Sift Trust and Safety Architect Rebecca Alter and The Fraud Practice’s Justin McDonald discuss strategy and provide insights as it relates to responding to payment fraud attacks in digital channels. With the holiday sales rush approaching, being prepared to respond quickly and with agility is critical to successfully navigating this high-volume time of year with elevated fraud activity.

Watch the On-Demand Webinar

Close

Thanks for submitting!

close

Video Transcript

0:16
Welcome back. Hello everyone. Thank you for joining.
0:37
Our webinar will begin shortly. Excited to have you all here today.
1:23
Hey everyone, thank you for joining. We still have about two minutes to the
1:26
official webinar start time. Um, so we will get started uh right about on time,
1:31
but just not quite yet. But but thank you for joining
1:47
Wish wish we had hold music, Justin.
1:57
>> You know, I should have uh, you know, had something like queued up on YouTube
2:00
or something, right? That could have been arranged. It would have been a
2:02
great idea. All right. Um, hi everyone. Thank you
2:43
for joining. Um, it is right at the top of the hour. I I do see the attendee
2:48
number uh continuing to rise. So, um, we’re going to wait to just one minute
2:52
after the hour to officially kick things off. Um, but a special thanks to all of
2:56
you who uh who who joined to sign in on time or even early. We’ll get started in
3:02
just uh less than one more minute. Y
3:29
all right. Uh we are now at one minute past the hour. So let’s go ahead and and
3:33
get everything started. Um hello again everyone. Thank you. Uh welcome to our
3:38
webinar. Thank you for joining. Um, our webinar today is titled Time Matters:
3:44
Swift and uh, Agile Responses to Payment Fraud Attacks. I think we have a great
3:48
webinar uh, prepared for you today and I’m happy to co-present this webinar
3:53
alongside uh, Rebecca Alter, trust and safety architect with Syft. Uh, I would
3:58
like to remind everyone that the webinar is being recorded and that recording
4:01
will be provided to all who have registered for this webinar today. So,
4:06
if if something takes you away uh from the webinar, you you will get a a copy
4:10
of the recorded link sent to you. Um it should be by tomorrow. We’re going to
4:14
reserve a little time at the end to address any questions you might have.
4:18
So, please use the Q&A feature. Um you could submit questions at any time. Uh
4:23
we probably won’t get to to those questions till the end of the webinar.
4:26
And at that time, we’ll we’ll do our best to answer as many as possible with
4:30
within the time we have uh allotted. So, I am uh excited to
4:37
discuss this topic today alongside Rebecca. My name is Justin McDonald. I’m
4:42
a senior risk management consultant with the fraud practice. I I’ve been in the
4:46
digital payments fraud and risk industry for uh oh, actually this is my 13th
4:50
year, so quite a while. Um, with the fraud practice, I’ve I’ve worked with
4:54
merchants, payment providers, and pretty much anyone active in the digital
4:58
payments, um, you know, payment acceptance, you know, merchants, anyone
5:02
in the space really, and primarily with the focus on designing and implementing,
5:06
uh, fraud prevention strategies. I’ve also led the development of the
5:10
fraud practices training and professional certification programs. Um,
5:14
and now I’d like to hand it off uh to Rebecca who will introduce herself.
5:19
>> Awesome. Thank you, Justin. Um, so as stated, my name is Rebecca Alter. I’m a
5:24
trust and safety architect at SIFT. Um, I have been in the fraud prevention
5:31
space for a little over a decade. Justin, I think I’m also at 13 years. So
5:36
I feel we but I don’t know if I want to admit that yet. Uh, so I feel like we
5:40
might align there. I’ve primarily focused my career on building out
5:44
various teams um at different fintech. So, I worked at companies um like Square
5:49
and Lock, Gusto, and Stripe. But um I’m excited to be at TIFF to help um other
5:55
companies develop and build out their own fraud prevention programs. So
5:59
excited to be here with you all today. And with that, we’ll move forward to
6:03
talk about um the meat of our webinar today. So, in this webinar, we will go
6:09
over proactive fraud detection um talk about a long-term fraud strategy and and
6:14
best collaboration tips and techniques. And then we’ll talk about um active mode
6:18
response as well. So what do you and your teams do when you’re actively
6:22
fighting um a fraud attack. So we’ll kick it off by first discussing
6:27
proactive fraud detection. So how to identify attacks in real time. So before
6:32
we begin with that, I wanted to just lay the groundwork so that we all understand
6:38
um just what a massive market the global fraud industry has become. Um so payment
6:45
fraud is a global industry. It’s also industry agnostic. So it affects any
6:50
online commerce business um that is processing payments. They will go after
6:56
I’ve seen some very crazy schemes where people are even going after these micro
7:00
deposits of 25 cents or or less than that to uh uh get per transaction. And
7:07
overall, if you look at this, this is actually going to be making up the uh
7:12
global payment fraud industry will be the eighth most profitable company in
7:15
the world. So, we’re looking at about $ 48 billion that are are up for grabs um
7:21
for all these uh fraudulent actors. So, it’s also quite lucrative. Um and not
7:25
only is this a lucrative space for individuals, but if you want to click to
7:28
the next slide, it is becoming more and more complex.
7:34
Um, so payment fraud is there’s different types of payment methods with
7:39
crypto wallets and buy now pay laters. There’s also um different types of
7:43
schemes that we’re seeing. So um social engineering is on the rise. Um account
7:49
takeovers is significantly on the rise. Sift actually just released um an index
7:54
report which indicated that there’s a 354%
7:57
increase year-over-year increase in ATOS across our global network which is
8:01
pretty mind-boggling to me when I think about that statistics. Um and yeah,
8:06
there’s just more things that you and your teams need to be looking at with
8:09
I’m sure fewer resources um as I know from my days. So it it’s super
8:14
challenging to meet the demands of your consumers who want to have all of that
8:17
diversity at the checkout flow. Um, so you have to protect more geographies,
8:22
more payment methods, and then more types of abuse are out there. So it’s
8:26
becoming more complex. So the question is, how do we really combat this in the
8:31
industry? So one of the the most effective ways that I’ve seen people be
8:35
able to combat payment fraud is really to leverage all of that amazing data
8:39
that you have at your disposal. Um, so that’s inclusive of collecting
8:43
comprehensive data. So that means transaction timestamps, IP addresses,
8:47
geoloccation, device information, user behavior really so that you can get a
8:52
firm understanding of how your good users are engaging on your platform so
8:56
that you can identify how your bad users um that are on your platform might be
9:00
doing suspicious activity or suspicious login. And then with this comprehensive
9:04
data is the foundational, it’s really important for you to implement and set
9:08
up real time monitoring. As we know, time is of the essence when you’re
9:12
having a fraud attack. Um, the quicker that you can shut it down, the the more
9:16
money you will be saving your company. So, it’s really important that you have
9:20
real time alerts that alert you when there is suspicious activity happening.
9:24
Um, a good example to do that is to also just to set some binary threshold
9:28
alerts. So, you know, whether that be monetary to protect your company from
9:32
unbounded loss or maybe there’s geography. Let’s say maybe you know that
9:37
you are not um selling any materials in Italy and it wouldn’t quite make sense
9:41
for someone to be there. You can set up some geoloccation thresholds as well
9:44
that can either trigger manual review or if you want you know a step off
9:47
authentication. Um and then also this last four month I think it’s really
9:52
important to collaborate and share data. As I mentioned earlier fraud and
9:56
fraudulent actors are not industry specific they are industry agnostic. So
10:01
they are going across the internet to try to find all these monies in
10:06
different forms. And so when it’s possible, I really recommend people
10:10
leveraging third-party sites to gain additional data outside of your own
10:14
platforms. Um, and so there might be another business that has different
10:18
pieces of information that you might want to gain as well, just to help you
10:20
build a better understanding of that global fraud network. Um, and then I
10:26
think once you have these foundational data sets, again, one of the best things
10:30
that you can do is set up early warnings of fraud signals. Um, so again, I’ll
10:34
hearken back to that real-time payment monitoring. It’s really important that
10:37
you’re getting your alerts and your important KPIs measured in real time and
10:42
reported on and looked at regularly, either again by thresholding or, you
10:46
know, when I was a fraud manager, every morning I just log in and look at my
10:50
stats to make sure that we were all operating smoothly. Um, unusual login
10:55
and payment volumes and withdrawals. So those really important moments when
10:58
either money is coming in or going out. um if there’s any kind of unusual
11:02
patterns there. I know I remember once just because you see lots of traffic um
11:07
it might not be a sign that your product is taking off, it could be a sign that
11:10
your fraudulent actors has also found out about it. Um and then also a
11:14
decrease in uh payment authorization rates as well. So that should also be
11:18
stable. I having been a chargeback girl in my past life also really recommend
11:23
people look at spikes in chargebacks and pre-chargebacks. Um and I actually have
11:27
an example once. So, back in my early days, I was a chargeback representative
11:32
and what that meant is that I manually disputed hundreds of chargebacks a day
11:37
and there was this one account and it was I think like a Friday afternoon and
11:42
they’re just kept on getting hundreds if not thousands of chargebacks coming in
11:46
and I was just like this isn’t good. I was counting all the money on the back
11:50
end. I knew that this was way above our normal thresholds or any kind of
11:53
forecast processed chargebacks. I you know back in those days you were
11:57
physically running around the office. So I physically was trying to get someone
12:00
to pay attention to this chargeback girl to say like hey something is going on.
12:05
Um and I reached out to multiple people and eventually um this concern got up to
12:10
a member of the seauite who then pushed back down and then people came and found
12:15
me um and and I said we need to shut this account off immediately like
12:18
something is really happening here. And what had actually happened is one of our
12:22
users, it was a case of a good business gone bad. And so they had been
12:26
processing with the company for quite some time. Um, but something happened
12:30
and they changed their course of business and they were actually selling
12:33
travel vouchers um that were not good or real. And so they were creating a type
12:38
of a pyramid scheme. And then this actually got picked up by their local
12:42
news channel and the business was reported as being a fraudulent scam. And
12:47
so once that hit the news, then it alerted all the card holders that they
12:50
should actually charge back some of these fraudulent vouchers that they had
12:53
purchased. And so that’s what indicated the rush um of chargebacks coming into
12:58
us. And with that, we’ll turn it over to
13:03
Justin, who’s going to talk about how you might want to be thinking about your
13:06
long-term fraud strategy um as well.
13:09
>> Thank Thank you, Rebecca. Um, you know, the fastest way to get the CFO’s
13:14
attention, it’s it’s not the it’s probably one of the worst ways to get
13:16
their attention, right? Um, certainly creates urgency and not in a good way.
13:21
>> Well, that’s why you have alerts and thresholds that it wouldn’t just be poor
13:24
girl running around an office trying to get people to listen to her.
13:30
>> Yeah, it’ll get their attention fast, but it’s not it’s not positive
13:33
attention, that’s for sure.
13:34
>> Um, no. So um I want to take some time now to uh kind of discuss some big
13:39
picture considerations when it comes to maintaining an effective fraud strategy
13:44
uh over the long the long haul. Um you know payment fraud related strategies
13:50
like an expression I like to use is fraud is a moving target. So what we
13:54
need to do to stop fraud tomorrow or in the future is probably going to be a
13:58
little bit different than what we’re doing today. So, I’m going to provide a
14:00
couple different frameworks of of of discussing this. And I’m going to start
14:04
with what I’ll refer to as the four pillars of fraud prevention, which is
14:09
detection, prevention, containment, and remediation. And then I’m going to kind
14:14
of bring this back to really the title and the theme of this webinar, which is
14:17
having a a response to payment fraud that is that is swift and agile. So, how
14:22
how does that relate to these these four pillars? So, you know, detection
14:27
um you know, this is just simply recognizing that a fraud event is
14:30
happening or has occurred and and exactly what you were just talking
14:35
about, Rebecca. It’s like, well, you know, this was a reactive uh detection
14:39
and the fact that the chargebacks have came in. Um but then if you have that
14:43
anomaly reporting and and things that that that are those kind of like
14:46
breakers in place, you can be a little more um proactive rather than reactive
14:51
in that detection. Uh the reality is is you’re going to rely on both. Um you
14:56
know detection is the first step but detection doesn’t solve anything right
15:00
you still have to then take action based on what you have identified or detected
15:05
and and that’s where prevention and containment come in and and these are
15:08
different things right so prevention is is stopping something outright. Um it’s
15:14
a binary outcome. As a transaction comes in
15:18
you’re either going to prevent it or or not. Right? if that transaction is
15:21
indeed illegitimate. It’s it’s either going to be accepted or or and a fraud
15:26
loss or it’s going to be fraud caught. Um so prevention is about avoiding that
15:31
financial loss or brand risk or or many of the other um costs um associated with
15:37
fraud, right? So um it’s still useful, right? Even if
15:43
it’s reactive detection, uh even if you miss that particular fraud event, it is
15:48
still useful in that it’s it’s going to drive, you know, detection, right? What
15:54
what do we need to look for in data? What risk signals do we need to look for
15:58
to be able to prevent similar instances of fraud in the future? So reactive uh
16:03
detection is still useful in that regard and that it drives proactive detection
16:08
in the future. And then with that proactive detection, well then we can
16:11
apply prevention um or containment. So whereas prevention is stopping something
16:17
outright, containment is more about mitigating something, not completely
16:21
eliminating it, completely avoiding it. Right? So a single fraudulent
16:25
transaction attempt that that is a binary outcome. We either prevent it or
16:29
we don’t. But if if you’re looking at a larger scale payment fraud attack, um
16:35
it’s more realistic to say, “Hey, most of the time we’re going to prevent a lot
16:38
of this, but not not every single instant.” And containment is really
16:43
important in payment fraud management because um I mean, realistically, can
16:47
you stop every single instance of of fraud, especially that that first time
16:52
fraud, clean fraud, synthetic identity clean fraud, right? It it’s too costly.
16:58
um you have to have too broad of a scope or too wide of a net to catch every
17:02
instance of first-time fraud. So, so containment is is an integral part of of
17:06
fraud prevention strategies. Um what it would take to stop nearly all fraud is
17:12
is going to have some unintended uh consequences in terms of side effects.
17:17
But through repeat use of certain data points, through other patterns, we we we
17:23
can start to see that, hey, you know, with the benefit of hindsight, maybe
17:25
these first couple orders we accepted, um maybe they weren’t good. Um maybe I
17:30
can stop it before fulfillment, um maybe I can’t, I can at least stop it from
17:36
continuing to adversely affect us, right? And then that last pillar is
17:40
remediation. So remediation is that corrective action that you’re taking to
17:46
actually drive prevention or containment. So um this comes in a
17:51
couple context, right? So we see something that’s going on, can we fix it
17:55
quickly, swiftly, right? Or um the measures we’re taking in terms of
18:01
containment or prevention, are they falling short, right? Do we need to
18:04
remediate our approach and and how we are going to stop these types of fraud
18:09
attacks? Right? what what what is it what is it that enabled it to fly under
18:13
the radar and can we remediate that so we do a better job detecting it in the
18:17
future. Now all four of these you know pillars
18:21
of fraud prevention are important but we also need to recognize the roles and and
18:25
really the interconnectedness of each of these. So, you know, detection,
18:30
prevention, they’re absolutely necessary. Um, even though detection
18:34
doesn’t directly stop something, right? We we need to identify something before
18:38
we can prevent or contain it. Um, if it’s proactive detection, that’s my
18:44
definition of a swift response to a payment fraud attack right there. Right?
18:48
We’ve seen this before. We’ve seen something like this before. That’s an
18:52
auto decline. Um, there’s no operational strain, right? that that that is, you
18:58
know, that that is the perfect example of a swift response to a to a payment
19:01
fraud transaction or or many transactions as part of a broader
19:06
payment fraud attack. But what it takes to prevent and contain payment fraud
19:11
attacks is is constantly evolving. It’s always changing, right? That is the
19:15
evolving nature of fraud. So, we must always be re-evaluating what we’re doing
19:20
with the re remediation side of things, right? remediating these new fraud
19:25
attacks and and making adjustments based on current fraud trends. And this all
19:30
does relate to being swift and agile. Um prevention and containment should be
19:36
mostly automated, right? Whether that’s through risk scoring models, whether
19:40
that’s through um a logic rules engine, right? But but there’s a swift automatic
19:45
response to decline or contain fraud attacks. And I think velocity of use and
19:50
velocity of change are are great examples of containment, right? Um, you
19:54
know, putting a data point on a negative list is is prevention, right? That
19:58
shipping address has burned us in the past. It’s never going to do it again.
20:01
Um, velocity of use, velocity of change says, well, I don’t have an explicit
20:06
fraud chargeback associated with these data points necessarily, but this
20:09
activity is is unusually high, right? And and I need to put some breakers in
20:14
place. Um and that occurs automatically right through um you know machine
20:19
learning based risk models through rules engines but agility right that that’s
20:25
that’s really remediation. Um how quickly can can your organization change
20:31
whatever it is that they that you need to change to to make sure that
20:34
prevention and containment can occur more efficiently. Right? So remediation
20:40
improves prevention and containment and being agile ensures
20:45
we can continue to be swift right via uh prevention and containment. Of course
20:50
all of that relies on detection first. Uh on one hand we have to detect that
20:55
that a a fraudulent order of fraud attack is happening so we can prevent it
20:59
and contain it right now. On the other hand, we need to detect uh when we need
21:04
to be more agile, right? When we need to take um a new approach in terms of
21:08
remediation because we’re not as effective and swift as we need to be
21:12
from the containment and prevention side today. So, um I’m apologize in advance.
21:18
I’m going to use a few cliches here, but but but fraud is a moving target, right?
21:22
It’s a constant battle. Success is fleeting, right? having a effective
21:26
payment fraud strategy. It’s it’s that’s how I would define success and and it’s
21:31
fleeting, right? It’s not a destination. It’s it’s an ongoing journey.
21:36
And then I’m all done with the cliches now.
21:41
So, um I’m not going to talk about everything on the slide real quick uh
21:44
here, but I do want to mention it real quick. Um there there are some recent
21:48
articles in a white paper that that we we’ve published in the last few months.
21:52
Um and it’s on topics adjacent to what we’re talking about in this webinar,
21:56
right? Um the white paper really kind of focused on this discussion and
22:01
differentiation on this concept of like quick pivots which is being swift,
22:06
right? And then this kind of like more long-term proactive strategy planning
22:10
which which is not just remediation in the short run but remediation in in o
22:14
over a long period of time. Um, so you can kind of differentiate this as kind
22:19
of like the more tactical side of risk management and the more strategy side of
22:23
of risk management, right? Where quick pivots are that immediate tactical swift
22:28
response to a payment fraud attack and proactive planning are those longer term
22:32
changes um like you know integrating new risk signals and technology tools
22:38
uh maybe even changing a primary fraud solution provider.
22:42
uh I don’t want to discuss every kind of comparative bullet point here on this
22:45
slide um which is really intended to to define and differentiate these kind of
22:50
two areas of of risk management but um you’re welcome to take a screenshot and
22:55
and and better yet you can reference the white paper um that we released a few
23:00
months ago um that white paper will be uh sent a link to download the white
23:06
paper will be sent in the email we send as a follow-up to this webinar right
23:10
it’ll have a link to this recording the recording of this webinar. I don’t have
23:13
a link to download that white paper. But the point I do want to underscore here
23:17
as I kind of relate the two um you know a quick pivot is an example of
23:21
responding swiftly. You know the proactive planning on the strategy side
23:26
ensures we continually have the agility right to to do that to apply that swift
23:32
response and and there’s there’s a mutual interdependence between being
23:37
swift and and being agile. um right just as there is that
23:42
interdependence between these tactical short-term fixes and kind of the longer
23:46
term strategy um solution side right when it comes to designing and
23:50
maintaining an effective uh fraud payment fraud strategy right and not
23:55
just a payment fraud strategy that’s effective today but is effective for um
23:59
for for for years right again it’s it’s it’s it’s ongoing so the the kind of the
24:06
last thing I want to talk about related to this is like a framework work
24:11
um for how we can efficiently allocate our our time and resources to exactly
24:16
this to maintaining that um effective fraud uh payment fraud
24:21
strategy for the long haul, right? And and two aspects of that are what I’ve
24:27
already kind of talked about being swift, being agile, right? the tactical
24:31
quick pivot immediate swift response side versus the kind of proactive
24:36
long-term solution uh strategy planning side. Um but there’s two other
24:42
categories I want to mention right in terms of and I use this as a framework
24:46
to say okay um these are all the things we need to do to maintain an effective
24:50
fraud payment fraud strategy. um how do we allocate our our our resources,
24:57
right? Our our assets towards these four areas. Um so
25:03
it’s it’s the tactical side, the quick pivots, right? It’s the long-term
25:06
strategy planning, but we also need to address this idea of of of ongoing or
25:11
regular maintenance, right? So let’s let’s reserve time to deal with um
25:17
essentially a form of tech debt, right? So, what when we get a
25:23
disruptive payment fraud attack, it’s like drop everything and and fix it. And
25:28
sometimes an an immediate response to to fix something isn’t the long-term
25:32
solution. Um, you could almost think of this as like uh like like triage, right?
25:37
Like a quick pivot, an immediate response to a fraud attempt might be
25:41
might be triage, right? We’re effectively containing the attack, but
25:44
it’s it it it’s a quick immediate fix. It’s not a permanent solution and this
25:49
does create like a like a a form of tech debt, right? Where we need to come back
25:53
and and and clean this up, right? We need to replace this with a longer term
25:57
solution. So, a lot of times it’s like a a broader blunter
26:02
rule or or you know, model feature um that’s saying like, hey, there’s an
26:06
attack coming from this IP range. Let’s just block everything from this IP
26:10
range. Well, that’s good for, you know, hours or days, but but not weeks or
26:14
months, right? And then um so so that you know there’s there’s the tactical
26:19
side, there’s the strategy side, there’s that okay, let’s go back and clean this
26:23
up. Let’s clean up that tech debt kind of ongoing maintenance side. And then
26:26
the fourth category is like just putting out fires, right? Um this kind of active
26:32
attack mode. Now there’s no oneizefits-all approach here. Um,
26:39
broadly speaking, these are kind of four major areas where you’d want to allocate
26:43
various resources and teams and and people to kind of like, hey, this is
26:46
this is your responsibility or this is how much, you know, time per month or
26:50
quarter you need to to kind of dedicate to these types of things. Um, you might
26:55
want to think of it as like percentages like what percentage of our time do we
26:59
have reserved for for you know these kind of quick pivots? What what
27:02
percentage of our time and resources do we have reserved for this longer term
27:06
strategy planning, right? How much time do we carve out to to go from immediate
27:12
quick fixes to longerterm solutions, right? More of that ongoing maintenance
27:16
and how much time do we reserve um to essentially deal with the
27:22
unexpected, right? Um it’s unexpected, but it’s also inevitable when those
27:27
major payment fraud attacks occur. So this is just kind of a general
27:30
framework, a way to think about how resources and time um can be allocated
27:35
to continually maintain keep our payment fraud strategy effective. And that last
27:40
one here, putting out fires, right? This is that, you know, um leaving time for
27:44
the unexpected. Um understanding that, hey, uh there’s
27:50
going to be times where we enter this active attack mode, right? where we need
27:54
to drop everything else and and fix this problem right now because it it will
28:00
grow to an even bigger problem the more we let it. Right? Fraud attacks don’t
28:03
just you know the fraudsters don’t just decide to stop on their own typically,
28:07
right? We have to stop them. So that active attack mode is is really
28:11
important and um I’m going to hand it uh back over to you Rebecca to talk a
28:16
little bit more about this this concept of active attack mode.
28:19
>> Yeah, happy to. Thank you. Um, you know, we maybe many of us have worked in fraud
28:24
here and we will inevitably have to go into active attack mode to fight these
28:30
um events when they happen. I’ve spent a lot of my time in my career in this
28:34
mode. Um, and so we just know it’s going to be
28:38
happen and how do you prepare your teams in order to to engage to really quickly
28:43
stop the fraud when they occur? So, um, the first thing that I like to tell
28:47
people to do is to have predefined requirements. Um, so a best practice
28:51
that I’ve used historically is clearly defined severity levels. The
28:55
recommendation here for severity levels should be like, you know, one to four or
28:58
one to five. The reason why you want to keep them um in smaller amounts is just
29:03
simplicity. So having only four or five levels can simplify the incident
29:07
response process. Um, and then it’s easier for your employees to understand
29:11
when to apply them if there’s not these nuanced categories that they’re having
29:15
to consider when when they’re calling a a SEV or um an incident. Um, it’s also
29:21
more clear if simplicity and clarity often go together. Not always, but they
29:26
can. Um, and then it enables people to be able to clearly communicate um those
29:30
levels to people. And then also the nice thing with issue classification or
29:34
severity scaling is that allows you to do resource allocation. So when you’re
29:39
in active attack mode, depending upon the priority, you’ll be able to
29:42
understand how many resources maybe that you need to divert from your ongoing
29:46
processes in order to actively um address this. Um and then the other
29:51
thing is to have established well- definfined protocols so that anyone um
29:55
within your organization can call an incident. Um typically this I’ve seen it
29:59
be organized by the security team. So it’s not just for your fraud and risk
30:02
teams, but there’s broader incidents that be may occur as well. Um, but as we
30:07
know, there definitely applies to fraud, too. So, it’s important that your risk
30:10
teams are ed educated on the protocols and the severity levels so that they
30:14
know how to proactively call these when they’re working in their day-to-day and
30:17
maybe see something off. And then, of course, it’s really important to build a
30:22
tracking system with regular reporting um and an accountability mechanism
30:26
within that reporting system so that you’re making sure that the remediations
30:30
from these attacks are are getting resolved and they’re getting resolved in
30:33
a timely manner. And also, it’s a good way to kind of step back on a quarter to
30:36
see like, well, where all are our issues coming from? Do we need to dedicate more
30:40
time proactively to fix this part of our business so that maybe this team isn’t
30:45
always um fighting like is our payments where else do we need to do more
30:49
investment in that? What’s something going on with our onboarding process?
30:52
So, we’re having a hard time with identifying um who might be coming on
30:56
our platform. Um, and having that organized and tracked and reported on
31:00
makes it much easier for you as an organization to see maybe your weak
31:04
areas through this lens. Um, and then when you’re actually in an active attack
31:08
mode, um, it’s best to again have that preparation that I talked about, the
31:12
clearly defined roles and responsibilities, training of your
31:14
staff, risk assessments, um, those detection and analysis tools. back to
31:20
what I spoke about earlier today about leveraging your data so you’re able to
31:23
identify when an incident is happening in your in your fraud team or fraud
31:26
department. Once that identification happens and you’ve anal like you’ve done
31:30
the proper analysis to understand what caused that or what is the root cause
31:34
that then you go ahead and you contain and you eliminate it, right? So you’re
31:37
not just consistently bleeding um from that area that might have caused that
31:41
detection analysis. And then you want to go ahead and go active recovery. um you
31:45
want to either a fix the account, a fix the product deficiency that led to those
31:48
fraudulent actors finding that loophole um patch up anything that might need to
31:53
be um fixed. And then there should always be a post incident analysis that
31:56
happens with this. In every company I’ve worked for, my teams have had this as
32:00
part of it. Um we’ve liked to say it’s a blameless culture. So, it’s a learning
32:04
opportunity where you can go back and see, okay, what what did we miss either
32:08
in the product development or maybe in the manual review that was cued or what
32:13
can we build in the future to make sure that we’re not fighting this fire again.
32:17
Um, and so I’ve always really loved those moments when we’ve had teams
32:20
across different, you know, product and engineering and operations coming
32:24
together to really look at a problem that occurred and what we can all
32:27
collectively learn from that problem. and uh Justin will talk about how you
32:32
built that response team.
32:35
>> Thank you. Thank you, Rebecca. Um yeah, so building a responsive anti-fraud
32:40
team. Um in my opinion, part of that is what you
32:44
just discussed, right? That that process that that you just laid out for the
32:47
incident framework. I mean, I think that’s great. Um and and and that’s part
32:50
of it, right? Um although hopefully that’s only a small percentage of the
32:54
time that you spend in that active attack mode. you got to be prepared for
32:57
it because you know as we said inevitably it will occur. Um so that
33:01
that is a big component of having a you know swift and agile fraud prevention
33:06
team. Um but at something that you’ve actually uh even kind of mentioned in in
33:12
the beginning of the webinar is this importance of data and and I I agree it
33:17
all starts with data right um and there should be roles kind of focused on that
33:23
right on internal reporting on um reviewing the red flags or anomaly
33:28
detection that you kind of have in place right um um not every single time
33:33
something is flagged is there a big issue at hand but there is something odd
33:36
going on and we need to look into that, right? So, um, a lot of data reporting
33:41
should be automated. Um, but the interpretation of it might not u, you
33:46
know, can’t always be automated. So, whether that’s kind of red flag
33:49
reporting, anomaly detection, right? Um, who who’s reviewing that? And then data
33:55
drives analysis, right? U such that our quick pivots and our responses to
34:00
contain or mitigate payment fraud attacks, um, they’re well thought out,
34:04
right? They’re back tested. We um obviously want to stop or contain the
34:09
attack at hand, but we want to do so with minimal disruption to legitimate
34:13
users, right? To to to good users and good orders. And and that’s an important
34:18
distinction I I want to really call out here when we talk about being swift.
34:22
Being swift doesn’t mean rushing to a decision. Um we still want to make good
34:28
decisions, right? Not rushed ones. And I know there’s a balance here, right? Like
34:32
sometimes if a fraud attack is so severe, the number one priority is
34:35
contain it and stop, right? But but other times like you you have a little
34:39
more time to to just be um you know to come in with with with good in intent
34:45
and um you know understand the total impact of the change you’re making.
34:50
Right? So this could be back testing you know uh the previous x amount of time of
34:55
orders. If this change how does it affect that? um sometimes it’s like a
34:59
shadow mode, right? I’m making this change. I’m going to run it in parallel
35:02
with with the uh model or rules that are actually in production today, right? So
35:07
that’s another kind of aspect of of this and could be totally different team
35:11
members or people, right? That specialize in these different areas. Um
35:16
and then there’s the actual implementation, right? So there’s the
35:19
data, the detection, the analysis, um the the remediation, how we’re going to
35:24
do it, and then there’s actually putting it in production, which which might be
35:28
another process, and there’s varying degrees of complexity here. Um there
35:33
might be another team member who who actually performs this implementation.
35:36
Maybe they have a certain technical skill set. Right? Now, some
35:39
organizations, they might be using um you know, a fraud solution platform,
35:44
right? the the hub of the risk architecture might be a really, you
35:47
know, slick user interface where you don’t have to have this technical skill
35:50
set to, you know, actually implement this change you want to make. Um, but
35:55
I’ve also worked with organizations that have these kind of homegrown solutions
35:58
or just, you know, different different platforms and solutions where they
36:02
actually have to have someone with a very specific technical skill set
36:06
implement this rule change or model change, right? Homegrown modeling
36:10
solutions probably have an in-house data scientist, right? Um, you know,
36:15
sometimes I’ve seen rules engines where someone has to literally kind of go in
36:18
and like write the the logic and hard code that rule in rather than kind of
36:22
using a user interface to to create and execute that, right? So, what does that
36:27
look like? And and and how does that potentially affect your swiftness or
36:31
ability to respond swiftly? And then, you know, lastly, and and this
36:37
is this is Rebecca kind of what you just just talked about. um when we get to
36:42
that active attack mode, where are those resources coming from? Right? So that’s
36:45
kind of some of the first steps that planning of your incident’s response,
36:49
we’re pulling resources away from something else. Now, if you kind of go
36:52
back to my efficient resource allocation discussion, you should have allotted
36:57
time for this, right? you should have allotted hey every quarter right or
37:02
every month we expect to you know if this is 100% of the time our risk
37:06
management teams h has let’s only commit them to use I don’t know 90% 95% 85%
37:12
some amount that’s less than their full utilization right because we we need
37:16
that time reserve for those active attack modes um but then like what what
37:21
are we pulling you away from right um what can we afford to kind of put off
37:26
longer what do we need to prioritize to say, “Okay, as soon as we get out of
37:30
active attack mode, here’s what you come back and do first.” And and you made a
37:35
lot of great points around those, you know, you know, that planning kind of
37:39
preparation going into your incident response framework and and and that’s,
37:43
you know, those are all very valid and very strong points. Lastly,
37:47
collaboration. So you know for any uh fraud risk management team to be
37:52
effective there has to be collaboration within the team and then you know
37:56
externally to to other teams and departments within the organization.
38:00
So you know there’s this important communication between the tactical and
38:04
strategy side of just the risk management or or or fraud prevention
38:08
team. So, um, you know, I like to think about this in terms of, um, when it
38:14
comes to remediation, like maybe I see what I want to do to stop a fraud
38:19
attack, but am I fully capable? Do I do we have the capabilities to to do that?
38:24
Right? So, um, basically, if your quick pivots, if your tactical responses um,
38:30
aren’t effective as they used to be, like why why is that? What risk signals
38:35
are you not capturing that you know could be helpful? um what technology
38:39
tools, right, are are out there that you know others might have that that you
38:43
could see the uplift it’ll provide that that you would like to have added. So,
38:48
if you’re on the more tactical side and you kind of see that your ability to
38:54
perform these these quick pivots is is waning, communicate that to the strategy
38:58
side. And you know, on the other side of that coin, if if you’re on the strategy
39:03
side and you’re like, “Hey, how do we evolve our strategy?” Well, go to the go
39:07
to the teams that are that are doing it dayto day and say what what do you need
39:11
from us? Like what what else would would make your uh would increase your
39:15
capability, right, to to to stop the the the types of attacks we’ve seen, right?
39:19
Where um have we maybe fallen short of what we thought we could do? And then
39:25
when you’re talking about outside of risk, right, whether it’s a a new
39:29
product launch, new SKUs, uh whether it’s a uh UX, right, user experience or
39:35
front-end, you know, app or site change, right? Um
39:39
you got to know that’s coming, right? We we on the risk, we have to know that’s
39:43
coming. And um sometimes I I mean sometimes I see events where it’s like,
39:48
well, we had this huge chargeback spike. Well, why? Well, we launched a new
39:51
product and it was bad or we we made this payment method change and no one
39:55
really communicated it to us, right? Or the UX team said we’re just going to
39:58
stop collecting the CVV, right? And and those are obviously like kind of
40:02
nightmare scenarios for the risk team. Um so like communicate that ahead of
40:07
time. Make sure that kind of stuff is being communicated ahead of time and
40:10
actually better yet um have that opportunity to give your feedback,
40:15
right? Say like, well, have you considered how it’s going to affect
40:18
this? um you know um here’s what we could do in response, right? But but
40:24
here’s like you know we might see an uptick in chargebacks or we might see an
40:27
uptick in um false positives and and and a um you know uh hit to our sales
40:33
conversion rate. So that that communication really is important both
40:38
within the risk department and um you know externally to other departments
40:43
within the organization. All right. Um, Rebecca, I’m going to
40:48
hand it back to you uh one more time um for this uh case study uh in the eye
40:53
gaming industry.
40:54
>> Yeah. So, next slide, please. So, we um we here at SIFT worked with a company to
41:01
help actively address a broad ring that was attacking their system. Um and so
41:06
the company was able to identify that um this one known piece of data so a domain
41:13
um proton.mmail was actually being used um not only by their good users but also
41:19
pretty quite prolifically by their bad users as well just because proton.mmail
41:23
it’s it’s very legitimate site but also its security and privacy um enhancements
41:28
are also great for fraudulent actors to use. So they identified that they were
41:33
seeing a lot of fraud coming from this domain. So they put up a bunch of
41:36
different rules in place to um block this domain from onboarding. Um so they
41:41
associated those domains with the same device. So making sure there wasn’t over
41:45
10 different email domains coming from the same device on boarding as well as
41:49
enabling the sift um score as to either auto accept, autoblock or cue something
41:55
for manual review. And so because of this rule building off of this unique
42:00
pattern that they had discovered within the system, they were able to reduce
42:03
their credit card fraud rates um a reduction in their manual reviews
42:06
because they were enabling auto accepts and also autoblocks. And then also of
42:11
course most importantly they increased good user activity because we didn’t
42:14
want to just make this a blanket block proton um mail they’re bad. That’s not
42:19
true. Um, so we were able to enable them to continue to process for their good
42:24
users while blocking their block user activity. Um, and again, this was all
42:28
done in a short period amount of time where they were able to quickly remove
42:32
this active fraud attack on their account.
42:37
>> And with that, um, I’ll hand it over to you, Justin,
42:40
for some questions.
42:42
>> All right. Thank you. Yeah. Um, no, that that was a good case. kind of is is
42:47
similar to that uh or or reminds me of that kind of example I gave for like you
42:51
know a quick fix containment and the long-term solution and the example I
42:55
gave was like an IP range and it’s the same thing it’s like if it’s a very
42:57
severe attack you know you know you can’t block all Gmails
43:02
right you can’t block all proton mails necessarily but um in the short run like
43:06
you know what do we do is that is that what we have to to continue with um all
43:11
right so so Q&A um so far I see two questions that came in and I think we
43:16
can answer both of these but um if if you didn’t submit a question um you know
43:23
you still have a few minutes too um so uh let’s see here one
43:30
question we have is um how much time should my organization
43:36
reserve for active attack mode um you know calling back to that
43:41
efficient allocation of time and resources slide So,
43:45
I’ll take this one. Um, and feel free to to chime in if you’d like, Rebecca, but
43:50
um, you know, I don’t know when the question came in necessarily, but but
43:54
there is, I believe I said this earlier, there is no true one-sizefits-all
43:58
approach. Um, you know, active attack mode,
44:03
you got to reserve some time for it. Um, you you definitely don’t want to
44:06
allocate too little, right? Because then when those attacks do come in, what are
44:11
you sacrificing? like what are they taking you away from, right? Um and I
44:15
think you have to be realistic, right, to some degree. Um if you dedicate too
44:20
much time to active attack mode, you know, you you could find that you’re
44:23
underutilizing your resources, but maybe I’m just a little more risk averse, but
44:29
um you know, jaded just from being in this industry. Um, but you know, I would
44:33
I would prefer to a little I I would on the side of caution of putting too much
44:38
time rather than not enough time for active attack mode because at the end of
44:42
the day, if if if you’re not using that active attack mode, you can find other
44:47
ways to to still be productive in that extra time you have, you can’t add time
44:51
back, right? Um, it doesn’t work that way. Um, and then I think there’s like a
44:57
risk profile like like an individual organization’s risk profile. There’s a
45:02
component of that you have to consider as well. So, you know, for a an
45:06
organization that’s relatively low risk that that doesn’t see that many major
45:11
fraud attacks, you could allocate less time, right? But if but if you’re
45:15
selling, you know, high luxury goods or, you know, high-end electronics, like
45:21
things that are like fencable, highly targeted by fraudsters to to sell on
45:25
secondary markets, then I would I would lean to more time towards active attack.
45:31
Um, and if if there’s like a new product launch, right? Um, hey, we’re going to
45:37
you know what if it’s one of those years where like um you know there’s there’s a
45:41
big increase in like t uh like technology for HD TVs or like new video
45:45
game systems, right? And like all the you know there’s like three new major
45:49
video game systems coming out and it’s it’s a highly soughtafter item. um maybe
45:54
in anticipation of that carve out a little extra active attack mode for
45:58
that, you know, uh upcoming quarter or whatever that might be. So, while
46:02
there’s no one-sizefits-all approach, I would kind of focus on those um
46:05
organization level specifics that that might make it a little different uh for
46:10
you, right, than than in general.
46:12
>> Yeah. Yeah. And I just will reiterate like you want to really make sure that
46:15
your team is not spending all their time in active attack mode because that is
46:19
very draining. it’s unsustainable and it really creates just this like vicious
46:23
cycle where you’re unable to do the strategic long-term investment so that
46:28
you’re not in that active attack mode. So I I I always caution people there
46:32
especially if you’re managing team to be really mindful of of how often you are
46:37
spent in that time and if it’s too much then it’s your responsibility to
46:40
advocate for additional resources and for change. That that is an excellent
46:45
point, Rebecca. And and um you know, if if if you feel like your organization is
46:52
always in that active attack mode or needs to reserve like a a a large amount
46:57
of time for active attack mode, like bigger picture, there’s probably
47:00
something else wrong there, right? And and I think the fact that you mentioned
47:03
the the longer term strategy side is that’s it, right? That that’s that’s
47:07
what needs to change to to to get you in active attack mode less frequently,
47:12
right? and less often. So, I think that’s an incredibly uh valuable point
47:16
you just made. All right. Um, another question. What
47:24
tools or resources uh do you recommend um or prefer to use when organizing a
47:31
response to an incident?
47:34
>> I can take this, Justin. Um, I think I mentioned in a few slides that it was
47:39
really important that you have a tracking mechanism. Um I’ve seen lots
47:44
different tools deployed um from Google Docs to spreadsheets to Jira to ASA. Um
47:51
I think the most important thing to think through your tools is um twofold.
47:56
One I think it’s really important to have everybody within the organization
48:00
relying on the same tool. As I mentioned these incidents that you’re calling are
48:05
not only for fraud but typically usually like housed under your security team. So
48:10
there’s other teams across the company that are also calling their own
48:13
incidents. So it’s making sure that everybody’s using that same collective
48:17
tool. I’ve seen Jira used really well this way. Um, and I think the other
48:21
thing is that there is an accountability mechanism built in. And that’s also why
48:25
I like tools like Jira or ASA over a spreadsheet and that you can um assign
48:30
people the tasks. You can add reminders. You can do calendar dates and things
48:34
like that because I think the accountability piece is really important
48:38
to ensuring that the remediations are completed and they’re completed in a
48:43
timely manner. Um, and then also if you’re the one organizing these things,
48:46
it’s nice just to have a simple tool so you can pull them up because another
48:49
important piece of accountability is making sure that these are getting
48:52
reported somewhere that they’re either getting actively ported up to upper
48:55
management. Um, and if they’re not, maybe start sending some of them out
48:58
just because it’s important for lots of people within the organization to
49:02
understand when these attacks are happening, how they’re getting
49:04
remediated against, and what your team has done to make sure that um, you’ve
49:08
prevented additional loss from that specific issue.
49:12
>> Wow. that that um you you had that was a really great
49:17
answer. There there’s one part of that I really I really appreciated a lot which
49:20
was you you really kind of just connected being swift and being agile,
49:23
right? When it comes to remediation and the accountability
49:28
um for um you know like like the remediation is your agility, right?
49:35
Saying hey we’re making this change, right? But then does someone need to
49:38
sign off on that new model feature or rule you’re proposing? Does someone need
49:42
to implement that change? Right? And then if there’s that accountability
49:47
piece to ens essentially you’re ensuring that that this you know for lack of a
49:51
better phrase like a support ticket, right? Is kind of going down the line
49:56
>> um to it actually gets to that final implementation stage. Um so what that
50:00
just said to me was you’re ensuring that your agility is swift, right? Like
50:04
you’re remediating, you’re being agile, but but is it being implemented swiftly?
50:08
And I think it’s really um great how you kind of really just connected those two
50:12
things.
50:13
>> Yeah. And I’ll also add is it working?
50:15
>> Yeah.
50:15
>> So also the post monitoring too. I don’t know if I’ve mentioned that which is
50:18
wild but making sure that these things are are also working effectively too.
50:22
>> Yep. Absolutely. All right. Um well we are
50:29
um right about 45 48 minutes on the webinar which to me is the sweet spot.
50:33
So, um um I I would uh just like to kind of take this time to thank everyone for
50:39
for joining and for registering whether you’re here in person or watching this
50:43
recording later. Um for those of you who are here now, you should expect the
50:47
followup with the recording and white paper I mentioned by tomorrow. Um and
50:51
just once once again want to say thank you Rebecca for for co-hosting this this
50:55
webinar with me and and thank you to everyone here who’s attended.
50:59
>> Echo that. Thank you, Justin, and thank you all for those who um signed in
51:03
today. And I hope you guys all enjoy the rest of your day no matter where you
51:06
are.
51:07
>> That’s great. Yes. Thank you. Yeah. Uh Rebecca, I hope you have a great day and
51:10
everyone in attendance. Yeah, you as well. Um yeah, thank thanks again
51:14
everybody. Bye. All right. Bye.