FinAi News

No products in the cart.

Subscribe
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
Log In
No Result
View All Result
  • Banking
  • Lending
  • Payments
  • Risk & Security
  • Strategy
FinAi News
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
FinAi News
No Result
View All Result

Listen: Automation, fraud farms aid cybercriminals

Scams, card-not-present fraud in the US will ‘get worse before it gets better’

Alijah PoindexterbyAlijah Poindexter
April 26, 2022
in Risk & Security
Reading Time: 15 mins read
0
Share on Facebook

Skyrocketing scams and card-not-present (CNP) fraud losses can be blamed on bad actors leveraging automation, experts say.

Consumer scams reported by bank executives have risen by double-digit percentages since the start of the pandemic, while CNP fraud losses look poised to reach $9.2 billion in 2023, a 15% year-over-year increase, according to research firm Aite-Novarica.

Photo by CanStock

While the scale of these attacks is unprecedented, automation plays a surprising role, David Mattei, strategic advisor of fraud and anti-money-laundering at the company, tells Bank Automation News in this episode of “The Buzz” podcast.

“Fraudsters are really good at automation, and what that allows them to do is commit fraud at scale,” Mattei tells BAN. “Bots are one of the significant ways that it’s happening today. The other way is via a combination of automation and human fraud farms.”

Fraud farms ensure humans step in for bots to complete manual inquiries that cybersecurity measures have made impossible to automate, like CAPTCHA requests and voice commands. This mix of automation and human input mirrors anti-fraud systems at the same financial institutions that fraudsters target, where process workflows and simple tasks are automated to ease workloads for employees.

Regulatory developments in Europe have “squeezed the balloon” of financial services fraud, Mattei says, forcing cybercriminals away from tougher targets but failing to reduce the problem quantitatively. U.S. banks should adopt machine learning and artificial intelligence technologies to increase stringency, he says.

“I am expecting things to get worse before they get better here in the United States,” Mattei says.

Help shape our agenda for the Bank Automation Summit by applying to join the speaker roster here. Potential speakers will be contacted and confirmed directly by the editorial team, and only qualified submissions will receive a response. 

Learn more about Bank Automation Summit Fall 2022. 

Subscribe to The Buzz Podcast on  iTunes, Spotify, Google podcast, or download the episode.

The following is a transcript generated by AI technology that has been lightly edited but still contains errors.

Alijah Poindexter 00:06
Welcome to the Buzz, a Bank Automation News podcast. I’m Associate Editor Alijah Poindexter. Recently I spoke with David Mattei, strategic advisor and research firm Aite-Novarica. We discussed how exactly fraudsters are using automations to scale skyrocketing fraud attacks, along with how banks can best leverage automation to protect themselves.

David Mattei 00:24
I’m expecting things to get worse, before they get better here in the United States. Part of the reason there is because last year in the European Union, they introduced something called strong consumer authentication, or SCA. And it’s just a program that’s put in place in order to make ecommerce transactions more secure. And so as the implementation of SCA over the European Union improves and expands, it’s going to be harder for fraudsters to commit fraud over there. But something fraud, sometimes it’s like just squeezing a balloon, you don’t actually reduce your losses, you just force them someplace else. And that’s where I see the US becoming more of a target, because e commerce fraud is easier to perform here. And so in the mid 2000, intense when countries were deploying the EMV chip cards that we all use now in store for transactions. As one country deployed chip cards, what we saw was that fraud migrated to other non chip countries, and the US being one of the last industrial countries to actually deploy chip cards. And so the same thing I see happening here, there are other countries across the world, not just in the EU, that are getting tougher on E commerce fraud losses. So I am expecting and waiting that at some point in time, I believe the problem is going to get big enough here, that somebody in a position of authority, whether it be the card brands or government or some other kind of body, is going to come out with some sort of a note announcement, it’s either going to be a carrot to incent or stick to penalize. So the characteristic approach and earning off with five CNP fraud, the tools are out there. But we have we had reluctancy here in the US in order to go off and deploy some of those tools.

Alijah Poindexter 02:15
So you know, we’re expecting this to get worse before it gets better. You know, I think pretty much every analyst and expert in this sort of field would probably you know, they’d unfortunately have to agree with that for a bank or an FBI. What does an environment where a bank, you know, and of course, I’ll preface this by saying that you want to do business and operate in bank in a financial environment that has no fraud, of course, but we just don’t live in that world, as as everybody well knows, again, with these skyrocketing losses and skyrocketing incidences of fraud, so when a bank says, Okay, we as an institution or an organization, we have a firm grasp on the sort of fraud and scam situation, both internally and for our clients. What does that look like? If that is even something that’s achievable? You know, is there are there banks out there, that you’ve seen that, you know, can say, with some sort of confidence that we at this current moment in time, we have a pretty good grasp on the fraud situation as it applies to us and our customers?

David Mattei 03:16
You know, there’s different levels of sophistication at banks, just because we got over 10,000 of them here in the United States. But I would say that I can stop all fraud all the time. But I’m gonna shut down your business as well. So I don’t think many banks are interested in that part of it. But then, if you want to actually drive your losses to zero, and do it effectively, the cost to go off and do that probably prohibitive for most financial institutions here in this country. And so it comes back down to the annual operating budget that every FY puts together. And in that operating budget, there is a line item for fraud, write offs, fraud loss, write offs. And when those losses that you start experiencing, exceed whatever you had budgeted. That’s when serious conversations start within the bank or the credit union. So the question is, you know, why are those losses increasing? Is it because I got the wrong people who are managing fraud, do have outdated tools that are no longer effective? Is there a rising sea of fraud across the industry? And everybody’s being hit by this? Or do I have unrealistic expectations of what my fraud losses ought to look like? And I just have underestimated them. So whatever the reason may be, you know, those conversations start getting had. And then what happens is that the people who are responsible for trying to mitigate those fraud losses, all of a sudden, their business cases for fraud investments get dusted off, and the ROI on those business cases start looking a lot better than what they had in the past. And so, banks definitely want to be able to control it. They’re willing to take a certain amount, but it’s all kind of the cost benefit analysis that they’re doing in terms of, you know, how much do I want to spend? And what does that incremental dollar spend going to do in terms of reducing my fraud losses I have to write off.

Alijah Poindexter 05:13
You know, and as a note, on top of that, you know, speaking to other experts, and hearing other experts, you know, in the space speak about this, it’s not just an industry problem as an issue, it doesn’t all relate to just what fraudsters are doing, as you say, you know, it’s perfectly within the power of a bank or financial institution to stop the fraud. But the question becomes sort of, you know, walking on this tightrope between a lack of stringency, which, of course, will just invite fraud, and too much stringency, which kind of overextended the use case and becomes, you know, it inhibits the sort of open and embedded sense of banking, that a lot of these digital banks and, and banks with really advanced technological sort of frameworks are trying to trying to promote, because I, you know, I don’t need to tell you this is that this tightrope is so thin and trying to strike that balance is so difficult, you know, because, again, where do you decide between this is too much stringency, we need to dial back a little bit, or we dial back a little bit too much, and then we have a really big problem on our hands. So it’s really difficult.

David Mattei 06:16
Yeah, it’s just like, you know, the group that’s being chased by the bear, you don’t need to be the fastest, you just can’t be the slowest. And so you just want to make sure that you have at least enough in place, that there’s enough vinegar in the milk in order to dissuade that froster from attacking you and going find some easier targets.

Alijah Poindexter 06:36
So, you know, how are fraudsters? How are they scaling these attacks? You know, or is there an automation angle to this? How are they accomplishing so much, you know, so, so much efficiency in the fraud attacks with the scale and the speed and the size of they’ve been sort of doing it with over the past couple of years?

David Mattei 06:52
Yeah, fraudsters are really good at automation and technology. And what that allows them to do is commit fraud at scale. Bots are one of the significant ways that’s happening today. So bots is just a automated program, where you can do large scale fraud. The other way that they are attacking is via a combination of both automation and human fraud farms. Human fraud farms are people that are hired by the fraudsters to step in, in an automated login process and respond when there’s a need for some sort of manual input. You know, it could be, you know, I have to click on the on not a bot on the login page. It could be I got to solve a CAPTCHA puzzle, or other kinds of similar things that just cannot be automated. And so you know, whether, whether if they’re not committing fraud complete, and through an automated way, and they need humans in order to be able to help through pieces of it, the other human fraud forums are another way to go off and do that. So they’re really good at both attacking at scale. The other thing that we’re seeing out there is scams, as I mentioned before, and you know, it could be through an email or a text message, sometimes a phone call, but especially we look at email and text messaging, you can send out millions of these things. And you don’t need a high percentage of people to fall for them. You know, a very small percentage of people falling for a scam, email are a scam text message that you click on the link, and you’re providing your credentials or what the case may be. That’s all the fraudster needs, because that small percentage still adds up to a lot of potential in terms of stolen funds.

Alijah Poindexter 08:34
You know, maybe backtracking a little bit to the bot part, because I find that extremely interesting. And it’s ironic, because fraud, you know, the majority of this fraud is being carried through digital channels. But we only think about the human aspect, you know, it’s always the hunched over figure with the computer and the hoodie on and you can’t see his eyes, but we forget about the fact that it isn’t always a human enterprise. And so maybe you could, you know, if you can, you can give an example of what like a bot in a fraud situation, what does that look like?

David Mattei 09:02
Yeah, easily take a look at some of the very popular data breaches over the past five years, where instead of stealing payment credentials, they’ve been more like like credit card numbers, debit card numbers, things like that, instead of stealing that, they have been stealing username and passwords that are on file at these various companies where they’ve been able to breach so we can do with it is you can create a bot that I got an Excel document, and it’s got username and one column, password and other column, I can create a bot to try to log into some popular website and see if that username password pair is still valid or not. And you could do it against you know, pick a website, any kind of E commerce company or maybe even a bank but you know, if you’re doing that scaling if you get a good hit, and you know this username password pair is still valid. Well then the other problem that we have here in this country is that consumers, we don’t like to have different passwords for different websites. So we tend to reuse that same password. So if I know this username password works on website a, it may work at Bank B, or credit union C. And so that way, the bot is doing all the hard work of trying to do the login and see if it gets in or it gets rejected. And every time there’s a good hit, well, then it just retros to the fact that this is a good pair. And they can then use that information to go in and commit some manual attacks. For example, use those credentials to log into your online banking account and borrowing funds to yourself.

Alijah Poindexter 10:42
Wow, yeah. Wow. Okay. Um, so on the bank side of things, and that’s super interesting. You know, on the bank side of things, of course, the easiest solution, I think would be, you know, from what I’ve heard for a bank to sort of mitigate these threats is simply to outsource to a some type of FinTech or vendor or, or some type of entity that can kind of do the fraud detection and mitigation for you. And whether that’s white labeled or not, that’s another conversation. But, you know, is there anything? First off? I think at first, you know, a good first part of this question is, you know, is there even a, is there a use case for banks in terms of like, you know, would it make a difference if a bank was to kind of tamp down into, you know, sort of providing their own internal fraud detection system and fraud mitigation system? Or is that something that it’s a little bit more efficient and economical for a bank to go outside? And then the second part of that question is, you know, how specifically can banks use automation, you know, to reduce risk, you know, to manage risk and manage these fraud threats, if that makes sense.

David Mattei 11:46
Yeah, the days of banks being able to build their own solutions in house in order to be able to address some of these problems are long gone, mainly because one, financial institutions just don’t have the it bandwidth any longer in order to go off and do that. And to, if they’re building solutions in house, then you have the issue of maintaining them and keeping them current over time, which is another huge cost issue. So commercial solutions are really the way to go. And you can really take commercial solutions and break them into two components, one we call passive authentication tools, and the other one being active authentication tools. And passive tools are tools that run in the background. And they kind of monitor activity, no user input is required at all for these, which is the beauty of them, because you can look for fraud signals, without the user having to take any kind of action, things like device fingerprinting, behavioral biometrics, or identity verification services. And you know, trying to verify whether this is a valid email address or phone number or things along those lines, you know, even the rise in artificial intelligence and machine learning, where you can actually do that as well. So these are all great tools that just run in the background, look for fraud signals. And then if they detect something, they raised a red flag, and then you can go off and take some additional action as necessary. And when that red flag does go up, then you can switch to what we call active authentication tools. And this is where you may need to interact with the consumer and ask the consumer to do something, you could ask them to take a selfie, or maybe scan their driver’s license and selfie and send them both in for you to go off and check. You may be sending them some type of one time passcode. And not the not the simple ones that you send through SMS text message through public channels, but some type of private OTP, which is much, much more secure than what’s being done through OTP sent through the carriers right now. But those are tools that you can use in order to require the user to take some kind of action, at least you know that you’re interacting with the good person at that particular point in time. But the thing about it is that there is no silver bullet when it comes to this, you really need to have a multi layered approach to mitigating fraud. Just because, you know, there’s no one tool that’s going to take care of it all for you all the time.

Alijah Poindexter 14:14
You say there’s no silver bullet approach? Were there any approaches or technologies, you know, of that maybe you’re considered a little bit unorthodox, or maybe a little bit underrepresented in the standard sort of anti fraud or risk management build, if that makes any sense.

David Mattei 14:29
You know, there’s some newer technologies that are coming out that have not really gotten a lot of widespread adoption within the banking industry here in the US. Some of the things like password list, authentication methods out there, you know, there are there are technologies in order to really kind of eliminate the whole username password fiasco that we have going on in this country, but I mean, the financial services industry here in the US has been very slow to go off and adopt He’s kind of solutions, because they’re just a little bit afraid that it does take some action on the part of the user. And, you know, you know, everyone’s standing around the pool, and they’re all afraid to be the first one to jump into it. And so some of those technologies are out there to provide a more secure experience, it does require the user doing something different. And, you know, banks and credit unions in general are a little bit leery of, you know, is that going to cause consternation on the part of my user? You know, are they going to look at that negatively, and maybe take their business someplace else? You know, are they going to think of it’s too intrusive, and to convince him to go off and do and I think also, I think banks and credit unions here, the US just don’t give the US consumer enough benefit of the doubt of being smarter than what they think they are. I think people have the ability to go off and adopt this. I mean, look at it, you know, we all figured out how to use a chip card, eventually. So, you know, I think there’s ways that there’s some technologies out there that are viable, but we just need to get overcome our fears of actually going off and deploying them.

Alijah Poindexter 16:04
You know, closing out the conversation here, obviously, you know, the days of saying, you know, what’s your prediction for 2022, or log on, we’re in the midst of 2022, we’re right in the middle of it. So you know, looking beyond 2220 22 and beyond to, you know, these projected, you know, fraud losses, and, you know, the fact that it probably will get worse before it gets better, where are in your mind the greatest vulnerable vulnerabilities for both banks and their consumers. And then maybe you can give some best practices to fix these or remedy these.

David Mattei 16:37
Yeah, we never know where the next vulnerability is going to sit, you know, something is going to come down the pike, I can guarantee you that much right now, what it is, is really hard to predict. But the biggest vulnerability in general is the fact that fraudsters, they are nimble, they have speed and can pivot quickly. And they’re very sophisticated. counter that to banks and credit unions that tend to be slow to react and adjust. That is the biggest vulnerability that we have is that banks and credit unions need to become as nimble and as fast as with the fraudsters are in or be able to stay ahead of our else you’re always playing catch up. In that case, you’re always on the defensive. So how do you get around that? Well, there’s a couple of ways I think you can do it. One is collaboration. As I mentioned earlier, we have over 10,000 financial institutions here in the US, you know, other countries, you’re talking about maybe a few 100, PacBio, Canada, they only got five. The problem with such an extensive number of FIS in this country, is that a fraudster could get one bank. And if the controls get strict enough, and it’s hard to commit fraud there, you know, I got another 9999, I can go off and hit. And so if the if the banks in this country were to actually come together and share the information that they have, in order to be able to identify some of these bad actors, I think we can do a great job of being able to mitigate the impact. You know, the fraudsters know, this is one of our weaknesses, the fact that we don’t share data that we don’t collaborate. But, you know, they’re, they’re using it to their advantage and to our disadvantage. So that was one way. And the other issue that we see out there is even between merchants, and banks, you know, we talked about e commerce fraud a little bit earlier, merchants have some great information for being able to detect fraud, but the banks don’t see it. And likewise, the banks have some great information for detecting fraud that merchants don’t see. So if those two groups could come together, and figure a way to be able to share data, another great opportunity being able to mitigate this. And then the last thing I would say is what we call orchestration. Orchestration is when you have a single interface into a, for example, a vendor solution, a multipronged vendor solution. And, you know, it’s kind of like the cafeteria plan. I can select a device fingerprinting solution today and all tomorrow, I can add behavioral biometrics if I want to, and then down the road, I can add a third or fourth or fifth tool if I want to, but orchestration that allows banks to achieve some of that nimbleness that we talked about before, in order to be able to be much better at reacting to what a fraudster does and even maybe putting a defenses in place proactively. nrdb always continue to be on their heels.

Alijah Poindexter 19:30
You’ve been listening to the buzz a bank automation news podcast. Thank you for your time and be sure to visit us at Bank automation news.com For more automation news. You can also follow us on Twitter and LinkedIn. And please don’t hesitate to rate this podcast on your podcast platform.

Tags: cybersecurityfraud detectionintelligent automationpodcastPremiumThe Buzz
Previous Post

TD seeks to tap growing Florida tech-talent base with 200 hires

Next Post

Inovatec launches improved, AI-based LMS

Related Posts

(Courtesy/Bloomberg)
Risk & Security

Anthropic AI models hacked three organizations during tests

July 31, 2026
Fortinet headquarters
Risk & Security

Fortinet’s billing for AI-driven security operations grows 25% in Q2

July 30, 2026
humans and AI work together to pinpoint risk and suspicious activity
Risk & Security

Retaining the human component as AI combats fraud

July 28, 2026
Next Post
Inovatec launches improved, AI-based LMS

Inovatec launches improved, AI-based LMS

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

The Buzz Podcast

SPONSORED

Build an Antifragile Strategy to Outperform the Market

July 14, 2026

How AI and Product Experts Turn Fuzzy Requirements Into Focused Dev-ready Roadmaps

April 19, 2026

Is Your Technology Supplier There for You?

April 1, 2026

  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

 [wt_cli_manage_consent]

Connect

twitter linkedin podcast podcast podcast
© 2026 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Unlock This Article

Create your free FinAi News account to access this article and stay informed on how AI is transforming financial services including banking, lending, payments, and risk.

Yes, I'd like to receive FinAi News updates, breaking news, and exclusive AI insights for financial services leaders.

Continue Reading with FinAi News Premium - Less than $2/Day

Upgrade to FinAi News Premium for unlimited access to news, insights, trends, and intelligence on how AI is transforming financial services including banking, lending, payments, and risk.
Upgrade to FinAi News Premium Subscription
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account