{"id":83992,"date":"2020-04-20T15:10:06","date_gmt":"2020-04-20T15:10:06","guid":{"rendered":"https:\/\/feedzai.com\/?p=83992"},"modified":"2024-04-09T09:21:52","modified_gmt":"2024-04-09T09:21:52","slug":"how-psps-can-get-ahead-of-fraud-in-the-post-covid-19-world","status":"publish","type":"post","link":"https:\/\/feedzai.com\/blog\/how-psps-can-get-ahead-of-fraud-in-the-post-covid-19-world\/","title":{"rendered":"How PSPs Can Get Ahead of Fraud in the Post COVID-19 World"},"content":{"rendered":"
[vc_row row_height_percent=”0″ override_padding=”yes” h_padding=”2″ top_padding=”1″ bottom_padding=”2″ overlay_alpha=”50″ gutter_size=”3″ column_width_percent=”100″ shift_y=”0″ z_index=”0″][vc_column width=”1\/1″][vc_row_inner][vc_column_inner width=”1\/12″][\/vc_column_inner][vc_column_inner width=”10\/12″][vc_single_image media=”90962″ media_width_percent=”100″][\/vc_column_inner][vc_column_inner width=”1\/12″][\/vc_column_inner][\/vc_row_inner][vc_row_inner][vc_column_inner column_width_percent=”100″ gutter_size=”3″ overlay_alpha=”50″ shift_x=”0″ shift_y=”0″ shift_y_down=”0″ z_index=”0″ medium_width=”0″ mobile_visibility=”yes” mobile_width=”0″ width=”2\/12″][\/vc_column_inner][vc_column_inner width=”8\/12″][vc_column_text]Fraudsters have been busy. During this crisis phase of the Coronavirus pandemic, they’ve launched an avalanche of attacks<\/a>. Perhaps more importantly, they’re poised to commit even greater fraud once governments start easing lockdowns and consumers start shopping again.<\/p>\n The number of consumer transactions has decreased, but scams are on the rise. It’s the perfect environment for criminals to be in attack mode. They’re using bots to initiate multiple login attempts from the same device or the same location. Their goals? Discover which login credentials they’ve garnered through phishing scams or other fraud schemes provide them with access to their victim’s accounts. Once they know a login credential is valid, they’ll either sell the credential on the dark web or use the credentials themselves.<\/p>\n Payment service providers (PSPs) can also find opportunities in this period of reduced transactions. Because the number of transactions has decreased, false positives should also have reduced.<\/p>\n Use the time this provides to beef up your fraud-fighting techniques and prepare for the wave of fraud that’s likely coming as governments remove strict lockdown measures.<\/p>\n Transaction monitoring, typically a superior method because of data, volume, and consistency, may need a boost from fraud prevention techniques rooted in the current crisis. Day-to-day consumer transaction behavior is significantly different than what it was pre-pandemic.<\/p>\n You could make major changes to models or your infrastructure to accommodate consumer behavior changes. Still, I’d advise against such drastic measures because the data that you’re using is in an artificial period.<\/p>\n Instead of making significant changes, double down or start to identify early fraud pattern indicators so you can block fraud in the coming recovery.[\/vc_column_text][\/vc_column_inner][vc_column_inner column_width_percent=”100″ gutter_size=”3″ overlay_alpha=”50″ shift_x=”0″ shift_y=”0″ shift_y_down=”0″ z_index=”0″ medium_width=”0″ mobile_visibility=”yes” mobile_width=”0″ width=”2\/12″][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row row_height_percent=”0″ override_padding=”yes” h_padding=”2″ top_padding=”1″ bottom_padding=”2″ overlay_alpha=”50″ gutter_size=”3″ column_width_percent=”100″ shift_y=”0″ z_index=”0″][vc_column width=”1\/1″][vc_row_inner][vc_column_inner column_width_percent=”100″ gutter_size=”3″ overlay_alpha=”50″ shift_x=”0″ shift_y=”0″ shift_y_down=”0″ z_index=”0″ medium_width=”0″ mobile_visibility=”yes” mobile_width=”0″ width=”2\/12″][\/vc_column_inner][vc_column_inner width=”8\/12″][vc_column_text uncode_shortcode_id=”761594″]<\/p>\n Municipal lockdowns and social distancing have forced many traditional customers to become digital customers. And customers who usually just look at their accounts online, whom I refer to as digital views, are now forced to transact online.<\/p>\n Most of this new digital customer base doesn’t trust online banking, yet they’re particularly vulnerable to fraud schemes. They’re going to need extra support making this transition. The strategies for determining who this population is can include:<\/p>\n Once you’ve zeroed in on this population, determine how to treat them given your policies and strategies as they’re the most vulnerable.<\/p>\n Educating customers to avoid fraud scams is the million-dollar solution, but far easier said than done. One crucial step is directing customers to legitimate sources of information on coronavirus fraud scams such as the Federal Trade Commission<\/a>, the World Health Organization, and INTERPOL<\/a>.<\/p>\n You may also want to help customers distinguish between trusted communications and advice from fraudsters. Providing an illustration that compares a legitimate email vs. a phishing scam can be helpful.<\/p>\n Be sure to utilize pop-ups in apps and on your website to spread this message as well.<\/p>\n Capitalize on existing relationships with e-crime providers, dark web experts, and both internal and external cybersecurity professionals to uncover credential testing and check customer scam reporting.<\/p>\n Because we’re in such unchartered territory, industry sharing of data may have slowed. While that makes sense from the perspective of not wanting to be wrong about what you’re calling fraud, sharing data across PSPs (be they banks or acquirers) is invaluable now.<\/p>\n Check whether you’re sharing the same amount of data as before the Coronavirus, and try increasing how often you share. I’d recommend sharing data twice a week for now.<\/p>\n When fraudsters steal login information, they test the credentials to ensure they work. Scammers often conduct credential testing on a volume basis via bots. Fraudsters attempt a large number of logins from the same device or the same location in an attempt to discover which credentials give them access to the victim’s account. We’ve seen bot-enabled credential tests attempt one million logins in one minute. They’re collecting, testing, and cleaning data.<\/p>\n You can help stop them by uncovering the telltale signs of credential testing, which can include:<\/p>\n Traditionally, looking at IP addresses to indicate fraud would be a fool’s task; many corporations require employees to share IP addresses. Having thousands or even tens of thousands of people using the same IP address makes that method implausible.<\/p>\n However, in the upside-down world of Coronavirus, large parts of the global population never stray far from home. The beauty of this, and the perversity of where we are right now, means looking for common IPs is more valuable than ever. Dusting off the cobwebs from this old technique can help distinguish good behavior from fraudulent behavior.<\/p>\n Most scams take longer than legitimate activities, so look at online session times. If sessions typically take four or five minutes are now fifteen minutes long or longer, that’s probably indicative of account takeover (ATO) or other fraud.<\/p>\n That’s true in reverse as well. Sessions that are less than thirty seconds long can also indicate fraud.<\/p>\n We all know that working in silos creates blind spots. That’s particularly true when fraud teams cut themselves off from the organization’s cybersecurity team. Instead, work together to understand:<\/p>\n These are all fraud tells.<\/p>\n If someone is logged in via a computer and also on a mobile device, that might indicate that a fraudster is trying to get a victim to take one action through the web and do something else through their mobile device.<\/p>\n Consumers understand the need for added protection right now. That won’t always be the case, so use this grace period wisely. Here are a few ways to build trust:<\/p>\n Let’s say you take all the advice I’ve outlined in this article. And sure enough, you find customers who’ve had long banking sessions or cross border transactions below a dollar. But you’re not sure it’s fraud, are you? And, let’s face it, the volume is too high to call every customer. And frankly, with everyone’s cell phone currently flashing the ubiquitous “scam likely” when the phone rings, you stand a good chance of getting lost in the noise.<\/p>\n Let’s face it; it’s one thing to know what to look for; it’s a whole other thing to implement processes based on those learnings.<\/p>\n Enter the gray list. A gray list is a method of integrating these insights into the system. The gray list allows you to say “wait and see” in a way that doesn’t lose the knowledge you’ve gained. It identifies and segments populations who will be at heightened risk later should further events occur.<\/p>\n When we shift from crisis to recovery, the number of transactions will increase. Fraud will increase as well, and this is when you can set different thresholds and values. It can be as simple as saying instead of waiting for a fraud score to hit 900, if the score is 700, but is also on the gray list, trigger an alert. What you’re doing is increasing your monitoring threshold for those at risk.<\/p>\n Fraudsters are in attack mode. They’re preparing to commit an onslaught of fraud once consumer spending picks up, indicating that we’ve moved past crisis mode and into recovery mode. PSPs should use this time to get ahead of the fraud that’s on the horizon by placing a particular emphasis on protecting the most vulnerable populations. Utilizing techniques well suited to the current environment will help uncover fraud behavior patterns. Finally, implementing gray lists ensures acting at the right time to help prevent fraud.[\/vc_column_text][vc_single_image media=”119063″ media_width_percent=”100″ uncode_shortcode_id=”291649″ media_link=”url:https%3A%2F%2Fhubs.la%2FQ01BBGDx0|target:_blank”][\/vc_column_inner][vc_column_inner column_width_percent=”100″ gutter_size=”3″ overlay_alpha=”50″ shift_x=”0″ shift_y=”0″ shift_y_down=”0″ z_index=”0″ medium_width=”0″ mobile_visibility=”yes” mobile_width=”0″ width=”2\/12″][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row]<\/p>\n<\/div>","protected":false},"excerpt":{"rendered":" Fraudsters have been busy. During this crisis phase of the Coronavirus pandemic, they\u2019ve launched an avalanche of attacks. Perhaps more importantly, they\u2019re poised to commit even greater fraud once governments start easing lockdowns and consumers start shopping again. Fraudsters are plotting future attacks, PSPs should<\/p>\n","protected":false},"author":8,"featured_media":90474,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[76],"tags":[77,454],"acf":[],"yoast_head":"\nFraudsters are plotting future attacks, PSPs should fight them now<\/h2>\n
Transaction monitoring in an upside-down world<\/h2>\n
How to protect your customers from fraud<\/h2>\n
Protect vulnerable digital users<\/h3>\n
\n
Educate your customers<\/h3>\n
Leverage e-Crime partnerships<\/h3>\n
Don’t neglect consortium data<\/h3>\n
How to identify early fraud pattern indicators<\/h2>\n
Fraudsters and credential testing<\/h3>\n
\n
IP addresses hold new value<\/h3>\n
Focus on session times<\/h3>\n
Collaborate with your cybersecurity teams<\/h3>\n
\n
Look for concurrent logins<\/h3>\n
Build trust<\/h3>\n
\n
Gray lists: putting it all together<\/h2>\n
Key Learnings<\/h2>\n