Explore the increasing threat of loyalty fraud and account takeovers (ATO’s). Former fraudster-turned-fraud fighter, Alexander Hall from Sift, reveals why ATOs are so appealing to criminals, offering insider examples of how fraudsters use multiple fine-tuned methods to successfully breach accounts. Maggi Fritzsche Manager Fraud Investigations at Hyatt Hotels, shares her insights on detecting and preventing advancing loyalty fraud threats. Watch the on-demand webinar to learn about:
- Passkeys and other identity verification technologies
- Cyber-Fraud Fusion and other fraud team set-ups to stay ahead of the latest attack vectors
- The most defrauded forms of payment
- Unique fraud attacks faced by the hotel industry
Watch On-Demand
Video Transcript
0:00
Hello everyone. Welcome to our webinar for June for the Loyalty Security
0:05
Alliance on Loyalty Fraudsters Playbook. Katie, can you please introduce
0:10
yourself? Maggie?
0:12
>> Yes, absolutely. Hi everybody. My name is Maggie Frriie. I am the manager of
0:17
the fraud investigations team with Hyatt Hotels.
0:21
>> And Alexander, can you please introduce yourself?
0:26
>> Yes, sir. Hello everybody. I’m Alexander Hall. I’m the trust and safety architect
0:30
over at Sift. Uh, prior to working at SIFT, I uh was an independent consultant
0:36
where I worked with many different fraud vendors to solve many different fraud
0:39
problems. Prior to that, I was a head of fraud at a vape company, a vape
0:43
distribution company. And then prior to that, I operated for about nine and a
0:47
half years as a fraudster. Ultimately, I have 18 years of fraud related
0:52
experience, something like 10 on the other side and eight on the side of
0:56
fraud prevention. Chris, Maggie, thank you guys for inviting me along for this
0:59
ride. Uh we’ve got a great session scheduled for you guys.
1:03
>> So, and can you tell us what were some of the what what were some of the types
1:06
of frauds that you committed as a fraudster?
1:10
>> So, it breaks down chronologically. Uh I think all fraudsters, you know,
1:14
immediately jump into like credit card fraud and check fraud and and that was
1:18
really stage one. Uh quickly after that, it became account takeovers and social
1:23
engineering of customer service. Uh after that it it became more um more
1:29
intense. So it moved over into identity related fraud and financial fraud like
1:34
the transfer of funds and things like that. And then towards the the height of
1:39
my time on the other side I spent my time manipulating the processes of
1:44
different systems in one fraud method. Right? So like one example would be to
1:48
take a low volume a low value you know uh identity profile and go open up a
1:54
bank account somewhere and use it as a mule account to funnel funds uh from a
2:00
funding account in another organization or another institution to funnel those
2:04
funds. And the reason why I bring that that example up is in order to
2:09
successfully combat methods that are actively taking advantage of multiple
2:14
systems uh the fraud programs need to have visibility into those programs and
2:20
currently as of today we don’t. So I feel that that’s what’s in the future
2:24
and that’s why I talk about that example. So, and one one more question
2:29
before I move on to the to to Maggie. Can how much has fraud changed, right?
2:33
Like, so today we’re talking about loyalty fraud and you started with
2:36
credit card fraud and uh but how are the methods the same? It may be faster now
2:43
as we you know there’s more speed with with technology but some of the the
2:46
mentality is still the same, right?
2:49
>> Oh yeah. Fundamentally I uh I feel that when you move into ATOS when a fraudster
2:55
moves into ATOS the or account takeovers the it’s fundamentally the same as it
3:01
was you know 10 years ago where a fraudster gains access to an account and
3:06
can use everything available in that account at their discretion. Now, it is
3:12
interesting to see that loyalty points have um become so important in the
3:17
marketplace overall because when I was operating, loyalty points really weren’t
3:21
a big deal, right? Uh uh across the entire marketplace, but now it’s more
3:25
familiar. So, in action or in execution, uh the fraud method isn’t changed. The
3:31
fraudster gains access to a to an established account. They see what’s
3:35
available and they use what’s available. So in that aspect um nothing new has
3:41
changed from 10 12 15 years ago. Um what has changed is I really anticipated that
3:48
with all the data breaches fraudsters would automatically jump. They would see
3:52
the value in compromised identity information and it would rise to be the
3:56
number one uh kind of fraud type uh across the marketplace. But that hasn’t
4:02
necessarily proven to be true. We’ve seen an uptick, but it hasn’t overtaken
4:07
ATO’s or social engineering. So, that was news to me.
4:11
>> So, we’re going to see about what what are the most defrauded payment methods
4:14
in a second. But, Maggie, how long have you been with Hyatt?
4:18
>> So, I’ve been with Hyatt for a total of 18 years. Um, I did five years. My first
4:24
five years I was actually in the call center. Uh, and then I shifted over to
4:28
the loyalty team. Um, and at one point in late 2012,
4:36
um, there was a pattern of weird hotel bills that were being sent in to get
4:43
credit to the loyalty program and they didn’t look real. I actually have one of
4:47
them still. Um, they didn’t look real, right? You can probably tell just from
4:52
that brief glimpse that it’s not real. Well, nobody else on the loyalty team
4:57
wanted to deal with this. And so as the newest person on the loyalty team, it
5:02
sort of got shoved onto my desk and I started digging into it and I loved it.
5:08
And at the time, Hyatt didn’t actually have any kind of loyalty fraud role or
5:14
team. Um, and I actually had to sort of fight kind of hard for those first few
5:19
years to look into different types of fraud that we were seeing and get a good
5:24
grip on how it was impacting us as a business. And there were several trips
5:29
to corporate offices to try to persuade um you know senior management that
5:35
somebody needed to be looking into this because it’s it was costing us money.
5:39
And so uh the role was officially created I believe 2015 um 2016
5:46
and I was lucky enough to be the person that they decided to uh head up this
5:51
team um and I have been doing that ever since. We now have um an international
5:56
team. We have colleagues in the US, but we also have colleagues in China. Um,
6:00
all within the the fraud team um because we do see a lot of fraud uh happening uh
6:07
in the Asia-Pacific region as well as here in the US.
6:12
>> And how have you seen fraud change during that time? As Alexander said, it
6:16
didn’t change that much. Maybe the speed, but the the but the methods are
6:20
the same. But what what have you noticed? is like when you started you
6:24
looked at this fake hotel you found this fake hotel portfolio from early days and
6:30
what how’s it changed since?
6:32
>> I think what’s really interesting from my perspective is how many holes we had
6:37
in our policies and procedures that we didn’t really think about um at the
6:43
time. I mean, this was, you know, years ago
6:47
and we were still receiving hotel bills, you know, via fax or via email. We
6:53
didn’t have a good method of validating information. We were accepting a lot
6:59
more on the word of the person who was telling us um and there was less
7:06
validation happening. And so I think as we have tightened up our validation
7:11
methods and also sort of filled some of those gaps in our procedures and also
7:17
tightening up our our terms a little bit to allow for less abuse, we are starting
7:23
to see a more refined cate, you know, refined categories of fraud. We
7:29
definitely suffer with ATO’s. Uh that’s that’s never going to go away, right? no
7:34
matter how much technology and manpower you throw at it, there will always be
7:37
people trying to get into other people’s accounts. Um, and we also have issues,
7:42
you know, in in other areas like the reselling of rooms and and things like
7:46
that. So, I think people are the the fraudsters are getting a little bit more
7:52
sophisticated in how they’re trying to to pull things off, but if there is a
7:57
hole, they will find it and they will exploit it. Um, so it’s sort of one of
8:02
those everything changes and all things stay the same. Like that’s just sort of
8:06
the nature uh in my opinion and in my experience of dealing with fraud.
8:11
>> So how do you
8:13
>> go ahead Alexander
8:15
>> Maggie you brought up two two great points and I used to do a series called
8:19
think like a fraudster or or something to that effect. T L I F. And you bring
8:23
up two really good points and I I shared during those sessions that a fraudster
8:29
will always go upstream, right? They’ll always go upstream. And there’s two ways
8:34
to think about that in the in the process of checkout, right? When it
8:37
comes to, you know, checking out a at a platform, they’ll always go upstream. So
8:41
they’ll think, okay, well, what does it take to log into to an established
8:45
account? What does it take to create an account? And then they’ll jump around
8:48
the platform. So that’s one way that they’ll go upstream. But then there’s a
8:51
second version of going upstream is is to say well how can I go upstream as the
8:57
person interacting with the platform. So the fraudster will say well first let me
9:01
be an enduser trying to book a room. Well now let me go be an agent trying to
9:06
book a room on behalf of somebody else. Well now let me go act like a hotel that
9:11
can sign up with this OTAA or let me go submit invoices as a hotel. And there’s
9:16
all these different dimensions that a fraudster will go upstream in in across
9:22
in and across the process and just play with those verifications because from
9:27
the fraudster’s perspective, they don’t care if this attempt makes it or not.
9:31
They’re going to glean some information. They’re going to say, why did it fail?
9:34
What validation process, what verification process did I come up
9:38
against? And then what do I need to be prepared for when I try to submit my
9:42
next attempt? Right? And so I think that if if we collectively as an industry
9:47
were to adopt that same mindset, we would be able to identify these these
9:51
vulnerabilities in our systems um you know before the fraudsters do. But you
9:56
bring up two really good points that that I speak about a lot. So I just
9:58
wanted to uh double click on that.
10:01
>> So I I have a question for for Maggie which is um how you consider what is
10:07
loyalty fraud to you? Because Alexander just gave some examples of fraudsters of
10:11
uh thinking like a fraudster, but you also have to deal with gamers or people
10:15
who are poke holes in your program, right? Like someone may have their
10:19
relatives stay for them in order to get status or something. So do you consider
10:23
that fraud sort of how do you define fraud? Like what is your role or do you
10:28
prioritize one type of over another or how do you look at this? We we do
10:33
definitely have some prioritization uh of of various things and it kind of
10:39
depends on how strict you want to be, right? Because everybody wants to have a
10:44
loyalty program that is considered generous and beneficial to its members
10:49
and along with generosity you do get people who are abusing it. Um, and I
10:55
think, you know, looking with the exception of ATO’s and room reselling
11:01
and things that are obviously clear violations of what our program terms are
11:06
set up to do. When it comes to gamers,
11:12
you really have to look at the severity of the issue, right? you if it’s
11:16
somebody who maybe does something once or twice that they’re not really
11:20
supposed to do, that’s different than someone who is habitually doing
11:25
something that yes, technically it is allowed, but there’s clear abuse
11:29
happening. So, I would actually consider that not necessarily loyalty fraud, but
11:34
loyalty abuse. It is abuse of a a loophole or something. And
11:40
occasionally we will reach out to people and say, “Hey,
11:44
you’re you’re abusing. You’re not really supposed to do this.” Um, and sometimes
11:48
we tighten our terms and we change what is allowed within the program. Um, just
11:54
to try to prevent that. Um, you know, I I I’m very conflicted about it because I
12:01
am a very the rule says this and this is what should be followed kind of person.
12:06
Um, but I also understand that there are people who go, “Hey, you didn’t say I
12:11
couldn’t do it.” So,
12:12
>> I think it’s Alexander’s point, they’re sort of they’re fraudsters who cross
12:17
ethical lines, but won’t cross legal lines, right? Like, so they’re they’re
12:21
thinking like a fraudster, but they just don’t cross they they know the legal
12:24
line, but they cross the ethical lines, right? So, how how do you deal with
12:27
that? It’s interesting. And one of the challenge in Lloyd’s fraud is how do you
12:32
mo how do you quantify this? Because is that fraud? one company might consider a
12:35
fraud. So, as we come up with, there’s no industry standard.
12:39
>> Yeah. Well, and we we had a case several years ago um where there was someone
12:45
like you mentioned earlier who had other people. She was completing stays for
12:49
other people, right? And we all know that this happens. It happens all the
12:55
time in every loyalty program around the world.
12:58
The difference in that case was she was a blogger and she was publicly talking
13:03
about doing this. And there’s a difference there. Like if you figure out
13:08
a loophole and you do it, that’s one thing. But if that you then go on social
13:12
media or you are publicly saying, “Hey, I’m doing this thing that technically
13:17
isn’t allowed, but I’ve never got caught, so go ahead and do it.” That
13:22
sort of takes it to a new level, right? So, there’s a lot of considerations when
13:26
it comes to that abuse factor that we have to put into play. Um, and of course
13:31
working closely with our legal team um to make sure that our terms are clear
13:37
and enforcable. Um, and then also how to handle when we do have these really
13:41
blatant abuse cases happening.
13:44
>> So, I have one one follow-up question to that which would be that made the press.
13:48
I read about that one. So, how was your job? Do did does senior management talk
13:54
to you when these things are in the press or how how is does that make for
13:57
an uncomfortable day for you because it gets attention or how how does that
14:00
work?
14:01
>> That actually made for a very happy day for me. Um,
14:06
upper management was actually very pleased. Um, the articles that were
14:10
written may have been a little bit critical of us. Um, but one thing that
14:15
I’ve always noticed anytime there’s an article about Hyatt and attempts to stop
14:20
loyalty fraud is the comments. And the comments on those blog posts were
14:25
overwhelmingly supportive of us taking this action. Because the thing to keep
14:31
in mind is that for every loud abuser or fraudster, there are thousands of
14:38
members who follow the rules and feel that it is unfair that some people are
14:45
getting away with things that they feel is not the right thing to do. Um, so
14:51
anytime there’s anything that’s critical of of us, any articles, I always look to
14:56
the comments and that really sort of shows the the true picture. The the
15:02
blogger might be upset about it, but what are the bloggers readers saying
15:07
about it? What do they feel about it? Um, and it’s all it’s almost
15:11
overwhelmingly positive towards any step that we take.
15:16
>> Well, thank you for that. And now I will move on to our poll. We have a poll
15:20
everyone. So if you’re on your second streams, come over. And this is some uh
15:24
this is going to we’re going to call in Alexander to talk about some data sift
15:30
has has has researched. What are the most defrauded payment methods this year
15:36
and last year? Alexander will share that data, but I would like to see what the
15:40
audience thinks. So can everyone um can can you see the poll poll? Maggie and
15:45
Alexander, are you able to see that?
15:47
>> Yes.
15:47
>> Yes.
15:48
>> Excellent. So, everyone, can you um if you could come over and vote and um uh
15:54
we’ll give it about a minute or so. Um we have about 20% of you have voted. So,
15:59
what what do you what do you believe are the most uh uh defrauded methods of
16:04
payment, right? So, I I’ve listed some here. Actually, Sift has done research
16:08
on on more than these as we as we will see, but come over and vote. I’ll give
16:12
it another 10 seconds. So, thank you everyone. So, I’ll count to uh five more
16:18
seconds. Thank you. I’m We’re at 75%. So, thank you. We’re hitting on over 80
16:24
now. So, thank you. What if Give it a couple more people. Thank you. So, I’m
16:28
going to close the poll, share the results and uh the most defrauded method
16:35
of payment is credit believed to be credit cards by the audience. So, uh,
16:42
Alexander, um, this came about because you shared some information from from
16:46
the floor of the airline and travel payment summit LSA conference in Dublin
16:51
on what CIF found. What did SIF find?
16:55
>> Sure. So, what we do is every quarter we release a digital trust index report and
17:02
that is accompanied by a webinar. In Q1 of 2025, the focal uh topic was payment
17:08
methods, right? We were talking about payment fraud, abuse or payment fraud
17:12
and the different types of payments that are exploited. In our polling or in our
17:17
report, we had um brought in information from across our entire global network uh
17:23
and and pulled even consumers about uh about uh different types of payment
17:28
fraud. And what we came away with was that in number one in in the number one
17:33
spot was loyalty points as the highest fraud rate. And now that’ll be the
17:38
highest fraud rate, meaning uh uh the attack attempt as well as successful,
17:45
right? So it’s all bundled in there together. So points was number one at
17:50
6.19%. Underneath that we have financing,
17:55
prepaid card, crypto, digital wallet, gift card, electronic funds transfer,
18:01
and only then do debit cards come in with 1.6% uh attack rate. and then
18:07
credit cards in the number nine spot at a 1.31%
18:11
rate.
18:13
>> So, and you you kindly looked up what CIF found exactly one year before. How
18:19
did that differ in in the year?
18:22
>> Uh, so I don’t have it in front of me, but uh anecdotally, what I do remember
18:26
is that we listed the top five payment methods in in Q1 2024 and loyalty points
18:33
wasn’t even an honorable mention. So, so we’re definitely seeing a shift
18:39
towards loyalty and uh we have Maggie here who’s a a loyalty manager and I
18:45
would like to ask you what what fraud trends you’re seeing. But first, one of
18:48
the other things that we saw at the LSA conference in Dublin was um someone had
18:52
pulled from the dark web the most uh searched uh travel companies uh
18:58
airlines, travel, rental car, everything in the travel space. Hyatt was number
19:02
three, right? So you have some huge airlines, you know that. So I mean for
19:07
for the size of Hyatt, that’s a lot of pressure on you. So uh you are the
19:13
number three search on the dark web by fraudster. So uh not not a not an
19:18
enviable place. But what what are the fraud trends that you’re seeing Maggie?
19:21
Like what’s keeping you up at
19:23
>> Well, I will say just because we are number three in searches not does not
19:28
necessarily mean that we are number three in actual impact. Um we are
19:32
definitely seeing more activity this year than we have in years past. Um so
19:38
far for the year uh the number of ATOs that we’ve experienced is roughly double
19:45
what it was last year. However, I will say even though the number of ATOs has
19:50
gone up, the number of points that are being impacted by those ATOs is actually
19:55
about the same in the same area that it was last year. So each individual attack
20:01
is impacting less points. Um I think one of the key things to keep in mind is
20:08
anytime there is an opportunity for a fraudster to double or triple up on
20:15
offers or deals or promotions or anything they will do that. And we’ve
20:21
been seeing that happening a lot. um if there is an opportunity to get enrolled
20:28
illegitimately through some kind of you know trial tier offer which I know a lot
20:33
of hotel companies offer um where you need a a smaller number of nights to
20:39
achieve a higher tier level they are going to get into that and then they are
20:43
going to have stays happen um whether they’re real stays or fake stays they’re
20:49
going to have those happen at hotels that are offering an opening bonus or a
20:54
seasonal bonus or a nightly bonus. If there is some kind of global promotion
20:58
happening for all members, they are going to be enrolled in that. And that
21:02
is has never been more true than this year. We are seeing that happen more and
21:07
more. Um, so there’s a like I said earlier, all things sort of stay the
21:13
same, but things are seeming to compile more this year. um where they’re trying
21:21
to get in and do more at a time. They’re not being as successful um thankfully um
21:28
this year in in terms of point impact, but they’re definitely getting into more
21:32
accounts.
21:33
>> But maybe and and I’ll ask Alexander the same question, but first maybe Maggie,
21:38
they’re getting into accounts to piece together information to fraud someone
21:42
else, right? Maybe you’re a piece of a puzzle that’s uh you know you’re not the
21:47
you’re good enough to stop the impact on you but they’re getting gleaning a bit
21:51
of information to defraud someone else would be would be one thought I have.
21:56
>> Yeah, I’m absolutely confident that that’s true. The number of people that
22:00
we reach out to whose accounts have been taken over the number of times that they
22:05
say I had this same thing happen at Hilton. I had the same thing happen at
22:08
Marriott. I had the same thing happen at IHG.
22:12
We are not in a bubble. Um the the fraudsters are working globally
22:17
universally at all proper at at all, you know, different companies, all
22:21
properties. Um we’re really, you know, what we are
22:26
seeing is probably happening at all of these other hotel companies as well.
22:31
Things go in waves. So we may see at Hyatt, we may see an uptick in how many
22:37
points to miles transfers are happening, right? and Hilton or Marriott may not be
22:42
seeing that and then it starts to decline for us and then it starts to go
22:46
up for one of them. So, you know, the fraudster sort of frequently will work
22:50
sort of in rotation where they’ll hit us really hard for a while and then when we
22:54
start catching them more, they’ll say, “Okay, let’s move to somebody else for a
22:59
while and then eventually they come back to us when they’ve exhausted all their
23:02
other resources.” So, it’s it’s whack-a-ole. It’s definitely
23:06
whack-a-ole. And you also have financial services partner with transfer in and uh
23:12
a lot of gamers focus on that one right like uh you know if you’re going to sell
23:15
your points you’re more likely to a small business may rack up a lot of
23:20
credit card points right so they they may then sell that on so that’s where
23:23
you may get some uh you know financial services partner definitely brings in an
23:27
aspect I believe so uh so Alexander what is um what what are the trends that
23:34
you’re seeing and I’ll give some background your trust and safety
23:37
architect. So you’re you’re you’re seeing you’re helping many clients get
23:41
fraud under control. So what what are the trends that you’re seeing
23:45
this?
23:46
>> Uh so it is interesting. So, another not to be continuously plugging, but in uh
23:51
in our Q2 digital trust index, we actually did a full-blown uh report and
23:58
uh webinar centered around um uh account account takeovers is the the current
24:03
topic that we’re um that we will be focusing on. When it comes down to uh
24:09
traditional fraud, what everyone see seems to think is that, you know, credit
24:13
card fraud is the is the big problem. that’s the it’s the focal point and it’s
24:17
all those things. What has happened with this shift into ATOS right is that
24:23
payment fraud has become a symptom of a bigger fraud method and the numbers
24:29
speak for itself. Uh actually in the webinar I did yesterday we shared that
24:33
the attack rate for ATOS was at 3.2%. And when you contrast that against the
24:38
attack rate for payment fraud from Q1 uh from the Q1 DTI webinar, we show that
24:44
the payment fraud attack rate was 3.3% I believe it was. So now what we see is
24:52
uh they’re not two separate methods. They they they require two different
24:56
methods but the one is a symptom one becomes a symptom of the other. So first
25:00
an account is taken over and then payment fraud uh ensues. So when we put
25:05
it in that context, it opens the door. Uh actually during the uh ATPS summit
25:11
that we did together, I shared a framework talking about linear methods
25:15
versus multi-touch methods. And ATO’s in order for an ATO to be valuable to a
25:21
fraudster, they have to do something else after they access the account.
25:26
Simply logging in successfully isn’t valuable. Now, of course, they can stop
25:31
there and sell the account access, but it’s with the intent of sharing that
25:35
access so that somebody else can either use stored payment information, use
25:40
stored loyalty points, make purchases, uh all of these different items. So,
25:44
there’s multiple touches, there’s multiple events taking place with any
25:48
ATO that that that happens. And when you put it in that context,
25:54
you or I at least realize that in any of the conversations, any of the TASSA
25:59
strategy sessions that I that I host with our customers, um we always dive
26:04
into these these these deep details about how the fraudsters trend, what
26:09
they what they try to do the most and we try to tackle that first and then what
26:14
do they do secondarily. So in one case we were seeing that dormant accounts are
26:18
being accessed and um this particular uh client had a a stored credit value on
26:26
these these accounts. So the initially a verified user would log in they would
26:31
submit a request for credit they do a soft credit pull and they would have a
26:34
credit line established to them that was established inhouse. Well, great. But
26:39
the problem is 3 years later, fraudsters are getting access to these dormant
26:44
accounts that have those stored credit lines on them and they would call in
26:47
customer service and place orders leveraging the stored credit
26:50
information. And so that was a very unique use case to to try to figure out
26:56
because of course the involvement of customer service, of course the dormant
27:00
accounts, all these different unique elements were really uh interesting and
27:04
uh to to play with. And so um yeah anyway through this
27:09
>> I have a question on the dormant accounts. What happens in that three
27:12
years? Are they selling it on to a different fraudster or what what’s your
27:16
sense of what went on in that three years?
27:19
>> I believe and we’re we’re still collecting data. This is a relatively
27:23
new use case. I’m I have made the assumption that what’s happening is over
27:27
the course of time with compromised uh login details. So, say for example, uh a
27:33
telephone company, we know that they’re they’ve had a rash of of data breaches.
27:37
When the login details are compromised from a telephone company, right? What
27:42
the fraudsters will do is they will take this name or this username and password
27:46
associated with this one user and go to their different platforms and try to see
27:51
if they reused the same username password combination. What I want to
27:55
check to be con to to either confirm or deny is if that worked for this
28:00
particular platform because it’s dormant. So it would make sense that hey
28:05
old email and password combinations might work. So I would assume that
28:09
fraudsters are just doing that as a test and they’re also attracted to it because
28:14
uh with the stored credit information or the stored credit line on that on those
28:19
accounts there is no secondary verification. they’re effectively
28:22
bypassing all payment verifications and just using a credit that’s on that’s uh
28:27
that’s associated with it. And that’s in the same vein as stored loyalty points.
28:32
>> What’s interesting to Oh, sorry.
28:34
>> I was just going to say what’s interesting to me about that is we do
28:37
see um loyalty accounts that have not had any activity for several years
28:43
become compromised. And my theory has always been that the
28:49
the account was not compromised several years ago, right? It’s just been sitting
28:53
there. The member hasn’t really been doing anything with it. And my theory
28:57
has always been that those are great targets because there is a lack of
29:02
engagement by that member. And so they’re not going to notice when all of
29:09
their points are stolen. They’re not going to pay attention because they’re
29:12
not actively engaged. Um, so it’s interesting that that’s happening in in
29:17
lots of other places as well for various reasons.
29:21
>> Exactly. And consider that over the course of three, four, five years,
29:25
however, whatever, however we qualify or quantify dormcancy, think about, you
29:29
know, anybody whose email address may have been updated. Think about anyone
29:32
whose phone number may have changed. All of these different contact uh contact
29:36
information changes over time. makes sense to the customer service team who
29:40
then is asked to go in and reset the information to new information,
29:44
>> right? So, it’s a very soft and easy target for fraudsters to exploit for
29:48
sure.
29:49
>> So, when you’re running essentially these what did you call it? TASA TASA
29:54
meetings with your with your clients Alexander like sort of focus groups
29:58
essentially what what are the other trend any other trends you’re seeing
30:00
coming out from your customers? We are seeing a rise in uh Maggie what
30:06
you were just talking about the the policy abuse the in promo abuse. We are
30:10
seeing more honest verifiable customers right becoming uh dishonest through
30:18
their actions. They know they’re getting more than more bang for their buck than
30:22
we anticipate. Um so I would definitely say policy abuse is is rising. Um and
30:28
and and early on in this this webinar when you asked me about you know current
30:32
trends and what I thought about it as a former fraudster I mentioned uh quickly
30:37
that social engineering uh has taken off and it’s interesting
30:42
because in addition to social engineering of the customer service
30:46
teams you know at a platform so a a fraudster focusing on exploiting the
30:50
platform directly right in addition to that they’re going offsite and I mean
30:56
this isn’t news it’s just you know the extent to which social engineering has
31:01
gone is is kind of shocking to me. The fraudsters going off platform to
31:05
manipulate the users into logging into their account and transacting in
31:10
different ways. And there are so many different flavors. There’s the romance
31:12
scams, there’s the investment scams, there’s the ransomware scams on
31:16
someone’s personal computer. There’s all of these different scams in in different
31:20
types of social engineering that takes place. Um but earlier I said that I
31:24
expected in 2024 and beyond for identity theft to be the focal point. It doesn’t
31:29
seem that way. It seems like social engineering uh is really uh the newest
31:37
uh h the the biggest hike in a new type of fraud is social engineering, right?
31:46
And like I said, social engineering isn’t new, but just to see this this
31:50
rise in how how much it’s propagating across the marketplace has kind of been
31:54
a shocker to me.
31:55
>> I see your head nodding, Maggie. You’re in agreement.
31:59
Yeah, absolutely.
32:01
>> And what one and how about the call center? Because the one thing I I’m
32:04
hearing is just that that as our online defenses, which we’re going to talk
32:08
about, get better, broadsters try some the contact center or chat bots. Are you
32:14
seeing any of this, Maggie?
32:16
>> Absolutely. Absolutely. Um, you know, and I know I know we’ll get to this, but
32:22
as you tighten the noose in one area, the fraudsters are going to go to
32:26
another. So, you know, everyone thinks that the vulnerability must be online,
32:34
right? Because a lot of accounts are accessed using login information that’s
32:39
acquired on the dark web or um you know, brute force password uh cracking or you
32:45
know, anything like that. But I think a lot of people overlook the human
32:49
element.
32:50
>> Um, but also overlook the human ability to identify things that aren’t quite
32:56
right.
32:58
>> So I know we’ll get to that in more detail in a in a little bit.
33:01
>> Alexander, do are you hearing about the call center as well?
33:06
>> Oh, for sure. Yeah. The weakest point of technology is the call is the human and
33:10
then the call center is just the way for a fraudster to execute against a
33:13
platform using that insight. Right. So, like I said earlier about the the use
33:18
case that I brought up about the credit lines that were in those dormant
33:21
accounts, fraudsters are aware that if they can either So, I’ll I’ll speak from
33:27
experience. When I was on the other side, I knew that if I had a list of 20
33:31
accounts that um were registered with, you know, Acme Inc., right, whatever the
33:36
the platform is, I would call in to number one through 10 without the
33:41
intention of ever gaining access. But what I would do is I would call in and
33:45
I’d say, “Hey, um, my dog ate my phone. I don’t have access to that email or
33:50
that phone number anymore, but boy oh boy, I really need to make this purchase
33:54
and I need to access my account. How do I reset information on your account?”
33:59
And then customer service, who is incentivized to be helpful and solve all
34:03
the problems, they’ll just tell me their process. And I’d be like, “Okay, cool.”
34:07
Then I would call back and I would ask the next set of questions. Well, hey, I
34:11
can’t satisfy the knowledgebased verification questions because when I
34:15
set them up, it was this. I can’t satisfy an MFA or an OTP because of this
34:19
and this and this. How do we get past that? And I would call in as someone
34:22
else and ask that set of questions. Meanwhile, I was taking notes over here.
34:27
Now, on the side, I’ve got five or six highv value accounts or people or
34:31
accounts that seem to be of high value. Now I use all of that information I
34:35
gleaned from the customer service team on one of those accounts and effectively
34:40
reset all of the information and just be prepared for the whole process that
34:44
customer service was going to, you know, put me through or or or the
34:48
verifications that they were going to ask. Now, that was in existence 15 years
34:51
ago that now it’s only going to be exacerbated and now uh with all of the
34:58
um defenses that we have at login and at checkout and you know all these
35:04
different things it’s forcing fraudsters to expand you know across and they
35:08
realize if I just go to customer service I can bypass all of the securities and
35:13
so that’s of course where they’re going and where we see uh a lot of action.
35:18
That’s a good segue for the next question about defenses. So, Maggie,
35:22
what are some of the defenses that you’re putting in place to stop the the
35:26
the fraud and abuse?
35:28
>> Um, I think some of the biggest things it honestly is training for customer
35:35
service agents, what to be on the lookout for, how to report things that
35:39
are weird. Um, we’ve definitely added defenses on the technical side, um, both
35:46
on our website, on our mobile app, um, things like that. But the real
35:50
vulnerability, as Alexander said, is the human element. So any any conversation
35:56
that’s happening, whether it’s by voice or by chat, is really really it’s a
36:02
really vulnerable spot for us because you’re absolutely right, Alexander. We
36:07
teach our customer service agents to be nice and to be helpful. And
36:13
99 times out of a hundred, that’s the right thing to do, but there will be
36:19
cases where something is not right. And having colleagues better aware of what
36:27
to be on the lookout for, what to be listening for. um in some of our smaller
36:32
call centers around the world because you have a smaller number of colleagues
36:37
handling those calls, they would recognize the same voice is calling in,
36:42
right? We actually have a a situation like that happening right now at one of
36:46
our call call centers in um the Asia-Pacific region and the colleagues
36:51
all know the voice of this person when they call and so they’re able to write
36:56
down what information are they asking for, what hotels are they looking at,
37:00
what what information are they providing, right? So that’s really key
37:07
and not only having them observe this, but having them know how to report this,
37:12
right? You can throw all the tech solutions that you want, but phone and
37:17
now chat is always going to be a point of vulnerability. So colleague awareness
37:22
is the biggest thing for us.
37:25
>> Thank you. And so Alexander also going beyond just the call center, what are
37:28
some of the technology solutions that that that SIFT will help uh companies uh
37:33
uh achieve or techn how do you help companies technology-wise?
37:39
>> Sure. So when it boils down to if we’re going to focus on the use case of ATO’s,
37:44
different use cases uh call for different types of technology, right?
37:48
And different data sets, right? So any technology is going to be supported by
37:51
their data. When it comes to ATO’s, we’re going to want to know, you know,
37:56
how many devices are accessing this account. How many new devices over what
38:00
period of time? What geoloc is there impossible travel that’s happening? Are
38:05
they are they sit supposedly sitting in a hotel room in New York yet accessing
38:10
their account from Los Angeles? And that might be indicative of fraud as a
38:14
service or of uh triangulation fraud. You know, all of these different
38:19
elements come into play. And and one thing that I love about working atto
38:25
products is I get to tell stories about what I call passive information. And so
38:30
the the it goes like this. When you think about active information, that’s
38:34
the stuff you can ask for, right? So your name, your email, your phone, your
38:37
payment information, your loyalty number, and all those different things.
38:40
Those are the things that get submitted actively. However, underneath that, Sift
38:45
specializes in collecting passive information. Well, that can be
38:49
behavioral analytics. That can be geoloccation, that can be device
38:52
intelligence, that can be all of these different elements that a fraudster
38:57
can’t actively submit. It’s just the way that they interact with the platform,
39:03
right? And so it’s extremely powerful when we’re trying to identify whether or
39:06
not this is suspicious behavior, if it fits an anomalous or if it fits a trend
39:10
that’s been identified, if it’s anomalous to this current account. All
39:14
of these different items can be evaluated. And then in addition to that,
39:18
on top of that data, what SIFT does is we sit across the entire customer
39:23
experience journey, depending on how the integration is set up, of course. But
39:26
SIFT has the ability to monitor and track across the entire customer
39:31
experience journey from account creation to login, checkout, all these different
39:36
items. SIFT can monitor those behaviors and extract very useful behavioral
39:41
elements and then transact through our workflows. we can actually create
39:45
different paths uh you know that we would be able to empower based on what
39:49
the strategy calls for. We can empower this bucket of users to to be put into
39:54
this category and and and when they do this type of thing we go over here. And
39:57
the thing that I love about workflows is we all know that friction is the f-word,
40:03
right? Friction is a horrible thing. We want to be as accurate as possible. And
40:08
in order to be accurate, we can’t just look at one single touch point and and
40:12
use the information there to um definitively decision on an engagement.
40:19
Yes, sometimes it’ll be useful, but now as fraudsters are moving across the
40:23
customer journey, we need to see the whole story. So if they log in from a
40:27
new device, but then they go about business as usual, we don’t want to put
40:30
them through, you know, high friction. However, if they log in from a new
40:34
device, they change the account details, they attempt to trans, you know, to
40:38
transfer out 50,000 points or 500,000 points, and then they book three hotels.
40:44
All of those items together will create a suspicious story. And it’s at any one
40:49
of those points that we can choose to to, you know, move them into manual
40:54
review or call a score or, you know, do any one of these actions. So anyway,
41:00
CIF’s viability is insane and highly customizable, but the fundamental thing
41:05
is that passive information supported by workflows that take into consideration
41:10
the entire story of the session or of the account.
41:13
>> So I’ll take from what you just said the word friction and ask Maggie. I’m sure
41:18
anytime you have a a merchant like Hyatt, there’s always some type of uh
41:24
different stakeholders, right? like you may have user experience, marketing, and
41:30
you’re more of a security-minded person. So, how does that debate play out
41:33
internally? And who
41:35
>> I love friction. I want all the friction. Um because
41:40
because in a lot of respects, friction equals safety, right? Because the more
41:45
difficult you make something for somebody to do, the more trouble it’s
41:49
going to be for the fraudster to be able to do it, and they’re not going to
41:52
bother. they’re going to go, you know, bug a different company. Um, so but yes,
41:58
you do have to balance user experience and there have definitely been some
42:02
times where we have made decisions based on this is better for the user
42:07
experience and it’s in my opinion speaking as the fraud person it’s not
42:15
the right decision and there are continuing vulnerabilities from that.
42:21
But it’s I think it’s easy for fraud people to get very laser focused on the
42:28
very very small percentage of fraud that happens. I mean it seems like that’s
42:34
your whole world, right? And so it can seem as though
42:38
everybody who’s using your loyalty program is a bad guy and we should just
42:42
shut the whole thing down and not like why are we doing this? But when you
42:47
consider how small a percentage of total activity it actually represents,
42:54
you do have to balance what’s best for the majority and then find ways of
43:00
better identifying and handling that that very small percentage that is
43:05
actually your whole world. So is there any friction that your customers embrace
43:10
like two-factor authentication or does do are there any examples of friction
43:14
where you find like the c customers really like it right like so you’re
43:18
marketing can can be on your side because the customers like what you’re
43:21
the friction
43:23
>> so I think the key yeah I mean I think the key we have not enabled two-factor
43:28
authentication we did enable um magic link um email email link login um and
43:35
that that was embraced by some, but it is actually it’s it’s a more difficult
43:40
thing to do, right? Because you have to go to the website, put in your email
43:45
address, then you have to go into your email account, click on the link, and
43:48
then it logs you in, right? So, it is adding friction as opposed to just
43:52
putting in a username and password. Um, and that was definitely embraced by some
43:57
people, and there was adequate security concern to enable that. I think what’s
44:07
ultimately the best is if you can find a solution that is not only safer but is
44:12
also easier. Um and that is where um Hyatt has gone with trying to implement
44:20
pass keys.
44:22
>> Um
44:22
>> I was just going to ask you about that. You’re one of the first travel companies
44:25
that implement pass keys. How what can you just briefly tell us what pass keys
44:29
are? I I know what they are, but maybe a few in the audience aren’t familiar. And
44:33
then how’s it how’s it going? Yeah. So, so keep in mind even though my
44:38
department is housed under the cyber security team, I am not a computer
44:41
person. So, I will do my best to explain it as I understand it. Um, a pass key is
44:47
essentially a coded quote unquote password that your com
44:53
your device knows and can use to communicate with the site that you are
44:59
logging into, but you don’t have to remember anything. Like if you look at
45:03
your phone and it does the face ID, it’s going, “Yep, you are who you say you
45:07
are.” And it’s sending back the the path key to the um the site going, “I
45:13
recognize the device. This is the right person. Log me in.” And that is such a
45:17
simple solution. And yet it is I I don’t want to say it’s completely impenetrable
45:23
because time will tell but it is it is much more difficult right to fake a pass
45:30
key login by a fraudster um because there’s like unless they actually have
45:35
your device they can’t get in using that method. Um
45:42
I I think as more and more companies implement pass key and it becomes more
45:47
and more standard, there’s a lot of apps that already do it um for mobile
45:51
devices. Um and I think people are starting to get more comfortable with
45:56
this idea. They understand it a little bit better and it’s so easy. You don’t
46:01
have to remember a password, right? Just imagine what your life would be like if
46:05
you never had to know a password for anything. your device, your face, your
46:09
fingerprint, whatever it is, would get you into anything. It makes life easier
46:14
for customers. So, it’s not adding friction, but it is also so much more
46:19
secure.
46:20
>> So, you you feel like your customers are embracing craft keys.
46:23
>> I think they are. I don’t know that we’ve really done enough to market that
46:28
we are now offering pass keys. If you go to the website and log in, there is a
46:33
button that says, “Hey, do you want to create a pass key?” Um, so I think
46:37
adoption rates have been a little bit slower than we had hoped. Um, but there
46:41
also haven’t been big marketing pushes saying, “Hey, get signed up for Pasi.
46:46
Use Pasi.”
46:47
>> Um, but I think as it becomes more common, it’s a solution that people will
46:51
be actively looking for in more places. So, I am I’m actively looking because I
46:57
am an American that lives in Panama that has constant password resets with
47:02
American accounts being physically in Panama and they’re getting more and more
47:05
complex and it’s just I can’t I mean it have to be a rocket science to be able
47:10
to come up with the passwords after. So, I I appreciate the pass Keith. So,
47:17
>> but hopefully more companies will follow suits. Alexander, um I believe Sift is
47:21
also moving a bit into the identifi uh has an identity verification product or
47:26
you’re moving into the space a bit. Can you tell us you were pretty excited when
47:30
we were preparing about about this product?
47:33
>> Sure. So um earlier I spoke about the importance of passive information and
47:38
behaviors and all these different things and typically what somebody when they
47:42
hear behaviors and they they see it in the context of fraud prevention they
47:45
believe that it means you know is this person copying and pasting from a
47:49
different screen? Are they copying and pasting off of a a spreadsheet or are
47:53
they It’s more along the lines of bot detection and like credential stuffing
47:57
and things like that that when people think about behaviors, but what SIFT has
48:01
done is we’ve been able to extrapolate out and actually track behaviors of
48:08
certain um identities. Yes, identities um but not
48:15
identities in the traditional sense. It’s hard to define. But what we have
48:17
what we’ve effectively created is how does Alexander interact with the SIFT
48:22
network at large and and present that information to a user while they’re
48:27
doing one of their their analyses. Now the reason why this is important is
48:31
we’ll be able to to show to any analyst um how Alexander for example has made
48:39
five or six different accounts and transacted five or six different times
48:43
across you know the last x period of time and how many of those items
48:47
resulted in chargebacks. Break it down by industry, break it down by
48:51
geoloccation, break it down by, you know, some superficial information that
48:55
was that was uh collected and actually indicate to anybody who’s, you know,
49:00
potentially at risk, uh, you know, exactly how this persona or this
49:05
identity or this, you know, digital identity has performed over the last x
49:09
period of time and actually present that to the user. Now, the reason why that’s
49:14
so important is let’s say that someone recorded that, you know, five or six of
49:19
these accounts, you know, seem to be in good standing and so there’s no
49:23
chargebacks associated with it, but they were labeled with, you know, potentially
49:29
labeled with with account takeovers, right? There was suspicious activity
49:32
that didn’t result in a chargeback. Okay. Well, we’re going to want to see
49:36
that. Let’s say maybe there’s suspicious spending behavior where hey this person
49:40
you know typically transacts you know from New York to New York but now this
49:44
person’s transacting to California and Kansas and you know somewhere in Asia
49:50
somewhere in another another continent we’ll be able to see those behaviors and
49:53
it’s those behaviors that are going to indicate to an analyst whether or not
49:58
something should be seen as suspicious or trustworthy and in addition to that
50:02
on the counter side me as a former fraudster I can’t go and mimic behaviors
50:09
of a a trusted verified uh user. I’m not going to I can’t do that. I only control
50:17
and manipulate what I said earlier, the active information. I can give you
50:22
accurate information. I can I can go over here and we we’re all aware of what
50:26
synthetic IDs are. We can I can go create an ID over here and have it
50:30
perform however I want. But what’s very difficult is to create a persona or to
50:36
to transact in these ways that mimic the uh behaviors of the person of the
50:44
persona that I’m attempting to exploit. Well, I have a question for you. Maybe
50:48
and maybe your your system would actually be helpful for me if if the
50:52
merchants are using your yourselves because um I cut and paste passwords
50:56
from there’s so many complex passwords that I honestly I have a I have a
51:00
document where I cut and paste them, right? But that’s my legitimate
51:04
behavior. Hopefully your maybe your system would see, hey, this is what this
51:07
guy does, right? He’s okay. Looks bad, but that’s what he does.
51:11
Is that am I am I off thinking that? Yeah. Oh, no. No, you’re not off. Sorry.
51:17
No, you are active.
51:20
>> Good.
51:20
>> Good. Good. Because that’s a that’s a problem. And so, um, but beyond systems,
51:24
another another solution or another another way of handling fraud is sort of
51:28
the fraud team setup, right? Like, so Maggie at Hyatt, you’re one of the first
51:34
companies to do a cyber fraud fusion where they put the fraud team and the
51:37
cyber together. So, this is a big trend. We’re seeing it a lot in retail. You’re
51:42
one of the early travel companies to do this. So, how what any comments on h how
51:46
that’s working?
51:48
>> Cyber fraud fusion. It sounds like a yummy drink. Um, yeah. No, I I think
51:53
it’s I think it’s a really good place to be. I think in in I mean, in my
51:59
experience, right, we had previously been part of the loyalty program team.
52:05
And I think a lot of people that makes sense. You’re handling loyalty fraud.
52:09
You’re part of the loyalty team. But I think there is so much that can be
52:14
learned and um there’s there’s such a good
52:21
it’s such a good learning opportunity for a fraud team to really be meshed in
52:27
with cyber teams because there are solutions and alternatives that I as the
52:35
fraud person never would have thought of if I’d never had a conversation with
52:40
someone on the cyber team. Um, the push to get past keys implemented was also I
52:48
mean that was a that was a directive by our CISO, right? That was that was the
52:55
cyber the head of cyber saying we have to make things more secure and here is
52:59
the best way to do it and that was very beneficial for us and we were very
53:03
involved in that process. Um so I think you know whether it’s you know
53:07
architecture or um you know even you know cyber security operations teams
53:12
vulnerability management um there’s a lot of teams that may not overlap on a
53:18
daily basis right but having those connections and working with those teams
53:23
and better understanding what they are doing can really help help you implement
53:29
new new tactics and new procedures that will help prevent fraud. fraud.
53:35
>> So, how do you keep your foot in the loyalty
53:38
department or team now that if you’re in a cyber fraud fusion, you’ve been
53:42
removed from loyalty, you still got to have the good relationship with loyalty.
53:45
So, how how do you do that?
53:47
>> Oh, absolutely. And and I am in communication with people on the loyalty
53:51
team on a regular basis. Um, and a lot of, you know, the the vice president
53:56
that I work most closely with within the loyalty team, um, I I’m emailing all the
54:02
time and and he is included in email communications. But I think I think one
54:07
of the biggest things is that fraud does not operate in a vacuum, right? You
54:12
really need to have connections with the cyber team, with the loyalty team, with
54:18
the legal team, with the various teams that are in charge of the, you know, the
54:23
systems operations and development. You have to have connections over a broad
54:28
area because all of those things need to come together in one way or another at
54:34
various times to solve various fraud problems. Um, so I think, you know, it’s
54:39
it’s easy to say, “Oh, you’re the fraud team. Go to the room in the basement and
54:44
do your thing and, you know, we’ll pay you, but you really have to be up
54:49
involved with all the other teams.”
54:51
>> Well, I think that maybe your personality is slight I I know you
54:54
fairly well. Your personality is a bit different. A lot of fraud people are
54:57
introverted. You’re a bit more extroverted. So, it it’s easier said
55:01
than done, right? Like a lot of people attracted to that doing fraud are
55:05
introverted. and that’s a skill set, but maybe this evangelization is not, you
55:10
know, their normal thing. So, it you know, it balancing. I’m naturally I am
55:14
naturally an introverted person, but after 10 years in my 20s being on the
55:19
radio, um I I learned how to be a little bit more extroverted. But um I I I just
55:26
kind of think you have to you have to make connections and even if it’s just I
55:30
am comfortable with this one person on the cyber team and I will ask them
55:34
questions and you know or this this one person on the legal team you you really
55:40
I I cannot overstate the importance of working together because the fraudsters
55:45
are working together and they are learning from each other. they are
55:50
learning themselves and then they are sharing what they’ve learned and they
55:55
will try any trick in the book. Um, so we really have to be better connected
56:02
internally within all of our different companies and also within our
56:07
competitive set, right? Which I is part of why I think the the LSA is so
56:11
important because trend sharing and things like that, it really really helps
56:16
all of us.
56:18
>> And I think that’s also similar to Alexander’s role as a trust and safety
56:21
architect. He’s sort of s sit in between with all his customers. So you’re you’re
56:25
more of an extrovert. Um, Alexander, can you can you speak to how you see your
56:30
customer set up in terms of fraud and the importance of uh communication which
56:34
is which I I understood that’s what your role is, right?
56:38
>> Yes. And there is no simple everyone has their own way. You know, everybody’s a
56:44
little bit different in these different ways. you consider the different
56:46
technologies, you consider the different responsibilities whether or not it rolls
56:50
up under cyber but is still kind of segmented, you know, uh to Maggie’s
56:54
point, you know, and to your point as well, cyber fraud fusion is only growing
56:58
in importance, especially, you know, as I said earlier, where fraud prevention
57:01
is now encroaching on, you know, data sets that were traditionally, you know,
57:06
housed under cyber security. Now we’re dealing with device intelligence. Now
57:10
we’re dealing with behaviors. Now we are dealing with geoloccation and all these
57:14
different items that you know 20 years ago would have only been in the cyber
57:17
security team’s purview. As far as standard setups go, there is no
57:22
standard. Everyone looks at at it a little bit differently. Maggie, with the
57:26
amazing work that you’re doing, you started in the loyalty, you know,
57:30
department over there and and started to grow over. Now now you’re you’re you
57:34
have this huge purview and you’re doing amazing work. You know, it happens like
57:37
that everywhere. You’ve got some fraud directors that started in customer
57:40
service. You’ve got some fraud analysts that came over from cyber. You’ve got
57:45
accounting departments that are handling fraud as a secondary responsibility to
57:50
keeping the lights on. Yeah, there’s there’s no standardized way to to
57:55
approach fraud, but where we’re going is pretty interesting because fraud is has
58:01
become a standard practice no matter how they set it up and it’s becoming more
58:07
formalized. Um, but yeah, as far as the the actual
58:11
setup goes, I don’t think there’s any any simple way to uh outline what’s
58:16
happening.
58:17
>> So, and with that, we’re coming to the end of the hour. So, Alexander, what
58:21
anything that you want people to remember from today? Like what are your
58:24
one or two thoughts that you would like people to remember?
58:27
>> Uh, account takeovers is uh is an example of a multi-touch system, right?
58:33
the storyline of account takeovers. It it it it spans the breadth of the
58:39
customer journey from login, you know, to dormcancy, from account creation, you
58:44
know, all the way to changing account information to transacting and all of
58:48
these different items. In order to effectively identify how ATO’s are
58:53
affecting your platform, you need data and the visibility to monitor all of the
58:58
trends across your entire system. and you have to pull in insight from
59:01
customer service and all all these different items. And I’d love to help
59:05
you guys get get set up so that you can see how ATO’s might be running through
59:09
your system. That’s one. Two is that not all ATOs result in chargebacks. I mean,
59:14
I think that’s the theme of this of this webinar is the fact that loyalty point
59:19
spend doesn’t result in chargebacks. It’s it’s a different type of loss. So
59:24
the the you know gone are the days of measuring eight you know fraud method
59:29
losses through chargebacks you know we have to think about customer
59:32
satisfaction we have to think about brand trust you know and everything else
59:36
it’s a new calculation and it requires new data it requires expansive data uh
59:41
and monitoring in order to uh to fix
59:44
>> so I would encourage everyone look for Alexander Hall on LinkedIn if you want
59:48
to know more about ATO’s and how CIF can help you with ATOS so I’m sure you’re
59:52
available on LinkedIn And with that, Maggie, what’s your final
59:56
final thoughts for the day?
59:58
>> Final thoughts. Make connections across departments and train your people. Train
1:00:04
your customer service people.
1:00:06
>> Excellent. So, uh, thank you for the short, sweet, uh, ending. So, I’d like
1:00:11
to thank Maggie for joining us here, for for sponsoring this webinar, Alexander
1:00:16
for sharing your expertise as Magg as well for that.
1:00:20
>> Have a good one, everybody.
1:00:22
>> Thank you.



