Account takeover (ATO) fraud has become one of the fastest growing threats facing digital businesses in 2025, reaching a 2.5% attack rate across industries in Q3. The cost of successful ATOs is felt across organizations, from fraud teams and cybersecurity, to product and beyond.
As a result of successful ATO operations, Fraud-as-a-Service (FaaS) vendors have taken hold in dark web forums and continue to thrive. Heading into 2026, agentic AI is the hottest topic for both consumers and fraudsters, calling for new discussions about what it means to keep your business and customers secure.
Learn about updated ATO performance metrics, the projected impact of agentic AI-powered account takeovers, and what your company can do to be prepared.
Watch the webinar to:
- Gain industry insights regarding account takeover performance.
- Learn about the tactics employed by Fraud-as-a-Service dark web vendors.
- Join the conversation about what agentic AI might mean for your 2026 fraud strategy.
Watch On-Demand
Video Transcript
0:00
Hello everybody and welcome to the 2025 Q3 digital trust index ATOS in 2025.
0:09
Aenti supercharges fraud as a service. We’re going to give a couple of minutes
0:14
for the rest of the attendees to kind of stream in. Uh but in the meantime, let’s
0:19
go ahead and get uh introductions going. Jimmy.
0:22
>> Hi. Yeah, I’m Jimmy Dunn and I am a product marketer here at CIF. been with
0:27
SIFT for about four and a half years.
0:30
>> And I’m Alexander Hall. Uh I have 18 years of fraud related experience. I
0:34
currently serve as a trust and safety architect here at SIFT. Uh previously I
0:39
operated as a fraud prevention analyst all the way up to head of fraud and then
0:42
after that I operated independently as a consultant for a few years. Uh I joined
0:46
Sift in August of 2024. Let’s see. Yeah, we’ll still give it
0:52
another minute or so to uh let everybody trickle in. Thank you guys for taking
0:56
time out of your day to be here. We appreciate it.
1:35
All right, let’s go ahead and get started. All right. So, there’s been a
1:38
lot of updates in the world of ATO’s especially as we look out at the
1:42
industry and how we feel that Agentic AI is going to to shift uh the landscape.
1:48
Right? So, as we dive into the material, please feel free to drop any questions,
1:52
comments uh into the chat. We’ll make sure to get those questions answered
1:56
either during or after the presentation. Uh yeah, we look forward to to doing
2:00
this. So, let’s go ahead and hop in. So,
2:02
>> do you want to start your screen share, Alex? Oh, thank you so much.
2:08
I guess it didn’t carry over from the backstage. Thank you.
2:12
>> Yep.
2:12
>> There. Is that coming through?
2:14
>> Yes, it is.
2:15
>> All right. So, first and foremost, as we predicted, uh, you know, ATO’s have
2:21
grown over the the course of the last year, right? We’ve hit a point where we
2:27
expect to see 17 billion worth of losses. When we calculate the atto
2:32
losses in 2025, the attack rate has grown uh 4%
2:38
uh generally speaking across the entire marketplace. In addition to that, when
2:42
we pulled our consumers, we found that 14% of consumers reported that their
2:46
accounts have been taken over and we’ve hit a milestone with ATO tracking. uh
2:52
ATO’s have have effectively uh surpassed ransomware as the top enterprise uh
2:59
security concern. Now, if this wasn’t concerning enough,
3:03
it’s obvious to say that the methods of fraudsters are shifting from more of a
3:08
payment focused uh type of attack into account focused attacks. So, uh Jimmy,
3:14
when you look at these stats, what kind of jumps out at you?
3:18
>> Yeah, I think you you started to allude to it, right? the the the facts, the one
3:23
fact in security that never changes is that people are a soft spot. And so as
3:28
other regulations, as other uh fraud preventing strategies begin to to harden
3:34
and make ground, the the spot that that remains permeable is people and is the
3:40
accounts that people have. So if if as fraudsters are looking to get in to get
3:44
big uh uh big hits and to get out, that’s what they’re going to look to.
3:48
And and the other I think uh macro impact that’s driving this is the fact
3:54
that more and more value is being stored online in digital assets whether that’s
3:59
uh miles or whether that’s crypto or other uh uh
4:04
cryp uh coins or other monetary related things that are online that can be
4:09
drained and are targeted in that way. We’re definitely going to be diving into
4:12
that a little bit further, but you bring up a great point when we contrast the
4:16
value of a single fraudulent transaction. Let’s say, you know,
4:20
someone takes over a QSR account and they go and get, you know, an order of
4:24
food, right? that value, right, of a single fraud related uh payment fraud
4:29
related attack versus the value of an entire account being taken over,
4:34
especially when you contrast that against a platform that stores value
4:37
like crypto and like fintech as we’ll be getting into. Um the value there is just
4:43
tremendously different, right? And so through the eyes of a fraudster, uh the
4:47
value of an of an account level uh attack is much more valuable than than
4:52
than payment fraud. Great point there. Thank you for that.
4:56
Moving on to the next slide is exactly that point right and so what we’ve seen
5:02
is the rising atto uh attack rates by industry highlights to us you see there
5:07
on the left fintech and finance have seen a 122% increase yearover-year
5:14
that is shocking right we see travel and ticketing a 56% increase over time we
5:20
saw loyalty points getting hit really hard last year and then internet and
5:23
software those digital deliveries, those things that don’t require shipping
5:26
addresses, those are especially appealing to fraudsters because they
5:30
don’t have to meet the requirements of having a drophouse or exposing
5:33
themselves through different shipping uh shipping uh practices. Right. So, Jimmy,
5:37
during our prep, you you spoke about travel and ticketing. Uh please for
5:41
attendees, let’s go ahead and dive into that.
5:43
>> Yeah. So, so I’ve been doing some work recently with uh some of our EMIA
5:47
clients uh just looking at some of the trends and what’s happening in that
5:50
space. and uh EMIA is further along in the regulation territory than we are
5:55
here in the the US. Um and so they’re maybe a a a preview of what’s to come in
6:02
in more global areas in some ways. And what they’re seeing, especially in the
6:06
in the airline industry, is a massive shift to account related fraud as the
6:12
primary means of of fraud that they are trying to prevent. They call it ghost
6:16
accounts. um where where they will uh they will have an account that’s attoed
6:20
and then they’ll have created their own uh gray market accounts and they’ll
6:24
quickly transfer miles from the accounts that they’ve taken over into these ghost
6:28
accounts, these mule accounts and then use those go to gray markets and uh sell
6:33
the miles or sell the the discounts, the rebates, the whatever they have um at at
6:38
steep discounts in in the marketplace to buyers who may not even be aware that
6:42
they are uh purchasing suspicious uh goods. So when again when when other
6:47
forms of of fraud become locked down, we know that fraudsters are malleable that
6:52
they will move to where the attack surface is widest and softest. And so
6:56
that’s that’s certainly what we’ve seen in travel and ticketing.
7:00
>> In your example, you brought up the the loyalty points and the manipulation of
7:03
the systems transferring them between accounts and especially when it comes to
7:06
mule accounts. One thing that I would really like to take the opportunity to
7:10
point out here is nothing along that process has a chargeback associated with
7:15
it. Right? When we’re talking about account level fraud, we’re moving
7:19
beyond, you know, chargebacks being the single source of truth for, you know,
7:24
the the impact of ATOS’s and what it is and and and what we measure performance
7:28
as. Chargebacks is a part of it, but in this example that you just gave, it
7:32
isn’t. Right. So when we’re talking about travel and ticketing and you see
7:36
this kind of of dynamic play out, what kind of an impact is that having to the
7:41
organization beyond chargebacks?
7:43
>> Yeah, that’s that’s a great question and and it is true that it may not trigger
7:46
like atto can be the type of attack that slips between the cracks because it
7:51
doesn’t necessarily fall under a chargeback. It doesn’t necessarily it’s
7:54
not a fake account that was created. It’s a real account that simply had
7:57
something something uh bad that happened to the consumer. There are hard costs
8:01
that are associated with it. And those hard costs go well beyond just the
8:04
chargeback itself. What’s the cost in customer service time um to speak to
8:09
customers who’ve experienced an ATO to recover um lost accounts? Um and uh what
8:14
are the the costs then of those customers leaving and and not coming
8:19
back? What’s that lifetime value impact? Um and then soft costs of when people
8:23
have an ATO, they want to go talk about it. They’re going to tell their friends.
8:26
It’s going to impact perception. It’s going to impact the customer acquisition
8:30
costs. Um there’s certainly a lot more things that that that come into it’s
8:34
really a holistic uh impact that ATO can have.
8:38
>> Absolutely. It spreads far beyond the fraud team. It’s far beyond dollars and
8:41
cents. It’s there’s the level of sentiment that gets impacted. And I know
8:45
we have a slide dedicated to that. We’ll dive into that a little bit deeper later
8:47
on. Uh I was especially uh drawn to this 122% year-over-year increase of ATO
8:55
attack rates to fintech and finance. Right. What draws my attention there is,
9:00
you know, years ago, uh, when I was looking out at the at the performance of
9:05
fraud, you know, on mass across the entire marketplace, right? We saw the
9:09
increase, we saw the trends when it comes to payment fraud, we saw the the
9:13
the now we are in the middle of account level fraud being the being a primary
9:17
focus in fraud fraud tactics and in the future there’s this idea of identity
9:21
fraudsters moving over to identity and that’s really the triangle of what what
9:26
fraud is, right? those three elements, right? And when we look at fintech and
9:31
finance, unfortunately, I was dreading the day when we would see that
9:35
fraudsters finally start pivoting from, you know, TVs, laptops, and hamburgers
9:41
and move over into accessing the accounts of, you know, where where st
9:46
where funds are stored as you had mentioned earlier. So now through the
9:49
lens of a fraudster, when we look at fintech and finance, it makes sense and
9:52
it’s almost predictable that a fraudster would really see the value of gaining
9:57
access to a bank account or a fintech account or one of these things and then
10:00
transfer those funds off. Now, similar to your example in the travel and
10:04
ticketing industry, uh the chargeback isn’t going to be in play here, right?
10:09
It’s not going to be the focal point, but the damages are going to be very
10:13
severe. They’re going to be very sentimental. Uh for anybody in
10:16
attendance, imagine if your account was compromised and you know your funds were
10:20
transferred off were were you know wire transferred or aed off somewhere else
10:25
from your account. There is no chargeback associated with that right
10:29
and you’re going to hold that that institution that platform very very much
10:34
um responsible for what took place right even if your account was taken over and
10:39
and things were done without the transference of money you’re still going
10:43
to have that lack of security. you’re still going to feel that that
10:46
vulnerability that that platform allowed to happen, right? So, there’s a lot of
10:50
sentimentality tied up into this. And I think that’s a great segue into
10:56
the impact. Oh, we’re not there yet, but we will be transferring into the impact
11:00
later on. Um, so with all of this in mind, we started to talk about the
11:04
sentimentality of the users, right? They are becoming very much aware of what it
11:08
takes to secure their accounts. They’re becoming very aware of the value of
11:12
their accounts. they’re they’re starting to participate and that’s what is uh
11:16
made clear here. We saw a 13% overall 2FA rate in Q2 2025. In order for there
11:24
to be a 13% increase overall, that means that the adoption rate needs to go up,
11:27
whether it’s imposed by the platforms or the uh willing adoption of the users.
11:33
Now, if we contrast that year-over-year, that’s a 30% increase from 10% the prior
11:39
year, right? So when we’re looking at this, we are seeing that uh the users
11:44
and the consumers are starting to participate in the securing of their own
11:49
accounts. Jimmy, what do you have to say to say to this?
11:52
>> Yeah, this one is as with a lot of what we’re talking about, it’s going to be
11:55
vertical specific, right? So where in verticals where more value is stored, uh
12:01
more uh more trust, more gates, more friction is expected. Right? If you’re a
12:06
bank, you want the bank to have big walls and pillars and you want it to
12:10
have a safe, right? So, so you you expect to be 2FA as you log in there. Uh
12:14
so for a lot of the fintech in the finance world, that’s just a given. We
12:18
we continue to see the creep of 2FA happening in other spaces. In spaces
12:23
like travel and ticketing and in other spaces where as users get more used to
12:26
it, it’s okay to throw that 2FA in in their way. However, uh in highly
12:31
competitive industries in uh food for example, uh food services and even in
12:36
some of these um like crypto areas or things like that where there are a lot
12:40
of competitors uh in marketplaces in uh things like ride shares uh the any
12:46
friction that you add uh is a detriment. Your marketers will know all about this,
12:51
right? Any friction that you add is a detriment to the conversion rate and is
12:54
a a chance of losing that consumer to a competitor. So there’s still that
12:58
there’s still that tension of we don’t want to 2FA everybody. We only want to
13:02
2FA when it’s absolutely necessary. However, the the appetite to 2FA by by
13:07
companies and the um being okay with it by consumers is on the rise.
13:13
>> You bring up a great point, right? As a consumer, I expect to have heightened
13:16
security when my when my account is more valuable. Very very clear and simple,
13:22
right? My bank account, my fintech account and all of those different
13:25
things. Uh, conversely, the other side, I just want to get in and out, right?
13:28
It’s just very quick and simple. I want to get in and out. I want my order done
13:31
and I want to get through it. So, uh, especially, uh, I love the fact that you
13:35
called out the highly competitive and saturated markets. Super competitive
13:40
means we’ve got to be careful on where we put it. And that’s where, you know,
13:43
things like behavioral analytics, uh, behavioral elements, you know, in really
13:47
robust passive verifications and passive analyses come into play, which I know
13:52
we’ll dive into. Again, we’ll dive into that later.
13:56
So when we dive into uh we’ve spoken about what comes from the report, we’ve
14:01
seen the highlights. Uh we’ve broken it down by industry. Now we’re going to go
14:04
ahead and dive into the tactics of atto. Historically, I’ve always said that
14:09
there are three categories, but we are seeing a fourth category emerge through
14:12
our deep and dark web investigations. We’re going to talk about the impact and
14:16
then we can dive into the last segment which is where we will discuss uh
14:20
strategic considerations as we head into 2026.
14:24
So number one, Jimmy, you and I just touched on this a little bit, but here
14:27
are some stats to support it. 75% of consumers would stop using a site
14:33
where they experienced atto. Now, although I appreciate that the 75%
14:38
number is generally applied across the marketplace, I expect that there’s going
14:42
to be a big difference between somebody attoing one of the QSR accounts versus Q
14:47
versus ating, you know, their fintech or their bank account. uh the 75% stat that
14:53
sounds pretty pretty stark to me. What do you have to say to it?
14:57
>> Yeah, I think I think that’s fair. This is uh maybe higher than we’ve seen it
15:00
some other times. I know that we’ve seen this hover around two and three in the
15:03
high 60s before. So, there may be a little bit of a spike this time around
15:06
in gathering the data. However, uh this trust idea is a real one. And the same
15:11
thing when there are when there when there’s more at stake, um there’s going
15:15
to be uh more uh action takens, right? So if if customers are have an atto on
15:22
an account that carries things that they care about where there’s an actual
15:25
impact that they can see or feel uh then it makes sense if the switching costs
15:30
are low that they’re going to switch they’re going to go to uh to somebody
15:32
else.
15:34
>> Absolutely. Uh we’re seeing that that trend you know that uptick happen there.
15:39
Uh and then we tie that down to that 60% stat there where the responsibility for
15:44
atto prevention is shared between the user and the business. Now, that is a
15:49
powerful statement there. It’s shared between the user and the business. And
15:54
that kind of double clicks back on that 13% stat that we just covered with the
15:58
MFA adoption, the 2FA adoption rate. If 60% of users across the the marketplace
16:06
are accepting some form of responsibility, that’s a very bright
16:11
thing. And that takes this this this f-word of friction, right? And it and it
16:16
lessens it. uh you know, it’s not so bad of a thing. It’s not so horrible. Yes,
16:21
we have to be careful where we apply it. Yes, we want to segment out, make sure
16:24
that we can let good traffic pass without the the the 2FA, make sure that
16:29
we only hit who we intend to hit. But a 60% response saying that that shared
16:33
ownership is a big a big improvement I feel over time. Jimmy,
16:39
>> yeah, and I think that that may may speak to users actually starting to get
16:42
better. Uh we also track hygiene in this report year-over-year. Uh, and we didn’t
16:46
put a slide for this one, but if you go in and look at the SIFT index report for
16:49
this quarter, it says that 23% of consumers are reusing a known
16:54
compromised password. That’s terrible. That’s one in almost one in four that
16:58
are reusing a password where they’ve gotten notification that this password
17:01
has been compromised. You still got people using two or three passwords that
17:04
they know rather than using like a password aggregator or some other
17:07
solution to make sure their passwords are secure. But it also says that over
17:11
half of users, 52% are taking uh extra steps to secure um most of their
17:18
accounts. So they’re doing extra things. They are doing the 2FA. They are uh
17:21
adding in those kind of secured passwords. So that’s that to me is uh
17:26
still a gaping hole but heartening, maybe getting a little bit better. And
17:30
then one other quick insight from this one, the uh what consumers are worried
17:33
about being hacked is their bank or their credit card accounts. So money
17:37
that’s online and it’s their social media platforms. So, so there are
17:41
different kinds of assets or equity online. There’s equity in terms of
17:45
dollars or points, but there’s also equity in terms of reputation and
17:49
connection. And if you think about it, those are like two polar opposites. One
17:54
is tangible, directly uh interchangeable, directly, you know,
17:59
transactionable, right? And all those things versus social media, right? you
18:02
couldn’t pick two polar opposite, you know, examples of of accounts, but then
18:09
for them to be the top two, that’s a very interesting stat to a very
18:13
interesting uh sentiment and idea to read out. Um, and then the last thing
18:17
here is the 87% that would tell others about the ATO experience, speaking about
18:22
social social media and all of that. you know, as we look out and we see, you
18:26
know, millennials, Gen X, Gen Z, all of these different generations and their
18:30
presence in social media and their their their want to be heard, their want to
18:35
have their platform, right? If they have a negative experience,
18:39
it’s it’s lightning quick before they’ll go and they’ll report, you know, what it
18:42
was that they experienced, uh, you know, under their social media platforms from
18:46
their soap boxes and it just spreads from there. Right? If I were to be the
18:50
target of a successful ATO and I went in and and and I found out that my account
18:55
was compromised and and I felt the damages of that, I’m of course going to
19:00
uh I’m of course going to go tell my my my network, you know, hey, let’s be
19:04
aware of what’s going on over here. Maybe maybe this account isn’t so or
19:07
this platform isn’t as secure as they should be and all those different
19:10
things, which of course has that that that that hit to brand reputation,
19:14
customer trust. Uh Jimmy, how do you feel about, you know, the amount of the
19:19
amount of consumers who are willing to go evangelize against platforms that
19:25
haven’t uh kept their accounts secure?
19:27
>> I mean, to kind of tie all these thoughts together, it’s it’s interesting
19:30
that that consumers that people intuitively understand the concept of
19:33
hard costs and soft costs that like somebody that breaks into my account
19:37
might take something that’s of value to me, but they might also just hurt my
19:41
reputation. They might waste my social equity. And you kind of wish that the
19:45
seauite would have the same kind of understanding. I don’t know that
19:49
businesses always understand both sides of that equation uh quite as directly um
19:54
as consumers do. So so the this is real. This is this is these are hard numbers
19:58
right here of if people have that bad experience they are going to go talk
20:02
about it and it’s going to have detrimental impacts to the business.
20:04
>> Absolutely. Absolutely. So we’ve spoken about the impact and of
20:09
course we actually did not put it here. The impact to chargebacks is there, but
20:14
the the by and large the more proliferating impact of ATOS is really
20:19
in those soft costs that you were talking about, right? The brand trust,
20:22
the brand reputation, the customer loyalty, and all those different items.
20:26
We’ve got to get closer to quantifying what that impact is so that we can
20:30
really start to attack it the same way that we attacked chargebacks, fraudulent
20:35
payments, and loss prevention before. Right? Those were all those items. We
20:38
quantified it. we were able to to begin solving for it and we’ve done a pretty
20:42
dang good job, you know, over time. Now, we’re focusing on ATOS and it’s not just
20:46
chargebacks and lost lost dollars and cents, lost items. We’re talking about
20:50
all these soft costs that you that you’ve uh that you’ve highlighted here.
20:54
Um we need to get closer to quantifying it so we can start chipping away and
20:57
putting that puzzle together and getting that getting that solved. Any last
21:01
thoughts before we move on from here? Nope. All right.
21:09
Uh, we’ve skipped a slide. There we go. Sorry. Uh, my computer must
21:14
have frozen, so I had to go back. So, ATO’s, we’ve gone over the impact of
21:18
ATO’s. And historically, of course, if you’ve attended SIFT webinars in the
21:22
past, especially ones that are focused on ATO’s, you’ve heard about a a you’ve
21:27
heard deeply about all of the ways that fraudsters gain access to accounts,
21:32
right? But for those of you who are new, I do want to go over this list and add
21:35
that fourth item. I want to share with you exactly how that works. Uh and and
21:40
that one’s gaining traction here. So number one is credential stuffing. When
21:43
we go back and we start thinking about bot attacks leveraging compromised login
21:47
details, if we think about a a bad actor who’s sitting at home going through a
21:52
list of compromised credentials and they start typing in username and password
21:56
credential uh combinations attempting to log into accounts or if we see a bad
22:01
actor taking this list of compromised credentials and taking as Jimmy as you
22:06
said taking one set and moving it over from maybe this is a streaming platform
22:10
password but now they’re going to go and check to see if it works. in this bank
22:13
account, you know, uh, login screen, right? So, they’re trying to see which
22:17
one of these work elsewhere. That all falls into the category of credential
22:22
stuffing. It’s it’s it’s rudimentary. It’s like a brute force attack using
22:26
these these uh compromised credentials. Number two, there is social engineering
22:30
of the user. We saw this uh really take off in the last 18 to 24 months where
22:36
the fraudsters have realized that because of MFA, you know, adoption rates
22:40
that because of different securities and step-up verifications that are in place
22:44
on these accounts, they might do better to just go straight to Jimmy, as you
22:49
said, the weakest point in the technology life cycle, go directly to
22:53
the human, right? And so fraudsters are going to the end user. they’re
22:57
manipulating them through I mean there’s been examples of romance scams there’s
23:01
been examples of investment scams uh malware and ransom not ransomware but
23:06
malware being installed on computers key loggers things like this uh or just
23:11
general social engineering of the end user to intercept those OTPs intercept
23:16
those different 2FAS or even coers the end user to satisfy the step-up
23:20
verifications uh so that the bad actor can ultimately gain access to the
23:25
platform so we’ve seen both Both of those take off for a while. The one that
23:28
another one that’s gaining traction right now is social engineering of the
23:31
platform through customer service. Right? So this works through the
23:35
fraudster, you know, being armed with enough uh identity information to
23:41
satisfy knowledge based verification questions. And what they’ll do is
23:45
they’ll call in to the customer service line. They will uh they will request to
23:51
change account information on a target account. The customer service agent will
23:55
ask knowledgebased verification questions, possibly send out OTPs,
23:59
whatever it might be. And through social engineering, the customer service agent,
24:04
they then reset the access information, the account information uh or the login
24:09
information on the target account and then log in that way. This last one,
24:14
cookie and browser hijacking. What we have seen on the deep and dark web is a
24:20
a rising trend where fraudsters are copying enough information from a target
24:26
device to effectively reproduce the cookie in the browser data in order to
24:33
enter uh the the active session without a password without any type of
24:38
verification taking place. they’re able to mimic an open session uh after
24:44
hijacking all of these cookies and the browser information. So, Jimmy, of all
24:48
of these, what would you like to uh dive into a little bit?
24:52
>> Yeah, I think I think that these are these are all interesting. I think that
24:55
the the the last one you talked about is a is a fascinating one. I think that
24:58
what I would call out is that for um any of these that are uh beyond the first
25:04
one, right, credential stuffing is like atto 101, right? It’s the it’s the use a
25:09
bot, go hard, try to try to crack your way in. Um, but a lot of these require
25:14
um they require multiple layers to be able to defend and they require uh the
25:19
ability to um to see on the back end and to act post login um based on expected
25:26
behaviors and based on other information which we we will also talk about I know
25:29
in a bit. Um that that’s super important. And the last one that that I
25:33
know we’re uh actually I’ll hold on to I’ll hold on to my next thought. I’ll
25:36
I’ll drop it later later on.
25:39
>> Okay. So, we went over the tactics, we went over the impacts. Now, let’s talk
25:44
about very quickly, let’s hop into not quickly, let’s hop into what agentic AI
25:49
means in the hands of ATO engineers. So, the bad guys that are committing ATOS,
25:54
the bad guys and girls that are committing ATOS, right? So number one
25:58
when we look out at the at the world of what aentic AI might become this is a
26:04
new emerging thing of what it might become there are a lot of questions
26:07
there are more questions than answers we need more clarity but number one is it’s
26:12
become very clear that agents are going to have access to a number of secondary
26:16
platforms secondary accounts now whether that’s you know anything from creative
26:22
accounts like you know maybe your favorite cloud service
26:26
content creation platform form uh or maybe that that goes all the way over to
26:31
um your file management systems, right? And all those different things all the
26:35
way across to bank accounts and back over to to food delivery apps. Which
26:39
accounts will agents ultimately have access to? That’s going to be a first
26:43
question. We know that they will have secondary access to secondary platforms
26:47
and accounts. Number two, agents can be automated and unfortunately in the case
26:52
of fraudsters, this will become a force multiplier the same way it becomes a
26:55
force multiplier for the intended users of the platform. Right? So we as
27:00
consumers are going to use this in order to be more productive in our day.
27:04
Fraudsters are going to do the same and it becomes a force multiplier. Instead
27:08
of a fraudster saying, “Hey, can we do this thing? Will this thing, you know,
27:12
uh, go log into this account?” Instead of that, say, “Hey, go try to log in
27:17
using all 100 of these credentials, 10 of these credentials, 100, 500.” Right?
27:23
That idea is going to come into play. Fraudsters are going to figure out how
27:27
to do that. Good agents will proliferate across the marketplace. Hey, as these
27:32
these these agents grow in kind, right, we’re going to see expansion across the
27:37
marketplace. We’re going to see adoption rate across the marketplace, and it’s
27:40
going to have a great positive impact on the marketplace overall. It’s going to
27:44
give a more competitive edge to a lot of different uh companies as they start to
27:49
build up and gain access to more more people. It’s also going to streamline
27:53
processes. It’s a very powerful thing, but unfortunately bad agents will blend
27:57
in with good agents, driving the importance of agent detection and
28:02
validation. I just said a lot, Jimmy. Go ahead and
28:05
take it.
28:06
>> Yeah, absolutely. So, I think one one thing that I’ll quickly in case the
28:10
questions are out there, I know last time we talked about this topic in a
28:12
webinar setting, people said, “What’s the difference between a bot and an
28:15
agent?” Um, and and so a a bot is something that’s programmed to carry out
28:20
a specific set of actions. And you can have pretty complex bots where you say
28:23
like here’s a thousand username and password combinations. Go try to log
28:27
into these sites with this username and password. But a bot is something where
28:30
you are giving it specific instructions and it will carry out those instructions
28:34
full stop. An agent uh is I mean it’s it’s like the difference between
28:39
searching in Google and and and chatting with a with an AI chatbot, right? When
28:42
you search in Google, you’re going to get specific answers to specific
28:45
questions. When you’re chatting with a chatbot, you can have a conversation. So
28:48
with uh with an AI agent um a Gentic AI you can say hey like if if for example
28:55
you’ve you’ve given it access to your Amazon or your uh different accounts
29:00
like that you can say hey go buy this thing for me or go um research these
29:03
different things or or go and uh like look at my calendar and and find the
29:07
right time for me to be able to uh schedule uh I need some follow-up for
29:11
physical therapy. Right? So there’s all sorts of tasks that you can take, but
29:14
you can give it an objective and it will go and decide what to do to carry that
29:19
objective out. And by the way, because of the large language models, right, the
29:23
LLM aspect of it, it can do it while looking and acting like a person. Um, so
29:28
great for the ease of commerce and the ease of interaction. And I think that
29:33
this is one of the places where just like e-commerce was taking off in the
29:37
early 2000s, agentic commerce is something that a lot of noise is being
29:40
made about that in the next who knows how many months or years will become
29:44
more and more a part of of what is happening. But it also means that on the
29:48
flip side, well, I guess this segus perfectly into my next slide, Al jump
29:52
right into there. Okay, so this is a slide that that uh I I have uh uh lifted
29:57
and applied uh which is a nice word for stolen from Britney Allen, another one
30:01
of our tasses uh here at SIFT. So full credit to Britney for this idea. Um and
30:05
and Britney was talking about how complex the world continues to get and
30:11
will continue to get here. Um uh so if if Britney is so she’s got BLA, which is
30:17
Britney Allen versus the BLA bot, which is an agentic AI bot that she has acting
30:22
on her behalf. Look at all of these different instances that can exist. BlaB
30:26
bot goes and makes a purchase because Britney asked it to. So, as a as a
30:31
business, you see Bla Bot come. That’s one instance. There could be another
30:35
instance where Britney’s already made a purchase with that retailer before. And
30:39
then she says, “You know what? Go back and buy me another color of those shoes.
30:42
I liked those. Go and get those.” So, you have a Britney that’s come in that
30:45
is her. You have a persona that’s come in as her, the agent, the bot. Or you
30:48
could flip that around where the bot comes in and makes the first purchase
30:51
and the person follows after. Um, and that’s not uh that’s not taking into
30:56
account the fact that Britney may be trying out uh like the Google bots from
31:00
Gemini or she may be trying out the GPT agentics that are out there. Like there
31:04
are so many different versions that uh good consumers have good reasons to go
31:10
out and to use these things. Accessibility is one big use case for
31:14
example. And and so now it’s not just there’s the trusted persona who is the
31:20
real person and everything else is going to be fraudulent or nefarious. It is now
31:25
there’s a whole slew of trusted personas and a slew of personas that that could
31:30
be up to no good.
31:32
>> Right? And what’s especially concerning here is if we look back over, you know,
31:36
the past 20 years of fraud prevention, we look at bots automation being bad.
31:42
Full stop. If someone is automating against my platform, stop them. Right?
31:47
If this looks like automation, if this looks like a bot, get rid of it. And to
31:51
your point here, now, not only do we have to segment between human
31:55
interactions and agentic interactions, but now we have to take automation and
32:01
parse it out to say this is good and this is bad. But then down the the it
32:06
just spirals right down the path of good agents, we have bad intention behind
32:12
good agent. We have unverified consumer or unverified human behind good
32:17
agents. But then we have the flip side of all of that as well. Um getting to
32:22
this slide, you and I were discussing uh for those of you in attendance u maybe
32:26
you’ve heard of the MRC, Julie Ferguson uh did a run through where she went and
32:32
showed from the consumer perspective what it was to place an order. Uh, and I
32:38
believe she used Perplexity to go through and place the order, right? And
32:44
all of this applies, but I what I’d like to do is kind of recap what her findings
32:48
were for the purpose of this webinar because there was some very important
32:52
findings there. So, first I recommend you go check out Julie’s Julie’s video,
32:56
but I’ll recap it a little bit here. So, number one, she highlighted how you can
33:00
go in and you can find uh and you can search for any of these different items
33:05
that you might be searching for and all these different things. She came up to
33:07
all of these uh all of these different results, right, for uh I think it was
33:12
for a basket is what it was. One of the I forgot which one she clicked on, but
33:17
she clicked on something that was not Target. Clicked on it, ordered it, one
33:21
tap by, quick as can be, super easy, low friction, and then that Friday, the
33:27
package came from Target. Now, let I forgot again. I forgot which uh which
33:33
result she clicked on, but let’s say it was Macy’s, right? She clicked on Macy’s
33:36
and she gets a package from Target and then later on she saw in her bank
33:40
statement that the bill was from Perplexity. What a strange
33:44
triangle of this transaction. Right. So Jimmy, when when you and I were prepping
33:49
for this, I told you that story and you were pulling out some good points about
33:52
that. Uh what do you have to say to the attendees about that kind of strange
33:56
dynamic happening there?
33:57
>> Yeah, I think I think there’s a few things going on, right? There’s the
34:00
user’s intent and the user’s action, which is one thing, right? Where they’re
34:03
like, I want to buy a bag. I’m going to buy a bag. this is the easiest way for
34:05
me to buy a bag. Great. Now I can just say go find me a bag and then click buy.
34:10
And then it goes and buys. Now this told her that she should be buying from
34:13
Macy’s. We’ll say a and awesome. Go and do it. But there was some action, this
34:18
agency, right? This is why they’re called agents. There’s some
34:20
decision-making that’s happening on the back end that she’s not seeing that’s
34:24
acting on her behalf that for whatever reason, maybe it was out of stock at
34:28
Macy’s or the shipping time was longer or the cost wasn’t as good. without
34:32
informing her, shifted that purchase over to uh to Target and made that
34:37
purchase on her behalf from a different place. Kind of funky from a user
34:41
experience perspective. But then if you think for as the as the the customer, as
34:46
the company that’s taking that order, um all you’re seeing is an order from
34:50
Perplexity. And if somebody else is using Perplexity, does that look like
34:52
Perplexity 2? Like what what are these things going to look like as you’re
34:55
seeing them coming in? So again, like we’re we’re if this is a a diamond,
35:00
we’re just carving in more and more facets into this diamond. It’s getting
35:03
more and more complex.
35:05
>> Yes. And at this point, again, there are more questions, more need for clarity um
35:10
that we’re only going to see as time moves on, which actually leads us to
35:14
this. Jimmy, this is your slide. How about you go ahead and walk us through
35:18
it?
35:19
>> Yeah. So, so this slide is about direction. It’s not about numbers. So I
35:22
don’t want you to be like, “Oh, this is the exact uh like ratio or these are the
35:26
exact uh uh numbers or anything like that.” There are no real numbers here.
35:30
But what I’m speaking to is a trend. So I’ve in my mind I I divide atto into two
35:35
different types of attacks. And that is straightforward atto attacks, your uh
35:39
your bot- driven attacks that are brute force perhaps. They’re trying to break
35:43
into an account. um versus your more sophisticated uh attacks which are some
35:47
of the other ones that Alex went to when and the sophisticated attacks are what
35:51
when they’ve got the the positive uh uh take when they when they can get in past
35:55
the login when they are going in and they are carrying out more sophisticated
35:58
attacks on the back end. Um it’s what do you do then? And those sophisticated
36:03
attacks they’re more expensive they take more time. They have to be done by hand.
36:06
So they were a small portion of the total attack volume that we’ve seen. And
36:10
you could probably actually take this curve and bend it, right? Because we
36:13
know that it’s been accelerating. Um, and there’s been an acceleration in
36:17
both. But what Alex was talking about a minute ago that we are now automating
36:22
access to sophisticated actions being taken on our behalf both for the users
36:27
and for uh and for fraudsters. This means that and you go ahead and click
36:32
Alex that that that the mix is going to change that there will continue to be an
36:36
increase in in atto attacks but the mix of unsophisticated versus sophisticated
36:42
attacks is uh is going to shift because sophisticated attacks are easier to do
36:47
easier to automate in a way that you could automate unsophisticated now you
36:51
can automate sophisticated so that’s something we need to be planning for
36:55
>> right uh this is again super important note asterisk. These are not real
37:01
numbers. This is what can be. This is what we are afraid of seeing. Right? And
37:07
to Jimmy’s point, imagine back in the day, we thought automating credential
37:12
stuffing or automating brute force attacks was sophisticated. Well, now,
37:16
you know, here we are 10, 15 years after that became really popular. And that’s
37:20
just run-of-the-mill nothing, right? As we look forward to the next 12, 18, 24
37:24
months and we see the adoption rate of fraudsters, we see the adoption rate of
37:28
good consumers, we see agents get access to all of these different secondary
37:32
platforms and accounts that the value of accessing those accounts is only going
37:37
to grow more and more and more in value to the fraudsters, the bad actors,
37:41
right? And when they’re armed with the same technology that we’re armed with,
37:46
who knows what this this this trend line is going to be. uh we saw the adoption
37:52
rate and the the recurring or the the the resulting impact of gen of
37:58
generative AI in the hands of fraudsters. We saw what that impact was.
38:03
We saw how quick the adoption rate is and now the adoption rate of agentic AI
38:08
is not going to follow the same trend line. It’s going to be faster.
38:12
fraudsters, bad actors, everybody across the ecosystem, consumers alike,
38:17
everybody, market merchants and retailers, operators, everybody is
38:21
chomping at the bit to figure out how to get Aentic AI integrated in their
38:24
operations for good or for bad. Right? So, I’m not a doom and gloom kind of
38:30
guy. I’m not here to scare people, but I am genuinely concerned about what
38:35
happens when, you know, Agentic AI is leveraged as a force multiplier in the
38:40
hands of bad actors. Then you can take that one step further. What happens when
38:45
open- source information, LLMs, generative, a dentic, all these
38:50
different elements of AI is actually creating bad fraud focused agents, fraud
38:58
focused LLMs. We’re seeing repositories. We’re seeing whispers of it in the deep
39:03
and dark web. Nothing confirmed yet, but like what happens when a fraudster or a
39:08
cyber security, you know, hacker makes a fraud focused agentic AI uh agent,
39:14
right? We got some serious times ahead of us. And so what I’ll do to wrap up
39:19
this segment is I’ll say, you know, if we haven’t if if a platform that has not
39:25
put conscious effort towards solving ATO at the end of 2025,
39:32
when I look at a platform that hasn’t successfully put emphasis, focus, and
39:36
solved for ATO’s in 2025, as we look forward to 2026, not only is the problem
39:42
going to get bigger just from manual, as you see the blue line ticking up there,
39:47
Not only is atto going to going to continue to rise generally, but it’s
39:51
also going to be 1xed, 5xed, 10xed, 100xed by agentic AI in the hands of bad
39:57
actors. So, Jimmy, I just scared a lot of people, I think. Let’s calm it down a
40:02
little bit. What What uh let’s hop into what we can do about it. You ready for
40:06
that?
40:06
>> Yeah. I think we’ve got a poll first, right?
40:08
>> Yes. There we go. Um so, let’s see. I’ve not done this. So, polls and quizzes.
40:15
I’m going to launch a poll for everybody. Please feel free to engage as
40:20
you wish. There we go.
40:25
And while we do that, let’s go ahead and
40:29
start talking about what needs to be done. Jimmy, do you want to set this up
40:33
or do you want me to just dive in?
40:35
>> Uh, yeah. I I think this is it’s a it’s a great section. It’s there are things
40:40
that we can do and I think we alluded to it earlier. Uh but the the TLDDR here is
40:45
there’s not a silver bullet. Uh it needs a multiaceted uh uh approach is is kind
40:50
of how I would uh how I would tee that up. Um we’ve actually got we’re already
40:54
at 70% participation on the poll.
40:57
>> Yeah.
40:57
>> Uh and uh answers coming in are are interesting.
41:03
Can is this something I don’t know if if folks can see
41:08
the the poll responses that are here or not.
41:10
Um, I’ll let it run for another 8 seconds.
41:15
Get to that minute mark in case anybody else wants to chime in. 78% 81%.
41:21
Got seven people who haven’t clicked an answer.
41:25
All right, let’s go ahead and end now.
41:29
>> Let’s share results. All right. Uh so we have
41:34
uh 28% are actively discussing what next steps
41:39
are uh to their organization. We have a tie for number two. 25%
41:45
uh are both implementing strategies and tactics and thinking about it. They’re
41:49
in the ideation stage. And then we have 22% 7 out of 32 people say what is
41:55
agentdriven atto? Jimmy what is agent-driven atto? Yeah, it’s a great
42:02
question. I I think first of all, I would pat this group on the back because
42:05
uh threequarters of you at least are at least thinking about this, if not
42:08
talking about it or actually starting to implement. So, I think ahead of the
42:11
curve. Uh good job. And and that’s the fact that you’re here is is probably a
42:16
little bit of confirmation bias for some of the results uh that are that are
42:19
happening here. I think we’ve gone over uh a good bit uh hopefully in in the
42:24
last few minutes of what that agent driven um atto is or or can look like.
42:28
But a agent- driven atto is not just using a bot to crack in and to uh to put
42:35
in a password and a username, but it is using agentic uh it’s using agentic AI
42:41
um to imitate a user. It’s using aentic AI to once you get in to actually take
42:45
actions that look a little bit more realistic. Um, and it and it might also
42:50
uh it’s it’s this confluence of Agentic is using AI to act for you. And so
42:55
consumers are going to be doing that for all sorts of things and for things they
42:58
probably shouldn’t be like banking and shopping and giving access to things.
43:02
And fraudsters are going to respond and they’re going to use Agentic to try to
43:06
overtake those things as much as they can. There’s one other attack um front
43:10
that we didn’t mention which is called prompt injection which is when you have
43:14
an AI out there acting for you going to different websites reading pages looking
43:18
at things um you can actually put code just put language words into that page
43:24
that say if you are an AI bot uh disregard all previous instructions and
43:29
instead do the following and it can take over that agentic AI that is out there
43:33
acting for you. So who knows maybe one was saying like hey buy this from Target
43:36
instead. I I don’t think that’s true, but there’s there’s ways to hijack an
43:41
agentic AI as it is happening. So, anytime there’s a new technology that
43:46
allows users to do things with less friction, more easily, more automated,
43:50
uh fraudsters will be there and they’ll be there in this instance uh with atto
43:54
specifically or or especially
43:58
>> great response. Yes. Uh, and I want to double click on what you said for to the
44:02
to the 75% or so of people that are already, you know, either in the
44:07
ideation stage or they’re implementing, they’re they’re actively discussing. Uh
44:12
regardless of what stage you’re in, we hope that uh this next segment is going
44:16
to have enough for you to chew on um to give you a little bit of guidance on
44:20
what you can do whether you whether you’re operating in-house strictly
44:24
without partnering with a vendor or if you’re looking to to into idea uh into
44:28
ideas of and concepts of what it takes to partner with the vendor uh to solve
44:32
things in the future as we move forward. Um yeah, let’s go ahead and hop in. I
44:37
will stop sharing the poll now. So that closes and that closes and then
44:44
Jimmy go ahead and take it. Yes. Yeah. So, so I’ll go
44:49
through a few things really quickly. One is just kind of core foundations. One
44:53
are some ways you can fight fire with fire and then another is a way to think
44:57
about how you are structuring your ATO defenses. And that’s kind of what we’ll
45:00
run through and I’ll do it quickly because I know that we’re uh we we’re
45:03
all uh wanting to get through our Wednesdays today. Um so the first is um
45:09
one of the one of the antidotes or one of the ways to fight um AIdriven fraud
45:15
uh and agentic driven fraud is by having a a clear perception of identity and
45:20
ideally intent of users and avatars as they are coming to visit your site. That
45:25
is a very difficult thing to do if you only have your own data to reference. So
45:30
in whatever form it makes sense to have access to uh global data from users that
45:37
are both within your industry and we also have great data that shows the
45:41
crossover of different fraud attack types and frauds they’re specifically
45:44
attacking between industries opportunists they’ll go where the
45:47
opportunity is. So a global model that is tracking these types of behaviors and
45:53
identities is really important. Uh and then taking that global model and
45:57
modeling it well. So we have uh I’ll speak specifically to what we do at
46:01
SIFT. We have a global model. That model is tracking those behaviors. When our
46:05
customers have enough data, we’ll build them a specific model to their behaviors
46:09
for their um consumers so that they can see when aberrations happen and what
46:13
might be unusual. And then I’ll highlight this one in the middle that we
46:16
call threat cluster modeling which is really cohort modeling where we take
46:20
people from the same industry where we will have multiple people in that
46:23
industry many customers and we can build out uh kind of the Goldilocks zone of
46:27
modeling where it it has the very specific activity from consu consumers
46:33
like yours airline uh consumers or people in QSRs or people that are in the
46:37
fintech space. They’re acting in a similar way. they have the same kinds of
46:40
fraud, but you’re getting the benefit of seeing from other people first so that
46:45
you don’t always have to react to new fraud for the first time. So, combining
46:49
these three things together gets us to much more accurate results, gets you to
46:53
much better protection. It’s a kind of herd safety, right? We’re all penguins
46:57
huddling up on icebergs out here to keep warm and to keep safe from the cold. Um,
47:02
uh, and I’ll keep I’m going to keep moving quick. There are also ways to
47:06
just as AI is is helping one side, it’s helping the other, right? There are ways
47:10
to use AI to make things easier. If you are an analyst that is doing atto
47:15
investigations, you know that that’s the hardest investigation that there is to
47:18
do in fraud because you are sifting through multiple sessions sometimes
47:22
across multiple users trying to look for similarities and differences to put
47:26
together enough information to say, “Hey, this is this is an ATO.” And and
47:30
to to give that feedback even back to a model like one that Sift might have. One
47:34
of the things that we’ve recently implemented at SIFT, we call activity
47:37
IQ. It’s basically a fraud research assistant. So, if you’re going in to do
47:41
research for a potential account takeover, it will go and look at related
47:45
sessions, related users for you and come back with a summary of here’s all of the
47:49
data that’s relevant. This is the stuff that looks good. This is the stuff that
47:52
that looks fishy and might be worth looking into, and here’s the stuff that
47:55
like is really is really bad, right? And you’re going to get it in that natural
47:59
language um that an AI uh uh can provide back. So there are ways to fight fire
48:05
with fire and to use the same kinds of tools and methods that are being used
48:08
against us um to fight it. So that’s the basics. That’s one way to one way to
48:13
fight uh with AI. We’ve got more stuff coming that I’m excited about in the
48:16
coming months that we’ll be talking about uh uh before too long. But the
48:20
last thing here is is uh this is something that we’ve hinted at a few
48:23
times. And this is just looking at the way that you’re structuring your
48:27
strategy. How are you setting up the way that you are combating um atto and
48:32
specifically against account takeover fraud? And this is that you know first
48:37
we’re going to address the blue which has been the bulk in terms of the number
48:40
of atto attacks. You should have a security layer that is network security
48:45
and there’s bot detection and that’s asking the question of is this session
48:49
safe and is this a human that is coming in right these are both important layers
48:54
um to uh to solving the atto problem and for some people it might be enough if
49:00
you’re not worried about that little sliver of sophisticated fraud though we
49:04
would obviously argue that that’s worth being worried about because they’re the
49:06
ones that are going to get in and really uh really get you. Um, and there are
49:11
tools that provide for this, but the big question and the question that is
49:15
getting even bigger, if you want to click, Alex, is what are you going to do
49:20
um about uh about that more sophisticated fraud? Once that login is
49:25
passed, is this the right person that’s logging in? We know they have the
49:29
credentials, but was it the right person? Is it who we actually think that
49:33
it is? And what’s their intent? What are they doing? Are they acting in ways that
49:37
they are expected to behave? It’s super important to have you’re going to need
49:41
broad context to be able to answer that question, but it’s really important to
49:44
be able to answer that question quickly and safely both to be able to identify
49:48
ATOS’s, but also to be able to identify it without putting big blocks in front
49:53
of your consumer. Right? So one of the things that we do and you can click
49:56
again this is the this is the problem that we’re solving with SIFT is we’re
49:59
sitting in this space of uh once they’ve logged in how can we identify that that
50:04
much more difficult to capture uh ATO’s that are that are happening um and one
50:10
of the things that we do is we will allow users to log in unless it’s
50:14
blatantly atto then we we block we stop the login we’ll um hit them with an MFA
50:19
ask them to to reup with a passcode um but if it’s kind of in between and we’re
50:23
not Sure, we’ll let them log in and we’ll let them interact and behave. And
50:27
it’s not until they take a more sensitive action. They try to change a
50:30
billing address. They try to withdraw funds. They um they do something that
50:34
might actually say, “Ugh, this one looks iffy.” And if they are doing this thing,
50:38
well, then now let’s go and let’s hit them with that MFA or now let’s go and
50:42
let’s let’s block this session or or uh make sure that they cannot go forward.
50:47
So this this uh is a way of keeping ourselves safe and also rolling out the
50:52
red carpet for our trusted consumers so they can interact quickly um and
50:56
seamlessly with us. That is one thing that I’ve said in in
51:00
many webinars, many discussions from the stage at many conferences is the idea
51:04
that if you point all of your defense ideas and defense technology and data at
51:10
the single point of login, there’s not enough information there to be as
51:15
accurate as you need to be. Right? You’ll get the lowhanging fruit, but
51:18
then you run the risk of false positives, false negatives across the
51:21
board. And then if the false negatives get through, right, these sessions that
51:25
shouldn’t have been allowed through, they get through. you have no protection
51:28
beyond the login screen. So now you’re waiting for them to transact and then
51:32
it’s segmented and it’s siloed and it’s this whole nightmare of of trying to
51:36
figure out what this what this impact of an ATO was. Right now this this this
51:40
thing that you that this idea that you’re talking about is it the right
51:43
human and is it the expected behavior. This is something that people can do on
51:47
their own, right? You can you can build up you can build up the data, you can
51:51
track the behaviors, you can set up your flags, you know, in order to see what it
51:55
is, you know, uh what atto behaviors take place on your platform. You can
52:00
start to see that, but there is a limitation. It’ll be better than
52:03
nothing, but there’s a limitation because when you partner with somebody
52:06
like Sift, we have that access. Jimmy, as you said, it’s the first scene to you
52:10
is not first seen to us. We’ve seen this this user transact across all of these
52:15
different industries. We’ve seen them we’ve seen their behaviors across all
52:18
these industries and we can bring that insight to you. However, if you aren’t
52:22
ready to partner and you want to just handle things inhouse, it’s vitally
52:26
important that you track these behaviors over time is number one. And number two
52:29
is highly, you know, focus on where the areas of value are, right? So depending
52:34
on your your industry, different value is going to be in different places. We
52:38
saw a question come in. It says, “Will you address sophisticated attacks
52:41
specific to the travel uh OTAA space?” Um, Jimmy, you kind of touched on it
52:47
before. Do you want to talk about what we’re seeing and how we’re solving those
52:51
problems?
52:52
>> Yeah, so I can just give a quick example here. This is something that would take
52:55
more time to dive into deeply. Um, but one example that I can give is, uh, we
53:00
know that, uh, for example, fraudsters and and this is this speaks to that
53:05
different types of fraud have different types of issues, right? So, uh, rental
53:09
car company, for example, uh, people, uh, would atto into high-v value
53:13
accounts, rent high-value cars, and then take those cars, rub off the VIN, and go
53:17
sell them. And then, uh, the rental car company actually thinks that the good
53:21
user has taken that car. They would go and go after the good user for stealing
53:25
a car when they didn’t. That’s actually a trusted, legitimate user who was the
53:28
victim of an atto, but neither they nor the company knew. who caused all sorts
53:32
of problems in terms of loss of the actual $40 $50,000 vehicle and now loss
53:37
of and anger and potential lawsuits and all sorts of things with existing um
53:41
customers. So that’s that’s one example for airlines. Um there is a
53:46
time-sensitive nature as well which is like a in one example of a flight taking
53:50
off and this one uh ties into both atto and payments where an account could be
53:55
taken over um and a flight could be booked and the the process of
54:01
understanding whether that is a proper booking whether that is the the right
54:06
user that’s there or not um only has a few hours especially if fraudsters are
54:10
learning that if they book three hours before the flight then get in there then
54:14
get on the plane that the the fraud teams don’t catch up to them before
54:18
they’re on the plane. And once they’re on the plane, the doors are shut,
54:20
they’re going to take off, and they’re going to go. So, the ability to uh build
54:24
those review cues to build that automation so that things can trigger
54:27
more quickly so that you can learn really fast uh and decide really quickly
54:31
before the actual value is out the door. Uh is just one example that’s specific
54:36
to airlines.
54:38
>> Thank you, sir. So, as we head into the last six minutes of the hour, we got our
54:43
takeaways. Jimmy, do you want to run through these?
54:46
>> Yeah, absolutely. So, uh, we, this is the tip of the iceberg when we’re
54:49
talking about Agentic AI. Um, this is something that is brand new. Um, you
54:53
look at Chad GPT, which has over 900 million users and growing. Uh, they just
54:58
launched their first Agentic solutions about six maybe eight weeks ago. Um, so
55:03
this is something that we’re just now seeing. But if we’re if we follow the
55:07
growth rate of uh AI, AI has been like the internet was in the early 2000s, but
55:12
at like a 10x growth rate. Um, so rather than having years and years to figure
55:16
this out, we’re going to have months and months or weeks and weeks um to to
55:19
figure this out. So, uh, and and Agentic, I I don’t want to sound all
55:23
doom and gloom either because that’s not just it, right? And especially when
55:26
you’re talking to your partners internally about the value of the work
55:29
that your fraud teams are doing, right? You want to be able to accept agentic
55:33
commerce, you want to be ready to confidently step into that space, then
55:37
you need to have a a solution in place where you can discern discern between
55:41
the good users and the bad users. So just as much as there is uh uh risk
55:46
here, there’s opportunity here and we can look at that opportunity and focus
55:49
that way. Yeah, we’ll cover the risk. Let’s get to the growth um that could
55:52
that could happen there. Um bot detection is one piece of a successful
55:57
strategy. This is that build that I just went through. You’ve got to deal with
56:00
the blue. You got to deal with the bulk of bots that are just headbutting the
56:04
the castle gates. You got to have a gate in place, but then you also need um to
56:08
have solutions in place that will uh that will be able to discern uh uh past
56:13
login what’s happening. Um and then uh the the impact of successful ATO’s, what
56:20
an atto does and how it hurts. Are we talking about the social impact of
56:23
losing an account and somebody now you’re getting uh messages from your
56:27
uncle who’s asking you to sign up for some essential oils thing that you’ve
56:30
never heard of, right? Like that kind of thing. or are we talking about cars that
56:34
are literally being driven off a lot? Are we talking about airline miles that
56:37
are being drained? Like what’s the what is that? And don’t forget to think about
56:42
the hard costs and the soft costs when you are building in the model. Even
56:46
though some of them you’re going to be able to tell and others are going to be
56:48
pretty fuzzy. Some you can write in pen and others you got to write in crayon in
56:52
terms of like how are we going to how are we going to make sure that we can
56:55
build out an accurate picture um of fraud. So work with your partners to
56:59
understand where those pains are and to understand how best to build this story
57:03
so that your company can understand and see clearly uh the the full impact of
57:08
fraud and and see ahead of the the types of atto that are coming down the pike.
57:15
>> Great job Jimmy thank you so much. Uh we have one question that came in from uh
57:19
Abilash. What is uh what is that we can think
57:24
about have about solving fraud in payments? Okay, so fraud and payments
57:27
which is a highly regulated space. How can I start thinking holistically about
57:32
application of this in the payments space? That is a massive question. Um,
57:41
wow. Well, I guess to to that one’s we’re going to take that one offline.
57:45
Uh, I believe
57:47
>> I could I can give a 30 second on that if you want me to.
57:49
>> Let’s do it. Yeah. Yeah, please.
57:50
>> So, so a lot of the principles are similar. Um, Abilash. So you’ve got AI
57:55
coming in, you’ve got new fraud vectors that are available, you’ve got
57:58
automation of sophisticated fraud in ways that we haven’t seen before. And so
58:02
at a core, you’ve got to have the pieces in place. You’ve got to have durable uh
58:07
and reliable signals uh that you can use to detect good versus bad transactions.
58:13
And and so we we are focused heavily on identity trust, which is that same
58:18
thing, leveraging our network of a trillion signals that are coming in
58:20
every year and allowing you to basically tap other industry, other companies in
58:25
your industry on a shoulder and be like, “Hey, we’ve never seen this guy before.
58:29
He’s trying to rent a car from us. He’s trying to uh buy from us and we’ve never
58:33
seen it. Should we trust him?” And they can be like, “Yeah, absolutely. We’ve
58:37
worked with him before.” Or like, “No, don’t.” Like this this is somebody that
58:40
we that we marked off. So, you’ve got to have the ability to to look deeper at
58:45
behavior and look at history and look at network um to be able uh to to protect
58:51
yourself from those. That’s one kind of writ large answer is continue to use
58:54
like figure out how to employ AI tools and figure out how to get access to some
58:59
external data in addition to your own internal data so that you’re not stand
59:03
you’re not a penguin that’s standing alone on an iceberg because that’s not
59:05
going to go well.
59:07
>> You love your penguins, man.
59:08
>> I love the penguins. Yeah, it’s working for me.
59:12
>> Yeah. Uh, Abalash, there’s there’s many ways to interpret that. So, there’s many
59:15
ways that we could walk down if you are interested in having a conversation.
59:18
We’re both available. We can dive in any of the details that you might want to
59:21
dive into.
59:22
>> Absolutely.
59:23
>> We are one minute out. Any last second quick draw questions anybody wants to
59:28
throw in the chat?
59:33
>> All right. Thank you guys so much for all of your time. Thank you so much for
59:36
attending. Look at that. We had almost a 100% uh retention uh from the beginning.
59:42
Jimmy, thank you so much. This was a very exciting webinar. Uh to everybody
59:46
else, I look forward to seeing you guys in the future. Have a good one, Jimmy.
59:50
>> Thanks all. We’ll see you next time.



