The world is changing rapidly. Automated, intelligent tools are more accessible than ever—to fraud teams and to fraudsters. Learn how to outsmart payment fraud by harnessing the power of automation without sacrificing transparency and control.

In this webinar, you’ll learn:

  • How you and your team can outsmart payment fraud
  • Get educated on how you and your team can use automation to protect your company from fraudulent activities and not lose control or transparency

Watch the On-Demand Webinar

Close

Thanks for submitting!

close

Video Transcript

0:01
Hi, good afternoon or good morning and welcome to our webinar automation and
0:07
payment fraud fighting fire with fire. My name is Mie Zondu, publisher of the
0:13
papers and I’m delighted to co-host this webinar with sift a leader in digital
0:18
trust and safety empowering companies of all sizes to unlock revenue without
0:24
risk. And it’s great to see so many of you tuning in today. Thank you so much
0:30
for joining. So what’s the story? Well, the world is changing rapidly and
0:35
automated intelligence tools are more accessible than ever to fraud teams and
0:42
to fraudsters. And to combat the ever evolving fraud economy, fraud teams need
0:47
to develop a strategy that leverages automated intelligence tools to stay one
0:52
step ahead of the fraudsters. And in this webinar, you will learn how
0:57
to outsmart payment fraud by harnessing the power of automation without
1:01
sacrificing transparency and control. And our speaker Kevin Lee will address
1:08
the ever evolving fraud economy, the state of automation, and how to fight
1:12
fire with fire. And before introducing Kevin Lee, I would like to start with
1:18
some quick notes regarding housekeeping. The discussion will take approximately
1:22
30 minutes and we will have 10 to 15 minutes for a Q&A at the end of the
1:27
webinar. And on the right side of your screen, you can see the chat panel which
1:31
includes a chat room and a Q&A widget. You can use that Q&A widget to ask
1:36
questions at any time throughout the presentation and we will take as many as
1:41
possible at the end of the discussion. And I also would like to point your
1:45
attention to a couple of valuable assets that we added to the handout section.
1:50
There is the just released Q1 2023 digital trust and safety index, the one
1:55
of Q4 last year and an interesting ebook on how to build resilient fraud and
2:00
management strategies. So do check out the the handout section. Um but for now
2:06
I would love to um introduce you to Kevin Lee. Hi Kevin.
2:12
>> Hello everybody. Good to see you.
2:14
>> I know it’s good morning for you u but very happy to see you. Um, let me
2:19
briefly introduce Kevin. Kevin Lee is VP digital trust and safety at SIFT where
2:25
he helps customers implement strategies that cross functionally align risk and
2:31
revenue programs. Prior to Sift, he has spent the last 14 years leading various
2:36
risk charge spam scams and trust and safety organizations at Facebook,
2:42
Square, and Google. And um Kevin and I, we um we met each other, what was it,
2:49
two weeks ago at MRC in Fagos,
2:52
>> which was again a blast. There were lots of people, but I was wondering, Kevin,
2:56
what did you and the SIFT team pick up? What what insights did you get from from
3:01
this event?
3:03
>> Yeah. Um well, good morning, good afternoon everybody. Great to to be here
3:07
on another webinar with the papers. um really uh we do webinars, you know,
3:13
often um but I really do look forward to getting together and congregating um in
3:19
person. Uh and a couple weeks ago in Las Vegas at the merchant risk council
3:24
conference um we were able to do just that. And so there were over I think
3:28
1500 attendees um whether they’re on the merchant side, marketplaces, solution
3:33
providers, issuers, banks, law enforcement. Um, and it was great to get
3:37
a chance to mingle and have really just spontaneous unplanned interactions. Uh,
3:43
but I’d say one of my kind of highlights that I look forward to each year at the
3:47
conference is going over the yearly fraud and payments survey. And so this
3:52
survey is sent out to thousands of merchants out there. Um, and it’s really
3:56
just to get feedback on the state of the industry. Um, and one particular stat
4:00
that is tracked year-over-year is how much time and resources are being spent
4:05
by fraud teams on either preventing fraud, improving the user experience, or
4:12
streamlining um kind of operations and being more efficient there. And so,
4:17
interestingly enough, a couple years ago, there was a big shift actually even
4:21
more so where the user the customer experience was more of a on top of mind
4:28
than uh let’s say even preventing fraud or kind of optimizing for um efficiency
4:33
and in automation. And over the last two years, there’s actually been a shift
4:38
back towards the top priority for fraud teams is actually now back to preventing
4:43
losses. Um and also what’s grown relatively significantly is that
4:50
is that essentially that focus on improving efficiency and because of more
4:55
budgetary constraints streamlining um the team and so there were some folks
4:59
that I I didn’t get a chance to even catch up with in person because of
5:03
budgetary constraints. So they opted to send some other folks on the team rather
5:06
than go themselves. And so certainly that was also a little bit of a topic at
5:10
MRC where you know not everybody can attend every single year um and people
5:15
are a bit more mindful of budgets as well and so a very timely topic when
5:18
we’re talking about automation and efficiency and so looking forward to
5:22
going over some of our findings.
5:25
>> Sure. And I’m I’m fine you will also address this this challenge for merchant
5:28
with with less budgets but still this push to prevent losses and how to
5:34
basically manage this this stretch in a way. So maybe you can tell a little bit.
5:38
I know quite a lot of people know but a bit about Sift, but it would be great if
5:42
you can tell a little bit before we before we kick off.
5:46
>> Sure. Um, essentially Sift, we are a trust and safety platform that helps
5:51
businesses protect themselves and their customers against various forms of
5:55
abuse. And so of course credit card fraud is very top of mind, but if you
5:59
can think about other areas of abuse like account takeover or different spam
6:03
or scams. Um many businesses there they are changing in the way that they serve
6:08
their customers. Some of you out there might be marketplaces. So you might have
6:11
buyers and sellers on your platform. Um if you’re in the on demand business or
6:16
food delivery business, let’s say, you might have drivers or other folks that
6:20
are kind of middlemen um in this equation as well. and part of that
6:24
ecosystem is uh growing and changing rapidly. And so in the next few slides
6:29
I’ll kind of go into kind of what that means.
6:33
>> But first want to go to a cold question here.
6:36
>> Yeah. I just wanted to say before we we kick off we really would like to ask a
6:41
question to you guys to the audience. Um because we were wondering when we will
6:46
talk about automation how much automation are you using in your fraud
6:50
program in your fraud stack? Is it none? Some is it fully automated or you’re not
6:57
sure? Uh please submit your answers. Um we’ll give you a couple of um 10 more
7:04
seconds for this. Then we will continue and we will address uh your answers on
7:08
this a bit later in our discussion. So thank you.
7:18
>> All right. So in terms of the agenda that uh Melisandre covered already,
7:22
definitely want to give you kind of an overview of the an update on the fraud
7:25
economy out there, the state of automation and really uh we are in a bit
7:29
of an arms race here. And so in doing some preparation for this this talk um
7:34
did some research and was able to get some screenshots of kind of what
7:38
frauders are actually talking about today and kind of what are their
7:40
capabilities and services and so wanted to cover some of that.
7:45
>> Cool.
7:46
>> All right. Um so really the first kind of area that I wanted to focus on was
7:51
the this concept of the fraud economy and the image that we’re looking at on
7:54
the the right hand side here is taken from CIS essentially data where we
8:00
service a bunch of different clients in a bunch of different verticals and
8:03
oftentimes people think that when it comes to fraud there might be just one
8:08
focus area that um a fraudster or um a hacker works in. Uh but the fact of the
8:14
matter is within our global network we’re actually able to map back the
8:18
relations between let’s say retail and fintech or on demand companies and
8:22
digital goods and the fact of the matter is it’s actually quite connected whether
8:26
it’s devices cards IPs emails phone numbers etc identities um really when it
8:33
comes to exploitation at this level it’s not just affecting one vertical and it’s
8:39
a silo really it is kind of broad and really a tangled web um of sorts and
8:46
kind of really to that effect really wanted to highlight when it comes to
8:50
this the fraud economy. People tend to think about it either in like like I
8:55
mentioned uh specific verticals or even potential specifically like abuse types.
9:00
So you might have content abuse on your site. Think of like ratings and reviews.
9:05
um a lot of dating sites. You might have uh people
9:09
illegitimate people interacting or attempting to interact um with with good
9:13
kind of customers on your platform, payment abuse and kind of all these
9:16
different flavors, whether it’s BNPL, promo abuse, credit card a um certainly
9:22
a lot of crypto um issues as well when it comes to transferring funds and and
9:27
purchasing funds and of course account takeover. So, I’d bet that the majority
9:31
of us out there when it comes to our phones, you probably have, I don’t know,
9:35
several hundred apps on there. And um I’m willing to bet most of those apps
9:39
that you have have some sort of option for a login and a password. And
9:44
certainly those um are quite popular as as targets as well.
9:49
And then even doing a bit more research um specifically for ANIA here. Um just
9:54
looking at things like credit card fraud. Um, I know Euro Vision’s coming
9:58
up in a couple months. Shout out to Ukraine who did very well last year. Um,
10:03
and really around when it comes to fishing and even FTX, uh, when it comes
10:09
to kind of the the crypto debacle over there. Um, originally I guess it was
10:14
reported that things were just imploding internally for really unethical kind of
10:19
behavior that uh, the CEO and the rather the seauite was uh, doing. but it also
10:24
happened to coincide with an outsider uh compromise of about $400 million um in
10:31
uh in a in a hack. And so really when it comes to the scale and the size of these
10:35
tax abuses, we have seen growing momentum in that regard.
10:41
Um in even in our own research, um specifically in our digital and safety
10:46
report, we’ve seen that there’s about a 27% increase in digital goods and
10:51
services fraud. Um and specifically there’s the biggest jump within BTOC or
10:56
business to consumer um companies that are selling these digital goods and
10:59
services and a lot of it is derived from more of these scaled or bot related
11:05
attacks and then we can see that the results
11:09
here. So these particular screenshots are from um different marketplaces that
11:14
are selling information um specifically um in these cases these are gift cards
11:18
that are for sale roughly for about 50% off. And it’s one thing and many of you
11:23
on the call today you might have you might be an omni channel retailer where
11:27
you have a physical presence and a digital presence. Now it’s one thing if
11:31
you have a thief or a fraudster and they’re they’re trying to exploit your
11:36
system one at a time. So maybe they’re purchasing one gift card or attempting
11:40
one fraudulent transaction. But certainly one theme that we’ve noticed
11:44
over the last few years is the tools, the scripts, the automation that
11:49
fraudsters have access to really we see a democratization of fraud here where
11:55
when it comes to the I’d say very advanced fraudsters and hackers out
12:00
there, they’re able to do some pretty dramatic things. But the entry- level
12:05
fraudsters as well are able to do an outsized impact because of the I’ll call
12:10
it power tools that they have at their disposal. Now,
12:15
um, and what that leads to is even more personal identifiable information uh,
12:19
for sale. And unfortunately, I’d say due to different data breaches, many of our
12:24
PII is compromised or is out there. And so, that really does leave us in a bit
12:29
of a challenge not only as consumers, but also as businesses knowing that
12:33
there’s this much information available, there are different services available
12:37
as well. What can we do to really protect ourselves, our customers, our
12:41
platforms against these various types of abuse?
12:44
And the fact of the matter is our teams are fighting more than just fraud. And
12:49
so I mentioned kind of things on the left hand side is that fraud economy
12:53
where yes we of course we had all these external threats to deal with but also
12:57
one common pain and challenge especially at MRC a few weeks ago that we were
13:01
talking about was around the different tools available and the siloed teams
13:05
that are also challenges for our fraud teams where really fraud tends to find
13:11
the cracks right within these different areas where if tools don’t talk to each
13:15
other or teams don’t talk to each other fraud can proliferate. And it’s really
13:19
up to essentially a single point of failure here when it comes to the fraud
13:22
team. Like I’d say we really are superheroes in that regard. Having to
13:26
connect all these dots and find those anomalies and really when it comes to
13:30
creating a mechanical advantage, different forms of automation, even
13:35
rules and scripts can help us kind of fight back to make sure that all these
13:39
things on the left hand side stay under control.
13:44
>> All right. So with that, I’ll pass it back to Melisand.
13:47
>> Yeah. things you talked about, you know, automation and the importance of that
13:52
and we we asked a bit earlier the level of automation that the audience applies
13:56
in their fraud stack. So, what what what do you expect? I mean, you talked with a
14:01
lot of merchants before we launched the results. What what would you expect?
14:04
Would it be none some fully automated or not sure? Not exactly. No.
14:11
>> Um I think there will be some automation in play. Uh hopefully for a lot of our
14:16
like digital first companies, you’ll need some automation kind of in play
14:20
there. Um and there might be some not sure because it’s uh the level
14:24
automation out there depending on the team you’re on uh sometimes can be a bit
14:28
fuzzy.
14:29
>> Okay. Well, let’s uh launch the results and see what the audience is mentioning.
14:34
So it’s none 8% some as you mentioned 75% fully automated a small part not
14:41
sure nine. So
14:44
>> all right to me I think that’s pretty much as
14:47
expected. The there is some I think one one theme that I’ll say that I really
14:53
want to impress upon uh the folks listening today is it’s not a binary
14:58
thing. So in terms of none and fully automated there’s a big spectrum in
15:04
between. And so I’ I’d say one focus or one challenge I’ve heard from a
15:10
lot of teams lately has been how do I do more with less and and part of that
15:15
comes down to automation even um Marcus Zuckerberg at Facebook uh said that you
15:21
know 2023 is meant to be the year of efficiency and so to me yes they’ve
15:27
mentioned layoffs and and things like that but it’s also around what can we do
15:31
from an efficiency standpoint and automation standpoint to make really the
15:35
best decision possible and be as as lean as possible. And um I certainly feel
15:40
that on kind of the fraud team side as well. So really my main goal for today
15:45
is hopefully the folks that have either none or some in that bucket, you can at
15:49
least increase that dial a little bit when it comes to being more efficient
15:53
and being more automated uh with your time and your team’s time.
15:59
>> Yeah. Thanks. All right. So, let’s talk a little bit
16:04
about automation for all. And really, of course, when we talk about it, many
16:09
people think automation is straight just computers. But, um, and that’s a a part
16:14
of kind of what we want to cover today. But there also is that sense of just
16:19
different policies and trainings and being efficient with our time and our
16:23
resources. And that I’d say that shouldn’t be excluded from our
16:27
conversation today. And so taking a step back when we think
16:32
about automation and how that’s changed over the years and the reason why I kind
16:36
of grabbed these particular screenshots is because if we think about let’s say
16:39
the automobile and maybe we had manual transmissions then we had automatic then
16:44
now we’re kind of getting into that fully self-driving car mode. And so
16:47
there’s been automation from that perspective. And even in the
16:51
audiovisisual world where back in the day we’d have our pointand-shoot
16:54
cameras, maybe we get some film developed and it takes a little bit of
16:57
time and then when we want to share them, we can share with our friends and
17:00
families, but there’s really only one copy or two copies. Then of course you
17:04
have like Polaroids and things like that.
17:08
Um, now with platforms like YouTube, like literally there are millions of
17:12
hours being uploaded onto YouTube every single day. Um, and this this guy
17:17
highlighted right here, uh, his name is Mr. Beast. Um, aka Jimmy Donaldelsson.
17:22
And, uh, he has currently, I think, 110 or 120 million subscribers on YouTube,
17:29
which puts him in like the top one or two spots here. And he uploaded a video
17:33
yesterday. Uh, and within a day, from a virality standpoint, he had 40 million
17:39
views looking at his content. uh which is mind-boggling to some extent, but
17:43
he’s able to essentially create this piece of content, upload it, and then
17:48
automatically kind of goes out to all of his subscribers. And the last kind of
17:53
photo I wanted to plug in here, this is something I used uh actually a couple
17:57
weeks ago going to Vegas. Um in the airport, there is a robot uh cafe. And
18:03
so this is located in terminal 3 of the San Francisco airport. If you want to
18:07
get a cup of coffee, buy a robot. Um, it will create one for you and it tastes
18:13
okay. Um, but the fact of the matter is automation is kind of all around this
18:19
and it comes up in uh the sense of AI as well. And I wouldn’t I’d be remiss if we
18:24
didn’t talk about chat uh GBT a little bit, but of course Microsoft purchased
18:29
this company um a couple months ago. what it seemed now it seems like a
18:34
bargain at $10 billion but certainly there is an AI race there where Facebook
18:39
and Google are also kind of investing pretty heavily into this AI front um and
18:45
looking back at the year 2022 generative AI funding was about 1.4 4
18:49
billion and I want to kind of differentiate generative AI funding is
18:53
really for AI that is creating new content like chat GPT um as opposed to
19:00
analytical AI which is basically data analysis models um so there’s a
19:04
difference on that front but certainly when it comes to investment from
19:08
different firms u we’re seeing that it should probably be well above 1.4
19:12
billion for the year 2023. So shifting a little bit more into kind
19:20
of our space, the fraud end. And so all those different advances in AI and
19:25
automation tend to or on the surface level. And this particular slide is
19:29
really actually to illustrate the dark web and actually how much information is
19:34
below the surface. Um whether it’s on forms like Telegram or other
19:37
marketplaces like Genesis. We’ll show you some some screenshots here of what
19:41
that looks like. But the fact of the matter is these tools and these models
19:44
and these systems that have been released to the public are now also
19:49
available from a fraud perspective. And so we see these same services. So I’m
19:55
thinking about bots, I’m thinking about um fishing as a service, uh different um
20:01
scripting companies. Now, what’s happening is these uh actors, if they
20:08
weren’t already trying to defraud you directly, they’re now actually creating
20:12
systems that they can sell um so other people uh can attempt to defraud you.
20:18
And so the the main takeaway from this slide is that when it comes to the
20:22
efficiency and the automation that is being deployed, it’s not only by a
20:27
select set of kind of really bad folks anymore. um it is democratized where
20:32
more people have access to these types of goods and services. Um and I think
20:37
that the these next three screenshots really were resonated with me in the
20:42
terms of like okay what is the severity of it and so the first screenshot on the
20:47
lefth hand side this person is selling different bots. So if you have to deal
20:52
with resellers for example or um you have certain promotions or deals going
20:56
out, this person is selling a script to essentially keep on scraping your site,
21:01
check for different services. Um even uh chat uh GPT accounts or for sale on the
21:07
dark web. Uh they’re going for there’s there’s a premier account for chat GPT.
21:12
Uh and the regular price is about $20 or $21. Um, this potential, this this
21:17
hacker or this person on the dark web marketplace is selling it for $6 a pop.
21:23
Um, and the last one I’ll focus on is around a essentially a developer for
21:28
hire and they’re willing to do things like uh create a checker for your site,
21:33
fix some possible scripts that you’re working on. And this is one of those
21:36
things that I find really interesting because now
21:41
if I equate to let’s say the gold rush in the US back in the 1800s where
21:46
certainly there was a lot of people that were opportunistic and looking for gold
21:50
uh but then there was also a whole other subset of entrepreneurs really that were
21:55
not interested in digging for gold. What they wanted to do was create the
21:58
pickaxes and sell blue jeans to all those other people that wanted to go
22:03
into the mountains and the mines and dig for gold, but the people that sold the
22:06
pickaxes made a ton of money. And the relative work that they had to do for it
22:12
was in my opinion lower. And we’re seeing a similar effect here where we
22:17
have developers selling their services for scripting, let’s say, not for the
22:22
good of mankind. It’s it’s really so much so for defrauding uh businesses out
22:28
there and these services like this screenshot was taken yesterday. Um and
22:32
so it’s live people are kind of searching and offering their services
22:36
um to the highest bidder to anybody that wants to take up the psycho contract
22:42
work. Um and the last thing I’ll add on that is given that we are in a economic
22:47
downturn or recession, people are entrepreneurial. They’re going to look
22:50
for ways to to make money. Um, and so I wouldn’t be surprised if more of these
22:54
services or these functions um, pop up as a result.
22:59
Um, and kind of the the last slide I’ll kind of mention on kind of chat GPT is
23:05
really around how good it can be. Granted, it’s just this is the latest
23:09
iteration. Um, when it comes to deep bakes and spoofing, um, that type of
23:14
technology has been around for the last few years, frankly. Um, and it’s been
23:19
okay. But kind of going back to our poll in in regards to how much automation do
23:24
you have or how efficient are you, the capabilities of these deep fakes and the
23:30
accuracy of these deep fakes is increasing. And so for I think about it
23:35
from a fraud perspective, that just makes our job that much tougher because
23:39
there is so much more gray area to deal with. And so being able to parse out
23:46
those good transactions versus bad transactions now becomes even more
23:49
difficult just because the bad looks more like the good. And I’d argue to
23:54
some extent there’s a lot of good actors out there that want more privacy. And so
23:58
they look they come from proxies, they come from different VPNs. Um and they’re
24:02
legitimate users, but they look more like potentially bad transactions just
24:08
because based on their activity. And so it really puts fraud teams um in a
24:13
challenging spot. And so with that kind of how do we fight fire with fire or how
24:19
do we level the playing field where I feel like from a tooling perspective
24:23
over the last certainly the last decade let’s say
24:27
fraud teams have from a tool straight tooling standpoint had an advantage. So
24:32
had access to either tools or teams whether it’s IT or engineering, data
24:37
science, maybe you work with a third-party vendor to deal with these
24:40
things. Um but now the I’d say the fraud community uh well the that kind of
24:47
hacker community is catching up and so kind of what can companies do to protect
24:52
themselves? Um, and I’ve shown this kind of layer cake before in in other
24:58
presentations and talks, but I still think it reigns um is very very
25:02
important. The areas that I want to focus on are specifically the live
25:07
machine learning and the rules like automation and optimization. Like even
25:11
on MRC um a couple weeks ago there was talk around hey can we completely
25:18
automate and I’m not talking about outsource where someone can uh basically
25:22
you have some offshore team doing manual review can we completely automate what
25:26
we do and c certainly some companies can do that um but when it comes to really
25:32
the vast majority of the population there’s always going to be some sort of
25:37
manual investigation so I’m not talking about review of transactions like live
25:43
like do we want to ship this order out or not. Most of the time that can be
25:46
automated but certainly to find those cracks in the system you need some sort
25:52
of an investigative tool or console to be able to do that type of review and
25:57
then look for those fraud rings. Uh really the name of the game today is not
26:01
about taking down one particular account or one particular transaction. It’s
26:05
really looking for those fraud rings and then taking them down in bulk in a in a
26:09
really automated or efficient manner. And so for the over the next few slides
26:13
here, I’ll kind of talk a little bit more about ML and AI. Uh but also um I
26:18
don’t want to forget about rules. Um really we can optimize those rules, but
26:22
um they do have a time and place with regards to to fighting fraud.
26:28
So really from an ML standpoint, the questions I would I would ask that you
26:33
ask either yourself or your team or your cross functional teams is how are we
26:38
using ML today and are we taking in different signals like behavior device
26:43
let’s say system or or account updates different linkages to different accounts
26:48
transactional information to create the most accurate prediction out there so we
26:52
can automate. Many companies I talk with today um are let’s say predominantly
26:57
have a rules engine which is okay. Um but when it
27:02
comes to a speed sophistication standpoint, if
27:06
we know that fraudsters are deploying these relatively larger sophisticated
27:09
attacks, what can we do to protect ourselves in that that way? And really
27:14
what I found is the most successful companies here are deploying machine
27:18
learning models first um kind of as a primary defense mechanism against these
27:23
new attacks that are popping up. Now that’s not to say that rules don’t
27:28
have their place and certainly when you do create rules they can number one of
27:33
course provide some short-term um relief dur especially during a fraud attack
27:39
where if somebody is coming from a particular IP or proxy or email domain
27:44
um it’s hopefully it’s quite easy to create a rule um to stop that. So
27:49
another kind of theme I’ve seen with regards to efficiency has been
27:55
and and really a change over the last few years. If your fraud team needs to
28:01
have an engineer make a rule or if you have to call, let’s say you use a third
28:06
party um provider, if you have to call them to make a change, oftentimes that
28:10
time and it’s key here can be too long. And so my challenge to you would be are
28:17
your systems able to operate relatively in real time where if you do
28:22
see a fire, if you do see an attack coming on board, can you deploy a rule
28:27
quickly and efficiently on your own without having to wait hours or days.
28:33
I’m not saying you shouldn’t get any uh sign off or kind of double check like is
28:37
this rule going to be correct? Um you for sure want it to get a second set of
28:41
eyes on that. But to be able to the ability to act quickly is key. Um and
28:47
also uh when the fire is done um oftentimes I feel like many teams forget
28:52
about this where the things to ask yourself or your team would be if I
28:57
create this rule now when should I turn it off or what is my customers tolerance
29:02
or what is my tolerance when it comes to insulting my customers with regards to
29:06
blocking their orders. And often times it’s easy to create a rule and then just
29:13
forget about it. But from a fraud perspective, if they see that they’re
29:18
getting blocked by a particular rule, you know, they just change their attack
29:21
vector. And then really all that you’re left with is a bunch of false positives
29:25
where obviously legitimate consumers if they get blocked, they may try again,
29:30
but oftentimes they may take their business to uh another company. And so
29:35
one thing I’d recommend thinking about as you let’s say look at your rule set
29:40
is when would I want to turn off this rule? And there may be rules that you
29:43
just want to leave permanently on where you know if someone makes a 2,000
29:48
transaction regardless of how safe it looks maybe you want a second set of
29:53
eyes on it which is totally fine. And the last bullet I’ll mention is around
29:57
bulk review. Um, as I mentioned earlier, the fraud rings that are hitting us
30:04
today aren’t individual instances anymore. And so having a tool in your
30:09
possession that can really take down fraud rings is I’d say table stakes at
30:16
the moment where otherwise we’re just playing a whack-a-ole game. Um, and if
30:21
this if our systems aren’t learning, um, if our models aren’t learning, if our
30:24
teams aren’t learning, we’re never going to be able to be in a more proactive
30:29
position. And so being able to take bulk reviews, being able to launch rules very
30:34
quickly, um, and also giving that also gives feedback to your models to then
30:40
hopefully learn in real time as well. And so really what I wanted to maybe
30:44
carve out as a a differentiator or something that is also changing is that
30:49
businesses that are leading with machine learning first, it’s not about
30:56
creating machine learning to create better rules at the end of the month. Um
31:00
that’s just not fast enough. Essentially really what I’m talking about is there
31:03
is a a fundamental shift where the ML leads first and then is it able to adapt
31:10
to new anomalies and then you’re going to have some business logic in there
31:14
where you want to have some rules. You’re going to have some fires that pop
31:17
up that you want to deploy a rule very quickly and of course be able to back
31:21
test those things as well. Um, just because I’ve been in some unfortunate
31:25
situations where we’re under attack, we think we know where the uh attack is
31:31
coming from. We make we launch a rule relatively quickly, but then we realize,
31:36
oh gez, there’s a lot of false positives as a result. And so then our customer
31:40
service lines begin to flood and it it’s it leaves us in a tough tough spot.
31:46
So, in summary here, uh, when I think about where we’re going and when it
31:50
comes to automation, um, I’m reminded by a quote that my my my friend’s dad used
31:55
to tell me growing up. Um, and he said, “Kevin, whatever you do, you need to
32:01
evolve or dinosaur.” Um, and the real the point of that is really when it
32:07
comes to automation or just the different challenges that we’re facing,
32:10
we have to evolve and we have to adapt. and it doesn’t feel comfortable
32:14
oftentimes like change is is is pretty hard sometimes. Um but we are in an
32:20
adversarial relationship with these fraudsters out there. The tools that
32:23
they’re bringing to the table, the functionalities that they are now
32:26
getting access to is is changing and we need to kind of evolve with that or risk
32:33
kind of exposing our our teams, our companies, our our consumers um to this
32:38
this potential threat. Um, other parting facts or kind of takeaways, I’d say look
32:44
for cheap non-engineering ways to optimize your current system. And so
32:48
when it comes to automation, yes, oftentimes it may require your IT team
32:52
or your engineering team, but there are other things you can do to create quick
32:56
wins for your teams or for your company. Um the other thing all is really my ask
33:02
of you. We know that from a fraud community uh those external kind of that
33:08
economy is certainly talking communicating gez they’re selling their
33:11
services to each other and and doing a pretty good job out of it. What are we
33:17
doing as a community to share data, talk to peers, whether it’s in person at
33:23
functions like MRC, I know today a lot of our folks are in the EU. Um there is
33:28
an MRC coming up in Barcelona as well in May. Um there are other forums like um
33:33
MPE uh merchant payments ecosystem as well um that I’d encourage you to take a
33:38
look at um to really grow our fraud community because then we can learn from
33:42
each other whether it’s from a data perspective and operations perspective
33:46
um to really um be more efficient and and and fight the good fight. Um we
33:51
talked about rules a little bit already in terms of kind of where they they go.
33:55
Um, and really from an ML perspective, um, it is table stakes at this point.
33:59
And what I mean by ML that adapts in real time and it’s not just for better
34:04
rule creation, um, that’s really where the shift is because time oftentimes is
34:09
against us because when it comes to different bots or scripts that are
34:12
hitting the system, unfortunately, um, it can hit like a title wave. And so we
34:17
need to have systems in line that can respond kind of in accordance with that
34:21
or kind of fight fire with fire, if you will. Uh but with that um wanted to
34:26
pause there, say thank you, open the floor to any potential questions. Um and
34:31
Melisander, I’ll uh pass it back to you.
34:34
>> Yeah. Well, thank you so much, Kevin, for for also for emphasizing the fact
34:39
that it’s now to time now is the time to step up the game and and also the
34:44
importance especially also in a time of economic downturn to start first with
34:49
optimizing your current systems. And if you um deploy machine learning, make
34:55
sure that it adapts in real time. Um so thanks also for the audience, but we
35:01
still have uh some questions and if you want to ask questions to Kevin, he would
35:05
be really happy to address them. So don’t be shy and do send in some
35:10
questions um if you have them. Um but let me start with some first questions
35:15
that we received from from the audience. Um a very simple one you refer to or
35:22
simple it’s not there’s never a simple question you refer to BOP B O P I S what
35:28
is that um
35:29
>> sure um apologies for the long acronym so BOP stands for buy online pick up and
35:35
store so in the EU there’s often terms like click and collect um which
35:40
basically where you purchase at at your your website and then instead of having
35:44
an item shipped to you just you know pick it up at the
35:48
Thank you so much. Was specifically popular in the p during the pandemic. It
35:53
was the big thing.
35:55
>> Um specifically, there’s a question um um
35:59
I’m speaking about API calls to work with our own propriety first party data
36:04
to better create new and more effective rules. Um,
36:11
I don’t know exactly what the question is, but are there any
36:17
im immediate plans to implement more API call capabilities or flexibility? It’s
36:22
basically the question.
36:24
>> Um, well, I I if you’re a a SIFT client, then u the short answer is yes. We’re
36:32
always building on API and different functionalities. But you know, I’d say
36:36
vast majority of the people if you are talking if whatever solution provider
36:40
you work with um I’d say the questions to ask them uh is certainly from an
36:46
automation kind of channel here is how frequently
36:51
are models updated. So there’s a difference between real-time learning
36:54
and real-time response. And so what real-time response I’ll say and maybe
36:59
this goes into like how to like work with a partner it’s around most
37:04
companies out there should be that should be table
37:10
stakes. What is kind of next level is around is the response it’s not just a
37:15
response saying you know you followed one rule or not but is the system
37:18
learning in real time as well because if you get hit by some specific anomaly and
37:24
the rule says accept all the time because it looks okay you don’t want you
37:28
I mean your rule should be secondary that po at that moment if it if the
37:32
system sees a flood of you know this type of behavior your you know models
37:37
should be able to learn in sub one second and then realize Hey, let’s flag
37:41
this for review or let’s block it or let’s at least um do something different
37:45
with regards to putting it through 3DS or you know 2FA or something like that.
37:50
Um are your models learning like that in real time? Um and of course there is
37:54
that aspect of using ML to create better rules like
37:59
that’s more like data analysis um which is important um but that can take a week
38:06
a month um or longer you have to you of course can learn from chargebacks too um
38:11
but the the time horizon or the runway is just too long um from a fraud
38:16
perspective and so really shifting it more towards are my models learning in
38:21
real time whether it’s from my engineering team or the third party I’m
38:24
working with. That should be the expectation going forward.
38:28
>> Thank you, Kevin. There’s another question about the capabilities of Sift.
38:33
Does Sift have the capability to verify bank account of uh suppliers or
38:38
customers?
38:40
>> Um I mean that’s a product question. The short answer is no, we don’t do that. Um
38:45
I’d actually if you’re like we work with a lot of fintexs that that want that
38:48
capability, I’d recommend a company like Plaid. Um so they they are very good
38:53
from the bank account side um in terms of verifying um balances um the type of
38:59
account is it a checking account a savings account whatever um companies
39:04
like plaid I you know uh recommend for that type of service if you’re looking
39:08
for that solution
39:10
>> okay um what is the most recent data about the average chargeback rate and
39:16
the fraudulent chargeback rate on on e-commerce businesses
39:20
>> sorry say that one more It’s more about first party abuse like
39:23
what is the most recent data about the average chargeback rate and the
39:27
fraudulent chargeback rate on e-commerce businesses?
39:31
>> Yeah. So first party misuse like also known as friendly fraud. This is uh I’ll
39:36
call it a sticky wicket in terms of being able to kind of digest and
39:40
determine like how big of an issue is it. The short answer is that it’s going
39:46
to depend. Um, and one of those big dependencies is around your business
39:50
model. And so, if you are a subscription-based business, for
39:54
example, or a a a gaming platform or a business, you’re definitely much more
39:59
prone or susceptible to first-party misuse. Um and really the main well the
40:05
good news is uh from a win rate perspective um your win rate should be
40:10
um quite high just because assuming you have your the education up front from a
40:15
user standpoint of this is how often you’re charged this is how it happens
40:20
this is the frequency um as long as you have that presented um and you have I
40:26
know compelling evidence um 3.0 is coming out next month. Um there should
40:30
be some good avenues for you to to win those chargebacks. Um but if you are um
40:38
in the e-commerce business dealing with let’s say physical goods, there
40:42
certainly is first party misuse. But um I’d still say that the prominent um I
40:48
I’ll call it traditional payment fraud is the the most prominent kind of u type
40:55
of use so far. First part of me assumes there’s still some especially during the
40:59
pandemic and if the kind of economic recession continues there might be
41:05
refund fraud other types of policy abuse um some first party misuse as well um
41:11
that can happen but I’d still say by and large for those types of businesses
41:15
businesses or those verticals um the the dominant area is still traditional
41:20
payment fraud.
41:22
>> Thanks you. Thanks Kevin. Um for this traditional payments fraud, there is a a
41:27
a question from the audience that this is a company that is currently using
41:32
rule bas a rule-based system and it it’s quite a long road for them before full
41:38
automation or some automation. What are the cheaper options to optimize their
41:43
current rule-based system?
41:45
>> Sure. Um so the thing I al I always used to do when I had I had my own rules
41:52
engine as well. Um, ML was still kind of the the primary defense, but rules were
41:58
a good backs stopper, kind of the the last defense, if you will. Um, number
42:02
one, and I I hated doing this and my team hated doing this, but it’s around
42:07
quality control and like auditing the rules of like like some at some point we
42:12
had like over a hundred different rules in place
42:16
and like it was dumb just because we we had
42:20
people create a rule and it was like a year or two old and that person like
42:23
left the team. They didn’t do a very good job of documenting it. I didn’t do
42:26
a good job as a manager in terms of like forcing that documentation where it’s
42:30
like what is this rule for I don’t even remember that fraud ring or whatever and
42:35
so we take it out um and because all that’s left is false positives and
42:40
you’re essentially insulting a bunch of customers that didn’t know like that
42:44
just want to purchase your product. And so number one, um it is leg work, but
42:50
auditing your rules, thinking about, hey, what would it take to turn off this
42:55
rule? And of course, you can only really turn it off if you’re depending more on
42:59
an MLbased system. Like you’re not going to hire a bunch of people to do this
43:02
stuff. Like we’re moving away from that piece, of course. Um but knowing that
43:07
there is that transition kind of in play and that’s sounds like your long-term
43:11
goal to invest more in in ML. Um it number one I’d say audit your rules.
43:17
Number two um there are some things that you can do with your team to streamline
43:21
things. So maybe you have rules in place and that’s your primary and that’s okay
43:25
for now. I I’d say it should change pretty quickly though. Um do you have
43:30
anybody somewhat technical on the team to do different queries of your data to
43:35
take down fraud rings? And so you’re still living in the rules world, but if
43:39
you have someone on your team or a cross functional team that is able to do
43:43
different queries on IPs, devices, emails, other linkages, that can be a
43:49
superpower for your team as well where uh you can essentially take down those
43:53
fraud rings because essentially what we’re dealing with is
43:57
not just individual attacks like there are like to put it simply 99 plus% of
44:04
the people out there are legitimate. They want to use your products. They
44:06
want to engage on your platform. We should let them do that. There is that
44:10
sub 1% of the population that is trying to do a disproportionate amount of
44:15
damage. And those that that 1% is the one we need to watch out for, right? And
44:19
so having the ability to do different searches in your own database to say,
44:25
“Hey, we found a particular signal that is linked to a bunch of bad accounts.”
44:30
Take that down immediately. Create a rule. Even better, the system should
44:36
learn from the accounts that you took down and then update the models. So any
44:39
future occurrences like that will automatically be taken down.
44:45
>> Yeah, thank you so much Kevin for this elaborate answer on the on the question.
44:50
Um do you see that AI um is reducing
44:56
false positives? That’s a common common uh challenge for
45:01
>> Oh yeah. Um,
45:03
>> and how does it work?
45:04
>> I’d say full full on like yes, full stop like AI, it needs to be trained and
45:10
controlled as well to some extent. Um, but with regards to removing false
45:16
positives, it absolutely is kind of when deployed correctly. And the reason why
45:22
is to what I mentioned earlier where if you want a rule then from a fraud
45:27
perspective whether it’s a change IPs change devices change um email domains
45:32
it’s so cheap at this point to do that from a fraudster perspective that um you
45:39
know they can just find it it’s just a whack-a-ole game where you have to put
45:41
in another IP address another email domain like it’s just endless. Um, and
45:46
then from a legitimate consumer behavior, like they probably only have
45:49
one device. They have their email is their email or their phone number is
45:52
their phone number. You can’t blacklist that. Like if you do, then you’re just
45:56
turning away good business. And so being less reliant on rules in that regard um
46:01
can be helpful. And then from an automation kind of an ML perspective
46:06
when it comes to these these models depending on kind of the types you’re
46:10
working with they shouldn’t be just looking at just device or just IP or
46:15
just um um email it should be a lot of different factors not just at the
46:21
transaction point um but the entire user journey when it talks when we talk about
46:25
logging in um we know for example um users that uh click or tick the box of
46:32
like send me your marketing emails or your your newsletters. Those have
46:36
significantly less fraud than consumers that um don’t click that um that button.
46:42
And so, hey, at the end of the day, let’s say I’m a consumer. I’m buying an
46:46
iPhone next day delivery or something like that. So, pretty risky. But if I
46:51
check that box that says send me marketing materials, I am inherently
46:55
less risky than a fraudster. Like fraudsters typically don’t want to
46:58
subscribe to those emails. uh so like an iPhone mix day delivery as
47:06
well but if they don’t check that box then um they should maybe have a higher
47:10
uh probability of fraud and so those are things that you can do that may not be
47:14
apparent to you on the outset but from an ML model if it’s looking at that
47:19
signal will automatically realize okay there is three times less fraud if this
47:25
box isn’t ticked or is ticked.
47:27
>> Yeah. Yeah. Makes sense. And um Kevin, do you see an increasing trend of
47:34
frosters getting through the transactions even though they are 3DS
47:40
enforced?
47:42
>> Uh the short answer is yes. Um 3DS uh I mean predominantly came through really
47:48
uh in a big way in the last year and a half or two. Um and it has done a good
47:54
job to some extent of reducing fraud um specifically in the uh AMIA region. Um
48:01
but fraud finds a way um when it comes to different thresholds and I mean 3DS
48:08
is by and large a rulesbased system. If it’s above you know 15 pounds or if it’s
48:14
um I I think it is
48:17
>> it is a rulesbased approach. it is a hammer approach and you might not need a
48:22
hammer every time is my main point. And so there already are um ways to kind of
48:27
circumvent 3DS. Granted, it’s not super popular yet, but I mean given the
48:33
evolution of how things are progressing on the dark web or these different
48:38
marketplaces, um unfortunately it’ll be become easier and easier in mass. Um,
48:45
and again, what you’re left with is a bunch of either false positives or just
48:49
friction from a consumer perspective that um, many I’d say many consumers are
48:54
looking for what’s fast, easy, and safe.
48:58
>> Yeah. I’ll go to another question that was
49:01
basically the same question that I had when you talked about, you know, you
49:04
need to take down the entire ring and not just take one out of it. And the
49:09
question is, you mentioned that fraud teams must have in the investigation
49:13
skills to not just stop an isolated transaction, but to take down a fraud
49:18
ring. And in your opinion, what are the best methods or techniques that fraud
49:22
teams can use to perform these types of investigations? And would open-source
49:27
intelligence like OST be an effective approach to uncovering
49:33
and disrupting fraud rings? So, what is your take on that?
49:38
um let’s say two or three answers to that one. So using different models and
49:44
whether they’re open source or not to detect this stuff is
49:49
>> the tool to kind of at least um uncover what we think is a fraud ring. Um I
49:56
think we’re still a ways out from being able to use that from a fraud team
49:59
perspective. um unless you have your own engineering team like that’s it’s
50:03
certainly possible but by and large I think when it comes to identifying th
50:08
those fraud rings number one and I see this let’s say just hiring a fraud
50:14
analyst for the team five years ago maybe SQL skills were was a nice to have
50:20
but more and more with the job wrecks I see out at the moment SQL
50:25
is almost mandatory and so being able to be a little bit more self-suff efficient
50:31
dive into your own data um and be able to query your data in a lot of different
50:36
ways um is very very powerful. So when we talk about being efficient or lean as
50:41
a team, um when you do think about your own team in your operations side or your
50:45
your fraud team, I would say do you have that skill set from a divers
50:49
diversification standpoint, you’re always going to need some like it’s
50:53
manual review and maybe it’s case by case analysis, but having that I’ll call
50:58
it spidey sense to connect those dots that you’re seeing like no no this is
51:01
not just one node. There’s a really larger kind of ring out here. Being able
51:07
to detect that is a skill set in itself, but also having the technical ability
51:13
via SQL, um even Looker or Tableau, like there’s other tools you can use to make
51:17
it a little bit easier. Um Sift has a console to to really um empower any ops
51:22
team to do it. So you don’t have to include your engineering team. Um, but
51:26
that’s kind of one superpower or tool or or um attribute if you’re looking at a a
51:33
job description or looking to hire for your team that I recommend um giving a
51:39
bit more thought to. Like I’ I’d encourage you to invest in it.
51:43
>> Yeah. Kevin, um there’s room for one more question. And for the audience,
51:48
questions that we do not have time to include in this Q&A session, um the team
51:52
will get back to you um in writing. Um so last question is thank you. Um no my
51:59
question is in terms of autom automatization and secure and
52:03
optimization and security. What do you think of switching to blockchain
52:08
technology completely while we are talking about payments and fraud? Is it
52:13
be possible at the near future um to use those blockchain segments as
52:19
interoperability smart contracts etc. Is that something that you’ve at SIFT been?
52:26
>> Yeah. So, I mean at SIF we don’t do blockchain, but I mean I do read up on
52:31
it quite a bit. I I chuckle there a little bit because in the US I know
52:35
right now US uh even in um the AMIA there’s like credit Swiss and just a
52:41
banking kurfuffle going on at the moment. Um and
52:46
with that bank run there might be some pressure to be like oh my god like
52:51
traditional banks they’re failing we should move to more like blockchain and
52:55
crypto like blockchain itself is the technology crypto is kind of like kind
52:58
of sits on it with with regards to a use case but
53:02
longer term yes there absolutely is an application for blockchain there I don’t
53:08
think we’re close to it yet it’s still several several years out we’re in that
53:12
oh I forget what that curve is called, but when it comes to like early
53:15
adopters, it goes mainstream and then it gets kind of like everybody has it.
53:20
We’re on that growth curve or that trajectory. When it comes to like using
53:25
ML or AI for fraud detection, we are in the later stages of the game now. Like
53:29
everybody should have some form of that today. Um or else you’re just a lagard
53:34
or too far behind. when it comes to blockchain and that application, I still
53:39
think we’re in the early part of that ball game where we’re still trying to
53:43
see what sticks, frankly, and you might have some different um hiccups along the
53:48
way. Um but we’re still very early on in that game and it’s not mature enough to
53:55
really put too many eggs in that basket yet.
53:58
>> Okay. Well, thank you Kevin and again thank you so much for um taking all the
54:04
questions and thanks for the audience to um thanks for the audience to engage
54:08
with Kevin and with us um and of course for your time. What we will do, we will
54:13
send you a link to the webcast shortly and we will cut back to questions that
54:18
we did not have time to include in this Q&A session. And for now, I wish you all
54:23
very good rest of the day and we hope to see you in the next webinar with sift.
54:28
Thank you so much and uh have a great rest of the day. Thanks.