This webinar covers how to decode dispute trends, along with actionable strategies to fight rising chargebacks and first-party fraud in 2025. You’ll also get a broad view into new fraud data and unique consumer insights.
Watch the webinar to learn:
- Market-wide chargeback performance trends and their implications: Understand how increasing dispute rates impact your business.
- Key consumer insights and emerging patterns: Learn about the reasons behind consumer disputes, including the rise in first-party fraud.
- Actionable strategies for the most impacted industries: Discover which sectors are most susceptible to chargebacks and how this impacts prevention strategies.
- Utilizing AI and automation: Leverage AI-powered solutions to accurately detect upstream fraud patterns and automate dispute management processes.
- Proactive measures and considerations for 2025: Implement best practices for dispute management and use comprehensive fraud management strategies to protect revenue.
Watch the On-Demand Webinar
Video Transcript
0:00
Today we’re going to be discussing the findings of the 20ou of the Q4 2024
0:04
digital index report uh which was centered around chargebacks, chargebacks
0:09
and disputes. So first let’s go ahead and get into introductions. I am very
0:15
honored to be joined by my buddy Luis from Coinbase. Luis, go ahead and
0:19
introduce yourself.
0:21
>> Yeah, thank you so much Alex. So my name is Luis. I work at Coinbase. I’m a
0:26
payments risk analytics manager for the cards and mobile payments team and also
0:32
other functions especially in terms of deposits.
0:36
>> And I am Alexander Hall. I am a trust and safety architect at Syft. I’ve got
0:41
17 years of fraud related experience and uh prior to joining I operated as an
0:46
independent consultant helping organizations across the marketplace
0:50
develop holistic fraud strategies. All right, diving into the agenda. We’re
0:55
going to go ahead and cover uh there are going to be three sessions within this
0:59
webinar. First, we’re going to go over the findings of the Q4 2024 report. Uh
1:04
that’s going to go everywhere from global down to industry and then into
1:07
platform specific uh items. Following that, we’re going to go ahead and share
1:12
our consumer insights that we were able to glean through our report. Uh and from
1:17
that, we’re going to be able to start talking about emerging trends and
1:20
emerging patterns, uh both fraud related and through the chargeback data. And
1:24
then following that, we’re going to get into the actionable insight that you can
1:27
fold into your strategies uh today and into uh 2025 and hopefully into the
1:33
future. Let’s make it be relevant for as long as we can. All right, with that,
1:38
we’re going to hop into the global findings. So, the four items that stuck
1:42
out to me were the fact that uh we’ve seen a tremendous increase in
1:49
chargebacks over the last several years. And that growth is continuing well into
1:54
2025. We saw a 19% increase in chargeback rates overall, which accounts
1:59
for all three categories, merchant error, true fraud, and then first party
2:03
fraud. Now, in addition to that, we saw the average value increase from $235
2:10
uh557 up to $374
2:14
and a penny in Q1 of 2024. Now, in addition to all of that, we’re
2:20
seeing a tremendous growth in specific industries. So, Lewis, when you hear
2:24
this information, uh you know, what comes to your mind? Are there any points
2:28
that you would like to raise uh relative to the to the global findings here?
2:34
Yeah. Um it makes sense to what we see on our side as well. So for example, we
2:39
saw uh average increase in terms of disputes on our side. Not necessarily
2:45
that much as in almost 50% of the increase, but we do see increases on our
2:50
side as well. Of course it depends on on moments and specific trends that you are
2:55
seeing but that’s a common pattern ac across the industry.
3:00
Also in terms of the categories from time to time we see uh some shift from
3:07
one uh category to another but also it increases depending on market market
3:13
conditions especially on our business that Coinbase operates. Crypto is really
3:18
volatile and sometimes we might see more true fraud or first party fraud
3:23
depending on how the market’s going.
3:27
>> Yeah, that makes a lot of sense. What do you think drives aside from market
3:31
performance? I want to hear what your thoughts are. What what does a platform
3:34
do that might drive uh a disparity or contrasting performance between
3:39
different chargeback types? So, what might a platform do that would trigger
3:43
fraudster or dishonest, you know, consumers participating in first-party
3:47
fraud from uh I’m sorry, what do you think a platform could do or might do
3:54
that would move their chargeback rates from being primarily true fraud into
3:59
being friendly fraud? If we were to isolate it down to a platform, what what
4:03
do you think would cause that shift? One of the things that it’s possible to
4:08
do is for you to to audit for example the merchant descriptions that you have
4:14
uh for your business. Sometimes it might be really old and you didn’t check and
4:20
the name that’s been built for the your customers does not reflect uh what the
4:25
current name of your business is. So for example, in the past we had well for
4:30
Coinbase instead of the full name Coinbase or Coinbase.com we had just CB
4:35
that was not informative for the customers. So they might dispute the
4:39
transaction because they not recognize that. But it was really uh some crypto
4:44
that they bought in the past but they didn’t remember like from what they did
4:48
one month ago. So that’s one of the things that’s possible to do to audit
4:53
and check. So this is a really simple check that can be done. uh and might
4:58
help you decrease your your chargeback rates.
5:03
>> Diving into uh the different types of chargebacks, I’d like to hear from you.
5:08
Speaking about from like a crypto perspective, what kind of methods result
5:13
in uh different types of of fraud? So, you just said one is important is is
5:19
your merchant, you know, listing, the way that the information is listed, and
5:22
that might lead into what we would categorize as friendly fraud. uh what
5:26
what do you think is the main leader for for true fraud?
5:32
>> Yeah, so it depends on the controls that you have on on your side on your
5:37
merchant. For true fraud, u having controls in terms of how the user can
5:43
access their account. Do they have two factor authentication?
5:47
do they have to perform some sort of verification on their card if it has
5:53
been inactive for some period of time. So in this sense I would increase the
5:59
controls in terms of what are uh the policies that are in place so that we
6:05
can safeguard our customers instead of doing uh a different audit as I
6:10
mentioned before.
6:12
>> Okay, makes sense. So let’s move on and really dive into
6:17
what what uh what we found with regard to first party fraud. Right? As you see
6:22
represented on the screen, we see that different age groups are participating
6:25
uh in first party fraud more willingly than others. And then of course to
6:30
report that during the poll is is very is very uh interesting at least to me.
6:35
So to highlight uh we see that Gen Z uh in an overwhelming number is willing to
6:40
participate and report that they participated uh in first party fraud,
6:45
right? And I think that that’s very interesting. Um especially when you
6:49
compare it against the baby boomers, right? The the 6% down there, right? Uh
6:54
in addition to what we see on the on the the graph or the um the graphic, the
6:59
quote that really grabbed me is that a quarter of consumers admitted to first
7:03
party fraud. So overall 25% right around there uh admitted to first party fraud
7:10
and I think that’s that’s that’s really a shocking metric to consider. Right. So
7:16
during our conversations you mentioned that friendly fraud is the most
7:19
demanding chargeback category uh in your in your work with crypto. Can you dive
7:23
into that for us?
7:25
>> Yes. So for example crypto as I mentioned is really volatile. So one day
7:31
it might be uh increasing uh 10% but then on the other week it might be on
7:37
the opposite direction. And that was something that happened in the past that
7:41
users in combination with those market conditions. They had bought crypto for
7:47
example at $100. They saw it increase but later it decreased before the value
7:53
that they they bought it. And they found one opportunity here to dispute those
7:58
transactions. and at the same time sending that crypto to other addresses
8:03
to other wallets that they had so that they could keep the money and also get
8:08
the money back from from the issuer of their card.
8:12
This was one trend that was u predominant during layoffs that we had
8:19
across the industry. So people had lost their jobs and were needing more money
8:25
and that was one of the strategies that they found to defraud us and get the
8:29
money back. Of course if you look into data points you can see why that’s
8:36
happening and you can uh represent those chargebacks. Uh, one of the signals that
8:42
you can use is for example is this transaction that’s being
8:47
disputed from the same device that it was used in the past 12 months. You can
8:53
compare those and see that it’s the same user that is doing both transactions. So
8:58
there’s not a lot of signals to that would make sure that that’s a really
9:03
fraudulent transaction. Of course, you can also use the IP address or any
9:09
livveness checks uh like a face match from the user so that you confirm that
9:14
the real identity. So those are some of the solutions that we implemented on our
9:18
side so that we can mitigate those risks as well.
9:22
>> That makes sense. Uh you also you you mentioned uh device intelligence and
9:27
step-up verifications. uh when it comes to first-party fraud um
9:32
let’s dive into a little bit about how multiffactor authentication OTPs all
9:37
these step-up verifications right biometric checks livveness checks and
9:41
all these different things let’s talk about why it’s so important um to
9:45
identify to use those data sets in order to identify evidence of true fraud um
9:52
and then why it’s so important to identify evidence of first party fraud
9:56
and kind of where that difference lies So different forms of authentication
10:03
might be used by different groups. So at Coinbase we enforced to use uh two
10:08
factor factor authentication. It could be SMS
10:13
OTP or any other means that we support. But we can see that for example more
10:20
advanced users will prefer uh OTP instead of SMS. So that’s one way that
10:26
you can categorize your users uh not only by being more trusted or more risk
10:34
or riskier but also by the authentication methods that they are
10:38
using. You can create clusters and have different profiles for each of them so
10:43
that you can know what is something that is common or not for that specific uh
10:50
age group combined with that category of authentication method and create
10:56
different anomalies anomaly profiles. Speaking of anomalies, uh let’s hop off
11:03
of crypto and into the intersection of Gen Z and clothing because there is a
11:09
trend that has been identified. I think you’re the one who who brought it to my
11:12
attention. Um where Gen Z is known for uh going online and ordering multiple
11:19
shirt sizes, we’ll say uh from a clothing retailer. They’ll order medium
11:24
and large. They’ll check the fit and then they’ll send the one back now or
11:28
the one that doesn’t fit, they’ll go ahead and send that back. Now, of
11:31
course, it’s not fraud, but it also is a form of policy abuse and it’s it’s
11:38
definitely has a negative impact on the business. And so, I feel that what’s
11:41
interesting about that is um there’s a clear you you mentioned anomalies.
11:45
There’s a clear anomalous uh data point to reference there for all of us, you
11:49
know, for all of the attendees who are who are, you know, selling clothing,
11:53
right? If we see orders where they’re ordering multiple of the same item that
11:56
are different sizes, that might be a model that or that might be a data point
12:00
that they could reference in their models in order to to see it happen in
12:03
real time and catch it uh in the moment. Now, if we do catch it that way, what
12:09
what might be a recommendation for them? Uh you know, how would they approach
12:13
solving for that type of method? What would what would you suggest?
12:18
Yeah, I just want to highlight that that will be one of the topics that we will
12:22
explore a lot during this webinar to not analyze a data point by itself but in
12:28
the context that it is. So the user is not filing a chargeback or a dispute for
12:34
those transactions but it’s definitely an anomalous pattern. So, how can we
12:40
make sure that we stop that so that it doesn’t become chargebacks in the
12:45
future? Because it might be if you start by doing one trend for abuse, there
12:49
might be a different one in the future that will result in chargebacks.
12:54
My recommendation would be not to work alone as like in a silo from fraud fraud
13:02
prevention team but also work with different teams like the product team
13:07
and policy to to try to understand why the users are doing that. You need to
13:13
have a broader perspective to understand the full context and mitigate that
13:18
problem. It might be that the description of the items is not clear on
13:22
the website and they do not know what size they should be buying. That’s why
13:26
they buying two or maybe they are really abusing uh for some other reason. So
13:33
really try to deep dive and understand why they are abusing. there is a root
13:38
cause and the answer is probably not within the fraud prevention team and you
13:43
need to go back to the user experience product teams so that you can find that
13:48
answer. Great.
13:51
Let’s go ahead and jump into uh what stuck out to us as the uh highest
13:57
year-over-year chargeback rate uh had the highest year-over-year chargeback
14:00
rate increases. So, we see on screen we see that the online travel and lodging
14:04
is continuing to grow at an alarming rate, right? Right? We’ve seen this
14:08
growth start all the way back um during the the pandemic. We started to see this
14:12
really take take shape. But to see an 816%
14:17
increase uh into 2024, that is shocking to me. Right. In addition, we see
14:23
e-commerce holding the top for volume but still experiencing an experiencing
14:29
an increase of 222%. That is a shocking metric as well. I
14:35
would not expect that there was still that much uh growth for or for uh room
14:39
for growth in that. And then we also see an interesting thing digital goods and
14:43
services seeing a 59% increase uh into Q Q1 2024. Um what do you uh what do you
14:52
have what does this say to you? What do you think about this slide?
14:56
Yeah, on our side we’re more on the digital goods and services
15:03
in terms of what products Coinbase offers. And as I mentioned before, we
15:07
saw an increase over the past year in terms of how much the chargebacks in
15:12
terms of amount are coming to us that that relates to different
15:18
macroeconomic factors. uh people getting to understand and know that it’s
15:24
possible to to file a chargeback and also abusing those policies as we
15:30
mentioned before. So there’s a combination here of different factors
15:34
that we can definitely isolate to understand what’s contributing the most
15:38
for each of the industries.
15:40
>> Makes sense. What I see here is is underlined by the fraud as a service
15:47
kind of fraud methodologies that exist uh across you know the criminal
15:51
landscape. Right? All right. So, if we look at online travel and lodging during
15:54
our DDW investigations that the TASSA team uh provides, we we we see many
15:59
posts about fraudsters who are willing to take uh or willing to make uh
16:05
purchases on behalf of other aspiring fraudsters or just other dishonest bad
16:10
actors uh where they will buy, you know, uh accommodations, whether it’s flights
16:15
or it’s hotels or it’s Airbnbs or whatever it may be. We’re seeing a lot
16:20
of that. um permeate throughout all of these conversations in the in the online
16:25
travel and lodging. And so from that, I feel it’s very important that we
16:30
identify leveraging the data points that you mentioned earlier, similar devices,
16:35
similar IPs, similar similar characteristics that kind of tell this
16:39
story of an ongoing uh fraud uh exploit that’s being uh targeting certain
16:45
industries, right? Then we move over to e e-commerce and we have the same thing
16:49
going on where people are able to buy buy products uh and then fence them or
16:53
sell them on marketplaces and things like this. Um now dig digital goods and
16:58
services is is very important because to me the fact that a a shipping address
17:06
is nowhere uh to be found right in in digital goods and services. I feel that
17:11
that’s a very important marker uh to consider when we’re building our fraud
17:16
strategies. I’ve worked with different organizations and they’ve they’ve kind
17:19
of tailored their fraud strategies to follow in the in align with with
17:22
e-commerce retailers and and others. But when it comes to digital goods and
17:26
services, the device becomes much more important. Right. So, uh, do you have
17:31
something to say to that?
17:34
>> Oh, as you mentioned, there’s no physical delivery of any goods. So, we
17:40
need to rely on different data points apart from the shipping address as
17:44
that’s something that will be the same as the the home address of the the user.
17:48
For example, device intelligence is what we rely the
17:53
most. So trying to understand if there is any sort of VPN usage, IP address
17:59
anomaly, uh some sort of network of devices that
18:05
are creating multiple accounts or logging in into multiple accounts in the
18:09
same period of time. Those are definitely signals that we can leverage
18:14
to understand if there is one criminal organization behind those disputes that
18:20
we are seeing. makes sense. Uh during our
18:25
conversations, you tied this this this to money mules. I’d like to hear from
18:31
you how this ties to money mules, how it’s represented in the data uh and why
18:38
it’s different from just traditional payment fraud.
18:43
>> Yes. So depending on the country uh that you are operating you can see that there
18:48
is some sort of money muing activity going on and it it can differ in terms
18:55
of age groups. So sometimes it will be younger individuals that are just out of
19:01
college and need more money or people uh in different age groups that are
19:06
struggling to to pay their bills and would like to receive some sort of
19:12
money um to to help them on dayto-day frauders will pay some money for them so
19:20
that they can access their accounts and do the money laundering. So that’s one
19:24
of the uh trends that uh exist and you can tie them together by looking at the
19:32
IP address and device ID because fraudsters won’t have like a 100 devices
19:39
with 100 different IPs to control all those accounts. So you can leverage
19:44
different signals like identifying clusters of IP addresses, clusters of
19:50
device ids, VPN usage as I mentioned and depending on the vendor that you have,
19:55
you can also get additional signals. For example, did the user take a screenshot
20:01
during the time of the of the payment. Was it being accessed by remote software
20:07
access? That’s another signal that you can leverage. That’s not something that
20:11
a regular user would do to use some sort of remote software to control their
20:17
computer while buying something. So you can combine those uh signals from the
20:22
device with the age group, country, time that is being bought. This way you can
20:29
have a much higher precision. You bring up a really good point that I
20:33
always said in in my past webinars, which was a fraudster might have access
20:37
to 10,000 different pieces of compromised information, whether it’s
20:42
payment or identity. What they do not have is 10,000 different devices. So we
20:48
will be able to see either through new device registrations like like uh like
20:54
in the case of ATO’s or in in like your case of mule accounts where access
20:58
either through a remote desktop or through collaboration where a new device
21:01
is added after the point um we will see the new new device and predicated and
21:07
and when contrasted against previous behaviors uh that’s going to seem
21:11
anomalous just the new device itself. And so in our workflows, in our in our
21:16
processes, we might want to make a consideration for new devices, um,
21:20
unique device ids, geolocations and all those different data points that you
21:24
mentioned.
21:25
>> Great. Great.
21:26
>> Yeah. And another thing, even if you do not have that much in terms of signals
21:30
from the device, you can see anomalies uh in terms of regular buy pattern from
21:36
the user. So in terms of uh traveling people most of the time plan in advance
21:42
their travels. So they would uh be planning like two six months earlier and
21:49
not seven days before
21:50
>> right
21:51
>> and that’s some of the exploits that fraudsters might use buying a flight
21:56
ticket for the next week. That’s not regular u behavior for a trusted user.
22:02
So that’s that sort of anomalies and identifying not in terms of fraud
22:08
prevention but in the customer journey what are the what is a regular pattern
22:15
what a regular user would do and what is some of the anomalies that we can see
22:20
during that flow might help you identify improvements that can be done in your in
22:26
your flow. And you just brought up another really good point is anomalies
22:30
can be uh detected at the account level, at the platform level, and at the
22:37
network level. Right? So wherever we define what these models may or may not
22:41
be, if Luis is interacting with the platform in a very particular way,
22:44
that’s the account, that’s the user model that we would see and try to
22:47
derive anomalies from, right, when we see them. But then there’s the the
22:51
platform. How do all of our users interact with our platform uh on any
22:57
given normal day? What’s a common behavior? And then what’s anomalous? But
23:01
then also what uh will identify, you know, emerging trends when we tie it to
23:05
our chargebacks. We go back and we evaluate these use cases. What kind of
23:09
trends can we can we pull from that information uh to view, right? And then
23:13
there’s the network model, right? which is vitally important because one thing
23:17
that I always say is even though this particular type of fraud hasn’t made it
23:21
to your platform, if it’s made it somewhere else, it’s just a matter of
23:24
time before it shows up at your front door, right? And so leveraging network
23:28
models uh are vitally important as well so that you get that proactive
23:32
information about what anomalous or suspicious behavior looks like as
23:36
reported by the network. Right? Great points.
23:40
Okay, so now we’re going to move into the next part, platform analytics.
23:44
Right. So, platform analytics is coming from the reports uh the the the
23:51
consumers that were that answered questions, right? And they came back and
23:54
gave us all of our answers that we see here. Uh the fact that 70% of consumers
23:59
have filed a dispute in the past 12 months uh was interesting to me. And
24:03
then the second point that was very interesting to me is that 22% of them
24:10
filed two in a year. Now, how many chargebacks have you filed in the past
24:14
year? Let me ask you,
24:18
>> I didn’t file any.
24:19
>> Same here, right? Uh the fact that that Okay, so uh not
24:25
stated on the screen is 22% of consumers report filing chargebacks for unwanted
24:30
subscriptions. And I think that’s really important and and you surprised me uh
24:35
with your insight regarding subscriptions in crypto. Uh can you
24:39
share with the audience what you shared with me?
24:41
Yeah, sure. So, at Coinbase, we have a subscription service that you get
24:47
priority support. You have zero trading fees and also boosted rewards when you
24:53
you stake your assets at Coinbase. And this is one of the products that we
24:58
launched uh probably in the past couple of years. And as I mentioned before, you
25:05
cannot look at a single data point. So usually subscriptions do not have a lot
25:10
of chargebacks but if you look why are you receiving
25:14
those and it’s a matter we had to deep dive and it was a matter of
25:19
understanding with product team how was the flow for a user to get a
25:23
subscription was it clear for the user that they were subscribing to a service
25:28
or not so sometimes it might be hidden uh in a lot of different screens and the
25:35
user isn’t sure that they are clicking to subscribe something. So that’s one of
25:40
the things that’s important to understand. How can we make more bring
25:45
more clarity to the user that they’re subscribing? Also, sometimes you have a
25:50
free trial period. Is it good to remind the user when that
25:54
free trial period is about to expire so that they are not surprised uh by a
25:59
transaction on their card? So those are some of the recommendations that we we
26:05
analyzed by that time and we made some improvements so that we could bring the
26:09
dispute rates down in terms of the subscription services that we have.
26:15
>> That makes sense. And and when we during our conversations, you also brought up
26:19
the the the incorrect reason code that was affecting you. Uh which of course
26:25
threw off a lot of uh for a lot of operators, I should say, throws off, you
26:29
know, the reliability of those reason codes when we take that back to our to
26:33
our to our operations. Uh we’re trying to see what went wrong as it pertains to
26:38
the reason code, right? And so you were telling me about uh item not received
26:42
first party fraud. Uh can you dive into that?
26:46
Yes, as I said before, we do not have a physical delivery of goods. So, it’s
26:51
digital assets. So, when we see a reason code for item not received, it doesn’t
26:58
make sense uh to our operations. So it’s important to understand if it’s coming
27:04
from a specific issuer that reason code if the users are having problems in
27:10
terms of filing a dispute and that’s why they are saying that it’s uh merchandise
27:15
not received. So trying to understand what is happening and also that will
27:21
affect matrix for uh card schemes. You might have a a dispute but you do not
27:27
have a chargeback and you have contrasting matrix and you have to
27:33
remediate and create uh action plans so that you can bring those dispute rates
27:38
down and it might change in terms of how you address them if you are receiving
27:44
both chargebacks and disputes depending on how the the chargeback or the dispute
27:49
was categorized. And I think that’s really important as a
27:53
takeaway here is is is how much accountability there is in in policies,
27:59
in documentation, in the customer journey. How much of this actually feeds
28:05
into uh opportunities for dishonest consumers to to take advantage of the
28:10
chargeback system and file these first party fraud uh chargebacks, right? And
28:14
so there’s a lot of work that can be done upstream um that that we are in
28:19
control of as the operators. I think that’s a common theme that I’m getting
28:23
from you. All right, let’s hop into uh the top
28:28
reason codes for disputes. Right. So, the things that stuck stuck out to us
28:33
were of course the obvious that true fraud persists as the top reason. Right.
28:38
Secondly, 16% of chargebacks are filed due to not receiving owed refunds. Now,
28:44
this stuck out to me very importantly and this kind of feeds into the
28:46
narrative that you were talking about, Luis, where where there is a lot of
28:49
accountability and a lot of action that we can take as operators, right? And so
28:54
what this is what this is saying to us is that consumers that are filing these
28:58
these chargebacks that are later classified as first party fraud or or
29:02
true fraud depending on how they what reason code they choose to use in the in
29:06
the context um came from being owed a refund and that that refund not being
29:12
issued right is there a dynamic like this in crypto I don’t I can’t imagine
29:17
it. Yeah, for sure. There there exists a lot of
29:21
>> all right
29:22
>> similar cases to us. So for example uh I think one of the most recent ones
29:30
if you have for example uh traffic congestion in one network for example
29:36
Solana uh and you the user is trying to buy crypto uh for that specific asset
29:43
and they don’t receive the asset in what would be the expected timeline like a
29:48
couple of minutes for some reason there’s a congestion it will take like
29:52
four hours. the user might file a chargeback because they did not receive
29:56
the money within the time frame that they expected even though there was no
30:02
fraudulent activity. It was an operational problem that led to the
30:06
chargeback. So this is one of the things that might happen. So it’s important as
30:10
a fraud prevention team not only to monitor your fraud prevention controls
30:15
but also uh be aware that other teams uh incidents might impact your your matrix
30:25
as well. So this is one of the most recent uh examples that we had
30:30
especially when asset prices are going up. The user don’t want to to wait four
30:36
hours to buy that token. They only want to wait 2 minutes. So that’s one of the
30:41
problems that might happen. That is a that is an interesting uh
30:46
dynamic of crypto how the time of delivery changes the value right and I
30:52
and I it’s obvious right that that happens but I didn’t consider how big of
30:56
a deal that was and so any delay at all might have monumental you know impacts
31:01
right if we delay the transaction if we do a step-up verification or something
31:05
like that might have dramatic impact on the performance of of that account.
31:10
Yeah,
31:11
>> it’s definitely translatable from like if you tell your user that the the good
31:17
will be shipped in two days and it will arrive by the end of the week on their
31:21
phone. If it doesn’t arrive by that time, they can ask for a refund and if
31:27
they don’t receive, they’ll file a charge back. On the same way for us, if
31:31
the user doesn’t receive the assets or the cryptos that they’re expecting uh on
31:37
that time frame, they might file a charge back on the same way.
31:41
>> That makes sense. While we’re here, let me ask you about
31:45
uh about ATOS on on a on a crypto platform, right? And and equally
31:51
important is when they’re represented in chargebacks and and when they’re not.
31:56
when they’re represented in chargebacks, we’re dealing with the actual payment
32:00
using maybe someone attos an account and they use a compromised card in order to
32:04
make a deposit and through that atto it becomes represented in chargebacks. Uh
32:10
when it comes to true fraud, you mentioned card testing, you mentioned
32:15
um high high dollar value deposits. Dive into that a little bit for me. after at
32:20
after frauds or attos an account, what behaviors are they engaging in that are
32:24
then represented in chargebacks?
32:28
>> You can definitely see a difference from the past behaviors of the user in
32:34
comparison to the ones after the ATO. So, we’ll see uh changes of course in
32:40
the device that’s been used, the IP address. You’ll see differences in terms
32:46
of what is the amount that the user is buying. So in the past, the user might
32:52
buy only a $100 per day and then in a single transaction, you might see a
32:58
$1,000 buy because the card is already on file in our platform. So you can use
33:04
those signals to identify u the AQ on a transaction uh moment for
33:12
example with a high value transaction or also in the login process if you see the
33:18
device uh mismatch compared to the past ones. you can identify by other patterns
33:26
in terms of velocity because the attackers will try to to remove all the
33:31
money that is on the card at the shortest amount of time. So you can also
33:36
uh identify that by velocity controls or even implement those so that that attack
33:42
doesn’t even happen.
33:44
>> That makes sense. And you you you touched on several big items that I feel
33:47
are very important when we’re talking when we do talk about ATO’s, which is
33:52
it’s not one single data point that’s indicating suspicious behavior, right?
33:56
And so the way that I word it is it’s like it’s like a collection of yellow
34:00
flags across a across a process that ultimately result in uh you know some
34:06
some definitive action whether it’s denying the transaction, closing the
34:09
accounts, stepping up verification, things like this. And the thing that I
34:13
feel is really important is those exact same steps apply across the board.
34:18
Right? If somebody goes and attos into a um into any established account, right?
34:25
If it’s if it’s someone’s uh hotel account or their air airline
34:30
accommodations account, right? They have the opportunity to then use compromised
34:35
payment details in order to transact. And those same data elements that you’re
34:39
leveraging in your determinations become important here. Same thing for
34:42
e-commerce, same things for the digital goods and services, especially when
34:46
we’re leveraging device intelligence and the elements thereof uh in our
34:49
determinations. And I so that would be number one is how expansive this one set
34:55
of insight is, how it how it pertains, you know, across the the marketplace.
35:00
Secondly, I feel that it is it is vitally important to not get hung up, as
35:04
you said, don’t get h don’t get hung up on one single data point, right? It’s a
35:09
collection of data points that ultimately say this is suspic suspicious
35:14
and from that we we’re able to uh say that anybody who just so happens to buy
35:20
a plane ticket for example on the day of the flight we don’t want to block them
35:24
but if in conjunction with a new device a new payment method a new geoloc and a
35:29
flight within an hour that’s suspicious right and that story is what needs to be
35:34
taken into consideration uh before we take any definitive action
35:39
Yes.
35:42
>> Yeah, I agree. It’s not only one single data point that will tell the whole
35:46
story. You need to combine them and see how they add up and if it’s suspicious
35:52
uh as a combination or not.
35:54
>> Absolutely. Uh the last point uh for this slide is that 10% of these reported
36:01
chargebacks bypassed the merchant resolution process entirely.
36:08
What do you what what do you have to say to that?
36:13
>> Yeah, sometimes uh we will not have the the data points. It could be that the
36:20
previous transactions of the user were made more than a year ago and you didn’t
36:24
have the device ID saved for for that anymore or you changed the vendor during
36:29
that time. So the device IDs doesn’t match or there’s a combination of of
36:35
course there could be an operational issue that you didn’t capture that
36:39
signal during that time and you’ll not be able for example to uh to represent
36:46
those chargebacks and you’ll take the loss on those. So it’s definitely a
36:53
problem that we we face. One thing that I’ve seen feeds right
36:58
into your narrative about upstream policies, upstream documentation,
37:02
upstream communications and all of this. Uh staying in communication with the
37:08
customers and making sure that they have every link and every notification that
37:13
they need in order are you satisfied with your purchase? Are you satisfied
37:17
with your service? Are you satisfied with uh your experience? And then also
37:22
um trying to pull in uh the idea of like discounts and things like this. All
37:27
these different types of communications are opportunities for us to communicate
37:30
with our customers in order to um drive them down the different processes that
37:35
we set up for them, right? And so if we use all of these opportunities to let
37:40
them be aware of, you know, that they can communicate how to communicate,
37:44
where to go, uh I feel that we can start chipping away at that 10% number.
37:51
All right, so let’s get into some actions. Right, so every fraud program
37:57
is comprised of three primary elements. At least to me, it is. We have data, we
38:02
have strategy, and then we have automation. And I feel it’s important
38:06
for it to be in that order. And the way that you pieced all of this together uh
38:10
was awesome. So, I’d love for you to take over on this slide and and describe
38:15
from the highest level what are the elements of of developing a a winning
38:21
fraud strategy. Um, and how do the elements play together?
38:26
>> Yeah. Starting by the data, you need to make sure that the data that you have is
38:31
correct. Both in terms of internal data and also data that is coming from
38:36
external vendors so that you can be sure that the analysis that you’ll be doing
38:41
on your strategy stage are correct otherwise you might go to the wrong
38:47
direction. Make sure that this the signals are
38:51
being received uh when they they need to be on your platform not like one day
38:57
after. So make this uh first housekeeping item to make sure that the
39:03
data is fully correct otherwise you cannot trust anything that you do
39:09
later. That would be my my first recommendation
39:14
and understand that some of the ETL processes so for your data to be stored
39:20
in your database uh might not be real time. So some of the data might be real
39:26
time some of them like aggregations might only come uh one day later. So
39:32
understand that you have those um different categories of data and that
39:37
you need different strategies uh on how to use them. That would be my first
39:43
recommendation.
39:44
>> Mhm. Uh my second recommendation in terms of data, sorry. In terms of
39:49
strategy, now you need to combine those signals. So now you have reliable data
39:55
that you can act on. Think about what are the real time data that you have and
40:01
those you can apply uh for example a real-time friction as well or you can
40:06
send to to manual review so that you can uh stop the fraudsters. If you have
40:14
batch data, you might need to have uh higher
40:20
frictions because you you are already one day late because the data took like
40:25
24 hours to be processed uh aggregated. Now you have to think about a different
40:31
strategy because the the fraudsters might have them the funds uh gone away
40:37
or the goods are stolen. So you need to think about a different strategy for
40:42
those cases depending on the data that you’re using.
40:46
And finally in terms of automation here I would think not only in terms of the
40:51
strategy u but also in terms of monitoring anything that you can
40:56
automate alerts uh as we mentioned it’s not normal for a lot of people to be
41:02
buying plane tickets one day before their flight. So try to see if there is
41:08
a new trend. How what’s the percentage of flight tickets that are being bought
41:13
in the last 24 hours instead of being planned in advance. This way you can be
41:18
ahead of the new trend that fraud stores are exploring.
41:23
Also in terms of automation, you can try to see what are the the fraud rates by a
41:30
specific bin issuer so that you can be ahead in terms of identifying the trend
41:37
that has been exploited on the other platform so that you can prevent it on
41:42
your side as well. This is uh one of the things that we we
41:47
explored before. So you can leverage those signals to create rules or
41:53
controls that will be automatically triggered once you see uh dispute rates
41:59
increase in one specific issuer. And as that is remediated on their side, you
42:04
automatically deactivate the rule on your site too. So you don’t need to to
42:09
be concerned about having a rule that’s blocking trusted users.
42:15
>> So you covered a lot of ground there.
42:17
>> Yeah. So automation uh you can explore a lot once you have reliable data and a
42:24
strategy defined you can automate from monitoring for rule strategy uh anything
42:31
that you want.
42:33
>> So let’s package that up a little bit. I feel that that based on what you’re
42:37
telling me and and I totally agree with it. We could simplify it to say that all
42:41
the data breaks down into three categories because you mentioned
42:44
in-house and you mentioned uh partnerships and that can uh be great
42:50
but then there’s also implied data right so there’s the data that we receive that
42:54
tells us fundamentally what is something yes or no is this accurate yes or no has
42:59
this been seen yes or no but then there’s that performance data that we’ve
43:02
mentioned historically so data lays the foundation and this foundation needs to
43:07
apply across the entire customer journey which you alluded to when you spoke
43:10
about the chargeback rates going up and how that needs to be tied back back into
43:14
our upstream determinations, right? So, we’ve got this whole customer journey uh
43:19
that needs to be taken into consideration, this whole story and then
43:22
all of the data feeds and builds this foundation of what our performance is.
43:27
From there, as you mentioned, we work on our processes. We’re going to clean up
43:30
what it is that we do, where we’re aimed, what handles what, unsilo our
43:35
operations. We’re beating a dead horse with that. But we’ve got to unsilo,
43:39
right? We’ve got to work together. It’s a team effort. Make your strategy. Then
43:43
and only then are you leveraging accurate, reliable, quick, up-to-date
43:47
information, a viable strategy that’s focused and
43:52
unsiloed. Then you can get into automation, right?
43:56
Because we don’t want to run the risk of automating something that shouldn’t be
43:59
automated and and all of the damages that would come from that, right? So
44:03
let’s dive into uh data specifically, right? We’ve spent a lot of time on the
44:09
importance of device intelligence uh implied behaviors and characteristics,
44:14
anomalous behavior predicated on device intelligence. Um I would like to ask you
44:21
what do you think when we’re building out our strategy, what do you think in
44:25
today’s world are the most important data sets and why?
44:32
My recommendation would be to think not only in terms of
44:37
user data but also user behavior on the payment data so that you can explore
44:43
different points of view of the same data point. So for example one user
44:49
might have five different devices. That’s one of the data points that you
44:54
can collect and use for decisioning. and at the same point that they have five
44:59
different devices. One of those devices could have been used in 10 different
45:04
accounts. So it’s basically the same data set that you have but you are
45:09
aggregating in different levels. One of them you are uh aggregating on a user
45:14
level and the second one you are aggregating on the device level. So you
45:19
can see different anomalies on those on that same signal. You mentioned before
45:25
you need to analyze in terms of a user, in terms of platform, in terms of
45:30
network and taking uh a step back and looking at that data point in different
45:36
angles might help you solve uh the problem with the data that you already
45:40
have in house for example.
45:43
>> I love that. That is vitally important. Um so on the on the platform level,
45:48
we’ll say it’s the platform level. We’re taking an element of the data from the
45:52
account level, bringing it up and checking against the whole platform
45:56
because like you said, this device and this behavior might work on an account
46:00
by account basis, but if that one single device is seen across 50 different
46:05
accounts, you have to ask yourself, is this normal behavior? Is it normal
46:09
behavior for one device to be accessing 50 different accounts? And from that,
46:14
what are we getting into? Yeah, I think that’s that is a crucial piece of of
46:18
information that applies uh to every to everyone attending this webinar. If you
46:23
see multip one single device or just a short list of devices that are that are
46:27
related to multiple different accounts, you got to ask yourself, is that
46:31
anomalous? Great point. I love that. Um, cool. Uh, so reliable data, uh, as
46:40
we mentioned, is the foundation, right? And so, uh, gaining clarity is going to
46:46
be top of mind whenever we’re dealing with chargebacks and in our fraud
46:49
strategy, right? We want to know what our performance is. So, we need to gain
46:52
clarity on what our chargeback uh, situation is, what our upstream
46:56
verifications are, how well they’re performing, and just view it in this
47:00
holistic story, right? That’s going to be first and foremost. Uh, and data is
47:04
going to provide that foundation, but we need that clarity. We need to know as
47:09
close as possible what the story is, right? All right. And then to your
47:12
point, Luis, we need to get creative, right? When we see that this data is
47:15
accurate, is that all we need? No. This accurate my information in this positive
47:21
performing account over here might be a a what is the word? Ah, there’s a phrase
47:27
for it, but it might be false, right? This one just might not have been
47:30
reported, but those other 20 would have been. And if we were to get creative
47:33
with our data, we might be able to see that a single device has been used. a
47:37
single address, a single phone number, a single any one of these individual data
47:41
points. And again, I want to I want to draw that even though, you know, there’s
47:45
been a lot of focus on crypto here, this dynamic applies to every industry out
47:49
there, right? Um, and then of course the the the the going upstream in the story
47:57
uh relative to whatever reason code is coming in which again we can only get so
48:02
clear on because as you mentioned we’re getting reason codes uh that are
48:07
impossible reason codes. Right. So we got to we got to piece these stories
48:10
together. We got to see what the trends are uh and we have to build it up. Uh
48:14
anything else you like to say on this slide?
48:18
I think that uh summarizes my my points.
48:21
>> Awesome. So, moving on to the strategy piece
48:25
right now. This is my favorite one to discuss because in the game of fraud, it
48:30
is so important to identify we’re playing chess, not checkers. And there
48:34
are so many dimensions where this analogy works because think about every
48:37
item in chess and how uh or every every piece in chess has different dynamics,
48:43
right? They can do different moves and all these different things, right? So
48:46
when we’re getting strategic, we need to appreciate that maybe the IT cyber
48:49
security team can handle these elements over here, but they need to collaborate
48:53
with the fraud team over here. But then in addition to that, they all need to
48:56
collaborate with customer service who’s you know having those interactions with
49:00
uh with the customers and then we take into consideration the data, the
49:04
workflows, the manual processes, the automation and all these different
49:08
elements are all of your different pieces on the chessboard, right? And
49:12
when we look at it that way, we start to be able to strategize a lot better and a
49:16
lot more clearly. So the four main takeaways that I would like to open this
49:20
part of the discussion up with are one, beating that dead horse, break away from
49:25
silos. Whether it’s your data being siloed somewhere, whether it’s an
49:29
operation being siloed somewhere, or I’ve seen a lot of operations take
49:33
specific fraud methods and the entire reporting process is siloed from
49:37
somebody else. As we just defined earlier, as we were discussing earlier,
49:41
we were talking about ATO’s and how nowadays social engineering to the
49:45
consumer might turn into an ATO down the line. That ATO might turn into withdrawn
49:52
funds that are not represented in chargebacks, but it might also respond
49:56
or or result in new payment methods being added to the account and then used
50:00
for purchases which do result in chargebacks. All of this fluidity,
50:04
right, in these fraud method methods need to collaborate and it needs to be
50:09
tied together and that story needs to be there. So break away from the silos,
50:13
collaborate with this unified vision in mind. Uh staying up to date with
50:18
marketwide performance, that’s that network data that we’re talking about.
50:22
But I would also say that for all of you guys who are uh attending this webinar,
50:26
thank you. You’re staying up to date. Um that’s that’s an idea of it. And then
50:30
there’s training, right? There are a lot of organizations out there who offer
50:34
training for specific types of situational issues, situational
50:38
challenges and opportunities. There are also different training organizations
50:41
that will keep you up to speed on different fraud methods. Um, if anybody
50:45
wants any more information on that, feel free to reach out. Um, I’ve got a lot of
50:50
friends who do trainings. Um, and then the last point is to respond. Don’t
50:54
react. There are a lot of people who will get greeted with this new method
50:58
and they’ll say to themselves, well, who markets the best? Who can sell me this
51:01
product? focus on this one particular use case and they don’t realize that in
51:05
doing so they’re uh in in signing a new contract. They’re kind of throwing the
51:10
the the baby out with the bathwater and that that whole saying where you’ve
51:15
covered all of this ground and now this new emerging trend comes up and yes it’s
51:19
the focus of the day but it’s not the only focus. We got to look into the
51:23
future. So I know I just unloaded a lot and you brought up during our
51:27
conversation some really interesting points that pertain to strategy. Um I
51:31
would love to hear what you have to say. Uh you mentioned the merchant ID
51:36
dynamics. So I I’d love to I’d love for you to share that with the audience.
51:40
>> Yeah. Uh one of the topics that I already explored was related to scenario
51:45
based rules like activating and deactivating based on different fraud
51:50
rates that you are seeing on your platform. But also you can use different
51:54
strategies to to remediate um your current dispute rates. One of them is
52:00
for example if you have different operations could be in different
52:03
countries uh in in Europe or if you have different products and different
52:08
merchant ids for each of those products. You can see one strategy that can either
52:15
combine those merchant ids or split one merchant ID that has too many things
52:20
going on one on like multiple products or multiple options in it so that you
52:26
have a better dispute rate in each of them. So for example, if you have one
52:31
product that is really low risk and you are seeing a different product in a
52:37
different merchant ID that has a higher dispute rate at the moment, you can try
52:41
combining those two in a new merchant ID so that they will balance and you have a
52:47
better dispute rate and maybe get out of a monitoring program from a card scheme.
52:53
That’s one of the strategies that you can explore based on the data that you
52:56
have. That makes sense. That does make sense.
53:01
Uh, another item that you brought up relative to determining what what a
53:05
strategy might be is is time. Right now, in many markets, uh, of course, the
53:12
holiday season is a big a big time uh, for us to be strategic for time to dict
53:18
dictate our strategy, right? The time of the year and all of that different
53:23
stuff. Travel season might be hot during the spring and the summer. So that would
53:27
be time affecting them. Now for crypto, every day is a new time. Tell me tell me
53:33
how you juggle that.
53:35
>> Yeah, we never know when our our all-time high will be. So we need to be
53:40
creative in terms of how we can activate and deactivate rules so that we don’t
53:46
hit um trusted users or we don’t hit enough riskier users. One of the ways
53:53
that we can do is as I mentioned if we start seeing an uptick in terms of
53:57
dispute rate and a specific bin issuer that’s something that we can
54:01
automatically deploy those rules but also if we see that an uh bitcoin for
54:07
example is increasing in price over the past 24 hours or over the past 1 hour
54:13
maybe it’s a good thing to deactivate one of the rules so that we don’t hit
54:17
trusted users that’s one of the strategies that you can automate based
54:22
on the data that you have in calls.
54:25
>> That makes sense. And again, that that type of dynamic carries over to many
54:30
different markets. As your volume increases, you know that there’s going
54:33
to be what would be anomalous behavior throughout the normal year. Think about
54:38
the holiday season. Whenever we’re getting into the holiday season, a lot
54:41
of the shipping addresses aren’t going to match those billing addresses. Many
54:45
of the many accounts are going to be sending it to many different uh many
54:49
different addresses as gifts. think about gift cards coming up for sale and
54:52
all these different things. So accounting for time, seasons, holidays,
54:58
accounting for all of that as we develop our fraud strategy is is vitally
55:02
important. The last item we have here is automation. Right? So once we have all
55:08
of this data that’s accurate, reliable, up to-date, we have the strategy, we
55:14
know what we want to do, we have this vision moving forward, we’ve been very
55:18
careful to craft the strategy. Um now it’s time to get into automating for
55:22
high v high volumes right and so the four points that we bring up are we need
55:27
to understand the story of the data primarily up to this point what stories
55:31
are we working with and then conversely how many good users are going to be
55:37
impacted by that and I think you and I have have clarified up on uh have
55:41
clarified that upstream prevention is worth its weight and gold. The reason
55:45
why I mentioned that here is chargebacks um are a result of upstream performance,
55:52
right? And so the if we can get these upstream performance dialed in, tuned in
55:57
and make all these upstream determination or upstream decisions work
56:01
for us, that number gets lower, right? And so there’s the idea, which is what I
56:06
would like to pose to you, there’s the idea of managing chargebacks
56:10
and upstream prevention. And I think the saying is
56:14
um an ounce of prevention is worth a pound of management or or whatever the
56:21
saying is. Uh what are your thoughts on that? When you’re developing a strategy,
56:24
where do you automate first? Managing the chargebacks or upstream?
56:29
>> It totally makes sense. If you if you can remediate that from
56:34
the beginning even from the product lounge that’s the best way that you can
56:39
prevent uh problems down the road. So try to make it right from the product
56:46
lounge. If it’s something that’s already built,
56:50
make an audit, see what’s not going well in terms of the product design, fix that
56:57
and you’ll see that your dispute rates will get much lower. And then you can
57:02
start mitigating u specific fraud attacks that you see instead of fighting
57:07
a fire every day. That makes sense. As for automating the
57:14
chargeback process, what are the main top top of mind items that you consider
57:21
when you seek to automate to manage chargebacks?
57:26
I try to think in terms of policies that can be automated in terms of rules that
57:33
we can deploy and also in terms of tools that we we might need and if we have the
57:39
the right people to perform those tasks. So it’s a combination of those four
57:44
factors that we can uh build together to fully uh fully
57:52
automate that process. So here it’s not by looking at one specific factor but
57:58
through the entire ecosystem.
58:00
>> Yeah, that makes sense. And then of course when it calls to automate, we’re
58:05
going to be looking to the future. And it’s it’s vitally important to leverage
58:09
industry experiment uh expertise in order to make quick adjustments. What
58:13
works today is going the the factors of what works today is going to be
58:17
identified by the bad actors out there. they’re going to pivot and therefore we
58:22
need to pivot. And then we go back to square one. What’s the new data? What’s
58:27
the new strategy? And then what kind of automation can we safely do to protect
58:31
our users uh and and and not drive up the risk of customer insult. Right.
58:39
So with that, thank you all. We ran right up to time. Uh Luis, do you want
58:44
to sign us off with the with the takeaways?
58:48
>> Yeah. So as we said uh chargebacks will continue to increase year-over-year. Uh
58:56
otherwise we wouldn’t have our jobs. We we can expect both in terms of the
59:00
number of disputes and also the amounts to continue to increase. That’s
59:05
something that we saw in the last report and we’ll continue to see try to
59:10
understand what trusted users and risky users have in terms of patterns will
59:16
help us a lot in terms of deploying strategies. And finally, think about
59:22
your data not only as a single data point but as a platform so that you can
59:28
identify uh similarities and anomalies and make
59:34
sure that that data is correct and you’ll see how much further you go in
59:38
terms of strategies and automations that you can build uh in your companies. uh
59:44
those are the takeaways that we we have discussed uh a lot today. So I really
59:51
want to thank you and thank everyone who attended this webinar. I really
59:56
appreciate uh your time.
59:59
>> Thank you everyone. Uh expect to see the recording up uh and the email will be
1:00:04
going out to everybody so you can share it with your colleagues who weren’t able
1:00:06
to attend. And uh until next time, have a great one.



