Zencastr
00:00:00
00:00:01
Speed1x
Format
Share
Embed
Report

Stories From The Trenches: A Fraud fighter's Perspective - A conversation with Seth Ruden, Former Fraud Strategy Leader At First Tech Federal Credit Union

Scam Rangers
Scam Rangers

564 plays · Jan 26, 2023

Transcript

Speaker: That's just the tip of the iceberg, as you would say, right? And what that doesn't suggest is, well, what if you are a victim of a scam and you've got all that shame and embarrassment and all of that reminder of every time you log in, every time you have to call the context centers, this person's going to judge you based on its event that happened. All of these things that you've got shame about, you're not going to want to stick around. And that retention issue becomes a problem in its own right.

Speaker: What do fraud fighters need to take into consideration when deciding how to, and even if, to tackle online scams? Scam Rangers, a podcast about the human side of fraud and the people who are on a mission to protect us. I am your host, Ayelet Bigger Levine, and I'm passionate about driving awareness and solving this problem.

Speaker: Welcome to Episode 6 of Scam Rangers. Today's Scam Ranger was until very recently a leader of Fraud Protection Strategy at a credit union and will share insights from the trenches. Seth Rudin is a certified fraud examiner and a certified anti -money laundering specialist and has 20 years of experience in fraud and compliance

Speaker: supporting strategy and consulting for global organizations such as HSBC, ACI Worldwide, and Pfizer, to name a few. Most recently, he was a leader of fraud strategy at First Tech Federal Credit Union, navigating the institution through an account takeover fraud crisis in the pandemic era, where he reduced the credit union's fraud losses significantly year over year. He presently leads Biocatch's global advisory program.

Speaker: Hi, Seth. Welcome to the podcast. It's great to have you on. Thanks for having me. I'm excited to participate and hopefully get a really great message out. I really want to hear your perspective about this whole topic. Before we start, maybe tell me a little bit about yourself. What is a day in the life of a fraud manager at a credit union and what is a day in your life today?

Speaker: Well, a day in the life of a credit union fraud leader, I think what's important to recognize is that while banks and credit unions have specific distinctions, the nonprofit versus for -profit model, credit unions tend to be a little bit more customer -centric. In fact, we don't call them customers, we call them members. And so that changes the dynamic just a little bit about how we interact with our

Speaker: member base and what our priorities are relative to how we create, construct our policies and procedures around making a more member -centric cooperative environment. In terms of the day of the life, a lot of the things are really the same. You start your meetings maybe with a vendor talking about some issue that you're trying to solve for. You have a team stand -up meeting where we go over the new

Speaker: threats or we talk about a new emerging element or some specific technology or a newsy item, we share that camaraderie. Maybe that's one of the other distinctions too is that because employees are also considered to be cooperative members as well. And as a result of that, we all have a stronger shared sense of mission and duty to the member base.

Speaker: But then, you know, you move into the next phase, which would be monitoring a specific channel or a specific initiative that's occurring in a channel. Your credit union tends to be that you've got a lot of the fraud management elements are going to roll up straight to one specific leader, wherein a lot of banks, there's a lot more segmentation and more of a matrix in the environment where you could have a online banking fraud leader.

Speaker: and you could have a card fraud leader and you could have account opening and these would all roll up into different executives. And maybe one executive has purview over two or three of those verticals and then another leader has purview over some other verticals.

Speaker: credit unions tend to be not as large as most of the financial institutions that most of the Americans will have visibility and exposure to. And as a result of that, there tends to be not as much of a span of influence in the larger institutions where the credit union leaders will have more oversight to a comprehensive set. And the regular day -to -day administrative oversight for employees and processes.

Speaker: Great. So it sounds like everything goes through you. You're aware of everything cross -channel, cross -initiative and cross -type of fraud. Everything goes through you and you have visibility into everything. So when it comes to online scams, what are some trends you've seen over the past couple of years?

Speaker: Well, the scams have become so complex and so overwhelming. You know, I come from the card space. So when I started my career, I was at a card issue, I should say. And as a result of that, I learned how to manage fraud from a card perspective.

Speaker: And I think that really created much of my ethos and how to apply those lessons and those strategies across the rest of the threat landscape, if you will. And online banking was in this infancy when I started my career. And at this point, it's very mature and we are using

Speaker: online banking to perform so much more of our day -to -day administration and even making most of our payments that are not card specific via online banking where historically we were not.

Speaker: So that threat landscape and that threat surface has increased. And as a result of that, the fraudsters have started to recognize, hey, there's opportunity here. And especially in the last decade, this has become far more thoroughly leveraged by bad actors to be able to acquire illicit funds. And one thing that's really interesting is that fraudsters have certainly recognized that there is a greater opportunity to

Speaker: socially engineer a individual into providing funds to the fraudster rather than a fraudster trying to apply an account takeover scheme with a lower reliability of being funded because when you bring the true user to the table in an authenticated session with the correct device on the correct computer with a cookie sitting on it and all those other elements,

Speaker: that make the session look very legitimate, then it's far more difficult for us to disrupt and identify that this is a high -risk session and put a control in place such as a decline or alert on that transaction and be able to interdict that payment.

Speaker: And you talked about scams that drive financial losses. So when someone is scammed into transferring money, but there are also different kinds of scams like mule scams. What about those? What are some observations that you have in terms of the trends over the past few years when it comes to mule schemes?

Speaker: Oh man, those really got so much more vicious over the last few years. Especially during the pandemic era, that was really heavy. We saw so many instances where bad actors would attempt to acquire a legitimate individual's confidence to start a business or to engage in a romance scam and take some funds that were illicit in orientation.

Speaker: and move them around on behalf of the bad actor. Sometimes those funds would return. Sometimes those funds would be coming from stimulus. Sometimes those funds would be some other kind of illicit activity. And what's really nasty about that is if those funds are the members funds,

Speaker: then that member would be liable and frequently held accountable to those funds. And unfortunately we would not be able to return them. And so they'd be out their own money. If those funds belong to the government initially, now you've got a law enforcement investigation and there's potential legal ramifications and somebody's going to have to have a phone call with Secret Service or FBI.

Speaker: And we're seeing a lot of that right now happening, a lot of news stories about people who illegitimately passed out PPP loan money to cybercriminals and they're being held accountable for being a part of that transfer process.

Speaker: And what's even more frustrating is that sometimes fraudsters will deposit what I like to call unseasoned funds or funds that might return to the place where they were issued from. And those funds could be, when they return, that puts the account in a negative position. And now that individual is having to be responsible for those funds that returned.

Speaker: And if they are unable to source those funds or there's not a corresponding deposit for those, then those could be charged off. And that individual has a nasty mark for the rest of the next seven years or so. So there's a lot of different permutations that these scams can take. And many of them are just very painful for these end users who get wrapped up in scams and essentially are victims.

Speaker: So one thing that strikes me when you share kind of the different types of scams and how they evolve is scams for financial losses, scams that lure people to become mules, and scams that present fake jobs that we talked about in an earlier episode about human trafficking.

Speaker: They all share one common thread, which is the same psychological effect. There's always the manipulation, the luring, those different steps of a scam that then cause that psychological element so the victim becomes

Speaker: a participant in the scam. It's something that I deeply believe we need to stop before the manipulation happens, but I wanted to ask you if you can share some examples of cases that came across your desk, stories of victims that we could share with our listeners to understand what is happening.

Speaker: It's frequent and consistent. You might have an individual who's contacted via email or they get a text message that says their account's been frozen or that they've had a action placed or they're not going to receive their goods or a package is delayed. And those individuals, they take the bait. They make the phone call.

Speaker: they click the button and they're brought to an individual who tells them that they need to start taking specific actions. And that's going to be highly dependent on what the individual's vulnerability is if they give access to a online banking session or if they're

Speaker: device does not allow for that. It's going to be highly dependent on the flow of the event. So let's say that an elderly gentleman has not been able to give access to that individual, but the social engineer is telling them, look, we overpaid you. You might be able to see that there's been changes in your account balance. What I need you to do right now is head on down to a pharmacy or a grocery store and pick up some prepaid debit cards

Speaker: and send those to me so that I can get the account balance correct. And once that happens, then suddenly I'm going to be able to resolve this imbalance and my job won't be terminated and my family won't go hungry. That's so very consistent, but it could be even more malicious where an individual says, look, I'm your son or daughter. I live over in

Speaker: a country that you've had exposure to or you've got a relationship with and I'm in an emergency and I need you to send me a large sum of money to get me out of the hospital and I need you to wire this immediately. Those are consistent episodes as well. And it's gonna take whatever pathway that appears to be the least friction prone for the attacker and get them the best yield possible. It's always an economics game.

Speaker: If I see that the doors are closing, I'll go for the smaller amount and use the more reliable way to get there. But if I smell an opportunity for a significant payday, then I might take the risk as the social engineer and attempt to realize a better outcome for my nefarious deeds.

Speaker: And I want to ask you a question about the other side of the victims or what you do when you detect these types of things and how they react, but I'll park that for later because before that I wanted to ask you as a credit union, what are other reasons financial institutions should take more action when it comes to scams, to detecting, identifying, responding, helping their customers with scams?

Speaker: Well, let's do the right thing for the right reason approach for a second here. And let's talk about how financial institutions have a fiduciary interest in protecting their customers and consumers. And you can see that in many different facets. The first facet being, you know, I'm going to inform you of what scams should look like and what you should be aware of. And I'm going to try to create opportunities to educate you

Speaker: on the right behaviors for specific situations. And most institutions should be doing that, and those might be optics if taking at the highest level, unfortunately. We want to inform people, but I think it's pretty clear that that only works so well, and people will still take the bait.

Speaker: A lot of people also said that they don't remember being educated by financial institutions, although we know that most financial institutions definitely send information to their customers. I think it's also how the information is delivered in a way that people will consume and remember it.

Speaker: It's hard for that information to stay persistent when you're in the heat of the moment and when somebody is telling you that you need to do this thing or bad things will happen. They're going to find ways to coerce you into performing a specific action and usually there's a timeliness component to it.

Speaker: So if you don't do this now, then I'm not going to be able to get out of the country. I need to pay the hospital. We're going to shut off your power. There's always these incentives to do things rapidly. And when you're in the heat of the moment and you have that pressure and you need to make a swift decision, you're not going to really remember all of those tips and tricks we told you about, well, just hang up and call the number on the back of the card.

Speaker: It's always going to be something a little bit more challenging to perform the common sense approach and they're really, really good at coming up with those excuses because they're practicing this all day long and we're trying to accommodate people as a part of our social responsibility and maintenance of the social fabric. And these fraudsters have no interest in doing so.

Speaker: Let's talk a little bit about what are some of the other incentives that I have to do so. And I think that the fiduciary interest is a very important one, but I also believe that there is a lot more business sense in protecting

Speaker: consumers, customers, members, whatever your approach is. And that comes from a handful of different elements. The first one is that I need to make my institution resilient to scams because there is an obvious operational inefficiency if I'm putting a lot of effort and emphasis on resolving these things.

Speaker: what we call servicing internally, that I need to lock an account down. I need to send it to different individuals along a process chain. There's procedures that need to be completed. There's reporting that needs to happen. At the end of it, there's going to be a lot of oversight. If complaints start coming from regulators that I'm having too many scams in contrast to my peers, all of these things start to

Speaker: aggregate. And these become pain points for those institutions who have to manage all of that. So if I can find a mechanism to be able to protect my customers, my members, and I can try to disrupt some of these attacks, then I'm creating an obvious benefit for my institution. And that obvious benefit is that I'm just not spending as much time and all those other process items because I'm able to interdict, I'm able to interrupt a scam in process.

Speaker: And so let's talk about that for just a moment and then I'll come to the last point. So interdiction, I had this really strong individual on my team. She was able to make contact with these members as they had some of these scams occurring in real time. And so she'd call as the member would be on the phone with a bad actor and her script, her talking track was so compelling.

Speaker: that she knew that if she approached them with a different type of logic pathway that she could interrupt the scamming process and be able to take back that member's perspective and put them back into safety. Now that does two things. Number one, it creates a stickier relationship with that member. You've just protected them and now they're going to look at your institution with a halo. Look at how

Speaker: clever, my institution is trying to protect its member base and it's doing all of these things that are valuable to me as a vulnerable participant in this ecosystem and that's going to create something that's very reliably sticky for them.

Speaker: That's a really, really interesting story because I did hear from a lot of financial institutions, and I think you mentioned this too, that it is a problem to convince people who are now being scammed. Even if you're able to detect the scam when it's happening or if it's a romance scam or repetitive scam, it's really hard to convince people that they're being scammed.

Speaker: and often law enforcement needs to get involved. So what you just told us is that someone on your team was able to find that psychological angle to actually counter that and convince the person. So definitely an important blueprint to consider and talk more about that drives a load of hope, I think.

Speaker: It does. But the flip side is even more compelling. I mean, it's wonderful to save a person. This is one of my favorite things. And that's the great good that we can do. And you feel fantastic about these outcomes, and you just want to scream them from the rooftops. But

Speaker: What's also painful, and in one of my former roles, what we did was a survey, and the survey and study revealed that 20 % of people who have a bad experience from a fraud event will leave that institution. And this is just on a card basis. You have a card fraud issue, and you've got a situation where it wasn't handled well, or you lost money, or it wasn't all the transactions and the dispute didn't work out, any of these things.

Speaker: 20 % of customers will leave. That's just the tip of the iceberg, as you would say, right? And what that doesn't suggest is, well, what if you are a victim of a scam and you've got all that shame and embarrassment and all of that reminder of every time you log in, every time you have to call the contact center, is this person going to judge me based on this event that happened?

Speaker: all of these things that you've got shame about, you're not going to want to stick around. And that retention issue becomes a problem in its own right. Because we all recognize, and every bank looks like the total lifetime value of a customer, and they see that there's a cost to acquisition and there's a loss if retention becomes a problem.

Speaker: And so if you look at those two angles, then you recognize that any credit or deposit operations leader will recognize that there's a lot of value lost here as well. And the number you brought, the 20 % attrition is actually from the credit card industry. I want to point out that we talked to

Speaker: Julie Conroy from Itenovarica Group in Episode 4, and she mentioned that they did some consumer research across UK, US, and Singapore, and 80 % of customers surveyed said that if they will fall victim to a scam and their bank will not reimburse them, they will leave the financial institution.

Speaker: Now, will it really be 80 %? I don't know to say that, but I definitely agree that it's more than 20 % and it's more than a credit card account take over fraud, which there's no shame associated with it. Whereas there is shame and there is frustration and there's that whole emotional impact that comes with the scam. So I wanted to ask you, what are some controls that you did put in place given that your approach was to do the right thing and to protect your customers

Speaker: So early on in my tenure with First Tech, I had deployed a solution called BioCatch. And BioCatch allows me to look at behavioral biometrics of a session and leverage those elements, as well as session details, including device information, network information.

Speaker: and use that in the acquisition of deploying controls that could be defensive. And this allowed me to be able to interdict those payments or at the very least alert when I could tell a session was high risk. Some of these controls were allowing me to get the

Speaker: that individual on the phone with my agent and disrupt that campaign. And I'd be looking for specific elements within the session that were high risk. There are specific fingerprints that exist within these sessions and they are actionable. And if you are efficient and can create rules and strategies that you recognize are consistently valuable in the session,

Speaker: and leveraging the biometric behaviors, the device elements, and the network elements, you might be able to make determinations about things that are inconsistent with your true user's typical behaviors.

Speaker: And these can be as nuanced as the amount of time they take within a specific phase of the attack. These can be consistent with what's going on at their device. These can be consistent with the behaviors that are occurring within the online banking session itself.

Speaker: but there are tattletales and breadcrumbs across all of these elements. And when you apply them all together, you're able to get to a place where you develop these rules and strategies that can be very fruitful. And we were able to have fraud capture rates that were elevated with false positive rates. That is where we create low friction events for customers and they become transparent. Those false positive rates could be very low,

Speaker: And the alert rates can be managed, and you can get those alerts to your destination with an efficient turnover. And if you hit that trifecta, that fraud capture, that false positive, and that alert rate into the thresholds that you're looking for, then you can get efficient at making those outbound contacts, disrupting these campaigns, and putting your members in a spot where they're better protected than they would be if you didn't have this strategy in place.

Speaker: And that's really interesting because I talked in one of the earlier episodes about how it's so hard to deploy technology to actually identify intent. It's not identifying a device change or an IP change or seeing that someone else is using the online banking application or some other application. It's the legitimate person, but they're, something's off and detecting that change in intent is very, very

Speaker: hard to do. So being able to do that is a huge step in the right direction. And also, as you mentioned, being able to disrupt that and really convince the victim that they're being scammed. I know that in many cases, it's not helpful because they are too deep into the emotional state of the scam. So a lot of progress on one side, but I wanted to ask you, in your opinion, what needs to be done

Speaker: to drive real change in the state of scams. Well, there's a few things that are happening right now. Some networks. Can you explain what you mean by networks?

Speaker: Sure, the payment networks are like the card networks when you see these are MasterCard are examples of payment card networks, but there's other networks that exist, networks that allow you to wire money or transfer funds domestically. You've got other payment applications, the P2P networks that exist to facilitate some of those payments and they can change the rules about who gets to say what was legitimate and what was not and who's going to be on the hook for liability when

Speaker: that happens, dependent on pressures that exist in the environment. So if a regulator says, hey, look, you know, we don't like what you're doing here, you got to have to change a thing. They can make a decision on their behalf to do that, or they face other potential consequences and you have first movers advantage by saying, okay, I'm going to do it.

Speaker: some networks are starting to take action and they're saying, well, who is responsible for, I'm not going to say negligent, but allowing for some of the bad actors to allow for the exfiltration of funds. And this is starting to occur, not just in this country, this is starting to occur in some European models as well. And those changes are starting to look at where those funds are headed to.

Speaker: But the networks are also saying your profile, your risk profile is elevated in contrast for scams to others in your business. And as a result of that,

Speaker: we want to hold you more accountable. And so the networks are starting to take some action and they're changing some of the rules in terms of liability and how liability will be able to be disputable. So similar to how cards work, if you've got a problem with a merchant, he didn't get delivery of goods, the amount was incorrect, you are able to dispute the transaction. And this is starting to take place in some other networks as well.

Speaker: Yeah. I wanted to ask, we talked about identifying scams when the transaction happens. One of the challenges that I see is we don't spare the victims from the emotional impact of the scam. What do you think we can do to drive that change?

Speaker: Well, I think it's really important that we start to look at scams as a larger threat to the totality of the environment. So in the UK, what we call authorized push payments scams, or scams where the customer is participating via social engineering, is now overtaking credit card fraud, which credit card fraud had been the leader for so many moons and decades.

Speaker: And at this point in time, when we realize that there is so much more exposure, we need to start looking at this from the lens of, okay, what are we going to do to fix some of this to create more confidence and create more consistency?

Speaker: and how we approach detection, resolution, and overall hygiene within the environment. Because if we allow this to get worse, then we're gonna have greater turnover

Speaker: attrition, there will be more scams, not less. So we need to apply more controls and those controls need to be effective like the ones that we just discussed. They need to be effective at not just informing as we talked about with the optics, they also need to be effective at disruption and that we need to ensure that we create the right levels of protection and not just the right levels of awareness.

Speaker: Great. Well, Seth, thank you so much for joining the podcast, and it was great to get your insights and your perspective, and have a wonderful day. Cheers. Thank you for the opportunity, Ayelet, and I hope that we can together find new mechanisms to inform and detect and prevent. Absolutely. Thank you so much.

Speaker: Be sure to subscribe to the podcast, and if you want to keep current with the latest news on online scams, follow me on LinkedIn, yet at Bigger Levine. Have a wonderful week.

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Recommended