Thursday, April 5, 2012

Global Payments Cold War - Heats Up in 2012

There's a technological cold war going on in the global payments space. One that has been bobbing along for over 15 years. But the average Joe is unaware of what's going on "behind the scenes". This battle is for market share, a battle between magstripe, EMV, NFC and now virtual wallets. Naive merchants are saying they're just going to have to wait and see who the winner is before making any major plans. The astute merchant says ALL of these technologies (and likely even more) are going to be here for another 20+ years, and they'll need to support them all. That means PoS systems, and online check-out pages, will continue to evolve like a Swiss Army Knife e.g. I can’t wait to see the first spoon, tweezers, tooth pick or saw hanging off a retailers terminal:)

I feel like 90% of the content shared at mobile conferences today is simply marketing hype intended to fluff up one's personal agenda. But nobody is really looking out for the merchant, and nobody is looking out for the consumer, and nobody seems concerned about the impact on our global economy when proposing total gutting of existing infrastructure with simply different technologies that are essentially unnecessary.

Friday, March 23, 2012

2012 - The year the Payment Paradigm began to shift!

I predict 2012 will be the year we all remember as "the year the payment paradigm began to shift!" Granted Jack Dorsey (founder of Twitter) did launch his ground breaking service (Square) back in May of 2010. Nevertheless, this is going to be the year the mass market will remember and the year consumers began to see relevant products hitting the marketplace from the "big boys", namely: Intuit GoPayments and PayPal Here. And if adoption rates continue to climb at such a rapid pace, we should expect to see many more "thoroughbreds" entering this race this year and next.


Thursday, March 15, 2012

“Mass Market Joe” and “Mass Market Jane”

According to the US Census Bureau 1.4 billion credit cards are circulating here in the US. The Federal Reserve reports that $1.9 trillion is spent on those cards each year. Yet according to Forrester, only 7% of this is spent online. And they forecast by 2016 this percentage will only grow to 9%. The person I call “Mass Market Joe” or “Mass Market Jane” is the consumer who is spending 93% of $1.9 trillion offline. Who are they? I believe they are the consumer who simply does not trust the internet. The 2010 Census found that 80% of US households have a PC connected to the internet, yet 64% of American’s surveyed said they’ve abandoned a shopping cart check-out because they felt the site was either asking for too much information or they had security concerns.

Tuesday, February 21, 2012

The Mass Market Lacks Online Trust

The mass market simply does not trust the internet channel. And why should they? Every day Americans see horror stories in the news of identity theft and credit cards scams orchestrated by high-tech online fraud rings (annual fraud losses have hit the $ billions). http://www.forbes.com/sites/kellyphillipserb/2012/02/20/irs-warns-taxpayers-to-avoid-scams/

Friday, February 17, 2012

GDC Expo, March 7-9

Online sales represents only 7% of total US retail sales. http://techcrunch.com/2010/03/08/forrester-forecast-online-retail-sales-will-grow-to-250-billion-by-2014/. The Federal Reserve reports that credit cards are used more than 20 billion times a year in the U.S., with the total value of these transactions at about $1.9 trillion. A growing majority of Americans 64% report they have not made an online purchase from a specific website because of security concerns. When asked to explain why they did not make that purchase, 60% said it was because they were not sure if the site was secure, 51.4% were worried about providing information requested, and 48.4% felt a website requested more information than was necessary for the transaction. The pool found that 69.3% research potential purchases over the Internet. All this may be spun into good sounding news, but at the end of the day, the bottom line is this - after all our efforts to grow eCommerce it still only represents 7% of the total annual US credit card spend.

Friday, February 18, 2011

Top-3 Mobile Fraud Attack Vectors

1. Stolen Credit Cards: Fraudster buys a new phone using a stolen credit card. Then uses the phones for 30-45 +/- days until the victim spots the fraudulent purchase on their bank statement.

2. Account-Takeover: Fraudsters “hacks” the victims phone account online (phish username::password) so and provisions addition phones on the victims “family” plan. They then use these phones for 30 +/- days until the victim spots the fraud on their cell-phone statement.

3. Corporate Accounts: Same scenario as #2 only this is within corporate accounts, not personal accounts.

Tuesday, June 22, 2010

iDate-West Conference (SLS Hotel, Beverly Hills)

I just attended the iDate-West conference last week down in Los Angles. And anything and everything “mobile” seemed to be hot-hot-hot in the dating and social networking spaces. According to Courtland-Brooks, browsing and application usage on mobile phones have both risen 110% over the past 12mo. And according to Morgan-Stanley, by the year 2014 mobile devices will overtake PCs as the primary device people use to access the web. That really is not that far off into the future…

Monday, March 8, 2010

Proxy Piercing: "to pierce" or "not to pierce"?

Proxy Piercing has an interesting “marketing spin” to it, but it simply means we can acquire a PC’s actual local IP address.

In order to read a PCs local IP address and deliver it reliably back to your own servers you must execute some native code on the PC e.g. Java applet, a toolbar, or an application which will then send that IP Address back to your own servers using a TCP/IP or UDP socket connection, by-passing the HTTP data stream being sent through the proxy server. This is because all IP addresses that are passed within the x-forwarded-for string will be scrubbed (deleted) by the proxy. Alternate methods for transferring an IP address “transparently” might include methods of encrypting the IP Address using JavaScript or ActionScript into some target data field on the PC that will be transmitted within the HTTP stream’s user-agent-string. But since a “smart” proxy is going to re-write ALL of the attributes within the user-agent string, your encrypted IP data is simply going to get dropped on the floor, and lost! So this fraud management technique comes with challenges.

But is knowing the actual PC’s IP address ultimately beneficial for fraud management? If it was possible to reliably acquire the IP Address transparently (and it’s not a unroutable IP address) the answer is going to be yes only sometimes, and its usefulness is going to be temporary at best. Because, as you probably know, IP addresses are not “owned” by a PC. They are not like license plates assigned to an automobile by the DMV. IP addresses are extremely temporary, assigned by an ISP for a real-time connection. But they can be re-cycled as frequently as every time the user reboots their router e.g. possibly everyday. And when another PC is re-assigned an IP address that you have put on your block-list, then you will introduce a false-positive potentially blocking a good customer. Also if a PC is sitting behind NAT (network address translation) firewall then the PC itself will have an unroutable “local” IP Address e.g. in the range of 192.168.xxx.xxx or 10.x.x.x etc., which will basically tell you nothing.

What I have found in my experience to be the most effective fraud management technique relating to IP Addresses and their subsequent geolocation is to monitor for suspicious activity generated by the use of a proxy server, that is what will be most telling. I look for suspicious velocity changes in geolocation that is the actual result of a fraudster’s activity while using an anonymizing proxy for fraudulent and abusive objectives.

Monday, November 16, 2009

PhoCusWright Conference 2009

Are you going to the PhoCusWright Conference? If yes, then come attend my workshop on fraud http://www.miamiherald.com/business/press-releases/travel/story/1336006.html

Monday, October 12, 2009

Well I’m sitting here at SFO waiting for my flight. This is always a fun place to sit with my headphones on and doing fraud investigations; because, I’m always glancing up wondering, “have any of these people been caught by our system before?”

Thursday, April 2, 2009

[Criminal Diversification, Repeat Offender in 2005 (Part 1 of 4)

Back in 2005, most of the online fraud and abuse that I saw committed was from what I’d call the “repeat offender”. This is the case where the individual perpetrator is working alone to repeatedly defraud or scam a target online business. This perpetrator might purchase or steal victim’s identity or credit card and then use this data to repeatedly make purchases or commit online abuses. Once a particular “virtual” identity is flagged, caught or stopped, the perpetration then simply moves on to use another identity from his spreadsheet. This is what I saw back in 2005.
Next week’s topic: Criminal Diversification, Fraud Rings Develop in 2006 (Part 2 of 4)

Thursday, September 4, 2008

[Fraud Series: Topic 4] Fraudsters are no longer showing site loyalty

I’ve been analyzing the online behavior patterns of criminals for about 4 years now. When I first started, the criminals were clearly “specialists” targeting a particular vertical market with their organized crime operations, e.g., online gaming, Internet dating, eCommerce, or financial institutions. They would craft their schemes to specifically exploit a victim Web site until they got caught. Then, they would simply shift their focus over to the next Web site with similar vulnerabilities in that same vertical market.

However, more recently I’ve been noticing fraud rings crossing over vertical markets and perpetrating their crimes/scams simultaneously upon multiple Web sites. I’ve seen, for example, criminals who have been committing Internet dating scams now moving into other vertical markets like eCommerce. In one case, a fraudster was buying “items” at an online jewelry site using a stolen credit card. Simultaneously, he/she was creating accounts on an Internet dating site, paying for their subscription using a stolen credit card.

Conclusively, fraudsters are “diversifying” their operations and committing various forms of fraud across a spectrum of vertical markets in order to increase their return on investment. However, I do still see the “old school” fraudsters sticking it out within the same vertical and focusing their efforts to try and overcome deployed fraud prevention tools within that vertical market.

My advice is simply this: don’t limit yourself to fraud strategies specific to one vertical market. The most effective fraud strategies today are the ones that leverage fraud intelligence collected from across the Internet, not just a subset community.

Thursday, May 22, 2008

[Fraud Series: Topic 3] Credit Card Phone Scam

This isn’t an online fraud, per se, but since both ANI/MIN/CLID spoofing and credit card frauds are current topics of discussion, I thought you’d find this interesting (if only for your own personal protection). The following is an example of both a credit card scams to collect from me all of my key credit card information so the criminal could use my card to purchase stuff online, via ANI/MIN/CLID spoofing (making the caller-ID be some other number) .

I just received a phone call on my cell phone (from a Voice Response Unit-VRU) with a caller-ID number of 321-504-7429. The recorded message said…

“This is your final notice to lower the interest rates on your credit card…blah blah blah…please select 1 to lower your rates now…blah blah blah”. I hung up, as should you!

Notes/Warning Signs:

  1. There was no indication for which bank it was calling me (I actually have 3 credit cards from 3 different banks).
  2. There was no authentication for who the credit card actually belongs to e.g. they might have said my name so I know it’s me their looking for.
  3. They called my work cell phone, which was likely taken off my business card picked up from one of our show booth tables. I NEVER use my business cell phone for credit card accounts.
  4. After I hung up I dialed the number back, and as expected it said, “The number you are trying to reach has been disconnected and is no longer in service.”

Thursday, February 7, 2008

[Fraud Series: Topic 2] Stolen Credit Cards

There isn’t much I can add to the discussion on the topic of criminals using stolen credit cards to make purchases online. I could talk about various methods used to catch them. However, this week what I thought would be interesting is to comment on the relationship developing between “Easy Identity Theft” and the fraudulent usage of credit cards.

Like many Americans, I used to think that the only way a criminal could use someone’s credit was to steal the plastic card, or at minimum steal the numbers and CVV off of it, to make fraudulent purchases. But now, as I discussed last week, I know that this is not the only use case. In fact, more and more people are starting to fall prey to criminals acquiring their personal information and then applying for credit cards on their behalf. In this scenario, the victim may or may not receive the invoice for the credit card. If they do, they are left with protesting and deactivating this account, if not it could go completely undetected and have lasting consequences.

This is one of the most common uses of identity theft and potentially has the most adverse impact, because unlike a fraudulent charge to your credit card, which most often is credited back to your account, a fraudulent credit application may go undetected and can negatively impact your credit rating for years.

Next blog [Fraud Series: Topic 3] Advanced Fee Frauds

Tuesday, January 8, 2008

[Fraud Series: Topic 1] Easy Identity Theft

I used to think it was very difficult to steal "good" identity information. But after a little research, I have learned it's really very easy!

CASE 1: Criminals simply drive into any community that re-cycles and pick up the bags left at curbside. This is nice, clean, paper (no smelly garbage mixed in it). The criminals instantly get the "victims" address (it's on the envelopes) , and all they need to do now is search through the papers for names, telephone numbers, bank account #'s, social security #'s...you name it, it's in there!

CASE 2: Criminals go to any domain name registrar (like www.godaddy.com) and purchase a seemingly legitimate URL, something like "www.californiarefinance.org". And if they're not a programmer, then they'll simply go visit an existing bank's web-sites and copy their pages. Using a tool like Adobe's DreamWeaver they can quickly build a "fake" web-site for their fake business. Now they're ready to apply at a search engine, pay top dollar for the best home mortgage refinance search terms, such as:"refinance", "mortgages" etc. to link to their new domain name. Finally, real victims come willingly to visit their web-site. The victim enters page after page of personally identifiable information, which is then immediately stored in a database. The victim might be told they will receive an email notification regarding the status of their application (but they either never get the email, or the email simply says, "I'm sorry, your application has been declined."). Either way, the criminal now has the victims very good identity info.

In both of the above cases, the criminal can use your information and apply directly online for credit cards, on your behalf.

Next week's [Fraud Series: Topic 2] Stolen Credit Cards.

Friday, December 28, 2007

Goodbye 2007...Hello 2008

Over the holiday break, I found myself repeatedly explaining to both friends and family the difference between identity based fraud management tools and device-reputation based fraud management tools (I know, I know...who'd have thought this could be a "hit" ice-breaking topic at a holiday party?). But when people ask me, "so, what do you do?", and I say, "I stop identity theft and stolen credit cards." They immediately want to know, how can they protect themselves, including my father-in-law?

My father-in-law uses a MAC and I use a Windows tablet PC. As I stood there this morning looking down at our respective machines, I suddenly realized that after 20 years of having a relationship with him either one of us could positively identify the other one out on any street corner. But then I suddenly felt a growing sense of vulnerability; only 2-mouse clicks away (out in the virtual internet world) either one of us could so easily become the other one and nobody would be the wiser! We each know enough about the other, or have easy access to the personal documents (like wallets, drivers licenses, passports etc.), that the only thing standing in the way of such a crime, and is protected us one from the other, is the combination of personal ethics and mutual "trust".

But as I recall looking around the living room of various holiday parties this year, I suddenly realize that there were many people there neither my wife nor I even knew. Meanwhile, our coats and her purse lie in wait, amidst a mountain of other coasts and purses pilled high onto our hosts bed. I know I trust my close friends and family, but what about all these other people, the ones we are calling friends of friends of friends? How protected am I, online ??

Thursday, November 15, 2007

ItsMyMarket.com (UK) WARNS about Scams

While I've been holding off posting my own list of common frauds, mainly because I haven't decided how to best organize them in a blog, here are some links to other fraud lists....enjoy!

http://www.itsmymarket.com/scams/common.php
(UPDATED) http://www.lookstoogoodtobetrue.com/fraud.aspx

Friday, November 9, 2007

iovation - Intel Capital - TheFraudKahuna

Yesterday, iovation (Portland, OR - U.S.A.) announced that they have partnered with Intel Capital, who has made an initial $10M investment in the company's fraud management solution.

iovation IS NOT simply a "device printing" company, rather, it uses "device recognition" as one of many design components within their Device Reputation Authority.

Beyond fraud management, iovation's manypending patents are designed to protect its IP (intellectual property) in and around what they call "Device Reputation". In today's vernacular, "device" = "PC", or PDA, or mobile phone, or Xbox, can be virtually anything which is used to access the internet. Eventually, when IPv6 becomes more universally deployed, a device will likely refer to anything with built in electronics, such as, automobiles, televisions, even refrigerators. The reputation of a device is not only us asking the question, "has this PC been used to commit online fraud?" But is also us asking the question, "has this PC been used for email spamming, chat abuse, and other sorts of unwanted online behaviors?"

NEWS LINKS
http://www.bizjournals.com/portland/stories/2007/11/05/daily21.html
http://home.businesswire.com/portal/site/home/index.jsp?epi_menuItemID=887566059a3aedb6efaaa9e27a808a0c&ndmViewId=news_view&ndmConfigId=1000017&newsId=20071108005370&newsLang=en
http://www.redherring.com/Home/23128
http://news.google.com/news/url?sa=t&ct=us/0-0&fp=4734e0a5f545a105&ei=ljw0R9PLDZveqwPcsNTrAQ&url=http%3A//www.redherring.com/Home/23128&cid=1123328964&sig2=rCRFk67zoOzDmtFFXKZgVQ

Wednesday, October 31, 2007

NCFTA...more help is on it's way!!!

I recently visited the guys at NCFTA. Check out their web-site at www.ncfta.net. This is a new organization focused on the exchange of intelligence data. I fully support their charter. In their own words...

The National Cyber-Forensics and Training Alliance provides a neutral collaborative venue where critical confidential information about cyber incidents can be shared discreetly, and where resources can be shared among industry, academia and law enforcement.

The Alliance facilitates advanced training, promotes security awareness to reduce cyber-vulnerability, and conducts forensic and predictive analysis and lab simulations.

Thursday, October 11, 2007

Do you know where your PC has been?

I was looking at a device the other day (PC) in our database. It had been flagged with repeat counts of identity theft in 1 particular vertical market. I then looked at the other markets this PC has visited. What I found interesting was this: although they have been repeatedly flagged for identity theft in the target market, but at the same time, they have been flagged with no fraudulent activity in any other markets; they appear to be "good" citizens in other community while a "bad egg" in the other.

Has anyone else seen this sort of profile by fraudsters?