With every leap forward in e-commerce, fraudsters adapt just as fast, putting retailers at risk if they fall behind. Brands must stay vigilant to protect revenue while maintaining a friction-free experience that builds customer loyalty. Establishing identity trust is key to keeping transactions secure and experiences seamless. This requires the ability to recognize and welcome legitimate customers while blocking fraudsters.

Identity trust can help prevent fraud while preserving customer trust. In this webinar, industry experts explore the many red flags that appear throughout the customer journey, current risks brands should be aware of heading into the biggest shopping season, and ways to stay one step ahead with smarter fraud prevention. The discussion uncovers:

  • How the fraud landscape is evolving
  • Why identity trust matters
  • How AI-powered intel can prevent fraud and preserve customer trust
  • The exciting future of AI-powered intel

Watch On-Demand

Watch Now

Thanks for submitting!

close

Video Transcript

Hello everyone and welcome to today’s webinar: Safeguarding customer loyalty with smarter fraud prevention. We’re glad you’re here. You’re here for this important conversation on fraud, identity and customer trust in retail. As we all know, every advance in e-commerce brings new opportunities for retailers and also new tactics from fraudsters looking to exploit them. Yet retailers are weary of overly onerous security procedures as they can deter shoppers. So to that end, today we’ll be discussing the concept of identity trust, how retailers can confidently recognise and welcome legitimate customers. It allows brands to deliver a seamless customer experience that. Strengthens loyalty while keeping bad actors out. While you’re in for a treat with our guest Alex Hall, a trust and safety architect at Sift, which delivers an AI-powered fraud decisioning platform focused on the concept of identity trust in order to provide friction-free customer interactions. While Alex has dedicated his career to becoming a champion of online security, he actually started out on the other side of the screen, deeply entrenched in the world of online fraud. That firsthand experience gives him a fascinating perspective and unique expertise that he brings to his current role with the Sift team. Company he joins is poised to lead the charge with innovation and clear vision for the future. Before we get started, I have just a few housekeeping items. Please note the slides will advance automatically throughout the presentation. To enlarge the slides, click the large slide button located in the top right corner of your presentation window. Now. Need technical assistance? Click on the help widget that’s located on the bottom left corner of your console. We encourage you to submit questions at any time throughout the presentation using the Q&A widget at the bottom of your console. We will try to answer these during the webcast, but if a fuller answer is needed or we run out of time, it will be answered later via email. So please know we do capture all of your questions. All right, now I know you’re eager to hear from Alex about the fraud risks retailers should be watching as we head into peak shopping season and what the future may hold. So Alex, thank you so much for being here with us today to help our audience cope with this evolving and significant issue. Welcome, Alex. Hi, thank you for having me. I’m very excited to dive into this topic. It’s a huge topic, very impactful. So yeah, I’m very excited to share with the attendees here. Let’s dive in. You know, we hear every day fraud is increasing. Many of us have experienced it as consumers, you know, firsthand. So the problem is even bigger for retail organisations. You know, while consumers often have recourse to recoup a potential fraud situation, retailers really bear the brunt, whether it’s from the pain of chargebacks or outright loss from fraudulent activity. So, Alex, how do you see the fraud landscape evolving, and what should brands consider about how fraud prevention can protect revenue while also building customer trust here? Absolutely. So if we look at it from a fraud exposure and a fraud performance perspective, right, fraud has been evolving for the last twenty years, and it seems to be following this very rigid framework of payment focus fraud, account focus fraud, and then identity focus fraud. So when we talk about payment related fraud, payment focus fraud, we think about you know. What everyone describes as fraud, it’s a compromised payment method being used for fraudulent transactions, and then that results, of course, in losses to the merchant retailers. Well, when we look at that from a fraud prevention point of view, the the perspective is very straightforward, or the calculation is very straightforward, right? We look at the the checkout form, the information that’s collected there, we look at the performance of the transaction that results in chargeback or not, and then that wraps up into our strategy, you know, in order to calculate losses and see what’s ahead for us, right? When it comes to account account focus fraud, so we call that the industry we call it account takeovers or simplified down to ATOs. When it comes to ATOs, that calculation is a lot bigger, it stretches out across the entire journey a lot more, and it has a lot more variables to come into. So let’s say for example that a fraudster goes into an account and. And then they use the stored payment information there to transact downstream. Downstream, yes, it will result in chargeback and we can fit that same calculation. But let’s look at a at a at a marketplace or something like that. If that seller account gets compromised, the value to the fraudster is to extract the funds that are stored or to later, you know, maybe change the account information so that any payments that are intended to go to the seller account actually are being filed off into a fraudster platform. In that equation, we’re not talking about chargeback. There’s no chargeback to measure. It’s all a behavioural element that takes place against the seller account. If that takes place, that seller is going to be very very angry. The brand reputation is going to drop in their eyes. Brand trust is going to drop in their eyes. Depending on the seller on that platform, that might be five digits, six digits. Right, that single ATO can be deeply impactful to an organisation and require all these new calculations, all these new these new considerations. So it’s because of these these exercises and these thoughts that you can see that the damage extends beyond the financial impact of just chargebacks and fraudulent payments, right? And when you run those calculations, you tend to realise that an effective fraud strategy is really interconnected and interwoven across so many behaviours and so many actions that a user might take on a platform. So we’re only just beginning to realise the impacts of that, and now we’re starting to imagine where agentic AI will will take us in the future. Wow, a lot of things to think about there. So thank you for laying the groundwork, and it’s really frightening when. Think of all the ways AI can be manipulated, you know, for nefarious means. So how is that happening already? So there’s another framework to think about. When it comes to fraudsters who are operating manually, right, they’re going to have to do everything on their own. And when we think about document verifications and step up verifications, they take the time to go into Photoshop or go into whatever word document processor that they can in order to make fake documents, just images and do all these different things. When generative AI came into the fold, the adoption rate into the fraudster you know communities and all of that was was pretty sudden and pretty pretty big, right? And they started using generative AI in order to overcome step up verifications. Through doc document manipulation, they started to use generative AI to create videos of people speaking, and so in that we’re able to use DeepFace to both satisfy you know likeness checks and face detections that are offered by platforms, but then also to manipulate consumers and end users you know off to the side. And then you consider whenever all of that gets wrapped up, all of the processes that that type of information we use against that type of process we use against. The takeaway from that or the end result of all of that is Frontier still has to do every item one by one by one by one very manual process is just empowered by generative AI. As we step into the world of agentic AI, we start to realise that that agentic AI can be a force multiplier, right? And what we see on screen is the rising account takeover attack rate. Contrasted against payment fraud. Payment fraud at the same time was around three point one percent, right? And we see a two point five percent attack rate for account takeovers. Meaning, anybody who thinks that fraud is just payments has this this this rising trend of account takeovers coming up in their neck neck, right? So anybody who isn’t already solving for account takeovers and account focus fraud should look at this graph and say, well, it’s time to get something going. We we got to take care of this. We got to get ahead of this. We got to nip it in the bud, right? And so I heavily recommend that we start to to build out these these strategies that take into consideration you know the the login form, but not only the login form. We found you know by working with so many different merchants and so many different vendors across the ecosystem that if you Point all of your your defences at the login screen, you risk running into a lot of false positives and a lot of false negatives. There’s some low-hanging fruit you can you can you can confidently decision on just from login. But beyond login is really where the important storylines are, right? So in that example I gave earlier about marketplaces, perhaps a fraudster logs into an account using a similar geolocation, a new device that they satisfy OTP. If all of your decisioning ends at login, you’ll say that’s a great user, that’s a great session to to respect and allow to go transact on the platform. But then secondarily, that person that that actor might go into the account details page and update contact information, update the banking information, and start to do all these other troublesome activities on the platform. Only once we get that context can we clearly say that. Looked like a good session. Actually was very bad, very impactful to us. And we need a decision on, right? And then you extrapolate that over payment, card building, you know, any of the policies, any of these different items that might come into play, it paints a story that allows you to be more accurate. Yeah, a great explanation. And let’s explore those touch points in more detail here, Alex. You know, including the common red flags retailers should be watching. What are those? Sure. So if you’re just starting out, it’s fine to you know understand the value of you know the device accessing an account, you know, a new geolocation, you know, where a user is accessing an account from a brand new from a brand new geolocation, right? Somebody has an account that they typically access in California and have never changed that behaviour, but now all of a sudden they’re being logged into from New York in Florida, you know, all of that can be very. Right. So for the red flags before the transaction point, you’re going to be looking at a lot of behavioural and device intelligence items, right? New device, new geolocation, what we call impossible travel. So let’s say I log into my account Monday night at 8 PM. Right, so 8 PM I’m logged in and I’m in California. Within 20 minutes later, my account is being accessed in New York. So this behavioural element, only available after tracking geolocation and device intelligence data, that you’ll be able to infer that storyline and that story of impossible travel. So that’s an example at login, right? Red flags during the transaction, we have to be very cognizant of whether or not this account is using a new payment method following a suspicious session. That right there, those behavioural elements typically don’t go in and out. If I access my account from a new location and I satisfy the checkpoint at lot again, but I’m logging into the new area, right? It’s not I’m not likely going to be changing my payment method. It happens, don’t get me wrong. But more or less, you’re not going to see a change payment method, especially one that has a billing address different from yours or a shipping address different from what you used in the past, right? And so all of that can empower you at checkout to see the storyline and again use that information to make an accurate and confident decision regarding that transaction. And then after the transaction, of course, things are going to come in. You’re really waiting until the chargeback comes in, right? Once that charge that comes in, this is where you can go back on that session, back on that customer’s. Information and check to see what behaviours they they participated in, what behaviours they exhibited. You can then roll that into your decisioning for more proactive approaches in the future, right? So to assist us, we look at the story of the account, whether that’s at login, after login, but before transaction, at transaction, beyond. We look at this entire story holistically, and that is definitely necessary in order to see if if what seems like a good session should actually be treated as a good session. And all those elements. I mean, there are many examples, right? If you’re just starting out solving cases, think about guest checkout or not cases. I’m sorry, fraud in general. Is this a guest checkout? Is this a brand new account? What kind of verifications do you have? Were they able to satisfy them? At what what timeline do they take to satisfy them? Let’s say for example, somebody gets a an email verification sent out and they don’t satisfy, then they go and make new account with a new email address but the same shipping address or the same you know information and add a new email address and then they facilitate right based on that information and force tracking behaviour devices intelligence over your platform you’ll be able to see that those two accounts are linked and maybe they shouldn’t be respected and the person comes back and tries again right for customers that have KYC you know were they able to satisfy it within five to ten minutes like any of us would be able to do. Did it take a few hours? Did they have to come back and request another KYC check? That’s another element that we definitely look at. I feel like I’m rambling, but yes, there is a lot of storylines to be watching here in order to see what suspicious activity looks like to your organisation, and then roll them into proactive measures down the line. Yeah, so let’s you know let’s talk about that. You can imagine if retailer has a different calculation for how much promotional abuse or return fraud, for example, is too much. So based on metrics like lifetime customer value, customer acquisitions, cost, and more, how does Sift interact and help support that? So the bottom line, I guess the top line item here is that when it comes to abuse, separate from fraud, right? Fraud we’re optimised into. That this person is who they claim to be, right? And that whole tree of decisioning and data aggregation and workflow management, all those different things come into play when we’re trying to figure out whether or not this person is who they claim to be. We take fraud and set it up to decide. We agreed with this this bucket of users, so this this container of users that is who they claim to be, using payments that they’re allowed to use, their methods, right? They have authority to use them, using email and phone numbers that are truly theirs. And because of this, we extend to them right the opportunity to transact, interact with our policies, our promotions, and things like that. And so when we look at this, the storylines become even more important, right? Because in these settings, the customer always has the control. But we at Sift, we provide the insight that helps the using the operators, the users to make accurate determination. About those confirmed users, right? So we like to say what is first seen is not what is first seen to you is not first seen to us. What we mean by that is we have this huge robust network of information, whether it’s performance data, storylines, outcomes, chargeback information. How has this particular identity dataset interacted with all of these different platforms prior to ever coming to yours, right? And so we get to use that information, we pull in that data from many different networks and industries, right? And then our AI powered fraud decisioning platform will take that information and bubble it up into it can be used many different ways, but primarily there’s a score that becomes associated with it, where you can see what what our machine learning has dictated as reliability for this particular transaction, whether it’s account creation, a log in, or. Transaction. We can get you that information bundled up in the Identity Trust XD product. We can also show to you exactly what elements go into that determination so that you can be informed and make a decision on your own. And that’s where Sift, in a retail partner, like really handling. Yeah, and we touch on the concept of identity trust. So let’s go more in depth about why that matters and how Sift solution safeguard and promote it. Sure. So the storyline behind that is, you know, when a fraudster operates, they they we know that they’re very effective at manipulating and submitting accurate information and manipulated information. And I put all of that into a category that I call active data sets. Right. So when a form asks for checkout or for payment information, when a form asks for email, phone, identity. All those different items, those are all items that we know fraudsters have access to. So when they’re greeted with a form to actively put in that information, we know that information is going to be accurate, right? And so what Identity Trust XD focuses on is the passive information. So playing out the the hypothetical here, if I were to gain access to a compromised identity dataset, I want to go to a platform and create an account, right? The likelihood that this identity dataset has performed across the Sift network, very deeply across the Sift network, is there. And so when it comes to Identity Trust, we track the performance of that identity dataset, of that payment dataset, we track that over the performance of the network. And so now by leveraging Identity Trust XD, you’ll be able to see that this person is now logging in from you know Texas where they have. No historical marks. You’ll see that they’re using an email address that you know in the past five or six days has been used with five or six different you know suspicious activities. You might see that this name has hasn’t been seen before or at all. It’s a brand new name because the person’s using you know a nickname or something like this, or just skewing the name just a little bit in order to you know get past or bypassing any security verifications. All of those storylines are presented in our network and bubbled up to the top. And what this results to, right, is we protect our revenue of our of our partners, right? We reduce chargebacks upstream instead of relying solely on the chargeback on that transaction, we can we can stop chargebacks, we can stop transactions from ever happening, we can stop suspicious activity before they ever make the checkout form. And the Overall goal is to safeguard customer loyalty, the seamless experience. Because this is passive, because this is on the back end, we never have to trigger in MFA. There’s value in triggering in MFA, but for you know organisations that don’t want to rely so much on these these friction step up verifications and things, we can support that, and we’re actually optimised to support that, right? And so above all of this, we get to demonstrate you know the understanding of the customer journey, not just on your platform, across the marketplace, and we can effectively use that to beat out fraud while welcoming the real customers. Yeah, and this Alexia, this has been a fascinating discussion about so much about just you know how to manage e-commerce fraud, and most importantly how to make sure you’re not inserting friction into the process or otherwise scorting you know real customers. That’s some break. Points that you touched on. So as you look ahead to the front of the future, what are the things that keep you up at night that probably keep your clients up too? I so I only don’t buy into like fear tactics, but we have already realised that AI, as I mentioned earlier today, will multiply every fraud method. Right, we’re heading into a brand new universe of fraud, and the time the time is now to get ahead of it. Right, and so earlier I spoke about the progression from manual fraud, like fraudsters operating very manually and doing everything on their own. When we move forward to them being empowered by generative AI, and now we’re looking forward to what generative AI you know might mean. Right, the generative AI being innovated on, innovated. Yes, the adoption rate we expect, because frosters adopted generative AI so quickly and to to such an extent, we expect that frosters are just hungry for agentic AI to to to grow to a point where they can use it in their tactics, right? So the first point that I want to raise is imagine when a froster prompts an agent to find ten, fifty, one hundred different websites that fit the criteria, he otherwise he otherwise needs to go look for manually, right? So as I mentioned at the top of this, I am a reform froster. I used to spend so much time researching which platforms you know had which points or which data points were collected during checkout. Well, if I can prompt an AI agent to go find me one hundred Websites that have this or that criteria. Maybe maybe a checkout doesn’t have billing address or CBD. Well now I know which payment methods I can use. If if agent AI will pull up 100 platforms for me. Now I just made that list in what matter of minutes. It’s a very quick thing to get get all of those results. Likewise, what if an agent can be tasked to go find to go through social media posts or any of these things to find websites that do not have you know KYC verification checks and then give me a list of those. What if the agent agent is prompted to go and create a number of accounts. Right, say Froster needs you know five or six different accounts you know made in order to create information for synthetic ID. Okay, well what if I can task what if Froster can task an agent to go create five or six different social media platforms, five or six different emails, seven or five or six different you know phone numbers, all for these. And I said five or six. What if it’s fifty or six? What if it’s five hundred? What if it’s thousand? What if? Right? So the very idea of fraudsters tasking agents to go do fraud things, not only is that scary enough, but now let’s take that sentence. But now let’s talk about what happens when ATOs reach agentic platforms. So now you have a hundred good consumers who you know however number of good consumers. Now the fraudster wants to gain access to their accounts, their agents’ accounts and reassign access to now to his new device. Well, does that agent have access to banking documents, directly or indirectly, or banking accounts? Does that agent, when they transact, are they transacting on a new retail account or establish? Retail account, can I can Fraudster now go in there and say, hey, using store payments information, why don’t you one click buy fifty different TVs and have them all sent to this address over here? The one to many, the force multiplier that is associated with generative AI is terrifying. Now let’s take that sense inside, because what happens when with all of this open source AI, you know, code and all of this these platforms, programmes, what happens when Fraudster creates a fraud focused generative AI? About the the beginning. I’m so sorry. We are definitely at a point where you know we generally accept it across the board that depending on the organisation that you’re focused on, one percent of revenue gets lost to fraud. And I know. Many ways to set that that data, but we pretty much accept that one percent of revenues lost to fraud on an organisation or organisation based. That is the case, and any fraudster can be just as successful, but just say do it ten times instead of do it once. It’s reasonable to to to assume the possibility that that one x becomes that one percent becomes ten percent becomes twenty percent, and we’ve got to get ahead. Yeah, well said. So there’s definitely no doubt it’s only getting worse and underscores the importance of really having a solution in place that can help protect retailers, you know, while ensuring that valid customers are able to continue to conduct business. You know, we need the best of both worlds here, and I know we’ve got some questions in our queue, so let’s move on to tackle some of those. In this first question, it says thank you for. learning so much about these red flags and their repercussions, I was wondering if you could walk us through how this works practically. How Sift solution is able to help mitigate sure. So I’ll break it down in three categories. So one is going to be payment fraud, right? And so when when payment fraud comes across, what we are going to be tracking is the performance of that not only that identity dataset over our robust network, but also the behaviours across the the journey of that session, how those behaviours come into play, right? You can track. I was mentioning earlier about the storylines and painting the picture and all these elements that go in to making accurate determinations, you know, at any point, right? So when it comes to payment fraud, yes, we’re tracking of course what’s collected at chargeback or at checkout, but we’re also tracking. To see how this identity set and this payment set has been seen across our network, and that rolls up into our machine learning model. And so we’re using all of this expansive data to come in and and get to that accurate determination. When it comes to ATOs, the behaviours are going to be vitally, vitally important, right? I think I’ve beaten that horse enough to how you know aggregate all of these story elements, all these storylines, all these different parts of the picture. There is no way to do it without that. People have been trying to do it for a long time now. You’ll find the low hanging fruit, but what you risk is insulting good consumers, good customers. You end up risking insulting them, triggering too many MFAs. If you’re in a highly regulated industry, you’re triggering too much, too many step up verifications, which ends up costing you just a tremendous amount of money. When you can do it with passive information, you can do it by monitoring behaviours. Yes, that’s how we stop ATOs, going to be tracking the behaviour elements, painting that picture, and coming out with a very, very accurate decision against all of it. And then when it comes to identity overall, that third category that I mentioned, it really does boil down to the performance of identity over time. And when you lean on our identity trust platform, what we’ve found and realised is that you can offset the cost of KYC, you can offset the cost of step up verifications on mass, you can down, you can step down on on the customer friction and use and leverage passive information not only to be more accurate, but. Be more informed when you make your decisions, right? We understand that there’s the those those regulations typically apply to high value, you know, high value platforms, high value interactions, and so we bubble that information up to you, the front end, the front investigator, so that you have all of the information that you need to tell the story as accurate as possible. Excellent, great answer there, Alex. Thank you for walking us through that. Another question here: What are some actionable steps a retailer could take now to prep for 2026? Because goodness, that’s around the corner, right? Yes, it is. So 2026 is synonymous with the age of agentic AI. We have to accept it, right? And what, who? I’m sorry to bring down this hammer, but the truth of the. Matter is, looking at payment fraud that’s been around and it’s not going away. Account fraud is here. It’s not connected with payment fraud we’re seeing. In the future, looking at ID. As I said, the truth of the matter is there are far, far too many merchant organisations, retailers or whatever operators that we might be speaking with who are not aware of the impact that ATL either is having on their platform today, right now, because they believe that all fraud is going to be represented in chargebacks. That’s not the case. We’re past that. We’ve been past that for three or four years now, and it’s only getting worse. We’re at a tipping point now. Where the idea of ATOs is, yes, it’s becoming front and centre because of the impact that it can have. But now consider, every element of fraud is going to be automated by the bad guys. So what I would say as we step into 2026 is, if you do not have a fraud strategy that that absolutely focuses on upstream fraud verification or fraud prevention, you don’t think about ATOs, for even upstream fraud account creation. If you are not rolling those in your fraud strategy and you believe that all fraud is just represented in chargeback rate, you’re already behind the curve. And when agentic AI comes in, frauds are starting to deploy agentic AI toward both payments and ATOs. I mean, I said 10x earlier, but what’s stopping a fronter from saying 10x, 20x, 100x? What is stopping them from finding 100 platforms at once versus 50 at once? If you’re not up to speed on, you know, effectively stopping ATOs at this point, it’s only a matter of months before, you know, effectively the fire to the fire. You got to get this under control to have a successful 20x. Excellent. All right, I want you in the morning, so it’s time to take action, right? So let’s fit another question here. It says, how can smaller or mid-sized retailers approach fraud prevention if they have more limited resources? Resources here, how can you help them out, Alex? Absolutely. So that is, I will say one thing, and I think I said this earlier in the session. Nobody knows your business better than you do. We might know the industry, we might know the marketplace, we might know the trends that are happening at you know astronomical rates across the entire marketplace. We might be able to bubble that down to give you actual actionable insight. As a matter of fact, reliably we can bubble that down to give you actionable insight. But nobody knows your business better than you do. One problem that I see when it comes to small and medium sized businesses is they don’t have the data built out internally to actually tell them the story of what’s taking place in their company. One one example that I’ll bring up is a year or two ago, someone came up to me and said this: “Are you just misclassification of a fraud method?” came up to me and said, Hang on, we are experiencing a truckload of first party fraud, first party misuse, chargeback abuse, first party fraud, friendly fraud. There’s lots of different names for it. The idea is that first party fraud or friendly fraud is when a good verified user goes and uses their own payments information to transact. So they buy a thousand dollar TV. Well then they file a chargeback on it and enjoy ownership of the TV. You can imagine the kind of impact that has on an organisation. When they came to me and they said this, I said, Okay, first show me the data. Why do you believe this is happening? What they presented to me was, Well we have all these good accounts, all these good accounts we’re doing just fine. And now as of in the last quarter we have fifteen different cases of these thousand dollar TVs being purchased by all these good accounts and they’re filing chargebacks. It must be friendly fraud. I said, well, let’s pause. Let’s go upstream on each and every one of those. Did a new device access this account? Oh, wait, yeah, it did on this one. And they triggered an OTP that was satisfied on this one. Oh, this one accessed and this one. So you don’t have a first party fraud, you don’t have a friendly fraud problem. You have an ATO problem, right? And so we would go back and build out that data and then we would wait it so that it was it was reported appropriately for ATOs. Since then they built out their data, they identified it happened, and they had no problem laying down a heavy hand and doing their own step-up verifications. But all of that was possible before partnering with a service provider or a third-party vendor. It’s all stuff that they can do inside. To wrap it all up:
– Build out your data.
– Stay up to date with trainings and webinars.
– Understand the methodologies that are out there in the place of payment fraud and the iterations of ATOs.
– Start to ask yourself: if it happens on our platform, are we equipped to have it reported up to us so we know what to solve in the future?
Those are steps you can take: build data and act on your own. Just understand that whenever you are ready to partner with a vendor, it’s a steroid shot, right? You can get bulked up, right? You can take care of yourself in ways that you can’t do on your own. As far as first steps go, data, automation, and reporting are going to be great advice there. That’s all the time we have today. I thank you again to Alex for a great discussion today. We appreciate you sharing your insights and expertise with us and I’d also like to thank our audience for joining us today. We hope to see you again soon. Have a great day.