So thanks for sticking around this afternoon. Yeah, last year, pretty much every year, I'm talking about fraud, doing an update. We do leadership conferences on fraud reduction intelligence platforms.
So today, I'm just going to jump in and talk about what the fraud landscape is, how it's changed, give you a refresher on what the fraud reduction intel platforms are all about, and then talk about some deepfake threats and threat detection methods. So what's new this year? All these are actually links, so when you get the slides later, you can click on the links and you can find the underlying detail. But I think it's really interesting that 99% of organizations have reported being hit by account takeover attempts in the last year, and 62% of the time, it was successful.
50% have reported being hit with account opening fraud, including using fake documents. Over 21,000 reports of business email compromise at the FBI, and these are the people that just happen to bother to file a report. I'm sure there's many more than that. Investment scams are up. Crypto fraud is up. Fake tech support calls, fake calls from government agencies are way up. But I think the staggering number there, and this statistic was just released last week, is the FBI says over $16 billion lost in fraud and different kinds of scams last year.
I mean, so that's a huge amount of money. So these things are unfortunately just getting worse. So ATO fraud, what is it?
Well, it's just what it sounds like it is, you know, trying to take over somebody's account, usually to get money or anything of value. All industries are targeted. It's not just banks or fintechs or things like that.
It's, you know, going after, you know, rewards programs, frequent flyer miles, anything that they can get value out of, they will try to take over. Account opening or new account fraud, this is also used for monetary theft, but it can also be used to abuse platforms.
You know, if there's a signup bonus that's offered, people will create multiple accounts and try to get the same bonus over and over again. Or when a free trial period expires, they'll use a different email address and try to sign up and get another account. Retail fraud, you know, using a credit card and having, you know, somebody else's credit card number and having goods delivered to, let's say, a house with an abandoned address or something like that. So there's just a wide variety of uses for this new account fraud. And they try to build trust.
They, you know, prime the credentials. They build up credit histories. Some of these are slow burn exploits against real people. So they might create this fake account, you know, in the name of somebody else and then just let it sit there for a while before they use it.
Because, you know, there are a lot of services now that look at email reputation, account reputation, IP reputation. And of course, newer ones are going to get flagged as potentially suspicious. That's why they age these accounts. Synthetic identity fraud, it's kind of similar, but maybe a little bit different in some ways. We'll talk about that in a minute. But this too is used for stealing money. This is also another way mule accounts are made. Then there's bust out fraud where, again, you have an account, the bad guy has an account. They let it age for a while.
They'll make some small purchases, pay them off. And over the course of like 12 or 18 months, they'll get a bigger and bigger credit line. And then one day when they get a sufficient credit line, they'll, you know, max that out and then walk away and not pay the bill. This is also used for like government benefits fraud. We saw this during COVID. A lot of synthetic IDs were made and people were getting payments that shouldn't have been getting payments. It's also common in the gaming industry and against crypto exchanges. And they build trust for all the same reasons.
Oops, wrong way. So some key differences between account opening fraud and synthetic. New account fraud really is targeting mostly real people. Synthetic fraud is trying to make something that looks like a real person. So there's a lot of untrue information that can be mixed in, but it's plausible information. How do you tell, you know, if you're going to have a fraud reduction system, how can you tell what's real and what's not? Device intelligence, which I'll mention in a minute.
There's a lot of information that you can get off of, you know, somebody's phone or the computer to kind of build a profile of normality. So if you have a real person, you know, and they're, you know, in Belgium and they're pretty much always in Belgium, but then suddenly there's an account created in Italy, you know, on a different device, then that information can kind of help you raise a flag that maybe something isn't quite right. With synthetic identity fraud, it can be more difficult because this might not be linked to any other piece of an identity that you can determine.
And one report that I saw showed that a very aware fraud reduction Intel platform saw the same photo reused 4,000 times on credit applications. So, you know, being able to tell is this the same photo that's being used for one application and the next is also pretty useful. So how do they go about doing these things for account takeover?
Of course, there's phishing, vishing, smishing, all the different ishings to try to get people to give up their account information. You know, brute force password guessing still works. And malware. Info stealer malware is on the rise.
So, you know, getting information directly from somebody's device is certainly pretty helpful. Session hijacking also deserves a mention. This has become rather prevalent, you know, in the last couple of years.
This is, you know, hijacking somebody's active cookie or token. And depending on how the website on the other end has this configured, the session might be very long lived. You might be able to get, you know, 30 or 60 days out of it. So even these sessions are for sale on the dark web. And QR codes. I think a lot of us have reached the point where we don't trust QR codes that we see in public just because who knows what that's really going to take you to.
You know, parking lots was a big example where a fraudster will come and stick up a QR code that takes you to their site. They harvest your credit card information and use it for whatever they want to do. New account fraud. Lots of different sources there.
You know, public records. They can, again, use to try to make an identity that looks like one of us, but it's not us. Synthetic identity fraud. This is where AI comes into play a lot these days. There's a lot of reason that these guys are using this, because they can generate those fake photos. They can clone voices. They can even use generative AI to create a fake utility bill.
You know, if you want to get a bank account and you need to prove you've lived in an address for a while, guess what? It's pretty easy to do with generative AI. You can kind of make a template out of it. So a different set of tools there.
But, you know, sometimes synthetic identity fraud also involves bits and pieces of real identities, too. So they might take something like a social security number or something else just to give it that, you know, ring of realism. I don't expect everybody to be able to read this, but I think I'll just start with the top, because it's kind of the most severe. And in a lot of ways, it draws on some of these other techniques, too. But pig butchering, I can't stand the name. It sounds terrible. But what they're doing to people is terrible, too.
You know, this is the case where you may receive a text, an SMS from somebody, and you think, oh, it's a mistake. They're hoping that a nice person will just reply, and they can start a conversation. And apparently, this works really well.
You know, so you'll start a conversation. You'll sort of become friends over SMS. And then at some point, the fraudster will say, oh, by the way, you know, I've been investing in this crypto thing, and it's really cool. You might want to give it a try. So they'll send them a link to that, and they'll start out by putting a small amount of money in that.
And, you know, then the fraudster will pay them. You know, here, you know, we're going to build your confidence. So they start to think this is legitimate. And the websites they send them to look as good as or better than some financial institution sites I've seen. They look very modern. They'll have you use MFA.
I mean, wouldn't it be great if all financial institutions did that everywhere around the world? So, I mean, it looks legit. The idea is get them to go all in at some point, make a massive investment, and then they walk away with the money. And it's very difficult to ever recover it. But you can see, I mean, that kind of draws on, you know, the crypto, the romance, investment-type scams all put together.
They have, you know, some tactics and techniques that are in common. You know, there are other scams, fake delivery calls. These have been rampant at least in the U.S.
for years, you know, claiming that you need to call back here, go to this website, and put in information. They're just trying to harvest your credentials. Credit card fraud, still alive and well. Card not present, you know, you buy something online, you put in the 16-digit number, the CVV, your expiry date.
Well, you don't even have to go to the dark web to get these valid credit card numbers. These are on social media. So credit card fraud is still, you know, way too rife out there in the world. Same thing with skimmers.
You know, you'd think skimmers, why are we still seeing these things? I mean, I've seen two physically in the last year, and I even talked to management at the store about it, and they're like, yeah, we know it's there. What's really going on? So fraud reduction, what is it?
You know, these are specialized security services. They take in all kinds of intelligence. They take in information from your point of sale systems, your banking systems, and they look at it to help determine which transactions are normal, which ones are anomalous, and of those that are anomalous, which ones are suspicious. So then they will make a risk decision, you know, that they can pass on to like a banking application or whatever the customer application is, usually over API.
The six pillars of fraud reduction technology are identity verification, and this might be, you know, the mobile app for, you know, doing remote identity onboarding. Credential intelligence, has this credential been used for fraud somewhere else recently? Device intelligence, you know, you can get a lot of information off of devices, IP address, does it have malware on it, does it have anti-malware on it? User behavioral analysis, looking at not only login locations and locations of transactions, but also transaction details. So the more detail you can get, the better a baseline you can create.
You know, some of these will look at transaction types, amounts, payees, is this a normal payee for you to be sending money to? Of course there's privacy concerns with doing this too, so how much information that you want to share between entities. Then there's behavioral biometrics, that's how we all interact with our devices, and simply, I mean, obviously it's keystroke and mouse for a computer, but these things have accelerometers and gyroscopes, and of course cameras and microphones, and they can collect data that can be used to build an individual profile.
Again, there's privacy problems in some jurisdictions with that. Bot detection, a lot of fraud is perpetrated by bots, so you really want to be able to know if a human is behind a transaction or not. So bot detection is very important, and a lot of that is built on behavioral biometrics. Some things to think about when this is deployed, the client side pieces are JavaScript and SDK, that's to collect all the device and user behavioral analysis and behavioral biometrics, but it's always usually delivered as a SAS.
You price it by how much you use it generally, some of the vendors have different pricing mechanisms, but it's generally based on usage. ML, it's kind of baked in, it's not that exciting anymore, especially for this kind of technology, because there's so much data that you have to have ML to be able to sift through it and determine whether or not something looks anomalous, and many of these do integrate with CIM systems.
In fact, over the last couple of years, we see more and more emphasis on integrating CIM to fraud reduction platforms, but they also integrate with your line of business apps, core banking apps, and things like that. Also a little sidebar on deepfakes, we've all probably heard the story about the employee in Hong Kong that thought he got a message from a CFO, a video message, it looked like the CFO directed him to send $25 million to some place that shouldn't have gone, but great unfortunate example of a video deepfake that was used for a substantial loss.
Another chart I don't expect you to read, but you can take a look at in the slides, I tried to just compile a short list of some of the tools that are out there for creating these deepfakes, and it was really, really surprising. You know, there are deepfake creators for voice, video, and just photo, and some of them are fairly easy to use within like Teams and Zoom and social media. And some of these are open source kits, some of these are even just apps you can download from the App Store. So they're out there and fairly easy to use.
Deepfake document detection, you know, since we saw that increase in the use of deepfakes like during the identity verification process, some of the ways that sophisticated fraud prevention tools can detect that. On the passive side, you know, it's ideal if you can use like NFC to like read the chips, not just look at the photo to selfie comparison off the document itself, that's one thing that's good.
Compression artifacts in the pictures, but I think maybe what's going to be the area of most development going forward will be a focus on active liveness detection, where you actually have to hold your thing, your ID up and move it around to get sort of that whole 3D feel for it all. In the interest of time, I'll speed up a little bit. Deepfake detection on video.
Video, of course, can be a lot more difficult, difficult for users to discern, but also a little bit more complicated on the technical side. You know, there's a lot of different steps that can be involved here. It starts with the SDK. When the user initiates a session, you can collect that device and tell, figure out if, you know, first of all, is this coming from a device that we know is at least suspicious or has been caught making fraudulent accounts before. Then you can look for the presence of virtual camera apps. So there's more than just these three.
So if the SDK sees, you know, these virtual camera apps here, well, I'm going to raise the risk level just because I'm not entirely sure they're not being used for that. You can look at things like video quality, again, liveness detection, active liveness detection. Now a lot of these apps will ask you to do things like blink or smile or turn your head. It can also look for GAN artifacts, you know, generative adversarial networks, the way you create the photos in the first place. It can leave artifacts that can be detected. The biometric matching.
And then finally, you know, the risk engine evaluation. But so lots of different steps, lots of different technical means that really need to be in place to help detect videos. Voice is problematic, too, because I just read in the last couple of days stories of the increase in the numbers of messages, audio messages that are going through social media and, you know, various messaging applications, just short clips like, hi, mom, I've lost my wallet. I need money. Can you send, you know, some amount of money to my friend's account here?
And all they need is like a three or five second clip, a voice sample to be able to have enough voice information to then get it to say whatever they want them to say. And how do you go about distinguishing that?
I mean, I don't think it would be easy to train users to do that. I mean, you can set up, you know, back channel codes or whatever, which is probably ideal.
But, you know, from a technical perspective, there are ways that a good fraud reduction program could help you to figure out whether or not it is a legitimate audio message or not. And that's because it may add on reverb.
You know, it might have an unnatural sound to the voice. It doesn't usually follow the normal ups and downs of speaking. It seems to be a little bit flatter. But this isn't necessarily going to be the case for long, because if they know that we know that this is how people can recognize a voice deepfake, then I'm sure they're going to be working on introducing that variation in the pitch and things like that, too.
So, wrapping up, yeah, fraud rates are increasing. The fraudsters are always innovating.
I mean, it's only been in the last year or so that we've seen ATOs used to be on top. You know, ATO was the thing that everybody was worried about in the consumer space. Now scams have kind of overtaken that.
I mean, it's not to say that ATOs aren't still happening and aren't a problem, because they are, but that's just how quickly things have changed in the fraud landscape. And once they see that, you know, certain actions are rewarding them, then others will sort of migrate to using the same tactics. But the good news is there are plenty of different fraud reduction intel platforms out there for commercial use.
Some are, you know, geared toward banking. Some are geared toward merchants and e-commerce. And right now I'm working on an update to the report. It should be out, two different reports this summer, one on the finance side, the other on the e-commerce side.
So, yeah, if you have any questions, I know we're almost out of time, but feel free to track me down. I'll be around for a while. Any questions from the audience? Okay. I do have a question. A quick one. How can organizations integrate fraud prevention into existing CIAM systems, so to speak, or into the workflows?
Well, orchestration is a good way. You know, all of this stuff is API driven, mostly REST APIs. So if you have a CIAM solution that supports customization through REST APIs, then, you know, it could be as simple as building that.
It could, there could be out-of-the-box connectors available from the CIAM solution to some of the fraud reduction intel platforms as well. And I think we're going to see a lot more of that because I keep hearing more and more customer demand for exactly that. They want a CIAM solution that has fraud reduction either built in or easily available through a quick connector. Okay. Great. Thank you. Okay. You can stay here.