Payment fraud continues to hold its position as the most prevalent form of fraud as we head into 2025. Over the past year, fraud has become more mainstream, with 34% of consumers seeing offers to participate in payment fraud online—blurring the line between fraudsters and everyday consumers. Payment method adoption rates, growth within specific verticals, and easier access to fraud tools are all contributing to the democratization of fraud.
Alexander Hall, Trust and Safety Architect at Sift, and Sudhir Lanka, Sr. Manager, Head of Fraud Strategy at Grubhub, discuss the findings of Sift’s Q1 2025 Digital Trust Index report and provide actionable strategic considerations as we move further into 2025.
Watch the webinar to learn:
- Current trends in payment fraud methods
- Industries with the highest attempted payment fraud rates and year-over-year increases
- How to leverage data to identify trends quickly
- How new developments in automation stand to empower fraud prevention teams
Watch On-Demand
Video Transcript
0:04
All right, so welcome to the webinar. We are going over tracking the evolution of
0:09
payment and fraud insights and strategies from the Q1 digital trust
0:13
index of 2025. And Sabir and I are going to discuss strategies moving on to uh
0:19
defend ourselves against payment fraud. So as I just mentioned, I’m very honored
0:23
to have Sabir here with me. Sadir, go ahead and introduce yourself.
0:27
>> Yeah, absolutely. Thanks, Alex. Um hey everyone uh my name is uh Sudhir Lanka.
0:33
Uh I’m currently leading the fraud strategy team here at GrubHub. Uh my
0:38
team is responsible for all verticals and all products and everything fraud on
0:44
these right. Uh so I’ve seen everything everything that we can think about fraud
0:50
from account creations to post checkout experiences as well and I’m I’m very
0:55
excited to be here and I’ll be you know sharing insights on payment fraud and
0:59
more.
1:01
>> What was really interesting during our conversations leading up to this is the
1:05
many perspectives that you have
1:09
>> perspective. There’s the B2B, there’s the B TOC, there’s all of these
1:13
different perspectives that fall under your be. So I’m very excited to get your
1:17
take on a lot of the items that were discovered in the report.
1:20
>> Absolutely.
1:26
>> Uh so I am Alexander Hall. I’m a trust and safety architect here at SIP. For
1:30
those who don’t know, that’s like a fraud subject matter expert. Uh we
1:34
support the product team, we support our partners, we support our customers and
1:38
clients, and we also go on stage and advocate in different fraud fraud
1:42
prevention areas. We uh we speak on stage and in webinars like this in order
1:47
to educate and inform uh everybody in fraud prevention. Prior to that, I was I
1:52
operated as an independent consultant where I worked with many different fraud
1:55
solution providers and many different companies solving many different fraud
1:59
related problems. Ultimately, I have 17 years of fraud related experience. Thank
2:03
you all for being here today. I hope you gain some great insight from our
2:06
webinar. Let’s go ahead and get started. All right. So, the agenda for today,
2:10
we’re going to go over the Q1 2025 DTI digital trust index report highlights.
2:16
We’re going to dive into some emerging emerging dis uh patterns. Then, we’re
2:20
going to go into the individual methods and really talk about what makes them
2:23
unique in today’s landscape. Following that, we have some very interesting
2:27
consumer insights to cover that are really going to show uh just how much
2:32
fraud is propagating throughout the marketplace on whole on the whole. Uh
2:36
and then of course we’re going to dive into the proactive considerations for
2:39
2025 and then we’ve left time at the end for some Q&A. So here we go. Number one,
2:46
our findings. So the biggest one, the biggest story that we’re that we uh
2:51
extracted from the report was what you see up top. E-commerce fraud is expected
2:55
to rise from 44.3 billion in 2024 to 107 billion in 2029. And that is a growth of
3:05
141%. When we look out at that and we see just
3:09
how consistent this growth is, I think that was a very shocking metric to take
3:13
in. Sudier, what are your thoughts on that?
3:16
>> Yeah, absolutely. You know, I was actually, you know, when I was reading
3:18
this report the first time, right? You know, I was I was just, you know, I just
3:21
took a moment for the number to sink in and I think I suggest everyone do the
3:25
same as well. uh we’re talking about a 141% increase over the next 5 years in
3:30
you know which is $ 107 billion I mean that’s that’s such an exponential
3:36
increase right now I think this what what you know to kind of put it into
3:39
perspective right you know if if let’s assume that if you know if if fraud were
3:43
a business right it’d be one of the largest and one of the fastest growing
3:47
industries in the whole world uh it it I think it what what it shows is that
3:51
fraudsters are adapting right so if there is a new payment method if there
3:55
is a solution, if there is a new platform, if there’s anything new in the
3:59
in the in the market, fraudsters are there to exploit it. Right? Now, the now
4:03
the and and that’s that’s what these numbers are showing this consistent
4:06
payment fraud attacks that that that that we see year-over-year and and the
4:11
exponential increase that we are expecting in the next 5 years, right? I
4:15
think the main question as merchants um is is that are we ready to to fight
4:21
this? Are we ready to counter this? what are the what are some of the uh you know
4:25
innovative solutions that we need to look through and and and you know what
4:29
what we need to kind of consider as part of our fraud mitigation efforts is is
4:33
probably the most critical point that merchants need to be thinking about in
4:38
in this in this perspective I would say
4:40
>> I love that you bring up the question of what we should be considering right
4:44
because when when we speak about payment fraud we typically relate it directly to
4:49
credit cards and debit cards we’ve started to see it related with gift
4:53
cards in that idea being being generally accepted across the marketplace. But
4:57
what we discovered in this report is that loyalty points actually saw the
5:02
biggest increase in um you know fraudsters focus right now. That’s a
5:07
very interesting thing to consider because loyalty points as a payment
5:11
method normally doesn’t get roped in there um you know across the board. We
5:16
in fraud prevention understand it but generally speaking we don’t think
5:19
loyalty points is is equal to credit cards and to see it surpass it in in
5:24
fraud interest I think was very interesting. What what do you think
5:27
about that? Yeah, absolutely. You know, this is this is this is the exact point
5:31
that I was I was I was about to bring up is that and I think the the you know,
5:35
traditionally traditionally everybody you know most of these digital
5:39
transactions currently even now I would say do happen through the traditional
5:43
payment methods like you know credit cards, debit cards and digital wallets
5:46
and and so on right and that’s where you generally expect the fraud to be right I
5:50
mean that’s you you’d say that hey maybe the highest fraud is coming from these
5:54
buckets right but what’s surprising here is that as you mentioned you It’s
5:58
actually kind of fraud is creeping up in you know loyalty points in financing in
6:03
prepaid cards and crypto and all these new and emerging alternative payment
6:07
methods right I think it’s very surprising but but you know thinking
6:11
about it a little little kind of uh you know in little deeply right I would say
6:17
that fraudsters are you know uh fraudsters are pivoting right they are
6:21
actually moving away from these traditional payment methods uh I would
6:26
say they are moving upstream right in sense that they know that all these old
6:30
traditional payment methods are are guarded really heavily. There is set
6:36
standard guardrails, payment guard rails that have already been set up for
6:40
decades and decades and and I think fraudsters have realized that um the
6:45
least resistance is is is within these alternative payment methods, right? So
6:50
for example, loyalty points, right? This is where almost all the companies are
6:54
offering these loyalty points or credits or concessions these days.
6:58
companies are using these as levers to kickstart their growth to kind of bring
7:03
the company back to their growth phase right and and I think even from a
7:08
company perspective they don’t want to place any kind of restriction they don’t
7:11
want any kind of uh you know uh friction to be placed in in this in this you know
7:16
when customers are trying to use this payment method right and I think
7:19
fraudsters do realize that and and you know and and combine that with let’s say
7:24
you know weaker identity checks right you know let’s say you have getting
7:28
loyalty points on your account doesn’t require any kind of identity check. You
7:32
don’t need any kind of oversight. There’s no real-time authorization
7:35
that’s being done here. Uh so I think combine this with that weaker controls
7:41
up front uh have kind of made these uh you know alternative payment methods
7:46
like a gold mine for fraudsters. They’re just become very easy targets, right? Um
7:50
just thinking about it, right? You know somebody’s you know let’s say my account
7:53
is taken over, right? Just imagine how easy is it to drain out all the loyalty
7:57
points that you that you’ve been acrewing for the last let’s say two
8:00
three years right people people do that right they just keep acrewing and they
8:03
just maybe want to make a big purchase later but right but for fraudster it’s
8:07
like it’s like a matter of like an hour right they just drain out everything and
8:12
and poof it’s gone right now I think I think the the takeaway is that frosters
8:16
are moving away from a traditional payment method they’re moving to the to
8:21
the point where there’s least resistance from a from a merchant perspective, from
8:26
bank perspective, and there’s no upfront controls at all. And and I think that’s
8:30
what I take away from this. I couldn’t agree with you more. Fraudsters are
8:34
absolutely moving upstream. They have identified that the majority of our
8:39
microscopes and magnifying glass are looking right at the checkout. So,
8:42
they’re going back upstream. And we’re also seeing a huge trend in them moving
8:47
upstream and off platform by by engaging in social engineering of the consumer.
8:52
>> Right? We’re going to get into those items more. I love that you brought up
8:55
ATOS because that’s an extremely important trend now that’s leading to to
8:59
the use of loyalty points as you just said, of course, the use of
9:02
transactions, but then there’s even more that’s available to uh to fraudsters
9:06
that are accessing accounts through ATOS.
9:08
>> Absolutely.
9:10
>> What do you think about seeing that uh retail e-commerce um is still seeing a
9:15
32% increase year-over-year? Yeah, I mean, you know, I think this was
9:21
this was kind of a little surprising for me. I mean, the way the way, you know,
9:24
we’re, you know, the way, you know, we’re trying to interpret the numbers. I
9:28
think what we have seen is that, you know, there’s a 32% increase in in in
9:32
the attacks in 2024, which makes sense, right? Which which makes sense, and I’m
9:36
from GrubHub, so I I couldn’t agree more with that. But what is surprising is
9:40
that even though there’s a 32% increase, it still stands at 10th place in the in
9:45
the attempted fraud rates for 2024, right? which is which is I would say
9:49
which is quite telling right I think I think it’s not that you know you know we
9:54
may feel tempted to say that hey you know the fraud is going down in
9:58
e-commerce but I don’t think that’s true right maybe it is going down in
10:02
e-commerce but I think the overall fraud is not right it’s possible that the
10:06
fraud is being just just being redistributed fraud is moving on to new
10:10
and these newer platforms right you know uh for example you see uh we we have
10:16
this uh you fintech platforms like buy now pay later platforms or we have these
10:20
ticketing platforms uh like we have you know seedgeek and you know you know
10:25
ticket master and all these platforms right people are moving into travel
10:29
people are moving into crypto when I say people fraudsters right frosters are
10:33
actually moving and redistributing their attacks to newer platforms and I think
10:38
and and that’s what I can read from this even though even though it stands in
10:41
10th place I feel that the fraud is just being redistributed it’s not that the
10:45
overall fraud is going down and uh and and and yeah, that that’s how I see
10:50
that.
10:51
>> That makes sense. And it actually to further embellish on your point, the
10:54
third point there, 34% of consumers have encountered offers to engage in payment
11:00
fraud. So, not only is it propagating fraudsters being fraudsters, but
11:05
fraudsters also trying to recruit from the consumer side, right? So when we see
11:10
that growth and then we secondarily see uh the fourth point there, the
11:14
democratization of fraud as a service and we’re seeing all of the different
11:18
ways that fraudsters are offering their services, it just becomes this huge
11:22
spiderweb. Great points.
11:24
>> Mhm.
11:26
>> So let’s move on. Of these, we were just touching down on the different types of
11:30
payment methods of which loyalty points was the number one uh fraud rate that we
11:36
measured here. But it was interesting to me to see that debit cards and credit
11:39
cards actually dropped to the last place for the increase. And to your point, we
11:45
see financing, we see the crypto, we see digital wallets and gift cards. Anything
11:49
here that you’d like to offer offer some perspective on.
11:52
>> Yeah, absolutely. I think you know, as as I was mentioning earlier, right, I
11:55
think, you know, fraudsters have started moving upstream into these alternative
11:59
payment methods, right? But I think if if we if we kind of go a little little,
12:03
you know, deeper into this, right? Why why did debit cards and credit cards and
12:08
you know these other payment method these traditional payment methods have
12:11
dropped off um potentially as I was mentioning earlier is that um you know
12:16
we have a lot of standard controls that that have been that are being developed
12:21
for the last let’s say last 10 or 20 years u and and and you know this this
12:27
shows that hey these controls that we’ve been working on they they’re working
12:30
really well right for example let’s say we have 3DS right 3DS is something that
12:34
we use to identify stolen credit cards, we can use that to identify account
12:39
takeovers, right? I think the the coordination between merchants and banks
12:42
and payment processors, you know, with 3DS triggers um and I think, you know,
12:46
it’s been really successful, right? U for example, if you look at um if you
12:51
look at the um you know, the device intelligence or the geoloccation
12:55
information that we that that we are able to capture, right? All these
12:58
traditional signals are are are working really well. uh and and and hence we
13:04
have seen we’re seeing a decrease in these in in fraud in these traditional
13:07
payment methods and and that’s what the fraudsters are moving towards the path
13:11
of least resistance right you know um creating a financing application or or
13:16
you know putting in a financing application with a with a BNPL merchant
13:20
is is is pretty easy at this point right you know this the the the identity check
13:24
or the the upfront checks checks have have become very lax I think the reason
13:29
being that you know um these platforms generally, you know, u generally have uh
13:35
generally pride themselves on on, you know, rapid approval processes, right?
13:40
Um um you know, and and that actually kind of u ties back into saying that,
13:46
hey, their KYC is probably not as comprehensive enough or they’re not
13:50
tracking the behavioral metrics as much as they should be at the time of sign
13:54
up, right? I think I think there’s like multiple multiple factors combined here
13:59
which basically uh you know the the the the takeaway here is that processor are
14:04
moving away and they’re moving into alternate payment methods and I think
14:08
this is this is only going to grow. It’s not going to go down at all. Absolutely.
14:12
Um and I think this uh one one one last point and I’d like to mention here is
14:17
that given that loyalty points or prepaid cards or gift cards you know all
14:22
these things right and companies use these as levers to create growth for
14:25
their companies at this point it becomes a a decision it becomes a business
14:30
decision whether you want to put more friction in in in in these payment
14:36
methods or you just accept the fraud as as a as a cost of doing business and and
14:42
then just move on, right? It just depends on the business. What is your
14:45
appetite to to to mitigate fraud on this uh and how far are you willing to to put
14:50
controls in in in for these, right? So, I think this this is this is the
14:54
probably the most important discussion that merchants or any company needs to
14:58
have. And you bring up a good point when it comes to calculating and making a
15:02
decision on treating it like a fraud risk because the definition of the cost
15:07
of doing business fraud conversation has changed because now with loyalty points
15:13
>> you don’t have chargebacks to measure. Someone spent a million loyalty points.
15:17
There’s no associated chargeback.
15:19
>> The the responsibility for that comes in the form of brand reputation. Right? if
15:24
if Jim’s account gets compromised and Jim’s million loyalty points gets spent,
15:29
it’s Jim who’s going to hold the platform, you know, accountable for
15:32
that. And so now the calculation and the variables that we take into
15:36
consideration are going to change depending on the payment method, you
15:40
know, as we see up here. I think that’s a really interesting call out.
15:43
>> Absolutely. And I think one sorry one one more point I’ll quickly want to
15:46
mention here is that uh you know we’re talking about you know uh you know I I
15:50
know that we’re talking about payment fraud here, right? But I think generally
15:53
speaking right as you mentioned you know there’s there’s no end result of saying
15:57
that hey you know we’re going to get a charge back or somebody’s going to call
15:59
and say that hey I have an ATO on this right it’s not going to these these you
16:04
know when somebody’s using these payment methods it’s not going to end in that
16:06
way right you know for example somebody can buy a gift card let’s say at Target
16:12
right and they use it on on on a platform right we are not going to get a
16:16
charge back right we’re not going to do that target is going to get a charge
16:19
back right but how do we know that Hey, this this gift card is being manipulated
16:24
and it’s being used again and again to to you know to order food for themselves
16:29
right so this is where the tricky part is right how do you how do you track and
16:33
monitor these kinds of payment methods to ensure that you know what is fraud
16:37
and you know what is not fraud right and this is where it becomes really really
16:40
tricky I would say yeah
16:42
>> you just brought up an example that we’re going to dive into later on but
16:45
I’ll I’ll take a second here you just you just touched on what I categorize as
16:49
multi-system exploits, right? So, the gift card
16:53
purchased at Target, used at GrubHub, neither company has all of the
16:58
visibility onto what the fraudster’s doing, and fraudsters are taking
17:02
advantage of that by by manipulating this system over here to use it at this
17:06
system over here. Thank you for for queuing me up on that.
17:12
Uh so industries with the highest year-over-year increase in attempted
17:16
payment fraud rates and we see financial institutions and fintech at the top. I
17:22
feel that uh what I’ve been saying for for quite a long while is that the
17:27
compromised identity information in the hands of fraudsters hasn’t yet been
17:31
fully realized for its value. And I think that this is starting to
17:37
illustrate that fraudsters are going to your point going upstream on the
17:41
platform but then upstream in the systems available and they’re moving
17:46
from payment information up to identity related fraud which then empowers them
17:51
to come back with more payment in more payment fraud. So I’d love to hear your
17:55
thoughts uh on the trends that we see as far as the industries go.
17:59
>> Yeah. Yeah. Absolutely. Um so I think I think looking at looking at the top two
18:03
right I think you know it’s it’s very obvious that fintech and ticketing
18:06
platforms have seen the largest spike in payment fraud here like which is 90 and
18:11
85% which is which is ridiculously high number if if you if you ask me but you
18:16
know to be honest right I think these two platforms you know um is where you
18:20
know as I was mentioning earlier is that you know these companies want to scale
18:24
rapidly and and I think this is where there’s a really high chance of risk a
18:29
really high chance of fraud happening, right? Um, you know, for example, right,
18:33
ticketing platforms often allow, you know, people to, you know, purchase
18:38
tickets like they they do uh same day or instant issuance of tickets, right? You
18:42
know, if you’re talking about any concerts, any games, right? There’s
18:45
instant issuance of tickets, which means that, you know, fraudsters can use
18:50
stolen credentials within minutes and nobody’s nobody’s going to bat an eyelid
18:54
about it, right? You just don’t have the time to look at it, right? Or if you’re
18:57
talking about fintech, let’s say let’s let’s talk about the buy now pay later
19:01
uh companies or like that that that payment that we have at this point,
19:05
right? We have an explosion of these these payment methods coming up, right?
19:10
We have a lot of new banks coming up, right? You know, we have Chime, we have
19:13
Dave, like so many neo banks are coming up. I think with these new uh innovative
19:18
and modern payment styles coming up, right? I think there’s a massive influx
19:22
of users, right? Everybody wants to sign up. Everybody wants to pay through
19:26
installments, right? AB: Absolutely. Which is okay. Nothing wrong with it,
19:29
right? But the problem is given that there’s massive influx of users combined
19:34
with weaker upfront controls, maybe a significant chunk of that is is
19:41
synthetic identities, right? Maybe it’s just not who they claim to be, right?
19:45
You just don’t know, right? I think I think this combination where where you
19:49
know as I was saying earlier is that these companies like you know they they
19:53
promise low friction onboarding saying that hey you come to our platform you’re
19:56
done with sign up in a minute or two. I think this this combined with this all
20:01
these factors together makes it a potent combination for fraud increase and and
20:05
and potentially that’s what we that’s what we are seeing here right I think
20:08
that’s a significant increase right and and I think you know leading leading to
20:13
that leading on that point I would say right you know if you’re talking about
20:17
the second point here we’re saying that account creation has become target
20:21
traditionally or at least from my experience at discover and you know I’ve
20:25
worked for Chase and discover before on the financial side generally speaking
20:29
the the focus the fraud prevention focus has always been at the time of checkout.
20:34
It’s at the time of transaction, right?
20:37
>> People always cared about, hey, you know, where where are we losing the
20:41
money from, right? And and the obvious answer is check out, right? So everybody
20:45
the fraud prevention has always been focused at at checkout. How do we stop
20:48
the transactions? How do you write rules to decline and and and so on, right? But
20:53
I think at this point, you know, fraudsters have adapted a lot. They’ve
20:57
evolved a lot. And I think at this point, fraud is is, you know, starts it
21:01
can start anywhere, right? It can start from a fake account creation uh which
21:05
can end up in loyalty exploitation. It can start with a synthetic identity. It
21:10
can you know u you know people are selling you know fraud as a service you
21:14
know as as we were talking about earlier. I think there’s the fraud has
21:17
expanded significantly. the playground has expanded significantly and I think
21:22
it’s important that our strategies also become more um you know our strategies
21:29
also evolve according to that and I think that’s where the the second point
21:33
what I was talking about becomes important right so you also need to be
21:37
looking at different touch points as you said earlier account creation right
21:42
account creation is a very important upfront control that’s where you you’re
21:46
going to have you’re going to need a good front fraud control at account
21:50
creation. Um, you know, it can be at login, it can be at, you know,
21:54
somebody’s changing their, you know, uh, profile information, it can be at
21:59
checkout, you know, there’s like multiple touch points that we want to
22:01
look at, right? And I think this is very important for merchants to adapt to this
22:06
um, you know, and and, uh, and and kind of approach fraud prevention from with
22:11
this mindset.
22:13
>> Yeah. Uh, perfect points. Uh I I typically like yesterday I did this this
22:18
session at RSA where I was moderating a conversation between fraud and CISO you
22:23
know uh roles and the thing that kept emerging is exactly what you just said
22:27
the pressure for holistic fraud prevention from account creation all the
22:31
way through
22:32
>> to fulfillment refunds returns chargebacks the whole journey we as
22:37
fraud fraud prevention operators need to have eyes across the entire journey and
22:42
the the interesting item was fraudsters and and various types of bad actors are
22:46
the ones dictating to us through pressure that we need to establish that.
22:50
So, great points.
22:51
>> Yeah.
22:54
>> Moving on. This is where we get to have a little bit of fun. I remember the the
22:57
config files were really interesting to you. We’re going to dive into uh the
23:01
different types of fraud methods that seem to be trending up or that are
23:05
trending up that are leading to payment fraud. So for a quick recap, what we
23:09
what everything kind of boils down to or bubbles up to is fraud as a service,
23:14
right? So fraud as a service is where a professional fraudster is offering their
23:18
services to the network, whether it’s through Telegram or Signal, dark web,
23:23
deep web, all of these different channels and forums, and they’re
23:26
offering their services. We see that primarily restaurants, QSRs, and rental
23:32
companies are major targets. And I feel that to your point, it’s because of this
23:37
quick delivery, this quick pickup, this quick setup, right? They want to be
23:43
quick to service, right?
23:44
>> And then an interesting item that I’d like to raise for our audience is the
23:47
use of vouchers, right? And so any professional fraudster who’s there
23:51
offering their services, when another fraudster or another consumer takes
23:55
advantage of those services, they come back with pictures and essentially like
23:59
Yelp and Google reviews, they’re offering vouchers with proof that this
24:03
fraudster performed well. And then to hop into the the one that I know you’re
24:07
interested in, they are starting to offer uh or they have started and it
24:11
just continue to offer the configuration files. These silver uh bullet
24:15
configuration files. I’m going to hop into that for you and hand it over.
24:20
>> Yeah, absolutely. So, you know, this is this is this is very interesting
24:23
actually. You know what one thing is that you know these fraud as a service
24:26
rings, right? You know, I’ve been I’ve been tracking them uh a little bit by
24:30
myself um just to just to understand how these frauders operate. You know, I I
24:35
sometimes find these Discord and Telegram groups and I just join and see
24:39
what they do, right? You know, how they define the playbooks, how they’re trying
24:42
to commit fraud and all these, right? But this this this is this has been very
24:46
interesting for me to look at this you know this uh you know this config files
24:50
that have come up. Um you know I think what we see here is of course this
24:55
config file is is being offered in this telegram group called typhon services
24:59
right but when I was actually looking at this code right I was trying to debug it
25:04
I think what these guys are trying to do I think just as a summary what they what
25:08
they’re trying to do is this is almost like an automated bot scripting kind of
25:13
thing where they’re trying to test the login endpoint and they’re trying to
25:18
evaluate the results that come out of it right in the sense the results that the
25:22
website or or that platform is sending out, right? I think if if you know if
25:26
you want to break it down, right? If we’re talking about like on the top you
25:29
see it says request post, right? What it basically is doing is it’s sending out a
25:35
login request to a particular digital website, whatever that is, right? Um and
25:41
it’s it’s also trying to identify the campaign and the user location with that
25:45
with that particular API or that URL that that they’re using here. They’re
25:50
trying to see if they can gather that data campaign and user location, right?
25:55
And then if you move on to the content here, right? Um the user attributes that
26:00
you see here, it says the email and the password, right? Um these fraudsters,
26:06
let’s say, right? They have a bunch of credentials that they gathered from a
26:10
databach or like they bought it from a dark web forum or something, right? And
26:14
if they want to test if how many of these combinations do work on a
26:20
particular website, they can actually keep entering that email and password
26:24
combination in the script and they can just keep hitting that login endpoint
26:28
until they get a result, right? And that’s what they’re doing here, right?
26:31
And then as as you as you’re looking at the header header um you know content
26:35
here, right? I think what something interesting that I’ve realized is that
26:39
they’re also trying to mimic uh you know how a normal human behavior is going to
26:44
look and and that’s what they’re trying to do here right you know if you look at
26:48
it um they are they’re trying to manipulate the the browser information
26:54
um they’re basically saying you know we want to they’re trying to manipulate the
26:58
language they’re trying to manipulate the content type um and and and they’ve
27:03
gone further to they’ve gone further to spec specifically feed in a user agent
27:08
as well. You see the last header in there, it says a user agent which is
27:12
Mozilla and and you know that’s what majority of the people use, right?
27:16
Mozilla and Chrome and all these ones, right? I think that this is more of an
27:20
effort to forcibly manipulate the API the the the the script which is going to
27:26
hit the login endpoint and they’re trying to mimic a normal human behavior
27:30
just like you and me, right? Um and and you know if you look at the the bottom
27:35
portion of this right the key check where it says key check that’s what
27:39
they’re looking for the result or or what comes back from the website right
27:43
they’re looking for a success response which basically contains possibly
27:47
contains a response code of 200 and they’re trying to see if they do get a a
27:51
response of 200 which they would classify as a success in the sense that
27:55
user email password combination is working right or they’re looking for a
28:00
failure which says basically you say failure or incorrect email or password
28:04
is what they’re looking for
28:05
>> or they’re also looking for if there’s a two-factor authentication either through
28:09
email or via SMS two-factor required right they’re also trying to see that
28:14
right now I think before I move on the last portion here is they’re also trying
28:19
to parse uh if they’re able to capture the full name of the account itself just
28:25
based on this response right some some some websites do return the full name
28:30
some Some some do, some don’t. It just they if if they’re they’re just uh
28:36
trying to see if they can capture the full name as well here, right? But I
28:39
think the intent from what I understand here is that of course trying different
28:42
combinations of password email password combinations, but also when they
28:47
evaluate the responses, right? I think let’s say if if it comes back as a
28:51
success, right? And that’s where these fosters can actually sell it sell this
28:56
account, sell these stolen credentials online for certain for certain amount.
29:00
So, right they can say let’s say $50 I have an account where you can login into
29:04
a certain website and you can you can do whatever you want right and this is
29:07
where this is where it ties back into that fraud as a service what we’re
29:11
saying right you know fraud as a service they can actually sell you stolen
29:15
credentials they can tell you how to do fraud they can give you these config
29:19
files uh they actually have different playbooks on how to commit fraud right I
29:23
think that’s what this script is leading to and I think um it’s it’s very
29:28
important that um the security teams I would say you know this is this is more
29:33
more in the realm of cyber security teams uh do keep an eye out for these
29:38
kinds of attacks any kind of credential stuffing or bot attacks that that we see
29:42
on on on our platforms and you know kind of be vigilant about it u but uh but
29:47
yeah I mean I found this very interesting and how they’ve been able to
29:50
manipulate uh the automation as well
29:54
>> you make you bring up great points and I think that uh what I would touch back on
29:57
what you said before You you had mentioned behaviors across the customer
30:01
journey, across a session, across an account, right? That the behaviors are
30:04
so important, right? And so when fraudsters are effectively using, you
30:08
know, scripts and and files like this in order to mimic the good behavior, the
30:12
good device setup that in order to blend in with the rest, it only embellishes
30:16
the importance of behaviors across the account and the the behaviors in the
30:20
session even more so.
30:22
>> Yeah, absolutely.
30:24
>> Anything else you’d like to add here?
30:26
>> No, no, no. I think I’m good here. Yeah.
30:29
>> So earlier on we were talking about multi- uh system exploits. One thing
30:34
that I bring up as a framework whenever I’m working with any clients or
30:38
customers is multi-touch versus multi-system. And you’ve done a great
30:42
job highlighting for us exactly what those stories are. We have fraudsters
30:45
that are creating an account using synthetic or truly stolen identity
30:49
information. We have fraudzers that are logging into compromised accounts,
30:52
established and compromised accounts, who then get to change contact
30:57
information. They get to change billing information. They get to use storm
31:01
stored payment information, stored credit cards, stored loyalty points.
31:05
They transact with new compromised payment methods. They go through and
31:09
abuse policies, abuse processes. The world opens up to a fraudster whenever
31:14
they successfully executed an atto. And it’s that multiple touch
31:20
>> where they’re bouncing around in the behaviors there that we’re going to need
31:23
to extract and evaluate in order to identify these trends. And the important
31:27
item here, the important distinction here is when it comes to the multi-touch
31:32
across one platform, that’s our call for holistic fraud prevention. We need
31:38
visibility through our data from account creation all the way through to
31:41
chargeback and beyond. That’s one. Then shifting over to multi-system where
31:46
we’re talking about triangulation fraud, fraud as a service, the QSR and the car
31:50
rental companies where the consumer uh the fraudsters consumer or I should I
31:57
should say the fraudsters consumer, right, is contracting him or her to go
32:02
and and make these these purchases on their behalf. triangulation aspect of
32:06
things um makes it even more important to to to have uh communication between
32:13
uh between platforms and tap into this this network that we’ve that we’ve
32:17
established. Um it makes it just that much more important.
32:21
Additionally, you brought up in our conversation how interesting it was to
32:25
see that both consumer and business accounts are being targeted um by ATOS.
32:31
And I think that that’s one thing that isn’t spoken about quite enough
32:34
>> is B TOC gets enough coverage. B2B not so much. So I’d love to hear your
32:40
thoughts on that.
32:40
>> Yeah. Yeah. Absolutely. You know I think as you mentioned right I think you know
32:43
ATO is not just about you know stealing a login anymore. As you mentioned it’s
32:47
it’s a multi-step sophisticated attacks that we that we are seeing right and I
32:52
think the same thing is happening with B2B as well. um you know one you know I
32:58
think the controls as well what you mentioned you know having multi-step
33:02
controls and you know looking at behavioral information login information
33:06
and you know payment information everything combined together is really
33:10
important right but I think coming to B2B um you know one
33:15
um difficulty would be that you know a business signing up for for let’s say
33:21
for a service right there’s there’s a possibility that people are spread out
33:26
or that employees let’s say there’s employees are spread out across the
33:30
country right or across the world right it could be that one person is ordering
33:36
to Chicago another person is ordering to California another person is ordering to
33:41
let’s say India right now according to according to them it’s normal right but
33:48
if you’re looking at it from a fraud perspective it looks it’s it’s very
33:52
uncomfortable for us to look at that kind of a pattern, right? I mean, it
33:55
cannot be happening, right? If you’re just looking at from a B2C perspective,
34:00
what I just mentioned cannot be happening. It’s it’s a it’s a peak
34:03
fraud, right? Now, I think this is where it it you know, this is where the nuance
34:08
comes in, right? You have to figure out how do you how do you separate out and
34:12
how do you formulate strategies for B2B separately as compared to B2C? How do
34:17
you understand what is the normal behavior of a B2B as compared to a B2C
34:22
and and try to formulate your strategies according to that and a lot of these
34:26
existing controls uh may not work um the same way it does on a B2C it
34:32
doesn’t work the same way on B2B it doesn’t right you have to figure out
34:36
maybe you know 3DS doesn’t work on that you know maybe the device intelligence
34:40
doesn’t work on that right maybe the device is coming from different
34:43
locations different you know uh different device fingerprints, different
34:48
IPs, it doesn’t work on that. So the traditional uh controls that we all look
34:54
at may not work on B2B, right? So this is where I think this it’s very
34:58
important for merchants to understand, you know, what kind of a business do you
35:02
have? how do customers interact with your website uh from a from a business
35:06
account and figure out what is the baseline or or normal behavior and then
35:12
figure out what behavior deviates from it right so it’s it’s a you know I would
35:17
say I would say you know the end goal of a fraudster is still the same right but
35:21
how do you how do you protect your good customers is much more important from a
35:25
B2B perspective I would say uh uh rather than a B2C
35:30
>> sure and it’s it’s just a deeper a much deeper dive into knowing your customer,
35:36
knowing your user base, right?
35:38
>> Absolutely.
35:39
>> Great point, sir. Thank you.
35:43
>> Uh the next method that I wanted to dive into that we see spiking across the
35:46
entire industry is social engineering. Right? So uh for for the attendees,
35:51
social engineering is anywhere wherein a bad actor manipulates through text
35:56
messages, conversations, phone calls, emails, social media posts where a bad
36:03
actor is manipulating uh an unwitting consumer into action, right? And so what
36:09
we see is that social engineering is being applied uh by bad actors in order
36:13
to get these users or these consumers to give them account access to give them
36:18
their personal private information whether it’s payment information,
36:21
identity information or the login details to an account something like
36:24
that or initiating payments. But there’s also other things where they will um
36:29
socially engineer a a consumer to receive a package and then forward that
36:34
package on like a freight forwarder but on the consumer level. There are others
36:38
that will receive wire transfers, take a percentage, and send that money back
36:43
out, putting them at great risk of of fraud because of course those payments
36:46
are bad. Now, as you were saying about B2B having a unique frame that we need
36:53
to consider when it comes to to building up our fraud strategy, how we need to
36:57
know what what the business behavior is contrasted against what a singular, you
37:02
know, user’s uh information is. I feel that this is yet another category that
37:07
needs to have special attention because in these circumstances, they are the
37:11
verified users. They’re the they’re our best users who are doing these things
37:16
because they believe that they should be doing it or that they’ll benefit from
37:20
it. Think about romance scams. Think about uh investment scams especially in
37:24
the world of crypto where the consumer or the user is being manipulated off
37:29
platform by somebody who says hey you should invest in this crypto coin and
37:35
when they submit the first couple grand they they they manipulate the screen so
37:39
it looks like it’s trending up and before you know it our good crypto user
37:44
has drained their entire wallet into the secondary marketplace and for not
37:50
>> right And so when we’re evaluating these behaviors of a user who’s being socially
37:55
engineered, that introduces a new category of strategy. I’d love to hear
37:58
your thoughts on that.
38:00
>> Yeah. Yeah. Absolutely. You know, I think I think you know, personally, you
38:03
know, I’ve been seeing this social engineering fraud attack for almost like
38:08
8 years now. Right from the point where I was a discover as well, we’ve seen
38:11
significant social engineering from a from a bank perspective and we are
38:16
seeing the same thing uh from a merchant perspective as well. Now uh but but yes
38:20
you know as you mentioned I think you know this is where you know it’s being
38:23
you know people are being manipulated to reveal sensitive information right you
38:27
know it can come in the form of fraudsters posing as customer service
38:32
agents they can pose as drivers they can pose as customers uh and and so on I
38:37
mean they can they can do anything right but I think one one very important point
38:42
you know that that you mentioned and it’s it’s part of what you’ve written
38:45
here is that the verified user right now I think this This is where it becomes
38:49
very very tricky and I agree with you that it’s it’s a separate category by
38:53
itself right the reason being now the the let’s say the actual
38:59
customer right they are doing exactly what the froster is telling them to do
39:04
right let’s say that they are using their own device to log into it they are
39:09
doing the same thing that they do every day let’s say you know if we’re talking
39:12
about from a from a e-commerce perspective right they log into their
39:15
own device they order the same food that they’ve always been doing. They’ve been
39:19
uh uh you know they’ve ordered to the same location. and they were ordering
39:23
from the same restaurant let’s say right the behavior the problem here is that
39:27
the behavior is exactly what you expect for this user to be and that’s exactly
39:32
what what’s happening right I think the tricky part is the user is now part of
39:37
that fraud without them knowing it right and that’s where that’s where the bigger
39:43
problem comes in and this is where our existing controls let’s say like device
39:47
fingerprinting geoloccation this IP and behavioral not behavioral metrics but
39:51
all these tradition controls do not cut it anymore, right? It’s not going to
39:55
help you in any way to identify social engineering, right? Um now I think I
40:00
think the reliability on traditional signals not being existent anymore, what
40:05
can be done, right? I think the the um the potential takeaway here is that I
40:13
would say, you know, the first and foremost is that you’re going to need to
40:16
provide education to your end end users, right? you’re going to let them know uh
40:21
or at least from a from a e-commerce perspective, right? You know, you you
40:24
know, we interact with customers, we interact with drivers and also
40:28
restaurants, we need to have some kind of educational material being sent out
40:34
to them to for them to learn how fraud happens, how fraudsters can manipulate
40:39
them into revealing OTPs, in revealing their uh login information, their bank
40:45
account information, all these things, right? And I think that’s that’s
40:47
probably the the most important thing. And the second thing is uh you know uh
40:52
internally you know you’re going to need to have some kind of proactive alerts uh
40:56
um you know in in the sense looking at the behavioral information uh or or the
41:01
real-time behavior of an account right um having alerts to to identify any kind
41:10
of suspicious activity would probably one one thing that that that is that
41:14
would be really helpful internally uh to identify social engineering right Now I
41:20
think u one critical point that I want to end end this wrap up this this point
41:25
would be that generally speaking what are what are the three uh main metrics
41:31
that you want to track right you know and you know for payment fraud it would
41:35
be the first one is identity you need to know who that person is the second one
41:39
is you need to know the intent and the third one is behavior right now I think
41:44
the problem with social engineering is while the identity remains intact act
41:49
the intent is being manipulated right the intent of the original customer
41:52
customer is being manipulated and it’s really really difficult to understand
41:57
the intent I mean how are you going to understand what a human is thinking
42:00
right it’s it’s it’s it’s a very difficult problem to solve social
42:04
engineering
42:05
>> I think there are some solutions in place but there’s there’s you know I
42:08
personally feel that there’s much more much more to go and there’s much more
42:11
advancements that needs to happen in in for in terms of catching social
42:15
engineering I would say
42:17
>> great point what was that framework work one more time. It was identity,
42:22
>> uh, intent and behavior.
42:23
>> Intent and behavior. Yes, guys, take that away. Behavioral behavioral
42:27
analytics, behavioral elements are only going to become more important as time
42:30
goes on. And, um, yes, I couldn’t agree with you more.
42:36
So, now let’s hop into the consumer payment fraud insights. Nearly half, 44%
42:43
of consumers surveyed by SIFT have been a victim of payment fraud in their
42:48
lifetime. And of the 44% that were uh that were that fell victim, instances of
42:55
payment fraud in the last 12 months, we saw 9% of them were targeted three or
43:02
more times, whereas nearly half of those um were
43:07
targeted once. Now, I think this is really interesting because what an
43:12
interesting narrative that has uh emerged in fraud prevention is that a
43:16
fraudster will take a credit card or a debit card and they’ll use it as much as
43:21
possible, you know, until until it stops, you know, being useful. Um,
43:26
what’s interesting is with the emergence of all of these different categories of
43:30
payment fraud, I think the the number of attempts gets lower. Right. Right. you
43:37
can’t continue to take those same attacks like so for example if a
43:41
fraudster were to get access to Jimmy’s account and spend their loyalty points
43:47
well it’s one and done
43:48
>> there’s the the opportunity to to go again isn’t there right and so I think
43:53
that’s an interesting perspective uh what would you like to say here
43:57
>> yeah absolutely I think you know um you know talking about you know 44% I mean
44:01
that’s that’s nearly almost every other person that you know has been a victim
44:05
of payment fraud That’s that’s that’s a staggering number like if you think
44:09
about it right you know I think you know what I personally feel with this is that
44:14
with payment fraud being not just payment fraud you know generally as as
44:18
fraud being so pervasive I think it just creates uh a climate of fear right I
44:23
think you know people you know customers lose their trust on platforms right it
44:28
just leads to you know more sensitivity uh to using digital platforms right if
44:33
if a customer doesn’t feel safe that they’re that that their payment
44:37
information or their personal information is not safe with the
44:39
platform. They just lose the trust towards that platform, right? And I
44:43
think you know this this this uh this this also puts some you know kind of
44:49
pressure on on companies as well, right? You know you’re going to see higher
44:52
chargeback claims. You’re going to you’re going to um you know customers
44:57
are going to expect more controls or more reassurance at different different
45:01
end points, right? you know, you’re going to see uh more and more people
45:05
resetting their passwords. You know, they’re calling in too many times trying
45:09
to figure out what happened with their account. It also puts pressure on
45:12
companies as well, right? I think I think at this point I think just as a
45:16
simple conclusion here is that fraud is not just about mitigating
45:22
losses. It’s not just about bringing back the lost revenue, right? I feel
45:26
that this is this is almost about rebuilding that trust with the customer,
45:31
building that brand back to to ensure that and to make them feel safe that
45:36
hey, you know, they can come back and and transact on our platform, right? I
45:40
think the the the role of a fraud team has has has significantly changed I I
45:45
feel in the last 5 to 10 years. It’s not just about protecting money anymore.
45:49
It’s about protecting the image and reputation of a company at this point.
45:53
>> Absolutely. you went into the the responsibility, right? And and I wanted
45:58
to put this up on screen. The consumer places a responsibility for payment
46:02
fraud at the organization or the financial institution that allowed it to
46:06
go through.
46:07
>> 68% of consumers would no longer use a site where they had been a victim of
46:13
payment fraud. So, if you’re allowing, not allowing by choice, I understand,
46:17
but if if if someone if a platform allows fraud to go through and Jimmy’s
46:21
accounts used there, Jimmy isn’t going to trust that platform anymore by an
46:25
overwhelming majority.
46:27
>> 49% believe that the merchant should be held responsible for the use of
46:30
compromised payment information. It all points the signals are all there.
46:35
And to your point, what we’ve identified throughout our previous uh tracking
46:40
through our fiber network, we’ve found that MFA adoption is starting to or has
46:45
continued to rise over the the last period of time.
46:48
>> So, we’re able to see that that consumers are more comfortable with
46:52
multifactor authentications. Um,
46:55
>> which ones are going to depend on your industry, which ones are going to depend
46:58
on your your customer base. But we are seeing that the adoption rate is
47:02
increasing. So we know that consumers are becoming more comfortable with um
47:08
with this these types of friction and verifications in certain circumstances.
47:14
>> Absolutely.
47:16
>> All right. So now let’s dive into the fun stuff. Strategic considerations.
47:21
Um I’ll start by reading the title. 68% of consumers stated they would stop
47:25
shopping on a site if their payment credentials were used for unauthorized
47:29
purchases. So as we approach strategy development for 25 for 2025 and beyond,
47:36
this is really going to solidify the importance here, right? What goes into a
47:41
strategy? We’ve discussed uh leading up to this, we’ve discussed what a payment
47:44
method can be, what it entails, everything from loyalty points to buy
47:48
now pay later, financing options, crypto, and beyond. Um what do we need
47:53
when we are going to strategize? So on this screen, we’re going to talk about
47:56
the data. uh holistic fraud monitoring is the first step is to establish data
48:01
for every touch point. We need to identify what common normal good
48:06
verifiable behavior is in order for us to identify what anomalous behavior is.
48:11
Imagine if you get a login if somebody were to arbitrarily mention having
48:16
10,000 accounts created in a day. Well, that’s a lot for a pizza shop at the end
48:20
of the at the at the corner, but it’s not a lot for Amazon. you know the the
48:25
the perspectives are going to be different and only through data are we
48:29
going to be able to identify what works in our trends and what works for us. Um
48:34
to your point the different data sets tell different stories. So we have
48:38
device intelligence we have behavioral analytics and we have digital identity
48:42
and then as I just said payment methods.
48:45
>> I’d love to hear your thoughts on the emerging tech of device intelligence.
48:49
We’ve spent a lot of time so far talking about behavioral analytics but then also
48:54
how digital identity is is evolving through the marketplace.
48:57
>> Yeah. Yeah. Absolutely. You know I think you know talking about you know these
49:01
you know different controls or different data sets as you as you mentioned here
49:04
right. I think we’re saying you know device intelligence it’s it’s it’s you
49:07
know I feel it’s really critical to have device intelligence solution. Um, you
49:12
know, we’re talking about identifying if if a customer is logging in from a from
49:16
a jailbroken phone or are they using a uh or are they emulating a browser or
49:22
emulating a device, right? Uh have you have you seen this device previously on
49:27
your platform? Have you seen this across multiple accounts or have any of your
49:31
peers or any of your uh anywhere in the industry, have we seen this device ID
49:36
being used with fraud? Right? I think making that connections and looking at
49:40
it from a device uh perspective is really really important and I think we
49:44
have seen a good success in mitigating atto specifically uh with the device
49:50
intelligence or device fingerprinting I’d say here. Um and then we’re talking
49:54
about behavioral analytics. This is where you’re talking about you know how
49:58
fast are they typing? Are they are they copying and pasting too many times? You
50:01
know how fast is is their mouse or their or their you know this cursor is moving
50:06
right? Are they does it look like a human or is it does it look like an
50:09
exact bot? How a bot would do it, right? I think this this basically tells you
50:13
how human it is. Is it like a a a bot attack that you’re looking at? Uh is it
50:18
an automated script that’s running through your platform or is it like an
50:21
actual human doing it, right? And I think the last one, digital identity,
50:25
you know, this identity itself or what we are
50:29
calling it as a persona, right? I think this is really important to track it at
50:32
a persona level rather than just tracking it at a user level or a device
50:36
level, right? Uh taking a step up and looking at it from a persona level or
50:41
identity level is really important. Uh because you’re trying to see even if
50:45
they are changing their device, even if they’re changing their location, IP or
50:49
anything that they’re trying to manipulate, the identity still points to
50:53
the same single froster that we’re targeting, right? And I think having
50:57
this solution to look at the identity digital identity is very important. And
51:01
of course the way you’re going to look at it is you know where do you where
51:05
else do you see this identity? Did you see this fraudster uh in your previous
51:09
history or somewhere else right? And maybe some other fraud vendor saw it,
51:13
right? Or you know, you can also see that uh was this account which is
51:18
pointing out to this particular fraudster was it just created like 3
51:21
minutes back from a Starbucks or do you see that it was created like 10 months
51:25
back, 12 months back, right? kind of having that having that um view changes
51:30
a lot and you know it’s really critical to have these controls in place and you
51:34
know it’s it’s you know specifically for GrubHub it did work out really well to
51:38
have these solutions in place I would say
51:41
>> awesome great points I would offer that when it comes to behavioral analytics I
51:46
know a lot of people get intimidated by it think that what it will take in order
51:50
to get up and running with behavioral analytics is is can be daunting but I
51:54
would always pause it and I would say Well, consider this. Even on a when I
51:58
was first doing fraud analytics, fraud prevention analytics,
52:01
>> I was on Shopify with no plugins. I was bare bones, right?
52:06
>> And what I would do is I would look at those five or six, seven different data
52:10
points that we had available to us and I would be able to just infer they’ve had
52:14
10 transactions over the last two days.
52:16
>> Yep.
52:17
>> That’s a behavior. Now, is that normal? Did they use different payment methods?
52:20
Are they shipping to different places, different billing addresses? same email
52:24
with all of these different Well, that’s behavioral analytics.
52:27
>> Absolutely. Yeah.
52:28
>> Right. So, we all have access to elements that can be evaluated in order
52:31
to see what common verifiable is and to see what anomalous is. And I would just
52:36
invite anybody to kind of go through that exercise and see what kind of
52:39
behavioral analytics they can pull out.
52:41
>> Yeah, absolutely.
52:44
>> When it comes down to strategizing, and we’re getting into the the home stretch
52:47
here, there’s a lot to cover with the fraud strategy. So I will ask you what
52:52
would you say uh are the top three recommendations when it comes to
52:56
developing a fraud strategy?
52:58
>> Yeah, absolutely. I think one is you know what what we’ve been what we’ve
53:02
been saying for the last 1 hour is having a comprehensive fraud strategy at
53:06
different touch points is probably the most critical I would say at this point
53:10
to to counter payment fraud. You need to be looking at uh even before somebody
53:15
creates an account, you need to be looking at the at the traffic that that
53:18
is hitting your platform, right? Is somebody trying to do car testing? Is
53:22
somebody trying to do credential stuffing? And then you move on to
53:25
account creation, login, check out and having that control at different
53:29
checkpoints is probably the most important I would say. And uh the second
53:33
one is you know I would say you know what you wrote here the first one I
53:36
totally agree with that scenario based rules right I think you know having
53:39
dynamic not dynamic sorry having static fraud solution is not an option anymore
53:45
right so your your solution has to be moving it has to be evolving along with
53:49
the fraudsters and you have to be you have to be consistently on your feet
53:54
trying to understand what the fraudster is doing how they’re pivoting and you
53:58
know your solution and your your your your rules or whatever that you’re
54:02
doing, it has to evolve along with that. It has to be a dynamic solution. It has
54:06
to depend on the type of fraud that you’re trying to solve. What is your
54:10
what is the appetite for your company to mitigate fraud? How much friction can
54:15
you put? It depends on a lot of factors. And I think that’s really really
54:18
important. Uh rather than having just a static uh uh you know fraud strategy
54:23
here, right?
54:24
>> Mhm. Um and I think the last one you know I would say is that you know maybe
54:28
let me combine the customer insults manual review and block rates. all the
54:32
last three all combined into one point is very basically you know having higher
54:37
block rates is potentially not a great idea right uh but you also need to be
54:43
tracking how many genuine customers are you actually insulting right you’re
54:48
having uh having let’s say a high block rate in itself is not a bad idea right
54:53
but if your false positives are high where your customers feel insulted is
54:57
also high then your fraud strategy has a problem right you need to it’s it’s
55:01
veryant important to balance that uh customer experience with fraud
55:07
prevention and ensure that the false positives are not really high. Customers
55:11
feel safe and secure and they have a smooth experience on your platform. Uh
55:16
as a fraud strategy team, this is probably one of the most important
55:19
things that we need to take care of and I would say that will be the third one.
55:22
Absolutely.
55:24
>> You absolutely just covered everything in three points where I wrote it out as
55:28
six. Great job. And you kind of you you definitely nailed home the idea of
55:33
>> once a once a platform gets to a gets to a point and they have this holistic
55:37
fraud strategy in place then it then it enters into the next dimension for me
55:42
which is once you reach a higher volume once you reach a higher fraud attack
55:47
rate once you reach um different types of of geographic and you would you
55:54
expand geographically it enters the necessary step of automation Right. And
55:59
through automation, we’re always greeted with these points. Do we build in-house
56:03
or do we buy? And one one statement that I always respond to that is when it
56:08
comes to somebody looking to build inhouse, they’re evaluating a snapshot
56:12
in time of a vendor, they say, “Oh, well, it can do this and it can do this
56:16
and it can do this.” And they spend the next x period of time building to that
56:20
point. And in that time, the the vendor that they were attempting to supplement
56:26
in house has already moved on, you know, another year into the future because
56:30
they’re gleaning um from number four there. The new insights
56:35
>> fraud prevention solution providers are constantly ingesting from all over the
56:39
marketplace and making their product change and differ.
56:43
>> Right. So when it comes to automation, what would you say are your top
56:46
considerations? um you know specifically specifically
56:51
you know from my perspective you know I I I generally suggest that automation is
56:56
the way to go uh you know everybody’s talking about AI these days and you know
57:01
automation is definitely the way to go and I think from my experience as well
57:05
uh it has it has given us better results than
57:09
manually sitting and doing things right you know rather than us building let’s
57:13
say different strategies or different models or you know doing anything Right?
57:17
Doing anything manually did not get us better results than what an automated
57:22
solution would do from let’s say from a fraud vendor. Right? So I I would
57:26
definitely say that you know it depends let’s say you know if you’re talking
57:28
about manual review cues right I think it depends on the industry for GrubHub
57:32
manual review cues doesn’t make sense right we just have to deliver within 30
57:36
minutes so we don’t have a possibility of manual reviews right but you know
57:40
even even even where there’s a possibility I would say that you know
57:43
keeping the manual review cues uh to a minimum is is definitely suggestible
57:49
right um and and you know automating your solution from the start to the end
57:54
is definitely the way to go is is at least that’s my perspective. You know, I
57:58
always keep saying that to everyone um that I meet, but uh but that’s my
58:01
perspective. Yeah,
58:03
>> thank you so much. We are at time and to be respectful of yours and everybody
58:07
else’s, let’s go ahead and do a quick ret recap. The main takeaways for me was
58:12
the emergence of loyalty points as being the number one targeted payment method
58:16
uh in Q1 2025.
58:19
>> To Sadir’s point, many times over in this, we were really hammering it home.
58:24
fraudsters are moving upstream and they’re moving across your customer
58:27
experience journey. So in order for you to effectively respond to that pressure,
58:31
you need to respond in kind, build out this data, build out the technology,
58:36
glean those insights from from from different um partners in the space and
58:41
different different uh different industries across the marketplace. Um
58:46
there’s the pressure consumers that we didn’t get into this one which was kind
58:50
of you know we had to be uh respectful of time but 23% of consumers have
58:55
personally or know someone who has participated in payment fraud. Sorry we
59:00
weren’t able to get to that but in order to read more on that please go to
59:03
website and go ahead and get a hold of uh our digital trust index for Q1205.
59:10
Thank you guys so much. Sudir, thank you for joining me. I look forward to more
59:13
with you. Yeah, absolutely. Thank you. Thank you for the opportunity and uh
59:17
great hearing from you.
59:19
>> All right. Have a good one everybody.
59:20
>> All right. Thank you.



