Fraud in digital commerce is a systemic challenge reshaping how businesses operate online. From synthetic identities engineered with AI to bot-driven abuse at scale, attackers exploit weaknesses faster than enterprises can redesign defenses. The result is a continuous erosion of trust that threatens the foundation of digital marketplaces.
Technology has reached a point where prevention must be as dynamic as the threat itself. Modern Fraud Reduction Intelligence Platforms (FRIP) aggregate behavioral analytics, device and credential intelligence, biometrics and bot detection into adaptive ecosystems. The question is no longer whether to deploy these tools, but which approaches deliver real impact and which simply add noise.
John Tolbert, Director of Cybersecurity Research at KuppingerCole Analysts, will present the findings of the 2025 Leadership Compass on FRIP for eCommerce. He will analyze the failures of traditional defenses, highlight key innovation and provide an unfiltered comparison of vendors across leadership categories. His presentation will challenge assumptions and uncover the realities behind marketing claims.
Who Should Attend:
IT security leaders, fraud prevention specialists, eCommerce platform owners, digital risk managers and solution architects.
Good morning, good afternoon. Welcome to the webinar today. I'm John Tolbert, Director of Cybersecurity Research at KuppingerCole, and today I want to talk about fraud reduction intelligence platforms. Recently released a leadership compass on that subject, particularly on the field of eCommerce and how to prevent fraud there.
So, a little bit of logistics info before we begin. Everybody's muted, so there's no need to mute or unmute yourself. I've got a couple of poll questions I'd like for you to answer, and then we will discuss the results during the Q&A period, which there will be a Q&A period at the end, and you can enter your questions anytime you like in the Livestorm control panel. And then lastly, this is being recorded, so both the recording and the slides will be available in a few days.
So, we're going to start off talking about the fraud landscape, talk about the different kinds of fraud that we see, how to prevent that fraud, and then we will go through the leadership compass methodology and results. So, you may have been with me a few weeks ago.
I some of the numbers that we see here are quite staggering, over $3 trillion worth of illicit fund movement, according to the NASDAQ report, which includes not only the fraud that we're going to talk about, but things like terrorist financing, money laundering, organized crime, but you can see it's just an absurd sum of money, more than $100 billion of which was direct fraud loss, and $58 billion was lost through money mules.
On the other side, we see, of course, statistics that show different kinds of fraud are going up, but I thought the one that was most interesting here in the middle was, I think there's a perception that older people tend to be more at risk for fraud, and while older people certainly tend to lose more money, younger people seem to be targeted and may be more susceptible in some ways to different kinds of fraud tactics. And here are some numbers from the U.S. FBI.
You can see investment fraud of different kinds has really grown significantly than lots of the others we have seen before over the years. Business email compromise, unfortunately, is a huge business. Fake tech support fraud, still a huge problem. Identity theft coming in there at $174 million. So certainly we see things like cryptocurrency fraud has been persistently growing over the last few years, including pig butchering, which is a terrible name, but it's a terrible crime, too, and we'll talk a bit more about that in a few minutes.
On the good side, though, things like PSD2 in the EU have helped out with strong customer authentication that's helped reduce certain kinds of fraud, but there's still the problem of authorized push payment fraud, where the fraudster tries to trick the intended victim into going ahead and authorizing a payment of some kind or another. So it takes different countermeasures to be able to help prevent things like authorized push payment fraud. So let's dive down a little bit on the different types of fraud, the main types that we see out here in the world.
We're all probably pretty familiar with account takeover fraud, ATO fraud. The goal there is to at least get temporary access to a real person's existing accounts. These can be used for, you know, anything of value. Commonly we think of things like attacking someone's bank account or credit card or any other financial institution because that's where the money is, but the truth is all industries are targeted. Anything that can be converted into currency in one way or another is going to be attacked.
So loyalty programs, which we'll also talk a little bit more about later, are heavily targeted here because think about how much money is represented by different kinds of loyalty programs, frequent flyer, you know, other traveler programs, hotel rewards programs. There's a lot of potential money that's locked behind those loyalty programs and the fraudsters want to get access to it. So the cases of ATO, they may compromise an account, they may sit on it for months before it's used, they may harvest it and put it on the dark web and try to sell access to those accounts.
So we've seen sort of a development of an ecosystem of fraudsters specializing their labor, you know, some will go after the accounts and then others will come and buy access to those accounts and then fraudulently use that. Then we have account opening fraud or new account fraud. There's a couple of twists on this. Synthetic identity fraud is a type of new account fraud or account opening fraud as well, but the goal with, you know, traditional account opening fraud is to create a fake account based on some real person's information. Why would they do that?
Well, to be able to commit major financial fraud. They might take out a line of credit, you know, try to take out a mortgage or a loan or something. So of course the amount of money involved there can be quite high. This is also a technique that they use to create new accounts. Synthetic fraud is a little bit different. It's not necessarily trying to create an account that mirrors another real person exactly, but here they're trying to create an account that looks real enough to be able to get credit, get a credit card, open an account at a bank or something.
So they may do things like use fake photos. I created these on thispersondoesnotexist.com. And then they'll use other techniques to generate information that looks real enough to hopefully in their view, be able to create an account. And they do the same thing.
I mean, for the same reason, it's, you know, about trying to commit some kind of financial fraud. It might be as simple as like targeting an online retailer or let's say a hardware store, get a credit account and they may, you know, buy things and pay them off because you probably get a small credit limit to start. So they farm these accounts, they grow them until they reach a sufficient size, then they will put a big charge on there and walk away.
And again, all kinds of industries are targeted here. It's not just finance for synthetic fraud. So let's look at the perpetration methods for ATO. The tactics they use are things like phishing, vishing and smishing. We all still see all of these different vectors in use today, voice calls, SMS texts. And they're getting craftier because the fraudsters are using generative AI.
But, you know, some old school methods still work pretty well too. Brute force password guessing, using those compromised credentials that are found on the dark web. They can use those credential stuffing attacks where they might use a bot, more about bots later. But they'll take compromised credentials, hoping that users have reused passwords between sites. So they'll use a username password combination that is known to have been breached and then spray that around a bunch of different sites and see where they can get in with it. They might try to redirect their user to a fake website.
The fake website might be simply designed to harvest credential information or it might, you know, put malware on their device because malware still works really well. Unfortunately, info stealers are, you know, a leading form of malware that's seen today. So these are things we have to keep in mind as perpetration methods for ATOs. Then for account opening, they're looking for information on a real user. So you may wonder why we hear about things like schools getting their records breached or healthcare providers.
Well, there's a wealth of information in those files that could enable a fraudster to build an account that looks just like a real person. So any of these different sources could provide name, address, prior addresses, because sometimes that's used in know your customer sorts of interactions. Lots of information from these different sources can be used to sort of corroborate or correlate and create an account that mirrors a real person. Synthetic identity fraud information sources. I already showed you this person does not exist. So there are other AI image generators.
There are tools for creating deep fakes for audio, video, generative AI can be used for, you know, coming up with information that can be used to fill in the blanks that looks plausible. You know, really sophisticated fraud operators will even have either mobile farms of mobile devices or virtual phone emulators, because you know, you have to up with some secondary contact information. So in order to be able to retrieve those OTPs, phone emulators or farms, mobile devices can be used for that. Credit card fraud.
This is still a big problem across e-commerce, finance, anywhere that accepts a credit card. Card not present is just what it sounds like using a credit card, let's say in an online transaction. So this is very relevant for the e-commerce industry.
You know, we enter the three or four digit codes, but it's usually not sufficient and there needs to be something like a fraud reduction intelligence platform behind it to provide additional information to help determine the risk at transaction time. There are card not received, stolen cards, physically stolen cards, counterfeit cards, skimmers are still a problem, you know, at some point of sale terminals or, you know, anywhere that a fraudster can physically put a device on there that can capture card information. Now there's also ghost tapping.
You know, you may have somebody pretending or to represent a charity or something running around getting people to tap their card, you know, in the name of contributing money to a good cause, but they're a fraudster and they're just trying to steal money from the card. So lots of nefarious tactics can involve credit card. I mentioned scams before and pig butchering at the top here.
Again, it's a terrible name, but just a quick overview on how that works and to show how many of these methods are combined into a campaign really where it may start off with something that seems like an innocuous text message. It might not even really be intended for the person that receives it, but they're hoping for the goodwill of the recipient that might reply. And in that case, even if it's not to, you know, say the name of the person, they will try to strike up a friendship over text. And this can lead to long-term grooming where, you know, this may take many months.
They're trying to build confidence in the intended victim. And eventually they will mention something like, I know about this really good crypto investment and, you know, I've made a lot of money with it. I'd like to share this information with you in the hopes, again, that the person will go to that site. And some of these sites look very legit. They may even require multi-factor authentication. So it could look very legitimate to the intended victim. So let's say they go ahead and put some money in, then come back to the portal and check it later. And they'll see that they've made money.
Of course, they haven't really made any money, but it looks like they have. And the idea is to get them to go all in and put in everything that they possibly can. And unfortunately, many, many people have lost, you know, their entire life savings this way. So obviously there are many different methods, many different techniques that are involved in trying to build up that level of confidence in a person to do that. And you can see that it's going to take multiple technological solutions to be able to help prevent that.
But, you know, I mentioned charity scams, business email compromise, already fake delivery calls, bank transfer scams. These are still quite prevalent. Unfortunately, banks today will provide information to users saying, look, we're never going to call you and ask you for your account number. We're not going to tell you that your account is unsafe and you need to transfer your money to a different account. These are techniques that fraudsters use, and it's still quite pervasive out there.
And again, many more different kinds of scams. Didn't have room for everything on the first page, but you can see that there are lots of different ways in which fraudsters use fake things like fake invoices.
I mean, this too is a problem in businesses where, you know, a fraudster will send an invoice to a business hoping that they will get paid, fake government welfare signup forms. This was a real problem during the pandemic, and still a problem today. Lots of fake notices from utilities or medical providers threatening, you know, service cutoff if you don't pay the bills, travel deals, vacation rental scams, event ticket scams. There's just lots of, if there's a legitimate business, there's an illegitimate business that can be run in parallel.
So, bot-driven fraud. This is something that definitely plagues e-commerce operations. I mentioned credential stuffing already, but there are lots of different kinds of bots that e-commerce vendors have to worry about. Everything from competitive price checking bots, which, you know, are not necessarily a bad thing.
You know, if you're running an e-commerce business, you might do this yourself, but you don't want to allow your site to become overwhelmed by competitive price checking bots or inventory hoarding. It may be, you know, jingle bots, you know, add to the cart and then abandon.
So, it like temporarily takes away from your inventory or, you know, some resellers will actually go out and try to find deals, buy lots of a product and then offer it for resale on another site. Ticket purchase, ticket scalping bots, gift card cracking, lots of bots out there that are just trying to guess numbers and pins for gift cards.
So, you can see that there are just many, many different kinds of bots that can be problematic for e-commerce vendors. But again, not all bots are bad. A lot of the business that gets done on the web gets handled through bots. And now we will be adding to that, talking about AI agents as well.
So, there needs to be discernment between what's a good bot and a bad bot and those that are kind of in a gray area. And I'll talk about that more in just a minute. E-commerce vendors also have to be concerned about policy abuse. And here I mentioned loyalty programs already.
You know, loyalty programs, many of these airlines, for example, have billions of dollars locked up in their frequent flyer miles programs. So, naturally they become a target. But then there are also things like fake reviews and fake comments. These two can be perpetrated by bots, but, you know, at the root of it, they're probably violating your website's policy. And fake reviews can kind of go in both directions.
You know, they can sort of artificially inflate the value or perceived value of a product, or they can be used to make something look bad and redirect to another vendor. Fake job postings, fake goods, fake goods on auction sites, you know, many of the auction sites do a really good job of trying to prevent the appearance of these things on their sites. And largely that's in part to things like fraud reduction intelligence platforms helping to determine what's real and what's not. Returns and chargebacks are a problem. And this might not even be organized fraudsters behind that.
You know, individuals might buy lots of things, claim that they didn't get them, and then try to get a refund for that. There are misdirected shipments, promotions and coupons, trying to reuse coupon codes or find coupon codes that aren't necessarily relevant and use those anyway. So you can see there's a lot of different kinds of policy abuse that e-commerce site operators need to be aware of and prevent. And in many cases, these are quite different than what the financial industry needs to worry about.
Of course, they don't want to be bothered by bots needlessly too, but the types of actions that they take are quite different. And I think that's why we see fraud reduction intel platforms that sometimes specialize in finance versus e-commerce. There are some that cover a wide variety of industries. So I mentioned that AI is helping fraudsters with things like phishing text, and you've seen examples of image generation. You can also feed an LLM a certain amount of PII and get some plausible PII back to use to fill in the rest of the blanks.
For some cases where they're looking for a higher level of identity assurance, they might use LLMs to create fake utility bills or bank statements. Sometimes those are needed as part of the know your customer process. So if you could have an LLM create that for you, I'm sure that helps the fraudsters. So now that I've described some of the major types of fraud, I thought it would be interesting to see what you say is the main type of fraud your business is concerned about, particularly with the e-commerce spin on it here. Is it account takeover? Is it new account fraud? Credit card fraud?
Some of those bot-driven attacks we've talked about? Or policy abuse? And that will pop up there, and feel free to enter your response, and we will talk about it in a little bit. So let's move on to the better side of things. How do we prevent fraud? First of all, a little background on what we call FRIP, Fraud Reduction Intelligence Platform. It's a service generally, you know, generally SAS delivered, API delivered, and they specialize in helping figure out if logins and transactions are legitimate or not.
They use a lot of different techniques and specialized intelligence, often from many, many different sources, to be able to make these real-time risk determinations. There are six primary mechanisms by which fraud reduction Intel platforms work. The first is identity verification. This is about raising the overall identity assurance level. This can help with like anti-money laundering and know your customer compliance. On the bank side, especially, you know, they need to do name and watchlist screening against various sanctions lists.
But even in e-commerce, we see a higher need for higher levels of identity assurance for, you know, an increasing number of industries as well. Many organizations, many of these vendors now offer SDKs and JavaScript that can help, let's say, create a mobile application by which, and you're probably all familiar with this, you do identity verification. You will take a selfie, take a picture of, let's say, a driver's license or passport or EID. Some of them can read the chips on those devices.
They can use either active liveness detection to make sure that it's a picture of a real person and a picture of a real document. This has been an area that's been targeted with deep fakes. So there's kind of a constant game of one-upsmanship on trying to do better, more secure, more rigorous identity verification to help deter fraudsters at this phase. Then there's credential intelligence. Wouldn't it be great if you knew if a particular user ID had just been attempted to be used in a fraudulent transaction somewhere?
That would certainly want to raise a risk flag in the event that information was available. So many of these vendors that we'll talk about will sort of aggregate information across their own customer networks so that, you know, an attack happens or an attack is tried to be perpetrated at one of their customers, then that information becomes available to any of their subscribers as well. Device intelligence. This is a really important one. There's a lot of information that can be gleaned from the devices that users are using.
Again, it's JavaScript and SDKs that help enable that. You can pull device identifier information, IP address, and there are third-party sources of both device and IP reputation.
So if, you know, an IP is associated with fraudulent activity or a particular device, especially thinking about devices that might have been used in, say, 50 different account opening events in the last two days or something, then that would certainly should raise the risk level. There's also things like looking at the patch level of the device, what operating system does it have, does it have an anti-malware capability, or is it showing signs of maybe a malware infection already? So lots of information can come from device intelligence that can help thwart fraud attacks.
Same with user behavioral analysis. This is looking at, you know, locations from which transactions have been originated before. Is this the same place that, you know, I would typically try to buy something, or is it, you know, varying wildly from what's normal? Same with network information. Some of these can also look at transaction details, you know, the type of good that's trying to be purchased, the amount, location, frequency. All this information could help deter a fraudulent purchase, for example. There's behavioral biometrics, how users interact with their devices.
If you're on a computer, how you're typing cadence, how you use a mouse can look very different from what a bot might do, but of course bots are getting better at emulating humans. But these behavioral biometrics can be used to build a profile of individual users, such that some of these solutions can actually distinguish between different users on the same device.
So again, on mobile phones, you know, it's how you hold the phone, how you move with the phone, touchscreen pressure. There's lots of different modalities that can be examined to build a user profile. And then lastly, that feeds into bot detection. Behavioral biometrics is an important category of input for bot detection. Being able to determine whether or not a legitimate user is behind a transaction can go a long way to help stop fraud. But then bot management is also very important, too, because like I said, you know, a lot of the some of it's legitimate, some of it you need to let through.
So how do you handle that? Once you've detected something as a bot, you probably don't want to just say, put that on the denial list, unless you know that it's, you know, a malicious bot. But you may want to do things like challenge, you know, CAPTCHAs. There are some of the vendors that are surveyed here who have really nice non-intrusive CAPTCHAs or, you know, mechanisms to help determine whether or not a real user is behind it. You may want to throttle it, you may want to, you know, redirect the bot elsewhere, or just block it altogether.
So you can see there's a need for quite a bit of granularity, particularly on the e-commerce side for how you handle bots. So tying back to our major types of fraud, you know, ATO fraud, account opening fraud, we say the two best mitigations for ATO fraud are multi-factor authentication and risk-based authentication. Risk-based authentication can, of course, be augmented by fraud reduction intel platforms and the scores and risk decisions that they output.
Account opening, identity verification, you know, really, really good, rigorous account verification at the time when it's constructed, as well as, you know, we're all probably used to this. There's a certain amount of ongoing AML KYC that banks and credit card issuers have to do. So not only at sign-up time, but also occasionally verifying that the real user is still behind that particular account. Things to think about when deploying a fraud reduction intel platform, like I said, most of these are delivered to SAS, and they are API-driven.
You probably want to integrate them with your CIM system, consumer identity and access management systems, or maybe your transaction processing systems, or maybe, you know, you're a sophisticated customer, and you already have another risk engine, and you just want to sort of pull it out of the box, and you don't want to plumb the output of a FRIP solution into that. They're licensed typically on usage.
You know, they may charge per transaction, or they may offer blocks of transactions. AI can be used on the good side here. I did mention how it can help fraudsters, but machine learning is the workhorse of AI, has been used for many years, and really, these FRIP solutions would not work well without them, just simply because the volume of data that needs to be processed is too great that individual human analysts wouldn't be able to do it all in time.
And integration, yeah, they'll need to integrate with your line of business applications, maybe another fraud decision engine, and I mentioned risk scores of decisions. Sometimes they will make the decision and pass that decision on to your calling application, you know, a yes, no, or maybe step up authentication or authorization, or sometimes they output very granular risk scores, which then you as the customer can decide what you want to do with that risk score.
So, second poll question, are you using FRIP solutions today? Our choices are yes, no, not sure, or we're in the planning phase.
So, please feel free to answer that, and we will continue on. So, now let's look at the leadership compass, which I recently completed. Like I said, I did two, one on finance, one on e-commerce. For the e-commerce edition, I really tried to focus on what I saw as the use cases for online merchants, media outlets, different kinds of service providers.
Of course, detecting card not present fraud is going to be a top concern they have, but then also the policy abuse and then bot-driven attacks, the various different bot-driven attacks are things that they are going to be very concerned about. So, the specific technical criteria I looked at were credential intelligence, user behavioral analysis, device intelligence, the behavioral biometrics, bot detection, and what's different here between e-commerce and finance is advanced bot management and policy abuse detection were sort of raised in priority because of the nature of the use cases.
And then lastly, you know, what's the analyst's user interface like? What's the policy builder like? And how are the dashboards to try to get a feel for what the customer administrators and fraud analysts would see? And that's represented in the leadership compass spider charts as well.
So, about our methodology, we examined nine major categories of functionality, security, integration, interoperability, usability. On the security side, it's about internal product security, functionality, pretty straightforward. Integration, you know, sometimes they will deliver these, trip vendors will deliver these as a set of discrete services.
So, how well integrated are they and how do they charge for that? Interoperability is about standard support, REST API, GraphQL, webhooks. Those are important standards for promoting interoperability. And then usability is mostly focused on the customer admin and fraud analyst. We also look at innovation, market size, market position, ecosystem, and the overall financial strength. Innovation represents whether or not they're, you know, leading edge or sort of falling behind the others. Market really depends on global reach, how many customers they have in various places in the world.
Ecosystem is about support and how globally distributed is that. And then financial strength helps us, you know, represent, you know, is this a startup or is it a, you know, major vendor? All these get rolled into four major categories of leadership, which is product leadership, market leadership, innovation, and those get combined into overall leadership. And I will show you the overall leadership graphic in just a moment.
So, the vendors that participated in this report were quite numerous. Every time I do this report, and I've been doing it for probably six or seven years now, we find more vendors. And now that I've tried to show specialization in the market, I think this is a better comparison of the vendors and their capabilities, particularly on those things that are specifically of importance to the e-commerce world.
So, here's a look at the overall leadership chart. We'll see a good distribution, you know, from leader all the way through mid-challenger. This to me means that all of the solutions that we looked at are quite capable. One shouldn't automatically gravitate to the highest point on the chart and think that that's necessarily the one for you. Each one of these has different capabilities, and it's probably worth reading the report in detail and, of course, looking at the specific vendors that you think are most important for your organization and then conducting a proof of concept with them.
So, with that, let's look over at the poll results. First question was, what is the main type of fraud your organization is concerned about? 50% account takeover and then roughly a quarter on bot-driven and policy abuse.
So, that's pretty interesting. And then, does your organization use the Fripp solution today? Almost everyone says no.
So, I hope this information is useful to you. So, let's see. Okay. Are there any questions? Feel free to submit a question if you have any.
Oh, okay. One just popped up here. How do fraudsters make deep fakes? There are a number of different tools that are out there, like the This Person Does Not Exist you can use for making images. There are some that can do video, do audio. Some of these are open source. There's quite a list of them that's are actually part of legitimate software packages that you might recognize.
Yeah, there's a number of different tools that can be used for creating deep fakes. Some of them are very convincing, too. There's a case that kind of came to the fore middle or end of last year that was using a video. The video had been created and then inserted into the channel, and it was very difficult for the recipients to discern that it was not quite real. This is the case where it was a business in Hong Kong, and I believe they lost somewhere in the neighborhood of about $25 million.
After that video call, one of the people involved called the headquarters office just to verify that that had been the intent and it had not been the intent. So, yeah, some of these tools. I probably won't mention any others specifically, but there are a number of them out there that can be used to do video, audio, and photo as well. Let's see. How does loyalty program abuse work?
You know, that's interesting. It is the case that they can often, if you think about it, you can, if you have a frequent flyer account or some sort of hotel rewards programs, you can use them for that intended purpose.
But, of course, in order for the program to appear more flexible, they sometimes allow you to use those points for other things, anything from like magazine subscription or game tickets, concert tickets, sometimes just converting them into gift cards even. So, if a bad actor gets into an account, takes it over, and finds that there are thousands and thousands of points, then they might do something like try to cash out that loyalty program just for a gift card that they can then use themselves or pass on down the line.
So, any way in which these loyalty programs can allow those points to be converted into something else, and again, it can be a wide range of other kinds of products or even cash, they will get in and drain those accounts. I think I saw a statistic that said something about 3% of accounts like it for frequent flyer programs can be, have been targeted for account takeover attacks.
So, this is quite a prevalent problem. Okay.
Well, I think that's all the questions I see for today. I hope that this was informational. And certainly, if you have any other questions, feel free to reach out to me. I would encourage you to take a look at the report. It's available on our website.
And again, feel free to reach out if you have any questions. We would be glad to help.
So, with that, we'll conclude, and thank you for joining today.
See All Locations
See All Locations