Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
Fraudology

Food Delivery Fraud: From Diner to Doorstep

38 min

Welcome back to Fraudology.

I'm joined today by Sudhir Lanka, Associate Director of Fraud Strategy at GrubHub. Sudhir's team doesn't just cover GrubHub anymore. His scope recently expanded to include Wonder, GrubHub's new parent company, and Blue Apron, which means he's thinking about food delivery fraud across three genuinely different business models at once, and I wanted to dig into how that actually changes his approach.

We get into what makes a three-sided marketplace uniquely exposed to fraud, since GrubHub has to protect diners, restaurants, and drivers all at the same time, and a gap in protection on any one side eventually breaks trust for everyone else. Sudhir walks through the primary fraud vectors his team deals with, account takeover, payment fraud, refund abuse, and promo abuse, and gives some of the most specific, real-world detail I've heard on this podcast about how each one actually plays out, down to the exact excuses customers give to get a refund they're not owed.

What you'll hear in this episode:

  • How Sudhir's career path through JP Morgan Chase, Discover, and GrubHub shaped his approach to fraud strategy at each stage of scale
  • Why GrubHub, Wonder, and Blue Apron each carry different food delivery fraud risks despite serving the same underlying mission
  • The three primary fraud vectors GrubHub tracks, account takeover, payment fraud, and refund and promo abuse, and how they show up differently across business lines
  • A detailed walkthrough of restaurant account takeover, including how a compromised owner's email can lead to a redirected ACH payout and an expensive double payment for GrubHub
  • Real examples of driver and diner collusion, including self-delivery loops and a surprising exploit tied to minimum wage laws in cities like Seattle and California
  • Why refund abuse and first party fraud can't be predicted at the time of transaction, and Sudhir's framework for placing controls at the actual point of irreversibility instead
  • How layered fraud controls work across account creation, checkout, and post-order stages, including multifactor authentication, 3DS authentication, CVV validation, and delivery PIN verification
  • The difference between soft friction and hard friction, and why Sudhir intentionally reserves harder friction for a very small percentage of customers
  • Why Sudhir sees fraud strategy as fundamentally pro-growth, not anti-growth, and how protecting trust across the marketplace translates directly into revenue

You should listen to this episode if you:

  • Work in fraud strategy at a marketplace, food delivery, or platform business balancing multiple user types
  • Are dealing with refund abuse, promo abuse, or first party fraud and want a real framework for controlling it without over-relying on prediction
  • Want to understand restaurant account takeover and payment redirection fraud from the platform's side, not just the consumer side
  • Are building or refining layered fraud controls and want concrete examples of where soft friction versus hard friction actually belongs
  • Need language to make the case internally that fraud strategy is pro-growth, not a blocker to it
Episode notes

Three business lines, three different food delivery fraud risks

Sudhir's team now covers GrubHub, a traditional online food delivery platform, Wonder, a newer ghost-kitchen concept offering multiple cuisines from a single physical location, and Blue Apron, a meal-kit subscription service. Each business model creates a different fraud surface. A three-sided marketplace like GrubHub, with diners, restaurants, and drivers all interacting, has far more entry points for fraud than a subscription-based service like Blue Apron, which tends to see more contained issues like card testing or account takeover instead.

Account takeover hits differently depending on which side of the marketplace it targets

Consumer-side account takeover is the fraud type most people already know, but Sudhir's most striking example was on the restaurant side. A compromised owner's personal email can lead a fraudster straight into changing the ACH payout information on a restaurant's account, redirecting real money away from a small business while GrubHub still owes that restaurant its original payment. Since this kind of compromise happens entirely outside GrubHub's own systems, Sudhir notes there's often no visibility into it until the restaurant calls to report a problem.

Refund abuse can't be predicted, so Sudhir places controls at the point of irreversibility instead

Unlike payment fraud, refund abuse involves a real customer using their own payment method, which means it can't be flagged at the moment of transaction. Sudhir's approach is to intentionally let the order go through, then apply controls only once a customer crosses a clear pattern of abuse, tens or hundreds of false claims, not one or two. His broader framework applies well beyond refund abuse. Place controls at the point where a loss actually becomes irreversible, rather than trying to predict bad behavior before it happens.

Driver and diner collusion shows up in some surprising forms

Beyond the more obvious case of someone posing as both the customer and the driver to collect a payout on their own order, Sudhir described a subtler exploit tied to minimum wage laws for delivery drivers in cities like Seattle and parts of California. Drivers place extremely low-dollar orders themselves, just to collect the guaranteed driver pay tied to that order, exploiting a policy meant to protect legitimate drivers instead.

Layered controls, and the difference between soft and hard friction

Sudhir breaks his approach into two tracks, long-term infrastructure built to stop major attacks like credential stuffing and synthetic identity creation, and a shorter-term investigative track that adapts daily to new attack patterns. Layered fraud controls get applied at each stage of the customer journey, device and behavioral biometrics and multifactor authentication at account creation, 3DS authentication and CVV validation at checkout, and delivery PIN verification after payment has already occurred. That last detail stood out to me specifically, since a PIN requested at delivery adds friction after the transaction, when it can't be exploited by someone simply intercepting a food order in a public place like a hotel lobby.

Reframing fraud strategy as pro-growth, not anti-growth

Sudhir closed with a point I think more fraud leaders need to say out loud. Fraud strategy isn't about blocking growth, it's about protecting the trust that makes growth possible in the first place. When diners, restaurants, and drivers all trust that a platform will pay them and protect them fairly, they keep coming back, and that directly turns into revenue.

Key takeaways
  • Food delivery fraud looks different across business models, with three-sided marketplaces like GrubHub facing more entry points than subscription services like Blue Apron.
  • Restaurant account takeover can lead to redirected ACH payouts, creating both a loss for the restaurant and a costly double payment for the platform.
  • Refund abuse and first party fraud can't be predicted at the time of transaction, since the customer is using their own legitimate payment method.
  • The point of irreversibility framework means placing fraud controls at the moment a loss becomes unrecoverable, rather than trying to predict abuse in advance.
  • Driver and diner collusion can take unexpected forms, including exploiting minimum wage laws through intentionally low-dollar self-orders.
  • Layered fraud controls should be spread across the customer journey, from device and behavioral biometrics at login to CVV validation at checkout to PIN verification at delivery.
  • Soft friction protects both customers and the platform without meaningfully disrupting legitimate users, and should be reserved primarily for that purpose.
  • Framing fraud strategy as pro-growth, rather than anti-growth, makes the business case for investment clearer to leadership and cross-functional teams.
Final takeaway

What stuck with me most in this conversation is how naturally Sudhir moved between three very different businesses under one umbrella and still landed on one consistent principle. You can't predict every kind of fraud before it happens, but you can be deliberate about exactly when you choose to act. Whether that's refund abuse, account takeover, or a driver quietly gaming a minimum wage policy, the real skill in fraud strategy is knowing precisely where the point of irreversibility sits, and building your controls right there.

Connect with Sudhir Lanka | LinkedIn
Associate Director of Fraud Strategy, GrubHub

Connect with Karisse Hendrick | LinkedIn
Host of the Fraudology Podcast
Award-Winning Cyberfraud Expert
Ecommerce Fraud Prevention Consultant
Startup Advisor, Keynote Speaker, and
Consultant to Fortune 500 merchants

Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:07
Welcome back to the Fraudology podcast. I'm Karisse Hendrick and I am really looking forward to my conversation today with my guest Sudhir Lanka. Sudhir is the associate director of fraud strategy for GrubHub. I have uh only recently gotten to know him but really enjoy our conversations and I think you will too. So, Sudhir, welcome to Fraudology.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
00:31
Hey, Karisse. Uh, thank you. Thank you for having me on the podcast. Uh, really excited to talk to you today.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:39
Me too. So, the first question I ask every guest on Fraudology, you know this uh because the answer is always different. How did you get started in fraud?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
00:51
Um, actually, you know, almost 13 14 years back. Um, you know, I just graduated from my college and um, to be honest, I was just simply looking for a job at that point and uh, I looked at the the job at JP Morgan Chase risk analyst and I found it interesting and I applied for it. I got the job um, you know, fortunately and uh, ever since then for 14 years I've been in the fraud world. Um, I got hooked onto the fraud world. It's very interesting, very intriguing. So I just I just been here forever now.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
01:28
And after uh being an analyst at JP Morgan Chase, you went to Discover. Is that right?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
01:35
Yes. Yes. Uh after JP Morgan Chase, I think I've been there for about 2 and a half years and then I moved on to Discover. Um again, same transaction fraud strategy team at Discover. Again, um kind of my my scope expanded a little bit. I covered uh both card present and card not present, transaction fraud. Uh you know I was kind of working on building you know uh crossover risk profiling, trying to understand how does fraud happen on card not present, how does it differ from card present. Um you know um you know I believe you know this is where discover is where I got a really good hold of uh what is fraud like, how does fraud happen, how fraudsters adapt, how do they attack at scale, and what do we do as as fraud strategists, right? You know, how do you counter attack, right? And uh yeah and And you know that's that's what I did at Discover at that point. Yeah,
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
02:28
That had to be interesting from the issuer perspective. The issuer and card brand perspective. Uh and really gave you a 10,000 foot. It sounds like it gave you more of a 10,000 foot view than being a transaction analyst at JP Morgan, which makes perfect sense. Uh and helped you see like, okay, this is how all the pieces go together and this is the bigger picture. Um, which you need for fraud strategy. Um, to be able to know not only what the pieces on the on the board game are now, but what they will be in several months and you know, okay, they're doing this now, what are they going to be doing soon so that we can get tools in place to counteract that.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
03:14
Yeah, absolutely. You know, I I feel that, you know, there's like um you know, uh possibly two things involved here. The first is um uh you know, once you gain some sort of experience, let's say you're 2 or 3 years into the into the fraud world, you try to, you know, you you start putting pieces together. You talk to a lot of different teams. You know after I came to discover I started speaking to the fraud operations or you speak to the chargeback management team or or you talk to you know account takeover team. Like there's there's a lot of different fraud vectors that we deal with, right? So sitting with everybody, speaking with everyone, you know um constantly talking to your leaders uh give me that 10,000 foot view you're talking about. And secondly uh companies like discover like you know specifically banks let's talk about them, right? They already have established process processes and SOPs and you know you know what you're dealing with. They've they've had they had they laid out everything um exactly how fraud needs to be handled, uh how much they are losing, uh what are the regulatory requirements, and everything is laid out. So you have, uh I would say, relatively an easy path to learn uh quickly. Uh uh so that actually helped me a lot um you know at discover. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
04:31
Yeah and then after Discover you went to GrubHub
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
04:35
Yes. Yes, that's where I am right now. GrubHub, uh, GrubHub has been, you know, has been great to me. Um, I've been here for about, uh, 5 years, almost 5 years now. Um, I'm currently leading the fraud strategy function um, at GrubHub recently, actually my team has recently expanded the scope to include Wonder and Blue Apron as well. So, we have three business legs under us now. Um so for anybody who doesn't know GrubHub has been acquired by a company called Wonder last year. So now we have um Wonder as a parent company and then we have GrubHub and then Blue Apron as well. So we're looking at all three business lines at this point.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:16
Wow.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
05:16
Uh so I lead the fraud strategy function end to end diners merchants and drivers. Uh pretty much looking at uh a wide variety of fraud vectors. Uh, at this point I'm I'm currently doing that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:29
That's a big job. Um, I'm familiar with GrubHub and Blue Apron, though my listeners are international, so they may not. Uh, I'm not familiar with Wonder. So, could you share just a little bit about each of those companies because I think they're while they're similar, they're also unique.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
05:49
Absolutely. They're 100% unique. So, Wonder is is relatively a new company, I'd say, compared to GrubHub. Um um so they are predominantly concentrated more in in the east coast of the of the country more in New York and uh you know Connecticut and all that. They're expanding to you know Wonder is expanding to Texas and other states as well in the coming years. But um what Wonder does is they have physical stores uh like you can consider them more as cloud kitchens or ghost kitchens. The unique concept of wonder is you go to a wonder store and you're going to find food from every single cuisine that you can think of. In one store, you can order Indian, you can order pizza, you can order sushi, you can order Mexican, any different food that you can think of. Uh, you know, Wonder offers that, right? So, that's the unique concept that Wonder has come up with. And um and uh Grubhub is is like a it's like a traditional online food delivery platform. Um it's it's a you know it's a it's a well-known company similar to a lot of businesses across different countries as well. And coming to Blue Apron, Blue Apron is a is a meal kit service. So you just um you know um you know figure out okay what do you want to cook? They deliver raw ingredients uh to your house planned out weekly and you can you can kind of uh use them as more of a subscription service at this point. Uh but um but the what Wonder wants to do um as a whole as a parent company is to become one-stop shop for all your food needs. Uh you want to order raw ingredients, you want to order online, you want to go to a store, you want to order any cuisine that you want, it's all in one place. And that's that's what Wonder is trying to do at this point.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:38
Wow. That's that's quite a goal. And yeah, it's uh the the through line is obviously feeding customers, right?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
07:48
Absolutely.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:48
Uh but they have different business models and with different business models come different fraud risks.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
07:54
Oh, 100%.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:55
Right. What you would have what you would see for traditional food delivery from a restaurant. You know, it's kind of a three-sided marketplace or four-sided marketplace. What do you consider it?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
08:08
We consider it as a three-sided marketplace.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
08:11
Right. Right. And as you mentioned, you have you have the uh customer who orders the the meal, you have the merchant that makes the meal, and then you have the driver that connects the two and brings the meal from the merchant to the consumer. So, you know, whenever you have whether it's two-sided marketplace with a buyer and a seller or three-sided in this case, uh I just didn't know if you considered yourself a a fourth part of the marketplace. That's why I was it was like I Yeah, some companies do and so they're like we're from a three-sided market. I'm like but are you you just have buyers and sellers and they're like but we sit in the middle. So um that's why I was asking. But um yeah that has such unique challenges because there's opportunities for fraud on all three of those, you know, sides, right? Um whereas a meal delivery service that runs on subscriptions is going to have a different type of fraud. You know, they're they're not going to um have as many opportunities for fraud as many channels or or sides. Um but you'll probably see some card testing or you'll see some account takeover or that type of thing. Um y what what are the type of fraud vectors or how do you define fraud at GrubHub or Wonder I guess?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
09:36
Yeah, absolutely. Now you know you know sometimes it's it's confusing not confusing but you know we keep thinking should we call ourselves Wonder or GrubHub but there still but it's just you just get confused. But uh but uh but yeah uh talking about fraud right you know, when we when we say fraud I'm like you know what what my team deals with. Um it's not a simple um fraud fraud that everybody knows of right. So what we deal with is um fraud is one aspect of it. We also deal with abuse. We also deal with any kind of scams uh um you know any internal fraud anything that happens end to end uh perpetrated by anybody on the platform right. So when we say fraud it can be uh the primary ones that everybody knows about is ATO what we call account takeover uh is the primary one obviously. And second is uh what we call the um stolen credit cards or stolen payments let's let's call it stolen payments at this point. Um these two are the primary crime vectors that we see um on GrubHub um and I'd say I'd extend it and say Wonder and Blue Apron as well. Similar fraud vectors is what we see. Okay. And talking of talking about abuse, um we do see a lot of refund abuse, right? Uh some companies call it as returns abuse. You know, in the food delivery platform, it's technically it's refund abuse. You cannot return your food. So, it's it's refunds of course. So people uh order the food, they take the food, they eat it, and then they call and they call the bank and say that I did not receive my my order or they call GrubHub and claim that they did not receive it, right? Or they'll make up like thousands of reasons to get a refund. Uh
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:17
The the meat was bad or the you know like
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
11:21
There's so many things that they can
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:23
Yeah. Yeah. The driver ate my food. I've heard that one. And I've heard uh um you know, I got food poisoning from this or I got I got the mo I got the cheapest item, but I didn't get the most expensive item, right? Like I got I got the soda, but I didn't get the steak dinner. Uh so I need a refund on that. Like those are just some examples of what you mean by by refund fraud.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
11:50
A refund abuse. Yes,
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:52
Refund abuse. Yeah, absolutely. Mhm.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
11:54
And uh and the third major one that we deal with is the promo abuse. Uh when I say promo, it can be uh a marketing promotion or it can be a a a credit that you received from uh from our customer care team. It can be it can be either way. You basically got a credit or a promo on your on your account and then just you're abusing it uh by creating a loop of your own accounts. You're referring to yourself, let's say, for example, or um or you're going to Google and you're trying to um you know, exploit the the marketing uh you know, promotions that we have on Google or any any online website as well, right? So, that's the promo abuse we're talking about. Uh and that is the third uh primary vector that we deal with at this point. And I'd say that, you know, it's it's pretty similar um across the three business lines at this point. Um same fraud vectors you see you know um on some on on one side you might see fraud is higher on one side you might see abuse is higher but still pretty much the attack patterns remain the same. Um one additional point or one additional insight we want to add here is that uh all we're talking about right now is more on the customer side right. There's also another a whole vector of fraud that we see on the merchants and the driver side as well right. So we see similar you know um uh merchant accounts being taken over on merchant or the restaurant when when I say merchant it's the restaurants owners being socially engineered to reveal their personal details. Um their payment methods or the ACH linked on the on the on the restaurant portal is replaced by fraudsters uh bank information and money taken out and and there's so many other fraud vectors that we deal with on the driver side as well but um, but it's huge. It's It's huge. And there's there's a lot of lot of things that we're dealing with at this point. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
13:50
Yeah. I would imagine with that example you just gave as far as account takeover on the restaurant side. I mean, especially for a busy restaurant, you're probably talking about thousands of dollars that GrubHub will be paying out via ACH to that small business, that restaurant. And if the restaurant owner is socially engineered to give up their, you know, GrubHub password or there's spear phishing emails or things like that and they, you know, are asked to log into GrubHub, but it's a fake, you know, website. They then automatic very quickly the fraudster goes in and as you said changes the payment method uh or the payee basically um you know changes the bank account that GrubHub is paying the restaurant and now the fraudster is getting that money and not the restaurant and that can really disrupt business and be really scary. And then on top of that, you know, the restaurant is looking to GrubHub to pay them again, right? I mean,
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
14:53
Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
14:53
Right. Right. I mean, they didn't get the money the first time, but on your end, it looks like a double payment. Uh, so that can get very expensive even though your AOV, your average order value is, you know, I mean, you don't have to tell me, but I would guess, you know, $50 to $100.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
15:11
Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
15:12
You know, that's, you know, in payment fraud, in credit card fraud, that's $50 to $100, you know, each time it's stolen, which adds up. But driver ATO or uh, you know, restaurant ATO is the risk is so much higher because the amount is so much higher.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
15:32
Oh, 100%. Yeah, absolutely. You know, um, you know, I just remember one thing as you as you were as you were talking about this, right? Um, one one scenario that that that I've seen happen again and again is um restaurant owners personal email address and password are compromised a lot of times. And when that happens um it's it's extremely difficult for even for a company like GrubHub to do uh to do anything about it, right? Because we don't know what's happening. It's it's everything that's happening. It's external. So we actually don't know until they call and complain that hey this happened or something you know any any kind of alerts that we receive until that point we don't even have any data to to say that hey there's something wrong with this, right? So those kind of scenarios hit the hardest, the reason being our small business restaurant owners are being impacted by this. And um and um that's that's much more impactful for for for a company like GrubHub is uh it's it's important for us for as as a company and a fraud team to protect our restaurants as well because that's what keeps our supply like that demand and supply chain going on, right? So it's it's very important important we take care of that as well. Yeah. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
16:53
Yeah. You need all three of those pieces in the marketplace to be thriving and happy and you know producing. You know, you've got three sides of the marketplace and you've got the consumer and the driver and the merchant. If one of them isn't paid or paying, then it falls out of balance and the marketplace doesn't function.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
17:18
Yeah, absolutely. I think it's it's very important to maintain that balance. Um not like you know, of course, the the main um you know, reason for that is like the end goal is to kind of maintain that balance of that supply chain. Now you have diners coming in and ordering, restaurants fulfilling the orders, and you need to have enough number of drivers to fulfill the orders themselves, right? But um but but you're right. I think it's important to take care of every single party in this cycle. Um you know um you know to ensure that drivers are getting paid fairly uh protecting merchants, we're protecting diners um you know from any you know fraud attacks. Um um absolutely I totally agree with that. Yeah. Hm.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
18:00
You know, do you ever I know a lot of times on marketplaces, whether two-sided or three-sided, they'll have some kind of collusion occur um between the buyer and the seller, or in your case, it could be the driver and the restaurant or, you know, maybe the customer and the driver or, you know, whatever. Um is that something that you've you've had to experience recently?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
18:24
Yeah, absolutely. You know um we do see collusion you know although it's not it's not as extensive as as a single party fraud let me say that. But we do see instances of collusion happening as well uh predominantly what we see is um you know diners and drivers colluding uh colluding sometimes um to to kind of create a fake loop of ordering in the sense that the the the same person could be posing as a driver and a driver and they're they're potentially accepting their own orders to create a fake loop um just to take the the driver pay um from GrubHub, right? So that's that's the net loss that the company is going to have. But in reality, the the same person is ordering and they're they're getting they're they're basically picking up their own goods, right? Um so that is that is one um one way we saw collusion. And in uh um in some cases what we see is um you know um diners do come in and u you know place uh like really low dollar orders like uh let me say like a sauce packet or like um something else which is like a a dollar or a $2. Um this we see this specifically happening in um in locations like you know Seattle or California where there's like minimum wage laws that are in effect that you have to pay a certain amount to drivers who are on on like on on this and like actually actively deluding at that point. Um so drivers sometimes do kind of exploit this you know of course it's a very small percentage of drivers not you know of course vast majority of them are of course good drivers that we have
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:04
Right
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
20:05
Um they're simply kind of um you know placing this $1 order and then just taking out the driver pay, right? Uh so that's that's kind of uh you know that fake loops and um you know exploiting the uh controls or the exploiting the laws which have been which have been put in place to protect genuine divers are being exploited. Uh um so those are the you know those are some of the scenarios that we see in terms of collusion um at GrubHub mostly. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:34
Huh interesting. I wouldn't have thought of the drivers but then again I wasn't thinking about the laws in place in California and the Seattle area about drivers. Um, I would have thought, you know, when I was thinking collusion, I was thinking the first scenario you said when a diner and a driver are the same person.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
20:56
Yep.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:56
And they're, you know, trying to do money laundering or they're using a stolen credit card um to place the order, get the food, and then they're the same person, you know, the same person is getting paid to deliver it to themselves, basically. Um,
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
21:16
Yep.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
21:17
That's what it Yeah, that's fascinating. So I mean without going into too much detail um obviously because this is on a public platform uh when you're looking at controls to put in place for these types of frauds whether it's account takeover or uh payment fraud or refund abuse. Uh what are you looking for in controls and um you know what are your goals there?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
21:47
That's a that's a good question actually. So to think about the way the way I think about you know placing controls right you know um this there's two ways. First is you need to have um long-term infrastructure on your platform to protect your platform from um from any of these major attacks that we see all the time. Right? So when I say major attacks, it can be in terms of credential stuffing uh like where you see thousands and hundreds of thousands of login attempts coming in within a matter of minutes. Um uh or you have thousands of synthetic identities being created on your account or um um um you know significant amount of account takeover happening at the time of order placement. To counter these kinds of attacks, you need to have long-term infrastructure in place where you where you have something like um a multifactor authentication or you have something like 3DS or or or or you have something like a photo verification at the time of drop off uh to ensure the the order is actually being delivered. Um you need to have all these things in place, right? And the second track, the way I think about it is more of a short-term or let me say more like a a daily investigative track is something that you need to have um where you have your set of agents or your set of investigators uh going in interactively uh looking at okay what's what's happening today what's what's out there what are the new trends or new attack patterns that are coming out, uh and uh and how do we stop it, right? Um that's the way I think about it now. Um talking about like more from a end to end perspective, right? Um at least at the the the way I've I've worked so far is to have uh layered controls, right? I'd say that fraudsters are best if they're not on your platform, right? Obviously, so you you want to stop them at account creation or login at most. It's probably always the best option that you can go with. So you need to have really really strong controls at that point. You're talking about uh risk scoring. You're trying to figure out their their device information. Uh where are they coming from, their location, their behavioral biometrics, um any of these controls, you need to kind of uh you know um um you know consolidate all these signals and build something at the account creation or login stage. And then obviously you're going to have something at the checkout phase or the order placement stage as well where you have real-time decisions being made on each single order or transaction. Right? You you either say that you want to accept the order or you want to reject it or you want to send it to 3DS or maybe you want to do an internal OTP just send out an OTP to customers phone number um or or you do something else you do a CVV validation. Uh there's a lot of different controls you can place, right? Uh and then you talk about, and then the other set of controls I strongly suggest, um, is post order order placement, right? So once customers have actually placed the order, you need to have a set of controls monitoring, more, this applies more for refund abuse I'd say. Um the way the approach that I have taken is I generally do not want to reject anybody suspected of refund abuse
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
25:17
Right.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
25:18
Um I I do want to take their order, right? And um and
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
25:22
They're using their own payment method. It's them right.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
25:25
Yeah. And then you you deal with them once the order is completed. Uh and they call you and say that, hey, you know, something is wrong with my order, right? Obviously, you want to protect your good customers and if they really do have, you know, a few orders that they have had bad luck with or bad experience with GrubHub, obviously they're going to get a refund. But if if you find somebody abusing your policies like hundreds of times, tens and hundreds of times, you do want to place a control to say that hey, you know, you know, we think, you know, you crossed the threshold of what we call as abuse and we're going to not give you a refund or we just give you a credit or something like that, right? So, kind of having this layered controls is is what I think works best. Um, at least that's what I've seen in in in in our case. Um um and and you know that's that's generally my approach in you know implementing any kind of control.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
26:20
I like the way you put that because I've I guess I haven't ever thought of it in that way in the two different ways but there's the infrastructure piece. There's the, you know, the systems that you put in place for transactional monitoring and account protection and um all of that. And a lot of those things can be done behind the scenes so they're not impacting the good customers. Um and then there's also that additional piece where it's almost like I'm trying to think of the right term. So, it's not like firefighting necessarily, but it's a little bit more like you've got these levers and these and these systems that you can, you know, dial up or dial down or, you know, you can add something in place like maybe, you know, and I don't know this to be true, but I know this to be true for your overall industry that, you know, for several years the picture of an item being delivered wasn't required. Um but then refund abuse you know came up and uh that was you know really uh painful financially. And so, you know, as an industry, your competitors and yourself, uh, made decisions at different times to, you know, store those pictures and do all that you have to do with those photos to be able to prove delivery happened and that, you know, the the item wasn't the bag wasn't opened or, you know, that whatever you need to prove. Um, and then I know more recently I noticed when I was traveling um, a couple of weeks ago I I didn't use GrubHub because they weren't super big in the city I was in, but I used a competitor and they required me to use a PIN, you know, to give the driver a number because I was, you know, outside of a hotel and anyone, it wasn't just a residential house. Um I had to give them a four-digit number in order for them and they had to enter that number and into their system and they didn't know what it was. They just had to enter the number I gave them um in order for um me to get my order. And so that that is one of those things, you know, the the systems and controls that second part where okay, we're starting to see this trend. We need to go this route and maybe we need to implement something new like PIN numbers. Maybe we need to um you know dial up our controls on two-factor authentication. Maybe we're you know we're doing more of that. Um same with like account takeover. There's also, you know, with ATOs, there's the ability to, you know, look at device and say, is this the same device that has logged into this account always or is this a new one? Um, yeah. So there's all different. I I love nerding out on fraud strategy because uh it's the methodology is similar but the solutions are a little different depending on the business model of the merchant right
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
29:45
Agreed. Yep. Um you know you're you're absolutely right. I think you know depends on the type of merchant and the type of business that they are operating in uh for a company. Like for example just taking some name for example somebody somebody like Best Buy right they they sell like high value items and is compared to GrubHub it's just the business is different and the kind of controls that you please has to be different. Uh and I you know what you mentioned earlier as well in terms of pin verification or you know these kinds of controls um this is more of a softer friction that we're talking about. We're placing we're placing friction but it's it's soft and we are giving a chance for customers to go through, right? Uh we're just doing this to protect the customers and in turn protect the platform as well, right? So, it can be in terms of, you know, entering a PIN. It can be uh as simple as say CVV validation. You just enter your your card details once more, right? We're just not asking you to do much here. Um this this this helps protect them as well company and a lot of hassle. Um right so you know we generally try to approach a lot of these problems with, of course, obviously we just don't want to do any friction but if we have to we go with softer friction. And a very very very small percentage of customers do get hard friction, right? And and you know I believe is it's it's necessary for some customers or a cluster of customers to have that hard friction. It's absolutely necessary in this in this business so Yeah,
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
31:23
I agree. I actually haven't ever heard the term softer friction, but I like it. Uh, the thing I was thinking about the PIN when you were talking about it just a minute ago was it's very smart because not only are you asking for it at the time that fraud would occur, right? You know, if someone else was staying at my hotel and they saw a food delivery guy standing outside, they could just say, "Oh, that's my delivery." and and get it. Um, so it's at the time that like some kind of fraud could happen and then I would be saying, "Ah, I didn't get it and I need my money back." And all that. Um, but also the transaction has already occurred. So, you're not you're not giving them friction before they pay you. You're giving them just a little bit of light friction. You know, at the time of delivery after you've been paid, which I think is really smart. You're not, you know, that that's something that you've done in all that you've said today.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
32:23
Mhm.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
32:24
That's something that I appreciate. I have seen some companies in my perspective make mistakes when they try to identify a certain typography of fraud prior to the fraud taking place. So what I mean by that is if it's not payment fraud, then you can't predict it at the time of transaction, right? You can't predict firstparty fraud at the time of transaction because it's the person using their own card. You can detect first party fraud when they're making the claim or when they file the chargeback or you know that's when the the act of fraud occurs. Um, you can't predict. Yeah, you can't predict refund abuse at the time of transaction either. You can't predict, oh, they're going to claim that they didn't get their food. Um, unless they've done it 36 times before on their same account. Well, then that's a little different. But we know that especially in the day of age and age of it being relatively simple to create online accounts for different apps and and services. You know, if they're denied on their 36th time or their 10th time or whatever it is, they'll just start open up another account. So, instead, let's do it at the time of uh where the compromise occurs or where the um you know, the kind of the the point of um compromise, not the point of compromise necessarily, but like the um the point that the loss occurs or that the claim is made or whatever else. I like that a lot.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
34:06
Absolutely actually the uh no another way to put it put that is you place control where you think the loss is going to be irreversible, right? So if you got fraud, if you let it past check out, you're not going going to get it back, you have to pay for it, right? For refund appeals, you can wait until they call you for asking for a refund and then do something about it, right? So figuring out that point of irreversibility is the is the important thing here, and then place the controls based on that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
34:42
You just made that sound so much smarter than I did. I like that you just took it very succinctly and yep that's exact. You're right. It's where it's irreversible. Um it's where it's identifiable and irreversible. I like that a lot. Well, Sudhir, we are um about at time and I want to make sure I respect your time because you're so busy, but um I wanted to just first ask you if there's anything else that you wanted to mention uh about anything that we talked about today.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
35:16
Um nothing specific about what we spoke about today. I'd say that, you know, um I generally I generally say this to you know, most of the folks that I meet is um you know, a lot of folks perceive fraud or fraud strategy as anti-growth. Uh and I want to I want to emphasize that it is not. It is actually I want to say that it is progrowth because if you want to spend your money wisely, you need to take out bad customers and you you spend the money but you want to give it to good customers who will come and order on your platform. You want to retain those customers, right? So I I I generally tend to say this to a lot of folks is that changing that mindset is is important. Fraud is absolutely absolutely necessary in almost every company. I want to say um and uh but yeah but yeah I think that's about it.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
36:14
For a long time I went through this phase of saying that we should try to rename our industry from fraud prevention to revenue retention. Uh it didn't really stick but uh but I get what you're saying. It's the mindset of no we I'm pro growth. I want to support growth. Um and you're also pro trust. We didn't talk a lot about the trust and safety aspect, but when your customers and your uh restaurants and your delivery drivers can all trust you to pay them or to give them their food that they paid for, you know, whatever that is for their their peace, they'll use you more and that turns into more revenue.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
37:01
Yeah. Absolutely. Mhm. Yep. Yep. Totally agreed. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
37:05
Well, I'd like to also mention that Sudhir is going to be at Merchant Fraud Alliance soon uh in Chicago, October 6th and 7th. I have mentioned the conference on almost every episode recently, but um it he will be uh facilitating a Merchant only discussion on refund abuse and um I think it'll be really uh really impactful for the merchants that are having those issues. Um, so if you're going to MFA as well, uh, make sure you say hi to Sudhir. If, uh, you haven't planned on yet, make sure you get your ticket, merchantfraudalliance.com. And Sudhir, I'm looking forward to seeing you in person in just a few weeks.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
37:49
Yeah, absolutely. Looking forward to seeing you as well. We never met outside, but absolutely looking forward to seeing you. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
37:56
Yeah. Only through the computer.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
37:58
Absolutely.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
38:00
Well, I assure you I have I have legs. I'm a you know, you could never see anyone's legs on Zoom. So,
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
38:07
Yeah, absolutely.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
38:08
Oh, well, um I look forward to that and thanks again. I really enjoyed our conversation today.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
38:13
Yeah, me too. Me, too. Loved it.