We Them Media logo We Them Media Back the work →

From Crypto with Kamal, by Kamal Hubbard

Risk and fraud in fintech: a panel hosted by Kamal Hubbard

This is Kamal’s video, shown here with his permission. Watch it on his channel, where the comments are.

Kamal Hubbard moderates a 2017 panel on risk and fraud in fintech, introducing what he calls “a great panel of anti-fraud fighters”: Lauren Russell, “the Fraud Investigations and Compliance Manager at AAA in Walnut Creek,” forensic accountant Nadav Paran, Crowdfy founder Abhishek Agarwal, and Olga of the fraud protection company Signifyd. They trade stories from their work, including an ATM scheme where thieves would take money mid-dispense: “They will bring this nail clip, and they will take out 3 or 4 $20 bills.”

The panel covers identity theft, machine learning in fraud detection, biometric authentication, and the risks of cryptocurrency. Nadav Paran points to the cyber currency Liberty Reserve, which became “the number one platform for human trafficking, drug smuggling, weapons smuggling, terrorist financing” before its founder was sentenced to 20 years in federal prison.

Transcript

Skip the transcript ↓

Spotted a wrong word? Tap its timestamp, then tell us.

Transcribed by We Them Media from the original audio, with Kamal’s permission. Speaker letters mark turns, as the model separated them.

These are the speakers’ own words. We have not checked their claims.

0:02ALet’s grab it.

0:04BWelcome everyone. Thank you so much for coming. It’s like, seems to be getting more difficult as the summer wears on, even to get people to come out. So I really appreciate that you’ve made it tonight. We’ve got a great panel, and Kamal Hubbard, who was the actual organiser of the panellists as well as the moderator tonight, I’m going to hand it over to him and he’s going to introduce the panellists. And I think it should be really interesting because obviously risk and fraud and security issues are high on our list in the fintech domain. Thank you.

0:37CAll right, good evening everyone. As Pemo said, my name is Kamal Hubbard, and I’m here with a great panel of anti-fraud fighters, as I like to call them. So I really wanted everybody to start with Lauren and introduce themselves.

Read the full transcript ▸

0:59AHi everyone, my name is Lauren Russell. I’m the Fraud Investigations and Compliance Manager at AAA in Walnut Creek. I’m really excited about fraud. I’ve been in fraud for about 10 years and I’m very happy to be here with a great group of people and I’m excited. Thanks for having me.

1:15DHi everyone, my name is Nadav Paran. I’m a forensic accountant with TM Financial Forensics, which is a litigation support group. I’ve been working in that area for 5 years. I hold a CPA, CFE, and recently got the CAMS certification, which is for anti-money laundering. I’ve also been a reservist with the Coast Guard for 7 years, where I’ve done some work as a federal law enforcement officer. I’ve been fascinated by fraud and the lengths to which criminals will go to take money and hide their activities. And lately I’ve been especially interested in money laundering and terrorist financing.

1:55EHi, my name is Abhishek Agarwal and I’m the founder and CEO of Crowdfy. At Crowdfy, we are bringing standardization to peer-to-peer and crowdfunding platforms using standard models which compare to bond ratings. Prior to doing Crowdfy, I was working at Bank of America where I was building these operational risk models which looked at fraud and we did a lot of So if someone has free time, I can tell you a lot of awesome stories about fraud. Like when you were saying people go to what lengths, it’s amazing. You can’t believe that. So really, fraud is such a fascinating subject, and I’m always interested with it. Thanks a lot.

2:34FHi, everyone. I’m really excited to be here. My name is Olga, and I work for Signifyd Fraud Protection Company for the e-commerce sector located in San Jose. I am really, really happy being in the industry of fraud protection for maybe the exact same reason as described by my fellow panelists. And it is an exciting area. I’ve been in this line for over 10 years as well. I first started with ATM fraud detection and investigation in Europe. After that, immigrated to Canada. Where I spent over 7 years working for a credit union assistance, protecting customers for their online banking fraud exposure and also credit card, debit card fraud exposure. And here I am here in Silicon Valley working for a fraud protection company providing the great services Kamal, I can just share one story around ATM fraud.

3:58GAbsolutely.

4:00EWhen she was talking ATM fraud, I had just this awesome story. So we had -- so if you have ever used an ATM, when you ask for like $100, it spits out 5 notes.

4:09BYeah.

4:09EAnd then do you know that if you don’t take it, it’ll actually take it back and credit the money back to you? So if you don’t know that, that’s how the ATM works. So for a long time at one of our ATMs at BFA, constantly the balance was off. It will be off by $100, few hundred dollars every day. And we checked the machine, changed the machine, redid it, and we couldn’t find out why that was happening. And then someone was watching the video, and then they closely watched the video, and what someone was doing is they will come every day, they will say I need $200, and then the machine will spit out $200.

4:09EThey will bring this nail clip, and they will take out 3 or 4 $20 bills between that stack and then wait for the money to go back. So that when the ATM machine takes back, it does not count the money back. So it will credit back $200, but they have taken $80 out of that. And they did that for a few years. I’m not kidding, because it was so hard to imagine that, and it was just such an awesome story which was talked about in Dartmouth all the time. So just to see how creative people can be, just to get started.

5:14DWas it always the same ATM?

5:15EIt was, yes, it was the same location, yes.

5:19GIt’s amazing.

5:20ESorry, Jack.

5:22CNo, no, that’s great. Actually, you know --

5:25EWe can sell 10 more of those.

5:29CAnd, you know, that’s actually a great segue to my first question, which is fintech is interfacing with consumers and merchants. Everywhere from the typical e-commerce purchase to a small business seeking a loan, workers planning for their retirements, or families sending funds across borders to help support each other financially. I’m sure you, you’ve all seen instances of these and where fraud arises. Please share some more of your stories if you can with myself and our audience here.

6:06ASo when I was in fintech, um, of course I’m sure all of you have seen this too, there was just lots of identity theft. And we had a pretty big ring of fraudsters who were replicating driver’s licenses. They would have a selfie of the actual person, and we put these through, you know, a tool called Yumio, and Yumio would say, yes, you know, this is a match. Of course the ID was fake, but that’s a whole nother story. So we had one instance where this 80-year-old woman was, you know, creating these transactions on the platform, and it was before I started working there. So when I came on board, there was some kind of sticky situation, and I said, there’s just no way. My gut is telling me it can’t be this woman. And, um, someone else had been communicating with her via email, and I thought, wait a minute, I don’t think an 80-year-old woman will be using this type of language. Something doesn’t feel right. So cases of identity theft are definitely prevalent. fraud and can oftentimes go undetected, but it’s really up to us to find a pattern and to stop this because these are real people’s bank accounts and identities being stolen and money coming out of their accounts.

7:12DSo yeah, I have a case right now that I’m working on where there’s a, there’s a company that manages a mutual fund portfolio and they had they had mispriced their -- some of the assets that they were holding within this mutual fund. And, you know, they’re saying that it’s not fraud. It probably wasn’t. It was probably a problem of internal controls. But they were relying on their technology to value all these assets. And after a couple years, they realized that they had been misvaluing the assets. And the SEC came in and said, hey, you’ve been mispricing these assets for 3 years and selling them to all these shareholders.

7:12DAnd that’s obviously not okay under regulations. And so now they’re going through this very lengthy process of not only fixing all their internal controls, making sure that to the extent that they’re relying on technology, they’re also implementing a proper quality assurance process and repricing everything manually. And then I’m now involved in going back and repricing all of these assets for a period of 3 years on a daily basis, and figuring out who were the shareholders on which day, how much did they hold, and as a result, how much should we pay them back? So if you can imagine, there was a multimillion-dollar fine from the SEC, and now they’re spending years and millions of dollars paying a large team of consultants what it costs to to remedy all of this.

7:12DSo that’s what we’ve been seeing, and I highly recommend that companies going forward really, really think about their compliance programs and really think about quality assurance, because not only do you run the risk of getting in trouble with the regulators, but also, I mean, hurting your shareholders, which I think that a vast majority of companies are not interested in doing at the outset.

9:07ESo something related, but I don’t think they’re doing fraud. So Prosper recently came out and said that calculations they did on their site for net returns has been wrong for last 3 years, and they restated for everybody, and pretty much for everybody the returns went down by -- so if you’re getting 16%, you’re down to 6%. So like really drastically. Quite a few people are trying to sue them. SEC has already opened an inquiry, and, uh, And they’re not sure what’s happening. Though I know from some other sources that they knew about it a few months back and it took them at least a few months to just get that fixed.

9:07EI don’t know whether it’s fraud or not, but that’s a concern which a lot of people have. On the other side, if you talk fraud and I bring slightly different topic, but if you’re looking for cryptocurrencies, there’s a lot of fraud there. So if you’re trying to buy something different from Ethereum and Bitcoin, A lot of new ICOs. If you try to go to one of these sites, they will want you to hold your license and move your head like this and this and do a lot of actions. There’s a reason for that, because everything can be forged. So let’s say if you have a license, someone steals it, they can actually change your -- Photoshop your photo with their photo and then use that as identity fraud.

9:07EAnd with cryptocurrency, As soon as someone buys it, they can actually move it to their private wallet and it goes away, unlike an ACH or a credit card transaction which you have 60 days or 90 days to return. So a lot of cryptocurrency companies are facing this where identity fraud or identity theft results in an immediate loss and there is no recourse for that. So a lot of them have moved to asking people to do various, pretty much, dances just to identify who who they are. But the other part is nobody has found a good solution right now to sort of manage that part.

10:59CJust real quick, I mean, touching on what you were talking about, the CoinDash hack for $7 million that came out yesterday.

11:09BYesterday, yeah.

11:10CLatest ICO. So people should be careful with ICOs, quote unquote.

11:14EI can talk about ICOs more if you want.

11:16CYeah, we’ll talk about that a little bit later.

11:20FWell, in the e-commerce world, at Signifyd, we see absolutely similar scenarios as Lauren mentioned. And fraudsters are obviously always, always being super creative, a lot of creativity. The main types of cases that we see are based on the type of fraud which we call also stolen financial data fraud. When our credit cards are being compromised and the data being sold on the black market or the dark web. And this is when we could, I guess all of us or majority of us, being able to experience the unfortunate situation, having a charge appearing on our credit card for something we never purchased. So we’re trying to help the e-commerce businesses to mitigate losses occurring based on those instances. And this is, I have to say, a very constant game of cat and mouse, which never ends, simply because fraudsters are utilizing different systems, being on a higher level, and trying depends on the level of organization. They’re very creative and all the time situations may change. So this is why our company is utilizing machine learning which helps analyze data and analyze also the proven fraudulent transactions from the past in order to protect the consumers for the future.

13:30EThanks.

13:34CMy next question deals with artificial intelligence. You just touched on machine learning, but artificial intelligence coupled with big data allows for the possibility of automating credit scores so that businesses and consumers can pay more competitive rates on their loans.

13:50EHow does this model for deriving new interest rates mitigate risks So there are 2 parts to that problem, and first is the model, and the second part is regulation. So if you are a lender in the US, there is a lot of regulation like the Community Reinvestment Act, Equal Credit Opportunity Act, ECRA, TILA, and quite a few others. And a lot of machine learning models which are black box are not allowed to be used because if it’s a black box, I don’t know whether it’s discriminatory or not. And a lot of times data is discriminatory, so it ends up being not getting used in the lending purpose, though it can be used at other places.

13:50ESo like at our company, we use a lot of machine learning and AI to do investing. But we don’t do it on the lending side. So there is a slight disconnect there. Government is trying to do that, but still, it’s still ways to go for lending to use a machine learning model. Having said that, big data can be used for underbanked, for KFIs and other places. Well, what I can use is something different, like people are using phone records, like how much payments you have made over time, GPAs in your school, college. So I know this company called Six Up which gives loans to poor students who are in high school who will go to a 4-year college.

13:50EAnd they sort of serve as a bridge between whatever loan you can get from the government and whatever is your need. So $10,000 to $15,000 a year, they give you that. And the way they look at it is What is your community involvement? How much has been your GPAs? How many other sort of any tickets you have for behavior, or do you have a good behavior? Sort of these are external data points they are using to come up with a good credit score. But these are all deterministic heuristic models. They are not a black box machine learning model. So if I go to a black box machine learning model, then what I say is this is -- let’s say a million records, you go and find me the best rate or best fit or whatever that is, then it’s very hard to replicate that or to tell that this is factor getting used by that much.

13:50EAlso because this is an important factor versus that. So as well as what will happen is it might redline as it goes by itself. You wouldn’t know that as an outsider. So consciously you are not discriminating, but the machine is discriminating.

16:28HRight.

16:29EAnd that’s the reason machine learning doesn’t go in lending. And it’s funny, like, we use it on my investing side, and I was talking to some Berkeley profs and they were like, yeah, you will end up promoting the discrimination, so we don’t think we’ll fund you. And that was their case. So it is still a gray field when you use machine learning for rating the people because of the discriminatory -- the data brings to that. And that’s just a few things.

16:56DI will say that in 2015, 9 million Americans were unbanked, meaning they had no bank accounts at all, which when I read that, I thought that was crazy for the US. I think that these types of technologies do enable you to collect a lot more information on people and make it easier to bring people into the banking system in terms of know-your-customer regulations and beneficial ownership. So you’re absolutely right. This is a topic that came up at the ACFE conference about, you know, how do you deal with the discriminatory manner in which AI works. So I think what it’s going to take really is an auditable process of some kind. But big data is absolutely the way that I think the financial sector is heading and using -- and fintech is at the forefront of this -- finding other ways to know the customer, finding other ways to determine whether they’re reliable from a credit risk standpoint. And so I’m pretty excited to see what’s going to happen with that. And it’ll be really interesting to see what kind of regulations are going to come into place and how a regulator is going to audit your process. for credit risk analysis.

18:15ESo one more example. So recently, if you read, Bloomberg came up with an article where they said that 33% of the loans on LendingClub are not income verified, and that’s why the defaults are going up. And we did an analysis and actually wrote a rebuttal that actually the loans which are not getting income verification are performing better than the loans which have verified income across the credit spectrum. So it’s not that they are better in credit quality across the credit spectrum, they do that. And then we work very closely with LendingClub’s analytics and their platform team, and then they came back and they were like, yeah, that’s great because we know that is true. The reason being they’re able to use alternate flags in their big data to find whether the customer is fraudulent or not. So once they have enough belief that the customer is telling the truth, they don’t do the income verification. And that has proven to be good. So From that perspective, a lot of cost which would have gone into verification is reduced for them, and it still performs equally well. So that’s one of the examples I can give you, but that’s still not in underwriting, that’s just on the verification part.

19:17FI absolutely agree that the method of using machine learning is very effective in terms of mitigation of fraud. If speaking about the e-commerce sector where Signifyd is working, I have to say that it impacts significantly the fraud percentage. For example, there’s been statistics data comparing fraud percentages between 2016 and 2017, 17 years. And it’s been shown statistically that based on machine learning fraud protection method, losses for the e-commerce companies decreased with a big percentage. 34% or so, which is speaking by itself that it is a great tool to mitigate fraud.

20:36CAll right, great. So in many ways, our smartphones have made life very convenient for us, and it helps us with our day-to-day chores and, you know, errands and things like that as well. So now the Internet of Things is on the rise and beginning to expand. And with the Internet of Things, we have interoperability with our phones. So we’re able to control the climate in our home and do all sorts of great things with our devices, our handheld devices. And also with fintech, we can also bypass that visit to the bank. So now with so many IoT devices having connectivity with our phones and more people conducting online transactions on their handsets, how susceptible are people’s financial information to intrusion, and what is the industry doing that you guys know of to mitigate this risk?

21:37DYeah, I think this is a huge issue that a lot of people are looking at for good reason. And there’s a couple different issues packed into there. For one, now that we can do transactions on our phones so quickly and so easily, it makes it so much easier to move money around illicitly. Traditionally, if a human trafficker who received $1 million would have to break up that $1 million into several smaller transactions, And actually pay an individual to walk into a bank branch, open an account, deposit less than $10,000 so that they don’t reach that reporting threshold. And that takes a lot of money and a lot of cost.

21:37DAnd then also there’s the risk of having these random people that it doesn’t make any sense why they’re depositing $9,000 every single week in ATMs all over the city. So now what we have is it’s much easier. go on your phone, you create it, you open an account, and you can start moving money much quicker and much more easily. Luckily, with more and more technology, there’s much more transaction monitoring. So theoretically, the financial platforms can pick up on that much quicker. But that’s -- but a lot of smaller companies that are creating these platforms don’t necessarily have the technology or the compliance organization to really flag these transactions as they should.

21:37DAnd maybe they’re not thinking ahead as much as they really could be to detect what kind of transactions are suspect. And then there’s the cybersecurity issue of all this information is on your phone. And not only that, all this information -- which maybe your phone is extremely well secure, as the FBI found out after the San Bernardino shootings, but But some other devices that are connected to your phone, a lot of those aren’t as secure. And there isn’t really any government regulation that determines how things should be secured. And so it’s kind of up to each manufacturer to secure things as much as they see fit.

21:37DAnd what a lot of cyber professionals are seeing are that customers just aren’t very savvy with their cybersecurity. And so people are using the same password for all their different websites. And even though maybe your Bank of America website is very, very secure, if you’re using the same username and password for ESPN, and ESPN gets hacked, then the criminals know that there’s an 80% chance that you’re using the same username and password combination. And so that’s how they hack into your bank account and clean it out while you’re sleeping. And so really the big risk is consumer savviness. And making sure that they’re being aware of their security posture in cyberspace across all their devices, all platforms.

24:32AI think as customers and consumers in fintech and all industries, you know, we hate being locked out of our accounts, but that’s really a protection for you. If a fraudster is trying to log into your account and enters your password repeatedly, typically they’ll be locked out. a protection. I think a lot of the customer friction that merchants and retailers and fintech companies want to avoid, but then at the same time they want to have these preventative measures in place, it’s really for our own protection. So I know that 2-factor authorization isn’t always fun, but it is needed. And having to manually change a password -- I just logged into Sprint the other day and they’re forcing me to change my password and they forced me to change my password again.

24:32AAnd, you know, like Nadav was saying, we’re all using the same passwords repeatedly, and if you are involved in phishing or pharming and your information is taken, then it’s pretty simple to log right into your bank account and move money around. When I was working for Uphold, we did have some challenges with ACH, and so there was a $2,000 limit per day, um, so that, you know, so that fraudsters could not move more than $2,000 out of someone’s account daily basis. And of course, you know, a legitimate customer might be affected by that, but ultimately these things are put in place to protect us and to protect our money and our data.

25:52ESo 2-step verification or authentication is the way to go. So I’m the first culprit, I have not done it, but I think all of you should do that because that’s the only way to more or less ensure that there is no fraud. Because even with a phone push, Mm-hmm. When you get the verification, that can be hacked and someone can sort of transfer your phone number to their own device. So the 2-factor authentication is the only way which a lot of companies are pushing for to sort of go and get that. Having said that, from a user perspective, so like I use -- I’m a Google guy, so I have a Google Home at home and sort of my phone and they are tied together.

25:52ESo at least I understand security and I have a pretty secure Wi-Fi network, but a lot of people just keep it unsecure. So someone can come and let’s say you’re using Amazon Alexa to do transactions or buying something or something like that, or Google Home, they can actually hack into your network and see all what you’re doing and then get all the stuff which you are not trying to give out but you are giving out by fire. So that’s the concern which sort of none of the fintechs can sort of address, it’s more on you rather than them. But When you talk about IoT and all the other stuff, it’s mostly a consumer responsibility to secure their devices and secure their identity.

25:52EBecause if you make an error, it’s very hard for a fintech company to make a certain -- sort of ascertain that it’s an identity theft, unless until there is a pattern for that. So if you’re talking about pattern matching, a lot of companies, at least the big ones I know, are doing that. They have machine learning programs which are constantly monitoring each and every sort of transaction to see that if there is a trend, or if there is a trend which is outside the norm, and then they are labeling that. I know Coinbase is doing that and a few others. But if you think about the expense of that is -- so I know Coinbase spends a few million dollars just on their Amazon Web Services to basically run all these servers in cloud and all.

25:52EWe being a small startup has $8,000 per month. expense, and we are not doing anything even remotely sort of similar to that. So expenses from a startup perspective are really high. So we sort of -- I know it’s not an excuse, but a lot of startups hope that consumers are more savvy with their data than they usually are.

28:12FYeah, I’d like just to add that even though there’s gaps in security I think IoT is the best thing that can happen when there is machine learning in place. And that is simply because the IoT helps for creation of a lot of footprints, digital footprints, creation a lot of more structured and organized data. Which the model could be analyzing, and thereby machine learning could be a better, better tool for fraud detection. In my case, in the e-commerce sector, this is how machine learning would be helping differentiate different behaviors and recognize if this particular transaction activity belongs to the original consumer or it’s a bad guy trying to get a lock?

29:28ESo I can give you an example around how machine learning can help. So let’s say pretty much every big company has IP tracking. So if IP is being used for a lot of transactions, outside the range, then it usually gets blacklisted for a certain amount of time, and that varies from company to company. So any transaction in that time limit, if it comes from that IP, would get marked and sort of moved to marked as fraudulent. Similarly, we will track your IP as such, like generic IPs where you will be accessing your account from, and if the IP is completely different, usually you will -- we will try to ascertain if it’s the case or if it seems fraudulent, that transaction would be denied. So machine learning, at least in the IP tracking area, can be used a lot, which couldn’t be done before because of IoT and constant IPs for everything available out there. So that’s one of the places which has helped a lot in reducing fraud.

30:23CGreat. So we just brought up 2-step verification and I’m at the point now where if I’m logging into anything, I use Google Authenticator, so I’m tied to my phone once again. And if I’m not using 2-step, I’m like, okay, I don’t feel secure going into certain sites or logging into certain sites. But, you know, along those lines of fraud protection, 2-step verification, biometrics is emerging too as a technique to authenticate identity. And tracking with e-commerce activity of users as well. How do you feel about this method, and what are some of the other technologies and measures you guys have come across in your, your studies or your work? And how do you feel that these are making fintech companies safer for their consumers?

31:16FI have to say from the perspective not only of fraud but also the false positives because they are also causing problems for both consumers, the original buyers, and also the e-commerce companies. That being said, I I think the authentication using biometrics is a great, great tool, as if stored in a proper, adequate way, it is tied 100% to our bodies, and it’s working much better and much more secure and authentic than the regular passwords. Thank you. And this by itself represents data 100% belonging to the original consumer. So for example, there are instances when regular history of transaction activity of one consumer changes. Let’s say the customer travels abroad, or just changes the behavior completely, buying big furniture or buying something unusual and using different device, different IP, different location all of a sudden, then this puts immediately a very interesting situation for the fraud analysis because then there is a question whether this is suspicious activity or just authentic behavior changing the usual activity for the consumer.

31:16FSo this being said, the information belonging 100% via biometrical data to the original consumer is helping also the good analysis whether the transaction to go through or be declined. Because there’s always risk when there’s a change of pattern or change of consumer behavior for transaction to be still positive. But yet being declined as being deemed suspicious. That’s why biometric is an excellent tool to help consumers approve more transactions that otherwise could be declined because of being deemed suspicious, and also for the consumers themselves to be able to process their transactions at any time, in any place, and with any change of their usual behavior.

34:31AI think moving in the direction of using biometrics, as Olga was saying, definitely helps a consumer to get a transaction processed and not have to go through additional verification, which can be very frustrating. Something that I recently read about was that a fingerprint cannot be shared, but a password or a PIN can be shared. And so it’s convenient and secure. And, you know, when I unlock my iPhone, definitely using my thumbprint, you can go right into your mobile banking account. And I feel as though, you know, my 13-year-old son who might want to get his hands on something won’t have access to that. So I mean, it keeps us safe in our own homes as well.

35:13HYeah.

35:15ESo don’t know much about biometric, but I use BioFace fingerprint. authenticator and I love it. I’ve already forgotten my password for that because that’s the only thing I use all the time and I love that because that just makes life so easy. And it has worked flawlessly till now, so I can’t show if it doesn’t.

35:31DJust one thing to think about is that though we can use our thumbprints for our iPhones, they’re also protected by a password. So it’s interesting to -- I I’m not a biometrics expert, but it’s interesting to see how companies are going to deal with that, where you have requiring biometrics, but maybe also having some kind of alternative so that your son can access your phone to play a game, but not go into your bank. So you still have to juggle having shareable devices, and maybe they can -- you can upload multiple different thumbprints and give permissions to different thumbprints, something like that. But it’ll be interesting to see where that goes.

36:18EYeah, definitely.

36:22ASomething else that’s kind of big now is the facial recognition. As Abhishek was saying, you know, taking a photo, your selfie, and then having to update or upload your driver’s license, or, you know, hold your license and talk in Blink. Again, it’s just for your protection, and it’s simply due to fraud. I mean, when I was at The RealReal, which is online luxury consignment, um, so I was the fraud manager there, and we sell -- we would sell $40,000 handbags, Rolexes, and things like that. And we use a tool called Count, which is really reliable. But sometimes you get a transaction and you just don’t know what to do. And we would ask for additional information, and it would always come back fraudulent. If we accepted the transaction because you kind of have your fingers crossed, We definitely get a chargeback for a Rolex, and learned my lesson pretty quickly that way.

37:08CYeah, that’s actually what I was going to ask as a, you know, quick follow-up. So when you’re doing ID verification, like you guys mentioned, you know, there’s ID and then like an ID selfie where you have your ID and hold it up to the picture. Now I see trends moving towards actual video verification. Do you know what’s beyond that?

37:31DHave you guys heard of it?

37:33CWhat else can you do past that?

37:35EDad’s in a cystic mass.

37:37DYeah, maybe. An implantable chip that’s in your, in your body.

37:41AI think something that was always very helpful was verifying the age of an email address. Um, in fraud, even with identity theft, if someone went on my Facebook page and got my selfie and just put another picture of me on a driver’s license, they probably don’t have my email address. And even if they use like lauren.russell@gmail to make it look, you know, as if it was really me, if you pop that into White Pages Pro and it’s never been found online, it’s never been seen, but you see I have a LinkedIn and I have a Facebook, my email address should have been found online many years ago. And so that was one way that we would stop fraud. If the email address, you know, isn’t registered somewhere and I can’t really tie that to the customer, then, you know, I reach out to them or cancel the transaction.

38:28CAnd also with ID verification, sometimes photos will be photoshopped or retouched or something. What do you guys use for detection to basically find that, you know, an image has been altered in some way, shape, or form?

38:47DHave you guys used those tools?

38:49EI have not, but as far as I know, you cannot. That’s the reason a lot of sites want you to move the head. Because what happens is, even if I take a photo like this, it doesn’t have a date, so someone can find it and use it. So having a video with you moving the face and with a date around it, that’s the only way to verify right now. Because the technologies are so sophisticated that Everything is going to a point where you can’t identify the fraud or not.

39:18AAlso, when I was at Uphold, we saw so many of these fraudulent photos and driver’s licenses, but you have to just really pay attention to some of the data on the license. Fraudsters are really slick, but sometimes they’re stupid too, and you can look at the ages, the birthdays. Sometimes they use the same driver’s license repeatedly or the same passport and they just change the photo. And you just sometimes it’s a gut instinct. If something doesn’t look right or you think it’s a little off, it might be. But typically you only really realize that once you’ve been burned, and then you sort of adapt and change. And as you adapt and change your business processes, the fraudsters do the same.

39:55HYeah.

39:57ESo, yeah. So actually most of the fraudsters use the same business license number or driver license number. They’ll just change the photo or something because it’s hard to -- because the license number is valid. So if they change the number to a random number, they cannot. So it’s very hard for them to steal that. Similarly, they will -- if they hack a phone, so let’s say they hack Verizon, so they will do a lot of Verizon phones. It won’t be like they’re choosing that. So you can sort of go on those trends to say that, hey, are these all accounts Verizon accounts, or are these accounts coming from Texas?

40:28DSo you can look at those, but those again, a lot of times And a way to track that is really, you want to build a substantial anti-fraud practice. Build an organization that collects all that data on what has happened to you in the past. Have those fraud professionals join groups like the Secret Service Electronic Crimes Task Force. Have them go to meetings with the Association of Certified Fraud Examiners. There are all kinds of groups and organizations, governmental or otherwise, where public and private sector are all sharing information on the trends that they’re seeing. And that’s really where you find out, hey, we’re getting a lot of identity theft and a lot of false IDs from people purporting to be from, I don’t know, Rancho Cucamonga, California.

40:28DSo if you get IDs from that place, be careful. It also has to do with collecting the data that’s coming on the IDs collecting email addresses, IP addresses, and compare that. Do a holistic analysis and look for positives. Have you seen this IP address before submitting different data than what you’re seeing now? And then trace it down. Maybe it’s a public library, but maybe it’s not. So it really, I think it comes down to letting your fraud professionals be fraud professionals, because I think a lot of them probably are either prior law enforcement or really excited by, you know, the thought of law enforcement type work.

42:00ESure.

42:01DSo letting them, letting them kind of go forward with that will help you collect a lot more information, not just to prevent fraud, but also just to learn more about how your platform, how your product is being used, which you can use down the road for, for not just loss mitigation, but also I have to mention that the bad guys are also very good, and there are instances when it’s close to impossible to catch everything that they do.

42:39FAnd this is actually a good practice to learn for the future. Yeah, I think that’s a good point. To be able to analyze the data, let’s say, from chargebacks in order to create a stronger fraud protection for the future appearing fraud activities. Also, when looking, let’s say, at ID verification or trying to determine the location of it and how genuine the ID is, It is also essential to look at the entire picture together, analyzing the entire situation because every single transaction is a unique transaction for itself. And as Laura mentioned, email could be off or any other data point could be alerting to you that something is wrong even though the ID looks perfect.

42:39FBut fraudsters, at times, they are funny. There are instances when you’ve got a perfectly looking ID, like let’s say from some country in Europe. And then because you can know anything, everything in the world, you would Google to see how the original ID from that particular country looks like. And then you may get surprised that your Google search will bring as an example, exactly the same face. And on that particular ID, you’re being reviewed. So there are different instances. And it is good to look from different angles sometimes to be able to be successful. I have to add machine learning to be extremely helpful in analyzing data.

42:39FData points in real time, enormous amounts of different data, which is amazing. And it’s helping industries to be faster, more efficient, instead of relying just on manpower. And to keep up with the fraudsters’ creativity as well.

45:06CAll right, so I think we’re going to move to question and answer right now. Does anybody in our audience have a question? Yes, you, sir.

45:19EYeah, I’ll take this out.

45:21HMy name is Alan. I work for Samsung. In the past, I’ve worked for Microsoft extensively. My question is about internal fraud. Great background there. When I was at Microsoft, I helped build the micropayment system for the Xbox 360 launch about a decade plus ago, and we had to have a PCI-compliant environment. And a lot of the defenses that the auditors were looking for to see that we had them in place were for internal fraud, because people like me and my peers that were building the system had access to the software so that we could do things. So let’s take a hypothetical. Amazon has, I don’t know, 40% of online e-commerce?

46:13G25%?

46:13HYou know, some large, large amount.

46:15G80%.

46:17HWhat kinds of -- my question is, what kinds of internal fraud is happening right now at Amazon? There’s got to be some. It’s too large of an organization for it not to be happening. What kinds of internal fraud are happening at Amazon, and what kind of defenses would you as professionals advising What kind of training would Amazon need to look for that type of fraud?

46:49DThat’s a great question. And in fact, insider threat is a big issue in the government and the private sector. A lot of that comes down to training and training people to look out for insider threats. I know that in the Coast Guard every year we take a training on the different warning signs to look for if someone maybe you’re a risk. That’s more for the release of classified information than for stealing money, but it’s a similar type thing. The red flags are going to be similar a lot of times. And then also there are different companies. Detex Systems is one. I think FireEye has a product that’s similar to this where it’s endpoint monitoring.

46:49DSo if you’re a company, you install the software on all of your company laptops and all your company mobile devices and everything. And it’s essentially tracking all the metadata for everything that’s happening on that endpoint. And so you’re tracking the websites that people are visiting, you’re tracking the movement of data, so you can start noticing if someone from your company starts downloading massive amounts of data from the server that they have no business reason to see. And this system uses sophisticated algorithms to throw up red flags for further investigation. So you know which individuals you need to look at and try to get to the bottom of what’s going on.

46:49DAnd other than that, having -- setting permissions on your IT network to make sure that people have the lowest level of privileges that they absolutely need to do their job. Not only is that going to stop fraud and internal theft, But it’s also going to prevent hacking and the spread of malware. Because if someone’s computer has very few permissions to access the network, their computer is not going to be able to infect the rest of the network quite as well as if they had administrator privileges. And that goes to even your IT administrators. Have -- give them the administrative access that they need, but have them only log into the administrator account when they need to for a particular task.

46:49Dspecific tasks. Generally speaking, they should be using much less permissive accounts.

48:57ESo at Bank of America, we had a huge internal fraud issue, but it was mostly around insurance claims where you would claim worker injury. Because for all the other stuff, as you talked about, the computers are completely locked out. Nothing, like, USB drive doesn’t work, hard -- like, you cannot write anything on the hard drive, you cannot install any program. You cannot visit any email site, any site where you can upload or download a document. So you cannot even visit Facebook. Like, if you can imagine a site, it’s pretty much not -- you cannot visit it from Bank of America. The only sites you can visit are Wall Street Journal, Bloomberg, like 5 or 6 financial sites, and then everything else is blocked out.

48:57EAnd then you cannot send even every email. So when you send, they say, hey, this email is tracked and record it, do you want to send it? And then every time it doesn’t stop. You can’t say no. They actually do it every time so that you are reminded that, hey, if I do something in this, they are tracking that. And they have very sophisticated sort of pattern matching software running behind any email to find that if you are doing something like that, they can track that. So the only thing left around that is, can you write something in the software which can sort of siphon money out?

48:57EOr something like that. That’s the only thing left outside that which can do that. And for that, they actually have different lines of reporting. So I built sort of -- so let’s say a risk organization is completely different reporting, QA was a different reporting line, and development was a completely different reporting line, and validation was done from a different reporting line completely. So there is, in theory, again, you can go to a extent to say that 5 teams are colluding together, but it’s really hard to argue when there’s a constant leadership change. So that’s all we did to manage the internal fraud on the technology front.

48:57EOn the worker comp, there is still a lot of internal fraud where people say, hey, there was water on the floor and I slipped and fell. But that is very hard to sort of come up with a policy against. But trainings and all of those things have, have been shown to be effective on that.

51:04FThere may be a big variety of different exposures for internal fraud and different scenarios, but I also think it’s a very interesting aspect to think of in terms of thinking of employee fraud is employee happiness because if people are happy at their workplace and they’re happy about what they do and how much they’re being paid, they enjoy their life, there won’t be or maybe the risk of employee fraud and theft could be minimized. That being said, I think Educational programs, not only on compliance and rules, but also on culture are essential for any organization like Amazon or any other industry.

52:09AAlso, to speak to employee fraud, there definitely needs to be internal controls and permissions being set. And if they’re not for some reason, let’s say your technology is not there, audit reports Definitely at AAA, we have audit reports that the fraud team reviews just to ensure that, you know, there’s no funny business. And also just thinking about the culture, if someone knows that someone’s watching, they’re a little bit less prone to fraud. So removing the opportunity, I think, is the first step. And of course, not to be like Big Brother, but, you know, if the CEO or the head of the organization sends the message that fraud is not -- You know, that fraud isn’t tolerated. You know, it kind of has to start from the top down.

52:58CHey, yeah, this gentleman.

53:00GSure. I, my name is Shaker. I have rather a difficult question. I hope cryptocurrencies now that you know companies like Amazon and Alibaba announced that they will be accepting crypto cards. And imagine a company is gonna come out there and let everybody to use cryptocurrency pretty much visually on any site, which is something I’m trying to do.

53:25EBut I have a worry. I’ll tell you why I have the worry.

53:29GMoney laundering. And that’s specifically, you know, a question to you because it is anonymous. You know, once a million dollar gets in, you can’t track where it goes.

53:41EI mean, you can track But it’s crazy difficult.

53:46GAnd it’s on public servers. There’s no government regulation whatsoever. And I’m scared because I don’t want to be associated with money laundering in any way. But people will do. I mean, nowadays, if you are buying a cryptocurrency with your credit card, there’s a $50 limit. They don’t want you to buy too much. One, fraud. Second, money laundering. But still, you know, it’s gonna go there and there’s no $10,000 limit. There’s actually no limit over there.

54:14DThat’s right. And I would say that all of that is true yet. There’s no regulation yet. I think that the UK has been much better about this than the US has, as well as some other countries. And we actually, some of us talked about this before this began. So I think it’s going to take time for US regulators to catch up. They’re still exploring it, they’re still trying to understand cryptocurrency. And, you know, I think there are going to be a lot of companies that are sort of forging ahead and making decisions and trying to kickstart the business and set the tone. And I think some businesses are going to do it right, some businesses are going to make horrible mistakes, and the regulators are going to decide, uh, this is not the way we’re going to allow it.

54:14DAnd they’re going to crack down, and potentially people could go to jail. Liberty Reserve is an example of a cyber currency from a couple years ago where it was set up in Costa Rica. They were taking money from all over the world, and they picked Costa Rica specifically because there were no regulations. And very quickly, this platform became the number one platform for human trafficking, drug smuggling, weapons smuggling, terrorist financing, all this stuff. DEA, and I think Secret Service, and a couple other agencies ended up arresting the gentleman in charge a couple years ago, and I think he got sentenced to 20 years in federal prison.

54:14DSo I don’t mean to terrify you. I really think what’s going to happen is There’s going to be the legitimate cryptocurrencies and the illegitimate ones. I think that cryptocurrency inherently does not have to be anonymous. I don’t understand the technology quite well enough, but I mean, if you wanted to implement a know-your-customer regulation, you could. I mean, if you set up the platform, then you only issue cryptocurrency, just like a bank. You only issue the currency to people who have properly identified themselves, and then it’s a public -- it’s a --

56:18GIt’s a public good.

56:19Ddistributed public ledger, you can track all the transactions. You could even crowdsource the transaction monitoring. So that’s actually a cost that you wouldn’t have to incur as a cryptocurrency administrator or facilitator. And so I really think the anonymity, for it to be legal and legitimate in the United States, it’s gonna -- they’re gonna have to figure out ways to make it Not anonymous and more identifiable.

56:46CAnd just to kind of hop in really quick, I mean, we think that cryptocurrencies are anonymous. There are the group of privacy currencies out there, but it’s really quasi-anonymous because, you know, if someone has an address and then they have your IP address too, so your wallet address and your IP address, you know, they know that your IP address is the Wi-Fi hotspot at your At your home, right? Or the laptop that can then be connected to your -- the MAC address on your laptop that pings to your router. So it’s quasi-anonymous in that regard, but there are things that we can do, people can do to anonymize it.

57:29GMoney’s origination can be from somewhere, but people transfer in between, like you can transfer the money like a million times speaking to several different people, and it’s going to be terribly difficult to track down.

57:40AYou can see the whole chain of events of the transfer.

57:43GI know, but it’s just difficult.

57:45ESo we are thinking about doing ICOs for our platform so that loans can use ICOs completely internally rather than doing fiat. So the way we have determined is we will sell ICOs to everybody, but if you want to buy US loans, you have to be a US resident and you have to go to an incumbent sort of I didn’t do verification at that point.

58:04GThat’s correct. But cryptocurrency is not bound to this country. No.

58:09ESo it can originate from somewhere else and actually come here. So from a US regulatory perspective, and I think, say, me and Kabir, man, actually, I think I forgot whether it was IRS or someone talked about it. So the regulators in US have a view that most of the cryptocurrencies like Ethereum or Bitcoin are 80% transacted outside US. So they cannot control it. So it won’t be part of the legal framework in near future.

58:33GSo they’re going to spend that money in US.

58:35ESo if they want to spend that money and there is an issue, you will be stuck because regulators have a very clear view that since 80% of the currency is transacted outside US and you cannot control it, what you’re saying, it will never have that framework. So that’s -- I’m talking from a government. So I forgot whether it was IRS, US Treasury, or one of those sort of -- one of the agencies which talked about it, right? The problem with cryptocurrency, us accepting that as a part of system, is we can’t control the valuation. We don’t know how the money is moving because 80% is transacted outside. So for you to do that, I would suggest to do an ICO which you can control rather than doing a pure cryptocurrency. Then you can control the ICO part.

59:17BYeah.

59:21CI mean, ICOs are a heavily debated topic right now, and the legality, once again, whether or not these are securities or are they not securities.

59:32ESo I shouldn’t have said ICO because I’ve been told enough times not to do that. It’s a token sale. It’s not a security, it’s a token sale. Sorry about that.

59:42CCrowd sale.

59:43ECrowd sale of tokens.

59:46CYeah.

59:48AThey’re a currency.

59:49CThey’re acting as currency or security?

59:51EThey’re acting as a currency, not a security.

59:54BSo one more question.

59:56COh yeah, you briefly touched on currencies and transactions coming from outside the United States, and I was curious what challenges are unique to having international customers And trying to detect fraud from customers that are based outside of the US and may not fit into the algorithms that you’ve developed for dealing with US customers? And what steps can be taken to mitigate risk dealing with customers outside the US?

60:29ESo I’ll give you a very simple answer. That’s a very weird answer, but if the dollar amount is not big enough, controlling them is really hard, so just deny that transaction. That has been a lot of our sort of point of view. It’s not that we don’t want them to be transacting, it’s like if you’re only getting 10% of volume from international transactions, the work would be 90% of that. So do you want to do a cost, sort of cost-return analysis? It’s just hard to justify in a lot of cases unless something your 90% of the business is coming internationally, or 80% or something like that. That’s a very different view, but yeah.

61:09AI think that’s where technology really steps in. In retail e-commerce, we used Count at a couple of companies that I worked for, and Count was really able to help us weed out the bad transactions. They were automatically denied typically in the tool because Count has access to all of Chase payment tips. Text transactions. So there are billions of transactions, you know, going through the platform every day. So I think technology really helps you because you may not be able to detect whether the transaction is fraudulent when it’s coming from out of the US because you just don’t know.

61:44DWell, it’s also --

61:46Ethe difference is whether it’s coming from Little Sibirs or from London.

61:50AYeah, sometimes you -- yeah, sometimes you You just have to not accept transactions coming from certain countries. And again, you need technology to be able to detect where the transaction is actually coming from. It may say Oklahoma, but the customer could potentially be in Nigeria, for example, and you may not want to have that risk.

62:10FI’d like to add an additional idea of reviewing international transactions, and there is a combination of technology and manual review. That is because there are certain aspects of human behavior that machines cannot really detect or cannot detect perfectly. That is why in some situations it is essential to combine the two. Machine learning, but also manual review when a human eye could look at a transaction. And that is simply because there’s nothing wrong with the international transactions. They may be absolutely legitimate, especially if you looked at different data points, not only the originating location or billing address or delivery address, which could be overseas, but also other angles of the transactions, other data points, including, for example, type of product. A vacuum machine, I wouldn’t say the bad guys would be interested in those low, so-called low-risk types of products. And that could boost the, for example, we speak about ecommerce boost the businesses and protect them from losing some income that could come from declining transactions by default.

63:51DYeah, and I would encourage companies as much as possible to leverage technology to allow them to process these transactions. Because a term that’s being thrown around a lot in the ACHMS community is called de-risking. And this is the trend for financial services businesses to not process transactions of certain categories simply because they’re too risky. And this is seen as a bad thing because we mentioned the underbanking in the United States. Well, throughout the world, it’s really a big issue with people in many, many countries that just don’t have access to financial services. And so it It’s very important, and the AML community doesn’t really have a good answer to it. Kind of the answer is, well, you know, let’s talk about it, let’s figure out the best way to allow these transactions to go forward. And so I think technology really, and finding other data points to verify as much as possible, is what you want to do.

64:48FI wanted to thank you all.

64:53BIt’s fantastic and so informative. And it’s great to have perspectives from all different views. So thank you.

65:00EThank you.

That was the whole conversation.

More from Crypto with Kamal.

Every episode, and who Kamal is →