Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
Fraudology

Fraude en la entrega de comida: del comensal a la puerta de casa

38 min

Bienvenidos de nuevo a Fraudology.

Hoy me acompaña Sudhir Lanka, director asociado de Estrategia contra el Fraude en GrubHub. El equipo de Sudhir ya no se ocupa únicamente de GrubHub. Recientemente, su ámbito de responsabilidad se amplió para incluir a Wonder, la nueva empresa matriz de GrubHub, y a Blue Apron. Esto significa que ahora analiza el fraude en la entrega de comida en tres modelos de negocio realmente distintos a la vez, y quería profundizar en cómo esto cambia su enfoque en la práctica.

Analizamos qué hace que un mercado de tres partes sea especialmente vulnerable al fraude, ya que GrubHub tiene que proteger al mismo tiempo a comensales, restaurantes y repartidores, y cualquier brecha de protección en uno de esos frentes acaba minando la confianza de todos los demás. Sudhir explica los principales tipos de fraude a los que se enfrenta su equipo —apropiación de cuentas, fraude en los pagos, abuso de reembolsos y abuso de promociones— y ofrece algunos de los detalles más concretos y reales que he escuchado en este pódcast sobre cómo se produce cada uno de ellos, hasta las excusas exactas que dan los clientes para obtener reembolsos que no les corresponden.

Lo que escucharás en este episodio:

  • Cómo la trayectoria profesional de Sudhir en JP Morgan Chase, Discover y GrubHub moldeó su enfoque de la estrategia contra el fraude en cada etapa de crecimiento
  • Por qué GrubHub, Wonder y Blue Apron afrontan distintos riesgos de fraude en la entrega de comida, pese a compartir la misma misión fundamental
  • Los tres principales vectores de fraude que GrubHub monitorea —la apropiación de cuentas, el fraude en los pagos y el abuso de reembolsos y promociones— y cómo se manifiestan de manera diferente en cada línea de negocio
  • Un análisis detallado de la apropiación de cuentas de restaurantes, incluido cómo el acceso no autorizado al correo electrónico de un propietario puede provocar el desvío de un pago por ACH y obligar a GrubHub a realizar un costoso pago por duplicado
  • Ejemplos reales de connivencia entre repartidores y comensales, incluidos ciclos de autorreparto y un sorprendente abuso relacionado con las leyes de salario mínimo en ciudades como Seattle y en California
  • Por qué el abuso de reembolsos y el fraude de primera parte no pueden predecirse en el momento de la transacción, y el marco de Sudhir para implementar controles en el punto real de irreversibilidad
  • Cómo funcionan los controles antifraude por capas en las etapas de creación de cuentas, pago y posventa, incluida la autenticación multifactor, la autenticación 3DS, la validación del CVV y la verificación del PIN de entrega
  • La diferencia entre la fricción suave y la fricción fuerte, y por qué Sudhir reserva intencionadamente la fricción más fuerte para un porcentaje muy reducido de clientes
  • Por qué Sudhir considera que la estrategia contra el fraude favorece fundamentalmente el crecimiento, en lugar de frenarlo, y cómo proteger la confianza en todo el mercado se traduce directamente en ingresos

Deberías escuchar este episodio si:

  • Trabajas en estrategia antifraude en un marketplace, un servicio de entrega de comida o una plataforma que debe equilibrar las necesidades de distintos tipos de usuarios
  • Se enfrentan al abuso de reembolsos, al abuso de promociones o al fraude de primera parte y buscan un marco sólido para controlarlos sin depender demasiado de la predicción
  • Quieren comprender el fraude relacionado con la apropiación de cuentas de restaurantes y el desvío de pagos desde la perspectiva de la plataforma, no solo desde la del consumidor
  • Están desarrollando o perfeccionando controles antifraude por capas y quieren ejemplos concretos de cuándo conviene aplicar medidas de fricción leves y cuándo medidas más estrictas
  • Necesitan argumentos para defender internamente que la estrategia contra el fraude favorece el crecimiento, en lugar de obstaculizarlo
Notas del episodio

Tres líneas de negocio, tres riesgos diferentes de fraude en la entrega de comida

El equipo de Sudhir ahora se ocupa de GrubHub, una plataforma tradicional de reparto de comida en línea; Wonder, un concepto más reciente de cocina fantasma que ofrece distintas gastronomías desde una única ubicación física; y Blue Apron, un servicio de suscripción de kits de comida. Cada modelo de negocio presenta una superficie de fraude diferente. Un mercado de tres partes como GrubHub, en el que interactúan comensales, restaurantes y repartidores, tiene muchos más puntos de entrada para el fraude que un servicio por suscripción como Blue Apron, que suele enfrentarse a problemas más acotados, como la comprobación de tarjetas o la apropiación de cuentas.

El impacto del secuestro de cuentas varía según el lado del marketplace al que se dirija

La apropiación de cuentas de consumidores es el tipo de fraude que la mayoría de la gente ya conoce, pero el ejemplo más impactante de Sudhir se produjo en el lado de los restaurantes. Si el correo electrónico personal del propietario se ve comprometido, un estafador puede acceder directamente a la cuenta del restaurante y cambiar los datos de pago mediante ACH, desviando dinero real de una pequeña empresa mientras GrubHub sigue debiéndole al restaurante el pago original. Dado que este tipo de vulneración ocurre completamente fuera de los sistemas de GrubHub, Sudhir señala que a menudo no hay forma de detectarla hasta que el restaurante llama para informar de un problema.

El abuso de reembolsos no se puede predecir, por lo que Sudhir aplica controles en el punto de irreversibilidad

A diferencia del fraude en los pagos, el abuso de los reembolsos implica que un cliente real utiliza su propio método de pago, por lo que no puede detectarse en el momento de la transacción. El enfoque de Sudhir consiste en permitir deliberadamente que el pedido se procese y aplicar controles solo cuando el cliente muestra un patrón claro de abuso: decenas o cientos de reclamaciones falsas, no una o dos. Su marco general va mucho más allá del abuso de los reembolsos: hay que establecer controles en el punto en el que una pérdida se vuelve realmente irreversible, en lugar de intentar predecir un comportamiento indebido antes de que ocurra.

La colusión entre repartidores y comensales se manifiesta de formas sorprendentes

Más allá del caso más evidente de alguien que se hace pasar tanto por el cliente como por el repartidor para cobrar por su propio pedido, Sudhir describió una práctica abusiva más sutil relacionada con las leyes de salario mínimo para repartidores en ciudades como Seattle y algunas zonas de California. Los propios repartidores hacen pedidos de un valor ínfimo solo para cobrar la remuneración mínima garantizada asociada a ese pedido, aprovechándose así de una política concebida para proteger a los repartidores legítimos.

Controles por capas y la diferencia entre la fricción suave y la fricción dura

Sudhir divide su enfoque en dos líneas: una infraestructura a largo plazo diseñada para detener ataques importantes, como el relleno de credenciales y la creación de identidades sintéticas, y una línea de investigación a más corto plazo que se adapta a diario a los nuevos patrones de ataque. Se aplican controles antifraude por capas en cada etapa del recorrido del cliente: biometría del dispositivo y del comportamiento y autenticación multifactor al crear la cuenta; autenticación 3DS y validación del CVV al finalizar la compra; y verificación mediante PIN en la entrega, una vez efectuado el pago. Este último detalle me llamó especialmente la atención, ya que solicitar un PIN en el momento de la entrega añade fricción después de la transacción, cuando no puede aprovecharlo alguien que simplemente intercepte un pedido de comida en un lugar público, como el vestíbulo de un hotel.

Replantear la estrategia contra el fraude como una estrategia a favor del crecimiento, no en contra

Sudhir cerró con una reflexión que, en mi opinión, más responsables de prevención del fraude deberían expresar abiertamente. La estrategia contra el fraude no consiste en frenar el crecimiento, sino en proteger la confianza que, ante todo, hace posible ese crecimiento. Cuando los comensales, los restaurantes y los repartidores confían en que una plataforma les pagará y los protegerá de forma justa, siguen utilizándola, y eso se traduce directamente en ingresos.

Conclusiones clave
  • El fraude en la entrega de comida varía según el modelo de negocio: los mercados de tres partes, como GrubHub, tienen más puntos vulnerables que los servicios de suscripción, como Blue Apron.
  • La apropiación de la cuenta de un restaurante puede provocar el desvío de pagos mediante ACH, lo que genera tanto una pérdida para el restaurante como un costoso pago duplicado para la plataforma.
  • El abuso de reembolsos y el fraude de primera parte no pueden predecirse en el momento de la transacción, ya que el cliente utiliza su propio método de pago legítimo.
  • El marco del punto de irreversibilidad consiste en aplicar controles antifraude en el momento en que una pérdida se vuelve irrecuperable, en lugar de intentar predecir el abuso con antelación.
  • La colusión entre repartidores y clientes puede adoptar formas inesperadas, como aprovechar las leyes de salario mínimo mediante pedidos propios deliberadamente de bajo importe.
  • Los controles antifraude por capas deben aplicarse a lo largo de todo el recorrido del cliente, desde la biometría del dispositivo y del comportamiento al iniciar sesión hasta la validación del CVV al finalizar la compra y la verificación del PIN en el momento de la entrega.
  • La fricción moderada protege tanto a los clientes como a la plataforma sin afectar significativamente a los usuarios legítimos, y debe reservarse principalmente para ese fin.
  • Plantear la estrategia contra el fraude como una iniciativa que impulsa el crecimiento, en lugar de frenarlo, permite exponer con mayor claridad ante la dirección y los equipos multifuncionales los argumentos empresariales a favor de la inversión.
Conclusión final

Lo que más se me quedó grabado de esta conversación fue la naturalidad con la que Sudhir pasó de tres negocios muy distintos bajo un mismo paraguas a un único principio coherente. No se pueden prever todos los tipos de fraude antes de que ocurran, pero sí se puede decidir de forma deliberada el momento exacto en el que actuar. Ya se trate de abusos en los reembolsos, apropiaciones de cuentas o de un conductor que manipula discretamente una política de salario mínimo en su beneficio, la verdadera habilidad en la estrategia antifraude consiste en saber con precisión dónde se encuentra el punto de no retorno y establecer los controles justo ahí.

Recursos y enlaces del episodio

Conecta con Sudhir Lanka | LinkedIn
Director asociado de Estrategia contra el Fraude, GrubHub

Conecta con Karisse Hendrick | LinkedIn
Presentadora del pódcast Fraudology
Experta galardonada en fraude cibernético
Consultora en prevención del fraude en el comercio electrónico
Asesora de startups, conferenciante y
consultora para empresas de la lista Fortune 500

Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:07
Welcome back to the Fraudology podcast. I'm Karisse Hendrick and I am really looking forward to my conversation today with my guest Sudhir Lanka. Sudhir is the associate director of fraud strategy for GrubHub. I have uh only recently gotten to know him but really enjoy our conversations and I think you will too. So, Sudhir, welcome to Fraudology.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
00:31
Hey, Karisse. Uh, thank you. Thank you for having me on the podcast. Uh, really excited to talk to you today.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:39
Me too. So, the first question I ask every guest on Fraudology, you know this uh because the answer is always different. How did you get started in fraud?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
00:51
Um, actually, you know, almost 13 14 years back. Um, you know, I just graduated from my college and um, to be honest, I was just simply looking for a job at that point and uh, I looked at the the job at JP Morgan Chase risk analyst and I found it interesting and I applied for it. I got the job um, you know, fortunately and uh, ever since then for 14 years I've been in the fraud world. Um, I got hooked onto the fraud world. It's very interesting, very intriguing. So I just I just been here forever now.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
01:28
And after uh being an analyst at JP Morgan Chase, you went to Discover. Is that right?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
01:35
Yes. Yes. Uh after JP Morgan Chase, I think I've been there for about 2 and a half years and then I moved on to Discover. Um again, same transaction fraud strategy team at Discover. Again, um kind of my my scope expanded a little bit. I covered uh both card present and card not present, transaction fraud. Uh you know I was kind of working on building you know uh crossover risk profiling, trying to understand how does fraud happen on card not present, how does it differ from card present. Um you know um you know I believe you know this is where discover is where I got a really good hold of uh what is fraud like, how does fraud happen, how fraudsters adapt, how do they attack at scale, and what do we do as as fraud strategists, right? You know, how do you counter attack, right? And uh yeah and And you know that's that's what I did at Discover at that point. Yeah,
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
02:28
That had to be interesting from the issuer perspective. The issuer and card brand perspective. Uh and really gave you a 10,000 foot. It sounds like it gave you more of a 10,000 foot view than being a transaction analyst at JP Morgan, which makes perfect sense. Uh and helped you see like, okay, this is how all the pieces go together and this is the bigger picture. Um, which you need for fraud strategy. Um, to be able to know not only what the pieces on the on the board game are now, but what they will be in several months and you know, okay, they're doing this now, what are they going to be doing soon so that we can get tools in place to counteract that.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
03:14
Yeah, absolutely. You know, I I feel that, you know, there's like um you know, uh possibly two things involved here. The first is um uh you know, once you gain some sort of experience, let's say you're 2 or 3 years into the into the fraud world, you try to, you know, you you start putting pieces together. You talk to a lot of different teams. You know after I came to discover I started speaking to the fraud operations or you speak to the chargeback management team or or you talk to you know account takeover team. Like there's there's a lot of different fraud vectors that we deal with, right? So sitting with everybody, speaking with everyone, you know um constantly talking to your leaders uh give me that 10,000 foot view you're talking about. And secondly uh companies like discover like you know specifically banks let's talk about them, right? They already have established process processes and SOPs and you know you know what you're dealing with. They've they've had they had they laid out everything um exactly how fraud needs to be handled, uh how much they are losing, uh what are the regulatory requirements, and everything is laid out. So you have, uh I would say, relatively an easy path to learn uh quickly. Uh uh so that actually helped me a lot um you know at discover. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
04:31
Yeah and then after Discover you went to GrubHub
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
04:35
Yes. Yes, that's where I am right now. GrubHub, uh, GrubHub has been, you know, has been great to me. Um, I've been here for about, uh, 5 years, almost 5 years now. Um, I'm currently leading the fraud strategy function um, at GrubHub recently, actually my team has recently expanded the scope to include Wonder and Blue Apron as well. So, we have three business legs under us now. Um so for anybody who doesn't know GrubHub has been acquired by a company called Wonder last year. So now we have um Wonder as a parent company and then we have GrubHub and then Blue Apron as well. So we're looking at all three business lines at this point.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:16
Wow.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
05:16
Uh so I lead the fraud strategy function end to end diners merchants and drivers. Uh pretty much looking at uh a wide variety of fraud vectors. Uh, at this point I'm I'm currently doing that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:29
That's a big job. Um, I'm familiar with GrubHub and Blue Apron, though my listeners are international, so they may not. Uh, I'm not familiar with Wonder. So, could you share just a little bit about each of those companies because I think they're while they're similar, they're also unique.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
05:49
Absolutely. They're 100% unique. So, Wonder is is relatively a new company, I'd say, compared to GrubHub. Um um so they are predominantly concentrated more in in the east coast of the of the country more in New York and uh you know Connecticut and all that. They're expanding to you know Wonder is expanding to Texas and other states as well in the coming years. But um what Wonder does is they have physical stores uh like you can consider them more as cloud kitchens or ghost kitchens. The unique concept of wonder is you go to a wonder store and you're going to find food from every single cuisine that you can think of. In one store, you can order Indian, you can order pizza, you can order sushi, you can order Mexican, any different food that you can think of. Uh, you know, Wonder offers that, right? So, that's the unique concept that Wonder has come up with. And um and uh Grubhub is is like a it's like a traditional online food delivery platform. Um it's it's a you know it's a it's a well-known company similar to a lot of businesses across different countries as well. And coming to Blue Apron, Blue Apron is a is a meal kit service. So you just um you know um you know figure out okay what do you want to cook? They deliver raw ingredients uh to your house planned out weekly and you can you can kind of uh use them as more of a subscription service at this point. Uh but um but the what Wonder wants to do um as a whole as a parent company is to become one-stop shop for all your food needs. Uh you want to order raw ingredients, you want to order online, you want to go to a store, you want to order any cuisine that you want, it's all in one place. And that's that's what Wonder is trying to do at this point.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:38
Wow. That's that's quite a goal. And yeah, it's uh the the through line is obviously feeding customers, right?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
07:48
Absolutely.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:48
Uh but they have different business models and with different business models come different fraud risks.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
07:54
Oh, 100%.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:55
Right. What you would have what you would see for traditional food delivery from a restaurant. You know, it's kind of a three-sided marketplace or four-sided marketplace. What do you consider it?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
08:08
We consider it as a three-sided marketplace.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
08:11
Right. Right. And as you mentioned, you have you have the uh customer who orders the the meal, you have the merchant that makes the meal, and then you have the driver that connects the two and brings the meal from the merchant to the consumer. So, you know, whenever you have whether it's two-sided marketplace with a buyer and a seller or three-sided in this case, uh I just didn't know if you considered yourself a a fourth part of the marketplace. That's why I was it was like I Yeah, some companies do and so they're like we're from a three-sided market. I'm like but are you you just have buyers and sellers and they're like but we sit in the middle. So um that's why I was asking. But um yeah that has such unique challenges because there's opportunities for fraud on all three of those, you know, sides, right? Um whereas a meal delivery service that runs on subscriptions is going to have a different type of fraud. You know, they're they're not going to um have as many opportunities for fraud as many channels or or sides. Um but you'll probably see some card testing or you'll see some account takeover or that type of thing. Um y what what are the type of fraud vectors or how do you define fraud at GrubHub or Wonder I guess?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
09:36
Yeah, absolutely. Now you know you know sometimes it's it's confusing not confusing but you know we keep thinking should we call ourselves Wonder or GrubHub but there still but it's just you just get confused. But uh but uh but yeah uh talking about fraud right you know, when we when we say fraud I'm like you know what what my team deals with. Um it's not a simple um fraud fraud that everybody knows of right. So what we deal with is um fraud is one aspect of it. We also deal with abuse. We also deal with any kind of scams uh um you know any internal fraud anything that happens end to end uh perpetrated by anybody on the platform right. So when we say fraud it can be uh the primary ones that everybody knows about is ATO what we call account takeover uh is the primary one obviously. And second is uh what we call the um stolen credit cards or stolen payments let's let's call it stolen payments at this point. Um these two are the primary crime vectors that we see um on GrubHub um and I'd say I'd extend it and say Wonder and Blue Apron as well. Similar fraud vectors is what we see. Okay. And talking of talking about abuse, um we do see a lot of refund abuse, right? Uh some companies call it as returns abuse. You know, in the food delivery platform, it's technically it's refund abuse. You cannot return your food. So, it's it's refunds of course. So people uh order the food, they take the food, they eat it, and then they call and they call the bank and say that I did not receive my my order or they call GrubHub and claim that they did not receive it, right? Or they'll make up like thousands of reasons to get a refund. Uh
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:17
The the meat was bad or the you know like
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
11:21
There's so many things that they can
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:23
Yeah. Yeah. The driver ate my food. I've heard that one. And I've heard uh um you know, I got food poisoning from this or I got I got the mo I got the cheapest item, but I didn't get the most expensive item, right? Like I got I got the soda, but I didn't get the steak dinner. Uh so I need a refund on that. Like those are just some examples of what you mean by by refund fraud.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
11:50
A refund abuse. Yes,
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:52
Refund abuse. Yeah, absolutely. Mhm.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
11:54
And uh and the third major one that we deal with is the promo abuse. Uh when I say promo, it can be uh a marketing promotion or it can be a a a credit that you received from uh from our customer care team. It can be it can be either way. You basically got a credit or a promo on your on your account and then just you're abusing it uh by creating a loop of your own accounts. You're referring to yourself, let's say, for example, or um or you're going to Google and you're trying to um you know, exploit the the marketing uh you know, promotions that we have on Google or any any online website as well, right? So, that's the promo abuse we're talking about. Uh and that is the third uh primary vector that we deal with at this point. And I'd say that, you know, it's it's pretty similar um across the three business lines at this point. Um same fraud vectors you see you know um on some on on one side you might see fraud is higher on one side you might see abuse is higher but still pretty much the attack patterns remain the same. Um one additional point or one additional insight we want to add here is that uh all we're talking about right now is more on the customer side right. There's also another a whole vector of fraud that we see on the merchants and the driver side as well right. So we see similar you know um uh merchant accounts being taken over on merchant or the restaurant when when I say merchant it's the restaurants owners being socially engineered to reveal their personal details. Um their payment methods or the ACH linked on the on the on the restaurant portal is replaced by fraudsters uh bank information and money taken out and and there's so many other fraud vectors that we deal with on the driver side as well but um, but it's huge. It's It's huge. And there's there's a lot of lot of things that we're dealing with at this point. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
13:50
Yeah. I would imagine with that example you just gave as far as account takeover on the restaurant side. I mean, especially for a busy restaurant, you're probably talking about thousands of dollars that GrubHub will be paying out via ACH to that small business, that restaurant. And if the restaurant owner is socially engineered to give up their, you know, GrubHub password or there's spear phishing emails or things like that and they, you know, are asked to log into GrubHub, but it's a fake, you know, website. They then automatic very quickly the fraudster goes in and as you said changes the payment method uh or the payee basically um you know changes the bank account that GrubHub is paying the restaurant and now the fraudster is getting that money and not the restaurant and that can really disrupt business and be really scary. And then on top of that, you know, the restaurant is looking to GrubHub to pay them again, right? I mean,
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
14:53
Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
14:53
Right. Right. I mean, they didn't get the money the first time, but on your end, it looks like a double payment. Uh, so that can get very expensive even though your AOV, your average order value is, you know, I mean, you don't have to tell me, but I would guess, you know, $50 to $100.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
15:11
Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
15:12
You know, that's, you know, in payment fraud, in credit card fraud, that's $50 to $100, you know, each time it's stolen, which adds up. But driver ATO or uh, you know, restaurant ATO is the risk is so much higher because the amount is so much higher.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
15:32
Oh, 100%. Yeah, absolutely. You know, um, you know, I just remember one thing as you as you were as you were talking about this, right? Um, one one scenario that that that I've seen happen again and again is um restaurant owners personal email address and password are compromised a lot of times. And when that happens um it's it's extremely difficult for even for a company like GrubHub to do uh to do anything about it, right? Because we don't know what's happening. It's it's everything that's happening. It's external. So we actually don't know until they call and complain that hey this happened or something you know any any kind of alerts that we receive until that point we don't even have any data to to say that hey there's something wrong with this, right? So those kind of scenarios hit the hardest, the reason being our small business restaurant owners are being impacted by this. And um and um that's that's much more impactful for for for a company like GrubHub is uh it's it's important for us for as as a company and a fraud team to protect our restaurants as well because that's what keeps our supply like that demand and supply chain going on, right? So it's it's very important important we take care of that as well. Yeah. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
16:53
Yeah. You need all three of those pieces in the marketplace to be thriving and happy and you know producing. You know, you've got three sides of the marketplace and you've got the consumer and the driver and the merchant. If one of them isn't paid or paying, then it falls out of balance and the marketplace doesn't function.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
17:18
Yeah, absolutely. I think it's it's very important to maintain that balance. Um not like you know, of course, the the main um you know, reason for that is like the end goal is to kind of maintain that balance of that supply chain. Now you have diners coming in and ordering, restaurants fulfilling the orders, and you need to have enough number of drivers to fulfill the orders themselves, right? But um but but you're right. I think it's important to take care of every single party in this cycle. Um you know um you know to ensure that drivers are getting paid fairly uh protecting merchants, we're protecting diners um you know from any you know fraud attacks. Um um absolutely I totally agree with that. Yeah. Hm.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
18:00
You know, do you ever I know a lot of times on marketplaces, whether two-sided or three-sided, they'll have some kind of collusion occur um between the buyer and the seller, or in your case, it could be the driver and the restaurant or, you know, maybe the customer and the driver or, you know, whatever. Um is that something that you've you've had to experience recently?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
18:24
Yeah, absolutely. You know um we do see collusion you know although it's not it's not as extensive as as a single party fraud let me say that. But we do see instances of collusion happening as well uh predominantly what we see is um you know diners and drivers colluding uh colluding sometimes um to to kind of create a fake loop of ordering in the sense that the the the same person could be posing as a driver and a driver and they're they're potentially accepting their own orders to create a fake loop um just to take the the driver pay um from GrubHub, right? So that's that's the net loss that the company is going to have. But in reality, the the same person is ordering and they're they're getting they're they're basically picking up their own goods, right? Um so that is that is one um one way we saw collusion. And in uh um in some cases what we see is um you know um diners do come in and u you know place uh like really low dollar orders like uh let me say like a sauce packet or like um something else which is like a a dollar or a $2. Um this we see this specifically happening in um in locations like you know Seattle or California where there's like minimum wage laws that are in effect that you have to pay a certain amount to drivers who are on on like on on this and like actually actively deluding at that point. Um so drivers sometimes do kind of exploit this you know of course it's a very small percentage of drivers not you know of course vast majority of them are of course good drivers that we have
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:04
Right
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
20:05
Um they're simply kind of um you know placing this $1 order and then just taking out the driver pay, right? Uh so that's that's kind of uh you know that fake loops and um you know exploiting the uh controls or the exploiting the laws which have been which have been put in place to protect genuine divers are being exploited. Uh um so those are the you know those are some of the scenarios that we see in terms of collusion um at GrubHub mostly. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:34
Huh interesting. I wouldn't have thought of the drivers but then again I wasn't thinking about the laws in place in California and the Seattle area about drivers. Um, I would have thought, you know, when I was thinking collusion, I was thinking the first scenario you said when a diner and a driver are the same person.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
20:56
Yep.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:56
And they're, you know, trying to do money laundering or they're using a stolen credit card um to place the order, get the food, and then they're the same person, you know, the same person is getting paid to deliver it to themselves, basically. Um,
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
21:16
Yep.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
21:17
That's what it Yeah, that's fascinating. So I mean without going into too much detail um obviously because this is on a public platform uh when you're looking at controls to put in place for these types of frauds whether it's account takeover or uh payment fraud or refund abuse. Uh what are you looking for in controls and um you know what are your goals there?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
21:47
That's a that's a good question actually. So to think about the way the way I think about you know placing controls right you know um this there's two ways. First is you need to have um long-term infrastructure on your platform to protect your platform from um from any of these major attacks that we see all the time. Right? So when I say major attacks, it can be in terms of credential stuffing uh like where you see thousands and hundreds of thousands of login attempts coming in within a matter of minutes. Um uh or you have thousands of synthetic identities being created on your account or um um um you know significant amount of account takeover happening at the time of order placement. To counter these kinds of attacks, you need to have long-term infrastructure in place where you where you have something like um a multifactor authentication or you have something like 3DS or or or or you have something like a photo verification at the time of drop off uh to ensure the the order is actually being delivered. Um you need to have all these things in place, right? And the second track, the way I think about it is more of a short-term or let me say more like a a daily investigative track is something that you need to have um where you have your set of agents or your set of investigators uh going in interactively uh looking at okay what's what's happening today what's what's out there what are the new trends or new attack patterns that are coming out, uh and uh and how do we stop it, right? Um that's the way I think about it now. Um talking about like more from a end to end perspective, right? Um at least at the the the way I've I've worked so far is to have uh layered controls, right? I'd say that fraudsters are best if they're not on your platform, right? Obviously, so you you want to stop them at account creation or login at most. It's probably always the best option that you can go with. So you need to have really really strong controls at that point. You're talking about uh risk scoring. You're trying to figure out their their device information. Uh where are they coming from, their location, their behavioral biometrics, um any of these controls, you need to kind of uh you know um um you know consolidate all these signals and build something at the account creation or login stage. And then obviously you're going to have something at the checkout phase or the order placement stage as well where you have real-time decisions being made on each single order or transaction. Right? You you either say that you want to accept the order or you want to reject it or you want to send it to 3DS or maybe you want to do an internal OTP just send out an OTP to customers phone number um or or you do something else you do a CVV validation. Uh there's a lot of different controls you can place, right? Uh and then you talk about, and then the other set of controls I strongly suggest, um, is post order order placement, right? So once customers have actually placed the order, you need to have a set of controls monitoring, more, this applies more for refund abuse I'd say. Um the way the approach that I have taken is I generally do not want to reject anybody suspected of refund abuse
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
25:17
Right.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
25:18
Um I I do want to take their order, right? And um and
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
25:22
They're using their own payment method. It's them right.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
25:25
Yeah. And then you you deal with them once the order is completed. Uh and they call you and say that, hey, you know, something is wrong with my order, right? Obviously, you want to protect your good customers and if they really do have, you know, a few orders that they have had bad luck with or bad experience with GrubHub, obviously they're going to get a refund. But if if you find somebody abusing your policies like hundreds of times, tens and hundreds of times, you do want to place a control to say that hey, you know, you know, we think, you know, you crossed the threshold of what we call as abuse and we're going to not give you a refund or we just give you a credit or something like that, right? So, kind of having this layered controls is is what I think works best. Um, at least that's what I've seen in in in in our case. Um um and and you know that's that's generally my approach in you know implementing any kind of control.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
26:20
I like the way you put that because I've I guess I haven't ever thought of it in that way in the two different ways but there's the infrastructure piece. There's the, you know, the systems that you put in place for transactional monitoring and account protection and um all of that. And a lot of those things can be done behind the scenes so they're not impacting the good customers. Um and then there's also that additional piece where it's almost like I'm trying to think of the right term. So, it's not like firefighting necessarily, but it's a little bit more like you've got these levers and these and these systems that you can, you know, dial up or dial down or, you know, you can add something in place like maybe, you know, and I don't know this to be true, but I know this to be true for your overall industry that, you know, for several years the picture of an item being delivered wasn't required. Um but then refund abuse you know came up and uh that was you know really uh painful financially. And so, you know, as an industry, your competitors and yourself, uh, made decisions at different times to, you know, store those pictures and do all that you have to do with those photos to be able to prove delivery happened and that, you know, the the item wasn't the bag wasn't opened or, you know, that whatever you need to prove. Um, and then I know more recently I noticed when I was traveling um, a couple of weeks ago I I didn't use GrubHub because they weren't super big in the city I was in, but I used a competitor and they required me to use a PIN, you know, to give the driver a number because I was, you know, outside of a hotel and anyone, it wasn't just a residential house. Um I had to give them a four-digit number in order for them and they had to enter that number and into their system and they didn't know what it was. They just had to enter the number I gave them um in order for um me to get my order. And so that that is one of those things, you know, the the systems and controls that second part where okay, we're starting to see this trend. We need to go this route and maybe we need to implement something new like PIN numbers. Maybe we need to um you know dial up our controls on two-factor authentication. Maybe we're you know we're doing more of that. Um same with like account takeover. There's also, you know, with ATOs, there's the ability to, you know, look at device and say, is this the same device that has logged into this account always or is this a new one? Um, yeah. So there's all different. I I love nerding out on fraud strategy because uh it's the methodology is similar but the solutions are a little different depending on the business model of the merchant right
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
29:45
Agreed. Yep. Um you know you're you're absolutely right. I think you know depends on the type of merchant and the type of business that they are operating in uh for a company. Like for example just taking some name for example somebody somebody like Best Buy right they they sell like high value items and is compared to GrubHub it's just the business is different and the kind of controls that you please has to be different. Uh and I you know what you mentioned earlier as well in terms of pin verification or you know these kinds of controls um this is more of a softer friction that we're talking about. We're placing we're placing friction but it's it's soft and we are giving a chance for customers to go through, right? Uh we're just doing this to protect the customers and in turn protect the platform as well, right? So, it can be in terms of, you know, entering a PIN. It can be uh as simple as say CVV validation. You just enter your your card details once more, right? We're just not asking you to do much here. Um this this this helps protect them as well company and a lot of hassle. Um right so you know we generally try to approach a lot of these problems with, of course, obviously we just don't want to do any friction but if we have to we go with softer friction. And a very very very small percentage of customers do get hard friction, right? And and you know I believe is it's it's necessary for some customers or a cluster of customers to have that hard friction. It's absolutely necessary in this in this business so Yeah,
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
31:23
I agree. I actually haven't ever heard the term softer friction, but I like it. Uh, the thing I was thinking about the PIN when you were talking about it just a minute ago was it's very smart because not only are you asking for it at the time that fraud would occur, right? You know, if someone else was staying at my hotel and they saw a food delivery guy standing outside, they could just say, "Oh, that's my delivery." and and get it. Um, so it's at the time that like some kind of fraud could happen and then I would be saying, "Ah, I didn't get it and I need my money back." And all that. Um, but also the transaction has already occurred. So, you're not you're not giving them friction before they pay you. You're giving them just a little bit of light friction. You know, at the time of delivery after you've been paid, which I think is really smart. You're not, you know, that that's something that you've done in all that you've said today.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
32:23
Mhm.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
32:24
That's something that I appreciate. I have seen some companies in my perspective make mistakes when they try to identify a certain typography of fraud prior to the fraud taking place. So what I mean by that is if it's not payment fraud, then you can't predict it at the time of transaction, right? You can't predict firstparty fraud at the time of transaction because it's the person using their own card. You can detect first party fraud when they're making the claim or when they file the chargeback or you know that's when the the act of fraud occurs. Um, you can't predict. Yeah, you can't predict refund abuse at the time of transaction either. You can't predict, oh, they're going to claim that they didn't get their food. Um, unless they've done it 36 times before on their same account. Well, then that's a little different. But we know that especially in the day of age and age of it being relatively simple to create online accounts for different apps and and services. You know, if they're denied on their 36th time or their 10th time or whatever it is, they'll just start open up another account. So, instead, let's do it at the time of uh where the compromise occurs or where the um you know, the kind of the the point of um compromise, not the point of compromise necessarily, but like the um the point that the loss occurs or that the claim is made or whatever else. I like that a lot.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
34:06
Absolutely actually the uh no another way to put it put that is you place control where you think the loss is going to be irreversible, right? So if you got fraud, if you let it past check out, you're not going going to get it back, you have to pay for it, right? For refund appeals, you can wait until they call you for asking for a refund and then do something about it, right? So figuring out that point of irreversibility is the is the important thing here, and then place the controls based on that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
34:42
You just made that sound so much smarter than I did. I like that you just took it very succinctly and yep that's exact. You're right. It's where it's irreversible. Um it's where it's identifiable and irreversible. I like that a lot. Well, Sudhir, we are um about at time and I want to make sure I respect your time because you're so busy, but um I wanted to just first ask you if there's anything else that you wanted to mention uh about anything that we talked about today.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
35:16
Um nothing specific about what we spoke about today. I'd say that, you know, um I generally I generally say this to you know, most of the folks that I meet is um you know, a lot of folks perceive fraud or fraud strategy as anti-growth. Uh and I want to I want to emphasize that it is not. It is actually I want to say that it is progrowth because if you want to spend your money wisely, you need to take out bad customers and you you spend the money but you want to give it to good customers who will come and order on your platform. You want to retain those customers, right? So I I I generally tend to say this to a lot of folks is that changing that mindset is is important. Fraud is absolutely absolutely necessary in almost every company. I want to say um and uh but yeah but yeah I think that's about it.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
36:14
For a long time I went through this phase of saying that we should try to rename our industry from fraud prevention to revenue retention. Uh it didn't really stick but uh but I get what you're saying. It's the mindset of no we I'm pro growth. I want to support growth. Um and you're also pro trust. We didn't talk a lot about the trust and safety aspect, but when your customers and your uh restaurants and your delivery drivers can all trust you to pay them or to give them their food that they paid for, you know, whatever that is for their their peace, they'll use you more and that turns into more revenue.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
37:01
Yeah. Absolutely. Mhm. Yep. Yep. Totally agreed. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
37:05
Well, I'd like to also mention that Sudhir is going to be at Merchant Fraud Alliance soon uh in Chicago, October 6th and 7th. I have mentioned the conference on almost every episode recently, but um it he will be uh facilitating a Merchant only discussion on refund abuse and um I think it'll be really uh really impactful for the merchants that are having those issues. Um, so if you're going to MFA as well, uh, make sure you say hi to Sudhir. If, uh, you haven't planned on yet, make sure you get your ticket, merchantfraudalliance.com. And Sudhir, I'm looking forward to seeing you in person in just a few weeks.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
37:49
Yeah, absolutely. Looking forward to seeing you as well. We never met outside, but absolutely looking forward to seeing you. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
37:56
Yeah. Only through the computer.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
37:58
Absolutely.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
38:00
Well, I assure you I have I have legs. I'm a you know, you could never see anyone's legs on Zoom. So,
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
38:07
Yeah, absolutely.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
38:08
Oh, well, um I look forward to that and thanks again. I really enjoyed our conversation today.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
38:13
Yeah, me too. Me, too. Loved it.