Skip to main content

Evolving fraud tactics need evolving solutions

Share

Megan Pulliam, SVP of Marketplace for MeridianLink and Isio Nelson, Managing Director – Research, Fraud & Thought Leadership for BAI, discuss fraud issues that continue to evolve and why it is important to have evolving fraud solutions to combat these bad actors.

Don’t miss the other insights, methods and tools that can help your financial institution shape and evolve its fraud strategy and prevention tactics in the BAI Deep Dive: Mitigating fraud threats.

Dive deeper into fraud insights 

You might also be interested in:

Opt for layered identity verification for safer, efficient digital operations 

Webinar: Strategies for identifying and preventing check fraud

As deepfakes redraw cybersecurity battlelines, banks must change their approach 

TRANSCRIPT:

Isio Nelson, BAI: Well hello everybody, and thank you for joining us. I’m privileged today to be sitting here with an expert in the industry that has a unique perspective, Megan Pulliam from MeridianLink. I’m Isio Nelson. I currently am the managing director here at BAI. I lead our research group, along with our fraud initiatives and our thought leadership. Joining me is Megan Pulliam, and she is SVP Partner Marketplace at MeridianLink. She’s going to speak to us about a couple of different things, especially that unique perspective of having partners that work with the different financial institutions that they serve. And then a little bit more specific around some synthetic fraud and account takeover, and some of the things that we see in the marketplace today. So Megan, welcome. Maybe you can set the scene for us a little bit about your role, and how your engagement with a range of stakeholders gives us insight into the wide reach of fraud across the industry.

Megan Pulliam, MeridianLink: All right. Thank you so much, Isio. It’s great to join you today. I appreciate the opportunity to talk about this. I will say MeridianLink, as a player, a FinTech player in the loan origination, account origination space, we’re actually exposed in a way to a lot of different perspectives. We work on a daily basis with our customers to understand how we can help them make the transition from what was largely a paper-based face-to-face in-branch kind of interaction with people, into this world where consumers, particularly younger generations, want to engage digitally. They get on their phones. They want to open a new account, they might need a car loan, they might need a credit card.

Being able to engage in a way that makes it a fulfilling experience for that consumer or a member of a credit union, while making sure that the institution themselves is conducting good business and managing their risk, controlling all the compliance and regulatory needs that they have for their institution. I will say over the last decade, as I’ve worked about the last year and a half here at MeridianLink, and prior to that at a FinTech and in the mortgage origination space, I’ve been absolutely astounded not just by the rapid movement from in-person interactions to digital experiences, but the just absolutely ever-evolving threat landscape that’s out there.

It seems like on a daily basis, one of our institutions is sharing with us something that you would never have thought possible of how bots and fraudsters are coming into the institution, not just physically, but also digitally. And the request of those institutions to us to say, “How do we protect ourselves? And frankly, how do we protect our customers? How do we protect our members and keep them safe, while not turning them off to the level of interaction that we need in order to do that and keep them safe?” In my role, I talk to a lot of vendors out in the market, a lot of larger organizations that provide solutions in this area. And really listening to our customers and weighing out what those options are, and making sure that they’re available through our platform.

Isio:Yeah. Such a unique place to be, as you see a vast array of providers and vendors in this marketplace reacting to a lot of the shifts that you just talked about. Then you hit on a couple of things we’ll dive deeper into in this conversation I think that’s important, right? One is the balance between keeping the fraudsters out, but keeping your good customers to the point where they’re not getting so much friction that they decide they’re going to go somewhere else. You talked a little bit about that ever-changing shift in fraud. We just had a study where fraud is now in the top three spots as far as where the banks are investing, and that had not been previous, but a lot of those shifts. And then a lot of that spurred on by the change to digital, to your point.

Then some of these new things that are coming out, AI and bots in other places are continuing to evolve faster sometimes than the industry can. So let’s talk a little bit about some of those things. Let’s maybe start with digital fraud concerns, and that shift within the partner ecosystem. Maybe you can go into a couple of places like synthetic fraud and maybe just… Sorry to go back one second. For everybody in the audience, I’m sure everybody that’s tuned in already knows what synthetic fraud is. But maybe a definition of synthetic fraud, and then some of those things you’re seeing digital really affect synthetic.

Megan:  Yeah, and I will say this. One thing that sort of astounded me in some of my interactions is just demystifying this in a way. Meaning a lot of terms are thrown out there, and frankly I think for some of the security experts among us, the notion of creating interesting taglines or interesting phrases. So I think there is a real need to demystify what it is. Synthetic was one of those that came up, and I personally said, “Synthetic, what does that mean? A synthetic human being?” I think as we start to unpack these concepts, and we really get to what is it the fraudster is doing in a synthetic takeover or a synthetic identity, a little different than a stolen identity. It’s a little different than a manufactured identity. But at the end of the day, it’s really taking elements of truth and putting them together in a way that makes an individual seem legitimate.

It’s a real social security number, a number that can be validated, but it doesn’t belong to that person. Cobbling together pieces of an identity and creating this synthetic human being that looks good on paper, but doesn’t actually really exist. So they check, they’ve figured out how to check all of the boxes and cobble together things that can be validated. So if you’re not looking, they can slide through the cracks. I think that synthetic identity is something that’s really evolved over the last, let’s say year, or year and a half, as really one of those things that an institution never would’ve had to deal with. But frankly, synthetic identities are now being brought into branches as well. So how do you validate when the person on the driver’s license, it’s their picture, but that person isn’t actually a real person?

Isio:  Yeah. I thought that synthetic IDs were just for college kids, but I know that the fraudsters use them too.

Megan: That’s exactly right. That’s exactly right. These accounts are used to create transactional, like applications, and then seek offers of credit. Unless you’re monitoring through the application process, you are unlikely to check those things or catch those things.

Isio:So, we know it’s out there. Synthetic ID is a thing, and it’s becoming more and more, especially with the digital. What approaches, and maybe specifically what digital tools are some of your financial institution partners using to protect themselves and their customers from some of that synthetic fraud?

Megan: Yeah. I will say some of these solutions extend to protections that cover several areas. So with new account fraud or credit abuse, meaning I’m trying to come in and create a new account, or consumers that are knowingly misusing existing accounts or misrepresenting their own identities, there’s a few ways to handle that. There’s the concept of a pre-screen. So proactively making offers to your good customers, taking data points from them in an application where you can pre-fill or you can pre-populate some of the information about what you know from them. There are a lot of tools out there today that will do that. Then within this particular realm, I would say ID verification, also known as IDV. You’ll hear IDV, IDA, but identity verification, there are tools and a number of different ways of doing it.

Whether it’s some of those tools that allow you to log into an existing bank account, therefore validating and authenticating your identity that way. There’s also tools out there that will help with device risk. So it will know, hey, Megan’s used this computer in the past. It matches her footprint. Frankly, one of the more astounding ones is on the phone. There are tools now that will say, “Yes. This phone and this phone number belong to Megan. So I know if she’s on it trying to fill out an application, that it actually belongs to her.” So some of these are low friction ways of engaging with the consumer, because those things run in the background. Meaning it’s validating data points as the consumer or as the credit union member is engaging.

Those things are, like the phone takeover risk, of knowing whether or not the risk score on this looks good or not, and you can stop the process before it goes too far. Another common tool here, and I will say most of us as consumers are used to now the one-time passcode. This system that actually validates Megan, validates my phone and says, “Hey, I’m going to send you a one-time passcode. You are going to get that, and you’re going to enter it here.” Thankfully over the last, let’s say year, or year and a half, that has become so ubiquitous that, again, it no longer feels like something that we don’t want to be bothered with of, “Oh, my phone’s over there,” or, “I’ve got to go figure out where to find that.” So those are common tools that actually help to offset the risk of a manufactured identity or a synthetic identity. They just won’t have access to those things.

Isio: Yeah, all great points. To your point, the adoption curve on one-time passcodes and some of these other things are no longer just for the younger generations. Even the older generations are used to it now, and it’s part of… Some of our research says it’s expected, in fact. They are glad, and there’s messaging that goes through it that the banks will say, “Hey, we’re doing this for your protection. This is why we do it.” And therefore, they’re happy that they’re being protected by the bank and institutions, even if it’s a little bit of friction. We’ll talk a little bit more about when you put too much friction in the process, and then what that might do to that customer experience.

Let me talk to you about another thing. So synthetic’s great, good information there about what’s going on. Another big piece that we are hearing a lot from the banks about is account takeover being a top-of-mind fraud challenge. Again, maybe explain to everybody. I know most people know what it is, but explain what account takeover is, and then walk us through what the industry efforts are to get ahead of that curve for those bad actors that are abusing the access.

Megan:  Yeah. Account takeover in many regards, it’s one that makes me sad, because it’s targeting certain portions of the population that may not be as digitally savvy. Where a fraudster will place a phone call, they’ll use social engineering, they have just enough information, they have a great call script. And unwittingly, consumers or members of a credit union will give out just enough information that allows that fraudster to gain access to their account. So account takeover is really a fraudster taking over the credentials to log in as though they are Megan. I’ve given them enough information that they can cobble together my username and my password.

The techniques that they do it, with the advent of AI, no longer does the email spoofing look so obvious that we don’t respond to it. They are really savvy in the way that they engage. So if for whatever reason, through social engineering or scams designed to convince this consumer to grant access or give credentials, back to that idea of the device-based authentication, that helps a lot. Because if you send a one-time passcode, even if the fraudster has access to my credentials, they’re not likely to have access to my telephone.

My cell phone will get a one-time passcode, which immediately triggers me as a consumer to go, “Well wait a minute, what’s happening here?” So we’ve seen an uptick in that. The other part that we’ve seen evolve in this area is inbound authentication. So again, using some of the tools that are out there that help authenticate that human being, more than just relying on the credentials that they’ve used to log in. Some of our more savvy partners are actually getting really adept at one of the latest ones that’s come up over the last couple of weeks. I was like, “What is this?” They called it credential stuffing.

Where maybe the fraudster has a certain packet of information, and they keep trying iterations of those credentials, and one of them is likely to click. So they launch a bot attack that comes in, and tries over and over and over and over, and waits for one to click. So there are tools out there now that recognize the volume of bot attacks, and sort of hones in on that. A basic tool that we’ve all used, and maybe we don’t like, but the reCAPTCHA tool that says, “Hey, let’s prove that you’re not a bot.” So whether it’s individual account credentials that somebody tries to use, or this new notion of credential stuffing, of seeing that volume and taking some very foundational steps to address that.

Isio: Yeah, just a personal story. I know my parents were a victim of somebody calling and getting information, and then they were concerned about their bank accounts. But again, the banks that they’re working will be able to make sure they’re authenticating at the right place, and understand something’s out of whack. But a lot of that is all the investments you’re making in the backend, again, to protect that consumer. Let them know while you’re protecting them, because the consumer will look to the bank to do that, and they’ll also blame the bank if they don’t.

Megan: That’s exactly right. That’s exactly right.

Isio: Megan, good information on synthetic and account takeover. So the industry as a whole, they’re fighting fraud on several different fronts. It’s almost like a game of whack-a-mole, right? The fraudsters are emboldened by the speed of digital. Some of the banks feel overwhelmed, especially some of those medium and smaller sized banks. Where do they prioritize, and what types of partners do they seek out? What tools are accessible? What guidance can you give to some of these that feel overwhelmed by everything that’s going on, and just feel like they can’t keep up?

Megan:Yeah, and it is challenging. I know I live and breathe it. I have a team member that focuses on fraud and verification tools, and it seems like there’s a new one entering the market on a daily basis. We encourage our customers to look at first things first. Native capabilities within the platforms, that our customers are using us, but others have this as well. Look at the native capabilities, some basic things like the reCAPTCHA tool, like ask and make sure that that’s part of it. There are thresholds that can be set, system settings that say, “If somebody’s trying to move more than $100,000 into the institution, maybe we don’t want to let them do that in a digital automated way. Maybe we want to put a little bit of a cap on that.”

So encouraging people to look at native security settings, and fraud and risk mitigation capabilities that are native in the platform. Then when you go out to evaluate the tools… We’ve been talking to our customers about this for quite some time, but I marvel at the level of maturity with not just the tools, but how those tools are used. For example, we have some customers that are convinced that running an OFAC check, like is this person on a watch list, are they a bad actor, and know your customer requirements, are actually not a substitute for fraud and verification. That’s sort of foundational.

Then we have other customers that we’ve gone in to talk to, and I liken it to they have belt, suspenders, and a full body cast. They’re running so much that we tend to stop and say, “Okay, well let’s look at the workflow. Let’s look at, is this right sized for a new account, versus someone taking out a loan?” So encouraging the financial institution to really step back and say, “Okay. What do we need to do and when?” Starting with that, know your customer piece, and then the verification. Whether that’s verification of the device, or verification of the identity, verification of the account credentials, some basic things at that point.

There’s a variety of ways to do that. The knowledge-based authentication, where they ask you, name or pick which one of these addresses wasn’t yours, or what was your first car loan? So knowledge-based authentication, the one-time passcodes do some of that. Then we’re actually even talking now to many of our institutions about a portfolio review, so encouraging them to take a look at all of their account holders on a regular basis. Because if you do that, you can start to minimize the friction. Say someone’s logged in and now we’re looking for a car loan.

How do we want to look at the portfolio of your institution’s members, and do it there on a regular basis. Because frankly, that’s a proactive service for the member as well, to say, “Hey, we’re seeing something that doesn’t look quite right.” Prompt them to change their passwords. Prompt them to secure their account in a slightly different way. So we really take people through a progression of that, and really looking at sort of that, “Start here, then this, then that.” I hope, again, that helps to demystify maybe a strategy of how to think about this.

Isio: Yeah, that’s great. One thing I might add on to that too, at BAI here, we’re all about the industry and helping the industry to make better decisions, part of that actually is the community that the industry has amongst each other. So whether it’s roundtables or different forums that they can learn from each other those best practices, whether they’re policies or procedures you talked about. Or whether they’re vendors that they’ve used before that they’ve had better success with, and where they found different issues that maybe they can teach them as they go through it. So part of it is just making sure that they’re not in the loan. We don’t want to just push them out from one to the other. We come together as a community within this industry, and work together to be able to institute some of those best practices. Hopefully, we can stay one step ahead of the fraudsters that way.

Megan: That’s exactly right. I think that’s helpful too. I mean, I will say on this topic more than most, everybody seems to be facing similar challenges. Crowdsourcing approaches, talking to one another about how we combat the fraudsters I think is super helpful. I will say like at our user conference and throughout the year, and having the opportunity to speak with you, I think it’s all important that we look at this holistically. There’s no secret in the fact that we’re all suffering from it, so banding together and figuring out what to do about it is equally important.

Isio:Absolutely. Well, one last question for you, Megan. We talked about it at the top of the program here. We talked a lot about fraud, and what we do to keep the fraudsters out, but sometimes that introduces friction. You talked about some things we can do behind the scenes that are less friction. But there’s some of the banks who are saying, “Listen, again, my consumer is okay with a little bit of friction, and there’s a balancing point here. Especially now, because they’d rather be safe than sorry. So as long as we’re explaining and educating them on why we’re doing certain things, and we’re doing that in their best interests.” But talk to me a little bit, are you finding the same thing in your ecosystem, that a little bit of friction is okay, as long as we’re not going too far and putting up a ton of hurdles that is frustrating the customer?

Megan:Yeah, absolutely. I think that’s where having that well-articulated plan, and thinking through the process from a consumer perspective. Mapping out the entry points. Where are people coming in? How are they coming in? Do we have gaps in that? Understanding where the gaps are, and saying, “Well, wait a minute. If I can accomplish this and this and this and protect myself that way, I can sort of streamline the interaction there.” Then once you’ve kind of gone through that, start building the moat. Start building the moat, but don’t make it too high. Don’t make it too low. I guess one thing that I would leave on this subject of friction is, again, there’s a growing acknowledgement that this is for the consumer safety as much as it is for the institution.

Having that well-articulated plan makes all the difference. At the end of the day, studies have shown… And I’m not going to call it, because many of our partners have written studies on this topic. We actually now are expecting more friction, because we know it protects us. So run the things you can in the background. Engage with the consumer in the right way. Leverage native capabilities where they exist, and communicate to the customer what you’re doing. I will say we’ve gone a step further, and have what we call our digital engagement, consumer engagement tools.

The companies out there in our ecosystem, that will actually measure interactions on a web-based application or a digital application, when they see fall-off, they say, “It looks like a whole lot of people are abandoning applications at this point. What’s happening there?” Using that to then refine the, “Okay. What’s my plan? Where are my gaps? How high did I build my moat? Is there an alternative to doing that?” So not just leveraging the fraud tools themselves, but keeping an eye on the experience using some best-of-breed technologies that are out there as well to do that.

Isio: Gotcha. Yeah. Yeah, a lot going on. Megan, I want to thank you for your time, your perspective. You have a very unique perspective, sitting there between the middle of the FIs and then the solution providers. That’s something that we find interesting, and I’m sure our audience will too. I’m sure there’s going to be lots of changes going on, especially as we go into the new year here coming up pretty soon. But again, this is a great tutorial for our audience about some of the things they should be looking for, as we all are kind of going after this common purpose of stopping the fraudsters and improving the customer experience. Thanks so much for your time.

Megan:  Yeah. Thank you for your time. Yeah, thank you too. I appreciate it. We’ll be back here in six months talking about some new crazy thing they’re doing, and the tools that are created to help prevent it.

Isio:  I’m sure some new terms that are out there too by that time. Thank you.

Megan: Exactly. Thanks everyone.

Related Articles

Login to View This Content

 

Become a member to unlock exclusive content, connect with industry experts, and gain access to valuable resources. If your employer is an institutional member, activate your ProSight membership benefits with a simple email address.