Account takeover (ATO) fraud is wreaking havoc across industries, leading to billions in losses and eroding customer trust. But it doesn’t have to. Get a deep dive into Sift’s latest innovations and features to surface and address the total threat presented by ATO. You’ll also hear about the latest data on ATO fraud from our Q3 2024 Digital Trust Index and discover cutting-edge strategies to protect your organization. Learn how to stop the revenue loss caused by ATO by empowering collaboration between fraud, security, and payments teams.

Watch the webinar to learn:

  • How to enhance ATO detection across every stage of the customer journey with real-time behavioral analysis and device fingerprinting.
  • Why a unified, AI-driven platform can boost revenue by turning risky sessions into opportunities without sacrificing security.
  • Ways to recognize the broader scope of impact that ATO can have beyond chargebacks, including transfer fraud, misinformation and withdrawals.
  • Key findings from the Q3 2024 Digital Trust Index on account takeover trends including AI’s Impact on ATO.

Watch the Webinar

Close

Thanks for submitting!

close

Video Transcript

0:01
Welcome to today’s webinar, Stop the Drip: Uniting Fragmented Account
0:05
Takeover Challenges and Operations. Uh my name is Eli. I’m on the marketing
0:08
team here at SIFT. And before we dive in, I just want to go over a few
0:11
housekeeping items. Uh this webinar is being recorded and will be made
0:15
available um after to all registrants uh later this week. We know you’ll probably
0:21
have some questions for our speakers, so we reserve some time at the end for Q&A.
0:25
And you can submit your questions through the webinar by using the Q&A
0:28
button at the bottom. We’ll try to answer as many questions as we can live,
0:31
but if we don’t get to your question here, we’ll be sure to follow up with
0:34
you directly after the webinar. And with that, I’ll hand thing things over to
0:38
today’s hosts, Alex and Lewis.
0:42
>> Awesome. Thanks, Eli. Um, really appreciate it. Excited to be here today
0:46
and talking about uh a topic that’s near and dear to my heart, which is uh
0:49
helping to prevent account takeover fraud. So, uh my name is Lewis Gunter.
0:52
I’m the product marketer for the ATO defense product here at SIFT. Um, I’ve
0:57
been at SIFT for uh, two and a half years and uh, passionate about this
1:02
space and helping to protect people um, specifically innocent account users
1:05
online. Alex,
1:08
>> thank you. Hey everybody, thank you uh, for taking time out of your day to be
1:11
here for the webinar. My name is Alexander Hall. I am the newest trust
1:14
and safety architect over at SIFT. I have 17 years of fraud related
1:19
experience and that experience has been chopped up over a lot of different uh,
1:23
areas. I’ve worked with financial institutions, marketplaces, merchants,
1:27
uh, and everywhere in between in order to build holistic fraud prevention
1:30
strategies, and today I’m here to, uh, partner up with Lewis in order to
1:34
present with you or to you, uh, actionable insight that you can use in
1:38
order to build a defense for ATO’s. Very important stuff today. So, uh, again,
1:42
thank you all for being here. We’re gonna have a good session.
1:45
>> Awesome. Thank you, Alex. We’re, uh, we’re glad to have you. So, it’s great
1:48
to have you, uh, here. Fantastic. just a quick uh highlevel agenda of what we’re
1:53
looking at accomplishing today. So, first we are going to talk a little bit
1:56
about just the general state of account takeover and what’s driving some of the
2:00
trends that we’re seeing in in ATO. Um we’re also going to review some of the
2:04
key findings of a report that CIF puts out called the digital trust index
2:09
report um that talks about atto and some of the the trends we’re seeing both from
2:13
our customers and uh their end users. And then finally, we want to make sure
2:17
that you have something that you’re going to walk away with. Uh and so we’re
2:20
going to talk about three tactics you can start implementing today to better
2:24
uh size and manage your ATO problems. With that we’ll jump into it. So first
2:30
we’re going to talk a little bit about the state of account takeovers. Um one
2:33
of the findings that I wanted to highlight was that uh we continuing to
2:37
see substantial uh atto rate growth. So this is looking across our our customer
2:42
base and looking at what percentage across the entire network of our atto
2:46
defense customers. Um what percentage of login are atto attempts. Um this is
2:52
showing data up to Q2 Q2 2024. Um when you get to Q3 that number is now
2:56
approaching three 3.9% almost 4%. Um which is kind of kind of crazy to think
3:02
about. I remember when I first uh came into the world of ATO, this number was
3:06
down in the or the suspect number was down sub 1% uh even less than 50 pips
3:11
kind of in that neighborhood. Um Alex, what would you say are some of the top
3:15
factors that are driving some of this rapid growth of ATO?
3:20
>> So I think looking at it from the top down, uh really it all stems from the
3:24
data breaches, right? Over the past I think it’s been 36 months. I mean, data
3:27
breaches have been going on for a long while, but I think over the last 36
3:30
months, we’ve been seeing just a tremendous growth. Every couple of
3:32
weeks, we see uh new reports of data breaches happening. And I think that
3:37
within that uh all of the data that’s being breached and leaked out to bad
3:41
actors can break down into three primary categories. We have payment information.
3:45
We have PII information like names and addresses, social security numbers and
3:50
dates of birth. But then we also have that third category which is account
3:53
information. So this could be your login details. this is going to be a username
3:56
password combination, phone number password combination, etc. And I think
4:00
that well it’s not that I think this it’s it’s just the way it is
4:03
unfortunately with all this information flooding the market bad actors are
4:06
looking to see what they can do with these different types of information. So
4:10
specifically when we look at ATOS’s um the value that’s there is just
4:15
tremendous when you compare it to the workload that goes into into the work of
4:19
creating synthetic IDs or committing identity theft and creating these new
4:23
accounts uh versus if you look at payment information being leveraged by
4:27
by fraudsters they’re going to go to these platforms and we all know that
4:30
that’s where the majority of our defenses are built around the checkout
4:33
right and so fraudsters quickly realize that if they can access accounts if they
4:37
can use the compromised login details to go gain access to established accounts.
4:42
Uh they get a quicker route to value and and to your point that you just made. Um
4:48
now they’re seeing the value in it and it’s becoming a focal point. We’ve seen
4:51
it for enough for a long enough period of time for fraudsters to see the value
4:55
in it and so now they’re they’re actively targeting it as well.
4:58
>> Yeah. Yeah, that makes sense. And I think what’s really interesting that you
5:00
mentioned about the data breaches is, you know, we’ve had customers and we’ve
5:04
had prospects that we talked to that that have said, well, you know, we
5:06
haven’t been implicated in a data breach. we haven’t had a data breach,
5:10
you know, we’re okay, right? And and to them, it’s like, uh, Alex, maybe you’ve
5:14
seen more recent numbers, but you know, what percentage of people reuse a
5:18
username and password or phone number and password combination? It’s it’s
5:22
significant, right?
5:23
>> It’s shocking. Yes.
5:24
>> Yeah. Yeah. So, hygiene hasn’t quite caught up with the sophistication and
5:29
like you said, um, you know, fraudsters are like like like many of us and that
5:34
they want to get the best bang for their buck, right? where can I get the most
5:37
return for the least effort? Um, and so for them, right, like you said, versus
5:41
creating synthetic identities, etc., being able to take over an existing
5:45
account, a trusted account, um, there’s a lot of value that they can capture in
5:48
that. Great. Um, another thing, another trend that we’ve seen and and, uh, this
5:54
seems to be prevalent, you know, in in earnings reports and in every uh,
5:58
industry, everybody’s talking about AI and, uh, it’s no exception in the world
6:03
of of trust and safety either, right? So, um, more and more consumers, this is
6:07
another finding from the the DTI. Um, more and more consumers are concerned
6:12
about the the likelihood. Oh, I’m sorry. I jumped ahead.
6:16
>> We’ll get there. Dang it. I was so excited to talk about AI. Um, so this is
6:22
talking about what happens to compromised user accounts, right? And
6:24
that could be that a credit card or or stole or or credit card information is
6:28
taken from one site and then used somewhere else. Um that could be that a
6:33
transaction is h happens on the site that was actually compromised. Um or it
6:37
could be that there are you know a siphoning of of rewards points. So um we
6:43
kind of started alluding to this but but Alex what do you consider the value of
6:46
committing atto fraud over simply creating a new account right and using a
6:50
stolen credit card or whatever. Why are fraudsters finding more benefit uh in
6:55
going the ATO route? So, the first item that I like to bring up is the idea of
7:00
insulation, right? When a fraudster’s out there operating and they create a
7:04
new account, every single bit of that account was established typically
7:07
fraudulently. It’s not like they’re using their own information and then
7:10
they’re building off of it. At least the smart ones are not doing that. um by by
7:14
volume the the appeal of ATOS and taking over established accounts is insulation
7:19
because now the fraudster is able to operate under the guise of that positive
7:24
performing profile or that that that persona that’s associated with the
7:28
account. Um and then through that of course they’re able to move on to the
7:32
second and third steps which is one is to access stored value and as you just
7:35
mentioned that can be loyalty points that can be logging into a streaming
7:40
service subscription that can be logging into uh an account that has stored
7:44
value. Think about these digital gaming platforms that have stored wallets and
7:48
all these different things separate from stored payment information. I mean like
7:52
think about these gaming platforms that have stored points and stored coins and
7:56
and all of these different things. um they just get access to it. And
8:00
something something that I think about whenever uh I start discussing ATO’s is
8:04
that it’s it’s something akin to like getting access to a treasure chest,
8:08
right? These different accounts, this one’s going to have access to a
8:11
streaming profile. These ones are going to have access to stored funds. These
8:14
ones are going to have that. And it’s just really easy for fraudsters to uh
8:18
insulate themselves, one from detection, but then two to just get into the mix
8:21
without having to build, without having to uh uh associate new payment methods
8:26
and start to deposit funds and all of these different things. So the path to
8:30
value is is is very very very quick. And then in addition to that the execution
8:35
of ATOS is unique in that you can act fraudsters can access uh these
8:41
established accounts and take over these established accounts in a lot of
8:45
different ways right they can go to customer service they can go and log
8:49
into the login form they can call they can submit tickets and they can go
8:53
attack the consumers directly they can target the consumers directly in order
8:57
to get this information and coers them into these actions that give that give
9:00
them access to the accounts. And the reason why that’s so valuable fraudsters
9:04
is because when we first establish a fraud prevention program on a platform,
9:09
we focus all of our efforts on that checkout form. We see the chargeback
9:13
rates go up. We focus on the checkout because that’s where our correlations
9:17
lie. When we shift gears into atos, the whole platform becomes uh open to
9:22
fraudsters. And I think that that’s what unfortunately makes it easy for them.
9:26
It’s a quick path to value. And then of course they’re operating under the guise
9:30
of an established profile.
9:31
>> Yeah. Yeah. That makes a lot of sense, right? Like you’re not going to go stand
9:34
in front of the security camera to commit fraud, right? If they know that
9:37
there’s a lot of focus on the, you know, on the point of checkout, on the point
9:41
of transaction. Okay, maybe you step away from that.
9:44
What other ways can you extract value from a platform that do not directly tie
9:48
to that? Um, fantastic. Okay, now we get to talk about AI and some of the some of
9:52
the concerns that um that consumers are expressing, right? And you can see here
9:57
a vast majority of uh of consumers out there are worried about what the
10:02
emergence and the and this rapid iteration and growth of generative AI is
10:07
going to have on their ability to protect their accounts, right? I think
10:09
they’re all a little bit concerned. Um I know that there are lots of ways that
10:13
this has manifest from, you know, uh all the way from my parents have been called
10:17
multiple times now with someone whose voice sounds a lot like one of my
10:21
brothers, right? Claiming that they need cash and whatever. uh but but you know
10:27
it’s also being used in the world of being able to um spoof people’s uh
10:31
accounts and be able to log in via ATO via compromising accounts. So I guess
10:36
first off how like how validated would you say these concerns are like like if
10:41
you were to talk to these customers um how validated do you think their
10:44
concerns are regarding the role that that AI could play in driving additional
10:49
ATO?
10:50
>> Let me say one thing first. I am in fraud prevention. I am not a big big
10:56
advocate of the idea of like fear-mongering.
11:00
Not typically in this setting. Uh the fear around AI and other technologies
11:07
being employed by bad actors is wholly justified. Right. And and and I spoke to
11:12
it in a sentence before where now target platforms are not the only the platforms
11:18
are not the only target of bad actors. Right. Now, as you just mentioned, the
11:23
general public is being hit. The general public is being blasted through
11:27
automation, uh, you know, spam and all of that. They’re being blasted with that
11:31
form of automation. They’re getting phone calls with deep fake voices.
11:34
They’re getting video calls. These companies are getting these video calls.
11:37
There was that one um the the attack that was I think it was 30 million plus
11:42
that was lost through a deep fake uh video that took place uh along with
11:47
other actions but ultimately it was a deep fake video that really sold the the
11:51
internal agents on participating in all the scam and it is absolutely a new
11:57
level that where the fear is is wholly justified. Absolutely. And so when you
12:02
break it down in these two categories, you have the people, the general public
12:05
who get attacked in one way, which of course raises up the the need for them
12:09
to be aware of what scams and what uh spam can can do to them. But then you
12:14
also have the opposite side where businesses need to understand that it’s
12:17
not just forward- facing AI and deep fake and uh automation that’s attacking
12:21
their platform. It’s also attacking behind the scenes. So overall, in all
12:25
three of these dimensions, AI and general technology in the hand of bad
12:29
actors is definitely something to be concerned about.
12:31
Yeah. Yeah, it makes a lot of sense. Um, yeah, it’s it’s it’s crazy. And and and
12:37
what’s I think really kind of, again, not in the spirit of fear-mongering, but
12:41
I think what’s really scary is that we’re seeing the beginning of this,
12:43
right? There’s there’s um in the next we saw how fast it’s it’s gone from, you
12:48
know, Will Smith eating spaghetti to to what we have today. And we can only
12:52
imagine, right, that that in the next, you know, 18 months, like what it’s hard
12:57
to predict what exactly will happen and the tools that’ll be available. I know
13:01
um I’ve heard rumors of of 9year-olds in in other parts of the world who were
13:06
able to uh you know no longer be bound by in in in fraud 1.0 of the web, right?
13:13
It was pretty easy and and almost easy to make fun of, right? Uh Michael Scott
13:17
responding to a Nigerian prince, right? Like people being able to pose, but you
13:20
could always say like, “Oh, well, there’s weird punctuation and
13:22
capitalization.” Guess what? With generative AI now, that’s all gone. you
13:26
you could have the voice of a of a seasoned author uh uh you know spamming
13:31
and sending sending emails pretending to be someone else but using their their
13:34
voice and writing style. So it’s it really is incredible um to to start
13:39
thinking about what could happen here and uh and we’re just seeing the
13:42
beginning of it. Right. So
13:44
>> absolutely.
13:45
>> All right. Another insight from the uh digital trust index is um just basically
13:50
what uh what services what industries what platforms are getting most
13:54
frequently targeted uh for ATO. Now this is as reported by consumers right like
13:59
where are they seeing atto happen would love let’s get your thoughts on you know
14:04
we we kind of mentioned that in in in the world in worlds past in times past
14:09
it was easy to say okay well we’ll look at transactions and when we look at the
14:13
transaction the point of transaction we can protect both against synthetic IDs
14:17
uh new accounts being created with stolen credentials right and ATL we kind
14:21
of bucket all those into one sort of fraud and like as long as we’re pointing
14:24
the transaction we’re probably Okay. Um, but I’d love to looking at at these
14:29
industries specifically,
14:31
>> you know, where are you seeing uh the ways where fraudsters are being able to
14:35
extract value out of a of a platform um that would never result in an in a
14:41
chargeback, right? That wouldn’t be just at the point of transaction, but
14:43
wouldn’t and and wouldn’t result in a chargeback.
14:46
>> Sure. So, I think uh before I hop into the three top mentions, I think one
14:50
honorable mention is the one that you you you noted uh up at the top of the
14:54
call, which is um airlines, they’re getting hit for the loyalty points,
14:58
right? When those loyalty points are spent on the account, there is no charge
15:01
back associated with it, right? And so these atto accounts uh were wreaking
15:05
havoc for the past several years, ever since, you know, the co everything that
15:09
happened with COVID, everything afterwards, loyalty points have been
15:11
have been hit really hard. So, that’s the honorable mention. Now moving into
15:15
the three uh categories that I feel are the most important are going to be
15:19
social media uh fintech and financial institutions and i gaming right so if we
15:24
start with social media think about an influencer think about uh a politician
15:29
think about a band or a brand right and what kind of damage can be done when
15:35
they get access to that account imagine for example that a brand gets a brand
15:39
account gets hijacked on uh Instagram and the link that they that they link
15:43
out to is actually a a fake website, right? So, you see a post from Walmart
15:48
pro promoting some $500 TV. That’s a huge great deal. Awesome. Well, then
15:53
somebody clicks that link and it’s actually a website that a fraudster set
15:56
up. Well, that’s not going to be represented in your chargebacks. Think
16:00
about the implications for, you know, the politicians. Think about the
16:03
implications for uh, you know, the the Logan the Logan boys, right? When
16:08
they’re coming out and they’re sharing their links, you know, selling their
16:11
prime products, right? and all of the damages that can be done that is not
16:15
going to be represented in chargeback. So that’s number one. Number two is i
16:18
gaming. Um we all know this is a booming booming industry. It’s taken off. It’s
16:23
flying. Uh users jump from platform to platform to platform and they’re heavily
16:27
motivated by the policies and the promotions and the discounts and and all
16:31
this different stuff. If we’ll imagine um in a similar fashion, one of these
16:35
platforms accounts gets attoed and their promotions go out and that that excites
16:40
their user base and now they go to a different website and it’s not theirs.
16:43
That’s one. Two, once the user gets access once the fraudster gets access to
16:48
an established eye gaming platform and they go to withdraw funds that have been
16:52
sat there, well, that’s not going to be represented in chargebacks. And then
16:55
let’s look at the the the one that for i gaming the one that is represented in
16:59
chargebacks which is for a user to get access to an established account and
17:03
then start depositing funds through a and third party apps and and credit
17:07
cards and debit cards. It can just be a flood all the while
17:12
they’re being insulated because they’re not providing their they’re not starting
17:15
the account from scratch. They’re not under heavy scrutiny. Right.
17:19
>> Yeah. Yeah. Oh, go ahead. Oh, and then it’s just similar for
17:23
fintech and financial institutions because again under the guise of
17:26
installation now a fraudster can take stolen checks and deposited it into this
17:30
account. This fraudster can add authorized users, send out new books of
17:34
checks, new authorized cards or new secondary cards for secondary accounts.
17:38
They can establish secondary accounts. The the when it comes to ATOS attempting
17:44
to handle ATOS through the funnel of chargebacks is just not effective. Not
17:49
not on the whole, right? there are going to be instances where chargebacks uh
17:54
will result after an ATO. Um but it doesn’t represent the majority of
17:58
actions fraudsters can take.
18:00
>> Yeah. Yeah. You bring up some really great points. I um I know that as uh I
18:05
first kind of got into this world and was explaining to people you know what
18:08
what the product was and what we did at SIFT um I you start hearing the stories
18:14
right of people who are in that situation where they had their um one
18:18
person had a formerly Twitter account that got compromised and they used some
18:23
email address that they set up you know years before and hadn’t really thought
18:27
about it and uh just didn’t think about it. Obviously, probably a case where
18:31
they were reusing a password. Um, their account was compromised, uh, likely as a
18:35
result of, you know, credential testing from another data breach. Somebody was
18:38
able to go in, get access to her account, and, uh, started just posting a
18:42
lot of adult content, right? And, uh, this is not the type of content that
18:46
this friend would, uh, typically post. And, uh, you know, they were linking off
18:50
to, you know, an only fan site or something, right? But they were they
18:53
were posting a lot of adult content. And the worst part was because of the the
18:57
prominence of uh of Twitter, when you would Google this person’s name, the
19:02
first result was this Twitter account that they no longer had access to. And
19:06
because they didn’t have the email address anymore, they’re like, I can’t
19:09
even remember the email address credentials. So, like, I can’t get into
19:11
the email to reset a password to to get it back. And Twitter basically said, you
19:15
know, customer service was like, well, sorry, that that kind of sucks, but um
19:19
and now they don’t even exist probably since they’ve uh been slashed. But um
19:23
you know you think about that damage that uh you know the likelihood of that
19:27
person to come back to that site is near zero. Um but it also you know it can it
19:32
can cause damage that’s that’s farreaching that has very little to do
19:35
with a single point of transaction an order um etc. But it causes you know
19:39
brandwide reputational damage as well.
19:42
>> Absolutely.
19:42
>> We’ll come back to that. We’ll come back to that as well. Fantastic. There were
19:46
just a couple more points that I wanted to touch on from the uh the digital
19:49
trust index as well as a a resource that we have called the fraud index
19:53
benchmarking resource or fiber. Um this is just a great way to get a sense of
19:58
you know where your industry or where you sit in regards to your industry when
20:02
it comes to ATL. We’ll jump into that uh in just a second. But one of the points
20:06
that I wanted to bring up and I started touching on this right is that uh
20:10
consumers reported that 80% of them at least said they would not use a site
20:14
again. they would not make another purchase on a site. Um, and I believe
20:17
that could be extrapolated to say wouldn’t make a purchase, wouldn’t use
20:21
again, wouldn’t recommend, wouldn’t promote, right? Like like they go from
20:24
users and fans to uh absolutely being uh you know appalled or or or just you know
20:31
completely rejecting their their association with a brand or a platform
20:35
after being atto. Um, and that’s a you know that’s a shocking number. The other
20:39
thing that’s kind of scary about this is, you know, traditionally if you think
20:42
about fraud and you’re just protecting a transaction, right? You may think like,
20:46
okay, we can protect a transaction, block a user, right? If that’s a
20:49
fraudulent user, block the user, they’re gone. The challenge is if you measure an
20:54
ATO, a bad transaction via ATO the same way that you measure a bad transaction
20:59
with a fake account, well, they’re very, very different values, right? Because in
21:03
the world of an ATO, you’re not just stopping a single point of fraud. you’re
21:08
stopping basically you’re taking into uh or discounting all of the the future
21:13
purchases that that user would have made on your site or the future interactions
21:17
on a social media platform, right? The future engagement that they would have
21:20
had, the future ads they would have seen, however you’re monetizing that
21:22
user, that’s all gone now, right? So, it’s that customer lifetime value that
21:26
that just evaporates as soon as that player or that person’s atto. The other
21:30
the other challenge is that the uh you know and a lot of times trust and safety
21:34
teams aren’t thinking about this but there was a cost associated right there
21:37
was marketing spend that it takes to bring that user to your platform in the
21:41
first place right and now some marketing some poor chaps in marketing and you
21:45
know sympathy to him being a product marketer you know some other marketers
21:48
are going to have to go out and figure out how to replace that customer right
21:51
they’re going to have to bring new customers on to replace the revenue that
21:54
was lost in addition to that their job just becomes harder because as you know
21:58
right like Like almost everybody who gets impacted by an atto does not keep
22:03
it to just themselves, right? They share they they share their experiences and
22:07
whether that’s word of mouth, you know, one-on-one with other people or whether
22:10
that’s posting it on social media on another platform, right? And saying
22:13
like, “Hey, my account was hacked.” And talking about the negative experience
22:16
they had, it’s uh it’s almost impossible to define like the true reach of the
22:21
negative impact of of atto. Um but it’s much bigger than just the single
22:25
transaction. Of course, this is we’re not talking about this. That’s one thing
22:29
that I always spoke about when I did my uh my other webinars when I was by
22:33
myself and that was the idea that we have session security, we have account
22:37
security, we have transaction security, we have platform security, right? And
22:41
all of those things together are required in order to uh they need to
22:45
dance in this this this nice balance in order to make sure that both our
22:48
customers are protected and that we maintain a uh a good customer experience
22:53
for them. And to your point, when you when you alienate on an account basis or
22:58
you allow for an account to get uh damaged on an account basis, it’s not
23:03
just that transaction anymore. And it’s not just that account, it’s not just
23:06
that person anymore. It’s their friends, it’s their family. Brand trust plummets.
23:11
Uh and it’s a very big deal that extends far beyond uh just the financials.
23:16
>> Yeah. Yeah. Absolutely. Um, one other thing I wanted to mention was, you know,
23:20
obviously one of the most powerful tools to help combat ATO is is 2FA multifactor
23:25
off. Um, so one thing that we’ve seen is there has been, you know, drastic uh
23:30
increase in 2FAS being sent out. Now, this isn’t shocking, right, given the
23:34
overall trends. Um, and the one thing that we that I wanted to mention here
23:37
was just that, you know, 2FA is is imperfect but really powerful, right?
23:42
It’s imperfect but good. Um and we do encourage people to you know think about
23:46
the role that 2FA or multifactor authentication um will play in in a in a
23:51
holistic ATS strategy. Um, but the the challenge is especially in an industry
23:57
where the switching cost is not super high, right? If somebody can go from
24:00
your site and say, “Boy, man, I like these guys, but every time I log in,
24:05
they they 2FA like every time, right? If you’re if you’re adding friction to the
24:08
user experience, and they can jump ship to go somewhere else, boy, they’re sure
24:12
going to consider it, right? Because uh, you know, people are more and more
24:16
consumers are more and more comfortable with 2FA, with you know, that SMS,
24:19
getting the getting the text, getting the email. they’re increasingly
24:22
comfortable with it, but it’s still an additional step, right? And it’s still a
24:26
negative customer experience for them. And so, uh, the thing that we want to
24:30
think about is like, well, how do you make sure that you maximize the the
24:33
value you’re getting out of a 2FA? How do you make sure that you’re introducing
24:36
a 2FA only at the right times, right? Like, like what are the factors you
24:39
should be looking at to know when to 2FA versus when not to FA? Um, because yeah,
24:44
obviously nobody wants to introduce just like blanket friction, right? If you
24:47
wanted to require a retinal scan every time somebody logged into their eye
24:50
gaming site, like sure that might make security topnotch, but it would also
24:55
mean that people just jump to other platforms where you didn’t have to do
24:58
that every time because that would be really obnoxious, right? Um, anything
25:01
that you want to add to like, you know, this need to balance you. I love the way
25:04
you talked about it. There’s a dance, right, of adding the right amount of of
25:08
friction and balancing that with platform security.
25:11
>> Oh, absolutely. But you nailed it. I don’t have anything to add. I would just
25:14
simply reinforce that whenever we start talking about new technologies and new
25:18
implements like the 2FA or the MFA. Uh we it’s it’s it’s we’re initially going
25:24
to paint with broad strokes, but we can’t disregard the idea that we need to
25:27
then refine it, right? So let’s start let’s let’s put something down that’s
25:32
going to be fundamentally effective. Let’s make sure that we can catch this
25:35
bucket, but then within that bucket of of caught good or bad depending on what
25:40
we’re identifying, let’s make sure that we refine it as best as possible. So,
25:43
we’re keeping the bad guys out, but allowing the good guys to to do as they
25:47
please because that’s what they deserve to do.
25:49
>> Yeah, absolutely. All right. And then finally, I wanted to touch on um this is
25:53
the uh the fraud index benchmarking resource. So, this is something that we
25:57
released uh starting last year and we’re we’re continuing to update it. Um and I
26:01
will tease that actually tomorrow. Uh there’s a big update coming out
26:05
specifically on the the payment fraud data side. Um there’s some really
26:08
interesting breakouts that we’re now going to be sharing around fraud and uh
26:11
fraud happening by payment type and you can also filter that by industry similar
26:15
to how you can do in the current version of fiber here. You can you can drop down
26:18
by industry. Now in the world of uh account takeover data um what we have
26:22
here is uh two major uh numbers that we published with trends over time. One is
26:27
the overall atto attack rate. Uh as I mentioned now this has gone from you
26:31
know 3.6% in Q2 up to it’s not highlighted here but 3.9% in Q3. um that
26:37
number continues to rise. And now this is the overall percentage of of you know
26:41
if there’s a hundred loginins we’re now saying that four out of every hundred
26:44
loginins is an attempt um by a fraudulent user uh or an unauthorized
26:49
user to log into an account which is kind of mind-blowing. Um the way I think
26:53
this is useful is you know one of the things that we hear frequently from
26:56
prospects is like well we haven’t had a big data breach. we, you know, we get
27:00
customer service calls that uh that report, you know, there was there was an
27:04
atto um but it’s, you know, we maybe get 100 calls a month or something, right?
27:09
So, it’s like it’s managed. It’s manageable, right? It’s a manageable
27:12
amount. Um the reality is if you want to use this to try to extrapolate like well
27:17
the you know the actual likelihood or what’s probably actually happening is
27:22
that there’s a significant number of login that are happening that are not uh
27:26
being captured in a in a CS call right um in fact most likely the vast majority
27:32
of these atto are just going unnoticed and so one thing that we encourage
27:35
people to do is go look and say hey if you think that your atto attack rate is
27:40
like here and you come and you see that the industry is here there’s a chance
27:43
that you’re just missing a lot of uh potential atto attacks. So the other
27:48
thing that we highlight here is two-factor authentication rate. So if
27:50
you want to get a sense of like how often should we be 2FA um this is just
27:54
an opportunity for us to kind of share uh in an aggregated data sort of fashion
27:58
across Sift customers um what we’re seeing as the as the industry based or
28:03
industry based attack rates and the two-factor authentication rates. Um
28:06
really great resource. Again, encourage you to go check it out. If you go to
28:08
sift.com it’s just on the on the main page. for fiber and uh and you can
28:12
filter you can get all this information by by industry um both in the payment
28:16
space and in the ATO space.
28:19
>> You brought up a really good point centered around data, right? And that
28:22
that what we’ve identified is X, but what is true and real it might be Y and
28:26
those numbers might be there might be a huge uh uh disparity between those
28:31
numbers, right?
28:32
>> And it reminds me of a story that I had where somebody came to me and they said,
28:35
“Hey, we’re trying to figure out, you know, what we should do about this
28:38
friendly fraud situation.” And this is this is about data and
28:41
miscatategorization. They came up and they said, “Hey, who do you recommend
28:44
for friendly fraud?” Started asking questions. Started asking questions. The
28:47
big thing that pointed out to me that they pointed out to me was that these
28:50
established accounts were resulting in chargebacks after having been
28:53
established for years. Now we’re getting a bunch of chargebacks that are fraud
28:56
coded. So they assumed it was friendly fraud. After digging in and establishing
29:00
data, as you were just saying, monitoring the data and looking for
29:02
these signals, we identified that the target accounts had been accessed by new
29:07
devices, had associated new payment methods, which then resulted in
29:11
chargebacks. And so what we found by by by building out the data and trying to
29:16
really get a clear picture of what was going on, we found out that what was
29:19
previously categorized as a friendly fraud attack was actually an atto attack
29:23
and we were actually to find the root cause and solve the problem. So data is
29:27
tremendously important. Uh I just wanted to reinforce that.
29:30
>> Yeah, absolutely. Um that’s a great segue too into talking about, you know,
29:34
using SIFT ATO defense as a unified platform. Um I wouldn’t be doing my job
29:39
if I didn’t get to share some of the stuff I’m excited about uh when it comes
29:43
to um SIFT and and the platform that that we’ve created to help basically
29:48
combat atto. and uh specifically want to share a couple of the innovations uh
29:52
that are driving I think some of the ability of our customers to get even
29:56
more value out of the ATO product. Um I don’t I won’t spend a ton of time here
30:00
because I do want this to be valuable as a webinar and not simply a pitch for
30:04
Zift ATO defense. Um but there are a couple things that I’m excited about
30:07
like you said you know it’s all about data and how you organize and arrange
30:10
that data specifically in the world of atto. trend that we’ve seen right is
30:14
that there’s there’s a little bit of a gray area right and uh a lot of
30:18
companies will will handle ATOS’s very differently in some in some
30:22
organizations it will reside with the security persona it’ll be it’ll be under
30:26
the ops of the CISO and part of you know security and upstream in some places in
30:31
some places it’ll be more on the fraud or it’ll be under payments because they
30:34
see you know the chargebacks that are a result of atto and so you know every
30:38
company’s a little different how they structure but one thing that we’ve seen
30:41
is fairly consistent is a lot of companies feel that they have a big gap
30:44
to address regarding uh how they go about analyzing, right? Getting all that
30:48
data into a single place, a single source of truth that everybody can
30:51
collaborate on and work together on and kind of start to see trends. Like how
30:55
hard would it be to see those trends if you had to start building from scratch,
30:58
you know, as you mentioned in the example before, right, of being able to
31:02
see the trend of like, oh, actually what we’re seeing is that these chargebacks
31:05
are the result of established accounts but with new payment methods, right? So,
31:09
so CIFT creates a platform where you can bring all that together. You know, we we
31:13
pull this because uh we know that historically um another thing about
31:17
ATOS’s is uh you know, we called this webinar stop the drip, right? And the
31:20
reality is uh atto happens in both little drips but then also giant floods,
31:26
right? So, it kind of comes in in in like steady state atto and then there’s
31:31
also, you know, big bursts where there’s uh credentials or or a coordinated
31:34
attack. And so what’ll frequently happen is atto kind of gets swept under the
31:38
rug, right? People are thinking about operationally how do we handle the
31:41
day-to-day, you know, fraud. We have we already have our review cues. We’re
31:45
looking at, you know, analyzing a bunch of different fraud vectors. And so
31:48
they’re thinking about day-to-day and then when an ATO hits, it is just a
31:52
disaster, right? And if you’re using older technology or you don’t have your
31:56
data ducks in a row, right? If you don’t have the ability to to coordinate and
31:59
have all those platforms um all the different participants u an
32:05
investigation into what actually happened like in a cyber security breach
32:07
in atto can take over a month right that’s this is an a an average based on
32:12
a baker hot settler uh research they did last year so if you’re not using the
32:18
right tools the right platform then this can take a significant amount of time
32:21
which is one of the reasons that you know I’m so proud to be working with our
32:24
team here at sift really proud of some of the innovations that they’ve also um
32:28
added recently with regards to atto and the ability to look at sessions. Now,
32:32
one of the things that sift has done very well in the past is they they look
32:37
at the point of transaction, right, and look at users and accounts. Um and one
32:42
of the things that the our team has done recently has been to elevate session
32:47
level data to get that same sort of treatment as users and transactions.
32:52
Right? Users and transactions are great for analyzing that kind of point of
32:55
transaction fraud, right? Is this a bad payment? Is this a bad user? If so,
33:00
block them, you know, like reject like reject the transaction, block the
33:04
account. But in the world of ATO, obviously, you can’t do that. And so,
33:06
you need a set of tools that will help you work at a session level. And so
33:11
they’ve rolled out a series of uh just in the last quarter they’ve rolled out a
33:14
series of enhancements that give uh SIFT customers that same session level uh
33:19
sort of detail that we already had for transactions and users. So really proud
33:24
of that. Um, and you can imagine, right, if you’re if you’re moving from a, not
33:28
that anybody on the webinar would necessarily be in this situation, but if
33:30
you’re moving from spreadsheets, right, and you’re using, you know, exported
33:34
spreadsheets and trying to go through data sets and like SQL dumps and going
33:38
from that to something like this where you can actually see all the login, all
33:42
the sessions where you can quickly drill down, where you can take actions on it.
33:46
uh it’s it’s a really powerful platform for bringing that together and where you
33:50
can have multiple users from multiple groups within your organization all
33:53
working from the same data set all working on the same source of truth. Uh
33:57
anything Alex you want to add there? Yeah, this is something that actually
34:01
really excited me about SIFT is the the empowerment of the users, right? And
34:05
then when you couple that with the idea of sessions, I feel that it’s wildly
34:10
powerful because at the same time that we’re trying to identify what is through
34:14
a network being identified as as you know suspicious for for X Y and Z
34:19
reasons, right? We empower our users to identify what’s good, right? And nobody
34:24
knows anybody’s platform better than the people working at the platform
34:27
themselves, right? We can provide amazing insight from the network. We can
34:30
provide amazing insight from our cohort models. But the subtle tiny little
34:35
changes that have a great impact are going to be done at the uh the analyst
34:39
level, the ones who are telling us what’s good and what’s bad in these
34:42
subtle little cases. And I think that empowering our users is something that I
34:46
definitely stand behind, especially when we start to consider sessions and we
34:49
start to break away from the thought that all fraud results in chargebacks.
34:53
Suspicious session behavior being brought up to the surface and bubbled up
34:58
is going to empower users uh a lot more than than many other options.
35:03
>> Yeah, absolutely. Um the other side of the coin uh and some of the changes that
35:07
have that have uh recently again been rolled out uh on the sub platform is
35:11
it’s not just about the ability to analyze and look at what’s going on.
35:15
It’s the ability to incorporate uh friction at the right points. Right?
35:20
So, one very specific use case, a customer came to us and they and they
35:23
said,”Well, look, we uh we’ve seen that there’s increased risk in um dormant
35:30
accounts, right? They they haven’t logged in in 6 12 months and we’ve seen
35:33
that there’s, you know, some behavior that’s happening where, you know, these
35:36
accounts are potentially being compromised and they didn’t want to
35:39
simply, you know, introduce a lot of friction. Say you haven’t logged in for
35:42
a number of months. They wanted to still reduce friction as much as possible and
35:45
they didn’t want a 2FA just at login. So, one of the things that we’ve
35:49
recently rolled out is the ability to look at session level data and creating
35:52
these what we call workflows, right? These are like the rule sets that you’ll
35:55
see on other platforms, but basically taking, you know, looking at user
35:59
behavior and then being able to do a certain action based on that. And so
36:02
instead of just saying, “All right, we’re gonna, you know, like throw a a
36:05
big 2FA wall at login, so everybody has to be doing 2FA,” we can say, “Well,
36:10
they they notice a trend where in these compromised accounts, and like you said,
36:14
it’s all about like knowing your your business and then being able to react to
36:18
those trends that you’re seeing, right?” Um, in this case, they noticed a trend
36:21
that within 30 seconds of login, within 30 seconds of login, without fail, it
36:26
was like consistent behavior. they would see that they would go to uh account
36:30
details and they would update account details, right? They would they would
36:33
change an email address, change contact information, right? That was the first
36:36
thing they did immediately after login. And they started to see this behavior
36:39
and they said, “Oh, well, here’s what we can do. We can introduce a 2FA, not
36:42
necessarily, you know, slapping everybody with a 2FA wall at login, but
36:47
if they log in and we’re a little bit suspicious, let’s 2FA before they can
36:51
update any user information, right?” And so this is something we called at beyond
36:55
login. Um but it’s basically taking information like session session since
36:59
login in this session and being able to you know introduce friction only at the
37:04
point of uh of users taking certain behaviors and and very and getting very
37:08
specific about when you want to introduce that friction to create you
37:11
know the best customer experience that you can while also being able to react
37:15
to the to the trends that you’re seeing.
37:17
>> Exactly. It allows us to paint uh processes and workflows without a broad
37:21
brush like we were talking about before. If everybody gets a 2FA every time they
37:25
try to log in,
37:26
>> it’s a mess. But you don’t want to turn it off entirely. So, we want to avoid
37:30
painting with broad broad brush strokes and we want to start making it as
37:33
detailed to our uh organization as possible. We want to make sure that it’s
37:37
as accurate as possible and through workflows we’re able to accomplish that.
37:40
>> Yeah, absolutely. And then finally, um we recently announced as Zift is uh now
37:45
creating low code integrations into some popular SCMs including ping identity. So
37:49
via the da Vinci workflows they have um or ozero by octa. So if you know
37:54
customers or prospects are using these currently for identity management for
37:57
their consumer identity management um but then and you know potentially using
38:02
it for MFA to FA. Um they no longer need to do a full integration with SIFT. Um
38:07
they can now pass the information or the information go from ping or from Ozero
38:12
directly into SIFT and then leverage that global network. And basically what
38:15
this is doing is uh increasing the ability because SIFT has a I’ll like
38:21
trying to to not overstate this but an incredible amount of data on on
38:28
successful on like what we call safe looking IPs devices right we have this
38:32
global network um that has a lot of insight and information so when when
38:37
we’re past a small amount of data we can leverage that existing you know with
38:41
years worth of of labeling and and billions and billions of of uh
38:46
transactions and events, right? Uh we can pass that information basically
38:51
supplement the ability uh of someone using a ping or an oz zero to quickly to
38:56
quickly assess, okay, is this a high-risisk or a lowrisk uh login? Is
39:00
this a high-risisk or low-risk event where they can call that score at any
39:03
point in their in their own workflows? Um really exciting. I know again one of
39:07
the biggest things we hear is like especially in trust and safety teams
39:10
everybody feels strapped for engineering resources right uh it’s it’s always a
39:15
challenge to uh to get the engineering resources in fact we hear a lot of our
39:19
customers say like look I get one atbat a year basically so if it’s not this
39:23
tool it’s like this other big feature that we’re asking for uh and we know
39:26
that this is a constant struggle in the world of of fraud prevention um and so
39:31
yeah I’m really excited about some of these partnerships and excited to see
39:34
what this does to open up the power of that SIP global network to customers
39:37
using these these scans. Okay, I promised not to be too much of a
39:41
pitch. So, let’s let’s shift gears again and uh Alex, we’re going to talk about
39:46
some of the things that people can get started on today, right? Uh in addition
39:49
to yes, come and talk to a SIFT account representative. We’d love to we’d love
39:53
to chat. But what are some things that organizations can do today to start
39:57
getting a handle on uh both sizing their atto challenges but also starting to
40:03
think about how they can mitigate and protect against bigger atto waves to
40:06
come. the number one Alex.
40:10
>> So yeah, first and foremost, ATO’s as I hope that I I painted this picture
40:14
earlier, ATO’s attack the entire platform, right? Anywhere where an
40:17
established user can transact or interact or engage or change or
40:21
influence the back end of a platform or any of the operations of the platform, a
40:25
fraudster’s going to try to monetize that access. Right? So whenever we come
40:29
to solving ATOS, we need to get out of the mindset that ATO’s only live at
40:35
checkout or at login. Apologies, they only live at login, right? There’s
40:39
plenty of credential stuffing out there that does exist. So, yes, let’s make
40:42
sure that that fits into our road map. But in addition to that, let’s look for
40:46
suspicious behaviors leading up to logging in. So, maybe contact customer
40:50
service, calling in, social media, uh, tickets, um, whatever it might be that
40:56
they interact with the platform prior to logging in. But then as Lewis had
40:59
mentioned, let’s look at these different behaviors that that happen during the
41:03
session after login that will definitely identify to us what suspicious behaviors
41:08
are happening and might be seen as evidence of an ATO. Now, in addition to
41:12
going to moving away from um just login and make sure to include login and make
41:18
sure to move away from only chargeback, be sure to include chargeback. What data
41:23
sets are we going to use that can track all of this? And so I feel very very uh
41:27
heavily right about the fact that we use passive data sets. Passive data sets
41:32
like device intelligence and uh user uh behavior analytics right these are
41:37
things that users good users are just going to interact with the platform. We
41:41
can collect we can identify we can identify velocities. We can identify new
41:45
devices. We can identify um strange behaviors just with them interacting
41:49
with the platform. We don’t have to ask them to step up. we don’t have to do any
41:52
of those different things until the need is called for. Right? So to wrap all of
41:58
that up, let’s get holistic coverage. Let’s understand where these users can
42:01
uh can interact with the platform either before a login or after. Let’s get a
42:05
holistic coverage. Let’s use data that is passive, something that users can
42:10
just interact with and we track that behavior uh uh on onto ourselves. Um and
42:16
we benefit because then it’s low friction and it’s high accuracy, right?
42:19
Right. It’s things that we can rely on. So I would definitely recommend uh
42:23
getting a holistic view using passive data.
42:25
>> Yeah. Yeah. Absolutely. And then you know uh like I mentioned and like you
42:29
said right like this is not this is not a light lift. This is not like oh like
42:32
you know snap your fingers and at solve because now you have a view but it’s the
42:36
work it’s the investment that you have to do if you want to take atto attack
42:39
seriously and prevent or prevent um and protect yourself against the the big
42:43
atto attacks. The other thing that I want to call out is like you said the
42:46
holistic view is not just trying to have a single team uh looking across the
42:52
entire you know user session and the data sources across a session it’s the
42:56
recognition that it can’t live with a single team right if you’re trying to
42:59
handle this in a siloed fashion um because it is because it touches
43:03
customer service because it touches payment because it touches fraud because
43:06
it touches security you know atto cannot be a single team’s responsibility with
43:11
like you know hard silos those teams are the ones that or those organizations are
43:15
the ones that are most likely to to be susceptible to the bigger attacks and
43:19
having the the bigger negative impacts from the attacks because they’re slow to
43:23
react because they’re because there’s um no comprehensive and holistic strategy
43:27
in place, right? And so our encourage or or I guess what we want to encourage is
43:31
just, you know, start looking at it holistically and start, you know, if you
43:34
have those silos, start doing what you can to break those down within your
43:38
organization. you know, work together on building a task force, work together on
43:42
building uh, you know, a cross a crossf functional team that is looking at ATO’s
43:46
holistically and the ways that they could be impacting um because it doesn’t
43:50
just live with one team. Right.
43:51
>> Right. 100%.
43:54
>> All right. Action number two. So in addition to just identifying what can be
43:59
done, let’s look at what value can be extracted from a platform. Now we’ve
44:03
gave four different examples from different industries. Um I think you
44:08
were going to speak to the health platform one. So you go right.
44:10
>> Yeah. Yeah. So that’s right. That’s right. So basically, right, if you’re a
44:13
platform that thinks, well, you know, nobody transacts here, right? So why
44:16
would why would we be super concerned about um people transacting here uh or
44:21
kind of not our problem, right? And part of this just goes down to being a good
44:25
citizen of the internet in addition to obviously like legal exposure and so
44:28
forth. The challenge here is uh and and what we want to do kind of with this
44:32
question is is put yourself in the mind of a fraudster, right? If you were
44:36
thinking, okay, what good is it to give to get access to, for example, a health
44:40
platform? Well, think about the value of of PII that’s stored in a health
44:43
platform, right? And whether or not they’re actually transacting or or
44:46
committing fraud on your site, the responsibility you have to your
44:50
customers um to go and to protect that data. And it’s not just about the health
44:54
data, right? It’s about it’s about visits and where they are and
44:58
appointments, right? There’s a lot of things that that a a crafty fraudster
45:01
could figure out without ever updating uh a password, without ever changing
45:06
credentials, without ever transacting, right? Like if you’re a health platform,
45:09
you likely don’t have a transaction portal on your site. Like there’s no
45:13
point of transaction, but there’s a lot of value there. And right, so one of the
45:17
roles is uh or one of the roles that we all play is to be, you know, good
45:20
internet citizens. Um, in addition to obviously, right, the need to do it from
45:25
a legal exposure perspective and so forth, right, and and compliance and
45:28
HIPPA and and uh and so forth, it’s it’s thinking about um put yourself in the
45:33
shoes of the fraudsters. What would I be able to do with access to to this
45:36
information on a health platform, even if the fraud isn’t happening on a health
45:40
platform?
45:41
>> Absolutely. uh for financial services and fintex. Uh
45:45
as I mentioned above, imagine when a when a user when a user’s account is
45:49
compromised and a bad actor gets in and they start to add an authorized user to
45:53
a spending card, they they ship out a secondary card, they add a sub account,
45:57
they order a new book of checks. My question to everybody in attendance who
46:01
might represent this industry is would you be aware of that? Would that get
46:04
automatically reported? Is that something that your data is showing to
46:08
you? You know, after a clean uh login with a, you know, with a good username,
46:13
password combination in a in a in a region that’s local to the user,
46:18
geoloccation fits and lines all up. Well, when they start sending out new
46:22
cards and new books of checks and all these different things, is that
46:25
something that your system set up to do? That’s a direct path to value for a
46:29
fraudster. And now all of the funds in that user’s account is up for grabs by
46:33
the by the fraudster. Um, so yeah, for finance for financial services and
46:37
fintex, I would definitely recommend getting your data your eyes on those
46:41
types of behaviors.
46:44
>> Awesome.
46:45
>> Yeah. And then finally, oh
46:47
>> yeah,
46:48
>> take over, man.
46:49
>> I was going to say, sorry. So finally for for in in the world of social media
46:52
right we talked about um you know popular compromised account we talked
46:56
about the the world of the politician the world of the and especially you know
47:00
combine that with that factor that we or with the element we talked about before
47:04
with generative AI especially in the world of a popular um like a popular
47:09
user on a social media platform. You want to talk about Logan Paul, right?
47:12
Like Logan Paul has so much content out there. It would be very easy to create
47:16
custom video, audio, text that would all match the look, feel, voice, etc. of a
47:21
Logan Paul. Now, obviously, not everything’s going to be at that that
47:25
scale, but think about if you are a social media platform, like what could
47:29
someone do uh that would not necessarily show up uh with customer service or
47:34
might take a long time to show up with customer service, right? Like how much
47:37
could a fster get away with if they had one week with a compromised account,
47:40
with a a semi-popular social media account, right? Like what could they do
47:45
if they had just an hour or a day, right, with somebody that has hundreds
47:48
of thousands or millions of followers? Um there’s there’s just a lot of ways
47:52
that that this could and and the reason that you want to think or put yourself
47:56
in that mindset is, you know, like like Alex was saying before, like would would
48:00
your systems would your current systems catch that until after the damage was
48:04
done and you either had a PR nightmare on your hand or you had, you know, a
48:08
massive uh customer support issue, right? Like like would you be able to
48:12
catch that? What would you be looking for? Um any anything else to add, Alex,
48:16
on that one?
48:17
>> No, you hit it. It’s it’s think about all the businesses who are trying to
48:21
start up their their their social media presence and they’re they’re doing their
48:24
best and then somebody comes in and takes over and and redirects all the
48:28
traffic that they would have been getting. Imagine the the extension of
48:31
brand reputation of that company.
48:34
>> Yeah.
48:34
>> Right. And then on your platform from the company, you know, being
48:38
dissatisfied with the service, the there’s dimensions of damage that’s done
48:42
that are not tied back to chargebacks. I think that’s that’s my biggest takeaway
48:46
when it comes to ATOS’s is just the dimension of the the the damages that
48:50
can be done that are not represented in chargebacks. It’s wild.
48:53
>> Yeah, absolutely. Okay. And then the final final action item here is just to
48:58
think about um your end users, your consumers being the best source of truth
49:04
when it comes to identifying atto. Uh, in the world of transactions, if you’re
49:08
thinking about transactions or orders, right, you probably have some process in
49:11
place where you have well-trained analysts who are good at their job, who
49:14
are who are probably overworked and and in their minds underpaid, right? Um, to
49:19
uh to to sit and look day in day out at fraudulent transactions, evaluate, you
49:24
know, use their use their human judgment, use a set of criteria and
49:27
their judgment to say, “Yep, this looks good or this looks bad.” In in the world
49:31
of atto, it’s almost impossible for me to know if I’m if say I’m a well-trained
49:36
analyst, uh, Alex logs into my site and he logs into my site the next day, but
49:41
the next day he’s on the other side of the country. He’s on the other side of
49:44
the state. He’s on the other side of the world. Is this Alex? Could I know just
49:48
from looking at that and saying like, okay, I mean, short of, you know, him
49:51
logging in and then being logged in from a thousand miles away somewhere else at
49:55
the same time. Sure. Right. there there’s some, you know, telltale signs,
49:58
but there’s a lot of gray area, a lot of gray area in there. Maybe Alex, you
50:03
know, has a a mom who lives in Vietnam and and he’s going to visit her and and
50:07
or he’s on he’s on holiday, he’s taking a trip. There’s a lot of situations in
50:11
which there are legitimately use cases that an analyst would never be able to
50:14
to uh fully understand by just looking at the data. So, it’s important to have
50:18
the data. It’s important to gather the facts, but the reality is you have to
50:22
lean on. you have to rely on those end users as the source of truth in training
50:27
uh yourself and knowing what to look for. Um, one very specific use case that
50:31
I have is, you know, we had a we had a customer come to us. This was an
50:34
existing SIFT payment protection customer who came to us because they
50:37
were they said, you know, we really should look into uh stepping up our ATO
50:41
protection game, right? So, what should we do? And we said, okay, well, you
50:45
know, we we started talking to them, well, how big is your ATO problem? How
50:47
many how many uh login a week do you think that you’re currently getting?
50:50
They said, “Well, you know, customer service says, and uh I’ll make up some
50:53
numbers, but let’s say that they said, you know, we have 100 per month.” Okay,
50:57
you have a 100 reports of of compromised accounts per month. Interesting. All
51:00
right. So, we uh got set up, we did the integration, and we started triggering
51:05
notifications. So, based on a risky looking login, we would start sending
51:09
out security notifications, not even introducing friction yet. Kind of this
51:12
is a, you know, stepping our way into the plan. Um so without even introducing
51:16
friction in the form of 2FA sending security notifications and they started
51:21
they went from having 100 reported to customer service login per month or or
51:27
compromised accounts per month to 10,000 right it was a factor of 100x so 100
51:33
times more uh security notifications being engaged with meaning we sent the
51:37
email we said Alex this was kind of a suspicious login was this you and Alex
51:42
said no that was not me so that’s not just notifications sent. That’s
51:45
notifications that were replied to where a customer reset their password because
51:49
they said, “Whoa, whoa, that wasn’t me.” Now, there’s going to be some false
51:52
negatives in there like that that happens. We get that. But even if, you
51:55
know, 90% of those are legitimate, right? This customer had 90 times the
51:59
problem that they thought they had because well, in a singleto session,
52:03
maybe nothing went wrong in that single session. Maybe, you know, there was no
52:07
uh incident in that session, but the reality is accounts are being
52:10
compromised significantly more than they realize. It’s critical to start thinking
52:14
about okay how in our plan to prevent atto can we lean on our customers more
52:19
can we lean on them in the form of security notifications via email um
52:23
email or SMS and andor 2FA MFA right like how can we make sure that we are
52:28
offloading a lot of that um that ability to identify atto the the end user who
52:34
really is the best source of truth
52:37
>> there are three things I’ I’d like to just reinforce with you here so one uh
52:42
this the same idea of what we’re shown in the data isn’t representing the whole
52:47
that’s the case with every type of fraud that exists. Not every fraudulent
52:50
payment results in a chargeback. Uh not every single um atto is reported by the
52:56
customer, right? And so it’s it’s continuing the trend that we’ve been
53:00
seeing for I mean well over a decade since fraud’s been tracked and all of
53:03
that. Um it’s just it’s it’s drastically different in that we aren’t monitoring
53:09
the data we need to monitor in order to see what suspicious even is. Right? So
53:14
now that we were able to have eyes on it from building from building the n the
53:17
the data great two is ground truth, right? When the when when we can
53:23
encourage our users to interact with our platform and tell us it was or it
53:27
wasn’t, it’s them speaking to us. Right? Now that’s truth, right? You know, of
53:32
course, some people aren’t going to interact and some people might might
53:35
play games and not take it seriously, but more often than not, they’re giving
53:39
us ground truth. The user is telling us whether or not that’s them interacting
53:42
with the platform. And in a lot of different ways, a lot of the data that
53:46
that’s that’s used in fraud prevention is very uh very much implied and
53:50
aggregated and compiled and and shifted around. This is ground truth. And uh you
53:55
brought up the slide earlier about I think it was the MFA adoption rate.
53:59
users are are getting okay with with with MFA. They’re they’re comfortable
54:04
with it. Along all the notifications about new Ariana Grande songs and new
54:09
new Logan Paul and all the stuff, getting a notification about my bank
54:12
account and telling the bank, “No, it’s not me or yes, it is.” I’m okay with
54:17
that. And I think a lot of our data is showing that a lot of other users are
54:21
okay with that.
54:23
>> Absolutely. Awesome. Well, we uh we pushed right up to the time. So,
54:26
hopefully we have time for one or two questions. I don’t know. Um, Eli, if you
54:30
want to bring some in. Uh,
54:34
>> absolutely. Uh, thanks so much. And, uh, if anyone else wants to add some, uh,
54:38
other questions into the Q&A function, you can there and we can answer any we
54:41
don’t get to after the fact. Uh, one first one here from Joe is asks, uh,
54:47
what is your advice for someone looking to build atto inhouse?
54:55
>> Yeah, go ahead, Alex.
54:57
>> Yeah. So first is holistic. Make sure that you understand everywhere where a
55:01
user can interact. That’s that’s definitely number one. When you move
55:03
into number two is understand what your data is showing you, right? You want to
55:07
understand what your data can show you versus what your data is showing you.
55:10
Like that’s actually what Lewis and I just covered is we want to make sure
55:13
that we know what’s being reported as close to ground truth as possible. And
55:16
then three, make sure that you strike that balance between stopping the bad
55:19
actors and empowering your good users uh to interact, you know, safely and
55:24
comfortably on your platform. uh uh and and of course my recommendation always
55:29
dials back to uh passive data sets like device intelligence, behavioral
55:33
analytics, uh IP resolution, geoloccation, things
55:36
like that.
55:37
>> Yeah. Um the one thing I’ll add is just like uh again focus on having it be
55:41
accessible to multiple teams uh and make sure that it’s something that can be
55:45
shared because because it is beyond it’s not one team not one team’s
55:49
responsibility, right? So whatever you build, make sure that it is um both
55:53
accessible and and adopted by all the teams who who are going to touch atto.
55:59
>> Excellent. Uh and then I think we’ll have time for just one more. Uh Emily
56:03
asks, “What’s the reason around not just implementing a broader 2FA policy?”
56:09
>> Yeah. Yeah. So, you know, Alex mentioned people are more comfortable with 2FA,
56:13
but it’s not going to be nobody would say between not needing to log in and
56:19
needing or specifically like not needing to 2FA and needing to 2FA. Nobody’s
56:22
going to choose to 2FA every time. Um, I mean, I guess some people do, but it’s a
56:25
very small percentage, right? The people that are like fidious about security and
56:29
it happens, but it’s, you know, in the like low single digits percentage of
56:32
adoption. So, in general, right, the remaining 90 whatever percent of people
56:36
do not want to go through that extra step. It’s just it’s not like the end of
56:39
the world, but it’s not convenient, right? Like you want to get to whatever
56:42
you were doing on that site as quickly and as seamlessly as possible. And and
56:46
again, if you have if you happen to be in an industry which has any
56:49
competitors, which is like every industry last time I checked, you want
56:53
to be as customer friendly from a from a user experience perspective, you want to
56:57
be as customer friendly as as humanly possible while also balancing the need
57:01
to protect user accounts from fraud, right? And so you it when when customers
57:06
just go, “Hey, I’m just going to slap a really broad 2FA policy,” it’s a little
57:09
bit like a slap in the face to the to the end users because they’re the ones
57:12
that have to bear the brunt of it, right? It’s like, “Well, yeah, this is
57:14
easy for this is great for infosc and and security teams, terrible for the
57:17
customer experience, right?” So, um I think that would be the strongest case
57:21
for not uh not getting overly aggressive on a on a 2FA policy.
57:26
>> Yeah.
57:26
>> Yeah. You nailed it. It’s that balance. Great for the infosc, bad for the
57:30
customer, and who wants to who wants to implement that? Yeah.
57:34
Excellent. Well, uh that’s all the time we have today. Uh just hit the one hour
57:38
mark. So, thank you all so much for joining. Uh shout out thank you to Alex
57:43
and Lewis for hosting and talking through all that. We’ll see you all at
57:46
the next webinar and we’ll send out a recording of this uh shortly or later
57:50
this week. Thanks so much.
57:52
>> Have a good one everybody.