Payments on Fire™

Episode 140 – Finding Fraudsters at the Front Door - Robert Capps, NuData Security - Payments on Fire® Risk Series


Listen Later

In a crisp explanation of account takeover and authentication risks, George and Robert Capps, Vice President, Market Innovation, at NuData Security. They discuss the findings of a recent NuData report and its experience with the sophistication of online fraudsters. NuData’s techniques are all about foiling cybercriminals as they bang at the front door of financial institutions, merchants, streaming services, and more.

Payments on Fire® listeners know that we’ve been taking a steady look at fraud issues over the past few years. Fraudsters have been pouncing on every opportunity, taking advantage of pandemic relief payments as well as the shift from card present to card not present, remote commerce transactions. If this topic didn’t matter, we wouldn’t be talking about it.

Measuring and detecting what the fraudsters are up to and their impact is critical. To better understand what’s going on, we speak with Robert Capps, Vice President, Market Innovation, at NuData Security, a company that specializes in behavioral biometrics.

NuData published in Q3/2020 its e report on cybersecurity trends. And the findings are really interesting.

What They Found

The current scourge is account takeover. ATO is a concern for financial institutions, for retailers, streaming media companies, and more.

Attack method sophistication goes well beyond reuse of stolen user IDs and brute force password guessing.

It is an arms race of increasingly complex and sophisticated attack and detection techniques.

NuData and others have expertise in behavioral analytics, tools that detect, among other things, bots that are build to emulate human interactions at the account login page. The use of CAPTCHA is one technique to deter these attacks. But the fraudsters have responded, going so far as to establish call center-scale operations with staff endlessly filling in CAPTCHA forms to add the human touch and smarts in what are otherwise highly automated ATO attacks. This is human farming to get around CAPTCHA and other rudimentary defenses.

Financial institutions and retailers aren’t the only targets. In this age of stay at home orders, streaming services have become targets of opportunity. Parasitic use of streaming service accounts has risen as the fraudsters sell streaming service account credentials.

The Defender’s Balancing Act

There are dedicated professionals working on both sides. But the defenders have the harder job. Besides having to protect every door and window, they also have to keep it simple for good users to transact. Adding friction to a transaction flow increases the shopping cart abandonment rate. That’s bad for the ecommerce merchant and insults the customer. It’s a tough balancing act.

Part of that balance is handled by “step up” authentication based on the level of risk. A bank might let a session proceed to a balance inquiry without asking for further customer input. But if a new payee is added to the account, the bank might insist on sending a one time code to the customer via email or SMS.

Getting to Good ASAP

Providers of authentication services see activity from a lot of devices. Building profiles based on these devices and the many variables surrounding each transaction, they use the profiles to efficiently track the behavior of each in order to separate the known good profile from the questionable.

A technique to “get to good” faster is to pool that profiling information in anonymized form from across all of the clients who agree to participate.

COVID Impact

Robert discusses the shifts in fraud given the pandemic. As a percentage of transactions, fraud increased substantially in the travel segment. And for those retailers operating in the physical world the shift to e-commerce was sometimes overwhelming. That’s a story we’ve heard a lot at Glenbrook. Check out our COVID Series book.

Podcast transcript

 

 

 

...more
View all episodesView all episodes
Download on the App Store

Payments on Fire™By Glenbrook Partners, LLC

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

41 ratings


More shows like Payments on Fire™

View all
This Week in Startups by Jason Calacanis

This Week in Startups

1,272 Listeners

a16z Podcast by Andreessen Horowitz

a16z Podcast

1,023 Listeners

The Twenty Minute VC (20VC): Venture Capital | Startup Funding | The Pitch by Harry Stebbings

The Twenty Minute VC (20VC): Venture Capital | Startup Funding | The Pitch

513 Listeners

Fintech Insider Podcast by 11:FS by 11:FS

Fintech Insider Podcast by 11:FS

189 Listeners

Invest Like the Best with Patrick O'Shaughnessy by Colossus | Investing & Business Podcasts

Invest Like the Best with Patrick O'Shaughnessy

2,299 Listeners

The Payments Podcast by Bottomline

The Payments Podcast

11 Listeners

All-In with Chamath, Jason, Sacks & Friedberg by All-In Podcast, LLC

All-In with Chamath, Jason, Sacks & Friedberg

8,912 Listeners

Dwarkesh Podcast by Dwarkesh Patel

Dwarkesh Podcast

379 Listeners

Behind the Balance Sheet by Stephen Clapham, Behind the Balance Sheet

Behind the Balance Sheet

46 Listeners

ACQ2 by Acquired by Ben Gilbert and David Rosenthal

ACQ2 by Acquired

209 Listeners

Sharp Tech with Ben Thompson by Ben Thompson

Sharp Tech with Ben Thompson

94 Listeners

Merryn Talks Money by Bloomberg

Merryn Talks Money

46 Listeners

The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis

455 Listeners

BG2Pod with Brad Gerstner and Bill Gurley by BG2Pod

BG2Pod with Brad Gerstner and Bill Gurley

455 Listeners

Complex Systems with Patrick McKenzie (patio11) by Patrick McKenzie

Complex Systems with Patrick McKenzie (patio11)

114 Listeners