Top Banner
A PRACTICAL GUIDE to post-EMV card-not-present fraud Noam Inbar, VP Business Development, Forter
36
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: A Practical Guide to Post-EMV Card Not Present Fraud

A PRACTICAL GUIDE to post-EMV card-not-present fraud

Noam Inbar, VP Business Development, Forter

Page 2: A Practical Guide to Post-EMV Card Not Present Fraud

$3 BILLION 2014 U.S. CNP Credit Card Fraud Losses (Aite Group)

Page 3: A Practical Guide to Post-EMV Card Not Present Fraud

EMV will make your fraud disappear

HRS.

0 9 MIN.

3 0 DAYS

9 9

Page 4: A Practical Guide to Post-EMV Card Not Present Fraud

REALLY?

Page 5: A Practical Guide to Post-EMV Card Not Present Fraud

NOT REALLY.

1 Being a fraudster is profession. EMV won’t make them disappear 2

Fraudsters look for the weakest link; EMV doesn’t protect Card Not Present Transactions

4 E-commerce will continue to grow 3

EMV migration will cause organizations to be slower and less efficient than before

5 Crime as a service: even fraudsters with low technical abilities can commit fraud online, lower barriers to entry

Page 6: A Practical Guide to Post-EMV Card Not Present Fraud

FRAUD TO SPIKE 40-50% In the 2 years following EMV migration

Research

Page 7: A Practical Guide to Post-EMV Card Not Present Fraud

WELCOME TO THE POST EMV FRAUD TSUNAMI

Page 8: A Practical Guide to Post-EMV Card Not Present Fraud

DOMINANT MARKET APPROACH to fraud prevention

Rule Engine Risk Score Fraud Policies

Manual Reviews

APPROVE

DECLINE

Page 9: A Practical Guide to Post-EMV Card Not Present Fraud

DOMINANT MARKET APPROACH to fraud prevention

Rule Engine Risk Score Fraud Policies

Manual Reviews

APPROVE

DECLINE

FRAUD PREVENTION

1.0

Page 10: A Practical Guide to Post-EMV Card Not Present Fraud

2.0 FRAUDSTERS Require 2.0 Fraud Protection

Page 11: A Practical Guide to Post-EMV Card Not Present Fraud

MACHINE LEARNING – BIG DATA – CLOUD REALTIME ALGORITHIMS – SCORES – RULE ENGINES – FINGERPRINTING – MACHINE LEARNING GEOLOCATION – CLOUD – REALTIME – BLACKLISTS – BEHAVIORAL – ALGORITHIMS – MACHINE LEARNING – CLOUD – SCORES –FINGERPRINTING – BLACKLISTS – BIG DATA – SCORES – REALTIME ALGORITHIMS – BLACKL

Page 12: A Practical Guide to Post-EMV Card Not Present Fraud

A PRACTICAL GUIDE

to post-EMV card-not-present fraud

Page 13: A Practical Guide to Post-EMV Card Not Present Fraud

1 KYF: KNOW YOUR FRAUDSTER

Page 14: A Practical Guide to Post-EMV Card Not Present Fraud

FRAUD IS CHANGING So should your fraud prevention

3 Fraudsters are quick and agile, methods that used to be the holy grail of fraud prevention can no longer get the job done

Traditional Practices are no longer enough

1 Dark-net Marketplaces enable a sophisticated fraud ecosystem

Crime as a Service

5 Wherever there’s internet, there’s the opportunity for CNP fraud

Fraud is Global

4 After Silk Road’s demise, fraudsters have become vigilant about operation security

Fraudsters Are Paranoid

2 2014’s massive data breaches flooded the market with high quality cards

Abundance of Stolen Data

6 Hardware is cheaper than ever, so fraudsters can burn through it & never look back

Hardware is Commoditized

Page 15: A Practical Guide to Post-EMV Card Not Present Fraud

2 AUTOMATE

Page 16: A Practical Guide to Post-EMV Card Not Present Fraud

81% of merchants

review orders manually

52% of fraud budget is used for

manual reviews

MANUAL REVIEWS

20+ MIN Per a manual review, for over

20% of merchants

Source: Cybersource Online Fraud Report

Page 17: A Practical Guide to Post-EMV Card Not Present Fraud

Nuances and patterns extracted from a user’s online behavior enables comparing and benchmarking against expected behaviors,

adding a whole new dimension of knowledge.

BEHAVIORAL ANALYSIS Automating manual reviews

Predicting people is not like predicting the weather

Page 18: A Practical Guide to Post-EMV Card Not Present Fraud

3 DON’T PANIC

Page 19: A Practical Guide to Post-EMV Card Not Present Fraud

FALSE POSITIVES

| Definition | False Positives

A "false positive,"... arises  when fraud detection software

blocks your card because the card has been identified as

the vehicle of potentially fraudulent activity when it isn’t  

~ Tech Republic

Page 20: A Practical Guide to Post-EMV Card Not Present Fraud

FALSE POSITIVES

$40 BILLION

lost every year due to unnecessary red flags and transaction blocks

Source: Trust Insight, Measuring Consumer Attitude on CNP Credit Card Declines Report

Page 21: A Practical Guide to Post-EMV Card Not Present Fraud

FALSE POSITIVES

Source: Cybersource Online Fraud Management Benchmark Study (N. American edition, published 2015), Ethoca research 2015

OVER 70% of merchants believe that

UP TO 10% of rejected orders are actually valid

BUT THE ACTUAL RATE IS ESTIMATED AT ABOVE 40%!

Page 22: A Practical Guide to Post-EMV Card Not Present Fraud

FALSE POSITIVES

NEARLY 20%

of consumers who experienced a fraud-related decline had no future spend 6 months after the decline event

 Source: Trust Insight, Measuring Consumer Attitude on CNP Credit Card Declines Report

Page 23: A Practical Guide to Post-EMV Card Not Present Fraud

FALSE POSITIVES - CAUSES

§  Processor rules and red flags §  Tools that require hard coding §  Outdated rules §  Manual reviews: bias

Page 24: A Practical Guide to Post-EMV Card Not Present Fraud

EXAMPLE: AIRLINE

Page 25: A Practical Guide to Post-EMV Card Not Present Fraud

3DSECURE DECLINED

Page 26: A Practical Guide to Post-EMV Card Not Present Fraud

MANUAL REVIEW EMAIL

Page 27: A Practical Guide to Post-EMV Card Not Present Fraud

APPROVED BY PHONE WITH SAME CARD

Page 28: A Practical Guide to Post-EMV Card Not Present Fraud

4 HUMAN-BASED MACHINE LEARNING

Page 29: A Practical Guide to Post-EMV Card Not Present Fraud

MAN VS. THE MACHINE

Page 30: A Practical Guide to Post-EMV Card Not Present Fraud

EXPERT KNOWLEDGE Interdependencies: What do the data points tell us?

Platinum+ Credit Card Type

San Jose, US Billing Neighborhood

Mexico (very low income) Shipping Neighborhood

$200, $90, $80 Past Purchase Amounts

$10,000 Current Purchase Amount

Spanish Browsing Language

Wireless Network IP Type

Page 31: A Practical Guide to Post-EMV Card Not Present Fraud

Platinum+ Credit Card Type

San Jose, US Billing Neighborhood

Mexico (very low income) Shipping Neighborhood

$200, $90, $80 Past Purchase Amounts

$10,000 Current Purchase Amount

Spanish Browsing Language

Wireless Network IP Type

EXPERT KNOWLEDGE Stories Model: Mexican National Holiday Sale

Immigrant shipping to family

Page 32: A Practical Guide to Post-EMV Card Not Present Fraud

5 SMART LINKING

Page 33: A Practical Guide to Post-EMV Card Not Present Fraud

UNCOVER THE FRAUDSTER SOCIAL GRAPH

Verification and authentication of a single transaction and blacklists that are based on IP match and email match provide a very narrow view

Similarities and proximities reveal beyond the transaction

Page 34: A Practical Guide to Post-EMV Card Not Present Fraud
Page 35: A Practical Guide to Post-EMV Card Not Present Fraud

1.  KNOW YOUR FRAUDSTER 2.  AUTOMATE 3.  DON’T PANIC 4.  HUMAN BASED MACHINE LEARNING 5.  SMART LINKING

RECAP: WHAT TO DO

Page 36: A Practical Guide to Post-EMV Card Not Present Fraud

GOOD LUCK! www.forter.com [email protected] @InbarNoam