SardineCon SF/2026

Learn More
The Saturday Fraud Strategist

How to beat undetectable AI-powered fraud, with David Liu

74 min

Okay, this episode made me rethink something I've been hearing more and more over the past year: "Our fraud stack is AI-powered, so we're ready for AI fraud."

Honestly, that's a comforting story. It just isn't necessarily true.

Because the problem isn't simply that fraudsters have AI now. It's that AI-generated fraud is becoming increasingly difficult to distinguish from legitimate customer behavior. The old tells are disappearing, and many of the assumptions we've relied on for years are starting to break down.

In this episode, I sit down with fraud strategy advisor David Liu to discuss what undetectable AI-powered fraud actually looks like, why traditional fraud detection systems are struggling to keep pace, and how fraud leaders should rethink their fraud prevention strategy before today's attacks become tomorrow's baseline.

This conversation explores everything from deepfake fraud and synthetic identity fraud to autonomous fraud attacks, AI-powered cyber fraud, and the growing role of AI fraud detection in modern fraud operations. More importantly, we discuss how organizations can build fraud prevention systems that continue learning as attackers evolve.

What you'll hear in this episode:

  • Why undetectable AI-powered fraud represents a fundamental shift in fraud risk management
  • How AI-generated fraud is changing the effectiveness of traditional fraud detection models
  • Why deepfake fraud and synthetic identity fraud continue to become more convincing
  • How AI fraud detection can improve real-time fraud detection without relying solely on static rules
  • Why fraud operations automation should focus on accelerating learning rather than replacing analysts

You should listen to this episode if you:

  • Lead fraud operations or fraud strategy teams
  • Are evaluating AI fraud detection solutions
  • Want to modernize your fraud prevention system
  • Need a stronger fraud prevention strategy for AI-enabled attacks
  • Want to understand how autonomous fraud attacks are changing the fraud landscape
Episode notes & key takeaways

Undetectable AI-powered fraud is becoming a scalability problem, not an intelligence problem

When people picture the future of fraud, they often imagine fraudsters suddenly becoming much smarter. Honestly, I don't think that's the biggest shift.

The uncomfortable part of this conversation is that AI doesn't have to invent entirely new fraud techniques to create a serious problem. It simply has to make existing attacks dramatically easier to execute, cheaper to run, and almost infinitely more scalable. David walks through a hypothetical new account fraud scenario that is surprisingly realistic. An AI agent doesn't need one magical capability. It just orchestrates dozens of existing ones: purchasing phone numbers, mining breached identity data, acquiring aged email accounts, selecting residential proxies, creating believable devices, and assembling them into applications that look remarkably legitimate.

Individually, none of these techniques are new.

Together, they create undetectable AI-powered fraud that challenges many of today's fraud detection systems.

Some of the biggest shifts include:

  • AI-generated fraud becomes highly personalized at scale.
  • Existing fraud techniques become dramatically easier to automate.
  • Fraudsters can launch thousands of attacks where they previously launched dozens.
  • Traditional fraud detection signals become much less reliable when every individual signal appears legitimate.

The concern isn't that fraudsters suddenly become brilliant.

It's that AI gives average fraudsters access to capabilities that previously belonged only to the most sophisticated attackers.

Why traditional fraud detection systems begin to struggle

One of my favorite parts of this discussion is that David doesn't argue today's fraud prevention systems are broken.

He argues they were built for a different world.

Historically, fraud detection models have relied on independent signals that were difficult for attackers to fake simultaneously. Device intelligence. Phone ownership. Email tenure. IP reputation. Identity data.

The problem is that AI-powered cyber fraud allows attackers to assemble believable versions of all of them.

You end up with an application that looks legitimate across almost every traditional fraud detection rule.

That's where the phrase undetectable AI-powered fraud starts making sense.

Not because it literally cannot be detected.

Because the evidence becomes increasingly difficult to separate from legitimate customer behavior.

That changes how we think about:

  • AI fraud detection
  • Fraud detection models
  • Fraud decision engines
  • Fraud risk management

The question shifts from "Is this signal good?" to "How do all of these signals behave together over time?"

Behavioral biometrics may become one of the strongest fraud signals

One insight I hadn't heard framed this way before was David's argument around behavioral biometrics.

Okay...that one made me stop for a second.

Fraudsters can buy identities.

They can buy devices.

They can buy phone numbers.

They can buy aged email accounts.

What they cannot easily buy is years of genuine behavioral history on your specific website.

David's point is simple.

Large language models don't know how your legitimate customers naturally interact with your application because that behavioral data only exists inside your own fraud prevention system.

That creates an important structural advantage.

Behavioral biometrics may continue improving because fraudsters lack the proprietary interaction data needed to convincingly imitate genuine users.

Some examples include:

  • Mouse movement patterns
  • Click positioning
  • Navigation behavior
  • Session consistency
  • Human interaction timing

None of these signals are perfect individually.

But together they may become increasingly valuable inputs for real-time fraud detection as AI-generated fraud becomes harder to distinguish using static identity signals alone.

Context will matter more than identity

One of the bigger themes throughout the conversation is that ownership alone becomes a weaker fraud signal.

Instead, context becomes the differentiator.

David explains that an email address being four years old isn't necessarily reassuring if its behavior changed dramatically three months ago.

The same applies to phone numbers.

Ownership is useful.

Consistency is better.

Future fraud analytics will likely place much greater emphasis on behavioral continuity than static identity verification.

That means fraud prevention systems will increasingly evaluate questions like:

  • Has this email suddenly changed its usage patterns?
  • Is this still the customer's primary phone number?
  • When was this device last associated with the user?
  • Does this communication channel still behave like it historically has?

These aren't entirely new data points.

What's changing is how much value they'll carry inside modern AI fraud detection and machine learning fraud detection models.

Winning against AI-powered fraud requires faster learning, not just better technology

The discussion closes on a surprisingly optimistic note.

Yes, fraudsters gain structural advantages from AI.

They iterate faster.

They automate faster.

They don't worry about regulators, false positives, customer experience, or compliance.

Not exactly a fair fight.

But companies have structural advantages too.

They have larger engineering teams.

Better coordination.

More investment.

Far richer proprietary datasets.

The organizations that succeed won't necessarily be the ones with the newest vendor or the most sophisticated fraud detection rules.

They'll be the ones whose fraud operations learn fastest.

That means investing in fraud operations automation, improving fraud prevention strategy, strengthening AI fraud prevention capabilities, and designing fraud detection systems that continuously adapt instead of relying on yesterday's assumptions.

Because the uncomfortable reality is this:

AI isn't just changing how fraud gets committed.

It's changing how quickly fraud evolves.

And if your fraud prevention system learns slower than the attackers do, the question isn't whether they'll find the gap.

It's how long it takes before they do.

Not ready to stop the conversation about my, and hopefully your, favorite subject? Subscribe to The Saturday Fraud Strategist newsletter.

Connect with David Liu | LinkedIn
Fraud Executive, Strategy & Product
Co Founder, Dispatchly

Connect with Chen Zamir | LinkedIn
Host of The Saturday Fraud Strategist
Helping fintechs build smarter fraud defenses
Co-author of “The Fraud Fighter’s AI Playbook

Episode transcript
Chen Zamir
Chen Zamir
00:27
Welcome everybody to another episode of The Saturday Fraud Strategist. And with me today we have David Liu. David, welcome to the show.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
00:37
Yeah, thanks. It's good to be here. It's good to see you.
Chen Zamir
Chen Zamir
00:40
Likewise. David, you and I met, I think, through LinkedIn, right? Around two years ago or so. And I remember us having the first conversation and we had like a very quick kind of like meet and greet call. And I remember, you know, saying to myself, okay, this guy gets it. So I'm I'm super excited to have you on the show. You're a veteran of the fraud prevention industry. You've worked both on the vendor side as well as the financial services side. But for those who don't know you, David, tell us a bit about yourself and your career so far.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
01:21
Sure, and I'll do it chronologically. So at American Express, I was the, I grew up at American Express. And I spent fifteen years there, about a little less. And I ended up being the owner of fraud prevention for all, basically all of the non-card products end-to-end. And we were a lot. We were the fourth largest bank. We had corporate client onboarding, membership rewards, business loans, savings accounts, checking accounts, SBA loans, et cetera. And then also I was responsible for new account fraud prevention globally as well. And then after that, not chronologically, I worked as the product owner for SoCure’s fraud products. Which is about half of them. So those 50% of SoCure's product team, their product responsibility. And then also for Trulio, their fraud products. And then I've also been a consultant for a good number of years, helping both solution providers and operators, all sorts of different kinds of solutions.
Chen Zamir
Chen Zamir
02:27
That's super impressive, David. I know that you've seen a lot in your career. So I'm super excited to have you on the show, as I said. And very anxious to deep dive into the topic that we have today. So we had, we were kind of like catching up a couple of weeks ago. And we were also talking about you appearing on the podcast. And initially I asked you what do you want to talk about? What's top of mind? And you, I think I don't remember what were the topics, but you mentioned two or three topics. And when we talked, you immediately kind of like said, I want to talk about the future of fraud. And what's coming in two, three years. We said okay.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
03:10
And even now sometimes. Like the future is now. The things speed up so much.
Chen Zamir
Chen Zamir
03:16
Yeah, yeah. Things, the time horizon gets blurry. Yes, I agree. And I, and I said, you know, yeah, let's definitely do that. And I really want this conversation not to be about scare tactics, and kind of like, you know. That is something that the industry is too good at, unfortunately. And I, and I do want us to take kind of like practical takeaways that fraud fighters can do something with. But let me start with actually asking, are you worried? Is this a top of mind topic because you're worried about it?
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
03:53
I’m not that worried. Because I think what always happens everywhere, every institution, is things are going fine. Something bad happens. No no, the sky's falling, people scramble, and figure out a way to fix the sky. And then they go, fine again. And that that's BAU. It's just, most of the time you can't describe how the sky will fall. And now, because of the rapid change in technology, it's really clear how the sky will fall. But that's always what fraud has been like.
Chen Zamir
Chen Zamir
04:26
Um, yeah, I mean, first of all, I agree. It's a pendulum swing. And I would say that, you know, something happens, as you said. We rush and fix it. And then the next thing is, that we block too many good users, and we have too many false positives. And the, and that's the BAU, right? This pendulum shift. But I, I'm curious to hear your thoughts about it. Because you know, you said it's very clear how the skies are going to fall. But I think that for a lot of us, and also including myself, I don't think it's like super clear. And I, and by the way, I will admit that I'm much more attuned to fraud fighter teams, or fraud fighting teams, than the fraudsters themselves and what they are up to. So it's always interesting to talk to people who are, you know, like more in tune, and are looking at that side as well. But share with us, like let, let's get a scary part out of the way. When, you know, you see AI. And you, and specifically Gen AI, and you were thinking about two, three years into into the future. And we already have deep fakes and we already have synthetic identities at scale. What are the unpleasant possibilities that go through your mind? How do you see fraud evolving?
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
05:47
Well, I think we're already. So I'm gonna focus, like I think this podcast is, this particular episode will mostly talk about Gen AI. And what that enables. And it's not just Gen AI in terms of you can use a large language model to do stuff. It can also be, you can use to do attacks and interact with people, but it can also be you can use one to do coding or or to build software. Which maybe in the past would have been much more difficult as a solo fraudster or solo entrepreneur. And right now already people are seeing scams happening, at like greater scale. And more personalization, and phishing happening at greater scale, and more personalization. Like, and we all see this. Because we, our phone explodes. And we're like, this is a better scam than we'd usually see. But I'll give a specific example and then we can maybe jump from my new account example to maybe an account takeover example or a money mule example. But my new account example is, if I were a fraudster today, which I'm not, I would probably use something like an OpenClaw and spend time training the thing. And then give it some high-level instructions. You know, I do my planning in one place. And the planning would say buy a bunch of phone numbers, get access to, like an Equifax data breach, you know. Load it with some kind of digital currency, Monero or something. And find out who used to own those phone numbers. And find out the identity of those people. And then buy a bunch of emails, and these emails should be tenured and not have a name in them. You know, loves to play basketball at gmail.com for your old email. And now that you know that, and sorry, Chen, you're now the victim. So now that I know that this phone number used to be owned by Chen, and I have this tenured email, and I know Chen's PII from a large data breach. I can also say, find a residential proxy. And buy access from the same city that Chen's in. And create a device that's plausible. Use just a common random device. So you can beat typical device ID controls. And now this, this new application for a loan, or whatever it is. Or buy now pay later, or whatever. Becomes really hard to detect as fraud. Because it's Chen's phone and email. Coverage isn't a hundred percent, and it's a tenured email. We can't say it's not Chen's email, and the device signal's weak, the IP address signals really weak. So how do you, how do you see that it's bad? So that's the first thing. You can't even detect that it's fraud.
Chen Zamir
Chen Zamir
08:29
Yeah, so sorry. I mean it, just because you mentioned OpenClaw. Obviously I heard the name, but can you, can you explain a bit what it is. And why it does, like what are the new capabilities that it provides fraudsters with? Because it sounds to me, like what you just described is something that I can imagine how a fraudster can do that exact same thing. Also today it might be very hard and very expensive to do. How would OpenClaw change that? What is it exactly?
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
09:01
Well, I think it's more about this, and and I don't mean OpenClaw itself, I mean similar agentic frameworks. But it's more the point that the automation becomes dramatically easier. That you can give hints, and then an agent can either through code or interactively as a loop, sort of perform this attack at really great scale. Much easier than it could have in the past. And now I can say, just find a residential proxy. In the past, that might have taken some work to find a residential proxy. That maybe could accept your your digital currency, which is sufficiently clean. You know, just very time consuming. And to do it at scale. And to do it repeatedly. And to do it with a new one, new proxy that matches the city and state that Chen lives in. You know, so each step in this requires a degree of customization, that in the past would have been pretty hefty, and probably not done at scale.
Chen Zamir
Chen Zamir
10:00
Okay, so you're saying that the new emerging threat here is the fact that for fraudsters, to conduct sophisticated attacks at scale is something that A) they are now capable of. So it's like zero to one, like many fraudsters are now like at a one instead of a zero, and and two, that it is also way cheaper for them to do.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
10:27
Yeah, that's right.
Chen Zamir
Chen Zamir
10:28
I can imagine, and I and I know that on the dark web fraud has been industrialized. In the sense that you have service providers. And that's the case for many, many years. And I'm wondering if these capabilities were not always, you know, for sale. You know, for maybe large sums that not all fraudsters could afford. And like, you know, I'm wondering what does it do to the fraudsters' economics themselves? Where maybe, you know, their own services are going out of business. Because now anyone can do that with AI. It's the Suspocalypse.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
11:15
A fraud suspocalypse. What a funny idea. Certainly I think that there's a lot of shifts in who the players are. So many times I don't think an individual fraudster will want it. Like in general the fraud tools haven't been that expensive. Right? And so as a fraudster, it's probably not worth it to build your own. Because the price of the tool has never been that much. So I don't think that it's like, I'm going to build my own because this tool I used to pay $200 for, you know, I can build it myself. No, it's still not worth the two hundred dollars to build the tool. Instead, what happens is just within, same as within the fraud vendor space, that there's a lot of change that with new technology. And you'll find that one vendor displaces another as technology advances. And so I think the rate of that change is happening.
Chen Zamir
Chen Zamir
12:04
Yes. Interesting. Sorry. So, you were about to describe how similar attacks can be performed on established accounts as well, right?
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
12:14
Well, and let me go back to something. So you asked a great question. I love the question. You're like, of course I did. Which is that, this thing I described, how is that new? What does that have to do with AI? I love that question. And the answer is like, if I was doing it with one account, and I was gonna spend a lot of time to do it, and I had the skill set, it doesn't have to do with AI. But now, many times there'll be pieces where I don't have the skill set. Or I'm not aware of the control. And AI can help me become aware of the control. And it can help do the thing. And then on the other side, you can say anything in the past that I could have done once, but it would have taken me a long time and a lot of effort, now I can do sort of at really high scale.
Chen Zamir
Chen Zamir
12:59
Yeah. And that goes also kind of like to the self education, and self training that many fraudsters. I mean, you don't go to school to learn how to defraud, right? You must be an auto deductant. And with AI, and the capabilities that it enables, I'm guessing that it is much, much easier to to do so today.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
13:21
Yeah, no, that you can turn that into a quote. You should excerpt that, you know, something Chen said in this podcast. This is a very, very good insight. But anyway, where I was going was that, we could come up with different examples of scenarios across the entire customer life cycle. Or different kinds of fraud attacks, where you're like, this fraud attack, this example, it would be really hard to detect. And then on the other side, you could say, well, how do we challenge today? What's the traditional way of challenging? And today the most typical way of challenging is to either send a code to your phone, if we know it's your phone, or to do document verification. Take a picture of your face, take a picture of an ID, do they match? And we know that almost all, probably all of the major document verification fraud solution providers, have had large fraud attacks. Which have beaten them. And then they scramble and they try to fix it. And it's becoming more and more prevalent. It used to be three years ago, let's say one person in a thousand or less, one in five thousand, would beat document verification solutions. And if I today, if I were to speculate, it would be one one fraudster in a thousand. Now if I were to speculate it would be like one fraudster in fifty or a hundred or maybe less, 25. Like it's still a useful control. I mean, it still stops the majority of the fraudsters. But on the other hand, clearly there are fraudsters who can beat it at scale, and they are, regardless of who your provider is. And so you can't, you can't identify it's fraud. And even if you were lucky, and you somehow were able to identify it was fraud, you can't stop it. You can't challenge. It's like a nightmarish possibility. So that's the scary scenario that I'm painting. And then the the obvious question is okay, so if there's such a scary scenario. Well, what do we do about it? And I have some proposals, but I'll throw the ball to you. And why don't you say what we could do about it, and then I'll add on just for fun.
Chen Zamir
Chen Zamir
15:15
I mean, let me ask you before that just one question. Because the picture of, that you were just painting of fraudsters being able to seep through. Or kind of like penetrate any type of, let's call this family KYC vendors, right? The KYC vendor family. Whether it's Doc V, liveness checks, it's the same. General KYC vendors. And I completely agree with you, like we're seeing exactly the same thing. I'm wondering if you see that as kind of like a new situation, a new status that we're at. Or do you think that this can actually, even get worse, like two years from now? Where do you think are we, at the arms race? Who's winning? Or who's ahead?
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
16:14
This moment in time, as in recent past, I think the financial institutions, the companies, are winning at this moment in time. But I wouldn't be surprised if there was a dip where the fraudsters just started to win. And it took the companies longer to pivot, and then I think the companies will win again.
Chen Zamir
Chen Zamir
16:37
Just about on one hand who is nimble enough to make quick changes, but once the technology kind of like let's say becomes more stable, I would say, and riches kind of like its peak, yeah. Yeah. Whoever has the more resources.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
16:54
Yeah, yeah. So let's jump to structural advantages. So I'd say the fraudsters have a lot of structural advantages, even more so today. For a fraudster, they can try once. And if they fail, they learn. And with a financial institution. It, or you know, an operator. You know, if they, if they see one fraud case, they may or may not learn. You know, it it's just the teams are stretched thin. With a, and the attacker can iterate after every attack, especially if you're using AI to automate. Even with AI, most companies can't iterate after every attack because you have to look at larger samples. You have to see the impact on good customers, you have to wait a few days. Maybe you have a, an A B with a control. How long does it take the control to react?
Chen Zamir
Chen Zamir
17:45
You have regulators
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
17:48
Yeah, yeah. You have to not break the law as a company, where as a fraudster, you don't care. So so I think there's a lot of advantages in terms of speed of learning, sample size, that favor the attacker. Especially today. And that's why I think, along with that bleak scenario I just painted, while there will be a dip and the fraudsters will start to win more aggressively for a while. But large companies also have meaningful advantages. And for all that fraudsters are quote good at information sharing. I put that in air quotes. In the sense that, you know, they'll sell products to each other. And that the life cycle gets coordinated by specialists from, who hand off from one to the next. On the other hand, like the degree of investment from one entity can, at the company scale, like much larger. Than even the largest fraud ring. You know, the largest fraud ring might have, who knows, a few hundred people. Of whom how many are sort of very technologically savvy? I don't know, a dozen, less. Whereas a company could easily have many hundreds of people who are technologically savvy, working on just one specific problem. And so I think the benefit of the people fighting fraud is the benefit in coordination. So we don't share, companies don't share information with each other, that well. But within a company, the degree of information sharing is fantastic. And there's a lot of smart people working on the same problem.
Chen Zamir
Chen Zamir
19:17
It's interesting. It's exactly the same thing that Shachar Meir brought it up in in our own episode a couple of weeks ago. Where he basically said almost the same thing. I think his point was more the coordination between different organizations, that this is something that we can do through consortiums. But I think your point is actually a very interesting complementary add-on. That, you know, pertains to the fact that we also are coordinated within the organization. We actually have much more firepower, much more resources. Budget to solve the same problem than what frosters have at their disposal.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
20:00
There was this bleak scenario. We're gonna have this hypothetical attack, what do you do? And I can propose the solutions I've thought of. But I'd be, you know, you can also. How would you like to do it?
Chen Zamir
Chen Zamir
20:13
No, I wanted actually to ask. What, why is it so scary in the sense, that like in the end. We know fraud today. We have fraud, we have fraud for thousands of years, especially in the digital world. Gen AI is not that new, right? I mean, we we've seen the implications over the past two years. And even agentic, we are starting to see the implications. And I'm not saying that there are no challenges here.But, you know, we are not necessarily seeing fraud rates going, you know, tenfold or even fivefold. So I wonder,
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
20:58
Yeah, yeah, no. Maybe it's even getting a little bit better.
Chen Zamir
Chen Zamir
21:00
Okay. I would be interested to to hear more about that. But I would ask, why wouldn't the current system, the current kind of like, you fraud fighting system, fraud prevention systems that we have within the industry. Whether this is in financial services or with merchants or with digital platforms. Why would it not be enough? Like where would they break with these new capabilities that frosters are now adopting?
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
21:27
Yeah, so I think in the past, almost everyone says, Well, there's a certain amount of fraud I expect. And I'm gonna budget for it. And so when I have large fraud attacks, where something breaks horribly, I'll lose many millions of dollars. But then there's the day, I'm gonna call it the day-to-day fraud, where I just expect I'm gonna lose X basis points to fraud. And I'm fine with that. And that's most large companies today. And in the past, we say, well, the fraudster attacks. There's a certain manual nature to the attack, they have to iterate. But any one particular fraudster is unlikely to be able to scale up their attack to large volumes in ways that I can't detect. And the argument now is, many of those people who were your three basis points or whatever it is a fraud. Now will be able to scale up their fraud attacks in ways you can't detect. Not many of them, some of them, when in the past they couldn't. Because they didn't have the tools. Or it was like too overly expensive. And obviously it's not all of them. Like, you know, I, if I see your credit card at a restaurant, like that's not something I can scale up. But some of the attacks that in the past weren't scalable, now will be.
Chen Zamir
Chen Zamir
22:40
And you're saying that, what we would be consider, like what we would consider to be a very sophisticated attack. Let's say, the top, you know, ninety-ninth percentile in terms of sophistication, would basically expand to be the ninetieth percentile in a couple of years' time. Just because the like fraudsters would have more access to the sophistication. Also to the scale.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
23:06
And especially the scale. Like maybe some fraudsters will get more sophisticated.But I think more the point is, if there were a hundred of fraudsters, and each of them attacks, whatever ten times. The person in the ninety ninth percentile, who attacks ten times, and beats all of your controls, now he has the tooling to attack a thousand times. Whereas in the past, maybe he didn't. Or it would have been, like much more difficult. [Ad Break (23:31): Hey folks, I want to take a quick break to speak about today's sponsor, me. If you're finding this useful, do me a small favor, like and subscribe. It really helps with the algorithm. And if you're not already on my newsletter, The Saturday Fraud Strategist, you should definitely check it out. Every Saturday, I break down fraud trends, real cases, and strategies from my own experience of building and operating fraud prevention systems. Whether you're new to the space or a seasoned practitioner, I'm sure you'll find it interesting. Check the link in the description. Takes 2 seconds. You'll thank yourself next Saturday. Now, back to the video.]
Chen Zamir
Chen Zamir
24:04
So let's talk a bit about, you know, how things, like in an ideal world. Where we have all the budget, all the resources, all the technology, and we've already gone through the transformation journey. Where we've implemented everything.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
24:24
Okay, okay. So ten years from now.
Chen Zamir
Chen Zamir
24:26
It's like this, right? Just a flick of the fingers. What should, it's not a modern it's like a futuristic fraud prevention system, should look like? So it can actually stop these undetectable fraud attacks, or patterns, at a scale that today we cannot really imagine. How should it look like?
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
24:56
Yeah. So first I'm gonna caveat this by saying, I'm not gonna assume any radical changes in society. So I'm not gonna assume every person has a digital ID that they go, when they go to the DMV. And with a fingerprint biometrically bound to all this stuff. So I'm gonna assume, sort of very modest evolution in the broader world. I don't believe that device intelligence will be that robust for that long. That it'll just be too easy to spoof in general. Like you can know it's a unique device, but you won't be able to say, this device is, you know, an emulator or something like that. I think that will be very difficult. And privacy policies make it harder, not easier, right? Regulation makes it harder. But I was talking to Matt, actually who used to be at Sardine, and he gave me this wonderful example. Where he Yeah, yeah, Matt Vega where he was saying that he saw, that the bot clicked right smack in the middle of the button. Like the exact middle of like the submit button or something like this. And I, I think this brings out a broader point. Which is that companies, if we ask how does David apply on a Bank of America website for a new credit card? Like Bank of America has millions of applications, it has millions of data points. This is how new people apply on their website. No larger language model has basically any data on that. And if you tried to train it, maybe you'd have like a few people at most. And those few people wouldn't be actually natural organic applicants anyway. So I think the behavioral biometrics, I think that will be resilient. And will stay applicable for a reasonable amount of time. Like you can add jitter, you can add, you can make things look curved instead of straight lines. But it's a lot harder to make it look like David on the Bank of America website. And the machine didn't know that human beings don't click s right in the middle of the button. But there'll also be much more sophisticated features, which will be also difficult for machines to, to emulate. Because the fraudsters don't have that data. So I think behavioral biometrics will continue to be resilient. And will get meaningfully better over the next year or two at detecting, you know, agents who are controlling devices. Who are trying to emulate humans. So that's one.
Chen Zamir
Chen Zamir
27:17
But I want to challenge you on that. I mean first of all super interesting. I, I didn't hear this angle. Why? Because usually the angle that I'm hearing, and also an angle that I'm raising myself, is that the main problem is that we will see more and more legitimate users using agents themselves. To, you know, like basically organize or conduct their presence online. And it, you, it would like at the same time that it is you know hard for fraudsters to train their models to behave like legit people, legit people will more and more use agents that would look more and more like bad agents. So how, how do you see that?
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
28:03
I love that. And I like, I like that you challenge it. It makes it much more fun. So I think this is a place where regulation and expectations help us. So this particular tax scenario is at time of no count on boarding. I'm applying for a loan at Bank of America, whatever. And in that context, I think there will be very few institutions, and I don't think many regulators also will like the fact that one could ask an agent to apply for me. And I, and I maybe haven't read the terms and conditions and I maybe haven't clicked that checkbox and I haven't been the one to click submit. So when you talk about checkout, I think it's very plausible that agents will do it for human beings, and that's a desirable state. But for onboarding, I don't think when it's a meaningful financial relationship, that that's something companies will allow or regulators will allow in the near future.
Chen Zamir
Chen Zamir
29:00
Yeah, that's super interesting. Because it shows that, it will be very much use case dependent.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
29:07
Yeah. Yeah, that's right.
Chen Zamir
Chen Zamir
29:08
And yeah, and financial services would probably have very different experience. And maybe even, like between different flows within the same organization, they'll have very different experience with how easy it is to combat fraud. Versus how easy it is to spot false positives. Yeah. Interesting.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
29:23
But, I mean, let's talk about terms and conditions. Does it count as having read the terms and conditions, if your agent is the one who executed the action? And my guess is most people would say no.
Chen Zamir
Chen Zamir
29:38
Yeah. I think, I think the question is not what most people say. The question is what the regulators say, right?
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
29:45
Yeah, yeah, yeah. Well, at least for highly regulated institutions at time of onboarding, I'm pretty confident the answer will be no.
Chen Zamir
Chen Zamir
29:52
Yeah, I agree.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
29:54
Anyway. So because of all of this, I think behavioral biometrics will be, continue to be really useful. Then after that, there's all the information you put on the application, the phone, the email, etc. And in my hypothetical example, I said, well, we're compromising the phone. And the way we're doing that is by getting a different phone number that was associated with you. And an email, but the email's not associated with you. And I think coverage of email ownership in the US maybe is 50, 60%. So ownership is not good enough, really, to use as a primary control. However, usually the fraudster won't, usually there'll be a change in the behavior of the email. So even if I buy a very tenured email, there are companies out there, you know, marketers, who will say, how often do you open your emails? How often do you click links? What's your typical behavior? And that's not something that's typically provided today by fraud solution providers. But I expect that they will be providing that in the next year or two. Because then the signal becomes, well, this email is behaving very differently than it used to behave in the last three months. So the email's four years old. And the last four months, three months, its behavior has been very different. Then that becomes a red flag. And I can't verify its dated email. So even though it's tenured, I shouldn't treat its tenure as four years. I should treat its tenure as three months. And maybe this is worse. Actually, if it was four years old, if it was four months old and it behaved consistently, that's better than if it's four years old and the last four months has changed. Like usually people will abandon emails and they'll become idle. It's not like I find an old email that I didn't use and now I start to use it a lot. That's actually a particularly bad kind of behavior. So I think you'll start to see more around the usage of the contact channel. So this story around email, you could do the same thing with a phone number. Like, is this phone getting or receiving text messages at the same rate as in the past? So I think usage will become important. And then with phone numbers where ownership is pretty good. You might get 85%, 90%, whatever it is in the US. I think we'll also start to see more focus on like, well, yes, this phone number was David's. But it's not David's currently active phone number. It's not the primary phone number. And so then it won't just be, is this. In today, it's usually sometime we saw this phone number attached to David. Like that's the solution today. The solution in the future will be, we saw this phone with David. But we stopped seeing, notice that it was attached to David nine months ago. And to some extent, you might get this from like a phone porting date or something like that, from some solutions. But many solutions not. And then not only will you say, is this David, was it when did this phone number stop being associated with David? You'll also get the phone's activity. Like has the phone's behavior changed in X time period? And then finally you'll get what's David's primary phone number, or primary phone numbers, primary email and primary emails. And so then if you see something that was associated, but it was a long time ago, or it's a very tertiary email or phone where the pattern of behavior has changed, then all of a sudden you can say, well, I don't completely trust that phone. I trust it much less. And these are signals that aren't surfaced today. But the data is absolutely there. And now, that I think the need will be coming soon. I think solution providers will start providing these.
Chen Zamir
Chen Zamir
33:25
Yeah. Basically you have to do much more data mining, to extract much more context and insights. And especially when it comes to whether it is established accounts or establishing your ownership on specific like assets. Like phone numbers and and emails. You're saying consistency and like measuring consistency is key here basically. Because this is something that fraudsters cannot train, even with AI. They cannot train to act and behave like you.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
34:08
Or at least the cost to do so is exorbitant.
Chen Zamir
Chen Zamir
34:12
Yeah, yeah, yeah. Um, I want to ask something. I mean, that made me very curious when you mentioned it a couple of minutes ago. You said I believe that device fingerprint, or device intelligence would be much less reliable in the near future. Can you, can you elaborate on that? Like why, why do you feel this is the case?
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
34:36
Well, I mean, even now, like this is not a new thing. Ten years ago. Actually. So it was easier, I think, to produce device intelligence ten years ago before the browsers started restricting access to a bunch of stuff, right? And so the fraud cover, coverage from a device solution, a very good device solution, ten years ago, or the ability to identify re-returning users. Was let's say fifty percent better than it is today. And that's because the browsers keep restricting what's available. You know, you hear all these speculations about like Google's privacy sandbox and privacy initiatives. And the EU, and what you're allowed to do. But beyond that, even ten years ago, there were many fraud attacks. Which would have a unique device that seemed plausible. That didn't have any dramatically risky signals. That beat at least many name brand device ID vendors. You know, I saw three of the top five. All of them had this thing, had happened to them. I'm sure the other two I didn't see had the same phenomenon. So I don't think device, typically device ID was used either. Because this device ID we saw with 20 different people. Therefore it's high risk. Or this device ID we saw with David, and now we saw him use the same device ID six months later, therefore it's low risk. That was overwhelmingly the typical use. And yeah, there's a whole bunch of features that device intelligence providers provide of like, oh, maybe this is a RAD attack. Maybe this is, maybe this is an emulator, blah blah blah. But I mean in terms of model predictiveness, all of those features for the major device ID providers I know, accounted to for like less than six percent of model predictiveness. You know, these weren't that important.
Chen Zamir
Chen Zamir
36:35
Interesting.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
36:36
So I mean it's not a new thing actually. This is an old thing and it's just made worse.
Chen Zamir
Chen Zamir
36:40
I cannot say that I'm surprised. Because I think indeed device ID used to be such a strong, I mean it I think it still is. It is such a strong, let's say, feature. Exactly when you are able to link it, either to other users or to basically the consistency. Again, going back to consistency, of the same user behavior. When it comes to like extracting the rest of the intelligence, I'm not sure if the fault is with the fact that this intelligence doesn't matter. Or that like with, you know, what we just discussed about email and address and phone, that organizations never really bothered to really extract the full potential from that intelligence. Especially with high quality, and especially with accuracy, of the on the road data layer. Because it wasn't needed, at least so far.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
37:34
I mean, I think I know of at least a couple organizations that looked at a lot of the variables. You know, like if there was an output of like three hundred variables, they'd throw the whole thing against some automated rule creator or something like that. And just most of the variables weren't that predictive. Now and to be clear, like if you say, I think this device is using, is from an emulator. Is that likely fraud? Absolutely. Or at least much, much elevated risk. Should companies use those signals? Absolutely. But on the other hand, the prevalence of that signal will be pretty rare. So there's a lot of signals, they'll be very predictive, but they'll each one will be pretty rare. And so it's not predictive enough. But to be clear, like even IP adjust geolocation, like everyone knows you can, you know, use a residential proxy. Appear like you're another place. IP address geolocation in theory shouldn't work at all. And yet it's still like a top ten variable in lots of models. So just because the solution is beatable doesn't mean you shouldn't use it. Like you should stop the stupid fraudsters. They're making it easy for you. Use it.
Chen Zamir
Chen Zamir
38:43
I agree. I agree. Yeah. okay. So we talked about, we have all biometrics and that this is going to be still prevalent in stopping fraud. We talked about extracting more intelligence specifically from email and phone. What else would a futuristic fraud prevention organization should look at when it comes to stopping these undetectable fraud attacks?
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
39:16
Yeah, another signal, I so when we talk about phone or email, then that's talking about making these traditional signals more useful. Because we have, you know, is it David's, is it David's primary. What's the the kind of behavior over time? But there's also the passive signal. So there's behavioral biometrics. Another one that I think is really nice is that there's a a number of different data providers who make available passive signals, saying this IP address or this device is attached to David. And is attached to this address and this name and this identity. And so this becomes then a positive signal. And like I mean a a classic example is, is silent network enrichment. Where the cell phone carrier will tell you this IP address is, this Verizon IP address or whatever. T Mobile IP address is. You can ask them. This is the phone number I got, and they can say, yeah, that phone number, that phone number is paying for this IP address. And then you can say, and that phone number is David's. Therefore, David, who's paying for this data, is the one on the other side of the screen, and that makes it meaningfully lower risk. So that's it one example where you can use passive signals to deterministically link David to this IP or device. And there are a few providers who do this in different ways, using marketing data, using telco infrastructure, using consortium data. And I think the problem in the past is each one only had so much coverage. Like, you know, maybe they'd have 20% coverage, 10% coverage, 30% coverage. But I think there will be a future state where there's some aggregator who puts all these things in the same place. Where you can start to get 70 or 80% coverage saying, I know this is Chen. And I know it the moment his browser hit my website. Or or maybe I know it after he entered his phone number and his name. And then I ask, and they verify that that's correct. And once again, this doesn't stop the fraudsters, but if you can start to say I have really strong positive signals on 80 or 90% of the population based on, you know, these passive signals. Based on the phone ownership, whatever. Then the fraudsters are, instead of occupying this large space, are compressed into the small space. And it's a lot easier to find them.
Chen Zamir
Chen Zamir
41:35
Interesting. I think I'm starting to see more and more such players in Europe. I don't know how it looks like in the in the US. I'm guessing it's less complicated in the US. But when you're when you're going after regions which are more fragmented, obviously it becomes a problem. Because when you are in Europe you have a few dozens countries. So yeah, that's definitely interesting, by the way. An interesting business opportunity as well, I would say as a new vendor.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
42:05
Yeah. Who knew that subscribing to Chen's podcast would be so profitable?
Chen Zamir
Chen Zamir
42:09
Yeah, yeah, yeah. You owe me money. Tell me, I mean, we've discussed a lot, the data layer. Like what features you want to extract and how to do so, and in what use cases. Do you see something about the basic technology that the system is running? Whether this is rules, models, or AI, or do you see something more on kind of like the policy or the team maker that would need to change to accommodate this new wave of fraud.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
42:47
I think it will be helpful to have the rate of change, to have org structures accommodate a higher rate of change. Already most fraud institution, most fraud fighters exist within organizations that can act like much faster than credit. Like you want to change a rule in credit, it takes you know years. Use a new variable, and two years later, if you're lucky, you have the new variable and fraud. If you're lucky, maybe it takes you a month. I think the existing org structure should be able to accommodate it. When we talk about, like for example, soups is posting about, you know, this AI agent that can create rules and that can find fraud attacks and stop them in real time. Or almost real time without needing manual review. And so certainly I think that's a cool innovation. Um, there are places that rebuild models on a daily basis. So you're like, we don't need custom rules. The model was just rebuilt last night. Now I think things like that will become more common. Um, there are these articles about foundation models, which just ingests data from so many different customer touch points. And it's not just that it's a foundation model, it's that the philosophy becomes different. So in the past, if you had a fraud model, it would be really unusual for a new account opening fraud model to have, for example, your call center data. And yet it's really believable that we'll end up in a future world where it does. And then you'll say, oh this phone call into my call center was marked as bad and came from this phone number. And you know, so by having just more complete data available. And by having data lengths being a standard, I think that will help us as fraud fighters.
Chen Zamir
Chen Zamir
44:28
On one hand I must say that I still don't know myself, like what would be the part that foundation models would play in in risk prevention? Is it more like a feature engineering layer? Is it more replacing machine learning? Which I don't really see happening, at least not in use cases. Or maybe, in very specific use cases that, you know, are not that time dependent. Or maybe where you're more lax, right? For example, around login where the friction is not that bad. Maybe there you can use it. Um, but I think the the interesting bit is indeed around extracting features for free, and maybe from a varied data source pool that maybe we haven't looked at so far in fraud prevention. I think that's an interesting, like that is the most interesting bit, and the biggest promise that I see in foundation LLMs. And sorry foundation models. But yeah, I haven't seen it yet.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
45:42
I think also there's, so my hypothesis is that our old traditional machine learning will continue to be really good. If you want, if it's based on the attacks of the past that are cleanly labeled. And if it's you, and assuming both have access to the same data. So I think a lot of the discussion about foundation models also, like the foundation model is given access to a bunch of data that the traditional machine learning wasn't given access to. So, like naturally, it will do better because it has more data. But on the other hand, I think the the change in the way that it's supervised also matters. So if you talk about like, unsupervised machine learning versus supervised machine learning. Traditionally in fraud, you'd have some sort of tree-based supervised machine learning. And I think there's independent value that can be generated by something that was not treebased machine learning with labels. In particular the labels, right? So you don't know that this is fraud. I think the, that they're, that these new models have an ability to extrapolate more.
Chen Zamir
Chen Zamir
46:52
Yeah. And then, and then to let's say reinforce the anomaly detection layer. Uh yeah. This also goes hand in hand where I think anomaly detection. Because of, you know, its lesser accuracy. Also with machine learning was traditionally, kind of like human in the loop, like the first human in the loop semi automated process that you had in fraud prevention and yeah, I I'm I'm guessing that foundational models can can fit there quite well.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
47:24
So I'm going to jump then to the other side. So we talked, okay how do, you how do you avoid detection? And then okay, what could the future look like? So that the frauds can no longer avoid detection. But then there was the other side which was, well even if you know they're fraud. If you're going to challenge them they'll beat your challenge. Uh so now what about the step-up authentication? How does that change? And on one side uh some of that we already got. Because like, okay we know that phone isn't trustworthy. So you just don't send the text message to that phone or to that email. So we already addressed some of that. Um I think more generally, uh the old is becoming new again, that we start to rely more on delivery. So we know that you're not a fraudster because you ship that big screen TV, or at least not a third party fraudster. Uh because you ship that big screen TV to your known and tenured and trusted address, right? And so the way that the consumer interacts with the company. Like I log in using my email and I get emails and I have to click a link or something. Uh so because I have to have access to this email because the email is David, and it's trusted. It's low risk because I got a code to my phone and the phone is David. It's low risk because the TV was sent to my address. It's lower risk because the bank account is my bank account and that's where the funds were sent yada yada. So I think that will remain robust. And often times these, I'm going to call them contact channels. Uh have attached to them some history. And that's helpful. And you have ownership, you have regularity. On the other side, I think there is a big growth in digital IDs and eIDs. And states or countries issuing some credential that's bound with key exchange and encrypted. Uh, which will be, continue to be, like really hard for fraudsters to break. Uh, and so not now, but in our, in our future world. That's not that far off. Uh, and you could imagine that I use my Apple wallet to authenticate myself. And you know, you're just not going to be able to spoof that. And maybe you're, and asking people to go to the DMV and be mules and say, "Go, I show up at the DMV and I say I'm Chen." You know, I don't think that's going to happen at scale.
Chen Zamir
Chen Zamir
49:46
Yeah. Being able to, to basically match electronic IDs, to devices, to physical devices, that are known to be owned by, uh by you. That were acquired with, yeah, um yeah. Let's see. And I think the main question here is not whether this would become feasible, but whether this would become an acceptable part of a digital experience in the eyes of a customer, right? I think this is, this is the question that remains to be seen.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
50:23
I mean, I think it will get there. And I say this just because for example, document verification, taking a picture, rolling your face around in a circle, taking pictures of the driver's license, like that's much more frictionful. It's meaningfully, less trustworthy. And basically, there's broad-based acceptance today. And so, we're taking this experience and replacing it with something meaningfully better.
Chen Zamir
Chen Zamir
50:43
That would be interesting to see. How that would shake things up. Uh because, I think, I mean, I think that we're pretty far from it. But this can also change quite quickly, right?
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
50:55
Yeah. Well, I mean. We, we're pretty far. But on the other hand, I think 7% of people have their driver's license in their Apple, of in the US, have their driver's license in their Apple wallet. So on one side we're far, and on the other side that's like non-trivial adoption. And not many merchants are using it today. But uh some are. And I think we'll continue to see the adoption grow rapidly, or you can go back to like Zelle. Where, you know, it went from nothing to something. Because the customer experience is just so good.
Chen Zamir
Chen Zamir
51:26
Yeah. And and I can
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
51:28
Or chip readers. You know, you put chips on credit cards. For a long time, Americans didn't have chip readers. And then, you know, they did.
Chen Zamir
Chen Zamir
51:34
Exactly. I can see how suddenly, you know, Apple comes up with a new schema that is unrelated to fraud or risk. Or even, you know, like finance. Um that would just, you know, like encourage, um encourage, adoption, right? With, uh, with users. That, you know, uh, as a side effect will also completely change how, like what kind of possibilities are open to fraud fighting teams. So yeah, I can definitely see, you know, that we will talk again in five years time. And, you know, that world would be completely different. Or not, we don't know. But this can happen, I don't want to say overnight, but this can happen relatively quickly. We've seen similar things. I mean, I'm just thinking about mobile, right? And how mobile affected, um the, uh, the kind of like purchasing behavior of users. And that changed very quickly. That changed, like within 3 years. It was, you know, there was a very big shift in around 20 I would say 2010 to 2013. Or right around that time. Uh, there was a very massive change.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
52:41
I mean, actually just speculating. Since we're talking about far future. So, I'm going to give, like two random scenarios, which are more far-fetched. I have less confidence, but I, I'm super curious. Um, so I think typically, if you're a large conservative institution. Uh, you typically don't want to give other companies massive control over you. And you typically don't want to trust other companies. But, and here's my but. But, and as an example, for the longest time, if you were going to log in through Google, no one who did financial transactions would ever allow such a thing. But now, you're starting to see some companies that, you know, are smaller, are, you know, maybe not as high dollar, maybe that are lower risk, allowing you to log in through Google. Where it involves money movement. Albeit not the most extreme cases. And if you're a smaller company or a less mature company, there's a very good chance that Google does a better job fighting fraud than you do. And so, just to pick on, like you can imagine, a state like let's say. I don't know the fraud controls in the different states in the US, but there are varying levels. Often times, it's older. There's regulation and acceptable vendors that gets in the way. But I bet there are many states where if you want to log in, and get some sort of state benefit, the controls are really weak. And if they said you can login with Google, that the people who log in with Google will be way safer. Um, and what's more, I don't know, but I bet you could trigger this login with Google. You could make Google think it was a high-risk transaction. So for example, let's say I wanted to do login with Google, and it was a high-risk transaction. And I said I'm going to make this request. I'm going to try to see if I can tell Google this request is coming from Zimbabwe. And I'm not saying this is the right way to do it. It's clearly the wrong way to do it. But my point is, they have internally some way to step up, and if you have a way of signaling to them that this is a high-risk transaction, can you force them to step up? Or let's say medium risk. So that they step up, but only if it's not a recognized IP address, or device. And you know math 65% customer penetration, great solution, lots of history, continuous investment, huge organizational scale, um should that be the only solution? Is that defensible in front of a regulator? Probably not. If it was one piece of a layered set of layered controls, maybe it is defensible. Maybe it does become a useful positive signal. Or another example. Uh let's say, uh you have a CapitalOne credit card or American Express credit card. And uh you can have a merchant account, and do an off, and say I want to spend money on this credit card. Uh but not actually charge them. You just just place a hold, brief, for a moderate amount of money. Uh, just to trigger their authentication path. And then, okay these companies have a long history on you and you're you're once again doing a $500 transaction, from a risky merchant, uh and your IP address is on the other side of the world, blah blah blah. Like they'll have pretty good risk assessment. Now they probably won't approve of people abusing their controls. It's probably against terms and conditions, because they don't make money if you actually settle I don't think. But I think there are large institutions which will have long history with you as a customer, which have really good sophisticated fraud controls, and it would be really interesting to create some mechanism to allow people to piggyback on those fraud controls.
Chen Zamir
Chen Zamir
57:28
Yeah. Well, I think this is exactly the the Achilles heel of, you know, of the industry. That on one hand we're saying coordination is our biggest strength, but at the same time,
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
57:41
It's not at all.
Chen Zamir
Chen Zamir
57:44
Yeah, I would say, but not not for the lack of trying. I think it's just very complex from a regulatory and also technological perspectives, right? So it's, it's just not that easy to do, uh these sorts of uh partnerships and cooperations. Yeah. And it's very times, it's just very very challenging. Just to share data. Just to share data between organization. It's already a big challenge in an offline manner. Um, and without you know, like using it for any kind of decisions. Um, but yeah. I agree um if if the regulator would, uh think of how to do something like that. And for example, you can see how I think it's a bit different. But in the UK and in Australia, where the regulator is, I think a bit more advanced. Or a bit more, I would say, forward thinking. Than for example, in the US. You do see these kind of, uh, initiatives. But at the same time these are also like much smaller markets, in terms of how many players are there/ And, you know, you basically, you capture four players. Then get them into some sort of a consortium, or some sort of network. And you have, you know, 80 95% of the market. And and that's pretty much done. So it's also a bit of a different game
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
57:59
I mean open banking I think is another example. Like not many places use open banking as a step up. And the challenge with using open banking, as a step up is, no I mean first of all you have to have coverage. But also maybe after I link my bank account, it doesn't clear the concern. It's like yeah, I see your bank account, you don't look any better than you did before. But I think there will be many people for whom if you did open banking as a step up, and you see a long history, and they can log into the bank etc. that meaningfully reduces risk. So I think there's a lot of ways to piggy back on other institutions potentially. That have like wide coverage, and decent fraud controls, that we're just not doing today.
Chen Zamir
Chen Zamir
58:36
Yeah. Yeah. Open banking is definitely a good point. Um, I want to ask you, David, I mean, we've been talking about how, you know, how fraud would look like in the future. We've been talking about how fraud systems should look like in the future. Um, now for our audience that, you know, are concerned about the here and now, but are also maybe a bit concerned about what's coming. What would be your kind of like top three recommendations? I just made up the number three. So use whatever uh whatever end figure that you are comfortable with. What are your top recommendations for teams to be busy with in the next 12 months, so they are better prepared, if and when these uh sophisticated attacks start to scale within their system.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
59:22
I mean I think it depends a lot on the institution size. So if the institution is relatively smaller, um probably just use a very good orchestrator. That can orchestrate not just uh vendors, and data. But also can do some amount of models. Can also perhaps orchestrate solution providers, uh which involve device intelligence, or behavioral biometrics. You know, just because it gives you a lot of flexibility and ability to move more rapidly. Um, if it's a really large organization. Many times with large organizations, it's very, it takes a long time to do anything. And things are super complex. And having a good foundation becomes really valuable. And all of them know this. So I'm telling things they already know, but I would say have a high quality data link. Where all the data is available, uh, from any kind of control point. From any decision engine. Uh and, uh, would be, have general wise, uh uh, feature creation platforms. Which are available across your customer life cycle. Have ideally, have models which can be trained, uh retrained, every night rather than every two years. Um so, I think for the large organization, it's more about creating an infrastructure which allows, uh rapid iteration. Which makes the tech cost of change lower. Uh, and I'd say the same thing for small institution. Smaller institutions, you do that through, uh third parties. Larger institutions, you do that through in-house build. But oftentimes the cost of change is just so large, and so slow.
Chen Zamir
Chen Zamir
61:00
I love it. Because I think in the end, I must say, I very much agree with these, with these two approaches. Uh, I mean, basically it's the same recommendation. It's just about how you approach it. Yeah. And to me, you know, it kind of like touches the most basic fundamental principle of fraud fighting. And that is, in my mind, and that is that you are just as good as how quickly you can learn. And I think it loops really nicely back
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
61:31
And that's a great quote. You can excerpt that, excerpt that as a quote.
Chen Zamir
Chen Zamir
61:36
Uh it, loops back to something that you said at the beginning of the conversation. I'm trying to remember the exact words but, um you said how you know fraudsters can iterate after the first time that they experience failure. Whereas, uh, organizations large or small, it takes them more time. And it's more costly. And the, like the closer you can be to a fraudster's, uh, speed of learning. And I don't know if you can be as close, or even faster. But the closer you can be to a fraudster’s, uh, learning speed, the better off you are.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
62:16
Yeah. It's funny. I like this, uh, an analogy. And it's almost, like a large institution might have 20 people learning. But each person, and I mean the people are learning, but each person represents, let's say a function/ And so you might have, 20 functions that learn. And each function takes a month to do one unit of learning. Whereas, maybe a fraudster might have two or three functions that learn. But they each might learn in the order of a couple days.
Chen Zamir
Chen Zamir
62:44
Yeah. By the way, I want, I want to say about that, is that also your, uh, learning speed is as good as the weakest chain in the link, right? You mentioned, hey, uh, it it's best if you update your models every night. But what happens if your labels are coming in only every week or every month through, you know, like an acquired chargeback, uh, file. Or what happens if, you know, whether it gets, uh, to you every month. Or every day. Maybe these labels are pretty old because up until you get the chargebacks, you know, time has passed. So there many times I find that when, uh, organizations try to, uh uh, kind of like, um increase their reaction speed. Uh, they tend to obsess and focus on very specific parts of the, of the chain. Uh, many times that, you know, they control directly when there are some kind of, like hurdles. Or kind of like bottlenecks, that they don't necessarily think about how they can solve them as well.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
63:47
I agree. It's, this is very good insight. I'm going to go on a tangent that you have sort of inspired me, which is, as it relates to labels. I think there are a lot of places where you can get labels that are much more rapid, that people just don't use. So, the normal label is, they talk to someone. The person says they didn't do it, and that maybe takes a week, or a month, or maybe they see a fraud loss. Maybe that takes three months. Um, but you can say what's the rate at which, uh, challenges are passed and that's almost real time. Or you could say after sign up, what percentage of this population does activities which indicate very high trust, like maybe afterwards I did open banking. And it was a really pristine account, and clearly this is me, and maybe that happens 5% of the time, and maybe or 10% or 20%. And then you can say, well, on a larger population, if you see that number meaningfully less, maybe that's an indication that it's higher risk. And you know, is it enough to be deterministic? No. But as a leading indicator or, you know, whatever they send in a bank wire, they pay a utility bill that you can find activities, which become really positive, or meaningfully, uh, riskier, uh, as fast labels. But no one does this. It would be really interesting to, if I, if someone if, someone does this. Please write to me on LinkedIn.
Chen Zamir
Chen Zamir
65:11
Yeah, I must say in general, I think that, you know. From everything, all the problems that I've ever encountered in fraud prevention, labeling and cleaning labels is probably the hardest problem of all. And I see very few organizations that not, not that tackle that, but that are even aware of that. Uh, so that's that's yeah. I uh, I'm with you on the, on the labels tension. Um, awesome, David. I want to take a moment and kind of like summarize, quickly, the harrowing journey that we went through, uh, in this conversation. Where we were trying to figure out how fraud would look like in the near future, 2 3 years from now. And I think the, like what you outlined, what you portrayed. Is basically that the same sophisticated attacks that we are already seeing today, and maybe over the last few years, um we are going to see uh plainly more of them. Uh why? Because um honestly they are just cheaper to execute, right? With uh with genAI, with agentic capabilities you are able as a fraudster to basically produce 10x the amount of attacks for the same uh for the same investment. And that's something that, uh, is definitely scary. And we also talked about the fact that this is exactly why fraud prevention systems would break. It's not necessarily because they would encounter a challenge that they haven't encountered in the past, but because they would encounter more of the very difficult fraud cases, um, that they are just not able to detect. Um, and that would lead to elevated losses. Maybe not a fundamental, uh system breakage, but definitely more losses. And by the way, we already see today, uh in some industries, and in some uh use cases, that this is already the case. Then we also discussed, um how fraud prevention systems should look like, uh in the future. So they are able to meet this kind of sophisticated fraud attacks, especially at scale. And I think you mentioned a few things. You mentioned, uh first of all on the data side, you mentioned, uh 1) that usage will be more important than ownership. I really like that point where you said it's more important to understand how you use certain assets, um, for example email or phone rather than whether you can establish your ownership on them.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
68:03
Or let me just say not, I won't say more important, but let's say it will be an added dimension that will be really critical as well. Carry on.
Chen Zamir
Chen Zamir
68:10
I take it. Thanks for the, for the uh fine tuning. Um you also mentioned consistency. That consistency will remain a very important dimension. Especially when establishing the risk of established, uh accounts. Where the, um the behavior of the legitimate account owner would not be something that fraudsters could easily, or cheaply, uh mimic. Uh, and that goes to everything from behavioral biometrics, to how you like literally the type of actions, uh, that you, uh, that you actually, uh, place on your account. Uh, last, you also talked about the fact that, um starting to look into aggregators,like data aggregators. That can match, uh, different dimensions of your identity. For example, your um, device and your IP. Or your IP and your, uh address.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
69:17
Digital physical linkage.
Chen Zamir
Chen Zamir
69:18
Exactly. Yes. Um, this would become, uh even more, I think, they were always important. But I think even more important than before. And look at, and looking at other industries, I think especially the telco data angle, I think is is very interesting. And I think I am already starting to see, over the past couple of years, more and more cooperation between telco data aggregators and fraud uh teams. Um, like exactly around this use case. I think that that was also very interesting. We pondered without, you know, like with a question mark not an exclamation mark, um around both foundation models as well as authentication methods. And we tried to understand how this would, um, shape the future of fraud prevention systems. I think especially foundation models, um to me, it remains to be seen exactly what would be their role to play. Um, we talked about, uh maybe feature engineering. You mentioned, uh them being used for anomaly detection, uh which I really like. So there are definitely places where foundational models could play a part. Which are not necessarily straight out removing or replacing machine learning models. Um, and I think it would be interesting to see how this would shape up. Um, and lastly we talked about what should fraud teams do, already today, so they are better positioned to A) become that uh that uh better future fraud prevention organization. And also meet these uh future fraud attacks or fraud threats. And I really like your point.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
71:14
You have the same point.
Chen Zamir
Chen Zamir
71:20
Yeah, I just agree with it. Um, that it's all about increasing your reaction speed. And that how you actually go about it might look differently. Uh, for different organization sizes. You mentioned that smaller teams, that have less resources and have less their capability to invest in house, should probably go with an orchestrator of sort that is able to give them um all the different capabilities in one place. And I think the important thing here is to be able to kind of like control the reaction cycle across all of these point solutions. Uh, but more importantly I think for organizations that have their own uh, their own teams, and their own resources, to really invest more in how quickly they react. And we also talked about the fact that how quickly you react doesn't necessarily mean how fast, uh can you deploy a rule. Or how fast can you retrain a model. But the entire chain of learning. And I think that is so so so crucial.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
72:24
I, I'd also add one other thing. Do you mind? Um, which which is that we walk through one detailed example for one kind of fraud. But you could do the same exercise that we went through today. And you could do it for account takeover, you could do it for scams, etc.
Chen Zamir
Chen Zamir
72:41
Yes. And if you're, uh if you're having trouble, uh doing it, uh yourself. I'll put David’s uh LinkedIn profile, uh in the podcast uh episode description. And you can, uh and you can message David. That's exactly the kind of engagements that he's, uh been, uh involved with, uh financial services today. David, I want to thank you. And I hope, uh dear listeners, that um other than scaring you, maybe I hope a bit. Uh just a bit. Uh and not a lot. Uh we also gave you, especially David, gave you some practical, uh ways in which you can improve your fraud prevention systems right now. Uh, so you are better positioned to whatever comes next. What comes Next, uh, we have guests, but, uh, well, we'll we'll all find out soon. David, it's been such a joy, such a pleasure having you here. Um, thank you very much.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
73:42
Yeah, thank you, too. I think this is the most in-depth conversation we've had. And it's been super interesting for me, too. You know, you are also, you're very quotable.
Chen Zamir
Chen Zamir
73:50
I try to, I try to.
Black and white headshot of an Asian man with glasses, short dark hair, and a goatee, wearing a dark jacket and smiling.
David Liu
73:51
We can have a, you can have a section, you know, quotes by Chen or something like this.
Chen Zamir
Chen Zamir
73:54
I try to. Uh that would be my next book. Uh once more, it's been a pleasure having you here. I super appreciate you joining us. And for all your listeners, I hope you enjoyed it as well. And I see you all next Saturday.