This webinar explores the Sift Q2 2024 Digital Trust Index, covering how cybercriminals are leveraging generative AI to launch increasingly sophisticated and scalable fraud attacks, and how companies can combat AI-fueled fraud with advanced, AI-powered technology.
We discuss the differences between fraudsters and fraud fighters in adopting AI technology, the most common uses of traditional and generative AI on both sides, and strategies merchants can use to stay ahead.
Watch the webinar to learn:
- Who’s ahead in adopting AI tech: Gain insights into the latest advancements in AI technology and understand who’s leading the race—fraudsters or fraud fighters.
- Common uses of AI: Discover the most common applications of traditional and generative AI by both fraudsters and fraud fighters.
- Strategies for staying ahead: Learn effective strategies to ensure your business remains one step ahead of fraudsters, leveraging the latest AI technologies.
Watch the On-Demand Webinar
Video Transcript
0:14
Welcome in everyone to today’s webinar. I see people are coming in from the
0:18
waiting room and a couple more people jumping on. So, we’re just going to give
0:22
ourselves a minute or two here for uh few more people to join and then we’ll
0:27
get started. So, just uh sit tight, get going here in a
1:21
Welcome to today’s webinar, the AI fraud frontier. How fraudsters and fraud
1:27
fighters have adopted AI technology. My name is Eli. I’m on the marketing team
1:31
here at SIFT. And before we dive in, I just want to start with a few
1:34
housekeeping items. Uh this webinar is being recorded. It will be made
1:38
available to all registrants and attendees later this week. We know
1:42
you’ll probably have a few questions for our speakers, so we’ve reserved time at
1:45
the end for Q&A, and you can submit your questions through the webinar uh by
1:50
using the Q&A button. You can submit questions at any time throughout. We’ll
1:54
try to answer as many questions as we can live. Uh if we don’t get to your
1:58
question here, we’ll be sure to follow up with you directly after the webinar.
2:02
Uh and with that, I’ll hand things over to today’s hosts.
2:09
Hi. Uh, my name is Kobe Mononttoya. I run CIF’s, uh, competitive excellence
2:13
program. And so, uh, what that means at SIFT is I sort of keep up with the
2:18
market, uh, do market research and try to understand where, you know, solutions
2:22
and capabilities are going, um, and then make recommendations to, uh, different
2:27
teams on how we can compete more successfully. I’ll pass it to, uh, I
2:31
also have Britney Allen on here, and I’ll I’ll let her introduce herself.
2:34
>> Yes. Hi, everybody. I am a senior trust and safety architect at SIFT. I have
2:39
been here for about four and a half years and a majority of my career was
2:44
spent as a merchant. So I’m really heavily focused on especially for
2:49
today’s conversation with AI and fraud. You know what merchants can be doing
2:54
better and what they need to know about what fraudsters are doing right now. So
3:00
I’m excited to share some of those insights as we dive into the Q2 index.
3:06
Great.
3:08
>> I can also touch on this agenda just to keep you all uh apprised of what we’re
3:13
going to be doing. So, we will start with the Q2 2024 index report findings.
3:19
We’ll show you some stats and figures that you can point to with real data for
3:24
how AI is being used in fraud. Then, we’ll get into a discussion of who’s
3:28
ahead in the AI race. Is it the fraudsters or is it the fraud fighters?
3:33
I’m sure you have your own opinion. Um, but we’ll share what we’ve got there.
3:36
And then lastly, end with strategies for merchants because we want you to have as
3:40
many takeaways as possible from our discussion today.
3:45
>> Awesome. So, we’re going we’re going to dig right
3:49
into some of the findings uh in our recent index report. So each quarter SIP
3:54
publishes uh what we call a index report to sort of highlight different trends uh
4:01
in fraud and risk that we see on our global network. Uh we source data from
4:05
something called fiber uh which is available on our website. It stands for
4:10
fraud industry benchmarking research and this sort of is uh performance metrics
4:16
uh when it comes to CIF’s global model as far as what we’re seeing when it
4:20
comes to new emerging bad actor activity block rates chargeback rates and things
4:24
like that. In Q2 when we when we specifically tried to understand trends
4:30
going on with generative AI we took a close look at uh our content solution
4:35
and what was happening happening with sort of usergenerated content. Um as as
4:40
most of you I’m sure already know content is an area where generative AI
4:45
is very useful when it comes to crafting messaging to influence or socially
4:50
engineer a victim into into doing specific things. Right? So it used to be
4:53
that broken English and bad grammar were you know common red flags and and and
4:57
chatbt or generative AI has sort of uh changed that uh in many ways and so in
5:03
looking at this data we saw a 22% increase uh in blocked content uh on our
5:08
global network. We saw that 72% of consumers have noticed an increase in
5:13
spam and scam which certainly doesn’t surprise me as a consumer that receives
5:17
many text messages every week it seems. Uh and then 76% of fraud risk uh fraud
5:22
and risk professionals believe their business has been targeted by AI fraud.
5:26
Now the definition of what AI fraud is is not standardized and so you may have
5:31
differing opinions but we’re going to talk a little bit about what you know AI
5:35
fraud implies uh to to what fraud looks like today.
5:41
Another thing we we looked at is how is generative AI being applied across
5:45
different attack vectors. And so fishing, you know, for obvious reasons
5:50
is is a common one. Uh KYC and deep fakes, you know, sort of defeating uh
5:55
selfie recognition is also a common one that’s, you know, talked about in the
5:59
media. But the takeaway here is that it’s not just focus on one sort of
6:03
attack vector. We’re seeing it across the board uh used in many different
6:07
ways. And so depending on the type of attack obviously changes the way it’s
6:11
used, but again, we’ll talk a little bit about how it is it is being used today.
6:16
Yeah. And it doesn’t just uh change the way that it’s used. It changes a
6:19
merchant’s ability to know that it’s being used. When you see a marketked
6:24
change in the quality of writing within a fishing email or text, then you can
6:30
reasonably infer they’re probably using a generative AI tool to help them better
6:35
craft these uh messages. We’ve seen that also in cases where there would be very
6:40
little fraud conducted in a particular language like Japanese. And then when
6:45
these tools became more easily accessible and better at translation, we
6:50
would see an increase in fraud targeting that particular language. So that’s
6:55
something that you can measure, you can point to. But in some cases, like there
6:59
at the bottom, payment fraud executed with or aided by AI tools. For some
7:04
merchants, they’re not going to be able to know if that’s happening or not.
7:08
Maybe they’ll see an increase in payment fraud attempts, but the actual AI tool
7:14
that is helping a fraudster better fish credentials or better obtain credit
7:20
cards may be unseen completely by that merchant and they may not even know that
7:26
challenge is there. And so that could be ranked the lowest because of that
7:30
perception issue, but it could actually be higher in the prevalence in the
7:35
world.
7:37
>> Excellent. Yeah. Excellent, excellent points.
7:41
>> Ah, so who’s ahead in the AI race, fraudsters or fraud fighters? Yeah, we
7:45
we teased this up uh because this was a real question that we have been posing
7:50
to groups of fraud fighters. Uh so if you go on to the next slide, this is a
7:55
photo of a lovely group of people in San Francisco at our final riskrevenue
8:01
forum, which was a series of six events that CIF did uh over the course of this
8:05
year. And at this group, we asked everyone in attendance, who do you
8:10
think, oh, excuse me, who do you think is using AI better, fraudsters or fraud
8:14
fighters? Uh, now Kobe wasn’t there, so I’ll ask him. Which do you think the
8:20
majority of people picked?
8:23
>> Uh, I would say fraud fraud today. I would say fraudsters. Are you using it?
8:27
>> Okay. And as a fraud fighter yourself, why did you select the other side?
8:33
Uh I tend well I tend to assume bad actors are like exploiting things faster
8:39
than you know uh folks like us are are uh using those things to com combat
8:43
those exploits. I guess
8:45
>> I think that that points to us having a healthy awareness of what some of the
8:48
advantages are that fraudsters have. But you’re right it was a runaway victory.
8:53
Uh and there were some points that I wanted to call out that the attendants
8:57
had who answered fraudsters and what they shared for their explanation. The
9:01
first was they can ship fast. They aren’t balancing other metrics, other
9:06
needs. They aren’t trying to fit work onto a road map that has a lot of other
9:10
conflicting priorities. They aren’t looking to what regulations they need to
9:15
abide by or any of those roadblocks that we have as merchants. They can try
9:21
something out. They can ship it fast. That is an advantage. If you’ll click
9:26
again, fraudsters, as I mentioned with the regulations, that they won’t be
9:31
stopped by that. They’re already breaking the law when it comes to buying
9:35
and selling of stolen information, when it comes to ripping off people. And so,
9:40
if there is any kind of regulation against using AI for a particular use,
9:44
they’re not really going to care about that. And we are actually going to look
9:47
at some fraud AI tools a little later on. So, you will see that in action. But
9:51
there were some denters in the group who said that the fraud fighters were ahead.
9:56
And one of the big callouts for them was that our advantage is trust. Fraudsters
10:02
do work in an environment where it’s more difficult for them to establish
10:06
trust between each other. They can be ripped off by other fraudsters. They
10:10
could, you know, pay somebody to do something for them or to help them out
10:14
in a fraud economy arrangement and then be left high and dry. whereas fraud
10:21
fighters are becoming more and more willing to share information and share
10:26
strategies. So we do need to remember that you attending the webinar today and
10:30
and hearing all this information from us that’s just a small part of that. But we
10:34
do have the advantage of trust and networking on our side. So all of that
10:40
to then set up what the fosters are actually doing and how they operate on
10:45
different scales of sophistication. I will hand it back to Kobe.
10:49
>> Yeah, thank you Britney. Yeah, so when I you know when we think about bad actors
10:53
uh I think it’s important to not look at all bad bad actors as the same. And so
10:58
the this is sort of the way I personally view bad actors. to have sort of
11:02
opportunistic bad actors. And these could be people that a friend uh told
11:07
them, hey, to get, you know, this free or, you know, you can uh return this,
11:12
you can use this thing and return it and, you know, it’s not it’s not really
11:15
uh going to come back to you or maybe you read something online. It’s folks
11:19
that are not deciding to be career criminals, but they’re taking they’re
11:23
making opportunistic decisions and maybe the area of ethics are, you know, a
11:27
little gray. uh but it’s not necessarily a crime that they would be prosecuted
11:30
for in their mind. Then you have intermediate fraudsters, bad actors
11:34
which are more vocational and so here there’s more of an awareness or
11:38
understanding of what they’re doing but also the tools and technologies that
11:41
they’re using right so awareness that their IP address for example while
11:45
they’re not providing their IP address they’re they know that their IP address
11:49
is being evaluated and so they may take steps to sort of manipulate it. And then
11:53
lastly, you have more advanced criminal enterprise uh bad actors. And so here,
11:58
bad actors are considering an ROI. Um so they’re literally operating like a
12:03
business and evaluating is the time spent uh on these exploits worth the
12:08
return that that we’re getting. And so generative AI tools are sort of enabling
12:14
more rudimentary, more intermediate bad actors to show up as more criminal
12:19
enterprise bad actors. uh because what it allows them to do when it comes to
12:23
sort of saving time uh and then understanding you know um emerging
12:28
exploits and so I think it goes without saying but the applications for
12:32
generative AI are the same for business users as they are for bad actors. So for
12:38
a business user you know I can find key information without performing as many
12:41
web searches. Uh a bad actor can find you know exploit intel without scouring
12:46
as many site sites and apps. Um maybe a business user spends less time
12:51
proofreading uh because they’re using chat GBT uh while a bad actor will spend
12:55
less time crafting a message uh to influence victims. And so takeaway is
13:00
that that time saved allows them to uh spend more time on making fraud uh look
13:06
more clean uh and more difficult to uh to detect.
13:10
>> Yeah. Oh, sorry. I just wanted to jump in. I as the former teacher uh I always
13:17
have to bring up any examples when they’re relevant to the field of
13:20
education and you know you were talking just about sort of the fraudster’s free
13:24
ability to use these tools to improve their fraud attacks. Well, a natural
13:30
thought then for a fraud fighter to try to get ahead of that fraudster is, well,
13:33
what we can we use to detect text that has been generated by AI. And that is
13:39
something that’s been a big question for quite some time within the field of
13:43
education where teachers and professors are trying to identify whether or not an
13:47
essay was actually written by a student or it’s been written by AI and then
13:53
submitted, you know, under the student’s name. And while there has been some
13:57
success in some apps that are able to identify if something is AI written,
14:03
what they’ve found is that it’s very rarely a stark answer 100% we know this
14:10
is human or 100% confident this is AI, but rather something in the middle
14:15
ground which then is difficult to discern. You know, if it’s if you have
14:18
it being a 50/50 shot, are you really learning anything from it? And
14:23
unfortunately in the field of education to combat the use of AI in essays in
14:29
other schoolwork they’ve fallen back on a really manual approach. They may make
14:34
students write an essay by hand on pen and paper in class or they may make the
14:39
student have a one-on-one meeting with a teacher afterward to explain various
14:43
parts of their essay to then prove that they even understood what they wrote.
14:46
That’s manual. That takes a lot of time. And so until you know tools like that
14:51
scale up, this could be an argument of fraudsters being ahead because they’ve
14:57
already got the tools that help them create the language whereas we’re not
15:01
quite there yet on tools that help us identify the AI generated language. So I
15:06
just wanted to jump in and and share that info. There’s a really good article
15:10
recently this week in PC World on that topic.
15:14
>> Yeah. Yeah. know and it’s you know it’s a nod to how solution providers you know
15:18
they’re going to they’re going to test and iterate you know for quite some time
15:21
you know be before feeling you know uh confident about those detection uh rates
15:27
I wanted to lean into what I mean when I talk about ROI or bad actors um so this
15:32
is something that I think most intuitively know but I don’t see talked
15:36
about much in the market as far as effort required when it comes to making
15:41
a transaction or event uh you know as undetected as possible. Right? So, I
15:46
think most are familiar with, you know, uh using proxy IP addresses and ensuring
15:52
that maybe an email address matches the the username matches the um the billing
15:57
name. Uh looking at casing of text, right? So, often times when casing looks
16:02
informal, it’s because it’s a script, you know, took data from some sort of
16:06
file and it’s just importing it. So, it’s just it’s just raw copy and paste
16:09
and not sort of normalizing text. Um normalizing it takes extra time, right?
16:14
uh velocity signals. So ensuring that things are not repeated like IP address
16:18
values, device ID values, things like that. So most most you know intermediate
16:23
to advanced bad actors are aware of these things but they may make a
16:27
decision that the time needed to use a unique IP address on a set of 100
16:32
transactions or to match the username of 100 emails to 100 billing names is not
16:38
worth the return. And so when we see uh more, you know, obvious quote unquote
16:44
looking fraud with uh with clear red flags, it doesn’t necessarily mean that
16:48
the bad actors lack awareness of those red flags. They may be making a
16:52
calculated decision that um you know, it’s better for me, it’s I have a better
16:57
ROI to spend less time on many transactions assuming maybe 50% will go
17:02
through than to spend a lot of time on 50 transactions when may or may not, you
17:07
know, be detected. And so, uh, I think it’s just kind of worth sort of keeping
17:11
that sort of bad actor, you know, psychology in mind. Britney, did you
17:14
have anything to Yeah,
17:16
>> it’s like it’s like the spammers psychology that they can spray and prey
17:20
and as long as some of it lands, it was worth the effort. I think we’ve all seen
17:24
that in our own transactions. I remember one company I worked at, there were
17:28
fraudsters who consistently got the surname and given name or first name and
17:34
last name mixed up for the card holder and they could just never get it right.
17:40
And that wasn’t anything that we could use for machine learning or was in our
17:44
rules to detect, but just visually looking at the order. we knew if it
17:48
said, you know, Alan Brittney that nobody out there generally has the last
17:51
name Britney. And so that was wrong and they just didn’t understand the data
17:55
they were dealing with. And they never quite figured it out or at least they
17:59
didn’t seem to figure it out on our platform because they hit us for years
18:01
and years like that. And so you will see these signals and I think it’s important
18:06
to note because we do talk about fraudsters increasing sophistication and
18:10
that’s true. They do they they adopt new tech. They learn new strategies, but
18:16
they don’t do that in isolation from maintaining the old strategies or the
18:22
old methods that still work. Like when we first started uh monitoring fraud
18:28
chatter around AI, which we’ll get to in a minute, explaining how CIF does that,
18:33
we were looking for, you know, what kind of excitement they had about adopting
18:38
AI. We did find some fraudsters who would say, “Yeah, I know I can use it,
18:43
but what I’m doing right now works.” There was one in particular who was
18:48
talking about how they send those spammy texts that you mentioned earlier, the,
18:53
you know, ones that pretend to be the United States Postal Service claiming
18:56
you have a problem with your package delivery or your boss asking to send you
19:00
gift cards. And they said, “Those work just fine. So, why do I need to upgrade
19:05
to a deep fake voice or deep fake video? You know, maybe one day I’ll do that.
19:10
Maybe I’ll do that for a higher target, but h what I’m doing right now, I don’t
19:13
really want to put more effort into it because I’m happy with my ROI, with my
19:17
returns. And I’ll just end on saying, uh, we are in 2024 and we still see
19:23
paper check fraud. So, do not lose sight of the established
19:27
methods. Do not lose sight of the loweffort clunky fraudster because they
19:32
will always be there and you don’t want to let them win.
19:35
>> 100. Yep. 100%. Great uh great points. Um and when we think about Okay, so like
19:41
effort required, right? So also effort required for bad actors is to understand
19:47
emerging exploits, right? So, they may go, if you go on YouTube, I took this
19:51
screenshot a few days ago, and type 3DS uh OTP bypass, you’re going to be
19:56
presented with a number of videos that, you know, supposedly educate and train
19:59
you on how to circumvent 3DS OTPs. Um, obviously, obviously, there are many
20:05
messaging apps that have, you know, group private groups, public groups, uh,
20:08
that you can glean information from. But the takeaway here is that this is
20:12
timeconuming, right? It’s it’s manual effort. And so when we think about what
20:16
chat GPT does as far as consolidating, you know, uh into one into one UI, one
20:21
screen to query and present presenting information from many different sources,
20:26
uh that solves these sorts of issues for uh for bad actors as well.
20:33
And then this is, you know, this is a screenshot that’s been floating around
20:36
for a while now, so many of you have probably seen it, but this was a forum
20:40
post. a bad actor is advertising, you know, um something called it’s like a
20:45
it’s like a fraud GPT. Um and then they sort of show some of the things that it
20:49
you know supposedly does. So what pops out to me find non you know VBV verified
20:54
by Visa that’s you know the first iteration of 3D secure from from Visa.
20:58
Um so finding bins that are not necessarily you know enabled for 3D
21:02
secure that’s kind you know that’s a little um alarming and you know finding
21:06
cable sites right cartable meaning like sites that have low low security. So
21:10
again, imagine how to obtain that information prior to being able to query
21:15
a tool. Well, you have to know the right person. That content has to exist
21:18
somewhere. Uh you have to find it. Whereas now it’s it’s much more easily
21:22
accessed and and delivered to bad actors.
21:27
And so kind kind of the takeaway here is just just to wrap that up. So you know,
21:31
preji bad actors are having to go through many different social media
21:35
sites, uh different forums and and areas on the deep and dark web. Whereas today,
21:40
as these tools continue to uh to get better, uh they’re only going to uh
21:45
they’re going to have to go to less sources to receive the same amount of
21:48
information that’s going to give them more time to invest to to make fraud
21:52
look more undetectable.
21:55
>> Yeah. And we do have uh some examples and some views into a particular tool
22:01
which I’ll explain as much as I can share or talk about now. So I am in
22:08
charge of our deep and dark web investigations team at sift. We have a
22:13
group that is embedded in quite a few different fraud channels on telegram and
22:18
then on other various dark web sites and marketplaces and we do searches and we
22:24
try to provide as much intelligence as we can to both uh sifts community and to
22:29
the broader fraud fighting community based on what we come across. Now, we
22:34
came across a new tool that allows you for a very affordable price to be able
22:40
to query large known databases of breached information. It includes when I
22:47
ran a general query, things popped up for companies that it’s not not really a
22:51
big deal that I mention them because we know that they’re tied to past data
22:54
breaches like My Fitness Pal and uh LinkedIn and others and has the data
22:59
aggregated there, but also they put in the national public data breach when
23:05
that happened very recently immediately folded that into the tool. So, we’ve
23:09
been looking through that tool to learn more about how fraudsters utilize things
23:14
like that to get more access to stolen data. But also, this tool has an AI
23:20
function to it. It’s not fraud GPT. It’s not worm GPT, which you’re probably
23:25
familiar with, and those are some of the wider known sort of unethical or less
23:31
ethical options or alternatives to chat GPT. But, this is one that’s been
23:36
proprietary and is built within this tool. So, I wanted to do a side-by-side
23:41
comparison with chat GPT just to give you a little insight into how it is uh
23:46
different. So, let’s go on to the next screen then. So, this is a screenshot
23:51
from chat GPT. You can replicate the search if you want to by typing in the
23:56
same question I did. Now, I didn’t type in a question a fraudster would know. I
23:59
was just interested in seeing what kind of information I would get about fraud.
24:04
So, I asked ChatGpt, “What is the most common mistake fraudsters make?” And I
24:09
got a reasonable amount of answers from chat GPT. Uh, but if I was a fraudster
24:15
and I was looking at this, maybe trying to see like what a what mistakes to
24:19
avoid, I would get some guidance, but I wouldn’t get as much insight as I might
24:24
elsewhere. So the number one there, inconsistent or suspicious transactions
24:28
says fraudsters often make transactions that don’t align with usual behavior or
24:32
legitimate business practices. That’s true. We all know about fraudsters who
24:37
will have too fast of a velocity from account registration to purchase, but
24:42
also there’s plenty of sophisticated fraudsters who do know how to mimic
24:45
legitimate customer behavior, you know. So that’s not always the the case there.
24:50
And you while some of this is interesting, like I said, it’s not the
24:54
biggest guidance for a fraudster. So, let’s ask the same question then to our
25:00
tool which is called Llama 3.1 AI. And the most interesting part for me from
25:07
this answer is the very top where they site the sources. After analyzing
25:12
various studies, reports, and law enforcement data, I’ve identified some
25:17
of the most common mistakes made by fraudsters. So, that’s really
25:20
interesting to me. It’s acknowledging that they do have law enforcement data,
25:24
they do have public data that has been rolled into their massive database. And
25:29
while some of their recommendations are equally high level, like the one of
25:33
saying number one, do your research, number two, you need to plan, number
25:37
three, don’t be cocky, don’t be overconfident. They do have some tidbits
25:42
here that if I was trying to figure out how to let’s say card a website, maybe I
25:48
would have some uh guidance. Number six, lack of operational security or opsec.
25:54
That’s an interesting one. Fraudsters of course need to obuscate their location,
26:00
their device, their identity in order to avoid getting caught. So what if I
26:04
wanted to learn something about OBSC more specifically? So, let’s flip it now
26:09
to asking chat GPT a more pointed question. Now, I didn’t put the word
26:13
fraud in the question. I tried to see does it know what carding is. I figured
26:18
it would, but I was just a little curious. So, I said, “What is the
26:21
necessary opsect for carding?” And chat GPT told me, “Uh uh uh,” which I’m sure
26:27
you would expect. Carding is illegal. I can’t give you any information. Uh, but
26:32
if you want to ask about anything else, then feel free. So yeah, maybe then I
26:35
could just ask what are good OBSSE practices and and get some info. But
26:39
instead I went over to Llama AI and asked what is the necessary OBSSE for
26:45
carding and I got some practical guidance that I doubt I would have
26:49
gotten from chat GPT. I think if chat GBT was giving me normal guidance as a
26:53
consumer, it wouldn’t tell me first off anonymity, use tour, uh, use encrypted
26:59
chats, etc., etc., cover your tracks, and then use burner devices for number
27:03
five. That’s not a standard recommendation. That is a recommendation
27:07
for someone who is looking to commit fraud. I could then ask further
27:12
questions of Llama AI about where do I get a burner device? How do I do these
27:17
steps? And the useful part of that is going back to that advantage that fraud
27:23
fighters have of having trust in our environment, being able to talk to other
27:28
fraud fighters and know who we’re talking to. If I’m a newbie fraudster
27:34
and I’m worried about getting ripped off, I can ask some questions in a
27:37
channel on Telegram, but I may or may not actually get a great answer or I may
27:43
pay for an answer and then have somebody ghost me and I’m just left without any
27:49
recourse. Or I might be worried about asking questions in a more public forum
27:55
like some of those Telegram channels where they aren’t invite only and they
27:58
aren’t private and then have what I’m asking being monitored by law
28:02
enforcement or being subject to subpoenas later on. But in this case, I
28:08
might feel safer if I’ve got this private AI tool and I’m just able to
28:12
make these queries and get a little bit more guidance. And then maybe I do
28:16
follow up on asking what is a burner device. So that is a straightforward
28:22
comparison between two different uh AI functionalities, a chat GPT and a Llama
28:30
3.1. And I might regret this uh but I do have Llama 3.1 pulled up right now. And
28:37
I know we haven’t gotten any questions yet. If you want to ask questions about
28:40
things Kobe and I have been covering, great. But also, if you have a question
28:45
that won’t get me put in jail that you would like me to ask Llama 3.1, like I
28:50
can’t give you, as Kobe referenced, the nonBBV bins, but if you have just a
28:55
general question where you’d like to see what direction this fraudulent
29:01
AI tool would point a fraudster in, I would be happy to run some of those
29:06
questions in the background and we can touch on them in the end. Again, please
29:10
don’t make me regret having asked that, but the floor is open.
29:14
>> Thank you, Britney. Yeah, and great points. Yeah, it’s like my take away
29:18
from a lot of what you said is the barrier to entry, you know, to to be a
29:22
bad actor has never been uh has never been lower.
29:25
>> So, I mean, just to emphasize to to to wrap a lot of this up, less time
29:30
researching and preparing to conduct fraud attacks, right? that barrier to
29:33
entry that we talked about and having to know the right person and can you you
29:37
know trust trust this person. Um all that gives more time uh for bad actors
29:43
to spend on conducting fraud attacks. So not not having to go to multiple
29:47
websites to look for exploit intel um not having to spend time you know
29:51
proofreading things like that um it’s going to get more time for bad actors.
29:57
Next, I’m uh Britney, you’re going to talk some about strategies for uh
30:01
merchants.
30:03
>> I am. So, I believe this first slide uh that is going to come up is yours, but
30:10
again, these are the practical takeaways. This is the guidance that
30:13
we’re going to give. It’s okay. I’m also getting questions that people want me to
30:16
ask. So, I’m going to go back on mute and type those in,
30:19
>> but I’ll jump on on the next slide.
30:21
>> Yeah. No, thank you. Yeah. So uh tradition you know traditionally again
30:25
part of my role is to is to monitor the market and I’ve been in this space for
30:29
you know almost 20 years fraud practitioner work uh working at solution
30:33
providers payment networks and I’ve sort of watched this market evolve um for a
30:37
while now and so tradition the traditional application of AI you know
30:41
has been very generic in nature you know it was rule rule uh rule pro rule based
30:47
solution providers that then layered in AI and you had rules in sort of this
30:51
generic AI uh that sort of approach is you know obviously not scalable uh today
30:56
and so a better approach that other providers uh as well you know take in
31:01
some cases but but SIP really leans into is having more customized uh AI uh based
31:07
models that are focusing on what’s happening in the broader ecosystem
31:11
whether it’s at a fintech company whether it’s at a travel site whether
31:15
it’s at a a dating app um what’s happening within the specific vertical
31:20
that you operate in Um so this is you know essentially intelligence outside of
31:24
your four walls and then of course understanding what is happening inside
31:28
your four you know figurative walls um is important to understand the nuance of
31:32
your business. And so that sort of approach allows better detection of bad
31:37
actor activity without disrupting legitimate customers. uh because what is
31:42
happening uh in a different business or or is defined as fraud and abuse may not
31:48
be defined as fraud and abuse within your own business or it may be and you
31:53
have not seen it yet. So it goes it sort of goes goes both ways.
31:58
>> Yeah. All right. So I have to step up and be the contrarian just because I
32:05
want to make sure that we’re sort of aware of all these exceptions and use
32:08
cases. You do have a risk if you are overindexing on let’s say some some
32:15
static rules or some key indicators that you believe point to fraud point to a
32:21
potential use of AI or a bot script on your platform you have the risk of
32:27
violating laws when it comes to discrimination for one. So, I’ve called
32:32
out in this screenshot some common tools that individuals will use who need more
32:37
accessibility options to be able to navigate the internet. One in particular
32:42
would be speech recognition software where somebody who would need a
32:47
alternative to using a keyboard and typing could speak into a microphone and
32:51
have their voice translated into text. the quoteunquote typing patterns of that
32:58
action aren’t going to fit the same typing patterns of myself or someone
33:04
else who is using the keyboard to enter text. It may be dumped all in at once
33:10
like it was copied and pasted. It may be put in in a very uh a very consistent
33:17
manner without a lot of typing variations like somebody might do if
33:20
they were using a keyboard. And so if you then sort of overindex on traffic
33:25
that you believe to be bot driven or AIdriven and you aren’t accounting for
33:31
the variances within your user user base and their needs that can put you in a
33:36
really difficult position. I just read an article this week. It is on wired
33:41
that is called struggling to unlock your phone. you might have lost your
33:45
fingerprints. And it was an interesting look into how fingerprint biometrics
33:50
have become so ubiquitous within our tech, you know, interactions. I have a
33:55
fingerprint scanner on my laptop. I’ve got one on my phone. Uh people use them
33:59
to enter workplaces, but there’s no real accounting for when people naturally may
34:06
lose their fingerprints. And I wasn’t really aware of some of these
34:09
situations. Uh there is the fact that you can lose it from manual work, which
34:13
does make some sense, or if you are a rock climber. I didn’t know that you
34:18
could actually lose your fingerprints during the process of receiving
34:21
chemotherapy. And so that then could be a discriminating action against somebody
34:26
for a medical condition. And so I hadn’t even considered some of those
34:31
possibilities. But there’s always going to be something that you need to
34:35
consider where someone can’t interact in the way that you want or quote unquote
34:40
prove they’re human through whatever those steps are. And you just need to
34:43
have awareness again of your user base and what you can do to make it an
34:47
equitable application of fraud prevention. So that’s that’s my soapbox
34:51
moment. Uh but yeah, I did not know about the potential for losing
34:56
fingerprints in so many different scenarios. And honestly, Kobe and I were
35:00
chatting earlier. are work laptops, you know, they don’t, as far as I know, I am
35:05
an Android person and these are MacBooks, but as far as I know, they
35:08
don’t do facial recognition. Uh, so the only biometric option would be
35:12
fingerprint. So, I could find myself in trouble there. So, anyway, that’s
35:16
something worth uh calling out if a consideration.
35:20
>> Great. Yeah, great points. Yeah. And also, I mean, it’s a it’s a great
35:23
reminder that a um AI is only as good as your training data set, right? So some
35:28
years ago there’s a an experiment done where AI was being applied to uh court
35:32
court cases and deciding sentences and it was biased uh because our legal
35:37
system in some ways you know can be biased and that’s the training data set
35:41
you know it was trained on. So what that means to me in a sort of a fraud you
35:46
know practitioner lens is it’s very important to send as much data as you
35:51
can uh into your into your AI you know based solution. Often companies will
35:56
send this channel to this solution, that channel to that solution, this market to
36:00
that solution. And in some case the trade-off is worth it, but it’s worth
36:04
considering the fact that you’re not really training uh an AI model on what
36:08
the world what the complete world looks like, right? It’s a subset and there’s
36:11
going to be more room for sort of bias there.
36:15
So this is this is you know this is sort of why SIFT uh tries to take the
36:19
approach uh we we take uh with the with the three different models. So you know
36:23
we have our global model which also acts as our consortium uh which is updated
36:28
you know every every 250 milliseconds when a when a SIFT user clicks a button
36:33
to you know approve an event or or block an event it’s updating those global risk
36:37
signals and our other clients benefit from that in near real time and then you
36:42
know we’ve had you know for a while uh sort of a custom model uh that’s unique
36:47
to each each client’s business. Recently we added you know industry risk signals
36:52
and this is sort of um everything between uh the global model in the
36:56
custom model and so uh today we’re consuming uh many events you know one
37:01
trillion events their their login events uh account signup events uh posting
37:05
content events and payment events and so that really you know every every
37:10
provider uh pretty much says the same thing every time I go to MRC I ask hey
37:13
what’s your differentiator and usually the differentiators are you know pretty
37:17
much the same thing that said our consortium is very much is uh is diverse
37:21
uh from a use case perspective, from a vertical perspective um and that you
37:26
know surfaces as being diverse from a a bad actor activity perspective as well.
37:31
And so um again kind of going back to to what Britney was saying earlier as far
37:36
as uh having data that represents uh a clear picture of your business. So if
37:42
you did have a a user that is using technology uh you know voice to text um
37:47
knowing that those users are in your system would be important you know for
37:50
for that training data set. So it is cliche to say more data uh the better.
37:55
Um but it is you know still true. And uh CIF today we also uh didn’t talk about
38:00
this a lot but we’re continuing continuously innovating. You know we
38:04
have this little uh 31 patents awarded. So we’re constantly sort of looking for
38:08
new ways uh to to use that data in a more creative uh and effective way. And
38:13
you know that allows us to to give what we we believe are industry you know
38:17
leading sort of uh fraud fraud performance results. So kind of the the
38:22
the summary key takeaways here generative AI uh the implications are it
38:27
enables bad actors uh just like it enables business users to simplify u
38:32
manual tasks and then repurpose time and energy to tasks that may be a little bit
38:38
more uh involved. And combating that uh means that businesses should expect an
38:45
increase in fraud activity that looks more legitimate. You know, it doesn’t
38:49
look uh like fraud that has, you know, all these sort of quite obvious red
38:53
flags, although those will still exist. And it’s important to have a solution
38:57
that is is really prepared to be able to detect the difference between a
39:01
legitimate user and a bad actor that looks very very close to a legitimate
39:05
user, right? And so we feel sort of taking a customized AI approach with the
39:10
ability to write custom logic through through workflow rules is the best uh
39:13
best approach to that. And so at this point I want to pass it back to to
39:18
Britney because I know you had some questions we were able to to find
39:22
anything.
39:23
>> Yes. So we’ll go through this uh pretty quickly but we had one question of where
39:30
can one find card holder data on the dark web? And so in that case,
39:38
we got a response that let us know that
39:41
>> you want to share the screen or or just read it off. It’s up to you.
39:44
>> I kind of don’t because I’m going to leave out some things that it says in
39:47
some instances. So I know that makes it a little clunkier. Uh I apologize, but
39:51
we did do this live. So we didn’t know exactly what we’d pull up. Um but in
39:56
this instance, it delineates the differences between various marketplaces
40:00
and forums. It guides you on cyber crime marketplaces versus carding forums
40:06
versus some other resources that are available on the dark web. Uh it
40:11
mentions a history of the sites being shut down like Silk Road and Alphab Bay.
40:15
And then it calls out ones that it says are still live including Empire Market
40:20
and White House Market. Now I know for a fact White House Market was taken down
40:23
and then came back. I do not know if uh Empire Market is back or not. But then
40:30
it gets into a more explicit list of the best and current sites. And this is the
40:36
one where I didn’t want to show exactly everything because I am not familiar
40:39
with all of these. And I would hate for someone to type it in and to I mean
40:44
there’s a lot that can be seen on the deep and dark web. You could be seeing
40:47
uh weapons for sale. You could be seeing human trafficking in some issues. So,
40:50
this is where I kind of wanted to keep some of these names uh hidden, but it
40:54
gave a list of three, all of which it says were established within the past
40:58
four years, and it gives uh links and information on how to access them. So,
41:02
that was pretty conclusive. That one I don’t have very many complaints about
41:06
what we got from it. Uh then there was a question of I want to test my employees
41:11
on fraud tactics. Can you recommend a good fishing email to send them? This
41:15
one was more straightforward. The guidance that it g gave was just keep
41:20
your email realistic. Use a convincing subject line that uh drives urgency and
41:26
include a malicious link or attachment. And it gave you two examples to choose
41:30
from. One is important update company policy
41:35
change. And then the text of the email says you as the employee have not yet
41:40
accepted this policy that was due. You need to you know accept this
41:44
immediately. And then the link is below. So sort of banking on I mean Kobe we’ve
41:48
we’ve kind of all been there where you’ve missed an email and you didn’t
41:51
agree to something you didn’t update something and you’re not in compliance
41:55
and so it’s banking on that and then the other one is uh a little I think
41:59
clunkier but says urgent your account has been compromised and then says we
42:05
have reason to believe your account has been compromised click the link below to
42:08
begin the password reset process to secure your account. I think people were
42:11
a little bit more suspicious of that one, but hey, it gave you some
42:15
guidelines on how to do that. And then the third question we got was, “What is
42:20
the average profit for a fraudster per customer or atto?” Now, that is
42:26
fascinating that idea. So, I typed the question a little bit differently
42:30
because I wanted to use, you know, fraud language. So, I said, uh, what is the
42:35
average profit for a fraudster per log, which is basically stolen credential?
42:40
And it said that there’s no set data for this, but we can make an estimate based
42:46
on the average loss for the following three factors. And it said credit card
42:52
fraud. The average loss per credit compromised credit card is around $200.
42:57
So they’re trying to tell a fraudster you might make $200 from using a stolen
43:00
credit card or get $200 worth of items. Then it says number two, identity theft.
43:05
According to a study, I won’t say who by, uh, the average loss per identity
43:09
theft victim was approximately 7,600. So, that’s really interesting. It’s
43:14
telling them identities are worth more. Identity data is worth more than just a
43:18
credit card number by an exponential amount. And then lastly, it says online
43:22
banking fraud. It references another company. A study by the that company
43:27
found that the average loss per online banking fraud incidents was around
43:31
$1,000. So that’s interesting because me as a fraudster, I’m already thinking,
43:35
okay, well then what do I do with this, you know, fuller robust set of identity
43:39
data that I might need to make more money. So yeah, uh again, I didn’t want
43:44
uh other companies names popping up. I didn’t want uh mentions and links to
43:49
dark websites that I haven’t had a chance to vet popping up. Uh so I didn’t
43:53
share my screen, but that’s that’s what we got. It’s pretty fascinating.
43:57
>> Yeah. No, thank you. Thank you, Britney. Yeah, it’s very very interesting. I see
44:01
and I see another question asking why like a you know a well-known tech
44:05
company is inefficient in catching uh scam ads and things like that. I don’t
44:09
you know I don’t know I’ve you know I’ve never worked at that company but I have
44:12
worked at many other large companies and so I tend to assume often it’s not that
44:17
they’re not aware of like what the signals look like it’s technology
44:21
limitations. when you have a really large platform that scales across, you
44:25
know, many user bases, you’re always dealing with the challenge of latency,
44:28
right? And so to do sort of risk checks and evaluations, you have, you know, a
44:32
system that calls out to this system and that system, but then you also have the
44:35
sort of SLAs’s and, you know, requirements to be able so the user is
44:39
not sitting there waiting. And so I think a lot of times, you know,
44:42
companies sort sort of struggle with that. And in addition to having sort of
44:47
really outdated tech stacks, right? So I’ve seen under the hoods of a lot of
44:50
companies that the the the tech stack has it’s it’s been there for you know 10
44:54
years 20 years and they just make incremental changes to it. They never
44:58
like rip and replace it. So um that’s just speculative answer but a lot of
45:02
times I think it’s due to sort of you know very challenging technical
45:05
limitations. I don’t know Bernie did you have anything to add to that that
45:08
question?
45:10
>> I would agree and I would just also add the additional wrinkle of policy writing
45:14
a policy as to what is permitted or not. Is there an instance where you’re
45:18
allowed to have a celebrity deep fake be in an ad? Well, what if it’s parody? We,
45:24
you know, allow celebrities to be portrayed in cartoons to be uh parodyied
45:28
on Saturday Night Live. Is that legal? Yes. So, how is the ad using the
45:34
celebrities image? That drills even deeper to a real nuance that would be
45:38
quite difficult for, you know, a tech company to tackle at scale with a huge
45:44
volume. But I do think it’s a really important issue because the deep fakes
45:48
that we see can absolutely be malicious and can absolutely be tricking somebody
45:52
into handing over funds. You know, we’ll see celebrities accounts on various
45:57
social media sites be taken over and then post malicious crypto links that
46:01
actually happened to a fast food restaurant within the past recent weeks.
46:05
Uh, and we will of course be using or we’ll of course be seeing this happen
46:10
with political figures as well. As we inch closer and closer here in the
46:14
United States to our federal election in November, there’s, you know, increased
46:19
chances for there to be the use of political deep fakes to spread
46:22
misinformation in addition to stealing funds. So, it’s still important to
46:27
tackle, but you’re right. There are technical
46:31
restrictions and then there are nuances that have to fall into policy to catch
46:37
up unfortunately.
46:40
>> Great. Yeah, great. Yeah, the policy aspect is Yeah, it’s always something I
46:43
tend to forget about myself. See a couple more more questions in
46:50
here. Uh, how are fraudsters able to get into customers OOLB without having any
46:55
contact with the Do you know what OOLB stands for, Britney?
46:59
>> I actually do not.
47:02
>> Yeah. So, not we’re not really sure um what that means, but if you’d like to
47:06
clarify if you’re still on
47:08
>> ah online banking. Perfect. Thank you so much for for popping back up. So, how
47:12
could they get into someone’s bank account without having contact with the
47:16
customer? Understood. So, uh, I would just say that there are robust data sets
47:22
or FOSs that are available out there that have enough customer information
47:27
that one may be able to log into someone’s account without needing to
47:31
contact them. However, contact is pretty common when it comes to something like a
47:38
onetime password or OTP code needing to be sent to somebody’s device to prove
47:42
you are who you say you are before logging in. And that’s where they use
47:45
social engineering or they use bots that can mass send the messages that are
47:52
intercepting or asking for those OTP codes in order to gain access to
47:57
somebody’s bank account. So they may use multiple layers of tooling. And I would
48:02
recommend whenever you possibly can turning on multiffactor authentication
48:06
for any accounts that you have online. I have a uh handful of accounts where I
48:12
get login attempt notifications multiple times a month. Like some of
48:18
them get so bad where I get it multiple times a week. But I just know that there
48:22
are accounts that fraudsters are interested in and I want to you keep
48:26
them locked down. And so I have as many places where I can put those protections
48:30
in place. I have them in place. But I’m also, you know, somebody who’s been in
48:34
fraud prevention for almost 15 years and I’m really suspicious of any texts that
48:38
I get or any phone calls that I get and I’m not likely to hand over information
48:43
to a fraudster. But there are people out there who who aren’t as savvy and will
48:47
unfortunately share that one-time password. So, they do have to have
48:51
contact with the customer in some cases, whether they’re pretending to be the
48:54
bank or just sending that text message. And it can happen either way. And one of
49:01
the more interesting things about that tool that we have been testing about,
49:04
which we’re hoping to be able to share more public information soon, is that
49:08
you can get so much partial information from all of the various breeze breaches
49:13
that have affected one individual that even if with the one query you’re
49:18
running about their bank account information, you don’t have let’s say a
49:22
phone number, if I’ve got another piece of information where I can look in
49:26
another database or base within this tool, then I can probably find a phone
49:31
number there. Um, we did a test of looking up sort of known identities and
49:37
seeing how fast we could get to certain pieces of information and it was a
49:41
matter of minutes before we were able to do so. So, I’m the downer at parties
49:45
when I share those stories.
49:47
>> And I and I would just tag on to the use of OTP, you know, um, just consider how
49:53
it’s, you know, what channel you’re using. um a bad actor could access an
49:58
email address much easier than a phone number, right? So there there’s
50:01
exceptions, but oftentimes traditional SMS content is stored locally on on a
50:06
device, right? So think about how your email address can be accessed. Well, any
50:10
internet connected device on the web, right? Um now, how can your text message
50:14
content be accessed?
50:16
>> Uh much more difficult, right? So sending an OTP via text traditionally
50:20
will always be more secure than sending an OTP via email. So, those are some
50:25
things to consider as well.
50:26
>> Yeah. And then there there’s I don’t remember how many years ago it was. It
50:30
must have been about six or seven years ago. There was one major cellular
50:33
provider that offered the ability for people to have their texts also be
50:37
viewable via the web. And fraudsters loved that
50:41
>> because then it completely bypassed any need to get the victim to send the
50:47
onetime password code to the fraudster because the fraudster was already logged
50:50
into their cellular provider account and would just watch the numbers pour in
50:54
there.
50:56
>> Yeah. Yeah. Yeah. Great. Yeah. Great points. Yeah. As as we um enabled things
50:59
for our convenience, we’re also enabling things for bad actor convenience. Um so
51:04
always keep that in mind. For sure.
51:06
>> Yeah. And so it looks like we got kind of one follow-up question about the idea
51:11
we’re talking about with celebrities and deep fakes that I think makes kind of a
51:14
a good point for us to to cap it up and end on. It’s the question of so is the
51:18
technology not there yet or is it a lack of will and man is that a constant
51:24
frustration for fraud fighters. You know something is a big problem. you know,
51:30
it’s important to fix, but maybe you can’t get uh management’s attention or
51:36
leadership’s attention. You know, I’ve had somebody that I used to work for who
51:40
told me that fraud takes care of itself from his opinion. He was a like VP of
51:44
operations and he believed that because my team was so good at stopping fraud
51:49
and I, you know, we did such a good job that we didn’t get the resources and
51:53
help that we wanted. It it can be that frustrating. I personally would be more
51:59
of the optimist saying it’s not the the lack of will, but
52:04
it’s so many more factors than we can cover in this moment about what a
52:09
publicly traded company does when they make certain decisions with their tech
52:14
stack and with their priorities. So, you know, I think the technology is there in
52:18
part. there is still, you know, quite a bit of nuance obviously that needed need
52:22
to go into. Um, but there are people who are within these organizations and
52:27
completely acknowledge that these are issues that need to be tackled. They
52:30
just may not be the uh loudest voice in the room or actually even be in the
52:35
room. And that’s a another conversation for another day, but it’s it’s a true
52:39
point of frustration. And at the riskrevenue forum that I showed you the
52:43
picture from earlier, uh when we were in New York, we actually had a conversation
52:48
about how long is it going to take before there is a chief risk officer who
52:54
has the same seat at the table along with the CISO and how long will it be
52:59
until there’s that executive exposure. We can’t think of a good acronym though
53:02
if someone wants to help because chief risk officer, CRO is also like chief
53:06
revenue officer and then chief fraud officer is like CFO or finance. So if
53:11
anyone can think of what the better title is, I’d love to hear it. But we
53:15
were wondering who in the fraud fighting world is going to be that first
53:19
executive level fraud fighter. And I’m excited to see it when it does happen.
53:24
Maybe it’ll be uh you Kobe.
53:26
>> Yeah. Yeah. Who knows? Uh yeah. No, great points. And it’s also you know
53:32
what what you said reminded me too of like the you know the constant pendulum
53:35
in the in the market is like okay focuses on loss reduction. No focuses on
53:40
business enablement. I think like the safest one is always especially during
53:43
these times business enablement. So like just just framing the investment not as
53:49
solely uh risk you know risk management but also business enablement right. So
53:54
how many how many legitimate customers are decline and go elsewhere. The
53:58
challenge is it’s often speculative because you don’t have data outside of
54:01
your business that they went elsewhere, but you can start to come up with sort
54:05
of uh calculations and extrapolate that um and then just you know sort of
54:09
provide those estimates. So focusing on the incremental revenue um that the tool
54:16
will provide uh it goes much farther sometimes than you know sort of the the
54:20
risk reduction.
54:23
>> And we got the suggestion of CFPO chief fraud prevention officer. That works for
54:27
me.
54:28
>> Nice. Awesome. I know we’re Yeah, we have five minutes.
54:36
I do see one more question. It’s a bit It’s a bit um um specific, I suppose. Um
54:41
what are best practices for detecting fraudulent claims from customers on
54:44
first attempt? Um yeah, I mean there’s I mean without a lot of details on what it
54:50
looks like, it’s it’s hard to say. Uh like the concept of velocity, for
54:53
example, relies on multiple events, right? So some of those fundamental
54:57
controls are not designed to uh to detect uh you know first attempts. But
55:02
the you always go back to just looking at as much data as you have and trying
55:06
to understand what is unique about this specific claim or this event that maybe
55:11
is not very prevalent or unique in in legitimate claims. And it’s not
55:15
necessarily about finding what’s the one signal that is only on fraud events.
55:20
Right? I think a lot of novice bad actors expect to see that. but it’s more
55:23
so what signal is on this event that’s not on many other legitimate events,
55:29
right? And so that will allow you to sort of manage your false positives, but
55:32
without having more details, I guess it’s hard to hard to say. Britney, do
55:35
you have anything to add to that?
55:37
>> I would say make sure it is actually the first attempt. There could be a
55:42
connected account that you’ve already taken action against and identified as
55:46
fraud. And you need to see does it fit the pattern of that account’s behavior.
55:50
Is it connected to any of the data from that account like reusing IP or device
55:55
or user agent or any other fields? And you’ll find often these repeated
56:00
patterns. It could be for actual fraudsters. It could be for sort of one
56:05
of those entrylevel fraudsters or entry-level people who are
56:09
opportunistically looking for a deal on your site, but
56:13
maybe they’re following a script or a guide written by a professional
56:17
refunder. And so they’re still taking steps and doing things in a pattern that
56:22
fits other known malicious activity. So I would say just make sure it actually
56:27
is a consumer coming in with a brand new fresh first attempt because you may be
56:32
surprised at how many repeated patterns you do see when you look at that broader
56:36
picture.
56:40
>> Great points. Looks like we have another one just came
56:44
in. How often would you say companies are part partly responsible for allowing
56:48
fraud to exist filling regulatory needs but otherwise giving uh I don’t I
56:51
wouldn’t say it’s common at all um in my my personal experience that said I did
56:56
work for a large fintech company I’m not going to name them but most of you would
56:59
know and they did have the idea of control groups uh where they would allow
57:03
fraud to slip through for the purpose of more effectively monitoring their false
57:08
positive rates. And so this was kind of shocking to me when I learned it cuz I
57:11
came from the merchant world and then I went to this big fintech company. I was
57:14
like, “Wow, like that’s very risk. That’s interesting.” Um, but it actually
57:18
worked. And so false positives are often, you know, just speculative. So if
57:22
you have a control group that allows fraud to go through, you can actually
57:26
see how effective your your model actually is on that on that sample
57:28
within the control group. But that said, I’ve only heard of that company doing
57:32
it. I’m not saying other companies don’t. I don’t think it’s a super common
57:35
thing. So I don’t my personal experience has not been that companies are looking
57:39
for ways to benefit from fraud. That said, I will say there are precedents uh
57:45
where merchants try to send every they’re more like smaller merchants that
57:48
aren’t uh savvy with risk practices. They put everything through 3D secure
57:52
right outside of the US. That is a little gray. Like this may be fraud,
57:57
maybe not. I’m not liable. I don’t care. I’m going to put it through. That’s
58:00
probably the closest thing I’ve seen to what you describe. I guess Britney,
58:03
anything to add on? Oh, well, with our last minute, I’ll just say uh again, as
58:08
the person who leads the deep and dark web investigations team, we’re really
58:12
enjoying watching the fraud chatter around the recent arrests of the creator
58:16
of Telegram, which one could potentially argue, although there are a lot of
58:21
legitimate and great uses for the Telegram app, does have a culture of
58:27
fraud being able to subsist within its network. and fraudsters are now having
58:33
conversations about what to do and where else to go if Telegram gets shut down.
58:38
And that’s that’s pretty interesting uh insight. I know that’s a little vague on
58:43
my part, but I do think it’s a valid question to ask because when you do
58:47
maybe find some instances of companies that have, you know, structures where
58:54
fraud can be a little bit more open and can persist. you could look at the fraud
58:59
activity there and learn something from it for your own org.
59:04
>> Great. Yeah, great points. And we’ll pass it back to our host.
59:07
>> Yeah. Uh, excellent conversation. I know it’s top of the hour and a lot of people
59:11
got to drop off, but uh, thank you all so so much for joining today. Again,
59:14
this webinar will be recorded and sent out uh to everyone. I know there are a
59:18
couple other questions in there we didn’t get to, so I will be sure to make
59:22
sure we answer those offline. Thanks again and we’ll see you all at our next
59:26
webinar. Thank you everyone.



