Showing posts with label fraud. Show all posts
Showing posts with label fraud. Show all posts

Sunday, February 16, 2014

Online Fraud Analytics



Tracking a customer’s interactions is something all companies do, but what happens though when the customer on your website has ulterior motives? A mistake that if overlooked or left unchecked, can cost a company hundreds of thousands to even millions of dollars in losses depending on the complexity of the breach. 

Welcome to the dark side of digital analytics, where fraudsters use the online channel to commit crime. With the emergence of new technologies, smartphones and tablets, the way which we interact with companies and financial institutions via the web is changing, and fraudsters are leveraging these new avenues to acquire funds and peoples identities through illegitimate means. 

"Data analytics, traditionally the domain of marketing and sales, has effectively migrated into the realm of internal audit, compliance, and corporate oversight. Companies now have opportunities to use forensic data analytics for proactive monitoring of business data. Organizations will be able to develop a better understanding of the risks and rewards of forensic data analytics and how these techniques can be used to transform data to help detect potential instances of fraud and implement effective fraud risk mitigation programs." - EY (1)

Industry Trends

While fraud continues to be an ever evolving industry and can take on many faces, there are areas analysts can pay close attention to within their population’s data to quickly identify threats:

  • Multichannel. A trend that has become popular among fraudsters in recent years. The customer may be compromised initially through offline means, and the actual loss occurs via the online channel or vice versa. Like most multichannel initiatives putting together a way to track customers across multiple channels or devices can be difficult, however many third party vendors are building into their algorithms ways to make this easier. (4)
  •  Malware and Phishing Attempts. Fraudsters have targeted consumers through this avenue since the launch of the internet. As society has advances in technology, so to have the methods fraudsters use to hijack ones computer or obtain ones identity. A computer takeover can be difficult to detect as fraudulent activity, as it will appear that the customer is the one making the transactions. (5)
  • Mobile Devices. Mobile commerce is projected to expand from 9% of all ecommerce sales to 18% in 2014. (8) As consumers move towards accessing information and interacting from smartphone and tablets more often, the next push by fraudsters is to compromise these devices. As most of us store a lot of personal and private information on these devices, one compromise could me endless possibilities to the fraudster. If your company uses an IP, or browser tracking system for your customers, make sure to build into your reporting and alerting software when these behaviors change. (5)

What Can Be Done?

As fraud is an ever moving target, steps can be made to hedge losses. Financial institutions and most companies are well aware of the importance this will be to their bottom line and are therefore allocating larger portions of their yearly budget to stay one step ahead. Deloitte, a risk and compliance company, has given four areas where companies should focus fraud analytic efforts for a successful strategy:
Components of an Effective Fraud Risk Framework
1.       Cultural assessment.
2.       Technology and data analytics.
3.       Effective control activities.
4.       Continuous monitoring and innovation. (6)

While these items encompass all aspects of Digital Analytics, there are more precise items that companies should consider when dealing with fraud for a more robust strategy. Proactively building relationships, with third party vendor companies like: Actimize, Fiserv, SAS, and Oracle, are key to having success. These companies are expected to have a growth rate of 6.9% through 2017 to help combat the problem. (3)  Building these strong relationships with third party vendors and leveraging their systems will empower companies and banks to identify, track, and prevent fraud losses from occurring. 

Due to the silo effect that exists in most companies however getting risk and data management processes up to speed with current fraud trends has been difficult and often red flags are overlooked. (3) Changes are being made to alleviate the silo problem and make it the problem of the department or company as a whole. Taking this approach holds everyone accountable for the loss.  

Because there are many types of fraud companies can face both internally and externally, making sure analysts are specialized in a particular facet of fraud: AML, BSA, Online, ACH, Credit card etc. is better for the company’s defense. This also helps to tailor the tools used to a particular fraud for quicker identification and prevention.  

Finally, financial institutions are finding success in fraud analytics by attempting to predict the customer and fraudster’s behavior. Applying a scoring system to what is normal and abnormal behavior for a customer have allowed for easier identification of abnormalities. (2) Along the same lines, another insightful way to identifying fraudulent customers is to detecting commonalities among customers. Are the same contact information points being used, addresses, phone number, email addresses among unrelated customers.(7) Linking what appear to be unrelated or single events together will reveal the  complete picture of the fraudster’s endgame more quickly. 

While the vastness of fraud can be overwhelming, having an empowered group of analysts with the right tools and a well-rounded strategy containing the aspects listed above, your company can greatly minimize the losses it will face due to fraudulent activity.

Works Cited
  1. Burger, K. (2013, December 17). Fraud and Corruption Trends to Watch in 2014. Retrieved from Bank Systems & Technology: http://www.banktech.com/risk-management/fraud-and-corruption-trends-to-watch-in/240164822
  2. Crosman, P. (2013, December 23). Six Bets Wells Fargo Is Making on Treasury Technology. Retrieved from American Banker : http://www.americanbanker.com/issues/178_245/six-bets-wells-fargo-is-making-on-treasury-technology-1064522-1.html
  3. Crosman, P. (2014, January 9). Banks' Risk Tech Spending Expected to Grow Steeply Through 2017. Retrieved from American Banker : http://www.americanbanker.com/issues/179_7/banks-risk-tech-spending-expected-to-grow-steeply-through-2017-1064780-1.html
  4. Current State of E-channel Fraud Trends: Online Banking, Mobile Banking, and Card Fraud. (n.d.). Retrieved from NAFCU: http://www.nafcu.org/NAFCU_Services_Corporation/Partner_Library/Current_State_of_E-channel_Fraud_Trends__Online_Banking__Mobile_Banking__and_Card_Fraud__Whitepaper_/
  5. Deloitte - Risk & Compliance Journal. (2014, February 3). Prevention Measures to Help Counter E-commerce Fraud. Retrieved from Wall Street Journal : http://deloitte.wsj.com/riskandcompliance/2014/02/03/prevention-measures-to-help-counter-e-commerce-fraud/?KEYWORDS=fraud+analytics
  6. Deloitte - Risk & Compliance Journal. (2014, January 28). Detecting Fraud and Growing Margins in Retail Using Analytics. Retrieved from Wall Street Journal : http://deloitte.wsj.com/riskandcompliance/2014/01/28/detecting-fraud-and-growing-margins-using-analytics-in-retail/?KEYWORDS=fraud+analytics
  7. Hardy, Q. (2012, January 19). Data Analytics Company Finds Fraud Is A Friend. Retrieved from New York Times: http://bits.blogs.nytimes.com/2012/01/19/data-analytics-company-finds-fraud-is-a-friend/?_php=true&_type=blogs&_r=0
  8. Infographic: Mobile Payment Management Trends 2012-2013. (2013). Retrieved from Cybersource: https://www.cybersource.com/products_and_services/fraud_management/mobile_trends/
 

Wednesday, February 13, 2013

Fraud: Part 2 - Why and What?

       

 Fraud: Part 2 - Why and What?


My last post discussed who commits fraud and the various ways they obtain your personal information.  You can check that out here.  As promised, this post will discuss the different types of fraud that cybercriminals commit after they have your information and what you can do to protect yourself.  I will also talk about the various ways that fraudsters are using web analytics to develop their newest fraud schemes.  Of course, I am focusing on cybercrime and cybercriminals, so the fraud schemes discussed will be focused on internet crime. 

Why? - To Get Your Money       

That seems obvious, right?  But there are lots of different ways to steal your money and that's the trick for a fraudster - figuring out the best way!  There are too many scams to name them all in this blog post so I will include references at the end if you're interested in learning more.  Now let's talk about some of the techniques that fraudsters use to separate you from your hard-earned cash over the internet!

  • Clean Fraud - This is a relatively new term and it is becoming a BIG problem.  Clean fraud happens when purchases are made on the internet with stolen credit cards...  here comes the but...  BUT the transactions APPEAR to be completely legitimate to fraud detection software!!  This is possible because cybercriminals can manipulate all of the elements of a card transaction and internet browsing session1.  In other words, someone in New York can use MY card and make it look like the purchase is coming from MY computer.  This is all made possible by web analytics.  Fraudsters have been smart enough to collect data and analyze what is causing their stolen cards to get declined.  And sure enough, they have cracked the code and are only getting better!  This is a huge threat to online merchants in particular because the "old" methods of detecting fraudulent transactions are no longer effective.

  • Account Takeover - What better way of stealing your money then to hi-jack your credit card and bank accounts?  A cybercriminal will use all of the ways we discussed last post (malware, SQL Injections, keyloggers, etc.) to obtain your credentials to your various accounts.  Once in, they make unauthorized transactions and move your money out of your account.  Because the cybercriminal was able to log in, it appears as though it was you that withdrew all your money and made those charges.
  • Identity Theft - Considering a fraudster can mimic your transactions and takeover your accounts, why not just give them access to your entire identity?  If a fraudster has obtained enough of your information, they can open new accounts in your name.  Some open credit cards and buy merchandise, others prefer to open bank accounts in the names of others to launder money and deposit fraudulent funds (resulting in cash).  
The examples above are just three of the most prevalent types of internet scams2.  I included them because these three crimes in particular have been able to evolve because of web analytics.  Without proper data collection and analysis, fraudsters would have never been able to determine what to change in their techniques to remain undetected.  It is a constant game of cat and mouse for those committing fraud and those detecting it.

What? - What You Can do to Protect Yourself from Fraud

So now that you know who wants to steal your money, the various ways they collect your information, and what they do with your information you probably want to know what you can do to protect yourself.  Here are some things you can do to reduce your risk of being scammed:

  • Educate yourself!  There are various websites that provide information on internet crime and fraud schemes.  Check out the website LooksTooGoodToBeTrue and visit the "Take Our Test" portion of their website.  Their assessments can help you determine if you have become or are about to become a victim of fraud.  You can also learn about all of the various types of internet scams3.  You will be amazed at what is happening out there on the internet.
  • Check your bank account and credit card statements regularly for unauthorized transactions.  If you see anything that you didn't do, report it to your bank or card issuer immediately!
  • Change your passwords regularly and make sure they are complex.  Many people don't realize that a weak password can be hacked in a matter of minutes by an experienced fraudster with the right tools. If you have a strong password it could take their software days, or maybe even prevent them from cracking it all together.  Get password tips and check the strength of your password here.
  • Protect your computer.  This is probably the most important thing you can do.  Make sure you have reputable and robust anti-virus software installed on your computer.  And most importantly, don't forget to use it!
Fraud happens to good people every day.  Cybercriminals are using advanced methods to develop their attacks and will continually find new and innovative ways to get your money.  Whenever you are on the internet, know that they are out there waiting for you to make a mistake.  Be aware!  I hope my posts have been informative and demonstrated that even the bad guys are benefiting from the wonderful world of Web Analytics!

References and Resources

1http://img.en25.com/Web/CyberSource/CyberSource_ScreeningExcellence_Final.pdf?utm_campaign=Order%20Screening%20WP%20-%20Thank%20You&utm_medium=email&utm_source=Eloqua 
2http://www.ic3.gov/media/2012/121126.aspx
3http://www.lookstoogoodtobetrue.com/index.aspx
http://www.saveandinvest.org/








Saturday, January 26, 2013

Fraud: Part 1 - Who commits fraud and how do they do it?


Fraud: Part 1 - Who and how?

This post will delve into the world of fraud and internet crime.  I could probably type a hundred pages on the subject; however I realize that’s not the best way to get readers.  I hope to provide you with enough information to spark your interest and the resources to find out more should you feel inclined.  This particular post will discuss internet crime trends and types of attacks.  My next post will discuss the various types of fraud and what you can do to protect yourself from the “bad guys”.  

Who? - Cybercriminals

Unless you've been living under a rock, then you have probably heard the terms cybercrime and cybercriminal.  But how much do you really know about the business of fraud?  Crime, particularly cybercrime, is a BIG business.  It is estimated that the cost of cybercrime in 2012 was $110 billion worldwide and $21 billion in the United States1.   In fact, cybercrime is the new organized crime that involves a complex business model and many intelligent players.  In Russia, magazine publications on how to commit fraud are sold in gas stations!  And they, the Russians, even hold seminars and classes on how to commit bank and card fraud.  The fraudster, or cybercriminal, will steal the identity and/or financial information of an innocent person and then use that identity and/or financial information to illegally obtain funds.  Cybercriminals steal information from large institutions by hacking into their networks or they steal information directly from the victim’s computer.  Stealing directly from the victim is usually the preferred way because it is often easier and less protected.    

A recent investigation by RSA, discovered that cybercriminals are using advanced web analytics tools and marketing techniques to refine their attacks.  By obtaining statistics on their attacks, they are able to identify the most effective attacks and the best time to conduct attacks.  For example, using web analytics and A/B testing, a cybercriminal can determine which phishing email got the highest open rates and most click-throughs2

Often, what is most surprising to people, is how difficult these criminals are to prosecute.  Many of the crimes are committed on computers in other countries, making prosecution next to impossible (and that’s if you ever find the bad guy).  To help law enforcement and regulatory agencies organize their investigations, the Internet Crime Complaint Center, or IC3, was established as a partnership between the Federal Bureau of Investigation and the National White Collar Crime Center.  I won’t go into detail about what they do, but in a nutshell, they enable consumers and businesses to report cybercrime to a centralized place.  Below is a chart that shows the number of complaints the IC3 has received by year3:
















Click here to view the 2012 Norton Cybercrime Report for more facts about cybercrime.

How? - Types of Attacks

As I mentioned above, the first step in committing cybercrime is to steal personal information.  There is an extensive black market that exists where cybercriminals buy and sell stolen personal information over the internet.  These online Fraud Forums are used to exchange goods and services and are a way for fraudsters to collaborate and offer up their skills and expertise4.  If you've never googled “credit card dump”, give it a try!  There is a high-demand for stolen information and the market is lucrative and pays well to those that can obtain it.  Cybercriminals use extensive resources to obtain everything from card numbers, email addresses, bank login information, to whole identities.  Once they have it, they sell the information to other cybercriminals who then use it to steal money!  It’s all very exciting really.

Below I have described the most common attack techniques5 and 6:

·    Malware – Software that collects personal information from a computer undetected.  Spyware, botnet, viruses, worms, keyloggers, Trojan horses, adware, and more are all types of malware.
·    Phishing – An email, instant message, or other communication that appears to be from a trustworthy source.  The purpose of these fraudulent communications is to obtain usernames, passwords, and card numbers.
·    SQL Injections – A technique often used to attack data driven applications. This is done by including portions of SQL statements in an entry field in an attempt to get the website to pass a newly formed SQL command to the database (e.g., dump the database contents to the attacker).
·    Denial-of-Service – Flooding a network or server with traffic in order to make it unavailable to its users.  This enables the fraudsters to redirect victims to a spoofed website in order to intercept their personal information. 
·    Skimming – Devices that steal credit card information when the card is swiped through them. The stolen credit card information is then sold online through an online action to carders who use the numbers to make counterfeit cards.





















For more information on the types of attacks cybercriminals use, click here.

I have included some resources below if you are interested in reading more about cybercrime.  My next post, “Fraud: Part 2 – Why and what?” will discuss the other half of the fraud business model.  What do fraudsters do with your personal information and what can you do to protect yourself from them?

References and Resources

[1] http://now-static.norton.com/now/en/pu/images/Promotions/2012/cybercrimeReport/2012_Norton_Cybercrime_Report_Master_FINAL_050912.pdf
[2] http://searchsecurity.techtarget.com/answer/Use-cybercrime-statistics-to-combat-organized-cybercrime
[3] http://butleritsec.blogspot.com/2012/05/cybercrime-statistics.html
[4] http://www.firstdata.com/downloads/thought-leadership/fraudtrends2010_wp.pdf
[5] http://www.carnegiecyberacademy.com/facultyPages/cyberCriminals/operate.html#techniques
[6] http://www.firstdata.com/downloads/thought-leadership/fraudtrends2010_wp.pdf
http://hackmageddon.com/2012/07/13/june-2012-cyber-attacks-statistics/
http://www.businessweek.com/articles/2012-08-02/the-cost-of-cyber-crime
http://news.techworld.com/security/3403711/rsa-cybercriminals-plot-massive-banking-trojan-attack/
www.fbi.gov
www.ic3.gov
www.ice.gov