Episodes / TPT #5
FRAUD
Video
👍 Like & comment on YouTube Subscribe to the channel
Listen
Open this episode in
- Spotify
- Apple Podcasts
- Amazon Music
- … AND PLEASE FOLLOW THE SHOW THERE — that is how new listeners find us.
Show notes
In this episode of the Payments Trilogue, Michael, Gijs, and Ralf discuss the evolving landscape of fraud in the payments industry. They explore the challenges posed by increasingly sophisticated fraud tactics, the importance of cross-sector collaboration in combating fraud, the role of technology and regulation, and the implications of AI in both facilitating and preventing fraud. The conversation highlights the need for a comprehensive approach to fraud prevention that includes data sharing, regulatory support, and technological innovation.
Transcript
Michael Salmony 0:02
Welcome to the Payments Trilogue, where three seasoned professionals discuss payments and more for Europe and beyond. Hello, my name is Michael Salmony and I'd like to welcome you back to another episode of the Trilogue with my good friends Gijs and Ralf, where this time we want to talk about fraud. Now, fraud, of course, is one of the topics that's been a cat and mouse game between the fraudsters and the industry for many years.
It used to be fairly simple. People would sort of fake a few credentials. Then they started modifying invoices and the industry reacted, for example, by putting confirmation of payee in so that you would verify who you're actually paying for. But again, the frauds has got more sophisticated and now doing things like APP fraud, where they pretend to be your bank and call you and tell you to move your money into a crypto account. And these things are getting more and more difficult to counter.
But the industry is coming up with some clever ideas and the regulators also coming up with some ideas. And therefore we want to talk about this topic, which is costing billions in Europe and is a serious topic. And so it's lovely to hear from these two industry experts. So, Gijs, maybe you could tell us a little bit what the banking industry is doing to combat this development. Yes, thank you, Michael. The brunt of the damages are always...
be borne by the account holding institutions that keep the money of the people and of course try to keep that money safe. As always it's a never ending arms race as we say. Of course the criminals are trying to get at the people's money. It used to be the cash in the steel vault and these days it's the digital cash in the digital vault.
So as a principle, it's the same as it used to be in the old days, but the means and ways, of course, they change. Especially the digitalization and the more complex value chains in the payments ecosystem, also with lots of non-bank players playing a role, let's say telcos or platforms, providing, let's say, the or sitting on or
Michael Salmony 2:16
controlling the access channels to the bank account have become increasingly important together with social engineering. What you typically see is that originally the fraud was committed by breaking the bank's security. That is no longer the case. The security is pretty much okay. And of course, that's why the criminals go for the soft spot. And that is the customer itself.
himself, herself, and through what we then call social engineering, an endless variety of schemes, sorry, scams, not schemes, but scams, people are, and the outcome is always the same, in any scam, the customer is enticed to make the payment, him or herself, because the security is okay, and you need the customer, him or herself, to really transfer the money to the criminal.
through all sorts of stories. Somebody calling from the fraud help desk from your bank, your money is at risk, you have to do this and that and we have opened a special safe account for you, you should transfer your money to that and then you're okay. But of course that is the criminal's account and well some people unfortunately do that, most people of course don't do that but enough people do that and that's what is called authorized push payment fraud, especially in the UK but also in my country.
the more digitalized you are, the more APP fraud you have. Just a bit of colour on that, because you're saying many people don't get caught by that. I could imagine somebody who is not in our industry, gets a call from this bank manager with the phone number of his bank manager, and he says, I know you have $137,000 in your account, because they got it through some other means.
We know your daughter is in Latin America at the moment. You really need to move that money quickly because the doctors need to help her because they've seen her picture on social media. That is a pretty convincing case, right? It's very large. Absolutely. But it also shows how several industries are involved. Social media, the phone companies allow you to spoof numbers. So it's not just the banks who can prevent this, No, absolutely not.
Michael Salmony 4:41
It's not just the bulletproof glass you need to keep the criminals out of your bank branch because that's not where the fraud takes place anymore. It's an extended value change with other actors controlling access channels. That is of course also why banks are calling upon the authorities to do more about that. So recently a report was submitted and it's not published yet.
in the Euro Retail Payments Board, which now has a new fraud working group, with an industry paper what we, as banks, believe could be done. it's an extremely complex problem. There is no silver bullet. So it's a combination of all sorts of measures that are being proposed. But one of the most important is indeed cross-sectoral collaboration and also more responsibilities also of those
non-bank actors in the payments value chain. I just read today, a couple of days ago, that for instance in the UK, labour is now proposing to also make Big Tech to a certain extent liable if the fraud is enacted through their channels and that is one of the things the banks also call upon, on the continent call upon the authorities to have a more cross-sectoral view on who should
be responsible for what in this whole payments value chain. There's at least one of the most important things that are being proposed also that has been very difficult over the years. Fraud data sharing and insights is of course absolutely conditional for effective fraud fighting, fighting of fraud. But then we have our GDPR which complicates things tremendously and
we really believe that of course privacy is a fundamental right, of course we do know that, but GDPR should not be unintentionally used to do to the advantage of the criminals because vital data on fraud cannot be shared because of supposed privacy concerns. we really think a lot of people, lot of authorities would understand if there were more data sharing.
Michael Salmony 7:00
I mean, I know from Japan that a lot of banks are sharing data. They see, I've been acting this way. They tell the other banks to watch out. They inform the consumers. I everybody understands data sharing is necessary and we need to do something. And for some mystical reason, we can't seem to get our act together in that context in Europe, the EU, supposedly because of GDPR. So I really think we have to...
to cut that knot to be more effective in fighting fraud because it's not just the damage to the consumer, which the bank may or may not reimburse, but the money goes to the criminals and it is reinvested in other lines of criminal activity like drug trafficking, arms trading, whatnot. The problem doesn't start with reimbursing the customer. That's too easy. The money should not go to the criminals. That is the aim.
and that's the whole point of the exercise. We should go for an opportunity to comment on that because he's the expert on data sharing. What do you think? For once here, I would agree that sharing this sort of data is important. What is a bit of a pity though is that with the interaction between on a between TPPs and banks, we've had
It was rather difficult here to exchange such data. for example, from a TPP's perspective, we have always had big concerns around getting information about the customer, the payer. And for example, to make sure that the person that we are just...
trying to initiate a payment from is indeed the person who says he is. So we would need the account holder name. you know the story about that. It took ages for actually getting that information in the regulation or interpretation for the regulation to actually have that name available. But maybe also maybe the other way around, because if you're a PISP, you're typically onboarding the merchant. there is already good.
Michael Salmony 9:14
knowledge about the recipient and what's so the what's called the authorized push payment fraud where people pay the wrong person or are tricked into paying the wrong person. So here a PISP can be very helpful already having on board it or making sure that the payee is indeed the payee intended. so
You described why that is, that's not immediately clear how a PISP can help there. do you Well, mean, we have just seen here also in the IP regulation that it has been baked in that if you are in a retail payment scenario, if a PISP has already on-boarded the merchant, so who knows who...
the PIS and it's actually the PISP who's putting the information into the payload. So it's the PISP who says who to pay. We know the name. We know even the account name of that merchant. So we know the IBAN. We know that they match and therefore this is thankfully one of the exceptions there where an individual VOP per transaction will not be required because we already know that it's going to the right person.
But if there is any doubt, then that is where we can obviously highlight that and flag that too. And maybe one other aspect which we have not touched upon is that, course, historically we've seen most fraud in the cards world because that was the main type of electronic payment and...
And yeah, and there wasn't SCA involved prior to PST2. And so that is where when SCA has come in, it has had its good effect. And from an account to account perspective, and therefore from a TPP or PISP perspective, we've always dealt with SCA. So historically there has been a lower level of fraud rates because we had those added security built in all the time.
Michael Salmony 11:29
That's a very good point. What do you think of the topics that Gijs raised on Parson about making the banks liable? Right. I mean, there are some who say that seems the natural thing to do. On the other hand, they will just put a lot more friction in the way and warn you about, I I bank in the UK and every time I just want to do a normal bank transfer, it asks me 17 times, are you really sure you meant this? Are you sure this isn't a fraud? Yeah, and it's disruptive. Is this a development we want? No, we don't.
And although, of course, even if it's the bank who is then initially liable for any reimbursement, of course making this double or triple checking is one thing, but they also have started to introduce limits on the amounts to be paid, and in particular, if a third party is involved. So we are now facing lower limits so that people can
pay only lower amounts through a PISP than they could if they go with the bank directly. So even if we are not directly in the filing line, we will then get hit in the aftermath of whatever reaction or whatever action banks are taking in order to reduce their exposure. Just one last question to you,
But I have to protest in what he said. Because we need some friction and of course the interest of the PISP is always as seamless, frictionless as possible. But if the bank is liable, because there is not enough friction, we need good friction. That is what we also discussed with the European Commission. Too easy is too dangerous. So there needs to be the correct amount of friction. And we can have a discussion on how much that should be.
and it's not the bad intent of the bank just to disgruntle the TPP, but it's for consumer protection because if you don't do that, you will have to refund the customer. So unfortunately, it's the criminal's fault, it's not the bank's fault that you need that friction. And sometimes that may end up a bit too cranky, I agree to that.
Michael Salmony 13:52
but you're now playing a little bit of the of the victim here as TPP. And I don't think it's that bad. mean, these spending limits, I mean, it's just natural and they would apply to the customer itself. Are you implying that banks are having specifically lower limits for payments initiation? Yes, unfortunately. So if you were right, if there was a level playing field, if the customer had the exact same limit online, then through APIs, then...
that would be fair enough, it's not the case of unfortunately. But is that a general thing across Europe? Because I haven't seen that at least not in my country. I don't know. I think there is some perception that going via PISP would be then even more risky, which I'm not sure I can see. And especially from a fraudsters perspective, if you want to do something wrong, the more parties you get involved into it, the more...
you know, the worse it is. And it's the same from, by the way, I mean, it's a different subject, anti-money laundering. So if I was to do that, I mean, the last thing I would do is I wouldn't do it via PISP because that's an unnecessary third party getting involved to, who may see something they shouldn't. But have we seen any authorized push payment scams connected through
PISPs, don't think so. It's mostly directly criminal calling the account holder and doing it. Yeah, exactly. the interference of the PISP that would only complicate the scenario. I don't think that's where the danger is. mean, that's what we've seen at least. But there are some people in the industry sort of saying, you know, the more people that are connected, the more difficult it is. And of course, one should make the social media liable and the telecoms liable because they're of the problem. And some people also
saying sort of the TPP should be put in there, right? I bet you find that a bit worrying, Ralf, right? Well, I think there is a big misunderstanding about liability there because we are liable. So it's true that the customer, the first recourse is against the bank where they have their account. But if for whatever reason the fault
Michael Salmony 16:11
is with the TPP, then the bank can come back to the TPP and get reimbursed for whatever damage there is. So the liability is not unclear. It is very clear in the law. Exactly. We fought hard for that. You fought hard for that. But the bank is what they call the first port of call for the customer. And then after reimbursement of the customer, can or not, can try to get recourse on the third party.
but first the customer has to be held whole or made whole. But since we're talking about the sort of regulator here, I mean, I know we all three agree that the regulator is far too often telling people how to do things instead of just saying what they should be doing, right? Like it has to be confirmation of payee or something. Or in the APP case, it's only when your bank calls you fraudulently, that's the case.
But there are going to be 17 other different ways the frauds are That's how it started. That is what the Commission originally proposed. Only that one specific scenario, but the discussions in Parliament are going in a totally different direction. Why not make all cases refundable, all scam social engineering things? At least that is a discussion we know that's going on in the trilogue or the council working groups and so on.
which is of course an uncertain outcome. It makes sense, otherwise you're always playing whack-a-ball when this scenario you hit it on the head and the next one comes up and you've got to generically solve the problem without trying to always anticipate what the latest thing from the process is. Yeah, but there's a horrible dilemma of what you can do in legislation and what you can't do in legislation. We even know there...
Rumor has it there's even discussions going on that some believe, and some in the co-legislative process believe that we should also, the notion of gross negligence, maybe we should give a couple of examples when a customer would be grossly negligent, whereas we would know this is a concept that has to be applied by the courts and we should not have indications in the law what that might be because it will, these are the things that you have to look at the individual case.
Michael Salmony 18:35
the person, the bank, the conditions, etc. The whole set of circumstances in the case and then the judge can say somebody was grossly negligent, but you shouldn't try to make it more objective in a level one legislation in Europe, I believe. Yeah, very good. Yeah. We only have a few minutes left, but just like to hear your thoughts on AI and fraud. I mean, some people think that AI is the best thing that ever happened for fraudsters because now they can automate attacks, they can...
write the scripts for the guy calling you based on the social media profile. There's fantastic things fraudsters can do, fantastic in an awful way, right? But on the other hand, the banks also have more opportunity of spotting patterns and defending against this. What's your thinking on this, of you? Well, if I may kick it off, think the jury is still out there. And as I said at the beginning, it's a never-ending arms race. It's just another battle in a never-ending war.
And so you are secure for some time and then there's a new technology or whatever that the criminals try to exploit to break through the existing defenses and then some damages will occur. And then the defending party will raise their defenses until such time that the new technology has become less harmful. That's the normal mechanism. And I would assume that this time around it will be the same. It will be both bad and it will be good as well.
And well, but it goes very quickly, the scalability of it. So in the old days, building big steel vaults took some time or heavily fortified back branches. But now in the digital environment, anyone can scale fraud scenarios in no time. So you have to be real fast to spot stuff and take countermeasures.
It's both sides as usual. So the AI will upgrade the bank help desk fraud scenario because it will be an AI generated bank person that will have a video conversation with you with a chatbot that is so intelligent. It can have a real conversation with you and you will be really believing you are talking to the bank employee, or herself and shit will happen.
Michael Salmony 20:59
I mean, as before, people are calling you pretending to be their bank manager. Now you can actually have a video call with your bank manager. but it's a deep fake, right? It's a deep fake. moves like he does. But Ralf, what do you think? Yeah, well, we've already touched on a lot of this fraud has its origin in social engineering, not necessarily in the financial side of it. So it's a social engineering, which, of course, will now be augmented big time.
by AI making it even more plausible and tricking even more people into doing the wrong thing. my fear, I must say, is that the AI in the end will be a bit more helpful to the fraudsters than it is to the guys defending it. Yeah, so it's... Well, at least initially... It will be promising, I must say.
No, I agree with Ralf, but as I said, first the attackers will find loopholes where AI will profit them and then the counter reaction will come hopefully quick. But initially it will be more to the advantage probably of the attackers than of the defenders. The fraudsters are always the most innovative, most technology savvy, they understand humans better, they do the best business cases, they are just incredibly professional.
That's the sad fact. On that sad note, I think it's about time to call it an end. We explored things fraud from hardware to software to wetware. Fraud used to be done with a crowbar and a pistol in the physical world. And then it was software where people entered and broke into the software. Then it's the wetware, the man's woman sitting in front of the computer using it. That's what's being attacked with social media.
And maybe the next phase is the robot wars where the robots from the fraudsters against the robots at the user. So I think we had a very interesting conversation again and thank you very much, Gijs and Ralf for this lovely conversation. And thanks to all who are watching this. I hope you enjoyed it and look forward to seeing you here at the Trilogue for the next topic.
Michael Salmony 23:19
Many thanks for watching and listening. We hope you enjoyed this episode. Looking forward to seeing you again next time.