Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm analyst and advisor with KuppingerCole Analysts. My guest today is John Tolbert. He is the director of cybersecurity research here at KuppingerCole.
Hi, John. Good to have you again.
Hi, Matthias. Nice to talk to you also. Great to have you. We are post-EIC, so we are allowed to cover other topics as well. So back to cybersecurity. So we want to cover two topics that are interesting from different perspectives. And for those who are watching this episode, by the end of this episode, you will have learned what rogue merchants are and you know why we desperately need organizational identity and what that is. So these are the two topics we want to cover today. So my fun topic, so for some definitions of fun, are rogue merchants.
And you did some research around that topic and it's really something that is gaining traction and it's just something that has bad influence on society, on organizations. But to start out, first the definition. What are rogue merchants? A little bit of background. So I've been covering fraud reduction intelligence platforms for many years now. And that's really been focused on individual consumer fraud. But you know, there is so much fraud that's perpetrated under the guise of a business when it's not in fact a legitimate business.
In fact, you'll see that their numbers are huge with some of the examples that we have to talk about today. But a rogue merchant, excuse me, is a slightly different kind of threat actor. Those who are misrepresenting themselves to the general public, it is kind of what it sounds like, you know, it could be a case of someone sets up a fake business online and they try to sell items, you know, maybe luxury items, high-end goods, you know, for a much lower price, they might advertise on social media and try to get people to come and buy, you know, a very expensive item for a lot less.
And what they're doing is they're with their website, they're harvesting a credit card and identity information, you know, and they're not going to send out the goods in most cases. So they're trying to pocket the money. And of course, there's a lot of instances where a consumer might push back on that, try to dispute the charge, and maybe the banks or credit cards can claw back some of that money. But they're kind of depending on people not to do that. And they can make an enormous amount of money just by doing that.
Plus, they have the credit card info and some identity information that they can use and, you know, other kinds of follow-on fraud. And so that's just like one big example of what a rogue merchant might be. And so that sounds scary. And I think it also has two dimensions.
First is, how can we, how can somebody enable potential customers from falling victim to those? And how to identify them in the first place? So that would be the end-user perspective. So can we really identify them? And the other part is, of course, the research that you are doing regarding the Fripp platform, that's help in identifying them before things happen, especially on a B2B use case, I assume. So how would that look like? How do these businesses actually look like? What are typical, call them use cases?
What are use cases that we should look for when protecting ourselves and other businesses from these rogue merchants? I guess the first thing would be, you know, if it looks too good to be true, it probably is. There are various scam detection sites out there and you can look up reputations, get reviews from others.
Of course, there's the problem of fake reviews too. And I think a lot of these rogue merchants use mechanisms to pump up their reviews to make them look more legitimate.
So, I mean, there's always a little bit of a gray area, but yeah, I guess I'd start with if it looks too good to be true, then it probably is. As you mentioned, the types of fraud, I think they vary very broadly. There is a wide range, you said, selling luxury goods or not selling them for a cheaper price, but getting to the money. Are there other business models, which there are, that are worthwhile knowing for the audience?
Yeah, that's kind of the entry level part. You know, then there are fake payment processors that act on behalf of many other rogue merchants. They will set up a legitimate merchant account and try to fool the large payment processing entities and then try to run lots of fake transactions for, you know, maybe a bunch of shell companies or things like that, that, you know, that are too not legitimate businesses.
So you have your fake merchants, your rogue merchants, and then you've got fake payment processors that are trying to scam banks and other entities within the broader financial landscape out of money as well. You know, and they can do, they can use these identities that they harvest from the consumer victims for lots of other kinds of attacks. They can use the basic information to create a fake account about a real individual. They can sort of take all the information and use it to build synthetic identities.
There are also businesses out there that are like running platform abuse, trying to defraud other members of the e-commerce ecosystem, you know, by say buying up a lot of goods and then trying to return them or saying that they didn't actually receive them. So there's just so many different permutations of how businesses can be defrauded by fake merchants, fake payment processors and scammers at large. Right.
So when we look into the research that you do, when we look at how to counter these activities, what are the typical technologies, the signals that are used for identifying these rogue merchants before anything can happen? So what are the technologies in place?
Well, I think at the individual consumer level, a lot of the things that happen within fraud reduction Intel platforms today are very useful. And we define that as six major categories of functionality.
There's, you know, device intelligence, identity verification, compromised credential intelligence, user behavioral analysis, behavioral bot, behavioral biometrics and bot detection. The combination of all six of those can be very useful at the individual level. You can look at behavior. Has this credit card been used in conjunction with a device or in a location that's not typical of that particular user? Is it being used to buy something that's, again, not typical of that user?
Those kinds of things can help legitimate payment processors and banks figure out whether or not this particular transaction is legitimate. Of course, that depends on having a lot of information about a user, and that can be problematic due to privacy regulations in certain areas to device intelligence, behavioral biometrics, you know, understanding how users interact with their devices. Both of these things can set off signals that might at least raise the risk level of a given transaction so that, you know, a merchant or a payment processor might see that they should take some caution here.
If you look at in Europe, for example, upcoming regulations or already existing regulations, they actually want to make sure that organizations take measures to identify these rogue merchants because they then would be part of the supply chain because you're using them for commercial purposes. And this is really something where DORA, NIS2, and Atisax, for example, in the automotive industry, really lay a heavy focus on to make sure that there's proper scrutiny applied when it comes to dealing with business-to-business partners.
So I think that's also really an important part for staying compliant, for proving compliance, that you say, OK, I have a mechanism in place that detects these or that signals these rogue merchants before anything can happen. Are there any examples? Because I cannot, as a German, as a European, I cannot think of very good examples of rogue merchants at scale. You've told me that there are quite some larger examples that you can talk about when it comes to really saying, OK, yeah, that is really an issue and it's nothing theoretical. This is costing money. Yeah.
You know, over the last five or six years, there have been some high-profile cases. One example might be Allied Wallet. It was a company that was doing a lot of this miscategorization of transactions. They used a bunch of different shell companies and designed fake websites to try to attract consumers. And then they passed these off against real payment processors. It was alleged in the lawsuit that they defrauded people more than 150 million dollars. So a pretty substantial amount of money, you know, probably the biggest one.
Actually, it was sort of a collection of somewhat related fraudulent patterns. It was back during the pandemic when the U.S. launched what they called the Paycheck Protection Program, which was designed to help small businesses especially get through COVID during the initial lockdowns. And I think we still don't know the full scope of the amount of fraud that happened there. People set up fake businesses and you've got money through different various government programs. About 800 billion was paid out through that program.
And some estimates are that more than 10 percent, maybe 80 to 100 billion or more, was fraudulently obtained by people creating fake businesses. And then at the same time, there was fraud against many states' unemployment funds. So really what happened there is that there was not nearly enough identity verification, both on the individual side or the business side. So I think that really highlights the need for organizational identity. Exactly.
I think that that would be also a solution for that to say, OK, there is a reliable, official, digitally secured mechanism for understanding this is the company that I'm dealing with, that I want to deal with. And it's actually the organization I wanted to be in touch with. So from a research perspective, you're covering fraud reduction intelligence platforms and, of course, detection of rogue merchants as part of your research. What is the status here? Is there an update to be expected? And is that also reflected in other areas of your research? Yes.
So right now, I've got two different reports related to fraud reduction until platforms that are in work. One is focusing on the finance industry. The other will more broadly look at merchants, e-commerce merchants. So that will probably be out in the early to mid-summer time frame, both of those.
But, you know, we're going to dive a little bit deeper this time on the CIM report, which we've done for years, too. The last time around, we got into a bit about B2B identity management and organizational identity will be a big part of that. But this time around, I think we're going to try to go a lot deeper because we're hearing more and more about concerns around organizational identity. And as supply chains grow and become more complex, organizations just need a higher level of assurance about the other organizations that they're going to be doing business with.
So, yeah, we we're covering it to a certain extent in the fraud reduction paper, and then we will go a little bit deeper the next time around on the CIM and B2B IAM organizationally. So, and you've mentioned that organizational identity just a few days ago, I've published a blog post to say organizational identity, why IAM must evolve beyond people, because if you're talking, this is a different type of identity and the number and the types of identities within an identity fabric is increasingly growing. And this time, it's really the identity of an organization.
So it says the name, but it's not it's not Matthias as a person, but it's Kupinger Coal as an organization that has an entry within the within state ledgers to say, OK, yeah, this is Kupinger Coal and they are identified as where they are and they have a CEO and they have representatives and Matthias is actually working for them and it's trustworthy. So that is the new type in air quotes of identity that we're talking about. But this is something that many organizations have done for quite a while. So what's new? I think it's the digital format.
It's the signature that's behind that digital signature. It's the verification aspect. So actually, what are the concepts behind that that you are looking for when you're looking for organizational identity verification in context of B2B solutions?
Yeah, there's so many different things that you can verify about businesses, too. And depending on where they're operating, you know, you might want to look at do they have a legitimate business license? Who are the authorized persons within that organization who can make certain types of transactions? Are those licenses still valid? Are there any complaints against them? And then are any of these people inside the organization or is the organization itself on some sort of sanctions list? And there are many different sanctions lists out there, too.
So I think we see now that that is becoming more and more important. And I did put quite a bit of emphasis on that in the first Fripp report on finance, being able to do sanction screening, politically exposed person screening and things like that. Like I said, a number of different sources that have to be checked and there are several different third party services that can be used to do that validation as well. So it's somewhat surprising that a lot of organizations still do that manually and that, of course, that is a lengthy process.
So there are legal departments, there are people that actually scan these documents and look them up and try to find maybe even by mail, by fax, by email to find these documents that are the proper proof. But it's 2025. It should be done differently. It should be done electronically. And there are services that provide that. So it's really something that you consume from the B2B platform as a service that is provided via an API, via a digital service. Am I right?
Yeah, exactly. It's API driven, given the fact that there are a lot of different sanctions lists and they do change from time to time. Trying to do it manually, I think, raises your own risks that you might miss something. So that's why I think these services can be very valuable. Right. I think you even save money when you say, OK, I don't have to spend weeks in verifying a larger customer, but I can do that within the fractions of a second in a digital format. But what are these components that are verifiable? What makes this interaction with the service provider reliable?
Where can I apply scrutiny myself to say, yeah, this is the result. And I know it's true because it's what happens, what happens when you want to verify that.
Well, you know, there's the I think it's the Global Legal Entity Identifier Foundation. That's something we've been tracking for a number of years now and really hoping that it kind of takes off more broadly to see businesses doing checks against that. A legal entity can obtain an identifier, which then makes it easier to do lookups against that particular LEI in different domains, find out more information about them. So this is kind of a verifiable identity, but for an organization in a digital format.
So even I know there's a first of all, the number that's assigned, but that's a number, a huge one, but not really user friendly. But there is a digital representation with a signature, which makes it possible to use it within electronic workflows to to provide proof in an automated way. I think that's that's the way to move forward. But as you said, it's up and coming, but it's not yet widely available. Or what is the current status of these LEIs?
Well, on the recent round of research, there are some of the vendors that understand and utilize LEIs as part of their ongoing services. But yeah, I would like to see it expand because we are in need of a global LEI registry and there is one available. And that's a great starting place from which to be able to do, you know, rogue merchant detection and other kinds of higher business level fraud. Right.
And if we look at these LEIs, EIDAS, as the European standard asks for verification, it doesn't ask for a glyph, but it asks for some some reliable verification of business practice as well or partners in general. I think that could or should also be a driver. We talked about that at EIC, that this is really something that is driving the development there as well.
And many of the participants also, just like you did, asked for contributing and for supporting this mechanism, these LEIs and VLEIs, verifiable LEIs, to get to even more critical mass to actually have this as a foundation layer for organizational identity. Yeah, I think it's a great starting point. And there's certainly much more that everyone needs to do in order to protect themselves against fraudulent businesses. Right. And if you look back at this, this organizational identity is not really new. There have always been organizations like Dun & Bradstreet earlier. They did that.
But having that A, at a global scale and B, digitally available via APIs, that takes more than yet one other step to achieve that. So we are not yet there. What are the challenges? What needs to be achieved?
Of course, broader usage. But are there other obstacles in the way to having this organizational identity as a commodity that just can be consumed?
Well, I think promoting awareness of it's a good place to start. The mechanisms that there are out there, like LEIs and other trends within fraud protection generally, maybe extending the kinds of coverage that we have for individual use cases and preventing fraud to the business level. But what are the problems?
I think, like you were mentioning, some of the older models that are still around are fragmented. So right now, if you're a global organization and you're doing business in multiple regions around the world, you've got to check with all these different countries and maybe municipalities within those countries, as well as those different sanctions lists. So there's just lots of different things that you need to check. And that leads to maybe omitting something that you should have checked or not having the most up-to-date information.
So as you were saying, I think the more that we can automate this, the more that we can make it comprehensive, call it through an API and get all the information that you need, the greater the risk reduction will be. We're used to verifying human identities, but also non-human identities at runtime again and again. So this is zero trust, always verify.
Usually, these checks for organizations are done at onboarding time and not very often afterwards. And I think especially if you think back to what you said, these rogue merchants, maybe they get detected and are no longer trustworthy. That would be a signal that you can receive and consume in your daily business processes. And that would be something that such an API can provide. And this is really something that also should be baked into such a cybersecurity supply chain risk management processes to understand what is going on with such an organization. So always verify for every transaction.
You might not want to do that for, I don't know, for Boeing or for Deutsche Bank, but for those who are not that well known or just came to your notion and you just make first business with them, maybe that's helpful to check them more often. I think that's important. Are there any other emerging trends in that area that we should consider when it comes to using organizational identity and organizational identity verification?
Well, to address the point that you just made and to kind of answer the question about an emerging trend is, yes, doing some sort of check at onboarding time is good, but we know from both the individual side of consumer fraud as well as the business side, fraudsters will set up accounts and then let them age, sometimes for very long periods. So if you do some sort of identity verification or organizational identity verification, they may sit on that literally for years.
So just because something was created and passed its organizational identity check 10 years ago, even may not mean that it's a legitimate organization today. So, yeah, I think knowing that definitely adds to the difficulty of doing organizational identity verification, but it's something we have to be aware of and try to mitigate. We need to understand that it's also just one building block. So if you think of it as B2B or a CIM platform, this is the building block that tells, yeah, this is A, a valid organization, B, it's well-represented, it's there, it has an account, it does business.
But then the association of a person with this organization is partially still a not yet solved problem to say, OK, yeah, Matthias is really working for KupingerCohle and John as well, although they are in different countries. Having that cross-border, reliable, digitally verifiable, there's a way to go, right?
Yeah, I think there's still a lot of work to be done there. You're right, combining individual verified identities and business identifiers is definitely an area for improvement going forward. Right. So this is the intersection of cybersecurity and IAM because it's identity at the end. And as we always say, all cybersecurity is somewhere around identities. And this time it's between organizational verification and the rogue merchant and preventing that. You've mentioned the research also will be done right now and will be out soon.
So B2B CIM as part of CIM, that is also, as you've mentioned, in the making and should be around somewhere here? Yeah, the first fraud reduction report will be out in the next month and a half or so on finance. The one on e-commerce will come early to mid-summer and then the CIM and B2B CIM will be out near the end of the year. Really interesting stuff. So this is really, as I said in the beginning, it's a bit scary that there is a full, not only businesses, but a full business supply chain from fake payment transaction processes to the businesses that use that. This is really, really scary.
But it's good to hear that there are means to counter that and to address these issues and for organizations to consume solutions that can help you in preventing that. Yeah, really interesting. Any final things that you want to mention around this area? Are there other developments that you're seeing that speed up things, that speed up adoption and make us looking more happily into the future that this can be prevented in the near future?
I guess I would say we have been aware of KYC, Know Your Customer, initiatives, and that's become much more embedded into products, specifically CIM kinds of products. Now we see a growing emphasis on KYB, Know Your Business, and trying to build that into products.
So, yeah, I expect some interesting results from the next round of CIM and B2B CIM kinds of use cases that we're going to be doing. Right. And B2B CIM and B2B partner management is a hot topic anyways. And so we need to get better there anyway. And then everything that we talked about today is a capability within that. We need to build upon that to, as you said, know your business or know the business of your peers. So thank you very much, John, for being my guest today, for talking about that interesting topic. I said EIC is over. It's no longer identity management. What was wrong?
It's identity management in the end, but a different type of identity management and cybersecurity combined. So really interesting topic and a real interesting market segment to watch also in the future.
As usual, if there are any questions around that topic, and it's not a new one, but we have not yet put that much focus on that, please reach out to John, reach out to me, leave a comment on YouTube in the comment section. We will pick that up. And if you are interested in learning more about that, I'll invite John back to this podcast and we have another episode digging deeper into the technicalities, into the processes behind that, maybe the business models for those who provide this information for these B2B platforms. Until then, thank you very much, John, for being my guest today.
And I'm looking forward to these reports. That sounds really interesting. And it's part also of my daily business. Thanks. Thank you. And see you soon. Bye bye.