View Full Library

Breakouts

How to Combat Fraud with Data

Let’s face it, fraud sucks and it’s only getting harder to combat. Every step forward we take in the financial industry comes with bad actors trying to warp new technologies for their own gain. Fighting fraud means understanding how it has changed and leveraging data to predict where vulnerabilities will pop up next. In this session, we will discuss the ways fraud has changed and how to use data to defend against it now and in the future.

Transcript

Hi everyone.

I'm Maisie Clark Bilotti.

I'm the Senior Director of Advocacy at MX

and I'll be facilitating today's discussion

of fighting fraud with data.

I think we summarized it well in the

description of this panel.

Fraud totally sucks.

Every technological leap forward in the financial services

space seems to be met with new attempts from bad actors

to exploit those same innovations for their own gain.

Reported losses

to fraud have soared since the pandemic in 2020.

According to the FTC,

consumer fraud losses reached over $12.5 billion in 2024,

which is a 25% increase over the previous year.

Let that sink in. That is a shocking

and horrible rate of change.

And this isn't just large sophisticated heists

that you might think about on, you know,

a movie or something.

This is a widespread issue that impacts millions

of individuals and businesses every year.

The key to staying ahead

of these threats isn't just reacting to them as they happen,

but using data to understand how fraud has changed

and to predict where the next vulnerabilities may occur.

Companies and experts represented on this panel

are developing and deploying advanced tools

and strategies to combat fraud.

And MX is a proud partner to many

of these organizations,

through innovations like Secure Tokenized API connections,

Instant Account Verification

and PFM tools that help customers actually monitor their own

finances for suspicious activity.

Our discussion will focus on three areas.

The first is understanding the

evolution of fraud over time.

The second is learning how we can use data

to defend against it.

And the third is to think about how policy makers might

consider the role of government in fighting fraud.

To guide us through this conversation,

we have an exceptional group of experts,

joining me on stage.

They bring a wealth of experience from different

facets of the industry.

So I'll invite our panelists

to go down the line and introduce themselves.

If you could please tell us your name, your role,

your organization, and perhaps just a sentence

or two of why the issue of fraud is important to you

and why you chose to be on the panel today.

Great. Well, thank you very much Maisie.

Appreciate, MX hosting this panel

and, being able to join it.

My name is Brian Bender. I work with Alloy.

For those who haven't heard of Alloy.

Alloy is a fraud prevention

and identity management platform based in Manhattan.

We serve about 700 financial

and financial institution clients, fintechs, banks,

and credit unions here in North America.

And in EMEA, people, you might wonder

what is the general manager of partner solutions?

So my role is to manage the side of the business.

That is all of the data

and product partnerships that Alloy has prebuilt the API

or SDK connections into our platform so

that our clients don't have to do that.

So, I'm managing all the partnerships from everything

from Alexis, Nexus,

or Socure, all the way through to credit bureau data

and everything in between.

So, very excited to be here today

and talk about the fraud trends.

Obviously Alloy a hundred percent in fraud

prevention, identity management.

So it is core to our everyday mission

to solve for clients.

Good afternoon. I am Zoe Strickland,

a senior fellow at the Future of Privacy Forum,

and I lead their open banking program.

Before that for about my 30-year career,

I led global privacy compliance

for Fortune 10 companies in different industry sectors,

including JP Morgan, Walmart, UnitedHealthcare.

And in those roles I partnered very closely with

global security and anti-fraud measures,

and I actually led the breach response process for each

of those organizations, and I've certainly seen

my share of horror stories.

So very happy to be here to figure out

how we can reduce the fraud risk.

Thank you. Hello everyone. This is Karan Gandhi.

I work at Best Egg.

We are a consumer personal loan lending online platform,

and my role is to ensure that we are giving loans

to the right customers and it's not going on a bad actors.

So I manage the fraud

and verifications for consumer lending.

Hi everyone. I'm Nicole Lauredan. I work at Stripe.

I lead product partnerships covering our consumer product

solutions as well as our payment intelligence,

risk identification, and verification solutions.

So this is very important to me

because I do the product partnerships to ensure

that we're working with the right third party providers in

the ecosystem to bring in the right data signals so

that Stripe can offer solutions to our merchant users so

that they can accurately detect and prevent fraud.

This is very important to me

because I'm actually a victim of fraud myself.

I was scammed by a

real estate agent ad when I was trying to get an apartment

and lost a lot of money by selling it,

sending out a Zelle payment.

And so this is something that's near

and dear to me and very important,

I feel that. I was also very nearly the victim

of having my down payment stolen by an impersonator.

when I was buying a house here in Utah,

USAA caught the transaction,

my husband actually hit send on hundreds of thousands

of dollars and USAA caught it.

So if anyone here is from USAA, heck yeah,

you guys saved my bacon.

We will be customers for life for sure.

So doing a good job in the fraud space drives loyalty,

like truly nothing else.

So definitely carry that with you as you

listen to these conversations.

We're gonna kick off with the question of

how financial fraud has evolved over time

and what the biggest shifts you've seen in

how bad actors operate.

We'll start with maybe the last five years as a window,

and I'll come to you, Brian for that one.

Great.

So five years ago puts us about five months into the

pandemic and, of course the payroll protection program,

PPP came out

and that was a significant driving force for fraudsters.

They're no longer independent of what I would call mom

and pop kind of fraudsters.

These are very well funded enterprises.

Think of a company being funded

by like a venture capitalist,

operating in a sophisticated ecosystem

where there are players that specialize in each part

of the value chain to create fraud, to get the data,

to sell it, and to then, create the fraud itself.

That's part one. I think the second main change

that we've seen is, although some

of the tactics are the same, whether it's phishing

or a synthetic identity approach,

what's happening now is that these players are very powerful

and they can launch these attacks very quickly.

They can create better synthetic identities

and they can do it at scale.

And I think that's the biggest change

that we've seen over the last five years.

Lots of tactical approaches within that,

but I think those are the two main things that we've seen.

Yeah, and Zoe, I wanted to come to you

and ask, I mean, we,

we were just talking about the last five years,

but you've had such a long lens of, you know, 20,

30 years looking at these issues.

What have you seen change over time

and kind of what are your observations on on that long arc?

Oh, Lord, I, I think that

people will all probably say the same, have experienced it.

The fraudsters are very smart

and they're very dedicated to their job,

and they will use every trick

and every technology to steal money from people.

And sometimes, you know,

I was working in privacy office when Hurricane Katrina

happened and people died

and they were trying to steal money from

those families, and they're like, really?

So the motivation is out there

and it really behooves us to figure out

what those attack vectors are and to use technology

and processes and people to counteract

and always be ready, both looking forward

to the latest attack, but also shoring up all your existing

stuff, which creates risk.

Yeah, obviously AI has been a huge topic

of everything we've been talking about here today at the

conference just across the board.

Do you think AI helps in preventing fraud?

How is it empowering fraud studs?

How do we think about sort of the advent

of AI in the space of fraud?

Nicole, I'll come to you on that one.

Yeah, so companies all over the world are using AI

to automate payments functions.

So all types of functions from compliance

to customer communications to payments,

performance monitoring, but most importantly,

and what we're seeing the most in terms of

how industries are using it is for detection and prevention.

Payments is ripe for this opportunity with AI,

because it's rich in data

and micro decisions are being made real time,

it moves very quickly.

And so this is where AI comes in

and becomes very beneficial for companies to be able

to leverage tooling.

The industries that we are saying, seeing really sort

of making strides in this, it's in insurance companies,

SaaS platforms, and then the travel

and hospitality industry.

So for insurance companies,

they're really interested in claims payouts, making sure

that they can validate and verify who the client is.

So they're increasing their machine learning models on the

verification and identity front.

SaaS platforms are really interested in making sure

that they prevent fraudulent actors from onboarding

onto their platform.

They're trying to prevent account stakeholders

and they're looking at fraud patterns tied

to subscription abuse.

And then lastly, for travel

and hospitality, they have high value transactions, right?

This is your booking flights, your booking travel packages,

so increasing their ML signals so

that they can look at patterns of fraud

and stop those payments if they look risky

before they're processed.

So we're seeing a lot of

different users on Stripe's platform really dig in, want

to leverage as much data as they can

to dynamically create the solutions

that are gonna work best for their use cases.

I'll say FreshBooks is an example, DoorDash, right?

They have different models for gift cards

and order checkout for DoorDash

and Stripe's, been able to help them in this case,

create different models for different use cases

and really drive down chargebacks, for example.

Okay, that makes sense. Outside of AI,

what emerging technologies are fraudsters exploiting

to more effectively commit fraud? Brian?

Right, it's

definitely a question we wanna drill into.

I think in addition to the technologies

that they might be using, I think it's important

to always remember the tactics are remaining relatively the

same, the ways that they're trying to create fraud.

And scam folks probably are age old.

And so whether that is trying to have an improved,

document that they're coming up with,

whether it's using other technologies to try

to spoof a device that they're calling in on,

because device intelligence is typically something

that a lot of our clients are starting

to incorporate into detection of fraud

and also being able to replicate behaviors.

And so figuring out ways to get that data

from client machines, whether it's a phone or a laptop

or something like that, so

that they can replicate the swipes

and types, if you will, the swipes and clicks.

So I think those are some of the other kinds of technology.

They aren't necessarily AI-based,

but it's important to note that the AI can be applied

to those other technologies once they get it right.

So once they figure out how to spoof a technology,

then they apply AI on top of that to

make it more powerful

and accelerate how they can take advantage of a

takeover once they're successful.

Yeah, not to overindex on my personal experience,

traumatic as it was, but it just, in that case, they,

you know, imperson they hacked into the email system

of the title company and impersonated the person

that we had been working with,

with one letter difference in the email address,

everything else was exactly as it would appear.

They clearly had been tracking email address, you know,

emails sent between people to

mirror the way it would look, exact dollar amount.

I mean, it's just absolutely wild the level

of sophistication and monitoring that they do.

But it is, that is sort of an old fashioned

attack vector, I mean, at least in the last 20 years.

So it's wild.

So who is targeted

and how are they reach was a question I have for Nicole.

It's us. Along with a lot of other Americans,

it's us and many

other customers.

I'll build on what Brian shared earlier,

like who's getting targeted, how we're seeing

car testing continuing to be the most challenging

fraud vector in payments, right?

And so with AI, fraudsters are using tooling to

create very sophisticated phishing

scams that look very real.

They're setting up fake websites that also look very real,

and then they are capturing all

of these card credentials from customers.

And then to your point, Brian, they have these, you know,

sophisticated tooling that allows them in

very large mass, right?

Go ahead and test all those card credentials

and start attacking customers,

personal customer information and steal money.

This is attacking the customer.

It's also attacking the merchant

that they're impersonating online.

So we're continuing to see from an individual customer

consumer right to a merchant side, everyone is being exposed

as the sophisticated tooling is being created,

and it's just moving very quickly.

It's hard to keep up with the pace of card testing.

It looks like payments transactions alongside

legitimate transactions.

And the fraud vectors are just becoming way more

sophisticated and constantly changing in terms

of strategic approach.

So that's something I would say is top of mind

for Stripe to solve.

Yep. Karan, my next question is for you.

How do you balance a quality user experience

with fraud prevention strategies?

Does one take precedence over the other?

So the short answer is we have

to strike the right balance between what you are

creating friction versus not.

If you're too loose,

then you will have more frauds going through your system.

If you're too tight, you're going

to impact your good customers

and then the conversion rate will go down.

So what we do is we follow a framework.

So first is to be, have a precision in terms of strategy

model or data that you're using to ensure

that you are capturing the highest amount of fraud

or the benchmark that you have, right?

We know that we are not gonna catch all the fraud

because there's an impact to that.

Second is in terms of placement.

So how do you place the friction?

Is it on the upper side of the funnel, the middle

of the funnel, the lower funnel?

That plays a key role in terms of customer journey

and how they are interacting with your process.

I think the third part is in terms

of perception of the customer, right?

For example, one time passcode, right?

Every one of us is now very familiar with it, easy to use,

and it doesn't create any friction

Anymore. Six years down the line.

Or in the past this was considered as a friction.

So you have to understand the customer's

journey where they are.

I think with the MX, that's something

that we are going through, right?

When we ask someone to link the bank account, it's kind

of creating a friction, right?

In some shape and form.

But if you're able to place it in the right place in your

funnel, you're able to extract maximum benefit out of it.

That's what we trying to learn,

you know, how we can do that.

So the short answer is, yeah, it's a

balance that you had to strike.

Yep. Makes sense.

Zoe coming to you for this one.

Where do you think fraud prevention

strategies are falling short?

Do you think it's a technology, process,

or people problem typically, or perhaps all three?

Well, you know, I'm gonna say all three of course, But

I'm gonna start with people 'cause

that's always a common attack vector

and people have talked about it here in each

of the large companies I work for,

the information security folks would do

phishing attacks within the employee community

and they'd even tell them ahead,

is it gonna be happening in the next week?

And it could be the whole population

or the CEO minus one always failures always X

percent are gonna fail.

You can train them all you want and you should train them,

but recognize there's gonna be some vulnerability there.

And so then how do you get technology to help with that?

And I'm really hoping that AI can assist with that

as in a particular example, like

how do you even block those emails from coming through

to begin with, if they can recognize that,

what else can AI do to either prevent the messages

or to address them if people do click a link incorrectly

and then make sure you're up

with the latest updates technology wise.

But like I was saying before,

make sure you're looking at your

weakest parts of your organization.

So one of the largest breaches I had to manage

the company had set up a website

and it was a little tiny website

where they were having a local race.

So it wasn't even very sensitive personal information,

but the bad guys got in there because it was a vendor site

and crawled all the way into the sensitive data.

So how are you monitoring

and using technology to be aware of those risks

on the process front?

Look for breakdowns between systems.

'cause usually when someone upgrades a system,

it might create some breakages that impact

downstream users or anti-fraud efforts.

And also think about what's missing

as the attack vectors change.

What else should you be doing?

Banking community tends

to think of those as controls.

So what processes can you put in place?

Make sure they're meaningful

and make sure they're efficient.

And I would say just overall as a solution, think about

what kind of reports are being generated around this.

Make sure you're challenging the folks

who are working in fraud,

that they're really thinking about the risk correctly.

I think one mistake companies can make is

that they hire smart privacy and security folks

and they go, right, job done.

The smart people will take care of this for us

and wash their hands of it.

And that really isn't the right approach.

They need to be engaged in this like they

are other parts of the business.

And then watch out for the two extremes, right?

If you've got your security

and fraud folks telling you

everything's green, everything's perfect.

I said in one meeting, a hundred page deck,

green, green, green, green, green.

Well, guess what? They missed something.

There was a big breach and they really hadn't highlighted it

and brought the attention to it.

And on the other side, you know, can't be the sky's falling.

Everything is a disaster because people tune you out.

So how are you properly thinking about your risks

and deploying people, processes

and technology to address it?

Always looking ahead

and looking at your weak parts of your organization.

Yep. Brian, anything to add there?

Sure. I would also say they're falling

short on all three areas,

but I'll highlight maybe some different

areas and add on.

I think for technology, what we see as many institutions

are still using static one-time checks

or they are using

some other point solutions

that are not holistically capturing

what fraudsters are doing these days.

Fraudsters are very innovative, they're very fast moving,

and some of the techniques

that may have worked in the past aren't working today,

like they could on like a holistic fraud

prevention platform.

I think on the process side,

I think folks are really trying to have processes in place

to catch, and they've, we're all working on this.

What we see sometimes is that the processes may be siloed.

So you've got a compliance process,

you've got a fraud process,

and you have a credit risk process.

Those three processes may be happening independently

or asynchronously connecting.

What that means is there are gaps in those processes

and of course the fraudsters exploit those gaps.

So the processes really need to be

synchronous working together across all three.

And I think the last piece that I would highlight

around people is what we're just seeing is the fraud teams

are just under-resourced compared to the volume

of fraud that's coming through.

And so, especially if you take the technology

and the process side of that, you know, they need tools

or more people, more training as you just pointed out.

But they also need the tools that can enable them

to really scale their ability to confront

and prevent all the fraud.

Thanks. Related to that question for Nicole.

How do we build fraud strategies

and systems that adapt fast enough to match the speed?

It feels like crimes, you know, online crimes

and criminals always seem to adapt the quickest to the,

a new technology and the rest of the world, is sort

of like in follow mode.

So how do we get there first?

So the answer is data. Data is critical here.

In order to keep up with the pace of the changing vectors,

you have to invest in robust data to solve the problem.

I will put in one little shameful stripe plug.

There is a chance that any card transaction that happens,

92% chance that Stripe has seen

that card transaction at least one time

or that card one time on Stripes network.

So we're able to pull all of

that data right from those transactions,

build them into our ML models

and offer risks, insights, different tooling data

that our users can leverage

to dynamically create different automated tools

that they need to keep up with the pace.

But the reality is each company is going to need

to make their own decisions here.

It's just really important to stay current on the data

that is out there, which companies are moving fast

to keep up with the changing vectors, Brian, your company.

But how do you partner, right?

To bring in the data sets that you need to really automate

and create what is gonna be best suited

for your business problems.

So yeah, I think really data is important.

Okay, thanks. Switching over to our third sort

of bucket of things we wanna cover here.

Zoe question for you, we can kick us off.

What should policy makers

and regulators be thinking about

to be proactive in this space with emerging threats?

Again, policy makers love them, work with them a lot,

sometimes a year

or five behind where we need to be technologically.

How do we help them?

Yeah, and it's interesting particularly in this space

because sometimes they shy away from technology issues

because they don't know it.

Remember the congressman

or senator talked about the internet being a series of tubes

that was fun.

So, but they shouldn't expect to be the top experts.

They're just never gonna be, they're not frontline.

And there are many ways they can still be helpful.

And so for policy makers, yes, be technology agnostic,

but they should also incentivize good

behavior and good relationships.

And they can do things like, okay,

let's require security personnel

and security standards and anti-fraud measures.

And amazingly that's actually not a federal standard

except in a very large sense the crime is bad.

But to actually require companies

to develop programs around it.

And then do things like set accountability.

So like in Open Banking, you know,

once you get the data you should

be accountable to manage it.

And I think if those kind of things were clarified,

that would help some of the liability questions that happen.

And they do need to think about how you balance privacy

and security, which you

and I have talked about, about quite a bit,

which is absolutely as a privacy person,

I wanna protect the data from

inappropriate access even internally.

But you've gotta enable uses

that allow fraud to be combated.

And so they've gotta think through that

and not just sort of

toss it out there and hope for the best.

For regulators, I do think it helps them to think

through how they really are tackling the risk,

which is their role, and not to be chasing nets.

'cause sometimes that happens too, both from

what they write in the regulation or how they enforce it.

And so a story there for, I don't know if everyone

remembers clean desk used to be a big thing.

And of course you don't wanna have confidential data on

your desk, of course you

don't and you should manage that.

But we had an enforcement action,

so the whole company, that's all they did.

And you know, this woman put police tape all over someone's

office who would violate the rules.

But you've gotta put your risk profile in context

and you've gotta really balance your highest

risk and go after those.

And policy makers

and regulators should really help drive that.

And they really should be listening to industry

and consumer groups' voices

because they really can't educate them.

And that's a very appropriate role, I think, for industry

to take to help them understand where it's going,

what kind of fraud we're seeing,

and what role they can have to help reduce it

because the consumer impacts are real and serious.

Yeah, and just to sort of echo

what Brian was saying at the enterprise level

with some underinvestment in staffing

and potentially funding,

I think the government faces a similar issue where they're

multiple departments that have, you know, fraud programs

that are really important and meaningful.

And, I hope that Congress continues to

authorize the important funding that's needed for that.

Moving on to a sort of the wrap up question

for everyone gonna kick it off with Karan,

looking into your crystal ball,

where do you think fraud is going in the next five years?

Where should we be anticipating the most, problems?

Okay, let me ask a question to audience.

How many of you have heard about

Telegram as a Messenger app?

Oh, yes. Alright. And dark web. Yeah.

So there's a lot of information being sold out there.

There are marketplaces out there

where you can buy credit card data

information, BI information.

So she mentioned about using data to combat fraud,

but they have a lot of data to do the fraud as well.

Mm-hmm. So that's one of the things

that is being very easy now to have and access to it.

The tools have become very sophisticated.

That's an easy, so I think what I feel is

that the access to information

that they have has become much more easier.

So you're gonna see a lot of targets happening

because of that and a lot of that is causing that.

Other thing is

what we're seeing is rising bot track, right?

With AI it's easy to spin off a bot

and attack an institute and get information.

So we'll see a lot of bot track going forward.

And that's where we have to be very resilient in terms

of how we tackle bots.

A second is consortium based.

Data sharing is very important as a,

from a fraud perspective because fraud always moves.

So if you're able to share data,

you can prevent fraud at some other places that,

and I think lastly, I feel like we are going

to be in a situation, place five down the line

where people are using AI or AI agents to shop somewhere

or book a restaurant.

Tomorrow they'll be applying

for loans using AI agents.

So we need to figure out who's a good AI agent versus a bad

AI agent, and whom should we allow to apply

for loans or something else.

So I think that's where we'll be going towards

and finding a solution on how to tackle that

on device agents.

Scare me, Nicole, come be

Next. I'll build on

that.

Because where I see it in five years is actually centered

around AI agents and it's going to be for good

and for not good, right?

So on the not good side, agentic commerce is going

to become mainstream.

With that we're going to see an increase in card attacks,

account takeovers, particularly as platforms are trying

to figure out this concept of a global wallet

as more credentials are brought onto these commerce

platforms, how do we make sure right that we stay up

to speed with the fraud vectors

that are gonna come in Agentic commerce.

The second thing is AI agents are actually gonna make our

fraud teams' lives easier, right?

So all the automotive tooling that we have out there,

manual reviews that fraud teens have to do, I think

that's gonna actually improve.

So I see that becoming a good thing.

And then the last thing is with generative AI,

making it very easy for fraudsters to create fake IDs

and profiles and false documents,

it's gonna be really important for companies

to think about the authentication side of this with AI.

How do we think about biometric and pass keys?

What are the next steps to really validate

who merchants and consumers are?

And also knowing your agent, KYA,

is going to be the next thing.

You have to know the agent.

We have to know that if we're sharing data

and permissions with agents, can we trust

that they're gonna do the right things for consumers?

So a lot to come, but I think AI agents

is number one for me.

Yep. Zoe, over to you.

So what I'm gonna say is I've always been in legal

and compliance, so I'm not gonna be the forefront either,

but a huge respect to the people on this panel

who are deep experts.

And if you are in a support role, be that support role, say,

Hey look, how am I learning what these problems are?

How am I helping avoid the separate processes

that aren't speaking to each other

and everyone doing their own separate reporting?

How do you help that? And

that would be extremely valuable for your company.

Brian. I have highly agree with both of

another panelists on their view.

I think know your agent is absolutely one of the main areas

and I'll broaden that out to say the new capabilities

and tools that we're all going to be exploring

to better serve our customers will be the

attack vector in the future.

Plain and simple because they're new,

it's an easier target than some

of these well defended areas that we've

as fraud fighters have all developed.

So I think I would also take it to show as fraud fighters,

an optimistic view going forward.

My company,

my team just in the past week reviewed the 250 solutions

that are connected.

And now I said, how many of those are AI powered?

Turns out over 60%

of those solutions are actively AI powered today,

which is up dramatically over the recent time.

And many of the others are simply tools

that are retrieving data from a discreet

stochastic database, if you will.

And this is across many different areas,

whether it's a fraud risk signal, a credit risk signal,

certainly documentation and picking up on faults

and documents or behavioral or intelligence.

They're really the broad spectrum.

And so the way I see it is the fraudsters are

gonna be out there doing their thing.

That's what they wanna do.

They're not bound by laws or restrictions like we are.

But we have an incredible opportunity as fraud fighters

to continue this level of investment

and apply these new technologies

and new approaches to defeat the fraud going forward.

Awesome. Thank you so much for all these insights.

Very inspiring for me.

As I think about fight, I wanna be a

fraud fighter like you guys.

So I like that term.

We're gonna open it up to questions for the audience.

If you have any questions, don't be shy.

We have one person behind and then then we'll come to

you. Thank you.

So the KYA thing is fascinating.

I'm curious whether, as that matures,

you think there's gonna be a similar dynamic that we saw

with, screen scraping relative to API calls

where like for a while you are gonna have

to separate the wheat from the chafe

because maybe these agents are using

novel new mechanisms to access data

and you don't know which ones are legitimate

and which ones are not.

You want to take that? Yeah. Yeah.

So I think we have to find a device solution,

which is like going to be able to, for you to understand

who's coming to your door, right?

The way one can achieve a,

so from biometric or education.

Like if I can authenticate through my iris or my fingerprint

and say this is a customer that I already know

and that's how I would let this agent now go in, right?

So there has to be device, something like that,

that will help us to authenticate

that this is a my agent versus not

a good agent or something like that. Yeah.

It has to be like persistent 'cause the agent is gonna,

Yeah. Yeah.

So yeah, we allowed to be,

I mean it's still evolving, right?

We are not there yet, so try

to understand like right now we are,

we also have like good bot versus bad bot, right?

So if you have a website, there will be like bots,

like let's say LinkedIn looking at your website

to figure out what job folder do you have.

There's some marketing websites

or looking at content on your website.

You still have capability to understand, you know,

where they're coming from, how, what they're doing.

So you have to keep monitoring that as well to understand

what exactly are they doing, are they gonna hit your funnel,

what kind of IP addresses are coming up.

So those are still the important information that we have,

but this is something that, you know, we will have

for you all as we see more

of those agents coming through our door.

Mary had a question. Yeah. I, oh sure.

Okay. I don't know if this is being looked at at all.

Shout out to Alloy, we use it, I'm at Granite Credit Union.

We love it. You can open an account really fast

and the fraud stuff's great.

Okay, so it would be really cool

if you could see when people log in from the wrong IP

or some bad actor is on an IP when they're trying

to log into people's mobile banking

because either the person's given out their stuff

or it's been taken

because that would actually prevent a lot of fraud.

And I just think about actually many takeover

account style things.

If there was some control like that, they could

more identify those IP addresses and then stop it.

Kind of like card fraud alerts, you know,

I can add a little bit to this.

So yes, IP addresses a very

key piece of information.

We work with many providers.

I would generally classify IP address

as being one data element

included in a device intelligence product, right?

So, a lot of the main providers,

whether it's Centrelink, LexisNexis, Socure, there,

I'm sure there are many others, if they have a device

product, the IP address is taken into account in

that product and is a component

of the score that they'll return.

So I'm happy to go talk to them

and figure out like, you know,

does the institution need the IP address itself

or, you know, what are other ways that they can include

that information in the device

intelligence product that they have?

We can see it after the fact. Yeah.

Where bad dude logged in and all of that,

but I'm just like, wouldn't that be great?

You could be like, no, shut it down. Yeah,

Most of the sophisticated fraud happens, they're able

to master IP address so they can come as close

to a victim by a 0.1 mile.

So there has to be like this mentioned combination

of things that you have

to look into it kind of a flag in the car.

Any other questions? Oh yes, Take one.

As financial institutions add multiple vendors into their

platforms, any thoughts in terms of how do you, you know,

obviously you have your initial authentication,

but as you pass that customer

through those other experiences, how can you inject

and do some checks along the way to make sure that yep,

they still are that right person

or just add another layer of protection.

So talking about the whole ecosystem?

Yeah, I think so. One of the things

that we recommend our customers do is they build sort

of a dynamic system for how to monitor the risk profile

of customers over time, right?

So you wanna make sure that the user experience is not

degraded and that you're not constantly pinging folks

for authentication or I'm gonna text you SMS

or you have to do this passkey or what have you.

You need to build a robust risk profile around the consumer

so that when you see things that you see a fraud pattern

that is off, you know, okay, it's time for us to go ahead

and validate and make sure that this is still the client

or still the customer who we think it is.

So I think the dynamic nature, right,

of creating the tooling to really address the profile

of the customer is really important.

And you have to maintain that

of course over time, to your point.

But I think yeah, that's what we recommend. And

Presumably you're gonna do the same for agents.

Exactly. You have to do the same for agents

and you have to upkeep that over time.

I would add too, every bank has got a vendor management

program, and so making sure that the anti-fraud analysis,

risk scoring, etc., is brought to that team

to make sure that they're looking at it too,

because vendors are definitely a vulnerable

way that bad guys can get to

you.

I think we have time for one more question if anyone has it?

Oh, Eyal, there you go.

Can't Let the agent go.

So.

We have not solved it yet. Yeah.

I expect you to solve it right now.

In the final question of the panel.

Maybe there's no difference at all,

but can you guess

what the differences would be in the way you track a profile

for an agent, like an agent AI versus a human?

Is there a difference

and what might some of those differences be? Yeah,

So let me start with an example, right?

So let's say if you had to apply a loan from, in my name,

it will take time to write Karan Gandhi

because you're not used to typing that name, right?

But if you type your name for an application, you'll be able

to type at a certain speed.

Interesting. Right? So what we do is we track the behavioral

biometric or how are you applying an application?

Are you copy pasting your SSN versus typing it, right?

How much time do you take,

what is the mouse speed that you have?

So all this information is something that we collect

and we try to analyze the pattern out of it.

How often do you hallucinate?

Right? Exactly. So those are the information

that now if an AI agent has to apply that, right,

you are not gonna get all those information.

There's other information

that you'll be getting from an agent

because the machine is coming, there is a type of IDs

that we might get it, there's a different way of how they,

we authenticate those agents. Is there

Like a capture equivalent sort

of thing? So yeah,

so capture right now helps you to stay,

keep the bots away because they have bots cannot go

and take the capture out, right?

There's also passive capture that happens

behind the scene as well.

So we also do that as well.

But yeah, I mean, with AI,

agents capture might not be the solution, right? Yeah.

Like an AI capture.

Yeah. Yeah. I feel like where it'll go is more

of a biometric saying that you are a person

and this is your agent.

It has to be a combination of both for you to go forward

and authenticate someone.

That answer gives me hope.

I thought they were totally indistinguishable

and there was absolutely no way we could ever distinguish

and we were all totally screwed.

So thank you, that does give me hope.

I think we're at time.

So I'm gonna wrap it up.

Thank you so much to the panelists.

This is a really, really great discussion.

Really appreciate it.

Round of applause for our friends here. Thank you.

Speakers

Brian Bender

Brian Bender

General Manager, Partner Solutions, Alloy

Brian Bender is the GM of Partner Solutions at Alloy, the leading identity and fraud prevention platform provider. A 20-year veteran in retail and financial services, Brian is responsible for establishing, growing, and operating the network of over 80 partners and 250 solutions on Alloy’s platform. Brian's expertise lies in data and channel partnerships, global business development, and cross-functional team leadership. His career includes strategic roles at Bain & Company, American Express, Experian, and 1010data.

exit icon
Maisie Bilotti

Maisie Bilotti

Senior Director, Advocacy, MX

Maisie Bilotti is the Senior Director of Advocacy at MX, focusing on financial data policy issues and consumer advocacy. She previously worked for Google for 14 years in a variety of roles including congressional relations, privacy and competition policy, and partnership strategy.

exit icon
Karan Gandhi

Karan Gandhi

Senior Director of Credit Strategy, Best Egg

Karan Gandhi is a seasoned leader in credit strategy, fraud management, and portfolio optimization. Currently serving as the Senior Director of Credit Strategy at Best Egg, Karan spearheads the fraud and verification operations for a wide array of lending products at Best Egg.

exit icon
Nicole Lauredan

Nicole Lauredan

Head of Product Partnerships, Stripe

Nicole Lauredan is an accomplished leader in global partnerships at Stripe, where she leads a team focused on driving innovation across payments, commerce, and risk management. Known for her expertise in product partnerships, Nicole has delivered industry-first solutions, including launching Google Pay’s mobile transportation launches in major global cities and leading Stripe’s partnership with Apple to bring Tap to Pay on iPhone to market. Passionate about increasing diversity in tech, Nicole frequently speaks at various industry events and is deeply committed to mentorship and empowering underrepresented communities. Her leadership earned her recognition as a 2024 ETA 40 Under 40 professional. Nicole's career foundation was built at JPMorgan Chase, where she honed her expertise in strategy, operations, and finance. She holds an MBA from the Tuck School of Business at Dartmouth College and a BA from Brown University. Nicole lives in Los Angeles with her husband, daughter, and dog.

exit icon
Zoe Strickland

Zoe Strickland

Senior Fellow, Future of Privacy Forum

Zoe is a Senior Fellow at the Future of Privacy Forum (FPF). She leads its Open Banking Program, bringing together stakeholders across this complex financial landscape. Over a 30-year career, Zoe served as head of global privacy and other roles for Fortune 20 entities, including in banking (JPMC), healthcare (UHG and Cigna), retail (WMT) and government (USPS). Zoe serves as co-chair for non-commercial entities on the Board of Directors for the Financial Data Exchange. Previously she served on the IAPP Board of Directors, and led the bank subgroup for the Business Roundtable regarding new privacy approaches. Other memberships included: GS-1 privacy workgroup (co-chair); privacy/security subcommittee of the Council for Excellence in Government (co-chair); AHIP Privacy & Confidentiality Work Group; HLC Confidentiality Coalition; RIM Council; RILA privacy/security workgroup; and FPF Advisory Board. Zoe is a frequent speaker at industry events, including keynotes at the 2022 FDX Global Summit, 2016 Executive Women’s Forum, and 2015 IAPP Asia-Pacific conference. She’s been quoted in several media sources like the New York Times, USA today.com, the Economist, and National Public Radio, and has testified at subcommittees of the House Energy and Commerce Committee. FPF is a non-profit organization that serves as a catalyst for privacy leadership, advancing principled data practices in support of emerging technologies. FPF brings together industry, academics, consumer advocates, and other thought leaders to explore the challenges posed by technological innovation and to develop privacy protections, ethical norms, and workable business practices. Through research, publications, educational meetings, expert testimony, and other activities, FPF works with organizations and governments to shape best practices and policies in the United States and globally.

exit icon