Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
Fraudology

Fraude na entrega de alimentos: do restaurante à porta de casa

38 min

Bem-vindo de volta ao Fraudology.

Hoje, recebo Sudhir Lanka, Diretor Associado de Estratégia de Fraude da GrubHub. A equipe de Sudhir já não cuida apenas da GrubHub. Recentemente, o seu âmbito de atuação foi ampliado para incluir a Wonder, a nova empresa-mãe da GrubHub, e a Blue Apron. Isso significa que ele precisa pensar nas fraudes relacionadas com a entrega de alimentos em três modelos de negócio verdadeiramente distintos ao mesmo tempo, e eu queria explorar como isso realmente muda a sua abordagem.

Analisamos o que torna um marketplace de três lados particularmente vulnerável à fraude, já que a GrubHub precisa proteger clientes, restaurantes e entregadores ao mesmo tempo, e qualquer falha na proteção de um desses lados acaba por comprometer a confiança de todos os outros. Sudhir explica os principais vetores de fraude com que a sua equipa lida — apropriação de contas, fraude em pagamentos, abuso de reembolsos e abuso de promoções — e partilha alguns dos exemplos mais específicos e concretos que já ouvi neste podcast sobre como cada um deles ocorre na prática, incluindo as desculpas exatas que os clientes dão para obter reembolsos a que não têm direito.

O que você vai ouvir neste episódio:

  • Como a trajetória profissional de Sudhir no JP Morgan Chase, Discover e GrubHub moldou sua abordagem à estratégia de prevenção a fraudes em cada etapa de crescimento
  • Por que GrubHub, Wonder e Blue Apron apresentam riscos distintos de fraude na entrega de alimentos, apesar de compartilharem a mesma missão fundamental
  • Os três principais vetores de fraude monitorados pelo GrubHub — invasão de contas, fraude em pagamentos e abuso de reembolsos e promoções — e como eles se manifestam de maneiras diferentes em cada linha de negócio
  • Uma análise detalhada da invasão de contas de restaurantes, incluindo como o e-mail comprometido de um proprietário pode levar ao redirecionamento de um pagamento via ACH e a um dispendioso pagamento em duplicidade para a GrubHub
  • Exemplos reais de conluio entre motoristas e clientes, incluindo ciclos de autoentrega e uma exploração surpreendente ligada às leis de salário mínimo em cidades como Seattle e no estado da Califórnia
  • Por que o abuso de reembolsos e a fraude de primeira parte não podem ser previstos no momento da transação, e a abordagem de Sudhir para, em vez disso, implementar controles no verdadeiro ponto de irreversibilidade
  • Como funcionam os controlos antifraude em várias camadas nas fases de criação de conta, finalização da compra e pós-encomenda, incluindo autenticação multifator, autenticação 3DS, validação do CVV e verificação do PIN de entrega
  • A diferença entre fricção leve e fricção intensa, e por que Sudhir reserva intencionalmente a fricção mais intensa para uma porcentagem muito pequena de clientes
  • Por que Sudhir considera a estratégia de combate à fraude fundamentalmente favorável ao crescimento, e não contrária a ele, e como proteger a confiança em todo o marketplace se traduz diretamente em receita

Você deveria ouvir este episódio se:

  • Trabalha com estratégia antifraude em um marketplace, serviço de entrega de comida ou plataforma que precisa equilibrar vários tipos de usuários
  • Lidam com abuso de reembolsos, abuso de promoções ou fraude de primeira parte e querem uma estrutura prática para controlar esses problemas sem depender excessivamente de previsões
  • Querem entender a fraude de invasão de contas de restaurantes e de redirecionamento de pagamentos sob a perspectiva da plataforma, e não apenas do consumidor
  • Estão a criar ou a aperfeiçoar controlos antifraude em várias camadas e querem exemplos concretos de quando aplicar fricção ligeira ou fricção forte
  • Precisam de argumentos para defender internamente que a estratégia antifraude favorece o crescimento, em vez de o impedir
Notas do episódio

Três linhas de negócio, três riscos diferentes de fraude na entrega de alimentos

A equipa de Sudhir abrange agora a GrubHub, uma plataforma tradicional de entrega de comida online, a Wonder, um conceito mais recente de cozinha fantasma que oferece várias gastronomias a partir de um único espaço físico, e a Blue Apron, um serviço de subscrição de kits de refeições. Cada modelo de negócio cria uma superfície de fraude diferente. Um marketplace com três intervenientes como a GrubHub, onde clientes, restaurantes e estafetas interagem entre si, tem muito mais pontos de entrada para fraude do que um serviço baseado em subscrição como a Blue Apron, que tende a enfrentar problemas mais circunscritos, como testes de cartões ou apropriação de contas.

O impacto da invasão de contas varia conforme o lado do marketplace visado

A tomada de controlo de contas de consumidores é o tipo de fraude que a maioria das pessoas já conhece, mas o exemplo mais marcante dado por Sudhir ocorreu do lado dos restaurantes. O comprometimento do e-mail pessoal de um proprietário pode permitir que um fraudador altere diretamente os dados de pagamento por ACH na conta de um restaurante, desviando dinheiro real de uma pequena empresa, enquanto a GrubHub continua a dever ao restaurante o pagamento original. Como este tipo de comprometimento ocorre inteiramente fora dos sistemas da própria GrubHub, Sudhir observa que muitas vezes não há qualquer visibilidade sobre o problema até o restaurante ligar para o comunicar.

Não é possível prever abusos de reembolso, por isso Sudhir implementa controles no ponto de irreversibilidade

Ao contrário da fraude em pagamentos, o abuso de reembolsos envolve um cliente real que utiliza o seu próprio método de pagamento, o que significa que não pode ser sinalizado no momento da transação. A abordagem de Sudhir consiste em deixar intencionalmente que a encomenda seja processada e só aplicar controlos quando o cliente apresenta um padrão claro de abuso — dezenas ou centenas de reclamações falsas, não apenas uma ou duas. Este enquadramento mais abrangente aplica-se muito para além do abuso de reembolsos: os controlos devem ser implementados no ponto em que uma perda se torna efetivamente irreversível, em vez de se tentar prever um comportamento indevido antes de este ocorrer.

O conluio entre motoristas e clientes assume algumas formas surpreendentes

Além do caso mais óbvio de alguém se fazer passar simultaneamente pelo cliente e pelo entregador para receber o pagamento da sua própria encomenda, Sudhir descreveu uma fraude mais subtil associada às leis do salário mínimo para entregadores em cidades como Seattle e em algumas regiões da Califórnia. Os próprios entregadores fazem encomendas de valor extremamente baixo apenas para receberem a remuneração mínima garantida associada a essa entrega, aproveitando-se assim de uma política que deveria proteger os entregadores legítimos.

Controles em camadas e a diferença entre fricção suave e rígida

Sudhir divide a sua abordagem em duas vertentes: uma infraestrutura de longo prazo, concebida para impedir ataques de grande escala, como o preenchimento automatizado de credenciais e a criação de identidades sintéticas, e uma vertente de investigação de curto prazo, que se adapta diariamente a novos padrões de ataque. São aplicados controlos antifraude em várias camadas em cada etapa do percurso do cliente: biometria do dispositivo e comportamental e autenticação multifator na criação da conta; autenticação 3DS e validação do CVV no checkout; e verificação do PIN de entrega após o pagamento já ter sido efetuado. Este último pormenor chamou-me particularmente a atenção, uma vez que a solicitação de um PIN no momento da entrega acrescenta fricção após a transação, não podendo ser contornada por alguém que simplesmente intercete uma encomenda de comida num local público, como o átrio de um hotel.

Reformulando a estratégia antifraude como favorável ao crescimento, e não contrária a ele

Sudhir encerrou com uma observação que, na minha opinião, mais líderes de prevenção a fraudes precisam dizer em alto e bom som. A estratégia antifraude não consiste em impedir o crescimento, mas em proteger a confiança que, antes de tudo, torna esse crescimento possível. Quando clientes, restaurantes e entregadores confiam que uma plataforma fará os pagamentos devidos e os protegerá de forma justa, eles continuam voltando, e isso se converte diretamente em receita.

Principais conclusões
  • A fraude em serviços de entrega de alimentos assume diferentes formas consoante o modelo de negócio, sendo que marketplaces trilaterais como o GrubHub enfrentam mais pontos de entrada do que serviços de assinatura como o Blue Apron.
  • A invasão da conta de um restaurante pode levar ao redirecionamento de pagamentos via ACH, causando prejuízo ao restaurante e obrigando a plataforma a arcar com um oneroso pagamento em duplicidade.
  • O abuso de reembolsos e a fraude de primeira parte não podem ser previstos no momento da transação, pois o cliente está usando seu próprio método de pagamento legítimo.
  • A estrutura do ponto de irreversibilidade consiste em implementar controles antifraude no momento em que uma perda se torna irrecuperável, em vez de tentar prever o abuso antecipadamente.
  • O conluio entre entregadores e clientes pode assumir formas inesperadas, incluindo a exploração das leis de salário mínimo por meio de pedidos próprios de valor intencionalmente baixo.
  • Os controles antifraude em camadas devem ser distribuídos por toda a jornada do cliente, desde a biometria do dispositivo e comportamental no login, passando pela validação do CVV no checkout, até a verificação do PIN na entrega.
  • A fricção suave protege tanto os clientes quanto a plataforma sem prejudicar significativamente a experiência dos usuários legítimos e deve ser reservada principalmente para essa finalidade.
  • Enquadrar a estratégia antifraude como favorável ao crescimento, em vez de contrária a ele, torna mais clara para a liderança e as equipes multifuncionais a justificativa empresarial para o investimento.
Conclusão final

O que mais me marcou nesta conversa foi a naturalidade com que Sudhir transitou entre três negócios muito diferentes sob a mesma estrutura e, ainda assim, chegou a um princípio comum. Não é possível prever todos os tipos de fraude antes que aconteçam, mas é possível definir de forma consciente o momento exato de agir. Seja abuso de reembolso, invasão de conta ou um motorista explorando discretamente uma política de salário mínimo, a verdadeira competência em uma estratégia antifraude está em saber exatamente onde fica o ponto sem retorno e implementar os controles justamente ali.

Conecte-se com Sudhir Lanka | LinkedIn
Diretor associado de Estratégia de Fraude, GrubHub

Conecte-se com Karisse Hendrick | LinkedIn
Apresentadora do podcast Fraudology
Especialista premiada em fraudes cibernéticas
Consultora de prevenção a fraudes no comércio eletrônico
Conselheira de startups, palestrante e
consultora de empresas da Fortune 500

Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:07
Welcome back to the Fraudology podcast. I'm Karisse Hendrick and I am really looking forward to my conversation today with my guest Sudhir Lanka. Sudhir is the associate director of fraud strategy for GrubHub. I have uh only recently gotten to know him but really enjoy our conversations and I think you will too. So, Sudhir, welcome to Fraudology.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
00:31
Hey, Karisse. Uh, thank you. Thank you for having me on the podcast. Uh, really excited to talk to you today.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:39
Me too. So, the first question I ask every guest on Fraudology, you know this uh because the answer is always different. How did you get started in fraud?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
00:51
Um, actually, you know, almost 13 14 years back. Um, you know, I just graduated from my college and um, to be honest, I was just simply looking for a job at that point and uh, I looked at the the job at JP Morgan Chase risk analyst and I found it interesting and I applied for it. I got the job um, you know, fortunately and uh, ever since then for 14 years I've been in the fraud world. Um, I got hooked onto the fraud world. It's very interesting, very intriguing. So I just I just been here forever now.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
01:28
And after uh being an analyst at JP Morgan Chase, you went to Discover. Is that right?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
01:35
Yes. Yes. Uh after JP Morgan Chase, I think I've been there for about 2 and a half years and then I moved on to Discover. Um again, same transaction fraud strategy team at Discover. Again, um kind of my my scope expanded a little bit. I covered uh both card present and card not present, transaction fraud. Uh you know I was kind of working on building you know uh crossover risk profiling, trying to understand how does fraud happen on card not present, how does it differ from card present. Um you know um you know I believe you know this is where discover is where I got a really good hold of uh what is fraud like, how does fraud happen, how fraudsters adapt, how do they attack at scale, and what do we do as as fraud strategists, right? You know, how do you counter attack, right? And uh yeah and And you know that's that's what I did at Discover at that point. Yeah,
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
02:28
That had to be interesting from the issuer perspective. The issuer and card brand perspective. Uh and really gave you a 10,000 foot. It sounds like it gave you more of a 10,000 foot view than being a transaction analyst at JP Morgan, which makes perfect sense. Uh and helped you see like, okay, this is how all the pieces go together and this is the bigger picture. Um, which you need for fraud strategy. Um, to be able to know not only what the pieces on the on the board game are now, but what they will be in several months and you know, okay, they're doing this now, what are they going to be doing soon so that we can get tools in place to counteract that.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
03:14
Yeah, absolutely. You know, I I feel that, you know, there's like um you know, uh possibly two things involved here. The first is um uh you know, once you gain some sort of experience, let's say you're 2 or 3 years into the into the fraud world, you try to, you know, you you start putting pieces together. You talk to a lot of different teams. You know after I came to discover I started speaking to the fraud operations or you speak to the chargeback management team or or you talk to you know account takeover team. Like there's there's a lot of different fraud vectors that we deal with, right? So sitting with everybody, speaking with everyone, you know um constantly talking to your leaders uh give me that 10,000 foot view you're talking about. And secondly uh companies like discover like you know specifically banks let's talk about them, right? They already have established process processes and SOPs and you know you know what you're dealing with. They've they've had they had they laid out everything um exactly how fraud needs to be handled, uh how much they are losing, uh what are the regulatory requirements, and everything is laid out. So you have, uh I would say, relatively an easy path to learn uh quickly. Uh uh so that actually helped me a lot um you know at discover. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
04:31
Yeah and then after Discover you went to GrubHub
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
04:35
Yes. Yes, that's where I am right now. GrubHub, uh, GrubHub has been, you know, has been great to me. Um, I've been here for about, uh, 5 years, almost 5 years now. Um, I'm currently leading the fraud strategy function um, at GrubHub recently, actually my team has recently expanded the scope to include Wonder and Blue Apron as well. So, we have three business legs under us now. Um so for anybody who doesn't know GrubHub has been acquired by a company called Wonder last year. So now we have um Wonder as a parent company and then we have GrubHub and then Blue Apron as well. So we're looking at all three business lines at this point.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:16
Wow.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
05:16
Uh so I lead the fraud strategy function end to end diners merchants and drivers. Uh pretty much looking at uh a wide variety of fraud vectors. Uh, at this point I'm I'm currently doing that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:29
That's a big job. Um, I'm familiar with GrubHub and Blue Apron, though my listeners are international, so they may not. Uh, I'm not familiar with Wonder. So, could you share just a little bit about each of those companies because I think they're while they're similar, they're also unique.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
05:49
Absolutely. They're 100% unique. So, Wonder is is relatively a new company, I'd say, compared to GrubHub. Um um so they are predominantly concentrated more in in the east coast of the of the country more in New York and uh you know Connecticut and all that. They're expanding to you know Wonder is expanding to Texas and other states as well in the coming years. But um what Wonder does is they have physical stores uh like you can consider them more as cloud kitchens or ghost kitchens. The unique concept of wonder is you go to a wonder store and you're going to find food from every single cuisine that you can think of. In one store, you can order Indian, you can order pizza, you can order sushi, you can order Mexican, any different food that you can think of. Uh, you know, Wonder offers that, right? So, that's the unique concept that Wonder has come up with. And um and uh Grubhub is is like a it's like a traditional online food delivery platform. Um it's it's a you know it's a it's a well-known company similar to a lot of businesses across different countries as well. And coming to Blue Apron, Blue Apron is a is a meal kit service. So you just um you know um you know figure out okay what do you want to cook? They deliver raw ingredients uh to your house planned out weekly and you can you can kind of uh use them as more of a subscription service at this point. Uh but um but the what Wonder wants to do um as a whole as a parent company is to become one-stop shop for all your food needs. Uh you want to order raw ingredients, you want to order online, you want to go to a store, you want to order any cuisine that you want, it's all in one place. And that's that's what Wonder is trying to do at this point.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:38
Wow. That's that's quite a goal. And yeah, it's uh the the through line is obviously feeding customers, right?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
07:48
Absolutely.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:48
Uh but they have different business models and with different business models come different fraud risks.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
07:54
Oh, 100%.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:55
Right. What you would have what you would see for traditional food delivery from a restaurant. You know, it's kind of a three-sided marketplace or four-sided marketplace. What do you consider it?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
08:08
We consider it as a three-sided marketplace.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
08:11
Right. Right. And as you mentioned, you have you have the uh customer who orders the the meal, you have the merchant that makes the meal, and then you have the driver that connects the two and brings the meal from the merchant to the consumer. So, you know, whenever you have whether it's two-sided marketplace with a buyer and a seller or three-sided in this case, uh I just didn't know if you considered yourself a a fourth part of the marketplace. That's why I was it was like I Yeah, some companies do and so they're like we're from a three-sided market. I'm like but are you you just have buyers and sellers and they're like but we sit in the middle. So um that's why I was asking. But um yeah that has such unique challenges because there's opportunities for fraud on all three of those, you know, sides, right? Um whereas a meal delivery service that runs on subscriptions is going to have a different type of fraud. You know, they're they're not going to um have as many opportunities for fraud as many channels or or sides. Um but you'll probably see some card testing or you'll see some account takeover or that type of thing. Um y what what are the type of fraud vectors or how do you define fraud at GrubHub or Wonder I guess?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
09:36
Yeah, absolutely. Now you know you know sometimes it's it's confusing not confusing but you know we keep thinking should we call ourselves Wonder or GrubHub but there still but it's just you just get confused. But uh but uh but yeah uh talking about fraud right you know, when we when we say fraud I'm like you know what what my team deals with. Um it's not a simple um fraud fraud that everybody knows of right. So what we deal with is um fraud is one aspect of it. We also deal with abuse. We also deal with any kind of scams uh um you know any internal fraud anything that happens end to end uh perpetrated by anybody on the platform right. So when we say fraud it can be uh the primary ones that everybody knows about is ATO what we call account takeover uh is the primary one obviously. And second is uh what we call the um stolen credit cards or stolen payments let's let's call it stolen payments at this point. Um these two are the primary crime vectors that we see um on GrubHub um and I'd say I'd extend it and say Wonder and Blue Apron as well. Similar fraud vectors is what we see. Okay. And talking of talking about abuse, um we do see a lot of refund abuse, right? Uh some companies call it as returns abuse. You know, in the food delivery platform, it's technically it's refund abuse. You cannot return your food. So, it's it's refunds of course. So people uh order the food, they take the food, they eat it, and then they call and they call the bank and say that I did not receive my my order or they call GrubHub and claim that they did not receive it, right? Or they'll make up like thousands of reasons to get a refund. Uh
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:17
The the meat was bad or the you know like
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
11:21
There's so many things that they can
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:23
Yeah. Yeah. The driver ate my food. I've heard that one. And I've heard uh um you know, I got food poisoning from this or I got I got the mo I got the cheapest item, but I didn't get the most expensive item, right? Like I got I got the soda, but I didn't get the steak dinner. Uh so I need a refund on that. Like those are just some examples of what you mean by by refund fraud.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
11:50
A refund abuse. Yes,
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:52
Refund abuse. Yeah, absolutely. Mhm.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
11:54
And uh and the third major one that we deal with is the promo abuse. Uh when I say promo, it can be uh a marketing promotion or it can be a a a credit that you received from uh from our customer care team. It can be it can be either way. You basically got a credit or a promo on your on your account and then just you're abusing it uh by creating a loop of your own accounts. You're referring to yourself, let's say, for example, or um or you're going to Google and you're trying to um you know, exploit the the marketing uh you know, promotions that we have on Google or any any online website as well, right? So, that's the promo abuse we're talking about. Uh and that is the third uh primary vector that we deal with at this point. And I'd say that, you know, it's it's pretty similar um across the three business lines at this point. Um same fraud vectors you see you know um on some on on one side you might see fraud is higher on one side you might see abuse is higher but still pretty much the attack patterns remain the same. Um one additional point or one additional insight we want to add here is that uh all we're talking about right now is more on the customer side right. There's also another a whole vector of fraud that we see on the merchants and the driver side as well right. So we see similar you know um uh merchant accounts being taken over on merchant or the restaurant when when I say merchant it's the restaurants owners being socially engineered to reveal their personal details. Um their payment methods or the ACH linked on the on the on the restaurant portal is replaced by fraudsters uh bank information and money taken out and and there's so many other fraud vectors that we deal with on the driver side as well but um, but it's huge. It's It's huge. And there's there's a lot of lot of things that we're dealing with at this point. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
13:50
Yeah. I would imagine with that example you just gave as far as account takeover on the restaurant side. I mean, especially for a busy restaurant, you're probably talking about thousands of dollars that GrubHub will be paying out via ACH to that small business, that restaurant. And if the restaurant owner is socially engineered to give up their, you know, GrubHub password or there's spear phishing emails or things like that and they, you know, are asked to log into GrubHub, but it's a fake, you know, website. They then automatic very quickly the fraudster goes in and as you said changes the payment method uh or the payee basically um you know changes the bank account that GrubHub is paying the restaurant and now the fraudster is getting that money and not the restaurant and that can really disrupt business and be really scary. And then on top of that, you know, the restaurant is looking to GrubHub to pay them again, right? I mean,
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
14:53
Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
14:53
Right. Right. I mean, they didn't get the money the first time, but on your end, it looks like a double payment. Uh, so that can get very expensive even though your AOV, your average order value is, you know, I mean, you don't have to tell me, but I would guess, you know, $50 to $100.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
15:11
Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
15:12
You know, that's, you know, in payment fraud, in credit card fraud, that's $50 to $100, you know, each time it's stolen, which adds up. But driver ATO or uh, you know, restaurant ATO is the risk is so much higher because the amount is so much higher.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
15:32
Oh, 100%. Yeah, absolutely. You know, um, you know, I just remember one thing as you as you were as you were talking about this, right? Um, one one scenario that that that I've seen happen again and again is um restaurant owners personal email address and password are compromised a lot of times. And when that happens um it's it's extremely difficult for even for a company like GrubHub to do uh to do anything about it, right? Because we don't know what's happening. It's it's everything that's happening. It's external. So we actually don't know until they call and complain that hey this happened or something you know any any kind of alerts that we receive until that point we don't even have any data to to say that hey there's something wrong with this, right? So those kind of scenarios hit the hardest, the reason being our small business restaurant owners are being impacted by this. And um and um that's that's much more impactful for for for a company like GrubHub is uh it's it's important for us for as as a company and a fraud team to protect our restaurants as well because that's what keeps our supply like that demand and supply chain going on, right? So it's it's very important important we take care of that as well. Yeah. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
16:53
Yeah. You need all three of those pieces in the marketplace to be thriving and happy and you know producing. You know, you've got three sides of the marketplace and you've got the consumer and the driver and the merchant. If one of them isn't paid or paying, then it falls out of balance and the marketplace doesn't function.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
17:18
Yeah, absolutely. I think it's it's very important to maintain that balance. Um not like you know, of course, the the main um you know, reason for that is like the end goal is to kind of maintain that balance of that supply chain. Now you have diners coming in and ordering, restaurants fulfilling the orders, and you need to have enough number of drivers to fulfill the orders themselves, right? But um but but you're right. I think it's important to take care of every single party in this cycle. Um you know um you know to ensure that drivers are getting paid fairly uh protecting merchants, we're protecting diners um you know from any you know fraud attacks. Um um absolutely I totally agree with that. Yeah. Hm.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
18:00
You know, do you ever I know a lot of times on marketplaces, whether two-sided or three-sided, they'll have some kind of collusion occur um between the buyer and the seller, or in your case, it could be the driver and the restaurant or, you know, maybe the customer and the driver or, you know, whatever. Um is that something that you've you've had to experience recently?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
18:24
Yeah, absolutely. You know um we do see collusion you know although it's not it's not as extensive as as a single party fraud let me say that. But we do see instances of collusion happening as well uh predominantly what we see is um you know diners and drivers colluding uh colluding sometimes um to to kind of create a fake loop of ordering in the sense that the the the same person could be posing as a driver and a driver and they're they're potentially accepting their own orders to create a fake loop um just to take the the driver pay um from GrubHub, right? So that's that's the net loss that the company is going to have. But in reality, the the same person is ordering and they're they're getting they're they're basically picking up their own goods, right? Um so that is that is one um one way we saw collusion. And in uh um in some cases what we see is um you know um diners do come in and u you know place uh like really low dollar orders like uh let me say like a sauce packet or like um something else which is like a a dollar or a $2. Um this we see this specifically happening in um in locations like you know Seattle or California where there's like minimum wage laws that are in effect that you have to pay a certain amount to drivers who are on on like on on this and like actually actively deluding at that point. Um so drivers sometimes do kind of exploit this you know of course it's a very small percentage of drivers not you know of course vast majority of them are of course good drivers that we have
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:04
Right
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
20:05
Um they're simply kind of um you know placing this $1 order and then just taking out the driver pay, right? Uh so that's that's kind of uh you know that fake loops and um you know exploiting the uh controls or the exploiting the laws which have been which have been put in place to protect genuine divers are being exploited. Uh um so those are the you know those are some of the scenarios that we see in terms of collusion um at GrubHub mostly. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:34
Huh interesting. I wouldn't have thought of the drivers but then again I wasn't thinking about the laws in place in California and the Seattle area about drivers. Um, I would have thought, you know, when I was thinking collusion, I was thinking the first scenario you said when a diner and a driver are the same person.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
20:56
Yep.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:56
And they're, you know, trying to do money laundering or they're using a stolen credit card um to place the order, get the food, and then they're the same person, you know, the same person is getting paid to deliver it to themselves, basically. Um,
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
21:16
Yep.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
21:17
That's what it Yeah, that's fascinating. So I mean without going into too much detail um obviously because this is on a public platform uh when you're looking at controls to put in place for these types of frauds whether it's account takeover or uh payment fraud or refund abuse. Uh what are you looking for in controls and um you know what are your goals there?
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
21:47
That's a that's a good question actually. So to think about the way the way I think about you know placing controls right you know um this there's two ways. First is you need to have um long-term infrastructure on your platform to protect your platform from um from any of these major attacks that we see all the time. Right? So when I say major attacks, it can be in terms of credential stuffing uh like where you see thousands and hundreds of thousands of login attempts coming in within a matter of minutes. Um uh or you have thousands of synthetic identities being created on your account or um um um you know significant amount of account takeover happening at the time of order placement. To counter these kinds of attacks, you need to have long-term infrastructure in place where you where you have something like um a multifactor authentication or you have something like 3DS or or or or you have something like a photo verification at the time of drop off uh to ensure the the order is actually being delivered. Um you need to have all these things in place, right? And the second track, the way I think about it is more of a short-term or let me say more like a a daily investigative track is something that you need to have um where you have your set of agents or your set of investigators uh going in interactively uh looking at okay what's what's happening today what's what's out there what are the new trends or new attack patterns that are coming out, uh and uh and how do we stop it, right? Um that's the way I think about it now. Um talking about like more from a end to end perspective, right? Um at least at the the the way I've I've worked so far is to have uh layered controls, right? I'd say that fraudsters are best if they're not on your platform, right? Obviously, so you you want to stop them at account creation or login at most. It's probably always the best option that you can go with. So you need to have really really strong controls at that point. You're talking about uh risk scoring. You're trying to figure out their their device information. Uh where are they coming from, their location, their behavioral biometrics, um any of these controls, you need to kind of uh you know um um you know consolidate all these signals and build something at the account creation or login stage. And then obviously you're going to have something at the checkout phase or the order placement stage as well where you have real-time decisions being made on each single order or transaction. Right? You you either say that you want to accept the order or you want to reject it or you want to send it to 3DS or maybe you want to do an internal OTP just send out an OTP to customers phone number um or or you do something else you do a CVV validation. Uh there's a lot of different controls you can place, right? Uh and then you talk about, and then the other set of controls I strongly suggest, um, is post order order placement, right? So once customers have actually placed the order, you need to have a set of controls monitoring, more, this applies more for refund abuse I'd say. Um the way the approach that I have taken is I generally do not want to reject anybody suspected of refund abuse
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
25:17
Right.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
25:18
Um I I do want to take their order, right? And um and
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
25:22
They're using their own payment method. It's them right.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
25:25
Yeah. And then you you deal with them once the order is completed. Uh and they call you and say that, hey, you know, something is wrong with my order, right? Obviously, you want to protect your good customers and if they really do have, you know, a few orders that they have had bad luck with or bad experience with GrubHub, obviously they're going to get a refund. But if if you find somebody abusing your policies like hundreds of times, tens and hundreds of times, you do want to place a control to say that hey, you know, you know, we think, you know, you crossed the threshold of what we call as abuse and we're going to not give you a refund or we just give you a credit or something like that, right? So, kind of having this layered controls is is what I think works best. Um, at least that's what I've seen in in in in our case. Um um and and you know that's that's generally my approach in you know implementing any kind of control.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
26:20
I like the way you put that because I've I guess I haven't ever thought of it in that way in the two different ways but there's the infrastructure piece. There's the, you know, the systems that you put in place for transactional monitoring and account protection and um all of that. And a lot of those things can be done behind the scenes so they're not impacting the good customers. Um and then there's also that additional piece where it's almost like I'm trying to think of the right term. So, it's not like firefighting necessarily, but it's a little bit more like you've got these levers and these and these systems that you can, you know, dial up or dial down or, you know, you can add something in place like maybe, you know, and I don't know this to be true, but I know this to be true for your overall industry that, you know, for several years the picture of an item being delivered wasn't required. Um but then refund abuse you know came up and uh that was you know really uh painful financially. And so, you know, as an industry, your competitors and yourself, uh, made decisions at different times to, you know, store those pictures and do all that you have to do with those photos to be able to prove delivery happened and that, you know, the the item wasn't the bag wasn't opened or, you know, that whatever you need to prove. Um, and then I know more recently I noticed when I was traveling um, a couple of weeks ago I I didn't use GrubHub because they weren't super big in the city I was in, but I used a competitor and they required me to use a PIN, you know, to give the driver a number because I was, you know, outside of a hotel and anyone, it wasn't just a residential house. Um I had to give them a four-digit number in order for them and they had to enter that number and into their system and they didn't know what it was. They just had to enter the number I gave them um in order for um me to get my order. And so that that is one of those things, you know, the the systems and controls that second part where okay, we're starting to see this trend. We need to go this route and maybe we need to implement something new like PIN numbers. Maybe we need to um you know dial up our controls on two-factor authentication. Maybe we're you know we're doing more of that. Um same with like account takeover. There's also, you know, with ATOs, there's the ability to, you know, look at device and say, is this the same device that has logged into this account always or is this a new one? Um, yeah. So there's all different. I I love nerding out on fraud strategy because uh it's the methodology is similar but the solutions are a little different depending on the business model of the merchant right
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
29:45
Agreed. Yep. Um you know you're you're absolutely right. I think you know depends on the type of merchant and the type of business that they are operating in uh for a company. Like for example just taking some name for example somebody somebody like Best Buy right they they sell like high value items and is compared to GrubHub it's just the business is different and the kind of controls that you please has to be different. Uh and I you know what you mentioned earlier as well in terms of pin verification or you know these kinds of controls um this is more of a softer friction that we're talking about. We're placing we're placing friction but it's it's soft and we are giving a chance for customers to go through, right? Uh we're just doing this to protect the customers and in turn protect the platform as well, right? So, it can be in terms of, you know, entering a PIN. It can be uh as simple as say CVV validation. You just enter your your card details once more, right? We're just not asking you to do much here. Um this this this helps protect them as well company and a lot of hassle. Um right so you know we generally try to approach a lot of these problems with, of course, obviously we just don't want to do any friction but if we have to we go with softer friction. And a very very very small percentage of customers do get hard friction, right? And and you know I believe is it's it's necessary for some customers or a cluster of customers to have that hard friction. It's absolutely necessary in this in this business so Yeah,
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
31:23
I agree. I actually haven't ever heard the term softer friction, but I like it. Uh, the thing I was thinking about the PIN when you were talking about it just a minute ago was it's very smart because not only are you asking for it at the time that fraud would occur, right? You know, if someone else was staying at my hotel and they saw a food delivery guy standing outside, they could just say, "Oh, that's my delivery." and and get it. Um, so it's at the time that like some kind of fraud could happen and then I would be saying, "Ah, I didn't get it and I need my money back." And all that. Um, but also the transaction has already occurred. So, you're not you're not giving them friction before they pay you. You're giving them just a little bit of light friction. You know, at the time of delivery after you've been paid, which I think is really smart. You're not, you know, that that's something that you've done in all that you've said today.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
32:23
Mhm.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
32:24
That's something that I appreciate. I have seen some companies in my perspective make mistakes when they try to identify a certain typography of fraud prior to the fraud taking place. So what I mean by that is if it's not payment fraud, then you can't predict it at the time of transaction, right? You can't predict firstparty fraud at the time of transaction because it's the person using their own card. You can detect first party fraud when they're making the claim or when they file the chargeback or you know that's when the the act of fraud occurs. Um, you can't predict. Yeah, you can't predict refund abuse at the time of transaction either. You can't predict, oh, they're going to claim that they didn't get their food. Um, unless they've done it 36 times before on their same account. Well, then that's a little different. But we know that especially in the day of age and age of it being relatively simple to create online accounts for different apps and and services. You know, if they're denied on their 36th time or their 10th time or whatever it is, they'll just start open up another account. So, instead, let's do it at the time of uh where the compromise occurs or where the um you know, the kind of the the point of um compromise, not the point of compromise necessarily, but like the um the point that the loss occurs or that the claim is made or whatever else. I like that a lot.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
34:06
Absolutely actually the uh no another way to put it put that is you place control where you think the loss is going to be irreversible, right? So if you got fraud, if you let it past check out, you're not going going to get it back, you have to pay for it, right? For refund appeals, you can wait until they call you for asking for a refund and then do something about it, right? So figuring out that point of irreversibility is the is the important thing here, and then place the controls based on that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
34:42
You just made that sound so much smarter than I did. I like that you just took it very succinctly and yep that's exact. You're right. It's where it's irreversible. Um it's where it's identifiable and irreversible. I like that a lot. Well, Sudhir, we are um about at time and I want to make sure I respect your time because you're so busy, but um I wanted to just first ask you if there's anything else that you wanted to mention uh about anything that we talked about today.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
35:16
Um nothing specific about what we spoke about today. I'd say that, you know, um I generally I generally say this to you know, most of the folks that I meet is um you know, a lot of folks perceive fraud or fraud strategy as anti-growth. Uh and I want to I want to emphasize that it is not. It is actually I want to say that it is progrowth because if you want to spend your money wisely, you need to take out bad customers and you you spend the money but you want to give it to good customers who will come and order on your platform. You want to retain those customers, right? So I I I generally tend to say this to a lot of folks is that changing that mindset is is important. Fraud is absolutely absolutely necessary in almost every company. I want to say um and uh but yeah but yeah I think that's about it.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
36:14
For a long time I went through this phase of saying that we should try to rename our industry from fraud prevention to revenue retention. Uh it didn't really stick but uh but I get what you're saying. It's the mindset of no we I'm pro growth. I want to support growth. Um and you're also pro trust. We didn't talk a lot about the trust and safety aspect, but when your customers and your uh restaurants and your delivery drivers can all trust you to pay them or to give them their food that they paid for, you know, whatever that is for their their peace, they'll use you more and that turns into more revenue.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
37:01
Yeah. Absolutely. Mhm. Yep. Yep. Totally agreed. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
37:05
Well, I'd like to also mention that Sudhir is going to be at Merchant Fraud Alliance soon uh in Chicago, October 6th and 7th. I have mentioned the conference on almost every episode recently, but um it he will be uh facilitating a Merchant only discussion on refund abuse and um I think it'll be really uh really impactful for the merchants that are having those issues. Um, so if you're going to MFA as well, uh, make sure you say hi to Sudhir. If, uh, you haven't planned on yet, make sure you get your ticket, merchantfraudalliance.com. And Sudhir, I'm looking forward to seeing you in person in just a few weeks.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
37:49
Yeah, absolutely. Looking forward to seeing you as well. We never met outside, but absolutely looking forward to seeing you. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
37:56
Yeah. Only through the computer.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
37:58
Absolutely.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
38:00
Well, I assure you I have I have legs. I'm a you know, you could never see anyone's legs on Zoom. So,
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
38:07
Yeah, absolutely.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
38:08
Oh, well, um I look forward to that and thanks again. I really enjoyed our conversation today.
A smiling man with glasses and a beard, wearing a black blazer over a blue t-shirt.
Sudhir Lanka
38:13
Yeah, me too. Me, too. Loved it.