AI-powered fraud is escalating at an alarming rate, leaving consumers unsure of who or what they can trust online. In this webinar covering the latest Q2 2025 Digital Trust Index from Sift, we examine why AI-generated scams have surged year over year, successfully defrauding more than a quarter of the victims they target.

Are GenAI scams now easier to detect, or more difficult? Are consumers who are more confident that they can identify an AI-generated scam more or less likely to become a victim of one? Join us as we uncover the identity signals that reliably characterize bad actors and demonstrate how to adopt AI at scale for real-time decisioning to counter these increasingly sophisticated threats with best-in-class strategies.

You’ll learn:

  • How consumers both trust and distrust GenAI
  • Best practices for leveraging AI-driven fraud tools
  • What information consumers are already sharing with GenAI tools
  • Behavioural signals and patterns that separate fraud from legitimate traffic

Watch the Webinar

Close

Thanks for submitting!

close

Video Transcript

0:03
Right. Hello everybody. Thank you for joining us today for I fraudbot signals
0:08
and strategy for preventing Gen AI fraud. Just like every other webinar
0:13
you’ve attended, we’re going to give it a minute or so for people to join and
0:17
then we will dive right in. Right.
0:54
Thank you everybody for joining. I want to call your attention to the QA section
1:02
of the the tab for the webinar. We would love to get your questions throughout
1:06
the course of our discussion today. So do not hesitate to put them in there.
1:11
But uh without further ado, we’re going to kick off i Fraudbot signals and
1:16
strategy for preventing Gen AI fraud. And we’re going to start out with a few
1:22
introductions from today’s three speakers. So Brian, would you mind
1:27
kicking us off?
1:28
>> Thanks for having me today. Always a big fan of the stiff team. Uh thank you.
1:36
I always like to pay credit when it is due. Uh, I’m Brian Davis, head of prod
1:41
at Dodgeball. I handle a lot of the customer strategy and really helping
1:44
understand what risks are worth solving.
1:49
>> Great, Jimmy.
1:51
>> Awesome. Yeah, thanks Britney. Um, so my name is Jimmy Dunn and I am on the
1:56
product marketing team at Sift. Okay. And I am Britney Allen, senior
2:00
trust and safety architect at SIFT. I’ve been in fraud prevention for about 15
2:05
years focusing on being the voice of the merchant and also education.
2:10
So today we are going to cover three different topics. First is going to be a
2:17
deep dive into some of the data from CF’s Q2 digital trust index which is a
2:22
quarterly report that we put out and in Q2 it focused on consumers and their
2:28
perception of AI. Then we’re going to dive into some of the complicated
2:33
questions that merchants have to work through separating fraud from legitimate
2:38
bot activity. And then lastly, we’re going to focus on leveraging AIdriven
2:43
fraud tools so that you can have some actionable takeaways after the end of
2:47
today. So let’s start with consumers and AI.
2:53
Now, all of the statistics from this section come from a poll that SIFT ran
2:59
which asked adults 18 and older in the US in May 2025 some of the following
3:06
questions. So, let’s start with consumer overconfidence in identifying AI scams.
3:12
Now, of those consumers surveyed, 33% said they were completely or very
3:19
confident they’d be able to identify a scam that was created using AI. And I I
3:23
think we all know what that might look like. We’ve seen those demonstrations
3:27
where uh you’ll go to the is this person real or not website and try to figure
3:32
out how you could tell if a face was AI generated or not, or you’ve seen a deep
3:37
fake video or voice used in a demonstration. But about a third of
3:41
consumers said completely confident or very confident they could identify that
3:47
that was a deep fake. But then of those same consumers asked, 20% said, “Well, I
3:53
was fished successfully in the past year.” And we have a similar connection
3:57
with another set of questions where 33% of consumers said they have been the
4:01
target of an AIdriven scam like a deep fake. And 27% of those who said they had
4:08
been a target were scammed successfully. So you then have to read into the
4:14
questions a little bit more deeply knowing that only a third of consumers
4:19
are completely or very confident that they’ve been able to identify that a
4:23
scam was created using AI. Well, then probably way more than 30% or 33% of
4:30
consumers were targeted by AI because we’ve got 66%
4:36
who don’t feel like they could even identify AI and might not have even
4:40
known AI was used in a scam that targeted them. And then of course we
4:45
know we’ve got people who are confident in identifying it, but still 27% of
4:49
those were scammed successfully. So what we can see here is that some consumers
4:55
are confident a majority aren’t and there are successful fishing and scam
5:02
campaigns that are being run using deep fakes. So Brian, does this sort of line
5:09
up with what you would expect to see from a consumer survey?
5:12
>> Yeah, because people are still learning what can I do? There’s different
5:16
populations who are very aware of the technology and a lot of populations that
5:20
just heard about it on the news. So honestly, I bet you some of the I’ve
5:26
been targeted by AI stands realistically is probably higher uh just because if
5:31
they don’t know it really exists how it can actually be used or they’re
5:36
confident definitely definitely confident that they know how to spot it
5:41
>> but might overlook a few things cuz 27% are still scammed.
5:44
>> Yeah. Bet you it’s still a little bit higher and it’s probably used a little
5:47
bit more so than a lot of people recognize.
5:52
>> Exactly. Jimmy, how about you?
5:56
>> Yeah, the similar thing. I mean, I’ve I I think about the experiences that I’ve
5:59
had and that even just friends have had, right? I had a a good friend whose his
6:04
parents were called on the phone by one of their sons saying that he’d been in a
6:08
car accident using deep fake voice. And the only reason that they caught it was
6:11
because uh uh he said that he was in the wrong location. He said that he was he
6:17
had recently moved states uh and and was actually across the country. So that
6:22
it’s getting better out there. I’m getting some that are saying like, “Hey,
6:24
have you paid your your tolls for, you know, to you on the east coast here,
6:28
right? You got all the easy pass stuff going on and you get all those coming.”
6:32
Like they are getting even to the point where I’m going, “Oh, was that and and
6:36
pretty dialed into this stuff.” So unsurprising that that this is probably
6:41
just the tip of the iceberg.
6:42
>> Yeah. So we’ve got that that base level set then here of consumers having some
6:48
confidence but it not really being an overwhelming majority. And so that would
6:52
then lead us to ask well if they are a bit worried about Genai deep fakes and
6:58
and other tools being used against them for fraud well how are they interacting
7:02
with the tools that are built for consumers? And we’re actually finding
7:07
that they’re interacting quite a bit. So 31% of consumers admit to entering
7:13
personal or sensitive information into a Genai tool. And some examples of what
7:19
that personal or sensitive information would be are things like email
7:22
addresses, phone numbers, home address, uh all the way down to unfortunately
7:27
information that’s not yet public and company trade secrets. Uh now I will say
7:32
when surveys like this go out some people don’t want to tell on themselves
7:37
even if they had done something like that. So you could maybe assume that
7:41
information that’s not yet public or uh information about employer and company
7:45
trade secrets that actually could be a bit higher. People are just hesitant uh
7:49
to admit it because they worry that clicking that button might somehow send
7:52
out a signal somewhere or get them in trouble. But knowing that over half of
7:56
people put their email addresses into a Genai tool, that lines up with the idea
8:01
of a Gentic e-commerce, they would have to be able to turn over some of that
8:06
personal information to allow a Genai agent to make purchases on their behalf,
8:11
for example. Uh, so I will pause here also because I’m not one of those people
8:16
yet. If you’ve heard me speak on this topic before, you won’t be surprised by
8:20
that. I am very, you know, hesitant to use Genai tools, but somebody on our
8:27
call today has put personal sensitive information into a tool. And so, Jimmy,
8:33
can you tell us about how you used a tool?
8:35
>> Yeah, I mean, I’ll proudly answer honestly on this survey, I guess. Uh, so
8:40
so yeah, absolutely. I I had my annual physical uh a couple of weeks ago uh and
8:46
got back the results of my my you know the blood test where you get like the
8:51
whole list of results and I went into the uh to the tool that that our medical
8:55
provider has to like look at all the results and there was no context no
8:58
information about like what’s good there were just ranges and dots on ranges and
9:03
I was like well this isn’t helpful at all. So I I just grabbed a copy of it
9:07
and dropped it into chat GPT and said, “Hey, could you help me understand
9:09
this?” And it was super useful of like both like here’s the implications,
9:13
here’s how things are related to each other. So like and I and I think what we
9:17
run into here, there’s a lot of generational stuff both with identifying
9:20
what fraud is, but also with just comfort level with being open and
9:23
sharing things that are online. So my guess too is that this is something that
9:27
is probably higher than is stated and and will continue to be. So people are
9:31
just kind of used to it, especially if there’s actual value on the other side.
9:36
>> Yeah. There’s still a lot of questions though floating around like are are you
9:39
comfortable having the information you entered then being used for training
9:43
purposes for the model?
9:45
>> Yeah. So and that’s a good question because I I I put myself as kind of like
9:49
one foot in each boat. Like I’ll share some things like a blood test like
9:53
what’s that going to do for the world to know like you know how my triglycerides
9:57
are? I don’t know. Um, so, so with that one, yes, but there are certainly other
10:01
things that I would be, uh, a little bit more hesitant to put out there.
10:05
>> Yeah.
10:08
>> So, we break down here another uh, question that was asked, which is
10:11
percentage of consumers, excuse me, percentage of consumers who are
10:18
extremely or very concerned about the security of their personal information
10:22
when using GI tools. That’s 52%. So, you know, maybe that 52% with that weird
10:27
overlap with 55% saying they put their email in. They might have put their
10:31
email in, but they are still concerned. So, we do have a high percentage of
10:35
consumers then that at least express some level of concern. And companies
10:40
have concern over what a consumer or an individual would be willing to share. If
10:45
you’ve got that information that’s not yet public or company trade secret part
10:49
in mind, you could think about the fact that many companies have policies
10:53
against doing just that. And if you entered company trade secrets into a
10:58
genai tool, you could actually be fired per your company’s policy. And then of
11:04
course there’s that idea of data being used for training which could
11:07
potentially result into uh inadvertent disclosure and the possibility of
11:13
fraudsters who were able to access jailbroken models of publicly available
11:20
genai tools who could then maybe you know use them nefariously based on the
11:24
information that’s been entered in and is available then for querying. So that
11:28
that leaves us with a lot of questions up in the air. Uh before I move on,
11:32
Brian, is there anything you’d like to to add here?
11:35
>> Uh no, I got some ideas which I think will kind of blend into a little bit of
11:39
the sneak peek that you sampled uh quickly already.
11:42
>> Um
11:44
>> right, then let’s move on. And you’re right, we already did sample
11:49
a little bit of this because this is a visualization of how consumers have used
11:55
generative AI tools comparing 2024 to 2025. Now, I have my own takeaways from
12:01
this and then a couple of reveals that will pop up at the bottom, but since you
12:05
already said you’ve got something here, Brian, why don’t why don’t you take it
12:07
away for a minute?
12:08
>> I think this just speaks to the advancement and how people are thinking
12:12
about using these tools on the consumer side of like, hey, what can I do? Help
12:16
me with my blood test. Help me understand this. What’s this mean?
12:19
Should I do that? Very, very kind of simple level one. And now you’re seeing
12:24
a lot of competitors in the market. And I’m not even speaking on the
12:28
competitiveness on the jailbroken models, but on what they offer, the
12:33
specialize the tools and now how people are thinking about how to use them.
12:37
Naturally, Britney, I think you probably go with a lot of these questions too of
12:40
like there’s a lot of good that can be with this, but there’s a lot of bad. So,
12:44
I am a tinkerer. I like to kind of see like what can I build? What can I do
12:48
with this? I actually create bedtime stories for my son to have him live
12:53
specific moments. he gets to pick the theme, so he’s involved with that. Uh,
12:57
so that’s like one use case that I like to use so I don’t have to read the same
13:00
book 17 times over. Get a little boring for me, but he gets to be involved with
13:04
that. But on the other side of this, there’s a couple things that stand out
13:08
to me. the improving code, generating code, uh generating ideas, enhancing
13:13
learning. For me, what do those stand out on the risk side of enhancing
13:17
learning, understanding how different businesses can be abused? Why should I
13:22
target insert one company versus the other? Account research, generate ideas.
13:27
What are some things that I can do to communicate to help me with customer
13:32
service? Now you can have social engineering or messaging and writing and
13:36
then improving code and generating code. We think about triangulation fraud uh
13:41
with fake uh websites being built and brought up. The scale and ease to make
13:46
these look legitimate is so quick and easy. Now I don’t know if you’ve played
13:50
around with building any websites with any of these or any apps but it’s pretty
13:54
impressive. Like I’m non-technical. So the ability of all the different ideas
13:59
that I have that I can get at least a working model that looks way better than
14:03
what I could have gotten two years ago. Now think about that for fraud and
14:06
abuse. Think about the scale that they’re able to do. That’s why you’re
14:09
seeing all these messages that the grammar the things that we have taught
14:13
in the past of what to spot, what to look for. I think we’ll talk a little
14:18
bit on like consumer education a little bit, but
14:21
>> like I think about the risks involved with this. So my brain always goes back
14:24
and forth. I am on both sides of this. I think playing for me gives me ideas of
14:30
how could I use this to abuse a company. So then I can think about the
14:34
protections, the risks, the signals. There’s a whole lot to unpack there.
14:38
>> There definitely is. And you for me, I agree with you where generate code that
14:43
massive increase was one of the the things that caught my eye. So, in less
14:48
than a month, I’m going to be starting a master’s program in cyber security. And
14:52
signing up to do it through Georgia Tech meant that I had to agree to all of
14:57
Georgia Tech’s policies about how I would conduct myself as a student. And
15:01
one of the first things I had to agree to was not using Genai tools to generate
15:06
any part of my application. And I’m therefore assuming there’s going to be
15:11
some sort of prohibitions on using Genai tools when we come to sections where we
15:15
have to code or you know take other steps. Of course, you know, are they
15:19
really going to be able to know if I’m using it or not? That’s sort of up for
15:21
debate based on the uh sophistication of these tools, but we know that quite a
15:28
few people are using Genai to generate code because we’ve even got a new phrase
15:32
for it, vibe coding. But fraudsters have decided that it’s it’s kind of fun to
15:38
have also a play on words for them. And they have decided to call vibe coding,
15:43
which is when you don’t have that technical background, but you’re asking
15:48
a generative AI tool to do something. You’re telling it what the end product
15:52
is that you want and asking it to build the code behind that. Well, fraudsters
15:57
are starting to refer to it as vice coding. I don’t know if that’s going to
16:01
stick around or not, but that is the idea of using generally a jailbroken uh
16:06
generative AI tool to then create malware, create uh I say a fake fishing
16:12
site, whatever they want to do that a legitimate tool would refuse to help
16:16
with. So, I’ve got a couple of examples down here of conversations from Dread,
16:22
which is a site that is basically the Reddit of the dark web, where fraudsters
16:27
are discussing what they might do with their AI agents to accomplish just this.
16:31
So, in this first post here, you see someone is complaining about being busy
16:35
in the summer, but they really want to place sports betting bets. So, they’re
16:40
saying here five to 10 large bets between now and the start of the month.
16:43
They still want to look into how to have good OPSSEAC or to not get caught and
16:48
then also just security in general, but they’re going to feed info into their
16:52
offline AI agent. So, one that they do not have connected to a major provider’s
16:57
servers and then get recommendations. So, in this case, they don’t care to
17:01
study maybe who’s going to be h I’m about to reveal myself as not being a
17:05
football fan, but like who’s the best new quarterback question mark of the uh
17:11
new season, but they’re going to get their GI agent to figure that out for
17:15
them. And then to also place bets on their behalf, so they don’t even have to
17:18
go to those particular platforms. The second example I’ve got is actually
17:24
somebody replying to another post. There was a post where someone said, “How can
17:30
I use Gen AI or AI agents in order to better fish credentials out of victims?
17:36
They were specifically looking to get credit card numbers.” A person replied
17:40
saying, “How much coding do you know? You know, it won’t be that hard just to
17:44
use AI to do it, but you know, if it’s complicated, you could just pay a dev.”
17:48
And so they’re acknowledging that there are limitations to this vice coding or
17:52
vibe coding uh you know let’s say strategy but we know that won’t be going
17:57
anywhere because historically we have seen script kitties or fraudsters who
18:03
just find code available online and then reuse it for their own purpose. This is
18:07
basically the same thing as being a script kitty just without finding
18:10
someone’s human pre-written code asking the genai to do it. So that’s that’s my
18:16
big take on this information here as a fraud and risk indicator.
18:25
Right. Before we go on then into separating out these bots from good or
18:31
bad, is there is there anyone else who wants to make a comment?
18:38
All right. So let’s go right into it. Separating fraud from the bots. So let’s
18:44
start with going back to that Q2 digital trust index from SIFT fraudster identity
18:51
signals. What have we found within our own data that seems to be indicative of
18:57
fraudulent activity? We highlight this because when you are a fraud fighter,
19:03
especially one that’s been working for 15, 20 years, any length of time, you
19:09
get this mindset of what fraud looks like to you. And as that changes because
19:15
fraudsters change their methods, you might still be stuck in relying on old
19:20
indicators or, you know, you may be hesitant to change your mind. And I
19:25
think some of these are, you know, really interesting to discuss because
19:29
they are different from prior conceptions that we may have had. So,
19:33
for example, 36% more payment methods are used by fraudsters than by
19:39
legitimate consumers. That one makes sense to me. Fraudsters using stolen
19:44
credit cards, other stolen payment methods. Of course, they would need to
19:48
cycle through those until they find a card that works. So, that makes sense.
19:53
But on the flip side, fraudsters use 20% fewer IP addresses than legitimate
20:00
users. And and I think a lot of fraud fighters can easily get stuck in that
20:05
mindset of well the more changes to an account the more variances then that
20:11
makes it riskier. Whereas in this instance, we’re pretty much pointing to
20:17
fraudsters who maybe have a stationary device where they aren’t often changing
20:22
their IP address, standing out in comparison to legitimate consumers,
20:28
walking around with a phone, walking around with a laptop or a tablet,
20:32
anything else portable and connecting from a lot of different points. Then
20:37
we’ve also got the call out here for peak hours for fraudsters, which again
20:41
sort of fits the the mindset of what I would have as a fraud fighter of them
20:45
attempting to hit your site during off hours. So I want to defer at this point
20:50
to Brian and say, you know, with with your experience as a merchant,
20:54
conversations you have as a merchant, what’s your feedback on these signals
20:58
here? And, you know, how do you think that actually applies to a day-to-day,
21:04
you know, life of a fraud fighter? Do you think they get hung up on some
21:07
historical patterns or you know what’s your take?
21:10
>> Absolutely. And it’s easy to like I know these patterns but they come and go.
21:15
They might disappear for a couple months but they’ll be back. They always come
21:19
back. Maybe a little bit of a different twist of a flavor and you have these
21:23
general trends and people know when you work. So they you think about
21:28
seasonality. Usually peak season for physical goods is around the holidays.
21:33
for gambling. You brought up gambling. It’s usually around the Super Bowl. So,
21:37
it’s when when is there a lot of pressure where I can kind of either
21:42
blend in with normal activity. Either I know companies are not staffed enough,
21:47
they’re on vacations, or I can take advantage of what I know about the
21:53
target that I’m trying to get. And then thinking about what am I really trying
21:56
to gain access there. Um the fewer IP addresses is one of those things I think
22:01
a lot of people kind of think about like well if there’s a variance there there’s
22:05
this that it’s an anomaly where you’re looking for anomalous behavior. Now,
22:10
when we’re pointing to non-anomalous behavior, that starts to make things a
22:14
little bit trickier of like what you’re thinking about and the way that
22:19
everything we’re talking about here are signals. Signals and data points
22:23
ultimately say what do we trust? What do we not trust? And I think that’s a big
22:27
piece of Gen AI moving forward and AI agents is there’s a lot of unknown and
22:33
what are the signals? Where do I get the signals? How should I consume these
22:38
signals? are there going to be variances to the signals that we know today. So I
22:43
think there’s a lot of curiosity into uncovering a lot of these signals but a
22:47
lot of hesitance of is it going to change everything I know is what got me
22:51
to this point to make me the expert to people think I am is that going to all
22:55
fall through so there’s like a little bit of like in some of the conversation
22:58
I having like from people that are incredibly smart and built awesome
23:02
careers little bit of imposter syndrome going through of like everything that I
23:06
know is what’s it going to look like moving forward. So it all goes back to
23:09
the signals and kind of what the unknown is because we’re all still kind of
23:13
figuring this out. Merchant side, vendor side, even AI companies are all still
23:18
trying to figure out what will it look like not even two years from now, three
23:21
months from now, six months from now.
23:23
>> Yeah. And that’s just another important point of not relying on these static
23:26
signals and you know being able to if you’re using uh machine learning to
23:30
fight fraud, to update the models to learn to follow those frauds for
23:34
patterns and to better prevent fraud. Uh how about you Jimmy? What what are any
23:38
takeaways you’ve got from these here?
23:41
>> Uh I actually didn’t have any specific ones um for this slide, so I think I
23:45
think I’m good on this one. We can keep going.
23:47
>> Okay. Well, actually, no. I I like to put you on the point or on the spot. I
23:50
think it’s a little fun. Do you connect to public Wi-Fi networks?
23:54
>> Do I connect Oh, uh uh occasionally. Like the the occasional
23:59
like airport Wi-Fi. I’ll do that on occasion, but for the most part, no.
24:03
Unless there’s a password.
24:05
>> How about you, Brian? Let’s get it all out there.
24:08
>> I’ll say absolutely. For the most part, no. I try to avoid you. But I will say
24:11
there are those situations where I’m like, I just need it for whatever it
24:14
need needs to be to connect to something. So yes, I’ll admit it. I will
24:18
be the first one to admit. There are scenarios. Do I try my best to avoid it?
24:24
Yes. Uh but not perfect. I do. I do sometimes.
24:29
>> Look, I I I wouldn’t shame you without also then contributing my own answer,
24:33
which is also that I do. So, there’s simply too many situations I find myself
24:37
in where connectivity is needed for one reason or another, and my only option is
24:41
a public Wi-Fi network. Uh, most recently, I was at an event where I was,
24:47
I guess, I don’t want to say in the basement, but I was sub, you know, level
24:51
of a building where I still needed to be able to use my phone. And so, I had to
24:57
get on their Wi-Fi network because I had no cell signal down there. So, those
25:00
things still still come up. But there’s an idea then that if you were a very
25:04
security-minded person and maybe you traveled with your own router and you
25:09
had your own connection, maybe you would fall then into the few IP address
25:14
category or fewer than a majority of consumers and you might look like fraud
25:18
when really you’re just a privacy-minded person. So I call all of that out then
25:22
to say we still can’t rely on, you know, one signal, two signals to indicate
25:28
fraud or not. It’s a glimpse over the whole user journey.
25:32
But thank you for admitting that. And I do want to also throw out the anecdote
25:35
that one time I was at JFK here in New York and there were two networks that I
25:41
could see that were related to airports. One said something like JFK free Wi-Fi
25:46
and the other said LAX free Wi-Fi. And I knew I wasn’t in LAX, but if that
25:54
person had been smart enough to switch it over to say JFK, I might not have
25:57
known which JFK to pick from. So of course there is still that risk.
26:02
All right. So, let’s talk about assistive technology. Now, this is
26:08
important to bring up because a significant amount of your customer base
26:13
may use assist of technology and assist of technology is going to look very much
26:18
like bot activity or automated activity on your platform. So, just to throw out
26:23
some stats of of how big this is, 20% of people worldwide use assist of
26:28
technology. uh to give you example what that could be could be speech to text.
26:32
It could be eyetracking technology in lie of using a mouse to click on a site
26:37
and that encompasses 13 million people in the UK and 65 million people in the
26:43
US. So using tools like speech detects and eyetracking technology is a benefit.
26:50
It’s something that we want to encourage and support to make the internet more
26:54
accessible. But if all of a sudden merchants who let’s say haven’t been as
27:00
concerned about automated activity or were only concerned about automated
27:04
activity that they already knew how to recognize as fraud and are now dealing
27:09
with incoming agentic AI activity. there’s a chance that they could then,
27:14
you know, make a mistake and potentially discriminate against individuals using
27:19
technology like this because now these types of agents are, you know, just for
27:24
convenience such as with AI powered browsers. Uh, and I know Jimmy, when we
27:29
were chatting earlier, you actually had something uh that was just, I think,
27:33
released this week or discussed this week from OpenAI.
27:37
>> Yeah. So, this is a big deal. Um so chat GPT is still for most people it is AI
27:43
and it is like the consumerfacing uh like they had they’re up to 800
27:48
million active weekly users. So when chat GPT does something it means that it
27:54
has kind of officially launched if that makes sense. And this week, ChatGpt
27:58
launched agent mode, which is where, right, you can use chat GPT to actually
28:03
go and take actions on the web for you that can go and do visit sites and do
28:09
things on your behalf. Uh, and it’s really interesting because if you read
28:12
through the release, there’s a section called novel capabilities, novel risks,
28:17
right? We’re talking about like the the Spider-Man scenario, right? With great
28:20
power comes great responsibility. When we talk about AI, with new capabilities
28:24
comes new risks. And this is maybe the most upfront I’ve seen them be on a
28:29
release about the types of risks that are coming here. We’re taking a new
28:32
step. We’re talking about like if you’re giving payment data, for example, to an
28:36
agentic AI to go and make purchases for you, that data is now potentially
28:40
compromised as it goes out and moves in the world. And they do call out
28:43
specifically prompt injection, which if you’re not familiar with that, that is
28:48
as your AI agent is going out and reading websites. Uh fraudsters could
28:53
potentially put instructions for the AI on a website that the the chatbot would
28:59
go and read and that would be taken in as a new instruction. So it’s it’s
29:03
taking over it’s adversarial manipulation taking over the the bot as
29:07
it is out um completing tasks for you. So getting into the world of a bot being
29:12
able to actually do real world things now opens up a new category of the the
29:18
type of shenanigans that can occur.
29:22
>> Shenanigans is a good word. Brian, anything you’d like to add to this?
29:27
>> I don’t know how I talk shenanigans. I think it’s a great way to kind of
29:29
explain it. It’s really goes into a lot of like the methodology of like when I
29:35
think about researching into it of when these are used on your platforms, how do
29:40
you know? I think that’s a great place to start kind of today of like thinking
29:43
about how do you know and what signals are telling you? And a lot of it will
29:48
kind of come from metadata and there are logs that you’re able to kind of revisit
29:51
and there’s the visual side of things and then there’s the data side of
29:55
things. So that’s really where I’m starting today
29:59
as I kind of have a lot of conversations of helping people understand how do you
30:04
know and where will I find this information. You can’t really build a
30:07
strategy and execute on it if you don’t know where it is and what kind of
30:11
signals you have today to start. Now there will be lots to learn from. You
30:16
got to start somewhere.
30:18
>> Exactly. Uh, and I think that leads us really well into our next slide of
30:22
talking about blah versus the blah bot. So, my initials are bla or blah. Thank
30:29
you, mom and dad. And so, I as an example for comparing human activity to
30:36
an agent activity, we’re going to talk about blah, the human, and the blah bot,
30:41
the agent. So, here’s four different potential scenarios that you as a
30:45
merchant could see on your platform. If you’re looking at a, you know, user
30:51
journey from start to finish in number one, I have never bought from your
30:56
platform before, but I’ve asked an agent, an AI agent to do it for me. And
31:00
so, BLBOT makes the first purchase. Now, I’m a legitimate consumer. We’re not
31:04
talking about fraud here. It’s using all of my legitimate information that I’m
31:08
providing to it. In number two, I’m already familiar with your platform as a
31:14
human and I have made at least one prior purchase, done some browsing activity,
31:18
saved things to favorites, whatnot, but then it’s followed by a purchase from
31:24
blah bot. Maybe I was then, you know, just comfortable enough to use a an AI
31:29
agent because I already like your service and I say just repeat my last
31:33
order. So, you get that activity. On the flip side, in scenario three, have you
31:38
thought about if the blah bot is the one that makes the first purchase and then I
31:43
liked the item that I got so much or I liked the service so much, I then when I
31:48
had time as a human came back to your platform and I walk through and make the
31:53
second purchase or four, which is when me the human experience with multiple
32:00
different AI agents because I want to see which one I like the best and Maybe
32:05
I am making four or five small purchases through your platform. Each one using a
32:11
different bot. So, it is all automated activity coming from the virtual machine
32:17
the bots’s running through or whatever signals you’re able to scoop up from
32:20
this activity, but it’s multiple different bots. Are you able to say that
32:27
looking at the signals from these four scenarios, you would be able to tell
32:31
that there’s no fraud here? that all of these four scenarios represent
32:37
legitimate customer activity. Uh I will click to reveal another quote from
32:42
Dread. This is a very dramatic fraudster here saying humans are corruptible and
32:46
then saying as AI agents take over there will be fewer signals or traces as he
32:52
says to point to for fraud but there’s also going to be you know fewer human
32:57
signals if the adoption of AI agents like this increases. So, I I have a
33:03
couple of takeaways, but I think I’ll I’ll pause here and ask Brian, what do
33:09
you think about these four scenarios? I know there could be even more, but I’ve
33:13
got a lot here, I think, for merchants to think on and try to discern whether
33:19
their system would be able to correctly identify all of this activity as
33:24
legitimate.
33:25
>> I want to call out this quote that it feels like it’s the start of a trailer
33:29
to a movie. goes to a black screen that pops up
33:33
>> cinematic music and then the it takes off. After that,
33:38
>> we’re living in the movie now today. But I think about it, there’s some news of
33:43
recently. It starts at the policy level. There’s the major online retailers
33:47
who’ve decided today we’re not taking anything we determine that are agentic
33:53
AI agents coming to our site to shop. That’s a policy that you’re deciding as
33:58
a company where we fall within all this. I’ll say my personal biases are it’s a
34:04
hybrid approach. It’s not a this or that and it shouldn’t be today because we
34:07
don’t do that with humans because a lot of humans are good. There’s some
34:11
malicious actors who are doing it manual and then there’s the gray area that we
34:16
as the experts live in through our entirety of a career. Same thing happens
34:20
with bots. Uh not to forget just bots that we’ve known today. There’s some
34:25
good bots, there’s some bots we don’t really know, and there’s some malicious
34:28
bots. The same thing goes with AI agents. So each one now, as the fraud
34:34
and risk experts that we are, we need to have a human strategy, a bot strategy,
34:39
and an AI agent strategy. There can be a lot of overlap, but it all starts with
34:43
the policy of where do we stand with what we want to allow or not allow on
34:50
our website. So for me, it starts at the policy level. you you’ll start to see
34:54
probably over the next couple months other companies making some of those
34:58
headlines of we’re not allowing it at all and some companies saying we love it
35:02
we’re going to find a strategy to drive them to our site. There’s going to be a
35:06
whole lot of that coming over the next couple months starts with policy where
35:09
you as a merchant want to land.
35:12
>> Well before we move on into some of those recommendations and to talk about
35:16
you know what is in the works to assist merchants I wanted to ask a question of
35:21
our audience. Now, I could have asked this up top, but there’s also
35:24
potentially people in attendance today who kind of weren’t quite sure what uh
35:29
AI could actually be doing from a a fraudster angle. But I would love if we
35:35
could get some human clicks on this poll question, which is, have you seen a
35:41
spike in AI based payment fraud? So, thinking through everything we’ve talked
35:45
through today, uh before we get to those
35:48
recommendations, is this something you’ve seen? Yes. No. And it’s okay to
35:53
click I’m not sure if you’re not sure because maybe uh you’re not able to yet
35:58
discern some of this activity. I I think that was really useful what you said a
36:03
couple slides back, Jimmy, about the idea of even the legitimate agents that
36:09
are initiated by a consumer being taken over through I think you said it was
36:15
like code injection or otherwise something malicious in that process and
36:20
then used by a fraudster just like man-in-the-middle attacks collecting
36:24
information work today. So, you know, not trying to influence anybody,
36:30
but I think we’ve got Okay, we’ve got well over half of people. So, I can end
36:37
the poll and share the results. I hope I didn’t influence too many people to
36:42
click the I’m not sure. I don’t think I did because I was watching it go up
36:45
early as before I even began to speak to that section. But we’ve got 53%
36:51
saying I’m not sure, 37% saying yes, and 11% saying no. So, with that, uh, Jimmy,
37:00
what do you what do you think about the responses to this poll? It’s a it’s a
37:05
it’s an interesting mix and and I think that that what’s going to be happening
37:08
as we talked about upfront too with AI is that this this amount of I’m not sure
37:14
makes all of the other answers a little bit probably directionally accurate but
37:18
also a little bit difficult um to to to gauge. And the term, by the way, is
37:23
prompt injection, right? Like prompts are the are the codes for an AI. It’s
37:27
what you tell an AI to do. And prompt injection is taking your prompts as like
37:32
a little virus and sticking it into somebody else’s AI um bot that is that
37:37
is taking action. So interesting to see that that either people aren’t sure or
37:43
it is growing. Just a few that are are positive that nothing is happening.
37:52
So take that away and we will move then into leveraging AIdriven fraud tools. So
38:00
the the origin of the traffic, you know, establishing your known uh Jimmy, I’m
38:05
going to hand this over to you to kick us off.
38:08
>> Yeah, absolutely. So, so I want to start with some some basics first when we’re
38:13
talking about how do we combat this new world of of AIdriven fraud that is uh
38:19
evolving really really quickly. Um, and when you when you start, you want to
38:23
start with the fundamentals. You want to make sure that your building blocks are
38:26
in place. And when I think about that, I think about global data and think about
38:33
making sure that you’re getting data from a vast cohort. Um, so that you are
38:38
seeing changes in uh fraud behavior from across industries, from across
38:43
geographies, and that it’s something that that the model is seeing and that
38:47
is adapting to really quickly. Um, so that’s why at SIFT we have our global
38:50
data network which has a trillion events annually. um we have 220 million plus
38:55
signals that are being added into that model uh by professionals such as
39:00
yourselves to make sure um that we’re staying uh ahead of what’s happening
39:04
there. The other piece which is something that that we work on
39:08
continuously is making sure that our that the modeling that we’re using what
39:11
we’re doing with that data and how we’re slicing it is as effective as possible.
39:16
Um so this uh we have this thing called ensemble tuning or having an ensemble
39:21
set of models that we used for our customers. Um so we have the global
39:25
model that we just talked about on the left side. In the yellow we talk about
39:28
custom models which is building a model just based on your data. And this is a
39:32
little bit of like a a Goldilocks scenario. Global model lots of data. You
39:36
see lots of things not very tightly tuned to your type of fraud. custom
39:40
model hyper tuned to your fraud because it’s just your data but you don’t get
39:44
that visibility from other places and something that we added uh about a
39:48
little over a year ago um that we call threat clusters which is basically
39:52
cohort modeling based on your vertical um so we’ve created a series of threat
39:58
clusters uh in travel and e-commerce and fintech and other verticals so that
40:03
you’re getting that kind of perfect view of uh I’m getting a lot of data that’s
40:08
not just me so that I don’t have to react to fraudsters for the first time
40:12
every time and I’m getting uh data or information that is tightly tuned to the
40:17
type of fraud that is common in my industry. Now there is no silver bullet.
40:21
You can’t use any one of these alone. So we actually use all three of them in
40:24
balance to then create the most accurate uh scoring that we can. So, so having
40:29
that foundation of data and the data that comes in um and the data that comes
40:34
not just from your own sources is key to being able to do things like identity
40:40
trust where you understand who is coming to you and what their intention is when
40:45
they come to um your sites. Now I’m going to give a few uh one very specific
40:51
example of how we are leveraging AI a tool that we are creating and then uh
40:56
talk a little bit about some uh some other things that that uh you can think
41:00
about in the space of of where those tools should be.
41:05
So this is a tool that we are actually excited about. We’re launching it uh
41:09
right now. We’re starting a a limited roll out for GA and this is for our ATO
41:15
um customers, right? Account takeovers are some of the trickiest fraud to
41:20
identify because there’s a lot of gray space. So when we look at one of the
41:24
major pain points um for atto it’s that atto investigation can take anywhere
41:29
from 5 to 30 minutes because you’re sorting through sessions, you’re sorting
41:33
through users, you’re trying to draw connections, you end up with like the
41:36
like beautiful mind board with yarn going to a bunch of pegs on a string and
41:40
then finally you get the whole picture and you’re like yeah I’ve got them
41:43
right. It’s it’s one of the most difficult things even for really
41:46
experienced uh fraud analysts and this is a perfect use case for Genai for
41:52
taking a lot of potentially related data and looking for connections. So, we’ve
41:58
built what we call activity IQ, which is an active Genai um bot that is looking
42:04
at through the data related to these atto investigations. And when you go in
42:08
and look, it will pop up um a summary for you of key data points that could be
42:13
related to the investigation as well as other related sessions or individuals
42:18
and uh uh aberrances of of things that are unusual or outside the norm that you
42:24
might want to look at. So it takes what would be a five to 30 30 minute session
42:28
of of real manual work and it really cuts it down to to giving you the key
42:34
insights and allowing you like somebody’s already done all the all the
42:37
string and the and the dots and you just get it back up and look at it and go
42:40
okay what’s my conclusion here maybe I want to dig into this part or that part.
42:44
So a great example of using Genai for doing intelligent work that’s going to
42:50
make you better at your job and faster. And
42:57
then uh I’ll tee you up, Brian, on this next one here where we just talk a
43:02
little bit about some of the the the variety of ways that you can use AI. And
43:08
AI, I know for some folks can can mean both Gen AI, that’s what most people are
43:13
thinking of now when we talk about AI. It’s also includes broader machine
43:17
learning, which Sift has been doing for the last 14 years. Um, but there’s a lot
43:21
of different things in here that you can dive into. Uh, like like in intelligent
43:27
rule builders where you can speak in normal language and you can have an
43:31
agent, a bot, an AI help you um come up with, okay, well, here’s how you should
43:37
tune a workflow. Here’s the the suggested package of things that you
43:42
should should put into your score to your workflow to help get to that
43:45
outcome that that that is desired. Investigation efficiency. We just talked
43:48
about that with ATO. Score explanability is not just getting back numbers and
43:53
terms, but also getting back real natural language around um some of those
43:58
kinds of things that that or or around the the data that you’re seeing so that
44:02
you can draw um so that you can draw good conclusions. And and as we flow
44:07
down, we get kind of more into that monitoring, pattern recognition, anomaly
44:10
detection, the stuff that uh that bots can be good at at a broader scale that
44:14
would take human eyes and and hands and minds a little bit more time to kind of
44:19
pull together. Brian, why don’t you jump in here? Yeah, I think there’s an
44:23
interesting So, I’m going to actually talk about a use case of one time when I
44:26
was trying to actually buy the ATO SIFT product inhouse about seven years ago
44:31
and it was really hard for me specifically, not because I didn’t get
44:35
the value, I got the value and that’s where I think a lot of the AI can
44:38
actually help here. I was a fifth customer about seven years ago. I wanted
44:43
to expand to ATOS’s ATO was a huge issue for us. The problem for me was ATOS’s
44:48
were happening. We were recurring subscription products. So like what are
44:52
they doing on our platform? For me it was really hard to ultimately tie enough
44:56
of a business case to my exec team to say this is a no-brainer. Instead it was
45:01
like well you already have the transaction model and I was drowning in
45:06
a backlog knowing I had a solution that would work wonderfully. And I think a
45:10
lot of these AI tools of what you broke down here is an area to that would have
45:14
helped me tremendously. you know, from the explanability to understand the
45:18
impact, the anomaly detection, all of this not only helps you fight fraud, but
45:23
if you’re leading the program helps you show the value, the scoreboard, the wins
45:27
of everything that you’re doing and making it easy. So, I don’t have to put
45:30
it in a jury ticket to say why I need a data scientist to help me pull the
45:34
reporting on something. I know exactly what I want to explain to get what I
45:37
need. And then it’s just always lagging. And then when you’re battling actually
45:42
under pressure from fraud attack, you’re just lagged. And then that’s how we
45:47
always end up in being reactive of just we’re waiting for the lagging indicators
45:52
ultimately to figure out what broke and then fix it. These are just so many
45:56
different levels and I think this can sometimes even be overwhelming of okay
46:01
Jimmy this is a lot. These are all wonderful ideas. The way that I kind of
46:05
start to kind of like put the boundaries around people of like you got to start
46:08
somewhere. So, is it about analyzing the impact of your rules to help you create
46:13
better rules? Is it in the investigation summaries of the ATO? Is it score
46:18
explanability of really understanding why did Brian get caught up because he
46:22
was on public Wi-Fi because he signed into LAX public bit instead of at and he
46:29
was at JFK. Something doesn’t really make sense here. Uh so there’s lots of
46:33
different areas of opportunities where I help people is I kind of help them
46:37
understand the risk surface area and how their program is running and we look for
46:41
different areas for this to start and saying what can I what are the goals
46:47
like really why are you thinking about AI like when people are say hey Britney
46:51
what’s your AI strategy that’s fully loaded well I’m a little hesitant I
46:55
don’t really want to be the first one to adapt I need to see some use cases so
46:58
there are some areas that you can use AI into your strategy that might be a
47:04
little bit easier to build some confidence personally for you and your
47:08
own reputation internally and then build that into something more comprehensive.
47:12
So when there are these wonderful tools like this that then kind of like I think
47:15
about the signals you talk about thread clusters. So all these different signals
47:20
is a lot for let alone one person and a team to monitor. There’s just some
47:25
different ways to get higher output per employee. It’s not necessarily always
47:29
about cutting the team, but getting higher output, better leverage, and
47:34
really using that human intelligence where human intelligence should be spent
47:38
and then complementing that with artificial intelligence. So, I think
47:41
about it like this hybrid approach. What you have up on the screen right here are
47:46
incredible examples of where to start, but you got to start somewhere.
47:53
>> So, that then will take us through to these three takeaways. And we have had a
47:58
couple of questions come through and we’ll take the time to answer them on uh
48:02
this slide. But first of all, what do we want you to take away from this webinar?
48:07
It’s got these three points. Consumers are wary of sharing sensitive data with
48:11
AI agents but are becoming more comfortable doing so. So only expect to
48:16
see an increase in that. Number two, you separating good bots from bad will be
48:21
vital to maintain customer trust. You don’t want to discriminate against a
48:26
population using assist of technology or against somebody using an AI agent to
48:31
pick out the uh birthday present for their niece. And then third, be vocal
48:37
with your fraud providers about developing AI tools and giving feedback
48:42
on them. If you want to see these tools available to you as a fraud fighter and
48:47
not just the fraudsters, speak up. Say what those use cases are that you want
48:52
help with. And when those tools are developed and become available, give
48:56
your feedback, help hone them, I I know I’ve been in the fraud fighting world
49:01
for over 15 years, and there’s very few times in that history when there have
49:07
been big shifts in the tools that are available and technology changing. This
49:12
is one of them. And so, it’s a great opportunity to speak up. Now, with that,
49:18
turning to some of the questions. One of them is a clarification question. So I
49:23
think we can start off with that. And we had a person ask what is the difference
49:28
between AI and a bot. So those are both automated systems. AI being a subset of
49:36
machine learning. But I I think what we were talking about through this webinar
49:40
was mostly we use the term bot and we use the term AI agent. So even though AI
49:46
agents and bots are both automated systems, uh when I was trying to make a
49:51
differentiation there, I was talking about bots as meaning sort of the old
49:56
the classic use of a script or code, let’s say via an open bullet config, for
50:02
example, to then take actions on a platform, but not really be intuitive
50:07
about it. So fraudsters would have a config that might be able to access
50:13
somebody’s email and then search their email account for specific names of
50:18
let’s say banks because this fraudster specializes in cash out fraud could then
50:23
see this individual how many bank accounts or or financial accounts or
50:28
whatever they’re looking into investment platforms this person had and then be
50:31
able to target them. Whereas, if they were using something like um an AI agent
50:38
that was able to be plugged into an email account, they wouldn’t have to
50:43
specify the names of those banks of those investment platforms, but they
50:47
could instead just say something as general as, you know, find all my emails
50:52
with financial and crypto, etc. companies that I have accounts with and
50:56
then you know summarize you know recent activity summarize balance summarize
51:00
whatever via that tool and that’s more intuitive and can give the fraudsters
51:06
better access to that data and of course those AI agents are going to be used
51:12
commonly now by legitimate consumers whereas maybe that what I described as
51:16
bot activity earlier wouldn’t be but we could definitely see a time when it’s
51:21
really common for people to use an AI agent to go through their email address.
51:26
So, they’ve connected it to say, “Hey, what subscriptions do I have that I
51:29
haven’t canled and other useful actions.” So, that was what I attempted
51:33
to do. I do apologize if I wasn’t clear with those terminology, but that’s kind
51:37
of how I was trying to separate out sort of the old more restrictive way of using
51:41
a configure code and then now what’s available to fraudsters. So, with that,
51:47
let’s dive into some of our more general questions. Uh to start with, is there
51:52
any way to help consumers get better at identifying deep fakes and other Gen AI
51:59
content related to scams? I got a lot of opinions on that, but I’m going to see
52:03
who unmutes first for letting Brian or Jimmy speak.
52:07
>> Jimmy,
52:08
>> I’ll jump I’ll jump in here. Um, so, so yes, I think that and one of the the
52:14
other I think it was in a recent survey that we saw, I don’t know if it was this
52:17
one where where it talked about um there’s like a social network that’s
52:22
happening like the Tik Tok of fraud, right? Like where people are learning
52:26
from each other how to commit fraud. Uh, one of the ways I think that that and
52:32
this is maybe something that’s a little bit less influencable by us, but people
52:35
starting to share what fraud they’ve seen, sharing what the types of attacks
52:40
that they’ve seen, the types of things that are working. And I know that I’ve
52:42
gotten that from like friends. I’ve sent things to my parents because I’m worried
52:46
about them even though they’re fairly savvy just to be like, “Hey, this is
52:49
something that I saw. It’s not actually you’re not actually late on paying your
52:53
toll bills, you know, that kind of thing.” um as well as getting examples
52:58
from like my bank um that says like, “Hey, here’s some of the types of fraud
53:02
that we’ve seen in the last six months.” I know I’ve started to get those types
53:05
of emails more and more and more often, which I find to be helpful, but I also
53:09
pay attention to that stuff.
53:15
>> Brian, anything you want to add for?
53:17
>> You and I have a lot of similarities. I know we are talking uh about this. I
53:22
think it’s just due to the scope of our role. I’ll let you I’m not going to
53:25
steal it from you. I’ll let you go and if there’s anything that I want to add
53:28
on, I’ll piggy back.
53:30
>> Okay. So, earlier um we we had been chatting. I I did bring up the idea of
53:36
uh consumer education being really important, but it also still just falls
53:40
on us as merchants to be able to protect our consumers. We can’t assume that
53:47
they’re going to be always educated to the point of being able to identify
53:51
these scams. the scams are going to change. They’re going to become more
53:54
sophisticated. You’ve also got newer users online, especially if you allow
53:58
minors on your platform. You can’t assume that they’ve got that experience
54:01
and the maturity and the knowledge to be able to identify these scams. And so it
54:06
also then just falls on us to use some of the tools and strategies that we
54:10
discussed today to be able to identify where someone is taking action
54:16
on a platform that is potentially indicative of them having fallen for a
54:19
scam or somebody’s credentials are being used. Think back to that uh email
54:24
example that I shared of finding all the financial accounts. It it still does
54:28
fall on us for detection. Did I say everything that we had chatted about
54:33
earlier?
54:34
>> Absolutely. And then I just want to tie back to an idea that Jimmy had said
54:38
earlier. Um, you said something that stood out to me, can’t assume. And Jimmy
54:43
said something earlier about the intention of the user in the platform.
54:47
And both of those combined obviously are very hard to execute on. It’s really
54:53
hard to understand intention. You can watch behavior, but intention and
54:57
behaviors are different. So really going on the fact that you just said we can’t
55:03
assume people know and a lot of us fall within the space because we want to help
55:08
and protect people kind of the altruistic nature of working within
55:12
fraud and risk. So always leading with that within your northstar of like
55:16
carrying a little bit more of the conservative protection side of things
55:20
on the merchant bit of like how can I help others naturally we all have that
55:24
northstar when you’re thinking about things like this especially in this next
55:28
era of what Gen AI will bring don’t forget that northstar
55:32
>> yeah and and I personally feel completely confident that I can identify
55:36
AI because I don’t trust anything and nobody is measuring my false positive
55:40
rate as a consumer so I’ll just trust nothing and then get it all. All right,
55:45
with that we have time for one more question and it is about uh fraudster
55:50
identity signals. So think back to that conversation on the IP addresses and the
55:53
the credit cards. Uh won’t they just keep improving their activity to mimic a
55:58
real customer to the point where these trends aren’t helpful? Yeah. Okay. Will
56:02
there be a bot or an an AI agent, whatever term we we want to use, that is
56:09
just so close to a customer’s activity as to not give us useful signals.
56:17
>> I can start with that. I think the blobot was a great exercise to kind of
56:21
start thinking about, yes, they’re going to improve. Yes, they’re going to test
56:26
what gets through through. They’re going to test your protections and controls.
56:31
Yes. To all of that, but with all of that, they leave breadcrumbs of how
56:34
they’re testing. They leave constraints of what they have. They only have so
56:38
many devices. They only have so many of these like cornerstone identity signals
56:43
before they run out. So, you got to think about the constraints that these
56:47
individuals have and these broad operations have. There’s there still
56:51
operate within boundaries and constraints. So that’s one piece of
56:54
where can I attack them on their constraints to get a better
56:57
understanding of how did they get through how did they improve why did
57:01
this happen again and ask those basic questions the other thing is I think
57:05
about like we have a session replay where we’re able to actually watch the
57:09
behavior and the actions of what is happening on platform. So actually
57:15
connecting the data, the logs with the visualization
57:19
uh calling out your football reference uh from the beginning of like going to
57:23
the booth to watch the action replay. That’s what I think about sometimes of
57:27
like if I just can’t really tell and I need to know a little bit. I’m a visual
57:31
learner myself. So it helps me a lot in investigations to be able to start to
57:35
connect the data says one thing. what actually happened on platform might tell
57:40
a little bit of a different story or have just enough context to give me
57:45
additional breadcrumbs that I didn’t know I have. So, um kind of going into
57:49
like always asking those questions. Why us? How did it happen? Where did this
57:55
start? What is their intention? What are they trying to get out of us? And that
57:59
will start to give you leading indicators and lagging indicators to
58:03
help kind of perform. It’s the game we all play. is the game we’re all used to.
58:08
Yes, they’re going to improve. Yes, we’re going to improve as well.
58:12
>> One thing that I’ll just add to that, I mentioned it a little bit earlier um and
58:15
it’s up on my background. Uh this uh concept of identity trust. Um I compare
58:20
it to uh speed dating, right? We’re all speed dating all the time where we have
58:24
somebody sitting in front of us and we have to make a quick decision on whether
58:27
or not we’re going to trust that person, take that payment information, send that
58:30
product or accept the subscription or whatever it is based on the model. We
58:33
got to make quick decisions about trust right away. Well, wouldn’t it be nice if
58:38
before making that decision, you could talk to that person’s exes or the other
58:42
people that they have been in relationships with just to get a feel
58:45
for for for what they’ve done in the past and for what what do they like?
58:48
What’s their what’s their vibe? Um, and that’s what identity trust does. It
58:52
actually collects information related to uh specific identities. Um, and and it
58:58
shares it through the global data network. I can see this person’s
59:01
actually been had transactions accepted and none of them have been marked
59:04
fraudulent by six different vendors over the last two years or over the last six
59:08
years on our network. And those kinds of signals, those behavioral signals over
59:13
time are very expensive and very difficult to fake. They may eventually
59:17
get there, but we’re talking several years down the road. And in the
59:20
meantime, we’ve got some leverage that we can use to win.
59:25
>> Well, with that, uh, one more question came in that says, “Can Britney tell us
59:28
how she identifies fraud?” And I think that was calling me out as how do you
59:32
trust nothing? I don’t have time to talk into it today, but you know what? That
59:35
sounds like a good idea for a little video to put together maybe to share on
59:38
LinkedIn. So stay tuned. I’ll I’ll share some of those tips. But with that, we
59:42
thank you very much for attending our webinar I fraudbot today. If you have
59:46
any further questions, if something springs to mind as soon as you leave the
59:50
session today, do not hesitate to reach out to any of us. We’d be happy to
59:54
answer those questions. Uh, and with that, I hope everybody has a great rest
59:59
of your Thursday.
1:00:01
>> Thanks, everybody.