Payment Fraud: What It Is and How to Fight It episode artwork

EPISODE · Oct 18, 2023

Payment Fraud: What It Is and How to Fight It

from Info Risk Today Podcast · host InfoRiskToday.com

In this episode of CyberEd.io's podcast series "Cybersecurity Unplugged," Alex Zeltcer of nSure.ai discusses how fraudsters access your payment information, how industrialized payment fraud attacks operate, and how nSure.ai uses discriminative AI to identify these attacks and cut their scale.

Episode metadata supplied by the publisher feed · Published Oct 18, 2023

Embed this episode

NOW PLAYING

Payment Fraud: What It Is and How to Fight It

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Welcome to Cybersecurity Insights, the podcast for the CyberEd.io learning community. Our goal is to bring Cybersecurity practitioners the latest and most relevant education and training to upskill and dive deeper into topics that matter in today's modern Cybersecurity world. Good day, everyone. This is Steve King.

I'm the managing director here at CyberEd.io. And on today's podcast, we have the pleasure of talking with Alex Zelser, who's the CEO and co-founder of nshure.ai. That's lowercase and uppercase S-U-R-E dot A-I. He's Alex is a digital technology advocate and pioneer with 20 plus years of I-T-E-R-N-D sales.

He's an active angel investor and has worked both as a founder and CEO multiple times. With nshure, he's leading the charge against chargebacks and helping global digital goods providers secure their high risk transactions from fraudsters. So welcome, Alex. It's a real pleasure for us to have you on the show.

Thank you very much, Steve. That's all mine. Well, thank you. Let's jump into payment fraud encompasses a whole range of deceitful activities and, you know, fraudulent parties are the objectives to gain unauthorized access to funds or work of transaction, what have you, and has been a continuous challenge for as long as I've been in this business for both traditional and digital commerce.

Can you give us kind of a payment fraud one-on-one? Yeah, sure. So payment fraud is something that happens when someone is using your payment information, your credit card information, your paypal information, your bank account information to try and steal goods online. That's the gist of it.

And there are various ways in which people can do that. They can either gain access to your payment information through buying lists on the dark net. They can take over an account you have. Either that's a paypal account or a bank account.

So there are various ways in which fraudsters can gain access to payment instruments that they can use. And when we say unauthorized, it means that it's not the actual owner of the payment instrument that is being used. And as a result of that, that's fraudulent and eventually the merchants have to deal with the chargebacks that relate to that. What we don't know is consumers, because as a consumer, we're always protected.

When someone is using our credit card, we see a line on our credit card statement that we don't recognize. And we call our issuer, we tell them, as we don't know that transaction, right? Or we take the button on the web interface and say, that's not us. We didn't do that.

And then we always get paid. We always get our money back. What we don't know is who actually pays the bill. And the reality is that if it's a brick-and-mortar transaction and payment fraud happens in brick-and-mortar as well, then the banks need to take care of that.

It's either the issuing bank or the acquiring bank to take the liability from that. If that was what we call a card not present transaction or something that has happened anywhere that is online, digital, sometimes even vending machines where there's no one to verify the card, then the liability lies with the merchant, which means if someone is using your PayPal information or credit card information to see that there are shoes at Nike on the Fifth Avenue, then it's the bank that takes the liability. If someone is doing that on Nike.com, it's Nike.com that takes the liability. And that's what payment fraud is all about.

Yeah, okay. That's pretty clear. And it has seemingly gotten far worse lately. And banks pretty much, I think, it feels as a consumer that they've kind of tightened up their filters and screens for what might be a non-elistic or unusual transactions.

Is that my imagination or is that reality? No, no. I think it's reality. And I think it shows that the thing that you're getting, that means that it creates friction for you.

Because when they approach you about something there, it's not necessarily a real transaction that was fraudulent. If the case was that every time they approach you, it's a really fraudulent transaction, every time they need to replace your card or do something about it, then it means that fraud has gone significantly higher. What they do, because fraud did go higher, is they create a lot of false positives. Every time they call you and everything's okay, it's actually a false positive on their system.

And what you're seeing now is, that's called the inability of a lot of the antiquated data, even fraud prevention platforms dealing with new types of fraud that emerge. Yeah. And what new types of fraud would include cryptocurrency, I imagine, right? Yeah, for sure.

Now, on crypto, there are different elements, right? There are different elements around crypto. And our experience on crypto in NFT is on what we call the fiat crypto side, right? So where you use a payment instrument that is using normal currency, like the currency that we all are familiar with, US dollars or euros or whatever, to buy cryptographic payment instruments, Bitcoin or neither, or NFTs on NFT marketplaces.

And the amount of fraud that is generated there is immense. We're seeing huge amounts of fraud there and very sophisticated fraud, because the attractiveness of crypto is very high for the fraudster. If you think about it from a fraudster perspective, primarily the fraudsters that do this as a business, what they do is, they go on the dark, they buy a list of stolen financial instruments, and then they need to turn that into cash, right? Because that's their return on investment.

So, and for them, imagine the difference for them between buying and reset. Once they got these, these payment instruments, they need to turn them into more cash, they need to buy and sell things. And you can imagine the difference between buying and resetting 1,000, 90 shoes or 1,000 iPhones and buying Bitcoin immediately turning and resetting it. And it's completely anonymized.

There's no way to construct the transaction. And it creates a huge incentive for them to adopt crypto exchanges, which is why crypto exchanges see such a significant fraud pressure. What is the current market value, if you happen to know this, of crypto currency globally? Oh, I don't know.

I don't want to know the number of changes every hour, right? Over a minute. I think that, you know, from our perspective, what we're looking at is this transaction. How much fee, how much standard cash is turned into crypto on a yearly basis.

And today, the numbers are staggering. It's somewhere between half a trillion and a trillion dollars a year. It's staggering now. It's staggering.

Yeah. Gosh. And so, how vulnerable is the digital wallet? You know, as part of the scheme here.

I mean, as part of the fraud scheme. Yeah. So, again, if we think about it from the thoughts of perspective, what they're looking for is they're looking for products or services or value that can be transferred immediately, that has no, you know, it's not delivered on a truck, but it's beats that go into a wallet or an email or a text message. And that they can, they can use in order to transfer the value somewhere, so can resell that value so that they gain the cash value for it.

That's what the fraudsters that do this business are looking for. So crypto is, you know, is one immediate assessment. There are others, right? Companies that sell gift cards are usually exposed to significant fraud pressures because of the same reason, because you can buy a gift card, you get it immediately.

It's a number. You can turn around, put it on eBay or on Craigslist and sell it. Yeah. And it's very easy.

So what happens to wallets is exactly the same thing. If you have a wallet that you can load with a reversal of financial instrument, with a credit card or with a bank account or with a PayPal account, and then you can take the funds from that account and put them in a different account, it creates the opportunity for fraudsters to do exactly that. So they would do that. They would create a wallet.

They would load funds into the wallet, get the funds in there, using a stolen credit card, for instance. And then transfer these funds immediately to a PayPal account that, you know, is completely untraceable and, you know, turn that into a prepaid debit card or whatever, and there go. So there's no controls and I say regulatory controls around the transfer, for example, of the cryptocurrency into fiat currency at that point. I mean, anybody can do that at any time.

No, no. So there are many regulations around it, but because the incentive is so high fraudsters find ways of overcoming that. So for instance, on the crypto side, a lot of the crypto exchanges today employ KYC, know your customer procedures, right? Know your customers is a term used in the financial industry.

Yeah. From a consumer perspective, it's when you were asked to take a picture of yourself plus your driver's license side by side, so they can see that, you know, that Steve is Steve, for example. And what we see today is that even though a lot of the crypto exchanges and the financial institutes employ KYC when people create accounts, because the value from a fraud perspective is so high, we see a lot of the fraud that is generated by accounts that were completely verified through KYC. And when you look closer into that, you see that these were people that were persuaded to go and create such accounts through either social engineering or simply, you know, we call them use, right?

They were persuaded to create that account and sell it to someone. And that someone is a fraudster. They're using that account in order to use their credit card to get funds in there, funnel them somewhere else. It was KYC that there's someone else's name and they're going immediately.

How prevalent is that? I mean, you know, we all understand that, you know, phishing and so forth is a very popular entry point for bad guys, but we never hear any, you know, and business email fraud also, but we never hear anything about about what you just described. I mean, are people doing that a lot? Yeah.

So the reality is that today we see more than 75% of the fraud of the charge but fraud that arrives at the crypto exchanges being generated by accounts that have gone through KYC. Wow. Then what's the work? Well, then obviously the work around is well known among the bad guy community.

Oh, yeah. Yeah. So why haven't there's no way to fix that from our side? On the KYC level though, there's once you are once you're trying to solve the problem through identity verification, you're going down a rabbit hole that is impossible to, it's a caps and robbers game that you cannot win, impossible to win.

Yeah. To win that is by tracking different patterns and identifying these anomalies. And you know, that's what companies such as ensure and others do. Very similar to what has been done, let's say a decade ago in cyber, a lot of the digital stocks that the digital stories distributed denial of service, and right, it's a wave of seemingly legitimate individuals that are actually representing one orchestra attack that happens somewhere.

This is something that the cyber industry has been coping with for decades. And we're now seeing in payment fraud being perpetrated on a daily basis. And we've got about 12 minutes left here. So I'm conscious of that.

I think we should let's devote the 12 minutes to how you guys use AI because that KYC issue, I'm assuming you have a product that addresses the vulnerabilities in KYC or no. So we don't really address the vulnerabilities in KYC. What we do is we do something different. We identify the anomalies and the behavioral patterns that are created by these orchestrated attacks by the machines.

What we came to realize is that in industries where the value for the fraudsters is so high, what they do is they create machines that attack these services. And these are industrialized attacks. It's not a person sitting in a coffee shop, you know, and typing like with a hoodie, like you see in the pictures, it's really, you know, it's a business. And they have machines and servers and they deploy code that attacks these types of sites.

And the only way to identify that is by identifying the group of people. And we're primarily utilizing AI for behavior analytics for that. When we say behavior analytics, all the people think, you know, you use behavior analytics to identify that Steve is Steve. All right, we see the way you are.

And we can relate that, you know, to other sessions that you have done. And we can see that it's the same behavior. But that's not what we do at ensure. What we do here is we look for patterns that allow us to connect different people or different sessions into groups of sessions in order to be able to identify them as the source of the attack.

And I'll give you, you know, I'll give you a simple example of that. Let's say we're looking at a crypto exchange. And there's, you know, there's a point that we look at how long you hesitate before you decide what kind of cryptocurrency to purchase. And let's say you, you know, you have two options, Bitcoin and Ether.

And you take, we see a consumer coming in and he takes him 13 seconds to decide whether he wants to invest in Bitcoin or in Ether. There's not a lot we can do about this one session. Now, a second later, some of us comes in and they hesitate for 13 seconds as well. Now that we can raise an eyebrow and say, okay, we don't know.

And but 15 seconds later, 30 people that have done that and hesitated for 15, for 13 seconds, you can identify that there's a group here by the fact that they behave similarly and then decide whether that group is for electronic or not. And then be able to cut the scale of the attack by, you know, by an order of money before it becomes uncontrolled. So that's the behavioral analytics that you're kind of monitoring and looking for is that's if you want to factor, I assume there's plenty more. Exactly.

So there are hundreds of thousands of such, you know, simple elements and because there are hundreds of thousands of them, the only way that you can work that is through machine learning models, right? It's impossible to put in rules that would work and create a decision at the end of the day on whether a certain transaction is for you or not. The only way for that to work is to drive all of that data through machine learning models that we've created that would eventually weigh the risk of every transaction. So it's really discriminatory of AI then not generally of AI, right?

Yes, it's algorithmic. I mean, it's an old math model, is it not? Yes, you can say to a certain degree, right? It's definitely not generative AI, right?

It's not something that creates something. It's something that tries to understand a pattern. It's like the AI we see that, you know, that looks at pictures and can tell you what it is or looks at images, looks at MRI and can tell you whether, you know, there's a tumor or no. That's the type.

That's what we do. We look at everything that happens on a certain site and we can identify, hey, there's a group of people here. They look fraudulent and we can first of all identify that there is a group and then say that the group is fraudulent. Yeah.

So in that, we go back to the simple example of 13 seconds for instance. So what does your engine tell you? Is it a normalization of the 13-second decision process and then it becomes kind of like your Bayesian or, well, becomes kind of a foundation in the decision tree or in anybody that is either above or below that becomes suspect? Is that kind of how that works?

Very, you know, very, I think in a high level, generally is. But the reality is a bit more complicated than that because what you need to do is you need to compare that to the normal behavior at that period of time. You need to identify the anomaly on that specific behavior compared to the normal behavior on the site. Because it could be the 13 seconds is an average number.

You know, everybody hesitates somewhere between 10 and 15. And 13 is not a big deal, right? But if everybody is taking a decision in two seconds or in 50 seconds and you find a group that does that in 13, it can help. Now, if the only thing you're looking for is how long they hesitate and obviously you're not going to catch a big chunk of the fraud.

Right. But if you're looking at hundreds of thousands of such very small elements and more than that it's compound because it's not only looking at a certain element, you look at three or four different features that are compounded together or three or four different elements that are compounded into a feature and you look at them over time and you look at them and then you classify. Right. It's a classification problem at the end of the day from much perspective.

Yeah. And without revealing, you know, too much of your secret sauce, but to help our audience better sort of understand this. Can you give us a couple of other examples that are similar to the decision process, the 13 second element? I mean, as you say, there are literally hundreds or thousands of these things.

What are other things that you might monitor? So there are other elements. Some of the elements are more trivial in nature. So, for example, are you, do we have a group of people now that are copy-pasting their passwords?

Right. One person that just copy-based maybe increases the risk to a certain degree. But if there is a group of people and it's an anomaly, then it's, you know, that it could be significant. Now, it's very easy to circumvent because, you know, good fraudsters would very easily singularly that you're keen in a password and not copy-pasting it.

But sometimes these type of features are helpful in identifying fraud. And again, they're only helpful not if you look at them on a transaction basis, but if you combine them together. So that could be an interesting, an interesting view. It doesn't have to be a password, right?

If you have anywhere that you need to put in data, are you copy-pasting or are you, or are you keying it in? That's one element. The other element could be a length of sessions in general, not just looking at, you know, at the how long you hesitate on a certain thing, but looking at the entire time it takes you to come in and come out of the site all the way through the session. And again, it could be that the feature that triggers it is the combination of how long you take you to hesitate plus how long was the entire session, right?

You know, it's a combination of things that would create that. These are the types, you know, if you're looking for, for simple examples of what are the things that you can look at from a behavioral perspective, that means these type of things. Yeah, sure. I get that.

So thank you. And in three minutes, you got to jump to a customer call, which is great. How many cuts can you reveal anything about your growth? So I can say that we're monitoring billions of dollars on an annual basis.

We're processing, which means we're providing decisions on over a billion a year, which is becoming a significant number. Okay. And how long have you guys been in business? Three and a half years.

And was much of that time developing the, and refining the algorithms and the, you know, sort of the whole predictive analytics puzzle. So the reality is that the previous company I was together with my partner here was a gift card marketplace. That's where we actually found the, we're exposed to the problem. And that's where we started building the tools and we saw how more are, how more accurate and how much stronger the tools that we've created are we decided to spread it out.

So the tools are actually based on the technology that we started developing in 2014. So there's been here for a while. And the team is the same team that worked up in our previous company. We've acquired the team in the technology to start it up.

But yeah, it sounds very cool. I'm, I'm happy you're doing that. It's a big, it's a big problem. It's a really big problem.

It's a huge, it's a huge problem today. Yes. So again, this is Alex Zeltzer, who's the CEO and co-founder of ensure.ai and Alex was kind enough to spend a half an hour of his time with us today. And we appreciate that.

And good luck with your customer call here in a minute or so. And thank you again for being on the show. Thank you very much, Steve. It's really my pleasure and I really appreciate the conversation.

That's great. And best of luck, Alex, to you and to our audience, thanks again for spending your 30 minutes with us today. And hopefully it was valuable information and a little bit of education around all the stuff works up. Until next time, this is Steve King, your host, signing off.

Thank you for joining us for another episode of Cybersecurity Insights. You can connect with us on LinkedIn or Facebook or send us an email at social at cybered.io For more information about the podcast, visit cybered.io or with slash podcast. Until next week, stay safe and secure, and we'll see you on the next episode of Cybersecurity Insights.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on October 18, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!