Welcome everybody to another episode of The Saturday Fraud Strategist. And with me today we have David Liu. David, welcome to the show.
Yeah, thanks. It's good to be here. It's good to see you.
Likewise. David, you and I met, I think, through LinkedIn, right? Around two years ago or so. And I remember us having the first conversation and we had like a very quick kind of like meet and greet call. And I remember, you know, saying to myself, okay, this guy gets it. So I'm I'm super excited to have you on the show. You're a veteran of the fraud prevention industry. You've worked both on the vendor side as well as the financial services side. But for those who don't know you, David, tell us a bit about yourself and your career so far.
Sure, and I'll do it chronologically. So at American Express, I was the, I grew up at American Express. And I spent fifteen years there, about a little less. And I ended up being the owner of fraud prevention for all, basically all of the non-card products end-to-end. And we were a lot. We were the fourth largest bank. We had corporate client onboarding, membership rewards, business loans, savings accounts, checking accounts, SBA loans, et cetera. And then also I was responsible for new account fraud prevention globally as well. And then after that, not chronologically, I worked as the product owner for SoCure’s fraud products. Which is about half of them. So those 50% of SoCure's product team, their product responsibility. And then also for Trulio, their fraud products. And then I've also been a consultant for a good number of years, helping both solution providers and operators, all sorts of different kinds of solutions.
That's super impressive, David. I know that you've seen a lot in your career. So I'm super excited to have you on the show, as I said. And very anxious to deep dive into the topic that we have today. So we had, we were kind of like catching up a couple of weeks ago. And we were also talking about you appearing on the podcast. And initially I asked you what do you want to talk about? What's top of mind? And you, I think I don't remember what were the topics, but you mentioned two or three topics. And when we talked, you immediately kind of like said, I want to talk about the future of fraud. And what's coming in two, three years. We said okay.
And even now sometimes. Like the future is now. The things speed up so much.
Yeah, yeah. Things, the time horizon gets blurry. Yes, I agree. And I, and I said, you know, yeah, let's definitely do that. And I really want this conversation not to be about scare tactics, and kind of like, you know. That is something that the industry is too good at, unfortunately. And I, and I do want us to take kind of like practical takeaways that fraud fighters can do something with. But let me start with actually asking, are you worried? Is this a top of mind topic because you're worried about it?
I’m not that worried. Because I think what always happens everywhere, every institution, is things are going fine. Something bad happens. No no, the sky's falling, people scramble, and figure out a way to fix the sky. And then they go, fine again. And that that's BAU. It's just, most of the time you can't describe how the sky will fall. And now, because of the rapid change in technology, it's really clear how the sky will fall. But that's always what fraud has been like.
Um, yeah, I mean, first of all, I agree. It's a pendulum swing. And I would say that, you know, something happens, as you said. We rush and fix it. And then the next thing is, that we block too many good users, and we have too many false positives. And the, and that's the BAU, right? This pendulum shift. But I, I'm curious to hear your thoughts about it. Because you know, you said it's very clear how the skies are going to fall. But I think that for a lot of us, and also including myself, I don't think it's like super clear. And I, and by the way, I will admit that I'm much more attuned to fraud fighter teams, or fraud fighting teams, than the fraudsters themselves and what they are up to. So it's always interesting to talk to people who are, you know, like more in tune, and are looking at that side as well. But share with us, like let, let's get a scary part out of the way. When, you know, you see AI. And you, and specifically Gen AI, and you were thinking about two, three years into into the future. And we already have deep fakes and we already have synthetic identities at scale. What are the unpleasant possibilities that go through your mind? How do you see fraud evolving?
Well, I think we're already. So I'm gonna focus, like I think this podcast is, this particular episode will mostly talk about Gen AI. And what that enables. And it's not just Gen AI in terms of you can use a large language model to do stuff. It can also be, you can use to do attacks and interact with people, but it can also be you can use one to do coding or or to build software. Which maybe in the past would have been much more difficult as a solo fraudster or solo entrepreneur. And right now already people are seeing scams happening, at like greater scale. And more personalization, and phishing happening at greater scale, and more personalization. Like, and we all see this. Because we, our phone explodes. And we're like, this is a better scam than we'd usually see. But I'll give a specific example and then we can maybe jump from my new account example to maybe an account takeover example or a money mule example. But my new account example is, if I were a fraudster today, which I'm not, I would probably use something like an OpenClaw and spend time training the thing. And then give it some high-level instructions. You know, I do my planning in one place. And the planning would say buy a bunch of phone numbers, get access to, like an Equifax data breach, you know. Load it with some kind of digital currency, Monero or something. And find out who used to own those phone numbers. And find out the identity of those people. And then buy a bunch of emails, and these emails should be tenured and not have a name in them. You know, loves to play basketball at gmail.com for your old email. And now that you know that, and sorry, Chen, you're now the victim. So now that I know that this phone number used to be owned by Chen, and I have this tenured email, and I know Chen's PII from a large data breach. I can also say, find a residential proxy. And buy access from the same city that Chen's in. And create a device that's plausible. Use just a common random device. So you can beat typical device ID controls. And now this, this new application for a loan, or whatever it is. Or buy now pay later, or whatever. Becomes really hard to detect as fraud. Because it's Chen's phone and email. Coverage isn't a hundred percent, and it's a tenured email. We can't say it's not Chen's email, and the device signal's weak, the IP address signals really weak. So how do you, how do you see that it's bad? So that's the first thing. You can't even detect that it's fraud.
Yeah, so sorry. I mean it, just because you mentioned OpenClaw. Obviously I heard the name, but can you, can you explain a bit what it is. And why it does, like what are the new capabilities that it provides fraudsters with? Because it sounds to me, like what you just described is something that I can imagine how a fraudster can do that exact same thing. Also today it might be very hard and very expensive to do. How would OpenClaw change that? What is it exactly?
Well, I think it's more about this, and and I don't mean OpenClaw itself, I mean similar agentic frameworks. But it's more the point that the automation becomes dramatically easier. That you can give hints, and then an agent can either through code or interactively as a loop, sort of perform this attack at really great scale. Much easier than it could have in the past. And now I can say, just find a residential proxy. In the past, that might have taken some work to find a residential proxy. That maybe could accept your your digital currency, which is sufficiently clean. You know, just very time consuming. And to do it at scale. And to do it repeatedly. And to do it with a new one, new proxy that matches the city and state that Chen lives in. You know, so each step in this requires a degree of customization, that in the past would have been pretty hefty, and probably not done at scale.
Okay, so you're saying that the new emerging threat here is the fact that for fraudsters, to conduct sophisticated attacks at scale is something that A) they are now capable of. So it's like zero to one, like many fraudsters are now like at a one instead of a zero, and and two, that it is also way cheaper for them to do.
I can imagine, and I and I know that on the dark web fraud has been industrialized. In the sense that you have service providers. And that's the case for many, many years. And I'm wondering if these capabilities were not always, you know, for sale. You know, for maybe large sums that not all fraudsters could afford. And like, you know, I'm wondering what does it do to the fraudsters' economics themselves? Where maybe, you know, their own services are going out of business. Because now anyone can do that with AI. It's the Suspocalypse.
A fraud suspocalypse. What a funny idea. Certainly I think that there's a lot of shifts in who the players are. So many times I don't think an individual fraudster will want it. Like in general the fraud tools haven't been that expensive. Right? And so as a fraudster, it's probably not worth it to build your own. Because the price of the tool has never been that much. So I don't think that it's like, I'm going to build my own because this tool I used to pay $200 for, you know, I can build it myself. No, it's still not worth the two hundred dollars to build the tool. Instead, what happens is just within, same as within the fraud vendor space, that there's a lot of change that with new technology. And you'll find that one vendor displaces another as technology advances. And so I think the rate of that change is happening.
Yes. Interesting. Sorry. So, you were about to describe how similar attacks can be performed on established accounts as well, right?
Well, and let me go back to something. So you asked a great question. I love the question. You're like, of course I did. Which is that, this thing I described, how is that new? What does that have to do with AI? I love that question. And the answer is like, if I was doing it with one account, and I was gonna spend a lot of time to do it, and I had the skill set, it doesn't have to do with AI. But now, many times there'll be pieces where I don't have the skill set. Or I'm not aware of the control. And AI can help me become aware of the control. And it can help do the thing. And then on the other side, you can say anything in the past that I could have done once, but it would have taken me a long time and a lot of effort, now I can do sort of at really high scale.
Yeah. And that goes also kind of like to the self education, and self training that many fraudsters. I mean, you don't go to school to learn how to defraud, right? You must be an auto deductant. And with AI, and the capabilities that it enables, I'm guessing that it is much, much easier to to do so today.
Yeah, no, that you can turn that into a quote. You should excerpt that, you know, something Chen said in this podcast. This is a very, very good insight. But anyway, where I was going was that, we could come up with different examples of scenarios across the entire customer life cycle. Or different kinds of fraud attacks, where you're like, this fraud attack, this example, it would be really hard to detect. And then on the other side, you could say, well, how do we challenge today? What's the traditional way of challenging? And today the most typical way of challenging is to either send a code to your phone, if we know it's your phone, or to do document verification. Take a picture of your face, take a picture of an ID, do they match? And we know that almost all, probably all of the major document verification fraud solution providers, have had large fraud attacks. Which have beaten them. And then they scramble and they try to fix it. And it's becoming more and more prevalent. It used to be three years ago, let's say one person in a thousand or less, one in five thousand, would beat document verification solutions. And if I today, if I were to speculate, it would be one one fraudster in a thousand. Now if I were to speculate it would be like one fraudster in fifty or a hundred or maybe less, 25. Like it's still a useful control. I mean, it still stops the majority of the fraudsters. But on the other hand, clearly there are fraudsters who can beat it at scale, and they are, regardless of who your provider is. And so you can't, you can't identify it's fraud. And even if you were lucky, and you somehow were able to identify it was fraud, you can't stop it. You can't challenge. It's like a nightmarish possibility. So that's the scary scenario that I'm painting. And then the the obvious question is okay, so if there's such a scary scenario. Well, what do we do about it? And I have some proposals, but I'll throw the ball to you. And why don't you say what we could do about it, and then I'll add on just for fun.
I mean, let me ask you before that just one question. Because the picture of, that you were just painting of fraudsters being able to seep through. Or kind of like penetrate any type of, let's call this family KYC vendors, right? The KYC vendor family. Whether it's Doc V, liveness checks, it's the same. General KYC vendors. And I completely agree with you, like we're seeing exactly the same thing. I'm wondering if you see that as kind of like a new situation, a new status that we're at. Or do you think that this can actually, even get worse, like two years from now? Where do you think are we, at the arms race? Who's winning? Or who's ahead?
This moment in time, as in recent past, I think the financial institutions, the companies, are winning at this moment in time. But I wouldn't be surprised if there was a dip where the fraudsters just started to win. And it took the companies longer to pivot, and then I think the companies will win again.
Just about on one hand who is nimble enough to make quick changes, but once the technology kind of like let's say becomes more stable, I would say, and riches kind of like its peak, yeah. Yeah. Whoever has the more resources.
Yeah, yeah. So let's jump to structural advantages. So I'd say the fraudsters have a lot of structural advantages, even more so today. For a fraudster, they can try once. And if they fail, they learn. And with a financial institution. It, or you know, an operator. You know, if they, if they see one fraud case, they may or may not learn. You know, it it's just the teams are stretched thin. With a, and the attacker can iterate after every attack, especially if you're using AI to automate. Even with AI, most companies can't iterate after every attack because you have to look at larger samples. You have to see the impact on good customers, you have to wait a few days. Maybe you have a, an A B with a control. How long does it take the control to react?
Yeah, yeah. You have to not break the law as a company, where as a fraudster, you don't care. So so I think there's a lot of advantages in terms of speed of learning, sample size, that favor the attacker. Especially today. And that's why I think, along with that bleak scenario I just painted, while there will be a dip and the fraudsters will start to win more aggressively for a while. But large companies also have meaningful advantages. And for all that fraudsters are quote good at information sharing. I put that in air quotes. In the sense that, you know, they'll sell products to each other. And that the life cycle gets coordinated by specialists from, who hand off from one to the next. On the other hand, like the degree of investment from one entity can, at the company scale, like much larger. Than even the largest fraud ring. You know, the largest fraud ring might have, who knows, a few hundred people. Of whom how many are sort of very technologically savvy? I don't know, a dozen, less. Whereas a company could easily have many hundreds of people who are technologically savvy, working on just one specific problem. And so I think the benefit of the people fighting fraud is the benefit in coordination. So we don't share, companies don't share information with each other, that well. But within a company, the degree of information sharing is fantastic. And there's a lot of smart people working on the same problem.
It's interesting. It's exactly the same thing that Shachar Meir brought it up in in our own episode a couple of weeks ago. Where he basically said almost the same thing. I think his point was more the coordination between different organizations, that this is something that we can do through consortiums. But I think your point is actually a very interesting complementary add-on. That, you know, pertains to the fact that we also are coordinated within the organization. We actually have much more firepower, much more resources. Budget to solve the same problem than what frosters have at their disposal.
There was this bleak scenario. We're gonna have this hypothetical attack, what do you do? And I can propose the solutions I've thought of. But I'd be, you know, you can also. How would you like to do it?
No, I wanted actually to ask. What, why is it so scary in the sense, that like in the end. We know fraud today. We have fraud, we have fraud for thousands of years, especially in the digital world. Gen AI is not that new, right? I mean, we we've seen the implications over the past two years. And even agentic, we are starting to see the implications. And I'm not saying that there are no challenges here.But, you know, we are not necessarily seeing fraud rates going, you know, tenfold or even fivefold. So I wonder,
Yeah, yeah, no. Maybe it's even getting a little bit better.
Okay. I would be interested to to hear more about that. But I would ask, why wouldn't the current system, the current kind of like, you fraud fighting system, fraud prevention systems that we have within the industry. Whether this is in financial services or with merchants or with digital platforms. Why would it not be enough? Like where would they break with these new capabilities that frosters are now adopting?
Yeah, so I think in the past, almost everyone says, Well, there's a certain amount of fraud I expect. And I'm gonna budget for it. And so when I have large fraud attacks, where something breaks horribly, I'll lose many millions of dollars. But then there's the day, I'm gonna call it the day-to-day fraud, where I just expect I'm gonna lose X basis points to fraud. And I'm fine with that. And that's most large companies today. And in the past, we say, well, the fraudster attacks. There's a certain manual nature to the attack, they have to iterate. But any one particular fraudster is unlikely to be able to scale up their attack to large volumes in ways that I can't detect. And the argument now is, many of those people who were your three basis points or whatever it is a fraud. Now will be able to scale up their fraud attacks in ways you can't detect. Not many of them, some of them, when in the past they couldn't. Because they didn't have the tools. Or it was like too overly expensive. And obviously it's not all of them. Like, you know, I, if I see your credit card at a restaurant, like that's not something I can scale up. But some of the attacks that in the past weren't scalable, now will be.
And you're saying that, what we would be consider, like what we would consider to be a very sophisticated attack. Let's say, the top, you know, ninety-ninth percentile in terms of sophistication, would basically expand to be the ninetieth percentile in a couple of years' time. Just because the like fraudsters would have more access to the sophistication. Also to the scale.
And especially the scale. Like maybe some fraudsters will get more sophisticated.But I think more the point is, if there were a hundred of fraudsters, and each of them attacks, whatever ten times. The person in the ninety ninth percentile, who attacks ten times, and beats all of your controls, now he has the tooling to attack a thousand times. Whereas in the past, maybe he didn't. Or it would have been, like much more difficult. [Ad Break (23:31): Hey folks, I want to take a quick break to speak about today's sponsor, me. If you're finding this useful, do me a small favor, like and subscribe. It really helps with the algorithm. And if you're not already on my newsletter, The Saturday Fraud Strategist, you should definitely check it out. Every Saturday, I break down fraud trends, real cases, and strategies from my own experience of building and operating fraud prevention systems. Whether you're new to the space or a seasoned practitioner, I'm sure you'll find it interesting. Check the link in the description. Takes 2 seconds. You'll thank yourself next Saturday. Now, back to the video.]
So let's talk a bit about, you know, how things, like in an ideal world. Where we have all the budget, all the resources, all the technology, and we've already gone through the transformation journey. Where we've implemented everything.
Okay, okay. So ten years from now.
It's like this, right? Just a flick of the fingers. What should, it's not a modern it's like a futuristic fraud prevention system, should look like? So it can actually stop these undetectable fraud attacks, or patterns, at a scale that today we cannot really imagine. How should it look like?
Yeah. So first I'm gonna caveat this by saying, I'm not gonna assume any radical changes in society. So I'm not gonna assume every person has a digital ID that they go, when they go to the DMV. And with a fingerprint biometrically bound to all this stuff. So I'm gonna assume, sort of very modest evolution in the broader world. I don't believe that device intelligence will be that robust for that long. That it'll just be too easy to spoof in general. Like you can know it's a unique device, but you won't be able to say, this device is, you know, an emulator or something like that. I think that will be very difficult. And privacy policies make it harder, not easier, right? Regulation makes it harder. But I was talking to Matt, actually who used to be at Sardine, and he gave me this wonderful example. Where he Yeah, yeah, Matt Vega where he was saying that he saw, that the bot clicked right smack in the middle of the button. Like the exact middle of like the submit button or something like this. And I, I think this brings out a broader point. Which is that companies, if we ask how does David apply on a Bank of America website for a new credit card? Like Bank of America has millions of applications, it has millions of data points. This is how new people apply on their website. No larger language model has basically any data on that. And if you tried to train it, maybe you'd have like a few people at most. And those few people wouldn't be actually natural organic applicants anyway. So I think the behavioral biometrics, I think that will be resilient. And will stay applicable for a reasonable amount of time. Like you can add jitter, you can add, you can make things look curved instead of straight lines. But it's a lot harder to make it look like David on the Bank of America website. And the machine didn't know that human beings don't click s right in the middle of the button. But there'll also be much more sophisticated features, which will be also difficult for machines to, to emulate. Because the fraudsters don't have that data. So I think behavioral biometrics will continue to be resilient. And will get meaningfully better over the next year or two at detecting, you know, agents who are controlling devices. Who are trying to emulate humans. So that's one.
But I want to challenge you on that. I mean first of all super interesting. I, I didn't hear this angle. Why? Because usually the angle that I'm hearing, and also an angle that I'm raising myself, is that the main problem is that we will see more and more legitimate users using agents themselves. To, you know, like basically organize or conduct their presence online. And it, you, it would like at the same time that it is you know hard for fraudsters to train their models to behave like legit people, legit people will more and more use agents that would look more and more like bad agents. So how, how do you see that?
I love that. And I like, I like that you challenge it. It makes it much more fun. So I think this is a place where regulation and expectations help us. So this particular tax scenario is at time of no count on boarding. I'm applying for a loan at Bank of America, whatever. And in that context, I think there will be very few institutions, and I don't think many regulators also will like the fact that one could ask an agent to apply for me. And I, and I maybe haven't read the terms and conditions and I maybe haven't clicked that checkbox and I haven't been the one to click submit. So when you talk about checkout, I think it's very plausible that agents will do it for human beings, and that's a desirable state. But for onboarding, I don't think when it's a meaningful financial relationship, that that's something companies will allow or regulators will allow in the near future.
Yeah, that's super interesting. Because it shows that, it will be very much use case dependent.
Yeah. Yeah, that's right.
And yeah, and financial services would probably have very different experience. And maybe even, like between different flows within the same organization, they'll have very different experience with how easy it is to combat fraud. Versus how easy it is to spot false positives. Yeah. Interesting.
But, I mean, let's talk about terms and conditions. Does it count as having read the terms and conditions, if your agent is the one who executed the action? And my guess is most people would say no.
Yeah. I think, I think the question is not what most people say. The question is what the regulators say, right?
Yeah, yeah, yeah. Well, at least for highly regulated institutions at time of onboarding, I'm pretty confident the answer will be no.
Anyway. So because of all of this, I think behavioral biometrics will be, continue to be really useful. Then after that, there's all the information you put on the application, the phone, the email, etc. And in my hypothetical example, I said, well, we're compromising the phone. And the way we're doing that is by getting a different phone number that was associated with you. And an email, but the email's not associated with you. And I think coverage of email ownership in the US maybe is 50, 60%. So ownership is not good enough, really, to use as a primary control. However, usually the fraudster won't, usually there'll be a change in the behavior of the email. So even if I buy a very tenured email, there are companies out there, you know, marketers, who will say, how often do you open your emails? How often do you click links? What's your typical behavior? And that's not something that's typically provided today by fraud solution providers. But I expect that they will be providing that in the next year or two. Because then the signal becomes, well, this email is behaving very differently than it used to behave in the last three months. So the email's four years old. And the last four months, three months, its behavior has been very different. Then that becomes a red flag. And I can't verify its dated email. So even though it's tenured, I shouldn't treat its tenure as four years. I should treat its tenure as three months. And maybe this is worse. Actually, if it was four years old, if it was four months old and it behaved consistently, that's better than if it's four years old and the last four months has changed. Like usually people will abandon emails and they'll become idle. It's not like I find an old email that I didn't use and now I start to use it a lot. That's actually a particularly bad kind of behavior. So I think you'll start to see more around the usage of the contact channel. So this story around email, you could do the same thing with a phone number. Like, is this phone getting or receiving text messages at the same rate as in the past? So I think usage will become important. And then with phone numbers where ownership is pretty good. You might get 85%, 90%, whatever it is in the US. I think we'll also start to see more focus on like, well, yes, this phone number was David's. But it's not David's currently active phone number. It's not the primary phone number. And so then it won't just be, is this. In today, it's usually sometime we saw this phone number attached to David. Like that's the solution today. The solution in the future will be, we saw this phone with David. But we stopped seeing, notice that it was attached to David nine months ago. And to some extent, you might get this from like a phone porting date or something like that, from some solutions. But many solutions not. And then not only will you say, is this David, was it when did this phone number stop being associated with David? You'll also get the phone's activity. Like has the phone's behavior changed in X time period? And then finally you'll get what's David's primary phone number, or primary phone numbers, primary email and primary emails. And so then if you see something that was associated, but it was a long time ago, or it's a very tertiary email or phone where the pattern of behavior has changed, then all of a sudden you can say, well, I don't completely trust that phone. I trust it much less. And these are signals that aren't surfaced today. But the data is absolutely there. And now, that I think the need will be coming soon. I think solution providers will start providing these.
Yeah. Basically you have to do much more data mining, to extract much more context and insights. And especially when it comes to whether it is established accounts or establishing your ownership on specific like assets. Like phone numbers and and emails. You're saying consistency and like measuring consistency is key here basically. Because this is something that fraudsters cannot train, even with AI. They cannot train to act and behave like you.
Or at least the cost to do so is exorbitant.
Yeah, yeah, yeah. Um, I want to ask something. I mean, that made me very curious when you mentioned it a couple of minutes ago. You said I believe that device fingerprint, or device intelligence would be much less reliable in the near future. Can you, can you elaborate on that? Like why, why do you feel this is the case?
Well, I mean, even now, like this is not a new thing. Ten years ago. Actually. So it was easier, I think, to produce device intelligence ten years ago before the browsers started restricting access to a bunch of stuff, right? And so the fraud cover, coverage from a device solution, a very good device solution, ten years ago, or the ability to identify re-returning users. Was let's say fifty percent better than it is today. And that's because the browsers keep restricting what's available. You know, you hear all these speculations about like Google's privacy sandbox and privacy initiatives. And the EU, and what you're allowed to do. But beyond that, even ten years ago, there were many fraud attacks. Which would have a unique device that seemed plausible. That didn't have any dramatically risky signals. That beat at least many name brand device ID vendors. You know, I saw three of the top five. All of them had this thing, had happened to them. I'm sure the other two I didn't see had the same phenomenon. So I don't think device, typically device ID was used either. Because this device ID we saw with 20 different people. Therefore it's high risk. Or this device ID we saw with David, and now we saw him use the same device ID six months later, therefore it's low risk. That was overwhelmingly the typical use. And yeah, there's a whole bunch of features that device intelligence providers provide of like, oh, maybe this is a RAD attack. Maybe this is, maybe this is an emulator, blah blah blah. But I mean in terms of model predictiveness, all of those features for the major device ID providers I know, accounted to for like less than six percent of model predictiveness. You know, these weren't that important.
So I mean it's not a new thing actually. This is an old thing and it's just made worse.
I cannot say that I'm surprised. Because I think indeed device ID used to be such a strong, I mean it I think it still is. It is such a strong, let's say, feature. Exactly when you are able to link it, either to other users or to basically the consistency. Again, going back to consistency, of the same user behavior. When it comes to like extracting the rest of the intelligence, I'm not sure if the fault is with the fact that this intelligence doesn't matter. Or that like with, you know, what we just discussed about email and address and phone, that organizations never really bothered to really extract the full potential from that intelligence. Especially with high quality, and especially with accuracy, of the on the road data layer. Because it wasn't needed, at least so far.
I mean, I think I know of at least a couple organizations that looked at a lot of the variables. You know, like if there was an output of like three hundred variables, they'd throw the whole thing against some automated rule creator or something like that. And just most of the variables weren't that predictive. Now and to be clear, like if you say, I think this device is using, is from an emulator. Is that likely fraud? Absolutely. Or at least much, much elevated risk. Should companies use those signals? Absolutely. But on the other hand, the prevalence of that signal will be pretty rare. So there's a lot of signals, they'll be very predictive, but they'll each one will be pretty rare. And so it's not predictive enough. But to be clear, like even IP adjust geolocation, like everyone knows you can, you know, use a residential proxy. Appear like you're another place. IP address geolocation in theory shouldn't work at all. And yet it's still like a top ten variable in lots of models. So just because the solution is beatable doesn't mean you shouldn't use it. Like you should stop the stupid fraudsters. They're making it easy for you. Use it.
I agree. I agree. Yeah. okay. So we talked about, we have all biometrics and that this is going to be still prevalent in stopping fraud. We talked about extracting more intelligence specifically from email and phone. What else would a futuristic fraud prevention organization should look at when it comes to stopping these undetectable fraud attacks?
Yeah, another signal, I so when we talk about phone or email, then that's talking about making these traditional signals more useful. Because we have, you know, is it David's, is it David's primary. What's the the kind of behavior over time? But there's also the passive signal. So there's behavioral biometrics. Another one that I think is really nice is that there's a a number of different data providers who make available passive signals, saying this IP address or this device is attached to David. And is attached to this address and this name and this identity. And so this becomes then a positive signal. And like I mean a a classic example is, is silent network enrichment. Where the cell phone carrier will tell you this IP address is, this Verizon IP address or whatever. T Mobile IP address is. You can ask them. This is the phone number I got, and they can say, yeah, that phone number, that phone number is paying for this IP address. And then you can say, and that phone number is David's. Therefore, David, who's paying for this data, is the one on the other side of the screen, and that makes it meaningfully lower risk. So that's it one example where you can use passive signals to deterministically link David to this IP or device. And there are a few providers who do this in different ways, using marketing data, using telco infrastructure, using consortium data. And I think the problem in the past is each one only had so much coverage. Like, you know, maybe they'd have 20% coverage, 10% coverage, 30% coverage. But I think there will be a future state where there's some aggregator who puts all these things in the same place. Where you can start to get 70 or 80% coverage saying, I know this is Chen. And I know it the moment his browser hit my website. Or or maybe I know it after he entered his phone number and his name. And then I ask, and they verify that that's correct. And once again, this doesn't stop the fraudsters, but if you can start to say I have really strong positive signals on 80 or 90% of the population based on, you know, these passive signals. Based on the phone ownership, whatever. Then the fraudsters are, instead of occupying this large space, are compressed into the small space. And it's a lot easier to find them.
Interesting. I think I'm starting to see more and more such players in Europe. I don't know how it looks like in the in the US. I'm guessing it's less complicated in the US. But when you're when you're going after regions which are more fragmented, obviously it becomes a problem. Because when you are in Europe you have a few dozens countries. So yeah, that's definitely interesting, by the way. An interesting business opportunity as well, I would say as a new vendor.
Yeah. Who knew that subscribing to Chen's podcast would be so profitable?
Yeah, yeah, yeah. You owe me money. Tell me, I mean, we've discussed a lot, the data layer. Like what features you want to extract and how to do so, and in what use cases. Do you see something about the basic technology that the system is running? Whether this is rules, models, or AI, or do you see something more on kind of like the policy or the team maker that would need to change to accommodate this new wave of fraud.
I think it will be helpful to have the rate of change, to have org structures accommodate a higher rate of change. Already most fraud institution, most fraud fighters exist within organizations that can act like much faster than credit. Like you want to change a rule in credit, it takes you know years. Use a new variable, and two years later, if you're lucky, you have the new variable and fraud. If you're lucky, maybe it takes you a month. I think the existing org structure should be able to accommodate it. When we talk about, like for example, soups is posting about, you know, this AI agent that can create rules and that can find fraud attacks and stop them in real time. Or almost real time without needing manual review. And so certainly I think that's a cool innovation. Um, there are places that rebuild models on a daily basis. So you're like, we don't need custom rules. The model was just rebuilt last night. Now I think things like that will become more common. Um, there are these articles about foundation models, which just ingests data from so many different customer touch points. And it's not just that it's a foundation model, it's that the philosophy becomes different. So in the past, if you had a fraud model, it would be really unusual for a new account opening fraud model to have, for example, your call center data. And yet it's really believable that we'll end up in a future world where it does. And then you'll say, oh this phone call into my call center was marked as bad and came from this phone number. And you know, so by having just more complete data available. And by having data lengths being a standard, I think that will help us as fraud fighters.
On one hand I must say that I still don't know myself, like what would be the part that foundation models would play in in risk prevention? Is it more like a feature engineering layer? Is it more replacing machine learning? Which I don't really see happening, at least not in use cases. Or maybe, in very specific use cases that, you know, are not that time dependent. Or maybe where you're more lax, right? For example, around login where the friction is not that bad. Maybe there you can use it. Um, but I think the the interesting bit is indeed around extracting features for free, and maybe from a varied data source pool that maybe we haven't looked at so far in fraud prevention. I think that's an interesting, like that is the most interesting bit, and the biggest promise that I see in foundation LLMs. And sorry foundation models. But yeah, I haven't seen it yet.
I think also there's, so my hypothesis is that our old traditional machine learning will continue to be really good. If you want, if it's based on the attacks of the past that are cleanly labeled. And if it's you, and assuming both have access to the same data. So I think a lot of the discussion about foundation models also, like the foundation model is given access to a bunch of data that the traditional machine learning wasn't given access to. So, like naturally, it will do better because it has more data. But on the other hand, I think the the change in the way that it's supervised also matters. So if you talk about like, unsupervised machine learning versus supervised machine learning. Traditionally in fraud, you'd have some sort of tree-based supervised machine learning. And I think there's independent value that can be generated by something that was not treebased machine learning with labels. In particular the labels, right? So you don't know that this is fraud. I think the, that they're, that these new models have an ability to extrapolate more.
Yeah. And then, and then to let's say reinforce the anomaly detection layer. Uh yeah. This also goes hand in hand where I think anomaly detection. Because of, you know, its lesser accuracy. Also with machine learning was traditionally, kind of like human in the loop, like the first human in the loop semi automated process that you had in fraud prevention and yeah, I I'm I'm guessing that foundational models can can fit there quite well.
So I'm going to jump then to the other side. So we talked, okay how do, you how do you avoid detection? And then okay, what could the future look like? So that the frauds can no longer avoid detection. But then there was the other side which was, well even if you know they're fraud. If you're going to challenge them they'll beat your challenge. Uh so now what about the step-up authentication? How does that change? And on one side uh some of that we already got. Because like, okay we know that phone isn't trustworthy. So you just don't send the text message to that phone or to that email. So we already addressed some of that. Um I think more generally, uh the old is becoming new again, that we start to rely more on delivery. So we know that you're not a fraudster because you ship that big screen TV, or at least not a third party fraudster. Uh because you ship that big screen TV to your known and tenured and trusted address, right? And so the way that the consumer interacts with the company. Like I log in using my email and I get emails and I have to click a link or something. Uh so because I have to have access to this email because the email is David, and it's trusted. It's low risk because I got a code to my phone and the phone is David. It's low risk because the TV was sent to my address. It's lower risk because the bank account is my bank account and that's where the funds were sent yada yada. So I think that will remain robust. And often times these, I'm going to call them contact channels. Uh have attached to them some history. And that's helpful. And you have ownership, you have regularity. On the other side, I think there is a big growth in digital IDs and eIDs. And states or countries issuing some credential that's bound with key exchange and encrypted. Uh, which will be, continue to be, like really hard for fraudsters to break. Uh, and so not now, but in our, in our future world. That's not that far off. Uh, and you could imagine that I use my Apple wallet to authenticate myself. And you know, you're just not going to be able to spoof that. And maybe you're, and asking people to go to the DMV and be mules and say, "Go, I show up at the DMV and I say I'm Chen." You know, I don't think that's going to happen at scale.
Yeah. Being able to, to basically match electronic IDs, to devices, to physical devices, that are known to be owned by, uh by you. That were acquired with, yeah, um yeah. Let's see. And I think the main question here is not whether this would become feasible, but whether this would become an acceptable part of a digital experience in the eyes of a customer, right? I think this is, this is the question that remains to be seen.
I mean, I think it will get there. And I say this just because for example, document verification, taking a picture, rolling your face around in a circle, taking pictures of the driver's license, like that's much more frictionful. It's meaningfully, less trustworthy. And basically, there's broad-based acceptance today. And so, we're taking this experience and replacing it with something meaningfully better.
That would be interesting to see. How that would shake things up. Uh because, I think, I mean, I think that we're pretty far from it. But this can also change quite quickly, right?
Yeah. Well, I mean. We, we're pretty far. But on the other hand, I think 7% of people have their driver's license in their Apple, of in the US, have their driver's license in their Apple wallet. So on one side we're far, and on the other side that's like non-trivial adoption. And not many merchants are using it today. But uh some are. And I think we'll continue to see the adoption grow rapidly, or you can go back to like Zelle. Where, you know, it went from nothing to something. Because the customer experience is just so good.
Or chip readers. You know, you put chips on credit cards. For a long time, Americans didn't have chip readers. And then, you know, they did.
Exactly. I can see how suddenly, you know, Apple comes up with a new schema that is unrelated to fraud or risk. Or even, you know, like finance. Um that would just, you know, like encourage, um encourage, adoption, right? With, uh, with users. That, you know, uh, as a side effect will also completely change how, like what kind of possibilities are open to fraud fighting teams. So yeah, I can definitely see, you know, that we will talk again in five years time. And, you know, that world would be completely different. Or not, we don't know. But this can happen, I don't want to say overnight, but this can happen relatively quickly. We've seen similar things. I mean, I'm just thinking about mobile, right? And how mobile affected, um the, uh, the kind of like purchasing behavior of users. And that changed very quickly. That changed, like within 3 years. It was, you know, there was a very big shift in around 20 I would say 2010 to 2013. Or right around that time. Uh, there was a very massive change.
I mean, actually just speculating. Since we're talking about far future. So, I'm going to give, like two random scenarios, which are more far-fetched. I have less confidence, but I, I'm super curious. Um, so I think typically, if you're a large conservative institution. Uh, you typically don't want to give other companies massive control over you. And you typically don't want to trust other companies. But, and here's my but. But, and as an example, for the longest time, if you were going to log in through Google, no one who did financial transactions would ever allow such a thing. But now, you're starting to see some companies that, you know, are smaller, are, you know, maybe not as high dollar, maybe that are lower risk, allowing you to log in through Google. Where it involves money movement. Albeit not the most extreme cases. And if you're a smaller company or a less mature company, there's a very good chance that Google does a better job fighting fraud than you do. And so, just to pick on, like you can imagine, a state like let's say. I don't know the fraud controls in the different states in the US, but there are varying levels. Often times, it's older. There's regulation and acceptable vendors that gets in the way. But I bet there are many states where if you want to log in, and get some sort of state benefit, the controls are really weak. And if they said you can login with Google, that the people who log in with Google will be way safer. Um, and what's more, I don't know, but I bet you could trigger this login with Google. You could make Google think it was a high-risk transaction. So for example, let's say I wanted to do login with Google, and it was a high-risk transaction. And I said I'm going to make this request. I'm going to try to see if I can tell Google this request is coming from Zimbabwe. And I'm not saying this is the right way to do it. It's clearly the wrong way to do it. But my point is, they have internally some way to step up, and if you have a way of signaling to them that this is a high-risk transaction, can you force them to step up? Or let's say medium risk. So that they step up, but only if it's not a recognized IP address, or device. And you know math 65% customer penetration, great solution, lots of history, continuous investment, huge organizational scale, um should that be the only solution? Is that defensible in front of a regulator? Probably not. If it was one piece of a layered set of layered controls, maybe it is defensible. Maybe it does become a useful positive signal. Or another example. Uh let's say, uh you have a CapitalOne credit card or American Express credit card. And uh you can have a merchant account, and do an off, and say I want to spend money on this credit card. Uh but not actually charge them. You just just place a hold, brief, for a moderate amount of money. Uh, just to trigger their authentication path. And then, okay these companies have a long history on you and you're you're once again doing a $500 transaction, from a risky merchant, uh and your IP address is on the other side of the world, blah blah blah. Like they'll have pretty good risk assessment. Now they probably won't approve of people abusing their controls. It's probably against terms and conditions, because they don't make money if you actually settle I don't think. But I think there are large institutions which will have long history with you as a customer, which have really good sophisticated fraud controls, and it would be really interesting to create some mechanism to allow people to piggyback on those fraud controls.
Yeah. Well, I think this is exactly the the Achilles heel of, you know, of the industry. That on one hand we're saying coordination is our biggest strength, but at the same time,
Yeah, I would say, but not not for the lack of trying. I think it's just very complex from a regulatory and also technological perspectives, right? So it's, it's just not that easy to do, uh these sorts of uh partnerships and cooperations. Yeah. And it's very times, it's just very very challenging. Just to share data. Just to share data between organization. It's already a big challenge in an offline manner. Um, and without you know, like using it for any kind of decisions. Um, but yeah. I agree um if if the regulator would, uh think of how to do something like that. And for example, you can see how I think it's a bit different. But in the UK and in Australia, where the regulator is, I think a bit more advanced. Or a bit more, I would say, forward thinking. Than for example, in the US. You do see these kind of, uh, initiatives. But at the same time these are also like much smaller markets, in terms of how many players are there/ And, you know, you basically, you capture four players. Then get them into some sort of a consortium, or some sort of network. And you have, you know, 80 95% of the market. And and that's pretty much done. So it's also a bit of a different game
I mean open banking I think is another example. Like not many places use open banking as a step up. And the challenge with using open banking, as a step up is, no I mean first of all you have to have coverage. But also maybe after I link my bank account, it doesn't clear the concern. It's like yeah, I see your bank account, you don't look any better than you did before. But I think there will be many people for whom if you did open banking as a step up, and you see a long history, and they can log into the bank etc. that meaningfully reduces risk. So I think there's a lot of ways to piggy back on other institutions potentially. That have like wide coverage, and decent fraud controls, that we're just not doing today.
Yeah. Yeah. Open banking is definitely a good point. Um, I want to ask you, David, I mean, we've been talking about how, you know, how fraud would look like in the future. We've been talking about how fraud systems should look like in the future. Um, now for our audience that, you know, are concerned about the here and now, but are also maybe a bit concerned about what's coming. What would be your kind of like top three recommendations? I just made up the number three. So use whatever uh whatever end figure that you are comfortable with. What are your top recommendations for teams to be busy with in the next 12 months, so they are better prepared, if and when these uh sophisticated attacks start to scale within their system.
I mean I think it depends a lot on the institution size. So if the institution is relatively smaller, um probably just use a very good orchestrator. That can orchestrate not just uh vendors, and data. But also can do some amount of models. Can also perhaps orchestrate solution providers, uh which involve device intelligence, or behavioral biometrics. You know, just because it gives you a lot of flexibility and ability to move more rapidly. Um, if it's a really large organization. Many times with large organizations, it's very, it takes a long time to do anything. And things are super complex. And having a good foundation becomes really valuable. And all of them know this. So I'm telling things they already know, but I would say have a high quality data link. Where all the data is available, uh, from any kind of control point. From any decision engine. Uh and, uh, would be, have general wise, uh uh, feature creation platforms. Which are available across your customer life cycle. Have ideally, have models which can be trained, uh retrained, every night rather than every two years. Um so, I think for the large organization, it's more about creating an infrastructure which allows, uh rapid iteration. Which makes the tech cost of change lower. Uh, and I'd say the same thing for small institution. Smaller institutions, you do that through, uh third parties. Larger institutions, you do that through in-house build. But oftentimes the cost of change is just so large, and so slow.
I love it. Because I think in the end, I must say, I very much agree with these, with these two approaches. Uh, I mean, basically it's the same recommendation. It's just about how you approach it. Yeah. And to me, you know, it kind of like touches the most basic fundamental principle of fraud fighting. And that is, in my mind, and that is that you are just as good as how quickly you can learn. And I think it loops really nicely back
And that's a great quote. You can excerpt that, excerpt that as a quote.
Uh it, loops back to something that you said at the beginning of the conversation. I'm trying to remember the exact words but, um you said how you know fraudsters can iterate after the first time that they experience failure. Whereas, uh, organizations large or small, it takes them more time. And it's more costly. And the, like the closer you can be to a fraudster's, uh, speed of learning. And I don't know if you can be as close, or even faster. But the closer you can be to a fraudster’s, uh, learning speed, the better off you are.
Yeah. It's funny. I like this, uh, an analogy. And it's almost, like a large institution might have 20 people learning. But each person, and I mean the people are learning, but each person represents, let's say a function/ And so you might have, 20 functions that learn. And each function takes a month to do one unit of learning. Whereas, maybe a fraudster might have two or three functions that learn. But they each might learn in the order of a couple days.
Yeah. By the way, I want, I want to say about that, is that also your, uh, learning speed is as good as the weakest chain in the link, right? You mentioned, hey, uh, it it's best if you update your models every night. But what happens if your labels are coming in only every week or every month through, you know, like an acquired chargeback, uh, file. Or what happens if, you know, whether it gets, uh, to you every month. Or every day. Maybe these labels are pretty old because up until you get the chargebacks, you know, time has passed. So there many times I find that when, uh, organizations try to, uh uh, kind of like, um increase their reaction speed. Uh, they tend to obsess and focus on very specific parts of the, of the chain. Uh, many times that, you know, they control directly when there are some kind of, like hurdles. Or kind of like bottlenecks, that they don't necessarily think about how they can solve them as well.
I agree. It's, this is very good insight. I'm going to go on a tangent that you have sort of inspired me, which is, as it relates to labels. I think there are a lot of places where you can get labels that are much more rapid, that people just don't use. So, the normal label is, they talk to someone. The person says they didn't do it, and that maybe takes a week, or a month, or maybe they see a fraud loss. Maybe that takes three months. Um, but you can say what's the rate at which, uh, challenges are passed and that's almost real time. Or you could say after sign up, what percentage of this population does activities which indicate very high trust, like maybe afterwards I did open banking. And it was a really pristine account, and clearly this is me, and maybe that happens 5% of the time, and maybe or 10% or 20%. And then you can say, well, on a larger population, if you see that number meaningfully less, maybe that's an indication that it's higher risk. And you know, is it enough to be deterministic? No. But as a leading indicator or, you know, whatever they send in a bank wire, they pay a utility bill that you can find activities, which become really positive, or meaningfully, uh, riskier, uh, as fast labels. But no one does this. It would be really interesting to, if I, if someone if, someone does this. Please write to me on LinkedIn.
Yeah, I must say in general, I think that, you know. From everything, all the problems that I've ever encountered in fraud prevention, labeling and cleaning labels is probably the hardest problem of all. And I see very few organizations that not, not that tackle that, but that are even aware of that. Uh, so that's that's yeah. I uh, I'm with you on the, on the labels tension. Um, awesome, David. I want to take a moment and kind of like summarize, quickly, the harrowing journey that we went through, uh, in this conversation. Where we were trying to figure out how fraud would look like in the near future, 2 3 years from now. And I think the, like what you outlined, what you portrayed. Is basically that the same sophisticated attacks that we are already seeing today, and maybe over the last few years, um we are going to see uh plainly more of them. Uh why? Because um honestly they are just cheaper to execute, right? With uh with genAI, with agentic capabilities you are able as a fraudster to basically produce 10x the amount of attacks for the same uh for the same investment. And that's something that, uh, is definitely scary. And we also talked about the fact that this is exactly why fraud prevention systems would break. It's not necessarily because they would encounter a challenge that they haven't encountered in the past, but because they would encounter more of the very difficult fraud cases, um, that they are just not able to detect. Um, and that would lead to elevated losses. Maybe not a fundamental, uh system breakage, but definitely more losses. And by the way, we already see today, uh in some industries, and in some uh use cases, that this is already the case. Then we also discussed, um how fraud prevention systems should look like, uh in the future. So they are able to meet this kind of sophisticated fraud attacks, especially at scale. And I think you mentioned a few things. You mentioned, uh first of all on the data side, you mentioned, uh 1) that usage will be more important than ownership. I really like that point where you said it's more important to understand how you use certain assets, um, for example email or phone rather than whether you can establish your ownership on them.
Or let me just say not, I won't say more important, but let's say it will be an added dimension that will be really critical as well. Carry on.
I take it. Thanks for the, for the uh fine tuning. Um you also mentioned consistency. That consistency will remain a very important dimension. Especially when establishing the risk of established, uh accounts. Where the, um the behavior of the legitimate account owner would not be something that fraudsters could easily, or cheaply, uh mimic. Uh, and that goes to everything from behavioral biometrics, to how you like literally the type of actions, uh, that you, uh, that you actually, uh, place on your account. Uh, last, you also talked about the fact that, um starting to look into aggregators,like data aggregators. That can match, uh, different dimensions of your identity. For example, your um, device and your IP. Or your IP and your, uh address.
Digital physical linkage.
Exactly. Yes. Um, this would become, uh even more, I think, they were always important. But I think even more important than before. And look at, and looking at other industries, I think especially the telco data angle, I think is is very interesting. And I think I am already starting to see, over the past couple of years, more and more cooperation between telco data aggregators and fraud uh teams. Um, like exactly around this use case. I think that that was also very interesting. We pondered without, you know, like with a question mark not an exclamation mark, um around both foundation models as well as authentication methods. And we tried to understand how this would, um, shape the future of fraud prevention systems. I think especially foundation models, um to me, it remains to be seen exactly what would be their role to play. Um, we talked about, uh maybe feature engineering. You mentioned, uh them being used for anomaly detection, uh which I really like. So there are definitely places where foundational models could play a part. Which are not necessarily straight out removing or replacing machine learning models. Um, and I think it would be interesting to see how this would shape up. Um, and lastly we talked about what should fraud teams do, already today, so they are better positioned to A) become that uh that uh better future fraud prevention organization. And also meet these uh future fraud attacks or fraud threats. And I really like your point.
Yeah, I just agree with it. Um, that it's all about increasing your reaction speed. And that how you actually go about it might look differently. Uh, for different organization sizes. You mentioned that smaller teams, that have less resources and have less their capability to invest in house, should probably go with an orchestrator of sort that is able to give them um all the different capabilities in one place. And I think the important thing here is to be able to kind of like control the reaction cycle across all of these point solutions. Uh, but more importantly I think for organizations that have their own uh, their own teams, and their own resources, to really invest more in how quickly they react. And we also talked about the fact that how quickly you react doesn't necessarily mean how fast, uh can you deploy a rule. Or how fast can you retrain a model. But the entire chain of learning. And I think that is so so so crucial.
I, I'd also add one other thing. Do you mind? Um, which which is that we walk through one detailed example for one kind of fraud. But you could do the same exercise that we went through today. And you could do it for account takeover, you could do it for scams, etc.
Yes. And if you're, uh if you're having trouble, uh doing it, uh yourself. I'll put David’s uh LinkedIn profile, uh in the podcast uh episode description. And you can, uh and you can message David. That's exactly the kind of engagements that he's, uh been, uh involved with, uh financial services today. David, I want to thank you. And I hope, uh dear listeners, that um other than scaring you, maybe I hope a bit. Uh just a bit. Uh and not a lot. Uh we also gave you, especially David, gave you some practical, uh ways in which you can improve your fraud prevention systems right now. Uh, so you are better positioned to whatever comes next. What comes Next, uh, we have guests, but, uh, well, we'll we'll all find out soon. David, it's been such a joy, such a pleasure having you here. Um, thank you very much.
Yeah, thank you, too. I think this is the most in-depth conversation we've had. And it's been super interesting for me, too. You know, you are also, you're very quotable.
We can have a, you can have a section, you know, quotes by Chen or something like this.
I try to. Uh that would be my next book. Uh once more, it's been a pleasure having you here. I super appreciate you joining us. And for all your listeners, I hope you enjoyed it as well. And I see you all next Saturday.