This session explores the increasing threat of account takeovers (ATO) from two expert perspectives. From former fraudster to fraud fighter, Sift Trust and Safety Architect Alexander Hall reveals why ATOs are so appealing to criminals, offering insider examples of how fraudsters use multiple fine-tuned methods to successfully breach accounts.
Stewart Reilly, Fraud Manager at Engine, also shares actionable insights on detecting and preventing these advancing ATO threats. You’ll learn about the real-world tactics used by fraudsters and discover strategies to protect their customers and business.
Key Takeaways:
- How ATOs put customer trust and brand reputation at risk
- Why not all ATOs are reported through chargeback metrics
- Empowering fraud teams with passive datasets to improve protection without introducing friction
- How to effectively defend against ATOs with a holistic fraud strategy
Watch the Webinar
Video Transcript
0:00
Thank you for taking time out of your day to join us for this webinar, the ATO
0:04
playbook, insights from a former fraudster, and Stuart, the fraud
0:08
manager. We’re going to give a couple of minutes for people to trickle in and
0:11
then we’re going to hop into introductions and then the content. Uh,
0:15
and hopefully at the end we’re going to save some time for some good
0:18
conversation. So, yeah, in a couple of minutes we’re gonna go ahead and get
0:21
started. While you’re waiting to uh we’re waiting
0:28
for people to uh to fill in, Alex, have you heard the uh the recent news about
0:32
Apple and their new approach to uh technology protections and all that
0:36
that’s been popping up recently? I’ve heard bits and pieces, but I
0:41
haven’t dived into it. It’s interesting. I haven’t dive dove
0:53
into it either. Um, but I think it’s a step in the right direction and
0:57
obviously once Apple or another company the size of Apple takes that initiative,
1:03
everybody will be following suit. So, some might find it frustrating or
1:08
intimidating with that those kind of changes upcoming, but I appreciate it
1:13
because it’s a step in the right direction to uh handle challenges like
1:16
atto and payment nonsense.
1:20
>> Very cool. Let’s uh pick up that conversation offline. Uh, all right. So,
1:24
let’s go ahead and get started with introductions. Stuart, please go right
1:27
ahead. Tell the beautiful people all about yourself.
1:30
>> Hey everybody, I’m Stuart Riley. I currently work for Engine, which is a
1:33
business tra. Um, I’ve been in the fraud space for the
1:37
last nine or 10 years. um anywhere from J C Penney, Amazon um to some direct
1:43
selling space with Modair. Um and then I got my my foot in the door with uh with
1:50
Radial, which is a service provider out of the Philadelphia region where we
1:54
service about 130 different merchants. So, a little bit of everything as far as
1:58
fraud and uh and workspaces go. E-commerce, travel, direct selling
2:04
space. Um, and then the big bad wonderful amazing Amazon U or Alex, I
2:11
know everybody should know you, uh, but you want to give a a brief rundown of
2:14
your your background, good and bad.
2:17
>> Hello everybody. My name is Alexander Hall. I am a trust and safety architect
2:20
here at SIFT. Uh, I joined back in August. Prior to that, I was a
2:25
fraudrevention strategy consultant where I worked with many different vendors.
2:29
Uh, and through that worked worked with many different companies. Prior to that,
2:33
I was the head of fraud at an international vape retailer. And prior
2:38
to that, uh, for about 9 and a half years, I operated as a fraudster on the
2:42
other side. Everything from check and card fraud, gift card manipulation,
2:48
ATO’s, identity theft, synthetic ID fraud, and more. Um, for this for this
2:54
webinar, I’m going to assume the persona of the former fraudster at the beginning
2:57
and give you guys actionable insight from the mind of a fraudster. Uh,
3:02
Stuart, thank you so much for joining me. Let’s go ahead and kick things off.
3:08
The agenda is we just went through the welcome and the introductions. We’re
3:11
going to dive into for like the first year fraud fighters, we’re going to dive
3:14
into what is an ATO. We’re going to get into the unique characteristics of ATO,
3:19
why it’s such a challenge, uh how it’s propagating throughout the marketplace
3:22
and things like that. Then we’re going to switch from talking from the
3:27
fraudsters for the former fraudsters speaking about their experience. We’re
3:30
going to switch over to Stuart where we talk about strategic uh development
3:34
discussions. We’re going to hop into all those items that go into it. We’ll recap
3:38
with actionable takeaways and hopefully we’ll have some time at the end for some
3:41
useful conversation. We just hit introductions. Let’s go
3:45
ahead and get started. When everybody thinks about payment fraud, they
3:49
typically think about credit cards. That is always what comes to mind is is
3:53
compromised credit cards being used for payments. Um, in our Q1 2025 report, we
4:00
found that payment fraud through various payment methods were uh had resulted in
4:07
an attack rate of 3.3% across the entire marketplace. Well, as
4:12
you see here, per our fiber uh resource, we’re seeing that atto is having a 3.2%
4:20
attack rate across the marketplace. So, we’re seeing these two fraud methods be
4:25
head-to-head. And that that should articulate to everybody here that ATOS
4:29
are rising as the number one attack vector for fraudsters. We can see the
4:33
trend lines on on on screen. And to the right hand side, we see that the current
4:37
two-factor authentication rate, the adoption rate is at 12%. One key
4:41
takeaway from that is the idea that fraud that uh that users are becoming
4:46
more familiar and more uh are adopting MFA verifications uh more and more as
4:52
time goes on. Stuart, what do you have to say about the uh the stats that are
4:55
on screen here? So, the the thing that jumps out to me
4:58
about 88% of the time, I know we talked about this in the past, um that’s where
5:03
the the multi the MFA is is not succeeding.
5:08
That’s what that that’s the unknown. But to me, what that screams is that there’s
5:12
a lot of lot of fraudsters and bad actors trying to get through. Um so we
5:18
need to continue to focus our attentions and our uh planning and architecture to
5:24
have layers of protection. Um because clearly there’s a lot of trial and error
5:29
in trying to get through these s systems and penetrate them. Um and we need to
5:34
make sure that we have systems in place to be able to handle that. And I’ve seen
5:38
it at the various organizations. Some do it very well. Some have it very planned
5:42
out and thought through and others that aren’t going to be named in this
5:47
conversation here. Um, clearly didn’t put the forethought into
5:53
protecting against issues like this and it creates a headaches for teams like
5:57
mine.
5:58
>> I love that you you spoke to the value of what I’ll call the contrasting data.
6:04
So, we see the 12% rate there on screen, but now what information can we glean
6:08
from the 88% that that remains, right? But I love the fact that you dialed in
6:12
on that and I know we’re going to cover it later on, but um I think that’s a
6:16
great kickoff because there’s a lot of useful insight that would come out of
6:19
that 88% that you know, like you just said, people need to be tracking 100%.
6:25
So kicking off, what is an account takeover? Right. So for you first years
6:30
out there, uh an account takeover in its simplest form is when a bad actor gains
6:36
access to an established account. Now you see on screen that there are
6:39
different types of targeted accounts. So we’re familiar
6:44
because of course that’s what we hear about. We are consumers ourselves and so
6:48
we’re worried about our accounts being taken over. But now in addition to that
6:51
we’ve got two other kinds. We’ve got business and employee. So imagine
6:55
whenever we’re talking about a banking system when a bank business account is
7:00
taken over or think about a marketplace where a retailer’s account is taken
7:04
taken over on the platform, right? that’s going to have its own set of
7:09
variables. It’s going to have its own workflows. It’s going to have its own
7:11
processing, but it’s also going to have its own value to the fraudsters. Right?
7:15
So, one case that comes to mind when I discuss that is whenever uh there was a
7:19
a big marketplace out there that handled food delivery service and they had
7:25
contacted me to to help assess and and and help develop a strategy. And what
7:30
was happening was the fraudsters were gaining access to the restaurants
7:33
accounts. Then they were getting in and they were changing the account
7:37
information like the billing information and that was uh allowing the fraudsters
7:41
to put their own bank accounts on the platform for withdrawals. So now we’re
7:47
seeing all all of these good restaurants and and good businesses raise their
7:51
funds and then lose it because a fraudster gained access to to to the
7:55
business account. An interesting item there is the fact that in that dynamic
8:01
that is a high value loss, right? Maybe low volume but high value loss and it is
8:07
not represented in chargebacks, right? So of course now we have to reimburse
8:12
the the the merchant. We have to u make them whole of course but we also have to
8:17
deal with you know brand reputation and customer satisfaction and all those
8:21
things. Stuart, what do you have to say when it comes to uh business accounts
8:26
being compromised through ATOS’s?
8:28
>> And you hit it hit the nail right on the head, Alex. You you have to deal with
8:31
the the repercussions of a situation like that with the the reputation of of
8:36
the company that’s handling the platform or protecting it. Um, the other part to
8:42
it is is for small businesses, like you said, it’s not a large impact as far as
8:46
financially goes and it’s not going to impart impact their chargeback numbers.
8:50
But let’s be honest, most small businesses don’t have the flexibility to
8:54
be able to take a hit like that. Whether it be a,000 bucks or $10,000 or more,
8:59
they don’t have the flexibility or the capacity to handle those kinds of
9:04
impacts. That could make or break a small business. And in the states, a lot
9:10
of the backbone of this country is small businesses. We don’t have the the large
9:14
retailers that can that have the flexibility and the capability to handle
9:19
impacts like that. So these types of attacks are are integral to to
9:23
preventing and it it goes back to what I was referring to earlier is when you
9:27
don’t plan and have these systems in place. Let’s be honest, hindsight’s
9:31
2020. There shouldn’t be an easy way to change
9:36
banking information on an account like this. Especially for a small business,
9:40
there should be a process in place. And if something does change that should
9:46
throw off some alerts to the appropriate appropriate teams at hand so they can
9:52
review those changes. Oh, they are banking with bank 123 and now we have a
9:57
bank that’s so many miles away. It doesn’t have a
10:02
good reputation. It’s I mean again hindsight’s 2020 but having those
10:07
controls and those alerts in place are integral into being able to alert and
10:11
identify when these changes occur and you get ahead of the problem instead of
10:14
trying to play cleanup. It’s, you know, going back to to like my story with
10:20
everything. You know, whenever I tell people and I have the conversation, I
10:24
work in fraud. Immediately, everybody goes right to, oh, that’s so cool. You
10:27
get to prevent fraud. You get to stop it. But it’s much more dynamic than
10:32
that. You’re trying, you’re trying to let the good flow and stop the bad. And
10:36
usually what that means in reality, you have to put in minimal friction so that
10:40
you allow your good customers to be able to conduct business, but you
10:45
also have the controls in place and friction in place so that it doesn’t
10:49
make it easy for the fraudsters or the bad actor actors to be able to pull off
10:55
stunts like this.
10:57
>> You bring up a great point when it comes to the businesses and and to touch back
11:01
on the MFA adoption rate. I know that a lot of people across the marketplace,
11:05
you know, they see friction as the f-word. You know what I mean? Like
11:09
that’s that’s it’s always a horrible thing. But the truth of the matter is,
11:12
um, yes, consumers, their adoption rate is is growing, but business adoption
11:17
rate is growing even further because they themselves recognize that in the
11:21
SMB territory, they can’t take a $10,000 hit. Like you just said, whether it’s
11:25
one, five, or 10,000, they can’t take that hit. they are happy to see, you
11:30
know, hey, something happened and and this is a very important thing to me. I
11:33
need to verify, I need to confirm then all these different items. Great point.
11:38
The last persona there that we’ll jump into is the employee. Now there was I
11:42
think it was last year or maybe the late the year before there was the employee
11:46
that was socially engineered and through uh through coercion and
11:52
account takeover you know within the platform the employee ultimately wired
11:56
out you know tens of millions of dollars you know from a company overseas. Now,
12:02
the persona being attacked here, at least through the lens of a fraudster,
12:06
is going to be much different because when a fraudster gains access to an
12:09
employee account, typically what they’re going to be trying to do is to go enact
12:14
processes on the back end. Like in that story, they were they were attempting to
12:18
to form a communication with somebody who had the authority to to initiate a
12:23
transfer of funds. Here’s what you need to pay. Here’s how I want you to pay it.
12:27
Go ahead and take care of it. And that loss was tens of millions of dollars.
12:31
Right. And so across these three personas, we see many different use
12:34
cases, many different value props through the lens of a fraudster and many
12:38
different processes in order to to uh in order to achieve it. Um Stuart, before
12:44
we move on, any final thoughts on this slide? Yeah, even when I was breaking
12:48
into the space, um, going back to kind of the the f-word, when I would have an
12:54
order cancel on a good customer and that friction was in place, it’s all about
12:59
controlling the dialogue. I would simply put it, hey, we have these controls in
13:04
place. Unfortunately, sometimes good customers and good orders get caught
13:07
into that, but we have these controls in place to keep our costs low and and be
13:11
competitive. And generally speaking, nine out of 10en times whenever I put
13:15
that that that narrative, people were appreciative that we were proactively
13:20
trying to protect their information and the companies.
13:23
>> And even now it it’s like you said, companies are adapting it much faster
13:28
because there’s an a business necessity for it. But people are more conscious of
13:33
of the challenges that these that companies are dealing with and they’re
13:38
tolerating it at a much higher rate. um both as a like a gut check and like with
13:44
with there’s the data to back it up
13:48
>> 100%. Yes sir. Uh so moving on to in practice when I
13:55
was on the other side and I was trying to extract value through accessing
13:59
different types of accounts I it was conscious to me that different platforms
14:03
have different types of of value right and so the two top the two top
14:09
categories that I’ve outlined here are I gaming and crypto on one side because
14:12
through the lens of a fraudster it’s very similar and then on the right hand
14:16
side we have e-commerce because of course that’s that’s what everyone
14:18
thinks of when they think about fraud prevention.
14:21
So gaining access to an account doesn’t provide direct value to the fraudster.
14:25
Fraudsters are after what comes next, what can come next. So on the lefth hand
14:29
side we see when it comes to eye gaming and crypto um gaining access to an
14:33
account, the fraudster can extract PII, the personal identifiable information,
14:37
they can update the account. So let’s say a fraudster gains access to an i
14:42
gaming account and they update the contact information or they update the
14:46
AC deposits and withdrawal situation. Let’s say they they change the banking
14:50
information generally. Um let’s additionally say that they update, you
14:54
know, credit card and payment information, right? All of these
14:57
different items are going to be important. And at that point in time,
15:01
there’s only a few data points that are going to be relevant. And if you’re not
15:04
tracking it, you’re going to miss a critical part of the story, right? And
15:07
then later on down the road is when they initiate the uh the withdrawals or the
15:11
transfers. Now, this is going to be equally important because when a
15:14
fraudster has funds sitting around in all these compromised cards or these
15:18
compromised checks or these compromised bank accounts and different different
15:21
types of categories, they’re going to be looking for opportunities to take those
15:25
funds, deposit them into something like a vehicle like I gaming, like crypto,
15:30
like fintech, like banking, like credit unions. But if they can park those funds
15:35
in I gaming and crypto and let those funds clear before finally withdrawing
15:39
them to another account, that’s going to be a a a gamewinner for them because
15:44
they get to transact and not lose any money. They don’t have to go buy
15:47
products and then go fence them off on the black market, sell them on
15:50
marketplaces and things like that. There’s a tremendous value in ATO in i
15:55
gaming and crypto similar to banking and credit unions. As far as e-commerce
16:00
goes, the same idea exists whenever it comes to the PII extraction. Uh but then
16:05
it’s pretty straightforward after that. Payments are used uh whether it’s stored
16:09
payments information or the new compromised payment information being
16:12
used to transact um and then ultimately commit the payment fraud. So when it
16:17
comes down to the industry breakdown of ATO’s and the value that fraudsters can
16:21
extract, uh Stuart, what what jumps out to you?
16:26
One thing I wanted to point out out of all of that is
16:31
clearly when there’s funds in place they can move them sit on them they can
16:36
extract them immediately. One thing that I wanted to mention is another pro
16:42
prospect to excuse me perspective to look at is
16:48
with traditional e-commerce and credit card fraud. Another thing that they’re
16:51
doing is selling the information through the the various markets, whether it be
16:56
the dark web, Telegram, or any of the other platforms that the the frauds just
17:00
like to to use and communicate on. It is much easier um to have somebody else do
17:06
the the heavy lifting and just, hey, I have an account with this amount of
17:10
money on it. It’s worth this much. And that activity is so easy, especially for
17:16
the amateurs in the area, um, to get their feet wet and they’re hungry for it
17:22
and they’re willing to pay for it, both with their information and with stolen
17:25
credit cards. That’s the one thing that I want to touch on here. And from my
17:29
space outside of these two areas, um, in the direct selling space, one of the
17:33
challenges that I had there is that we had um, commissions. So, we didn’t have
17:37
the traditional um hey, e-commerce uh a 24 to 48 hour authorization period. I
17:45
had to do an evaluation and decision right away. And then the same thing goes
17:49
for travel. So, I don’t have the flexibility like some of the e-commerce
17:52
does. So, it’s made my job of being able to sort through the good and the bad and
17:56
putting that friction in place much more difficult because I have to make an
17:59
immediate decision. There’s no manual review in either of those um in either
18:03
of those areas and it makes it even more complicated and challenging to tackle
18:08
challenges like this.
18:10
>> Everybody has a pressure to make their decisions in in in a shorter timeline.
18:15
Granted, yes, things can take time, but we’re always under pressure to make
18:19
decisions as quickly as possible. And you just touched on that point, but I
18:23
think that I want to ask you gleaning insight from across the entire
18:29
customer experience journey. Suspicious behavior at login, suspicious behavior
18:33
at account creation or uh account um changes, account updates, transaction,
18:39
customer service interactions, all of these different things. Can you imagine
18:44
or what do you have to say about the value of of getting the entire story
18:48
presented to you? um when it’s time to make a decision versus just watching
18:54
checkout or just watching login behaviors, right? Speak tell me a little
18:59
bit about the context and how important that is in order to make, you know,
19:02
short shorttimed decisions accurately.
19:06
>> The the comparison that comes to mind there is is having a a cheat sheet that
19:10
can fit in the palm of your head hand when you’re just looking at checkout
19:13
versus an entire playbook and and a a how-to guide when you’re looking at the
19:18
entire journey. And let’s be honest, over the last couple of years, even the
19:23
companies that have the the checks and balances and control points along the
19:29
entire journey creation changes, check out, you know, looking at the
19:35
activity as they’re shopping. Even those being in place with AI and bots in in in
19:41
the play now in play now, it makes it even more complicated and challenging to
19:46
be able to identify and and hold off some of the
19:51
challenges. With account creation, if you have identity solutions in there
19:54
like know your customer, KYC, and and identity validation, that’s all great,
19:59
grand, and wonderful. But with the assistance of bots and AI now, it makes
20:03
it that much easier to fake that information or to take good information
20:07
and create new accounts with it.
20:10
>> Great point. And from the fraud former fraudster perspective, 100%. Uh, I knew
20:15
when I was operating or seeking to find vulnerabilities and and draft up
20:20
exploits, I knew that if I would just satisfy the requirements at each
20:24
individual touch point, I knew that once I satisfied it, I was able to to go do
20:29
the other things I needed to do, which is actually a great segue into the next
20:34
slide. So where I lived while I was on the other side 15 years ago at the
20:39
height of my career on the other side was in a type of methodology or a
20:44
category of methods that I call multi-system. So for everybody in
20:47
attendance on screen you have a framework that I’ve created that I share
20:51
right and it breaks down all fraud categories into three different types
20:55
three different categories right we have linear at the bottom which is the most
20:59
the most simple right think about a fraudster who as as Stuart just said
21:03
gets a hold of compromised information that was obtained elsewhere and sold in
21:07
a marketplace. The fraudster gets a hold of this compromised information. They go
21:11
through guest checkout, no account creation, run over to checkout or build
21:15
their cart, run over to checkout, checkout A, B, very linear. And in those
21:21
types of methods, it’s easy enough to just track one touch point, the
21:26
checkout. That’s where all your decisioning lives. Now, think about
21:30
attos. Somebody gets a hold of compromised credentials, login
21:34
credentials. They go to the login form and they log in. Well, isolated and unto
21:39
itself, that’s fine. But as I said on the last screen here, fraudsters are
21:44
after what can come next after login. So now fraudsters are moving into that
21:51
multi-touch category there where across the one platform, they’re contacting
21:57
customer service, then they’re logging into the account, then they’re
22:00
transacting, then they’re manipulating the orders, and then they’re coming back
22:04
and updating account information. all of the visibility of their story. Granted,
22:09
it jumps around the platform place to place to place to place in order to be
22:13
successful. The entire story is visible on the one platform.
22:18
Up from there is multi-system and we won’t spend much time on that but it’s
22:21
just something to put in your uh to to to put in your head. Multi-system is
22:26
where I used to operate which is uh for example o like uh Stuart just said using
22:32
compromised details to open up an i gaming account using an atto gain access
22:37
to a banking account transferring funds between the two well that story in order
22:42
to get 100% of the story you need visibility across both platforms and
22:47
we’re not there yet and thankfully it doesn’t seem that fraudsters are
22:50
consciously using different systems as pawns as much as this multi-touch
22:56
category. So there’s a framework for that. Stuart, do you have anything to
22:59
add here?
23:01
>> So the the one thing that I wanted to add um especially when it comes to to
23:04
account takeovers, one of the the biggest enablers for fraud service is
23:08
compromised credentials. Often you often associated with widespread password
23:15
reuse. Password hygiene is one of the easiest things that you can do to
23:20
protect yourself. Let’s be honest, whether it be an Android, an Apple
23:24
device, we have password managers on our phones. And even further than that, to
23:29
to continue the the convenience, you can go into to various browsers of password
23:34
managers that can you can seamlessly jump from your mobile device to a
23:38
computer to your tablet. It’s really easy to say, generate a
23:42
complicated password for me and don’t recycle passwords. That’s the biggest
23:46
thing that I tell family and friends when we have the fraud discussions.
23:51
Don’t reuse the same password. It’s going to be compromised and it’s going
23:55
to cause a headache for you and nobody wants to deal with it. And ironically,
23:58
when that happens, I’m always the first PE person that people call be like,
24:03
“What should I do?” And I
24:06
>> being a fraud fighter, man.
24:09
>> It it’s it’s like working in it. Whenever somebody’s computer breaks,
24:12
they always come to that same person. the same thing with with being a fraud
24:16
fighter. They don’t hear my warnings until it happens to them. And I will be
24:21
blunt and honest. This is I take that opportunity to be like, “Hey, I told you
24:25
so, but let’s learn from this situation and let’s do this going forward.”
24:29
>> 100%. Uh so the three different categories of
24:34
ATS, we’ve spoken about the value, we’ve spoken about what kind of method it is,
24:38
we’ve spoken about the different personas that are attacked. So now how
24:42
do fraudsters gain access to accounts? Right? So it pretty much breaks down
24:46
into three categories and there are a few exceptions outside of this but these
24:49
are the three main ones that we’re going to experience. So number one Stuart
24:52
exactly what you were just saying credential stuffing where the login
24:55
details are compromised somewhere. They’re put up for sale copied and
24:59
pasted into a foreign form and the fraudster gains access. It’s at this
25:03
point that you’re going to want to be able to track things like geoloccation
25:06
against you know historical login. You’re going to want to track new device
25:10
performance. you’re going to want to track velocities. It might be great like
25:14
one thing that Sift offers is that we’re able to see when one device is used to
25:18
access 20, 30, 40, 50 different accounts. And one thing that that is
25:22
directly effective uh effective for is credential stuffing where a fraudster
25:27
gains access to or tries to access a number of different accounts from one
25:32
device. Right? So that’s going to be extremely important whenever it comes to
25:35
credential stuffing uh at login. Right? The second category there is social
25:40
engineering of the user. Now this is going to be an example of that
25:43
multi-system category I was talking about where the fraudster gets access to
25:49
the user. The fraudster says I want to access Bob’s account on this i gaming
25:55
platform. So instead of using instead of interacting with the platform directly
26:00
the fraudster will go to the user. It’ll go to Bob directly and I’ll say hey man
26:03
we’ve got this promotion running. You just need to log in here and offplatform
26:09
Bob types in his login details for whatever reason. And this can take place
26:13
through scams, email compromises, and the interception of one-time passwords.
26:18
That’s the second category. And again, that story is both on and off platform.
26:23
So, it’s a multi-system type of exploit. The third one there is social
26:27
engineering of the platform. This is something that I did exceeding I did
26:31
exceedingly well with. And the story goes like this. the fraudster will call
26:35
into customer service uh with 20 or 30 different accounts that were um being
26:41
identified. And what I would do is I would tell customer service, hey, my
26:45
name’s Bob. I’m trying to access my account, but my phone got stolen. My
26:50
email is compromised. I need to set up new access. What is the process for
26:55
changing the account details through customer service? and they’re more than
27:00
happy to tell me what their process is, what information they need.
27:05
Now, I take that and I copy and paste it across the 20 other accounts that I’m
27:10
trying to compromise, I’m trying to gain access to, right? So, now I know what
27:14
their process is and I walk through that process for all 20. I reset access to
27:19
new emails, new phone numbers, and I send out the password reset. But that
27:24
only works through socially engineering the platform through their customer
27:28
service. Stuart, what do you have to say here?
27:32
>> This this is a great call out. The the social engineering of the platform and
27:36
and customer service. Customer service is going to be your first line of
27:39
defense. There’s going to be more customer service. They’re going to be
27:42
dealing with the customers more. They’re going to have the insights that you use.
27:45
And if you don’t have a relationship there, you need to build one. Having a
27:51
relationship, building the information and the knowledge sharing is intricral
27:56
into stopping behaviors like this. And this was this is this was challenging 10
28:00
or 15 years ago when you were when you were actively on the on the bad guys,
28:05
bad guys side. In this day and age with AI and deep fake technology, it makes it
28:12
so much easier to socially engineer. I mean, going back to
28:16
the story that you had referenced where it was like $20 million that was wired
28:20
out of the account, it they use deep fake technology to pose themselves as
28:25
the CIO or the CEO in that scenario
28:29
>> to encourage the behavior. We need to have a basic, hey, when you encounter
28:35
these situations, this is a this is a playbook. This is your SOP. Have it
28:39
documented and have the conversation be be a two-way street. Don’t just
28:44
regurgitate a bunch of information to them because it’s not going to help
28:47
them. They’re going to have questions and they’re going to want to help out.
28:50
So, it’s integral to build those relationships, maintaining them, and
28:54
then continuing to have that journey and trail of education
29:00
because things are constantly evolving and changing. In some instances, they’ll
29:05
recycle and use old strategies and sometimes they’ll do variations of them
29:10
because they’re constantly trying to poke and prod and manipulate their way
29:14
through the systems both virtually and socially.
29:18
>> Uh you rose two great points. One, as we work in technology, there’s that that
29:24
that ongoing statement where we always say that the weakest point of technology
29:29
is the human. We say that in tech. We say it all the time, but we don’t we
29:35
haven’t yet standardized empowering or training or strengthening our CS team.
29:42
Now, on the opposite side, fraudsters know that the left hand isn’t know what
29:47
the right hand’s doing. And so, you rose another point about creating that
29:51
relationship, strengthening that relationship. When your fraud teams out
29:55
there are are are operating or offering trainings or creating webinars and
29:59
presenting amongst themselves, bring customer service in. Make them aware of
30:04
emerging trends. Build them up so that they can understand what what flags to
30:09
watch for. And then the last point you rose or raised was the idea that
30:14
fraudsters are going back to old strategies, right? And I and I was
30:18
always surprised when I came over to fraud prevention that for some reason we
30:23
think that the biggest trend represents the majority of fraudsters
30:29
when it doesn’t. It might be the biggest trend overall. Don’t get me wrong, but
30:34
there are still, I don’t know, I wouldn’t even begin to approximate how
30:38
many fraudsters there are operating, but there are still groups of fraudsters who
30:41
are just looking at this platform for the first time. And they’re going to try
30:46
this thing that happened on this website over here, they’re going to try it here.
30:49
And so as these strategies evolve and change and they they think that this
30:54
this method that took place five years ago is no longer relevant, fraudster B
30:59
is going to come over here and try that same method for the first time and see
31:02
that it’s an open door. So we need to to continually be robust and we need to
31:08
anticipate that fraudsters are they’re cyclical. They’re going to
31:13
everything’s going to keep coming all at once, right? 100%. Great points, man.
31:19
So my last uh slide here is just one thing that I wanted to present to the
31:23
attendees. It is a fraud method from my past that I saw great success with and
31:28
it goes like this. As I mentioned before, it started with social
31:31
engineering of the CS agent. I went into detail about that compromising uh
31:36
accounts through socially engineering the customer service agent. Access the
31:40
account that was pretty straightforward. Change the account details. Go through.
31:44
And now at this point I can can transact with either stored loyalty points,
31:49
stored payment methods, a new compromised payment method that I add
31:52
there. And to stay with this hypothetical method, let’s say that I
31:57
used a compromised card and I made sure to enter matching billing and shipping
32:01
address, right? It’s not my address, but I put matching and billing address in
32:06
the form in order to meet any rules uh at at that at that particular platform.
32:11
Well, after I get the order confirmation, I want that order to be
32:14
shipped somewhere else. So, I would either call back to customer service and
32:18
be asked and ask fulfillment to change my shipping address to one of my
32:22
drophouses or afterwards I will contact the UPS service or the the courier
32:26
service directly and have them redirect the package or hold the package at their
32:32
office and then I will go pick it up by presenting ID, whatever it is.
32:37
The point that I wanted to raise here is there’s so many moving parts. There’s so
32:42
much to watch. And as I just said, I knew that the left hand didn’t know what
32:47
the right hand was doing. And so if I successfully executed at each individual
32:51
part, everything in that story line on a linear mindset looks fine. It’s only
32:58
when you zoom out and track the performance across the entire journey
33:01
that you actually see that this story is suspicious. So Stuart, what do you have
33:06
to say to uh multi-system ex or multi-point exploits uh and storylines
33:12
like this?
33:12
>> It it goes back to to highlight a couple of things for me with with COVID and in
33:18
2019 2020 all of that you have the features and the the drop points that
33:23
you had mentioned for for systems and delivery. Another thing to be conscious
33:27
of especially when you have a retailer that has physical locations is buy
33:32
online and pick up in store. Before you had to go online, go in store and do
33:38
it. Now you can just do curbside and the controls in place. You just give them a
33:43
code. You don’t have to give them an ID. Again, going back to to removing that
33:47
restriction, making it convenient for people, but fraudsters are are very
33:51
conscious of this. And the other thing that I wanted to bring up, it continues
33:56
to be highlighted and be a chance of
34:00
opportunity for for the good guys is you want to make sure that you have those
34:04
relationships in place. So customer service is one is one area you
34:09
definitely want to have a relation an ongoing relationship and a two-way
34:13
educational street. Another is is fulfillment and distribution.
34:18
It all it all it has to do is is is have a conversation. Ask somebody within your
34:24
group or your circle or go into a bigger picture. Whether you use Slack, Teams,
34:27
whatever it is, G-hat, ask the question, hey, does anybody know that works?
34:32
Anybody that’s in dist distribution fulfillment, have those conversations,
34:36
develop those relationships because you can have a conversation with them and
34:40
say, hey, when there’s a change, and they’re conscious of this change more
34:44
than the the fraud systems are. When there’s a change, you want to be
34:48
conscious of this. Is the pickup name changing? Is the location changing? How
34:52
far is it changing? What kind of a location is it being held at? Is it
34:56
being a locker? Is it a a a post pack and ship place? There’s various methods
35:02
and drophouses. Like, do you see the same address? Like I can remember at a
35:06
previous company that I that I worked at, we
35:11
would constantly see addresses come up in in shipping
35:15
addresses when the billing and shipping was different. Why is this one address
35:19
in city A that’s a high-risisk city? It’s it’s a it’s a declining city as far
35:25
as population and economy goes. Why is this one address have 30 shipping um
35:32
points? Why are there 30 packages going to this one house? And you go in, you
35:36
look at Google Streets, it’s a $300 package, but you look at the house and
35:41
sometimes, let’s be honest, judging fraud is a judge a book by its cover.
35:45
Why does this one house have $10,000 worth of packages within the last 60
35:49
days? Those are key indicators and things that are hiding in plain sight
35:54
that you have to be conscious of. And as a fraud fighter, you need to empower
36:00
your teams and groups because you’re not going to be able to do it all by
36:03
yourself. So when you h develop those relationships, you can instill those
36:07
values and techniques of identifying and preventing these kinds of things that
36:11
are happening. And it’s integral to being able to be successful because
36:16
being in the fraud prevention workspace itself is is is playing whack-a-ole all
36:22
the time. And the more that you can educate and instill those values, the
36:26
more effective that you’re going to be be as an individual contributor and as a
36:31
company as a whole.
36:33
>> I love that you said that it’s a two-way street, the knowledge share, because it
36:37
is right in the fulfillment or in customer service. those reports coming
36:41
up and being evaluated by a fraud manager, head of fraud, whatever it is
36:45
that the where fraud bubbles up to is going to be super important. The these
36:49
trends that look benign and innocent, you know, to the to the to the to the
36:54
ices in, you know, the fulfillment of the customer service thing might tie to
37:00
a trend that we’re seeing over here. And that was the final piece that we need in
37:03
order to see the full story. Cool. So now let’s productize and automate this
37:07
data management system so that we can see it as it happens in real time and
37:11
actually have an effect in stopping it. Love that. Great point.
37:16
So this is where I hand it over to you man. Go ahead and take over.
37:20
>> We’ve touched on a couple of points already with this but as the title of
37:23
the slide says ask excuse me. How do ATOs impact a business? The explicit
37:30
impacts as on the screen you you’ll identify value at risk. It’s going to be
37:35
financial loss from fraud and chargebacks and refunds. And one thing
37:38
that kind of it keep constantly is popping into my head even though the the
37:43
topic at hand is ATO’s. One of the things that’s been growing over the last
37:46
couple years is first party fraud or friendly fraud. It’s an opportunity to
37:52
people. Um so once you identify some controls to address some of the ATOS’s
37:58
you can take those controls and develop policies to address it on the on the on
38:03
the first party or the friendly fraud side. Um theft of data PII personal
38:08
identifiable information is extremely valuable. You can create new accounts.
38:13
You can use old existing accounts to fly under the radar. You can use stolen
38:17
credit cards on those accounts. Um I’ve seen it all. And then ransomware as
38:23
well. That’s one thing that we haven’t touched on. Um but you brought up the um
38:28
the incident that happened at a at a institution in Las Vegas. We won’t name
38:34
names, but I’m sure we’re all thinking of the of the threeletter name that that
38:38
pops into mind. Ransoms. And and it happens in all businesses. Happens for
38:43
hospitals, happens in hospitality, happens in gambling, happens everywhere.
38:48
So, if you don’t have the controls in place, it’s going to make an impact to
38:51
your business. Sometimes it’s it’s just going to be, hey, it’s a one-off or it’s
38:55
going to last months and months and months. It’s going to impact the
38:58
reputation of your brand and it’s going to be a big pain in the neck for your
39:03
your chief financial officer because it’s not going to just be one
39:09
incident. It’s going to it’s going to grow and and spread like a virus.
39:14
the hidden impacts, just like I’ve kind of um spoken into the operational
39:19
overhead, the amount of time and effort that some of the teams have to put into
39:25
playing catch-up, playing cleanup, going through all the log files to investigate
39:30
to ensure that we’ve swept and we’ve cleaned everything out after an incident
39:34
has happened is very challenging to measure. How many
39:41
man-h hours are you spending handling challenges like this? And above all else
39:46
in a day and age where everything is so competitive and hey I want my item
39:50
shipped here tomorrow. Brand reputation with your customers and the fraudsters
39:56
is going to leave a lasting impact. I know in this day and age if I get
40:02
frustrated with a company not handling an incident with shipping or whatever, I
40:08
can go take my business elsewhere and everybody price matches now. It’s not
40:12
just one retailer here or there. Everybody price matches and everybody
40:16
has handheld devices where they can just scan and say, “Oh, well, we offer this
40:21
price here and we can get it shipped there.” So, it’s integral to have these
40:24
controls in place to make sure that you keep the business inhouse, but also you
40:33
want to put some friction in there. control the narrative, have the
40:37
policies, the the the terms and conditions in place explicitly there so
40:43
that you can win chargebacks when you get them, but you also control the
40:47
narrative and you communicate to your customers, hey, we have these controls
40:51
in place to protect you as a consumer. As long as you control that narrative
40:54
and you have confidence in doing so and you communicate effectively, people are
40:59
willing to handle some of the friction points
41:05
out of the the certainty that their information is being protected.
41:10
Was there any questions that kind of popped in in all of that? I know I’m I’m
41:14
all over the place, but
41:16
>> you covered a lot of ground. Yeah. Uh, I think that one thing that I really I
41:20
mean I wrote down a question for later on that I’m going to use to to uh perk
41:25
up the Q&A, but one thing that you really raised that I really liked was uh
41:28
these these older or dormant accounts that are being compromised and and I and
41:34
I know you were speaking from the employee uh level or the business level,
41:38
but in a consumer level there is another use case that popped up where accounts
41:42
that are 2 and a half three years old without any action were being
41:46
compromised because they had uh stored value in them, right? And so another key
41:51
element that I would like to raise is as breached information continues to flood
41:54
into the marketplace, we are seeing dormant accounts being reactivated and
42:00
because they’re so old, um it makes sense for the for the fraudsters to say,
42:05
“Hey, we need to update this information cuz I just don’t have access to that
42:09
account or that I’ve changed my phones or whatever it may be.” So dormant
42:13
accounts in in all three categories are super important to track. Great point.
42:19
So, what do we do about it?
42:23
>> Develop relationships is is the theme of the day. Yeah, you have to take a look
42:28
at the bigger picture. Um, if you you’re too focused in on one problem, whether
42:33
it be chargebacks, ATO’s, change events, you’re going to get lost in the data.
42:38
develop the relation relationships whether it be risk and control security
42:44
technology fraud risk strategic vendors and it’s just running through the
42:48
gambling here and this is a practice that I want to bring in a personal
42:52
approach that I have you want to have the relationships
42:56
within your organization but you also want to have it within the industry and
43:00
abroad I’ve known Alex over the last three years and I can’t tell you how
43:05
many times I’ve just shot a quick message over on LinkedIn and say, “Hey,
43:09
Alex, I’m handling this. What would you do in this situation?” Because there’s
43:12
sometimes where you just experience burnout or you you’re you’re tired of
43:16
playing the whack-a-ole. And you just draw a blank even though you’re you’re
43:20
an industry you’re hardened industry expert. Sometimes you just get worn down
43:25
by the game and you have to rely on your allies. Another thing that you want to
43:30
consider what other teams are involved and again customerf facing teams the the
43:36
reoccurring theme of today’s call your customerf facing teams are going to be
43:40
your front line of defense. Another thing to be considered and this comes
43:44
back to the the the attrusive f-word product and experience and design team.
43:51
You develop those relationships and you you have that storyline like hey this is
43:55
why we need it. Make sure that you’re not only telling the story, but you have
43:59
the data to back to back it up. Having the data to back it up is always going
44:05
to be the most important part of your storyline because you you can have an
44:10
amazing story, but if you don’t have data to back it up and you can’t
44:14
you can’t hold teams or groups accountable because hey, I’ve seen 20
44:20
chargebacks because of this reason over the last week. If you don’t have that
44:23
kind of data, your argument and your storyline just fades out. It fizzles
44:27
out. And again, continuing with the the the relationship aspect of of this
44:34
industry is collaboration. You’re only one person. It doesn’t mean matter if
44:38
you’re a fraud team of two, five, 20, 30. You’re only going to be able to make
44:44
so much of an impact yourselves. And it doesn’t matter if you’re using SQL and
44:47
and Python and everything. you’ve got all the the best and and brightest fraud
44:52
tools out there. You’re never going to be able to have an impact unless you
44:56
leverage your relationships and and collaborations with other the team. Make
44:59
sure that you’re working towards shared objectives. Hey, it’s great to have a
45:03
quick SLA, but it’s also important that we have controls in place so that we’re
45:08
not just sending money out the door. You want to be transparent.
45:13
Control the narrative. Put put it out with your terms and
45:18
conditions. Put it out in your checkout screen. Put it out in your order
45:22
confirmation screen. Be transparent. Hey, expect your package to be here.
45:27
Sometimes you expect experience delays because whatever it’s fulfillment,
45:32
however you want to control the narrative, make sure that you put it out
45:35
there and you’re transparent about it. active partnerships,
45:40
both internal and external, are imperative because again coming back to
45:44
the the the evolving theme is you’re only going to be able to do so so much.
45:50
Make sure that you’re engaged with these partnerships. You can’t just have one
45:53
conversation with customer service and expect that to be sufficient. You want
45:57
to be active and engaged just like this conversation in this back
46:01
and forth with Alex and Ias. I I would assume it would be difficult to sit
46:06
through a 45minute webinar if we didn’t collaborate and we didn’t work together
46:11
on this and we were just speaking to our points. It would be very bland and and I
46:15
no you would have no interest in it. Make sure that you make it fun and
46:18
exciting because it can be boring. It can be
46:23
mundane and it can be frustrating. But unless you have those relationships
46:28
in place, you water and grow them like a garden, they’re going to fizzle out and
46:32
they’re not going to be effective.
46:35
>> So there’s two things that you’ve you’ve I think there’s a recurring theme here
46:39
about our data management, right? It’s our eyes and ears. It’s what we see.
46:42
It’s what we it’s what we collect. It’s what we can monitor. It’s our data,
46:45
right? And so you mentioned how important it is to have data at all
46:48
these different points in order to create that narrative. But also what
46:52
goes into it is the the knowledge share right between customer service between
46:57
cyber security between uh accounting all these different items all these
47:01
different two-way streets for knowledge shares need to be coming need to come up
47:05
here then you have the narrative and I’m going to ask you uh in the world of
47:09
ATO’s there’s a lot of fraud fighters who are identifying that collaboration
47:13
between fraud and cyber security are extremely important right so in your
47:19
experience how do you take we know building the data is important. We know
47:24
that cross journey you know monitoring and storytelling is extremely important.
47:29
What elements go into creating that story that are going to drive the fraud
47:35
and cyber collaboration uh effectively when it
47:40
comes to solving ATO’s. I’m going to think on that for a second.
47:48
But the first thing that comes to my mind, especially when you’re coming into
47:52
a a program or company that doesn’t have a wellestablished, welloiled machine,
47:58
sometimes one of the things that you’re going to be doing in that startup area
48:02
is you’re going to be evaluating providers.
48:06
If you’re just doing that alone, you might already have solutions in place
48:11
from a security side of things that can help you on the fraud side. I’m not
48:14
going to name the specific solution, but there’s tools out there that can control
48:22
the geoloccation data. You can allow people to access it from certain areas.
48:28
And if you didn’t have that relationship, you didn’t take that into
48:32
consideration, you would go off and waste money on a on a fraud solution
48:36
that does that when you already have a tool in place that can can scratch your
48:42
back. And it goes back to the reoccurring theme of developing those
48:46
relationships and making sure that you’re watering them and communicating
48:49
to them because you’re not going to always have the answer. Always have the
48:55
conversations appropriately in the the the the right context both internal and
49:00
external and you’ll be able to keep up with the the madness of the flow of
49:05
everything with the how dynamic this this area of challenges can be.
49:12
You just brought up a really good point, which is why I love fraud prevention.
49:17
You don’t always have the answer. It’s not 1 plus 1 equals 2. It’s not some
49:21
static thing that you read in a book and you and now that’s that and it’s and
49:25
it’s static and exists forever. It’s always trial and error. It’s always
49:29
disperate information and connecting the dots. I think that’s one reason, you
49:32
know, all of us fraud fighters love fighting fraud is it’s exciting all the
49:36
time. Let’s move on to ATO. So that was mitigation. Let’s move on to atto
49:41
prevention. Uh go ahead sir.
49:44
>> So going back to the the solution I was referencing perimeter and bot defense
49:50
being able to stop the the the malicious traffic using early detection and and
49:55
perimeter security is the the first line of defense. Enabling controls and tools
50:02
like MFA single sign on uh options is another
50:07
layer that you can move towards. And again, we’re going to come back to
50:10
access control and p and password hygiene as a user. This is the number
50:16
one thing that you can do to protect yourself. Be conscious of what data
50:20
you’re putting out there. Be conscious of what you’re clicking on. But above
50:24
all else, if you have the ability to have MFA set up in an account, whether
50:30
it be your email, your your your social media, always enable multifactor
50:37
uh authentication. And don’t just do one single form cuz let’s be honest, ATO’s
50:43
exist on emails. SIM swapping exists for phone. Um it it can all be manipulated
50:48
and controlled. So, if you’re only using one form of MFA, it can easily be
50:54
targeted and overcome and if you don’t have a second layer in
50:59
there, it it you’re just making yourself more vulnerable.
51:04
Again, going back to what we were referencing earlier, ensuring you have
51:07
the technology and policies in place. Be transparent. Just like the other side
51:14
slides said, be transparent. Use clear policies and smart tools to enforce
51:20
fraud protection consistently and at scale across the
51:25
business. It goes back to having those
51:30
relationships and controls in place is the is another layer of protect of
51:37
defense. And one thing that the the last thing here education both with customers
51:42
and employees. This is such an open Pandora’s box as far as possibilities
51:49
go. We don’t leverage it enough. I admit it that I have not leveraged it enough.
51:55
Being transparent, educate your customers. As much as you’re maybe
52:00
showing your hands to the frauders, but the more you educate your customers, at
52:05
the end of the day, the customers and the employees are going to be an easy
52:09
way for fraudsters and bad actors to get into your systems.
52:15
I’ve seen over the last couple years, I’ve seen
52:19
fraudsters create up mirrored sites, target with um Google ads, and because
52:24
people are not educated, they’re not conscious of what they’re clicking on,
52:28
they’ll click on a site thinking that they’re going to an original site.
52:32
They’re putting in their username and password. They’re going through, hey, my
52:36
username and password didn’t work. Well, clearly it didn’t work because you’re
52:40
not at the original site. So the fraudster captures the login information
52:43
and then to take it to another level, they’re presenting them with an MFA that
52:48
goes to the phone or the email that’s associated with the count. The fraudster
52:51
is using that information, taking it, social engineering it, and that’s how
52:55
they’re gaining access to the system. And as soon as they gain access to the
52:59
system, as we pointed out, they can go through and order what they want, send
53:03
it where they want, or at that point, they can go through and sell it. Because
53:08
the ed if you haven’t taken the opportunity to educate your customer
53:11
base or your internal employees, if they’re not conscious of it, they’re
53:16
going to be like, “Oh, I’m just having issues with my with my password.” And
53:19
they’re going to get frustrated and they’ll walk away. I’m going to go get
53:22
something to eat. And in that time, that fraudster can take that information and
53:25
sell it, and somebody else gain access to the system.
53:31
>> You bring up a lot of great points. Uh and two things that jump out to me is
53:35
across this entire screen here, uh the use of passive
53:40
information I feel is often overlooked. So in the case of multifactor
53:44
authentication, um it’s one thing to just submit the OTP
53:49
or the the password that’s that’s being sent out to confirm that you received
53:52
it. Well, that’s great. But there have been setups that that collect
53:57
information, device intelligence, geoloccation,
54:00
uh, bot detection, as you have in the first piece there, there have been items
54:04
that passively collect information beyond just satisfying the OTP. And so
54:10
the MFA verifications, granted, there are many different flavors, on the back
54:14
side of that, or on the underside of that, there’s still passive information
54:18
that can be collected. and that can be collected and that needs to
54:24
be addressed. We’ve got a question coming in from chat. Feel like this
54:30
slide of how fraudsters gaining access is missing info steelers. Do we know
54:36
which slide that was on, Brian? I assume that was back here.
54:45
Okay. Uh true. We’ve spoken about uh info steelers um both in here with the
54:52
personal the PII extraction on both sides and then generally across the the
54:57
stream we’re talking about the webinar we’re talking about um data breaches and
55:01
things like this. If we were to be dedicating this entirely to social
55:04
engineering, we would definitely be diving into info steelers. But yes,
55:08
across the board, information is the currency of fraudsters, right? So, in
55:13
any capacity, if a fraudster can get access to um whether it’s payment
55:18
information or system knowledge, that’s one thing that I didn’t touch here, but
55:21
I do touch on in my um in my other webinars. If the fraudster can gain
55:27
access to can glean information from the customer service team or any other point
55:32
of contact within an organization, that information is going to be important.
55:37
All right. And so info stealing takes many different categories. Um
55:42
if you’d like, we can definitely pick up that conversation later.
55:47
Uh let’s see, where were we? Here and into here. All right.
55:53
I guess we’re running into a speedrun. Stuart,
55:58
you’re muted.
56:00
>> Yes, we’re up against time, but so with atto detection, uh, prevention is not
56:05
perfect. And again, highlighting is important to monitor for the changes in
56:10
activity levels, login, failures, MFA abandons, going back to that 88% uh data
56:16
um, attribute, and cross account linkages. You want to make sure that
56:21
you’re monitoring for um atto related impacts, losses,
56:27
contracts, chargebacks, refunds. Going back to first party fraud, refunds are
56:33
are a big portion of that. And people can water down the responsibility and
56:37
and um the attributes to that, but ultimately
56:42
it’s still a level of fraud. Use real-time risk assessments, add
56:46
activity, making sure you’re monitoring all levels of the journey, login,
56:50
changes, movements, um, contact, abnormal, um, abnormal
56:57
contact attempts. Um, why is this one phone number calling us about 30
57:02
different accounts? And that’s one of those things that comes back to the
57:05
relationship with customer service. They’re going to be conscious of that.
57:07
They’re going to see those phone numbers coming in. Does it match the phone
57:10
number on the account? If they’re not educated, they’re going to overlook
57:13
that. Um, and make sure that you’re sending
57:16
the down you’re sending the data in all directions, both upstream and
57:19
downstream. Making sure that those relationships every we’re not siloed.
57:24
We’re not linear. Make sure that you you have systems and parts of your
57:30
organization that are constantly communicating. Otherwise, it’s going
57:34
that that activity is going to be able to hide within
57:38
normal activity and and awareness. Um, go ahead and and go to the next slide
57:42
and unless something popped up for you, Alex.
57:45
>> Yep. Go right in.
57:46
>> So, how are we going to mitigate it? Choose the action that suits the level
57:50
of risk. Put in those places of of friction. MFA, alerting, contact, deny,
57:58
risk, deny, lock. It’s all matter of matching up with the levels. Is it
58:03
green? Is it yellow? Is it red? Linking feedback and learning. True positives
58:08
and false positives. Make sure that you’re looking at them. Assess the
58:11
failures and gaps in the controls. Make sure that you’re taking the opportunity
58:15
to to find new trends and always keeping them in the back of your mind. Past u
58:21
behaviors and trends because they’ll find a way when something doesn’t work,
58:25
they’re going to try they’re going to pull a play out of their book that’s
58:29
worked in the past and hey, this has happened in six months. Let’s adjust
58:33
this rule so that this we don’t have friction in place. You have to be
58:37
conscious of that when you’re making those changes. because the fraudsters
58:40
are going to be poking and proddding and testing limits within your system and
58:44
they’re going to recycle some of their past um attempts. Refine again cross
58:50
collaboration policies, processes and re-evaluate risk versus costs. Have
58:55
those conversations both upstream and downstream. Make sure that you build
58:59
those relationship within your leadership and instill the information
59:03
with the data to back it up so that your leaders can take that information to
59:07
senior leadership so that you can be empowered to make the changes and
59:11
adjustments that you want to make and ensure that you’re always balancing it.
59:16
You want to allow the good to flow while stopping the bad. Sometimes it and it’s
59:21
not a perfect science which is why it’s important to collaborate, leverage your
59:26
your um your relationships both internal and
59:30
external so that you can continue to refine your approach to your process and
59:35
the journey.
59:40
>> All right, we have one minute left. You want to run us through the takeaways?
59:45
>> Takeaways. ATO’s are rising across the marketplace. A lot of ATO’s don’t result
59:50
in chargebacks. Prevention is critical. Make sure that you’re choosing the right
59:55
level of friction. Refine, relearn.
1:00:02
Take chances, but make sure that you’re measuring it along the entire process.
1:00:07
>> And the the the main reoccurring theme of today’s conversation is cross team
1:00:12
collaboration. And I’ll even I’ll even leverage that is use your um use your
1:00:17
relationships both internal and external. Always be
1:00:22
always don’t always be selling, but always be building those relationships.
1:00:26
Um because you’re not always going to be have the answers. And the the better
1:00:30
that you’re suited with having those relationships and having that cross
1:00:34
collaboration, the more effective you’re going to be. You’re only one person.
1:00:38
Even if you have a gamma of tools at your um at available to your tool belt,
1:00:44
you’re only going to be able to do so much. It’s important to have multiple
1:00:48
eyes on the situation and have different perspectives when you’re having when
1:00:52
you’re making these changes and evaluations.
1:00:56
>> Thank you so much, Stuart. Thank you everybody for uh for making it to the
1:01:00
webinar. We hope that you gleaned some very actionable insight, strategy
1:01:04
considerations. Uh, thank you and have a good one.



