Understand the 2025 fraud threat landscape and how FRIPs address new attack vectors.
Learn how to integrate FRIPs with IDV, AML, and KYC systems for stronger defenses.
Preview the KuppingerCole Leadership Compass to benchmark leading FRIP vendors.
Get actionable strategies to optimize fraud operations with behavioral and device intelligence.
Fraud tactics are becoming more sophisticated — from synthetic identities to mule networks and real-time social engineering scams. In this exclusive webinar, discover how Fraud Reduction Intelligence Platforms (FRIPs) are reshaping fraud prevention and get an insider’s look at the latest KuppingerCole Leadership Compass results for 2025.
John Tolbert, Director Cybersecurity Research will share exclusive insights from KuppingerCole’s latest research on Fraud Reduction Intelligence Platforms for the finance sector. He will highlight how fraud operations teams can leverage behavioral analytics, device intelligence, and risk signals to make faster, more accurate decisions. John will also walk attendees through the Leadership Compass methodology, helping them evaluate vendor capabilities, prioritize integration points, and align platform selection with strategic fraud prevention goals.
Who Should Attend:
Fraud prevention teams, AML and compliance specialists, risk managers, fraud operations leaders, and decision-makers in banking, fintech, and payments.
Why Attend?
Gain practical insights and strategies to strengthen your fraud defenses, evaluate platform capabilities, and optimize your fraud prevention operations for emerging threats. Get an exclusive preview of the latest KuppingerCole Leadership Compass, helping you benchmark leading Fraud Reduction Intelligence Platform vendors and make informed decisions for your organization.
Hello, and welcome to our webinar today. I'm John Tolbert, Director of Cybersecurity Research at KuppingerCole. And today I'm going to be talking about results from a leadership compass I published recently on fraud reduction intelligence platforms. This one is focused on the finance industry. So a little bit of logistics info before we begin. Everybody's muted centrally, so there's no need to mute or unmute yourself. I've got a couple of poll questions in the middle, and we can talk about the results at the end. You can submit questions. There's a control panel in the Livestorm app.
Feel free to enter questions at any time, and I'll take them at the end. And then lastly, we are recording the webinar, so the slides and the recording will be available in a few days. So I'll start off by talking a little bit about the fraud landscape, some of the types of fraud that are out there, and then we'll get a preview of the leadership compass on fraud reduction intel platforms, the finance edition. So first up, the fraud landscape.
So I think it's always useful to go collect recent statistics, and there are several different organizations, government agencies, and others that look at the broad impacts of fraud across different industries. So looking at the NASDAQ report here, you can see that the number is just staggering, $3.1 trillion in illicit fund movement, and this includes things like not only fraud, but also terrorist financing, money laundering, all sorts of organized crime. Out of that, over $100 billion is just simply fraud loss, and about $58 billion was money moved by money mules.
You can see that fraud reports generally are increasing, and this might be a bit counterintuitive. In this report, we saw that younger people reported losing money to fraud more often than older people, but when older people lose money, it tends to be a larger amount. We see imposter scams on the rise, identity theft reports going up, particularly in the insurance industry. These are some statistics collected by the U.S. FBI. I think the really notable things here are the increases over the last year in areas like investment fraud and cryptocurrency scams.
Crypto scams jumped from around $4 billion in 2023 to over $9 billion in 2024, and this includes the horribly named pig butchering scams, which start off with maybe what seems like an innocuous text message. Maybe not even directed at the person, but designed to try to get them involved in a conversation that maybe involves a friendship over text. At some point, the fraudster will try to convince the recipient that, hey, I know this good crypto investment, and they will try to get the person to fall for that.
Obviously, it's worked out very well. A statistic I heard just yesterday was that some of these pig butcher operators are making more than $30 million a day with these scams. A lot of people lose their life savings of these, so they're very serious. But here you can see other numbers, lots of fraud involving things like business email compromise, data breaches. These numbers are really overwhelming in a way, and I think really illustrate the reason why we need things like fraud reduction intelligence platforms. Some numbers from around the EU are some facts.
PSD2 has been helpful at reducing account takeover fraud, but there is one that we call APP, authorized push payment fraud, where the fraudster tries to trick the victim into actually authorizing a money transfer. This would be like in the case of pig butchering, where they convince a person to transfer large sums of money. It can be harder for an individual to get their money back in those situations because it did appear to be an authorized payment. Let's dive a little bit deeper on some of the more common types of fraud that we see. Let's start with account takeover fraud, ATO fraud.
Well, the goal, of course, is to get at least temporary access to some existing account, like a bank account or a credit card account. But it doesn't have to be limited to financial accounts. It can be anything that can be converted into money. For example, loyalty programs, frequent flyer programs, those are highly targeted because there's a lot of value behind those loyalty programs. So this applies across many, many industries, really all industries. Anything that can be converted into money is going to be a target.
So in some cases, the fraudsters will use a taken over account immediately, but sometimes they wait. They might wait months to use it. They might harvest dozens, hundreds, thousands of accounts and then put them on the dark web for sale for use by a different fraudster. Then we have what we will more widely call new account fraud, and that encompasses things like account opening fraud and synthetic fraud. Account opening fraud is the goal to create fake accounts based on real people's data.
So this is where they might take bits and pieces of information about a real person and try to get a new bank account, a new line of credit, open a credit card. Of course, it can be used for any kind of major financial fraud or even money laundering. This is often what they do when they create new accounts to move money around from, like, drug trafficking operations. Then we have synthetic fraud. This is a little bit different. They're trying to make accounts that look like real people, so it will be based on plausible data.
It, too, can be used for financial fraud. It could be using fake information like these pictures that I generated at this persondoesnotexist.com. So they might create photos, you know, to get through identity verification processes, and then maybe addresses of abandoned buildings or houses or other places where, you know, maybe they're going to have goods shipped there. There's many, many different variations on the schemes used to create synthetic fraud.
And again, many different kinds of industries are targeted. So when they do synthetic fraud, they might start small. They might try to get a small line of credit for a department store or hardware store or something like that, and it may have an initial low value. But they will work on that account, and they will, over the course of a few years, build it up to where they have a higher line of credit. And then once they get a sufficiently high line of credit, they'll use it and walk away and not pay it back. So how do the fraudsters go about doing this?
Well, for doing account takeovers, things like email phishing, voice phishing, or phishing, smishing, you know, getting texts, are very, very prevalent. I think we all probably get texts and emails like this still every day. So we have to be extra vigilant about that. There's brute force password guessing. That still works. Compromised credentials that can be found or bought on the dark web. Big data breaches. The criminals will put that information out there and try to sell the accounts. Credential stuffing attacks.
So maybe from a data breach, they find lots of username password combinations, and they will use bots to try those username password combinations against lots of other sites just to see if anybody was reusing passwords. And as we all know, people do reuse passwords, so that can often be successful. They may set up fake websites where they try to redirect victims to go. It might look like a real bank or a real business, and the goal is to get a person to put their true username and password in it so that they can use it for fraudulent purposes.
They may use drive-by downloads to distribute malware, key loggers, rootkits, spyware. Again, if they've got total control over a device, then it makes it easier for them to get usernames and passwords. For account opening, it's all about the information, and you can see a whole bunch of different places where information can be gathered. Government records, school records.
Again, they're looking for things like name, date of birth, address, past addresses, employers, things that you might have to use to answer security questions, which aren't really all as secure as we know. But these bits of information they can use to assemble a profile that looks like a real person. Then on the other side here, synthetic fraud information sources. We've got the AI image generators like I just showed.
But, you know, in recent years, many vendors have rolled out things like remote onboarding apps, which allow someone very conveniently to, say, take a selfie and then take a picture of the photo on their document. It can do matching on that. It might use NFC to read the MRC on a passport.
And then, you know, to counter that, we've included things like liveness detection. Well, unfortunately, fraudsters in some cases are able to defeat passive liveness detection. Active is a little bit better, but then there are also video identification processes.
And, of course, believe it or not, fraudsters have the ability to create fake videos, virtual cameras, ways of, you know, fooling systems and even people who might be responsible for doing remote identity verification. So that's where we see things like generative AI coming into play. And if you have to put in a phone number, some of these sophisticated fraudsters have, you know, mobile farms or virtual phone emulators so that they can receive the calls. So you can see there's a fraud as an industry with lots of different facets to it, unfortunately.
Now we might want to take a look at, you know, how is AI actually helping fraudsters? We see AI all over the place. We hear it talked about, particularly in relation to helping us with, you know, IT solutions in one way or another. But it's definitely been very beneficial to fraudsters because, you know, in the old days, we could tell people, you know, if you want to be on the lookout for a phishing email, you might look for bad grammar or misspelled words or things like that.
But, you know, LLMs are very good at helping people create more realistic phishing emails or texts as well. You've got those image generators, video generators. AI can also be used for taking in a bit of PII and then sort of expanding on that to make it possible for fraudsters to say, let's, maybe they need to generate a fake utility bill or a bank statement for synthetic fraud, you know, because if you're going to go open an account with a bank, they might want some sort of proof that you've been at an address for a while.
So the fraudsters will take, say, the logo from a utility company and, you know, craft the text that needs to go along with that and then, you know, create a PDF that they then use to sort of bolster their claim that they are legitimately applying for a digital identity. So fraud has definitely been helpful. We see this in the rise of deep fakes. Many sources report exponential increases of the use of deep fakes, particularly during identity verification processes.
And, of course, we couldn't not mention credit card fraud because it's still rife across industry. There are several different kinds here, card not present being the most prevalent. This is where, let's say, any given day when you order something online, your card is not present. You're not inserting it into a point of sale system or tapping it. You're entering your information online. They'll ask not only the card number and CVV, but maybe information about your zip code or postal code.
In the background, hopefully they're also doing, you know, some risk-based authentication to increase the likelihood that it's actually you making that transaction. But card not present fraud is very, very prevalent. Then you have things like card not received or actually physically stolen cards. They're no longer in the possession of the account holder. Being able to detect that could be useful. Then there are counterfeit cards.
There are organizations, criminal organizations, that will print out thousands of cards and then go grab information from places on the dark web about stolen card number and CVV combos that they believe will work. So they can actually create physical cards that can be used for in-person fraud as well as card not present fraud. So drilling down a little bit on phishing, vishing, and smishing.
You know, I won't read through the entire list here, but there are an amazing amount of variety of how they go about doing this. I mean, we've talked about fake investment opportunities, fake delivery notices. We've probably seen, all of us have seen those. You have a package and you need to log in here.
You know, they may be trying to harvest your credentials there. They might want some payment for delivering the package.
Of course, it's not legitimate. You might get fake invoices for all sorts of different services. Fake government welfare signup forms. This was quite noticeable a few years ago. Fake tech support scams are still huge and increasing year over year. So there's lots of different twists that fraudsters put on this, but they're using the communication channels that we all have to use every day, like email and phone and SMS. So let's stop and take a poll question. I'm really curious. What's the main type of fraud that your organization is concerned about? Is it account takeover?
Is it the new account fraud, including synthetic ID fraud? Is it credit card fraud, which it might be if you're working for a merchant or a big online retailer or even a bank or a card issuer? Or is it one of the other kinds of fraud that we haven't really delved into just yet? So that should pop up, and when it does, please feel free to enter and we'll take a look at the results at the end here. So we've kind of set the stage for how bleak it is out there with the increasing amounts of fraud and the different kinds of fraud.
The good news is there are solutions that can help organizations prevent that. So let's look at the six main fraud reduction methods. First up is identity verification, and this can be used during onboarding and registration process, but it can also be used periodically to once again bring up the level of overall identity assurance. I talked a little bit about the mobile apps that can be used.
Also, a lot of these vendors that we'll look at here in a few minutes provide SDKs so that their customers can build this kind of capability into their own applications. And again, it's about raising identity assurance levels.
Banks, others in the finance sector are required to comply with anti-money laundering laws, know your customer initiatives, and then sanctions. Sanctions is a word we've heard a lot about in the last couple of years. There are sanctions lists at several different national and international organizations, and in order to be compliant with laws in those areas, you as a bank or other account-issuing organization have to make sure that you're not providing accounts to those who are on the sanctions lists.
So having all this bundled in an identity verification service, either within a fraud reduction Intel platform solution or if your FRIP solution has integrations with third-party IDB services, that's a good way to help meet these legal requirements. Then we have credential intelligence. This is simply knowing, has this user ID password combo been used somewhere else for fraud recently? There are a few services out there that can help with that. Maybe one of the best known is Have I Been Pwned? But other organizations are starting to share signals a little bit more frequently now.
There are some frameworks in place for that, which will be very helpful in deterring fraud that may occur between FRIP solution customer bases and others. There's device intelligence, information about the devices that we use to originate transactions. Devices have identifiers.
Of course, we all have IP addresses. There are services out there that aggregate device and IP reputation information, which can be very useful if others have observed devices or IPs being used for fraud. But the thing about IP reputation, some of these fraudsters only use IP addresses for literally a few minutes at a time. So it's not like you can come up with a block list of thousands or millions of IP addresses and depend on that being valid for a very long period of time. You need a service that keeps on top of that and provides you with the latest information.
The device intelligence part is often delivered by JavaScript, or it can be embedded in the SDK. And depending on how deep and how sophisticated these are, it will allow you to get information on what OS is running on the device, what's its patch level, does it have anti-malware installed, can it detect signs of an active malware infection. All these things are very useful to know if you're trying to do some sort of risk assessment on whether or not to let a particular transaction go through. Then we have user behavioral analysis.
This looks at history on users, from what physical locations or network locations have they originated transactions before. And then it can also look deeply at the transactions themselves, the history, are there periodic payments, is this purchase something that the user has done before, is it way out of line in terms of the amounts or the types of transactions that have been made before.
And again, with the right logic, it can help raise a red flag if something looks suspicious, or not raise a red flag if it looks completely legitimate, which can do a lot to help lower customer friction. Then we have behavioral biometrics. This is how users interact with their devices.
I mean, we're all familiar with regular biometrics with like touch ID or face ID, but this is, you know, if you're typing on your computer, we all have sort of an individual typing pattern or the way we move our mouse. If you're talking about your phone, you know, how we hold our phones, how we interact with the touchscreens, all this information can be used to build a fairly unique profile of individuals, such that it can even identify different users on the same devices. And this too can be a very good way of helping to deter fraud.
It's also one of the main drivers for bot detection because bots, as you know, are programs that behave somewhat programmatically. And behavioral biometrics can be used to help figure out if it's a real user versus a bot.
So, bot detection also can rely on, let's say, bot signatures or intelligence about where bots are operating. The management part is, okay, an acknowledgement that a large percentage of the traffic on the web involves bots.
So, bots are legitimate in many cases. They're used for getting stuff done online. But of course, a lot of them are bad.
So, you need to be able to figure out not only is this a bot versus a human, but is it a good bot or a bad bot? And, of course, there are some that fall in the middle.
Maybe, you know, like account or inventory checking bots. Maybe you want to allow some of that through, but not too much.
So, we need challenge mechanisms. We've all seen CAPTCHAs and probably don't like using them. But there are more intuitive ways, less intrusive ways of doing challenges that can help detect bots. But if you do detect a bot, and maybe it's not completely bad, you may just want to throttle it so it doesn't interfere with your normal business, or you may want to block it or redirect it altogether. And that's where the bot detection and management functions come into play.
So, the best mitigations for our two most prevalent types here, ATO, account takeover, and account opening. Multi-factor authentication is definitely a good place to start. There have been cases where MFA can be bypassed, which, of course, is unfortunate.
But, you know, we can back that up with risk-based authentication, looking at lots of different factors, like the ones that I just talked about. So, fraud reduction Intel platforms can provide risk scores or risk decisions for authentication systems, which can then help reduce the number of ATOs. For account opening, the best things that we can do are really good identity verification and ongoing identity verification. That can help you meet AML and KYC requirements if you are in the financial industry.
So, let's do another poll question. I'm curious, does your organization use a FRIP solution today? Our choices here are yes, no, not sure, or we're in the planning process.
So, feel free to answer that, and we'll look at that in just a few minutes. So, now to talk about the report. I thought we'd start off by looking at the evaluation criteria. I have done these FRIP reports for the last several years.
This time, I decided to break it into two reports, one that focuses on finance and another that focuses on e-commerce. I'll talk about the e-commerce one in a few weeks. Both are out and online, so feel free to go take a look at those if you want.
So, as you might expect, the finance edition really focuses on the use cases that banks have, credit unions, credit card issuers, fintechs, other kinds of financial institutions like investment houses. And they, as I've mentioned already, really need to be able to do AML, particularly this name and watch list screening. These are very, very top of mind for organizations in the financial industry, more so than, let's say, those in e-commerce.
So, identity verification is important, but they also need to be able to detect specifically things like card not present, authorized push payment, and buy now, pay later fraud. They need to be able to detect mule accounts and, ideally, figure out when scams are happening and stop them in the process. And there are some solutions that I reviewed and we'll talk about in a second have the capability of doing that.
So, we rate based on, you know, a number of different categories. The particular technical evaluation criteria that I looked at for the finance edition was, you know, identity verification with some preference for those that have built in IDV, or at least, you know, credit for having multiple third party IDV service connectors. They should have some form of provincial intelligence, and ideally here it would be using shared signals or looking at, you know, authoritative external sources. They should be able to do user behavioral analysis, device intelligence, behavioral biometrics.
Often these are either OEMed or partnership arrangements for behavioral biometrics. At least basic bot detection. The name and watch list screening. And then lastly, I look at what is it like for, let's say, an administrative user or a fraud analyst. What's the analyst user interface look like? Is it easy to use? Is it easy to build and change policies?
And, you know, the dashboards because both people in the stock or the fraud analyst area or even executives need dashboards to see how things are going. Then our standard categories and leadership compasses cover things like security, functionality, integration, interoperability, and usability. For security, we're not talking about how it increases customer security. We try to evaluate how internally secure is the product. Is it using strong authentication? Does it have attribute based access control? Does it use encryption appropriately?
And usability in this case, like I said, is kind of focused on the administrators and the fraud analysts. Then our other four dimensions we look at are innovation and then market ecosystem and financial strength.
So, you know, is it a leading edge product? Is it not quite so leading edge? What is their overall market position? Are they doing well financially? Which areas of the world are they operating in?
You know, the more areas, the more globally distributed they are, the larger of market share they're likely to have. So, from that we have, we create four categories of leaders. We have product leadership, which is exactly what you would think it would be, you know, looking at the functionality and security, all those different categories. Then market leadership, sort of an amalgamation of the number and geographic distribution of customers and their overall support system. And then innovation is solely focused on how innovative of a product is it.
But then those all get combined into the overall leadership, which I will show you in just a second. Our process is once we identify a field, then we go ahead and identify the most pertinent vendors. We invite them to participate. We send out a giant questionnaire with hundreds or maybe even more than a thousand questions. Very in line with what enterprises would want to do if they were conducting an RFP. So it can help get you started with an RFP. Then we talk to them, get demonstrations of how the product works, evaluate those technical questionnaires, write it up, send it out for fact check.
And once we get through the fact check phase, we publish it live on the website. So with that, let's take a quick look at the results. First of all, here we have the vendors that participated in this round. There are quite a large number. It tends to increase it seems every time I do this report. And here's a quick look at the overall leaders.
We see, you know, a very wide range. And I think it's important to note that while those on the right in red are maybe the most complete and or the largest solutions, it really depends on your organization which product is best for you. There can be some that are, let's say, highly innovative in some areas that really, really pertain to your business. Let's say there may be a need for built in identity verification or maybe you need really good behavioral biometrics.
It's important to look closely at all the different products and we try to cover that in the write ups for each one of these vendors. So our Leadership Compass reports are not just for organizations that are, you know, running RFPs looking for solutions in these areas. So here are links to the reports. You'll see both the e-commerce and finance versions are out. And then also we have Buyer's Compasses, which again are for RFP support.
In these documents we talk about, you know, what are the business challenges, what are the solutions, what are the top use cases that you have to solve, what are the main technical capabilities which align with what I was just showing you here in the case of Fripp for Finance. And then also questions to ask for if you're doing an RFP.
So yeah, please feel free to take a look at both the Leadership Compass and the Buyer's Compasses. So let's take a look at our poll results. And first question is, does your organization use Fripp solutions today? And of course this may have to do with the business that you're in, but only about half are saying that they are not using it currently, and about a quarter say that they are using it. So probably some room for improvement there. Then which type of fraud is your organization most concerned about? ATO and credit card fraud are tied at about a third, so that's very interesting.
Thank you for participating, Laird. So feel free to answer or ask questions, and I will try to answer them here before we wrap up.
Let's see, we have one question. Has PSD2 helped to reduce fraud in the EU?
Yeah, I would say on the ATO side especially, you know, the requirement for strong customer authentication is always going to be able to help people, at least with that particular type. But, you know, people all around the world are subject to these authorized push payment types of fraud as well as scams. And unfortunately, regulations haven't been able to bring down the frequency of that kind of fraud. Then we have, let's see, we have a homegrown fraud prevention solution that uses external intelligence feeds. Is it possible to use FRIP services to enhance our homegrown system?
Yes, and that would be a case where maybe you, a lot of banks do have their own fraud prevention capabilities in their transaction processing systems, but many of them do augment their own internal fraud prevention solutions with either, A, threat intelligence feeds or some sort of external risk scoring. But, you know, many of these fraud reduction Intel platform solutions sort of fit into the identity fabric model where you can take in various services as you need them. I think I mentioned that things like identity verification services are often consumed as a, you know, a third party service.
So definitely, you know, if you're a bank or, it doesn't say bank, but any organization could add on things like identity verification services. You could use SDKs to improve device intelligence or behavioral biometrics.
So yes, your homegrown system can be enhanced by adding on discrete fraud reduction Intel platform services. Let's see, I see one more. Do FRIP solutions create a lot of false positives? I think that's probably a little bit hard to answer, but they certainly should be designed to not create false positives. The idea being, you know, only alert when there's a pretty reasonable chance that there is a fraudulent transaction underway. That's where the use of things like machine learning come into play.
You know, looking at vast amounts of transaction data, being able to find the outliers, classify the outliers, and thereby hopefully reduce false positives. But yeah, I can certainly understand the motivation behind that question. You would not want to, especially in a bank or another financial institution, introduce something that, you know, makes it harder for customers to transact their business. So that's all the questions I see for now. Definitely want to thank everyone for attending.
If you have any further questions, feel free to reach out and please feel free to go take a look at our research and we will see you for the next webinar. Thanks, everyone.
See All Locations
See All Locations