Understanding your players is the key to protecting revenue, reducing fraud, and driving sustainable growth. But how do you go beyond basic KYC and homegrown systems to unlock real, actionable player insights?

Get a step-by-step roadmap to achieving better player insights using AI-powered risk assessment, advanced risk signals, and automation. In this on-demand webinar, you’ll learn how to:

  • Move beyond traditional fraud prevention and gain a deeper understanding of player behavior
  • Use AI-driven risk models to detect emerging threats before they impact revenue
  • Leverage flexible risk strategies to protect players while keeping legitimate customers engaged

Leave with a clear plan to enhance your risk management strategy, reduce manual reviews, and confidently grow your iGaming platform.

Watch the On-Demand Webinar

Close

Thanks for submitting!

close

Video Transcript

0:03
Hi everyone. Thank you for joining our webinar today. Roadmap to better player
0:08
insights, smarter risk assessments for i gaming.
0:13
My name is Stephanie. I am a PMM for SIFT is an AI fraud solution provider.
0:20
We’ve been recognized in analysts reports such as Forester. I’m proud to
0:25
say we’ve been consistently ranked number one in G2. Um, and we help
0:30
service I gaming operators. Uh, most notably, we help
0:36
90% actually of our, uh, operators in the US market. And with me today is
0:42
Alex. Alex, can you tell us a little bit about yourself?
0:46
>> Absolutely. Hello everybody. My name is Alexander Hall and I joined Sift back in
0:51
August as a trust and safety architect. For those of you who don’t know what
0:56
that is, uh we’re kind of like an internal fraud subject matter expert.
1:01
Prior to joining Syft, I operated independently where I worked with a wide
1:05
range of different vendors and through my work with those vendors solved
1:09
problems for a wide range of different platforms. Ultimately, I have 17 years
1:13
of experience.
1:16
>> Doesn’t look like it at all. Um Alex and I work together closely. My role here at
1:21
SIFT is to deeply understand uh the trending challenges of our customers
1:26
specifically in i gaming and make sure that the innovation that we deliver is
1:31
in line with that. So needless to say we spend a lot of time trying to understand
1:36
the cutting edge trends of i gaming. And with that I wanted to just give some
1:43
folks a bit of context as to why we’re here and why you’re probably here.
1:49
Recent reports say that for every dollar spent to acquire a new player, you can
1:55
lose up to 30 to 50% due to an increase in fraud. And jumping to the end because
2:05
I’m wanted to give just a highle framework of where we’re going to go is
2:09
what is the through line in the solution to that kind of scary stat. For us, we
2:16
think of it as a better understanding of the player identity story. A key part of
2:22
that is really this concept of context. The better you understand your users,
2:29
your players, where they come from, what perhaps their intents are, um the more
2:35
you might be able to trust them to be able to drive revenue.
2:42
And to get there, we’re going to talk about three things today. By the end of
2:46
this event, uh we hope you have a better understanding of why fraud is
2:51
accelerating, what you need to get in front of it, and how it applies to real
2:55
life examples. And so, let’s kick it off with why. Uh
3:00
being a fraudster has become more popular. We just launched hot off the
3:06
presses, our Q1 digital trust and safety report. And what we noted is a trend
3:11
that’s been growing. 34% of consumers have seen offers they’ve been solicited
3:17
to become a fraudster. In essence, becoming a fraudster has simply become
3:23
more popular. In fact, 23% of consumers have known someone personally or
3:30
participated in fraud. If you are not part of that segment, you are more
3:35
likely to be part of the 65% who have known someone who participated in fraud.
3:41
Now, these findings are focused primarily just on payment fraud.
3:45
However, this is part of an overarching trend that we’re seeing become more and
3:49
more prevalent. When we look at why, especially in i gaming, it’s because
3:54
fraud fraudsters are essentially more digitally savvy. Recent report also
4:00
showed that 47 47% of fraudsters are between the ages of 36 to 45. 39% are
4:08
the ages between 60 26 and 35 years old. And if you’re in sports betting, which
4:15
is one of the highest growing sectors, um the average sports better is about 38
4:20
years old. This is part of a group called Millennials, I am part of it. We
4:24
have been uh born and bred in the internet age. We are very very technical
4:29
averse and comfortable in that space. And on top of that, fraudsters in this
4:34
age group are connected more than ever. In a recent report uh by the EU, they
4:40
found that 821 criminal networks existed that consisted
4:45
of 25,000 members who commit crimes for profit. Now, keep in mind this is just
4:51
of those that have they’ve been able to keep an eye on. I am very very confident
4:57
that this is probably not a totality of what actually exists there. And so what
5:02
you’re looking at in terms of a wave of fraudsters are that they are of age that
5:07
are very digitally savvy and uh more connected than ever.
5:12
>> Stephanie, I think we’re having a technical issue.
5:15
I don’t see your deck.
5:17
>> Ah, thank you for that. Here we go. How
5:22
about that?
5:22
>> There we go.
5:23
>> Great. Um and in that sense uh kind of
5:30
resetting um
5:33
here are some stats in the image form. Broadsters are of an age like I said who
5:39
are very comfortable in the digital um arena and connected more than ever. And
5:47
part of the reason why, and I’m glad that we have images now because this is
5:51
quite a poignant one, is mainly because the access and the how-tos are more
5:56
readily available. So, if you’re thinking of uh what a
6:02
fraudster looks like, um they are younger, they’re more digitally savvy,
6:06
and they are using apps like Tik Tok and social media and the dark web. And now
6:12
this is some research um that Alex’s team from Tasa actually do conduct. What
6:17
you see in the dark web are accounts for sale, uh digital wallets, stored value
6:23
for sale. On top of that, um a how-to specific fraud guides that they are
6:29
collaborating on to better understand how to uh to conduct fraud on your
6:35
platform. Layering on top of that is new technology to help mask some of the
6:42
thing the detection mechanism. So a config guy can help mirror browser
6:47
movements. A huge part of this is fueled by a cyber fueled economy. Um it’s 160
6:56
billion underground industry focused primarily just on trading stolen account
7:01
data and um howtos. And so on top of that, if you’re in risk
7:10
and in fraud, um you’re looking at a younger, more digitally adept uh
7:15
fraudster who is using social media in a way that’s never been before, buying
7:20
account information in the dark web. And uh to grow, you are also probably laying
7:28
on layering on payment methods that don’t have as much of a direct line to
7:32
verification. So things like crypto and other alternative payment methods, those
7:37
that use it also fall into the bucket of those that are more likely to be fraud.
7:42
Millennials, for example, have a higher uh aptitude to use digital wallets, so
7:47
stored value accounts. And so if you are on this platform or on
7:55
this webinar, I’m sorry. uh there’s probably a wave of uh fraud that you are
8:02
trying to get in front of. Here is a recent report from gambling um IQ in ter
8:08
in terms of the types of fraud that is happening in i gaming. What we’re seeing
8:12
is bonus abuse still dominates, right? But the use cases are expanding. you’re
8:17
now you’re looking at things like opposite betting, crypto fraud, money
8:22
laundering on top of the traditional uh fraud methods such as payment and
8:26
chargeback. And this is part and parcel because uh fraudsters are leveraging
8:32
these uh mechanisms to become more sophisticated and how they breach some
8:38
of your platforms. And so with that, I’m actually gonna turn it over to Alex
8:44
because he’s going to walk us through a couple of these use cases.
8:50
>> Thank you so much. Hello everybody. So, as Stephanie mentioned, she covered a
8:54
lot of ground. So Stephanie mentioned, we’ve got the democratization of data.
8:58
We have the availability of automation. We have the expanding of payment
9:02
methods. We’ve got all of these expansive new fraud methods coming and
9:06
bubbling up and and finding its way into all of our systems and the systems of
9:10
the the customers that we work with. And what’s important uh from a fraud
9:14
prevention perspective is that now more than ever fraud prevention isn’t solely
9:19
reported through chargebacks. When we talk about there’s a lot of
9:22
conversations and historically, you know, chargebacks were were a key
9:25
indicator for where fraud is for for the health of a fraud program and and how
9:31
well our fraud program is performing. But now we’re seeing more and more and
9:34
more we are seeing these different types of fraud uh permeate throughout the
9:39
industries and represent itself differently. And so to to really put
9:43
that into context, what we’ve done is we’ve selected the top three listed
9:47
methods as they’ve been reported to us by customers that we work with. And I’m
9:53
going to cover them, the three most prominent ones, why they’re successful,
9:57
what fraudsters are looking to get out of it, and why they’re being why these
10:00
fraud methods are effective. And then we’re going to move into the through
10:03
lines as to why they work, right? We’re going to cover what fraudsters are doing
10:08
and the through lines that will really define what it takes to fight these
10:12
three. So with that, Stephanie, let’s move uh into the next slide, please.
10:17
So let’s talk about promo abuse via collusion. Right. So the real world
10:23
example that was presented to us described a group of bonus abusers
10:28
working together to find different pieces different either mules who might
10:33
be uh willing to submit their information and satisfy uh satisfy the
10:38
KYC requirements up front in order to create a wide range of accounts. Right?
10:43
So they this group will get a group of identities together in order to create
10:49
valid verified accounts. Right? Now, while they do this, they’re going to
10:53
create, you know, as you see there on screen, they’re going to be creating
10:56
email addresses and phone numbers. They’re going to be used for for
10:59
conversations and KY and uh MFA checks and things like this. Whenever they go
11:05
to make the deposit, they are using a legitimate credit card, one that is
11:08
actually associated with that identity, and it’s satisfying all of the
11:12
requirements, right? It’s not a fraudulent transaction. It’s a real
11:16
legitimate transaction. They do this up to a point where they can claim the
11:20
welcome offer by depositing any minimum amount or the play that’s required. Now,
11:25
here’s where things get interesting. Across this wide range of accounts,
11:29
what’s going to happen is another method that’s listed in that graph that
11:33
Stephanie showed called opposite opposite betting, right? To ensure that
11:37
across the spread, someone somewhere is hitting the nail on the head and there’s
11:42
a profit. Once one of those accounts profits, they result they remove all
11:47
they withdraw all the uh amounts and back to the depositing account and then
11:52
split out the profit. This is an interesting case because it
11:56
highlights many many different items. For this uh example, you have fraudsters
12:02
who are abusers, we’re going to say who are satisfying the uh onboarding the
12:08
account creation phase. So they’re aware of the verification processes that are
12:12
in place. They’re aware of the requirements and they are recruiting
12:16
different people in order to satisfy those requirements and walk through the
12:19
verification process. That’s step number one. Step number two is they’re being
12:24
sure as they jump from platform to platform to platform to use new email
12:28
addresses and phone numbers in order to avoid detection. In addition to that,
12:33
they’re aware that if they do this um that the payment, the deposit uh event
12:40
is going to be heavily scrutinized and they might as well just use real credit
12:44
card information. In addition to that, they’re well aware the well aware of the
12:48
policies and the procedures that are tied to the to the promotion. And then
12:52
in addition to that, they’re going up a level and they’re looking at the entire
12:56
platform to see, okay, how can we take advantage of the situation with all of
13:00
these betting uh the opposite betting method that was described. They’re
13:04
looking at all of these individual pieces. They’re well aware of what’s
13:07
happening up front and on the back end and they’re crafting these fraud methods
13:10
in order to be successful overall. Right? And so that’s a very interesting
13:15
example. Let’s move on to the next one. for this one. Uh, another one, right?
13:23
So, we have ATO’s that lead to the use of stored value, right? So, for anybody
13:28
who’s familiar with account takeovers, it’s where somebody a bad actor gains
13:32
access to an established account. So, separate from the last example, we have
13:37
verified born good accounts who are just going about their business. A fraudster
13:43
or a bad actor, depending on how you categorize it, gets access to the
13:46
compromised login details. They log into the account and once they’re there so
13:51
many different functions and processes are available to them. What they
13:55
typically look for is what can they do with the stored value. So in this
13:59
particular example the fraudster is getting a hold of uh compromised login
14:04
credentials through some form of data breach. They’re automating a script uh
14:09
uh in a in a bot attack that is that is uh doing credential stuffing. That’s
14:15
where they take the login details and they just try to see which combinations
14:19
get them into the account. Now on the back end, they are ready to satisfy
14:23
MFAs, two-factor authentications. Um they’re prepared to to satisfy those in
14:29
different ways due to their tech setup. Right. Once they gain access to the
14:32
account, what they’ll do is they will either use the funds to play and get
14:35
their excitement out of out of the the excitement of betting or um they will
14:41
deposit additional funds, wait for them to settle and then withdraw them to
14:44
another account. Right? So that way they’re treating this this account as a
14:50
um essentially as a bank account that they can extract funds from using stored
14:54
payment information. Right? And so to break it down to its parts, we have the
14:59
login form that’s being attacked. In addition to that, we have fraudsters
15:03
being aware of the behavior of the account being required uh in order to
15:08
either play to gain to to uh get those funds into it. Maybe there’s a scrutiny
15:13
level. I mean, we’ve heard of rules that are in place where maybe maybe a deposit
15:17
of $500 is scrutinized. Maybe a deposit of $1,500 is scrutinized. And what
15:22
fraudsters will do is they will fly under the radar in order to make those
15:26
deposits, have them sit in that account and then change the contact information
15:30
and extract it later. So within that storyline, there are three or four
15:33
different touch points that are being exploited and fraudsters are paying
15:36
close attention to the verifications and the scrutiny at each.
15:41
>> And I’ll double click on um what you just said there. Uh I think what has
15:49
been interesting is you know um the concept of this rise in atto uh part of
15:59
the payment methods that we had talked about or I did my audio go I think I
16:06
might have inter okay um you know why um we were talking about the ATO part of
16:13
the the stat that we saw right was this acceleration in adoption of alternative
16:18
payment methods like crypto. And so what we’re starting to see is this increase
16:22
in digital wallets or some type of stored value even if it’s loyalty
16:26
programs um from a fraudster’s perspective that it’s still of value,
16:30
right? And so we’re seeing this increase in atto under the kind of umbrella rise
16:36
of things like the rise in crypto. And I wanted just to double click on a story
16:42
that you had mentioned around this idea about aging accounts. Um we were
16:47
speaking to one of our operators and uh in the research that they were doing
16:52
they were suspecting they were getting atto accounts and um some of the
16:56
trending analysis that was interesting was that historically it was kind of a
17:02
buy a whole bunch of stuff credential stuff move as fast as you can right um
17:06
but in this particular use case they were buying credentials and actually
17:10
letting them sit for about a year so a lot of the fraudsters are to to what we
17:16
kind of talked about in the beginning is having guides on, you know, trying to
17:22
stay in front of the trends in which they think, you know, right? And mimi
17:26
mimicking that at the kind of account level to look like a a decent behavior.
17:32
And so, you know, um some of the traditional understandings of how atto
17:37
or accounts behave are starting to change faster and faster just because
17:42
they are colluding more and more on the fraudsters perspective. So, just wanted
17:46
to take a moment to double click on that.
17:48
>> Yeah, 100%. The the collaboration that’s taking place on the the the the
17:52
fraudster marketplaces, the fraudster forums, the the bad actors are
17:56
collaborating uh to deep levels, too. They’re supporting each like you
18:00
mentioned earlier, they’re supporting people. They’re supporting each other
18:02
with compromised data. They’re supporting each other with fraud guides.
18:06
They’re supporting each other through these forums where they’re
18:09
troubleshooting the process. There was one the other day that I saw where the
18:14
um uh this is an unrelated field, but just as an example of how how robust
18:18
these conversations can be. Um somebody had just made a quick post saying, “Hey,
18:23
when I successfully atto this account, I gain access to it where where the stored
18:29
payment methods used to be available to me. Now they’re not, right?” And so they
18:34
used to they were they were going in and they were troubleshooting it and you had
18:36
fraudsters from all over the country. I believe it was we’ll I’ll assume it was
18:40
the country um from all over trying to log into the account with accounts that
18:46
they had access to compromised accounts they had access to. They were
18:49
collaborating on how what was different between accounts in order to see where
18:54
that stored payment information was and through this is this like network of
18:59
collaborative reverse engineering of whatever rules in place. So, the reason
19:04
why I bring that up and why why it really stuck with me was because when we
19:07
think about fraudsters and fraud prevention, when we think about
19:10
fraudsters troubleshooting, you know, rules or workflows that that may have
19:15
been established, what we envision is is, you know, some guy in a hoodie
19:19
sitting in the dark, you know, and and just trying a bunch of different
19:23
combinations of things. And that in itself is bad enough because a fraudster
19:27
does have access to thousands of pieces of compromised payment information,
19:32
potentially thousands of pieces of compromised account information. But
19:36
what they don’t have are new devices, new geoloc, new addresses, and so on.
19:41
Well, when they extend this out to the network, now all of these fraudsters are
19:46
seeking to to to collaborate in order to define what that
19:51
rule is in order to then write it into the guide and then to pass it out for 20
19:57
bucks because they sell these guides for like 5, 10, 20 bucks and now the entire
20:01
world knows exactly what to do against this particular platform. So, you bring
20:05
up a great point and and the conversations are just wild about how
20:10
effective it is.
20:11
>> It’s it’s just another story. You know, this is
20:16
why I love this market.
20:18
>> This is it. We’ll just go back and forth.
20:19
>> Yeah. We’ll just go back and forth on some of this the the use cases um around
20:24
that because it’s not just, you know, atto or or traditional payment fraud or
20:30
um for the eye gaming um space in going to promo abuse. There’s a story about,
20:35
you know, those that operate internationally in Africa. Um, they have
20:40
different states with different regulations or whatever. And there’s a
20:43
story about, you know, a colluding group of promo abusers who were because
20:48
there’s they’re different. they’re more siloed than they are in the EU per se
20:52
because, you know, each country within Africa. There was a particular group of
20:56
promo abuse fraudsters who were just jumping, you know, country lines and
21:01
they’re just colluding in a way that has has never been happened before. So, um I
21:06
think that that was such an interesting piece. So we we kind of went on a can
21:10
tangent but the the the concept here is that you know um the fraudsters are
21:16
becoming more sophisticated but from the operator side but it’s actually easier
21:21
for them.
21:23
>> Absolutely. Yep. Uh so yeah let’s move on to the third
21:27
use case that we can walk through. So this one is a fraud money laundering
21:34
which is going to be in its operation when when you have visibility on the
21:37
entire picture it’s a little bit different than what the world has
21:41
defined as moneyaundering in banking right those are illicit funds that have
21:44
been gained through through some illicit uh
21:48
practice but then it gets it gets cleaned and washed and laundered so that
21:52
it can be used by the people who made the money. When it comes to fraud,
21:56
there’s a there’s a subtle difference, right? When it comes to fraud, money
22:00
laundering, it’s where a fraudster has access to uh all of these different
22:05
accounts, whether it’s credit cards or banking accounts, you know, at some
22:09
credit union and some fintech, but also in an i gaming platform where they might
22:13
be housing funds that they then need to extract uh to another account and
22:18
another unrelated account in order to go spend it. So there’s that subtle
22:21
difference where in traditional money laundering the, you know, we’ll call we
22:26
we’ll assume that they’re drug dealers. They have their illicit practice and
22:29
they have all this money sitting around, but they can’t get it digitized. They
22:33
can’t get it associated anywhere. So they need to go through the
22:35
moneyaundering. When it comes to fraud related, they have all of this access to
22:39
all of these different funds and need to funnel it through somewhere where it can
22:43
then be extracted and and and essentially laundered in that way,
22:47
right? And so when it comes to moneyaundering, to me this is the
22:50
biggest the biggest the most impactful method um in the
22:57
future of I gaming and it and it boils down to a very a very simple idea when
23:02
it comes to a fraudster looking at different platforms, right? It makes
23:07
sense for them to treat an i gaming platform very similar to a bank account
23:13
because to a fraudster the ability to deposit funds, have it sit and then
23:20
extract it to a different account is just the same as depositing funds into a
23:25
credit union into a bank account into a fintech account into a crypto account
23:29
and then extract them later on. Similarly, if a fraud, just like we said
23:33
in the last example, if a fraudster gains access to an account that has
23:36
stored value, they’re just going to extract it. So, it’s very similar to a
23:41
fraudster that these are just bank accounts, right? So, so very similar.
23:45
So, the real world example that was presented to us goes like this. The
23:49
fraudster creates multiple accounts using stolen identities. Now, this can
23:53
be supplemented with mule accounts in the in the case that we were mentioning
23:57
up above with promo abuse. um you know where they’re where the fraudster is not
24:01
able to satisfy the verification at account onboarding they might get
24:06
somebody else to create a mule account for them then they have access to all of
24:10
these different accounts cool beyond that they’ll use synthetic uh data so
24:15
that’ll be like your email your phone your address these are irrelevant right
24:19
to the actual operation because there’s nothing being shipped so addresses don’t
24:23
matter they can match the information of the identity that they’re seeking to
24:27
exploit when it comes to the phone number in the email. Yes, of course,
24:30
they need to create those new email and phone numbers and uh be able to satisfy
24:35
any MFA or 2FA that they set up. Beyond that, they will ultimately deposit large
24:41
amounts. So the fraudster has access to all of these different credit cards, all
24:45
these different bank accounts, AC um you know uh linking of of accounts uh
24:51
through a we have the credit cards, we got debit cards, whatever is available,
24:56
PayPal, crypto, anything that is available to them, they’re going to
24:59
deposit these funds into the centralized account, i gaming account, the
25:03
centralized account. Now, in order to uh reduce detection or to avoid a
25:09
detection, they’re going to play some bets, right? They want to play any they
25:14
want to avoid detection. So, they want to fit in with everybody else. So,
25:17
they’re going to play a little bit of the money. They’re going to consider
25:19
that uh you know, the the the loss leader, right? So, they’re going to play
25:23
some money in order to to fit in and avoid detection and then they’re going
25:28
to start to extract their funds, right, to a different account. Now, there are
25:32
rules in place where funds might go in that that might only be able to be
25:36
withdrawn to the same account that they were deposited in, but many times that’s
25:40
not the case. And fraudsters find those platforms. Fraudsters find those those
25:44
areas, and that’s where they seek to exploit. And so, they’ll start to
25:48
extract at different um intervals. They’ll they’ll withdraw 20 bucks, then
25:52
200 bucks, then 2,000 bucks, then 20,000 bucks. They’re going to do all of these
25:57
different things. Um now for them the last point there is
26:02
that the funds appear as winnings uh for that identity which is another key
26:06
component here. If the account is made under a stolen identity, it isn’t the
26:12
fraudsters winnings that are being awarded, right?
26:17
It’s it’s that person’s identity that those winnings are being afforded to
26:21
when it comes to, you know, taxes and all of that different stuff, right? So
26:25
walking through this process, if we look at all the individual pieces, we see
26:28
that fraudsters are not only taking advantage of the account creation either
26:31
through mule accounts or through stolen identities, synthetic identities, but
26:34
they are also preparing to uh submit contact information, email, phone
26:39
number, address that is relevant to the identity that they’re using. They’re
26:43
going to do their best to deposit any amount of funds that they can uh under
26:47
flying under the radar to avoid scrutiny. They’re going to deposit all
26:51
of these funds and treat the i gaming platform like a bank account. They’re
26:54
going to be aware that account behavior and performance is going to be
26:59
scrutinized by the platform. And so they participate in the system, right? And
27:03
then they’re not worried about winning. They’re just worried about playing long
27:06
enough to then withdraw after the fact and avoid that detection. Right? And so
27:11
we’ve got five or six elements that are happening right here that fraudsters are
27:15
well aware of. And the underlying theme is they have paid attention. They have
27:19
troubleshooted. They have experimented with all of the different touch points
27:24
across the customer experience journey. They are well aware of what it takes to
27:27
fly under the radar for anything they’re not aware of. They’re sourcing their
27:31
entire network in order to identify where these thresholds might be for to
27:34
to avoid detection. And they’re collaborating heavily. The end of the
27:38
story is they are well aware at a transaction level and at an account
27:43
level what needs to happen in order for them to avoid detection. So with that,
27:47
we’ve covered all three of the primary use cases. Steph, if you would, let’s go
27:51
to the next slide. The point here, the thing that brings
27:55
all three of these elaborate methods together is that fraudsters are
28:00
creatures of habit. They operate quickly, and when they find something
28:05
that works, they’re going to duplicate it as much as possible. So for each of
28:10
those examples, if they were able to do it once, it’s only a matter of time
28:14
before they copy and paste, copy and paste, copy and paste, and do as much as
28:18
they can for as long as they can uh to extract the value that they’re looking
28:22
for. Next slide, please. In order to be successful, fraudsters
28:28
are are relying on the gaps, right? So which gaps exist, right? So one common
28:33
item is that uh fraud programs when they start up, they are heavily siloed. We
28:38
have account creation that’s being managed by the IT team. We have payments
28:41
that’s managed uh that’s where fraudsters or fraud prevention teams
28:45
typically have all of their firepower aimed at the in this case deposits,
28:49
right? Then we have maybe the accounting team is is in charge of monitoring
28:53
withdrawals. We’ve got promotions and all of that being handled by a different
28:56
team. Customer service might be uh involved in in satisfying whatever needs
29:02
for the promotion abuse. We’ve got all of these segments, right? And within
29:06
each of those segments, we have the segment and data. So the data of each
29:11
individual silo is is housed separately. There’s no overlap. There’s plenty of
29:17
over operational overlap, but there’s not enough of um I should say there’s
29:23
plenty of overlap when it comes to, you know, the use of an email, the use of a
29:28
phone number. Yes, that persists the journey. But when it comes to actual
29:31
data monitoring and putting our eyes down on use cases and trends, that’s
29:35
where those silos are coming into effect and it’s only working to the fraudster’s
29:40
advantage. Right.
29:41
>> I wanted to to send a comment there actually and pause you if that’s you
29:46
know um you we we spent a bit of time kind of walking through the
29:50
complications of a of a use of those three use cases. Those are use cases
29:55
that were brought to us. Sometimes we hear things and like I have promo abuse
29:59
and then you know you crack open this box and it’s this intricate thing that
30:03
is happening at the multi-layers and multi-steps and uh what Alex had talked
30:09
about was this concept that you know um they’re on a foster side right it’s low
30:17
lift they’re spraying and praying in some in some ways and they’re able to do
30:21
so and get through because there are gaps and so um I just wanted to talk
30:25
about the prevalence of that. I was at a on a a panel last year um and with me
30:33
alongside me was an operator, an ID verification vendor, uh a PSP and in the
30:40
audience were operators and the through line in the conversation about how is it
30:44
that you can really drive growth, right? um despite kind of this comp
30:50
complication um is is a a key gap that is in fact operational. A lot of it uh
30:59
even when it comes to innovation, you look at biometrics, you look at kind of
31:03
the fancy smashy stuff. But you know when we ask the question um to some of
31:08
the operators like how often do your payment teams and your fraud teams and
31:14
your customer teams and your market teams collaborate, right? Because at
31:18
each point of the player journey, like Alex said, there are departments that
31:22
sit on top of that. Um and what what I think is hard when things are moving
31:27
fast especially in i gaming is simply that um how do you collaborate to
31:33
understand the user when each department has a different piece of information on
31:39
that user
31:40
>> and the all three use cases that you talked about right um actually starts at
31:46
account creation and moves across the customer journey and so there are fraud
31:51
activity behaviors that could be assessed in terms of risk
31:55
that is happening um that isn’t cohesive. And that boils down to not
32:00
even innovation to data gaps that are happening operationally because you know
32:04
some of the best practices that the operator said they wanted to instill is
32:08
things like weekly touch points, right? Sharing information on trends. A payment
32:12
team might see a trend um a customer service might see a trend um about the
32:18
same user. And so while you know operating especially the larger ones may
32:24
not have this cohesion of the collaboration of the Tik Toks you know
32:27
hey this is happening FYI the fraudsters are so I just wanted to take a moment
32:33
and and really kind of you know talk about the prevalence of of of this
32:38
challenge all about the data right
32:41
>> all great points Stephanie yes uh so with that let’s move into the next
32:48
slide So fraudsters rely on gaps which leads
32:52
to this point when it comes to fraudsters. They have proven through all
32:59
of these different items through all of their history. They’ve proven that they
33:02
have uh that they are in fact very successful at exploiting our all of our
33:08
platforms on two different levels. the transaction level. As I’ve mentioned
33:13
several times here, they have grown to be very capable of taking advantage of
33:18
the account creation, the login, the payment, the policies, the promo abuse,
33:24
the customer service through social engineering. They’ve proven that on a on
33:28
a touchbytouch basis, event byevent basis, they have become very uh capable
33:35
of exploiting that. Now we in during this webinar this is where we’re
33:39
introducing a new framework right so we have the transaction level and the
33:42
reason why we call it a transaction is because we need to look at this through
33:45
the lens of a fraudster when a fraudster gets a hold of login details they are
33:50
taking this valuable item and they are transacting with your login form to gain
33:56
access to the account it’s an exchange no matter how you look at it it’s an
33:59
exchange the fraudster gives us login details and we give them access to an
34:04
account and when we look at it through the lens of a fraudster, you’re going to
34:08
start to see all of the opportunities in which a fraudster can transact. And I
34:13
just went through them. So, account creation, login, deposits, withdrawals,
34:17
playing the bets, social engineering at customer service, think about
34:21
chargebacks, think about promo abuse. Every single one of those is an
34:25
interaction and exchange of value, right? But what fraudsters have also
34:29
done is they’ve moved up a level. They’ve moved into, well, we’re aware
34:33
that we need our account to look like other accounts so that we can fly under
34:38
the radar and remain undetected. And you can see this in the fraud guides that
34:42
exist. You can see this whenever fraudsters are talking about, you know,
34:45
making small bets uh in order to make small deposits, bigger deposits, bigger
34:50
deposits over time. They’re trying to gain that trust. They want to fly under
34:54
the radar as best as possible to to avoid detection. So the point that I
34:59
make here is fraudsters live at these two levels, the
35:03
transaction level, the account level. And unfortunately, they’re doing a
35:07
really good job. And that puts pressure on us as fraud prevention uh managers
35:12
and and vendors and and all of us. It puts a tremendous amount of pressure on
35:16
us. And for that, I’m going to pass it back to Steph to hop into.
35:21
>> Thank you. You know, we talked a lot about fraud um and um prevention, right?
35:28
The two key words here. Uh and it’s complicated, but the impact really is
35:34
the opposite. But what fraud is, right? The flip side is the ability to drive
35:43
growth. And the title of the road map was
35:47
smarter risk assessments to drive growth, right? And what’s happening is
35:52
that when gaps exist, what we see from an operator’s perspective either, you
35:58
know, in the departments that help drive this, whether it’s payment or if it’s,
36:02
you know, customer service or affiliates or, you know, is that they you you
36:07
typically have tool sets that are blunt force and they’re usually at the most
36:13
impactful points of the customer journey. account creation, we think
36:16
about proabuse, how do I stop them from, you know, abusing my how do I stop them
36:21
at the front door? And then at kind of a very high emotional state with this
36:25
deposit and withdrawal, right? Um, and I’m talking about across all those use
36:30
cases. And the truth is, especially in eye gaming, um, those that quote unquote
36:36
commit things like promo abuse, you may not actually want to stop them at the
36:41
the front door, right? The idea about fraud prevention is actually to maximize
36:46
the margins into who you can allow into your platform. And what’s happening is
36:50
when fraudsters are able to exploit these gaps and collaborate across the
36:56
entire player journey while operators only have levers usually at the front
37:01
and the back end. What we’re seeing is you’re either blocking too early, you’re
37:05
blocking too late, or worse of all inaccurately. Right? And um these use
37:11
cases come to us quite frequently because of all the markets i gaming is
37:17
perhaps some of the highest growth and h the highest competitive and so there is
37:22
a greater tolerance that I find for those to accept risk right because
37:27
you’re trying to open uh your platform and not let them jump. So there’s a
37:32
greater appetite for risk loss. And so going all the way to the front around
37:36
the cost of fraud for a player acquisition can be as up as high as 50%.
37:42
You know, we see stats out there that fraud in general hits 10% of revenue in
37:47
totality, right? And this is entire operator um revenue. And it’s mainly
37:54
because as a fraud riskrevention um department, you know, every play call
38:02
that you make to allow someone to come in or come out or or not allow is a risk
38:06
that you’re taking that you’re either blocking too early, too late, or
38:09
inaccurately. And so this is of all the the like boiling it down to why it
38:14
matters is this impact. And so um here comes the crux of the question right for
38:23
us it’s the fork in the road it’s a pivot it’s a shift it’s an evolution
38:27
from fraud prevention to really growth um in this environment of increasing
38:33
complexity more collaborative fraudsters people who use Tik Tok to pass your to
38:39
gain your minimum threshold trends right how is it that you can give players a
38:44
chance right isn’t that isn’t that the goal Even if you have someone that
38:48
you’re suspecting is um taking advantage of your promos, you may not want to stop
38:55
them at the front door. There might be pressure from the revenue side that hey,
38:59
so and so is grading more players. We have to have an acquisition, you know,
39:03
benchmark that we have to hit. Um and on the flip side, you know, you may be
39:08
getting pressure because there might be um a whole bunch of revenue loss. And so
39:12
it’s a tough spot to be and when risk and operators come to us promo abuse and
39:17
then you unpack it. It’s this what Alex walked through. This is a truncated
39:21
version of use cases that come to us. It’s it’s more and more complex. So I
39:26
feel for for those in your place and so this is where we sit right every
39:33
time you have a problem. It’s like oh I wish I could do this. Oh if only I could
39:37
do that. And so when we think about how do we give players a chance, we always
39:43
hear about how how how can I better understand my players more
39:50
intricately so that I can trust them, right? To give them a chance. What if
39:55
you knew every possible connected attribute the moment they hit your
40:00
platform? Meaning if you know in a second every single way that one user is
40:06
connected to the other would you have the ability to move faster? What if you
40:11
knew the exact moment every single action and the sum of those actions
40:17
didn’t match normal platform um normal patterns right and on top of that this
40:24
is what I kind of call the impossible questions. What if you knew if they had
40:28
a long history of risky behavior outside of your platform, specifically in which
40:35
industries, when and where? And what if you knew what risk teams with your
40:41
expertise in your industry and in others have assessed that behavior that that
40:47
particular player that just hit your platform or is making a sketchy, you
40:52
know, transaction um has assessed and exactly why, right? These are the h I
40:58
wish I could. And so for us when we talk about better play risk assessments, it’s
41:05
not single point signals, right? It’s not single point rules. It’s this
41:09
comprehensive understanding of who that user may be that you cannot see. I think
41:15
part of the things that this ongoing theme is really just about fragmented
41:20
user insights that are because of operator silos, platform silos. Well, on
41:25
the flip side, the fraudsters are not right. they understand your
41:31
um guard rails probably better than some other your departments in your teams.
41:36
How do you give operators that same advantage point? And this is where we
41:42
think about risk assessments because trust is at the core of fraud
41:47
prevention. Fraud prevention again we think about it gatekeeping and
41:50
eyegaming. It’s the o it’s the opposite intention of fraudster that of a fraud
41:57
prevention that you’re really trying to drive right is growth. And to drive
42:02
growth you have to have confidence in the data that you’re seeing that you can
42:06
allow players to move through your platform to the point where they cannot
42:11
be not before they do or you know at the point in which it’s too late. For us
42:18
trust is based on confidence. Confidence is based on context and context is based
42:24
on access to insight. And this is where I think the evolution
42:30
of risk assessments are and the impact of that is quite powerful. In all the
42:36
use cases that Alex had walked through, we talked about transaction level
42:41
behavior, account level behavior, right? This is where fraudsters sit. This is
42:44
where they spend the most of their time mimicking, right? What players may be
42:49
like. We’re not talking about lowhanging fruit, the ones that you know the same
42:52
use the same email a thousand time, right? We’re talking about more complex
42:57
use cases that are trending across i gaming. And this is where insight has
43:03
already been challenging for operators to get into.
43:08
What I’d like to introduce to you today is two new layers.
43:13
Platformwide behaviors and networkwide behaviors. This is where things like AI
43:19
is really taking off for fraud prevention. You have so much data that
43:24
is sitting in so many places and we still see examples of VLOOKUPs and Excel
43:30
sheets and or if you have a really robust data science team and have the
43:34
funds to create your own AI solution, you may try and understand the nuance
43:39
behaviors at the transaction level, at the account level and how that compares
43:44
to the platform level. What I mean by platform level is how do these accounts,
43:50
how are their behaviors slightly nuanced from quote unquote good
43:56
players across the customer journey compared to your entire platform? And
44:02
then on top of that, how is that sorry different across the globe? Right?
44:10
You’re trying to get the full context of a player the moment they hit your
44:16
platform and as they move across it so that you don’t have to blunt force
44:21
trauma at the beginning, you know, or stop a withdrawal when emotions are
44:25
high. You have more confidence because you have more detailed insights across
44:29
the customer journey and on different levels. And so this is where SIFT has
44:34
really taken off. I said in the beginning I briefed over it but you know
44:38
um 90% of the operators in the US um the US market and fast growing in places
44:45
like AMIA uh rely on CIFT because we have such deep insights using AI across
44:52
that entire digital journey taking it up to the platform level. So what does that
44:57
mean? Um, when we talk about promo abuse,
45:02
right, we talked about collusion. Um, a key part of promo abuse is also
45:06
multi-account creation. It’s still incredibly prevalent because they’re
45:11
using nuance changes in the account information using things like um, Alex
45:16
said about KYC’s to bypass some of your um, things like synthetic IDs. They’re
45:23
very creative. They’re passing your front door. When we talk about
45:28
platformwide insights for risk assessments, we’re talking about if you
45:33
could, if only I could in a single instance see for the very first time,
45:38
every time they hit your platform, every single way that particular player may be
45:45
connected to others on your platform and in a single instant, triple click to
45:50
block all of them or to review them or put them into a queue. you know, speed,
45:55
scale, especially for eye gaming is incredibly important. The amount of
46:00
manual resources or manual reviews that you may have to do, the the size of your
46:05
risk teams, right, is a cost that may be not completely attributed to it, but is
46:10
something that is held to the budget. This is what we mean by risk assessments
46:15
in terms of platformwide behaviors and that level of insight in an instance.
46:21
What if I understood every single way a person is connected instantly? And this
46:26
is what CIFT delivers. On top of that, um we have one of the
46:32
most robust and diverse global networks. It is um not in your favor to think that
46:41
a fraudster will only operate on your industry, right? There isn’t and there
46:46
is a there are fraud guides for eye gaming but these fraudsters are
46:51
opportunistic. They are using the same methodologies
46:55
across different industries and we are tapped into those industries at a global
46:59
scale. We look at one trillion events annually every across all different
47:07
segments including I gaming to understand the behaviors and trends that
47:13
is happening and to heat map in a sense where those fraud criminal networks are
47:19
in the EU. In uh in in the beginning I said you know there was a what was it
47:24
821 criminal networks just in the EU alone.
47:28
They are tapping into each other and SIFT is tapping into that. What does
47:35
that mean from a risk assessment perspective? This is the the the fourth
47:40
layer network wide behaviors.
47:44
In the instance above, I talked about kind of the uh uh unanswerable questions
47:51
of what if I knew if this player that just hit my platform has been assessed
47:58
by others with my same expertise in a different industry
48:02
based on their behavior that they may be of high risk. What if I knew that?
48:10
This is the third part or the fourth part, I’m sorry, of what we mean by risk
48:14
assessments in context. In an instant, you can see if that person that signed
48:21
up for your platform using an email, verified payment
48:26
address, this is a legit legit person, verified person, doesn’t mean that they
48:31
aren’t high- risk just because they are a real person, right?
48:36
In an instant, you can see across industries if they’ve been blocked
48:40
anywhere else. In i gaming, you can filter by and in other retail
48:45
industries. When we talk about context and identity story, it’s who they are at
48:53
every interaction. Who they are at the account level, who they are in context
48:59
to others on your platform, and who they are across industries in which is not
49:05
your own. And we believe that it is only with this full breath of context can you
49:13
really root into the confidence to give players a chance.
49:18
And Alex, as someone who is completely tapped in and has spent 17 years, you
49:24
know, kind of looking at this, um, I wonder what your thoughts are in terms
49:29
of the level insights because you spent a lot of time on the transaction and the
49:33
account level.
49:34
>> Yeah. So when it comes to this entire framework really what if I was to
49:39
simplify it down to anything it’s the story of the data right when we talk
49:42
about what what many what many fraud programs and many other fraud vendors
49:50
tend to do is they tend to bubble up a yes or a no. Is this person is this this
49:56
account something that should be trusted? Is this transaction something
49:59
that should be trusted? And it’s a yes no. It’s very binary. It’s very dry.
50:03
Right? Fraudsters are taking advantage of that. Fraudsters understand that as
50:08
long as they submit the right information and they act the right way,
50:11
they put on the right show, they’re going to be able to satisfy those types
50:16
of determinations, right? And they’re seeing that across,
50:19
you know, uh operator, especially against operators who are operating, you
50:23
know, independently without support from a third from third party data or
50:27
technology. Um they’re seeing it firsthand, right? And so frauders are
50:31
taking advantage of all of this. what we’ve created here at SIFT is the
50:35
ability to see the story of the data, right? And so to to to Steph’s point,
50:41
actually Steph, you made several really great points. Number one, let’s just
50:44
start from the beginning. Fraudsters are not they don’t have access to they might
50:48
have access to 10,000 different pieces of information. They don’t have 10,000
50:52
different devices. They might have 10,000 different pieces of identity
50:56
information, but they don’t have 10,000 different geographies that they’re
50:58
operating out of like geoloccated, you know, IP, however you you you might
51:03
resolve it down and how accurate it might be. They don’t have 10,000
51:06
different pieces, right? And and the third point, they’re not just sticking
51:10
to one method. The fourth point, they’re not sticking to one industry, right? So,
51:15
a fraudster doing or bad actor doing bad things is going to jump from industry to
51:21
industry. They’re going to be jumping from use case to use case. They’re going
51:24
to be using payment information and identity information, new email
51:27
addresses, new phone numbers, but their behaviors are going to be the same
51:32
because they’re going to find something that works. They’re going to copy and
51:35
paste it when they move to the next platform. That’s number one. Number two,
51:39
when it comes to the the the place that they’re operating from, the devices that
51:43
they’re using, geoloccation, IP address, whatever it might be, those elements
51:47
aren’t going to change as much as the information. And so imagine if you had
51:52
access to an umbrella scope of the world and this
51:58
one user comes to create an account and you can see how that user’s information
52:04
has been reported on across the globe right across all the industries or
52:10
industries that you pick right we do know that there are users that jump from
52:13
from i gaming to i gaming platform we know it’s a highly competitive market we
52:17
appreciate that so if you wanted to zero down and just see that we can zero it
52:21
down. We can see all of this information that is going to give you the story and
52:26
the context which will provide insight which will provide you uh what you need
52:30
the resources you need to make accurate determinations accurate decisions and
52:35
that’s going to strike the balance between customer satisfaction and fraud
52:39
prevention for your platform.
52:43
>> Thank you. And I think what you say always sticks with me is spray and prey,
52:48
right? The fact that they’re getting away with things like spray and praise
52:51
because they’re not operating at the platform and network level. And for i
52:55
gaming, what I think about is, you know, this may be in some ways the use cases
53:00
are overwhelming, but the this amount of data might be a little overwhelming. So,
53:06
what I wanted to do is kind of root it back to what as a fraud and risk team or
53:13
growth team, what you’re really looking at is taking this data but simplifying
53:18
it in a way to cut out
53:24
more quickly the most obvious folks that have a higher prediction of
53:30
illegitimate behavior, right? Maybe not to the point where you really want to be
53:36
so nuanced. You’re you’re assessing every single player. No, it’s really
53:40
about they are getting through these gaps in volume, right? And these this
53:46
they’re lowhanging fruit, but you can’t see it, right? And so this is where we
53:51
talk about um giving the ability to have the confidence to grow because you can
53:56
take a bigger hack at that lowhanging fruit that is getting through the gaps.
53:59
And so what you see here is from a SIF perspective,
54:04
you know, there’s a lot of data that we provide across the customer journey
54:06
site, but there’s a risk assessment score. There are instances in which that
54:10
risk assessment might be yellow, right? Neutral. Um, how do you understand where
54:15
to put this user? What if a single instance you could add on top of that
54:21
that that person has had a long history? Even if they’re a verified user, doesn’t
54:26
mean that they won’t drain your funds, right? um what if they have had a long
54:30
history across your industry and others um that has been um draining other
54:36
people’s funds. What if you knew that in an instant you would be able to make a
54:41
better play call more confidently, more quickly um across scale? And that’s what
54:46
we mean about giving you all this data but really trying to simplify it for
54:50
your broad and risk teams to understand who to let through the door more often
54:56
than others. It’s skimming off the lowhanging fruit that you couldn’t see.
55:01
And so when we think about a road map to risk assessments and we think about a
55:06
framework, what we think about is really trust identity trust, right? It’s built
55:11
in context layer with unprecedental
55:16
uh unprecedented insights at multiple layers. And the idea is really taking a
55:23
fragmented user insight and giving them a more robust so story so that you can
55:30
more quickly make a risk assessment, a play call to either let them at the door
55:35
and then more specifically kn know at a very specific moment where in that
55:40
player journey to to to add friction. So not at the front door or at the back
55:46
door, just more confidence because you have a better understanding of how they
55:51
are moving across your platform at the transaction level, at the account level,
55:56
at the platform level, and at the network level to be like right there,
56:00
you know, five wagers with one withdrawal in the last two days, you
56:04
know, or whatever that combination of deep behavior insights are so that you
56:10
can make that play call to trust more easily. So, we covered a lot and uh I
56:18
wanted to kind of bring it back for those that actually stayed on. Uh I
56:23
appreciate that. The TLDDR. Okay. Uh becoming a fraudster has just become
56:30
easier. There are folks that are my age who are using digital uh guides and Tik
56:36
Tok and social media to swarm. They are swarming your gaps and they are moving
56:42
faster than you can catch them, right? Because they’re exploiting those gaps.
56:46
And part of that is because even if it’s lowhanging fruit for them, you can’t see
56:51
it because you are typically sitting at different pieces, risk signals,
56:55
individual risk signals to make these play calls. And so it’s either kind of
57:02
letting promo abuse fly, right? or kind of maybe flagging your a potential VIP
57:09
user too late or too early and it’s stifling growth. So for us when we think
57:14
about a risk assessment we think about not a single risk signal but the
57:20
identity story behind that player with multiple dimensional multi-dimensional
57:25
insight and the goal is not to make it more complicated. The goal is actually
57:29
for you to get the lowest hanging fruit easier with instant context so that you
57:36
as a fraud and risk team have more confidence to make a play call to say,
57:41
“Hey, you know, this player might look a little risky. I’m not sure.” I feel
57:48
confident to let them move through the platform a little bit more because I
57:52
have more insight and the ability to stop them right when they are risk
57:58
they’re having a higher risk threshold um than just at the front door. And so
58:04
um I wanted to thank you again. We went a
58:11
little fast. we covered a lot um and showed a little bit about the innovation
58:15
behind the story that we’re telling. Um the TLDDR is we are here um to change
58:23
how risk assessments are looked at, how players are looked at so that you can
58:28
give players a chance with better context. Um
58:33
if you would like to chat with us, um please give us a call. If you would like
58:36
to see any of the innovation that we showed, we would be happy to spend a few
58:41
minutes with you and walking through your particular use case or if you just
58:44
have questions, the ones the three that Alex had walked us through um were just
58:49
examples, you can bring that to us and we’ll give you our two cents on that.
58:53
And so with that, we are at time and I wanted to thank Alex for joining us.
58:58
Alex, California, so it’s early for us. So, we
59:03
thank you for hanging in with us here. We hope you have a great week.
59:09
>> Have a good one, everybody.