journey. So, let’s say someone
28:33
comes in and signs up for uh a bonus um and they pass the first test and they
28:39
sign up as Steve Armstrong and not Stephen Armstrong. They pass a KY test.
28:45
um they use the bonus, maybe they uh create a second account, not quite
28:51
tracked, uh and they flag themselves as a self-exempt or you know, you know, I’m
28:56
a gambler, please don’t do it again. Uh the operator has a second bonus because
29:03
they’re, you know, expanding, it’s game day or whatever. and then they register
29:06
as Stephen Armstrong um with a slightly different email uh
29:11
with a slightly different Facebook and it it filters through and they get all
29:16
the way and they they bet um and they bet at a velocity in which uh they are
29:23
making a bunch of you know deposits but not withdrawing. So it’s a slight
29:27
variation but you’re not sure. Um and then it and then they come back and say
29:32
hey why did you let me gamble? And so there’s multiple checkpoints around the
29:37
customer journey in terms of slight changes in behavior um that could have
29:42
been checked um and it’s really difficult to because you have to
29:46
understand um you know where is it the KYC check how does that difference in
29:50
behavior as they go through the platform you know and then they make a withdrawal
29:54
and then it’s really difficult because you have to have some baseline layer of
29:58
what’s normal and then what the deviation is normal. So, uh,
30:03
understanding and working together between those that check the front line
30:07
like Vlad, those are at the middle that are checking betting behavior all the
30:11
way down to payments because they’re tracking deposit withdrawals and being
30:15
able to at least say as an operator, look at every single risk signal and
30:19
every single behavior that I have tried to track. And you know, Stephen had
30:24
talked about it in in uh in a different discussion with him in terms of please
30:29
tell me if I got it wrong, but you know, proving proving your case as a
30:34
compliance person that that you’ve done everything possible to check with that.
30:38
So it’s not all on Vlad right at the front end or it’s not all on the
30:41
payments team. It’s the collaboration of the both and having risk signals uh
30:47
across the entire customer journey. Yeah, on that Steph the I think that
30:52
I’ve the amount of times I’ve I’ve seen a policy say that a company has a zero
30:57
tolerance the risk can fraud or you know it’s impossible you know and so so
31:02
actually you’re setting yourself up to fail that policy because you’re saying
31:05
you know you’re not going to let the aim of of
31:09
all of us in what we do you know myself and and Vlad and and and others in in in
31:14
them type of roles is that you’re trying to minimize the impact of it on your
31:18
business at the same time trying to catch the people that are doing it. So
31:21
for me it was always about that secondary check or is a reporting
31:25
element of this are we uncovering something bigger you know is it criminal
31:29
um do I need to be reporting to the to the relevant authorities etc. Um but
31:34
it’s actually I would never sit there and say you know my role was to ensure
31:38
that you know there was never any crime that happened for an operator worker
31:42
because I’d be setting myself up to fail. It’s about it’s about trying to
31:47
you know control how much of it happens and it’s learning from it to then stop
31:51
that happening again and as we keep speaking about it then changes and
31:54
changes and changes. So you’re constantly learning something new about
31:56
the way they might tackle it. But it’s it’s about minimizing the impact of that
32:01
and and when you take bonus abuse you know you take responsible gambling for
32:05
example there is there is almost a assumption on people outside the
32:10
industry that it should be stopped there. Well, actually that that’s pretty
32:15
impossible when you don’t know enough about a customer who just logged into
32:18
your into your platform. It’s about learning about their customers being
32:22
able to interact and to intervene at the right stages be that because you believe
32:26
it’s criminal or believe it believe it’s might be an RG issue or it might just be
32:30
sort of promo abuse example. So it’s it’s really you know for me important
32:36
that there is an acceptance within an organization that this stuff happens and
32:41
actually it’s how do you tackle this to minimize the impact both on your
32:45
reputation on your profitability on on your resourcing
32:50
um and actually being able to distinguish between crime and promo
32:56
abuse and RG you know as much as they all use the same data point there’s a
33:01
different need and a interaction and a different outcome at the end of each
33:05
channels. So it’s really really critical that you as a business you understand
33:10
that the difference between promo and RG or the difference between why you know a
33:16
suspicious activity happens compared to this is a group of people chancing
33:20
themselves to try and get three bets you know it’s it’s the business
33:23
understanding that I think is is really key.
33:28
Yeah, definitely. And uh Britney, I want to kind of bring you in there because uh
33:32
it kind of goes back to your point at the the top of the webinar.
33:36
>> Yeah. And and actually let’s you know talk through some of those practical
33:39
situations because you know one of the things that can be frustrating is you
33:44
hear a conversation from great and amazing experts like us here today and
33:50
you see like what should be done and you have all these ideas for what you can
33:54
improve on but then maybe you don’t know exactly where to start. And we’ve called
33:59
out the idea of getting over siloed teams a few times and I’ve definitely
34:05
had to do that within my work in fraud prevention and that could be as you know
34:10
kind of complicated as being the people who shut down the transactions and are
34:14
seen as the revenue killers trying to work with a internal sales team or
34:20
trying to work with product. And in those instances, I’ve just found that if
34:25
I can find that common ground on how to speak their language, then I’m able to
34:31
show them that I’m okay. I’m not something that’s big and scary and
34:34
should be kept out of the room until the last minute because that could actually
34:37
lead to a larger failure of whatever new product or revenue stream they’re trying
34:42
to launch. And so when I’ve worked with, you know, sales teams, uh, instead of
34:48
coming up to them and saying,”Well, your job is to, let’s say, go out to
34:52
different sport organizations and try to see who wants to work with us on a big
34:56
push around this event.” And you really don’t want that to fall flat because,
35:02
you know, all of the promotion you did around it, let’s just tie it back to
35:05
bonuses and say there was a bonus, you know, code attached to that, gets tied
35:09
back to fraud. You don’t want all of your work to go to waste. So here’s what
35:13
you need from my team that will allow you to avoid that and make it easier on
35:18
you. They can work smarter, not harder. And the same thing with product. I’ve
35:22
dealt with teams where they were, let’s say, previously only in an app, but now
35:27
they’re adding a payment functionality to web and maybe they’re adding it in a
35:31
new geography and so we’ve launched a new uh payment provider for that and
35:36
they didn’t want to worry about putting fraud prevention or having that tied
35:40
into our overall system before they launched because oh fraudsters won’t
35:43
notice. That’s just one little thing we’ve we’ve ticked up in this particular
35:47
geo or on this particular platform. But me being able to step in and explain
35:51
what could actually happen in terms that they understand and that all then like I
35:57
said goes back to how do they report their success and how can I show where
36:02
fraud prevention will will keep that safe. So you’re so crossunctional in
36:07
fraud prevention. You work with customer support product and engineering. You
36:11
work with operations. If your chargeback disputes or a disputes are handled by
36:16
finance, you have to work with them too. And so that is an indispensable skill to
36:21
have within this role.
36:23
>> Yeah, I I agree wholeheartedly. And uh Mirara, I want to bring you in for kind
36:28
of one of one of the questions we’ve had come in. Uh just uh where would the
36:33
where would you draw the line between a customer legitimately seeking to
36:37
maximize the return from a bonus uh versus a bonus abuser?
36:47
So like we’re saying there’s there’s overlap in assessing these behaviors and
36:52
this is where um the company has to understand the tools and the data has it
36:58
at its disposal to be able to come up with a comprehensive framework of uh
37:03
markers of harm and and red flags and ensure that where there is um these
37:09
triggers which are um triggering and pointing to specific behaviors is
37:13
communicated to the rest of the teams not just siloed to one uh particular
37:20
team.
37:21
>> Yeah. Is I guess underlines the importance of yeah just being uh
37:26
spotting the red flags or being uh embracing the customer throughout the
37:30
whole journey. And Vlad, I’ll uh give you a chance to answer that one as well.
37:34
Uh yeah, where would you draw the line between uh a customer legitimately
37:39
seeking to max return from a bonus versus a bonus abuser?
37:43
Yeah, depend I I assume it uh it really depends on how you look at it and how
37:48
much risk you’re let’s say able to allow for uh for this particular
37:55
um I don’t know operator brand or etc. So eventually you can be more you can
38:00
ease the controls if you are sure that let’s say you can have more
38:05
opportunistic abuse which will eventually you will expect for them to
38:09
return at some point and deposit play with you and etc. Uh when it comes to
38:16
bonus abuse, maybe it’s easier to draw the line between the bonus and promotion
38:20
abuse because then you will have from one end people that will be searching to
38:24
maximize the um the return from a particular bonus while the promotion
38:30
abusers will try to use different um approach uh exploit different promotions
38:37
um use other uh prohibited behavior like for example chip dumping uh life casino,
38:43
poker and etc. So, it really depends on how you look at it and um what the risk
38:50
you’re able to take.
38:53
>> And I would like to to add on to that. We often get um this this request around
38:58
or or question around how do you stop bonus abusers at the front gate, right?
39:03
How do you not even let them in? And what Vlad had had kind of tapped into
39:08
was um you know the the a lot of the bonus abuse happens after sign up. And
39:15
the good frosters that do the max amount of um damage, we’re not talking about,
39:20
you know, mom and pop trying to capitalize on two bonuses. the ones that
39:24
have real damage are pretty strategic and they will sometimes wait um and and
39:31
behave differently further down the funnel um than the initial kind of open
39:36
the gates. And so um sometimes we we do get questions how you know I don’t want
39:41
to even let them in. Can you do that? And you know that’s the the risk
39:46
tolerance and the balance between the commercials and of trying to stop
39:50
everyone at the gate is probably not good because you you really don’t know
39:53
if that and if that person ends up who might have intentionally tried to do
39:58
bonus abuse ends up being a good player. You know it’s really monitoring them in
40:02
some ways further down um the line but keeping them you know within that
40:07
compliance guard rail. Um I think I think is key. and step on that. I think
40:12
that that one of the one of the um elements of it is is when we talk about
40:18
the cross department piece earlier is it’s generally a commercial team putting
40:21
a new marketing um or bonus in place
40:25
>> and actually what tends to not happen is that that stress test of that in a in a
40:32
in an environment because it’s generally one event to the next you’ve got
40:35
Chelenham then you’re into Premier League then you’re into this and
40:38
actually I think there’s you know there’s enough evidence now from
40:42
operators that actually they could be stress tested on it. So actually when
40:45
one of my push backs was always to the commercial guys well look this is your
40:48
marketing campaign. Yes, I’m here to to add value to it and ensure it’s, you
40:53
know, but actually if if it’s not working, you know, you guys needed to
40:58
come to us before you switch the arm in a way and let us test that and actually
41:02
create a program because a lot of the time they’re switched on for fast events
41:06
and then it’s like, you know, it’s a weak spell, but actually we should three
41:10
months before we’ve already built out what we would expect and who we would
41:13
see. you know, take a horse race in Cheltonham, you’re going to like most
41:15
likely get a different demographic of individuals who’s going to be signed up
41:19
to that compared to an Ascot race, you know, where it tends to be, you know,
41:22
I’m not going to offend anyone here, but it tends to be younger people um going
41:26
to ascot for a day out, um groups of friends, whereas if you go to a Chelham
41:30
festival, it’s your old school racing panels, you know. So it’s it’s all of
41:35
that that can be combined to to make sure that you know it becomes profitable
41:39
from a marketing and from a commercial element but with that becomes you know
41:43
have you assessed that you know that the the the it might be amazing you might
41:48
get you know a million more signups but actually you’re losing money behind the
41:52
behind the scenes because actually you’ve not fall through strategy and
41:55
controls behind it. So for me it’s that early testing um you know and being able
42:00
to give the likes of VLAD as we said you know I can define a policy but then hand
42:04
that over to to to individuals like Vlad who then build out that control function
42:09
to say you know okay this is how I’m going to meet this policy and if I’m
42:14
going to you know minimize the impact of that to the business. I think I think
42:17
not enough is done on something like promo abuse. We know we do it a lot on
42:22
the KYC on RG we do it, you know, it’s it’s it’s the hot topics, but actually
42:26
when you go back to the basics, it’s, you know, how do we how do we make it
42:32
profitable? That’s what these marketing campaigns are about. Um, and and you
42:36
know, it’s led by a commercial person, but actually it’s it’s one of the one
42:40
things where the opposite way tends to happen is that’s their policy in terms
42:44
of their campaigns. Now, we’re going around to go, okay, how can we make this
42:48
this okay? whereas normally it’s compliance saying here’s my policy where
42:52
I’ve been there guidelines. So it’s quite a unique thing with promo abuse in
42:55
that sense because it it does flip the roles a little bit.
43:00
>> True.
43:01
>> Yeah, Vlad, I’ll uh let you kind of uh come in there.
43:05
>> Uh yeah, ultimately not much to add here. I think Steven really really
43:10
elaborated it quite good. Um yeah ultimately like there should be a good
43:15
communication between uh between commercial and uh enough time should be
43:20
given for the uh analytical and fraud teams to prepare for eventually um like
43:25
big events and um let’s say new promos that eventually might lead to increase
43:31
in uh abuse operational work and etc. Um, of course, um, ensure that the
43:37
proper rules in the fraud solution systems are set, uh, just to make sure
43:42
that, uh, you are ready to meet the, let’s say, the consequences at at that
43:47
point. But,
43:48
>> and what are what are the challenges in Oh, go on, Britney. Sorry.
43:53
>> Oh, no. I haven’t started to say anything. That’s
43:55
>> Oh, sorry. I think my my my my uh thought around
44:00
that and um just to to think about uh what Steve said about the different
44:05
behaviors of you know different games, different markets. Um one thing that I
44:09
don’t see enough of um but it’s out there um is is uh you know the
44:15
collaboration of best practices. because I know gaming is so competitive. Um but
44:18
when you enter those use your network uh there are there are especially in the
44:24
vendors who sit across different ones they have they may have best practices
44:29
already um and reach out to your network to say hey if we’re expanding into
44:33
Nigeria what are some common trends and giving I I don’t I the amount of times
44:38
I’ve seen oh god the fraud teams or the payment teams is saying oh god they’ve
44:42
launched this already like we need to do this tomorrow um but making sure you
44:46
give the fraud team and payment team or whoever the compliance team enough heads
44:49
up is key but also uh tapping into the best practices of your networks and uh
44:53
your vendors and you know SBC you know professional services to say you’re not
44:58
the only operator here can we collaborate a little bit and um you may
45:04
get push back you may not but there’s no harm in in kind of asking you know
45:08
>> yeah and MRI getting enough enough time getting these these promos stress tested
45:14
that’s vital from a compliance point of view as well there.
45:18
>> Yes. U like Stephanie is saying, when you launch a new market where you’re
45:22
going through a new venture, it’s it’s a collaborative effort and maybe it’s also
45:27
um the role of compliance who’s a bit central to put the importance on this
45:33
topic also to be tackled um from the get-go. um because sometimes much focus
45:39
is put on certain elements and then other areas of compliance um are tackled
45:45
as we go along and not from the beginning. So that is also important
45:49
that from the the get-go of of delving into a new market or or expanding um
45:56
these these items are are reviewed from compliance and are put on paper are put
46:01
on policies which are then communicated to the teams.
46:05
>> Okay. Yeah. And um Britney, I want to come back to you here just for a kind of
46:10
a a new one. You you mentioned um aging accounts um new threats uh yeah what
46:17
what can companies do just to ensure that they do kind of stay up to date
46:21
with uh the the latest threats I guess and yeah they’re make sure they’re fully
46:25
equipped to know what they are tackling.
46:28
>> Yeah. So to to go back to some of the questions that we’ve had you come
46:32
through from the audience figuring out who is a bonus abuser or what that even
46:37
means. Um there was a word that was said a little earlier opportunistic. And I
46:42
think that’s an important distinction to make. Like know which of the people who
46:46
are violating or breaking a policy or otherwise taking actions that you’re not
46:50
really keen on. How much of that is just opportunistic actions and how much of
46:54
that is organized and malicious? Because what’s organized and malicious should
46:58
have a pattern. You know, Stephanie mentioned, oh, it’s really hard to stop
47:02
them from the moment they sign up. But what if you already know that they are a
47:07
malicious actor because of the connections that they have to a prior
47:11
pattern you’ve identified and other accounts you’ve already taken action on.
47:15
So, don’t lose sight of that. But when we’re looking to find research and to go
47:21
in, uh, that’s actually something that I do give trainings on just because I’m
47:25
always concerned about people, you know, not having the the greatest OPSAC when
47:29
they’re looking at the deep and dark web and, you know, maybe getting themselves
47:33
into a little bit of issue. Please on your work computer, don’t click any
47:35
links. I don’t want to be responsible for anyone’s work computer uh, getting
47:39
taken over. But beyond that, if you attend conferences or if you follow
47:44
certain thought leaders on LinkedIn and other platforms who are able to share
47:48
research that they find, that can be really really beneficial. But also just
47:52
ask uh I’m sure that you know anyone else here who has a team within their
47:56
org that does that type of monitoring, they’re also happy to give some
48:00
recommendations. And because of the way that fraud has shifted in recent years,
48:06
especially in an accelerated manner since 2020 to where they are more
48:10
comfortable operating out in the open, you’ll actually find a lot that you can
48:15
start with on apps like Telegram that don’t require as much, you know, work or
48:21
or software to access like Onion Links do. So, there are places that you can
48:26
start and to begin to gather some of that intelligence. But I just say again
48:29
uh not on your work computer and please don’t blame me. Please don’t blame me.
48:34
>> Um and I I’d like to double click. Vlad has an interesting uh I think you had
48:39
introduced yourself and and bringing in the security piece. Um security and and
48:44
account takeover is typically sat on one side of the house.
48:49
Um, but what Britney is doing and I always find fascinating whenever she
48:53
shares her insight is how much of that is now being sold on the dark web. And
48:58
the throughine is between security and account protection um and bonus abuse
49:04
and multi-accounting and online gaming is is really starting to merge. And
49:10
outside of behaviors, uh what I often see and um is difficult.
49:15
It’s just a business is a business and we’re all run by people is that I bet
49:19
you Vlad has some really, really, really deep insights that he spends a lot of
49:24
days in in terms of player behavior. And I bet you the payment team has really,
49:28
really deep insights around how the nuances of different behaviors and
49:34
payments types. Um and so going back to that cross intelligence, right, is
49:40
really important to have almost uh those discussions around and it’s hard because
49:45
everyone’s putting out fires, but really taking a moment as operation to share
49:49
like this is the trend I’m seeing in payments to be linked to promo abuse.
49:53
Um, and that can be linked to the dark web and also asking your network and the
50:00
vendors to see to to understand like what is happening on their end at the
50:03
KYC that is actually coming through the bonus abuse that is filtering through
50:07
all the way to um the payments team. Um, and and I they’re like you guys are like
50:13
FBI profilers here in the US. you understand really distinct behavior and
50:17
it changes and so it’s not just data it’s not just behavior but sharing those
50:22
really deep insights um I think is really key across the the departments
50:29
>> yeah definitely agree with you um ultimately after the merge of uh for
50:33
example the merge of uh 888 and William Hill we were able to use um and like the
50:40
best practices from both ends and it was funny how at some point we saw same um
50:46
uh same fraud profiles that were eventually trying to exploit and um same
50:51
happened also years ago with Mr. Green when William Hill um uh took yeah uh Mr.
50:58
Green but yeah that this leads us to the to to to the conclusion that eventually
51:02
they are trying their uh best efforts everywhere all across the business. does
51:07
it’s very important to um and underlining what you said to make sure
51:12
that eventually you have all the insights available from um from your u
51:18
fraud uh vendors, fraud solution vendors and etc. Whatever they can provide for
51:22
you as information is essential to ensure that you are um able to detect
51:28
the new trends and are up to date with the with those trends. So definitely
51:33
agree with you. That’s a a really interesting way to end
51:38
and yeah, we have run out of time, but yeah, I feel like we could talk about
51:41
this all day. It’s a so interesting uh such a good discussion. Um so so much to
51:46
deep dive into off the back of it as well. And yeah, thank you to uh a really
51:50
esteemed panel for for for your time and your insights and thank you to everyone
51:54
for tuning in as well and for your questions. Uh really appreciate it and
51:59
yeah, thank you and uh yeah, thanks ever so much.
52:03
>> Thank you, Joe. Cheers



