Tag: fraud

Generative AI Adoption and Impact on Fraud

"Grandma, it’s me, Mike.” Imagine hearing the voice of a loved one (or what sounds like it) informing you they were arrested and in need of bail money. Panicked, a desperate family member may follow instructions to withdraw a large sum of money to provide to a courier. Suspicious, they even make a video call to which they see a blurry image on the other end, but the same voice. When the fight or flight feeling settles, reality hits. Sadly, this is not the scenario of an upcoming Netflix movie. This is fraud – an example of a new grandparent scam/family emergency scam happening at scale across the U.S. While generative AI is driving efficiencies, personalization and improvements in multiple areas, it’s also a technology being adopted by fraudsters. Generative AI can be used to create highly personalized and convincing messages that are tailored to a specific victim. By analyzing publicly available social media profiles and other personal information, scammers can use generative AI to create fake accounts, emails, or phone calls that mimic the voice and mannerisms of a grandchild or family member in distress. The use of this technology can make it particularly difficult to distinguish between real and fake communication, leading to increased vulnerability and susceptibility to fraud. Furthermore, generative AI can also be used to create deepfake videos or audio recordings that show the supposed family member in distress or reinforce the scammer's story. These deepfakes can be incredibly realistic, making it even harder for victims to identify fraudulent activity. What is Generative AI? Generative artificial intelligence (GenAI) describes algorithms that can be used to create new content, including audio, code, images, text, simulations, and videos. Generative AI has the potential to revolutionize many industries by creating new and innovative content, but it also presents a significant risk for financial institutions. Cyber attackers can use generative AI to produce sophisticated malware, phishing schemes, and other fraudulent activities that can cause data breaches, financial losses, and reputational damage. This poses a challenge for financial organizations, as human error remains one of the weakest links in cybersecurity. Fraudsters capitalizing on emotions such as fear, stress, desperation, or inattention can make it difficult to protect against malicious content generated by generative AI, which could be used as a tactic to defraud financial institutions. Four types of Generative AI used for Fraud: Fraud automation at scale Fraudulent activities often involve multiple steps which can be complex and time-consuming. However, GenAI may enable fraudsters to automate each of these steps, thereby establishing a comprehensive framework for fraudulent attacks. The modus operandi of GenAI involves the generation of scripts or code that facilitates the creation of programs capable of autonomously pilfering personal data and breaching accounts. Previously, the development of such codes and programs necessitated the expertise of seasoned programmers, with each stage of the process requiring separate and fragmented development. Nevertheless, with the advent of GenAI, any fraudster can now access an all-encompassing program without the need for specialized knowledge, amplifying the inherent danger it poses. It can be used to accelerate fraudsters techniques such as credential stuffing, card testing and brute force attacks. Text content generation In the past, one could often rely on spotting typos or errors as a means of detecting such fraudulent schemes. However, the emergence of GenAI has introduced a new challenge, as it generates impeccably written scripts that possess an uncanny authenticity, rendering the identification of deceit activities considerably more difficult. But now, GenAI can produce realistic text that sounds as if it were from a familiar person, organization, or business by simply feeding GenAI prompts or content to replicate. Furthermore, the utilization of innovative Language Learning Model (LLM) tools enables scammers to engage in text-based conversations with multiple victims, skillfully manipulating them into carrying out actions that ultimately serve the perpetrators' interests. Image and video manipulation In a matter of seconds, fraudsters, regardless of their level of expertise, are now capable of producing highly authentic videos or images powered by GenAI. This innovative technology leverages deep learning techniques, using vast amounts of collected datasets to train artificial intelligence models. Once these models are trained, they possess the ability to generate visuals that closely resemble the desired target. By seamlessly blending or superimposing these generated images onto specific frames, the original content can be replaced with manipulated visuals. Furthermore, the utilization of AI text-to-image generators, powered by artificial neural networks, allows fraudsters to input prompts in the form of words. These prompts are then processed by the system, resulting in the generation of corresponding images, further enhancing the deceptive capabilities at their disposal. Human voice generation The emergence of AI-generated voices that mimic real people has created new vulnerabilities in voice verification systems. Firms that rely heavily on these systems, such as investment firms, must take extra precautions to ensure the security of their clients' assets. Criminals can also use AI chatbots to build relationships with victims and exploit their emotions to convince them to invest money or share personal information. Pig butchering scams and romance scams are examples of these types of frauds where AI chatbots can be highly effective, as they are friendly, convincing, and can easily follow a script. In particular, synthetic identity fraud has become an increasingly common tactic among cybercriminals. By creating fake personas with plausible social profiles, hackers can avoid detection while conducting financial crimes. It is essential for organizations to remain vigilant and verify the identities of any new contacts or suppliers before engaging with them. Failure to do so could result in significant monetary loss and reputational damage. Leverage AI to fight bad actors In today's digital landscape, businesses face increased fraud risks from advanced chatbots and generative technology. To combat this, businesses must use the same weapons than criminals, and train AI-based tools to detect and prevent fraudulent activities. Fraud prediction: Generative AI can analyze historical data to predict future fraudulent activities. By analyzing patterns in data and identifying potential risk factors, generative AI can help fraud examiners anticipate and prevent fraudulent behavior. Machine learning algorithms can analyze patterns in data to identify suspicious behavior and flag it for further investigation. Fraud Investigation: In addition to preventing fraud, generative AI can assist fraud examiners in investigating suspicious activities by generating scenarios and identifying potential suspects. By analyzing email communications and social media activity, generative AI can uncover hidden connections between suspects and identify potential fraudsters. To confirm the authenticity of users, financial institutions should adopt sophisticated identity verification methods that include liveness detection algorithms and document-centric identity proofing, and predictive analytics models. These measures can help prevent bots from infiltrating their systems and spreading disinformation, while also protecting against scams and cyberattacks. In conclusion, financial institutions must stay vigilant and deploy new tools and technologies to protect against the evolving threat landscape. By adopting advanced identity verification solutions, organizations can safeguard themselves and their customers from potential risks. To learn more about how Experian can help you leverage fraud prevention solutions, visit us online or request a call

August 24, 2023 by Alex Lvoff, Janine Movish
Money Mule Fraud

Money mule fraud is a type of financial scam in which criminals exploit individuals, known as money mules, to transfer stolen money or the proceeds of illegal activities. Money mule accounts are becoming increasingly difficult to distinguish from legitimate customers, especially as criminals find new ways to develop hard-to-detect synthetic identities. How money mule fraud typically works: Recruitment: Fraudsters seek out potential money mules through various means, such as online job ads, social media, or email/messaging apps. They will often pose as legitimate employers offering job opportunities promising compensation or claiming to represent charitable organizations. Deception: Once a potential money mule is identified, the fraudsters use persuasive tactics to gain their trust. They may provide seemingly legitimate explanations like claiming the money is for investment purposes, charity donations or for facilitating business transactions. Money Transfer: The mule is instructed to receive funds to their bank or other financial account. The funds are typically transferred from other compromised bank accounts obtained through phishing or hacking. The mule is then instructed to transfer the money to another account, sometimes located overseas. Layering: To mask the origin of funds and make them difficult to trace, fraudsters will employ layering techniques. They may ask the mule to split funds into smaller amounts, make multiple transfers to different accounts, or use various financial platforms such as money services or crypto. Compensation: The money mule is often promised a percentage of transferred funds as payment.  However, the promised monies are lower than the dollars transferred, or sometimes the mule receives no payment at all. Legal consequences: Regardless whether mules know they are supporting a criminal enterprise or are unaware, they can face criminal charges. In addition, their personal information could be compromised leading to identity theft and financial loss. How can banks get ahead of the money mule curve: Know your beneficiaries Monitor inbound paymentsEngage identity verification solutionsCreate a “Mule Persona” behavior profileBeware that fraudsters will coach the mule, therefore confirmation of payee is no longer a detection solution Educate your customers to be wary of job offers that seem too good to be true and remain vigilant of requests to receive and transfer money, particularly from unknown individuals and organizations. How financial institutions can mitigate money mule fraud risk When new accounts are opened, a financial institution usually doesn’t have enough information to establish patterns of behavior with newly registered users and devices the way they can with existing users. However, an anti-fraud system should catch a known behavior profile that has been previously identified as malicious. In this situation, the best practice is to compare the new account holder’s behavior against a representative pool of customers, which will analyze things like: Spending behavior compared to the averagePayee profileSequence of actionsNavigation data related to machine-like or bot behaviorAbnormal or risky locationsThe account owner's relations to other users The risk engine needs to be able to collect and score data across all digital channels to allow the financial institution to detect all possible relationships to users, IP addresses and devices that have proven fraud behavior. This includes information about the user, account, location, device, session and payee, among others. If the system notices any unusual changes in the account holder’s personal information, the decision engine will flag it for review. It can then be actively monitored and investigated, if necessary. The benefits of machine learning This is a type of artificial intelligence (AI) that can analyze vast amounts of disparate data across digital channels in real time. Anti-fraud systems based on AI analytics and predictive analytics models have the ability to aggregate and analyze data on multiple levels. This allows a financial institution to instantly detect all possible relationships across users, devices, transactions and channels to more accurately identify fraudulent activity. When suspicious behavior is flagged via a high risk score, the risk engine can then drive a dynamic workflow change to step up security or drive a manual review process. It can then be actively monitored by the fraud prevention team and escalated for investigation. How Experian can help Experian’s fraud prevention solutions incorporate technology, identity-authentication tools and the combination of machine learning analytics with Experian’s proprietary and partner data to return optimal decisions to protect your customers and your business. To learn more about how Experian can help you leverage fraud prevention solutions, visit us online or request a call

August 14, 2023 by Alex Lvoff, Janine Movish
Experian’s 2023 Identity and Fraud Report

Experian's identity and fraud report explores the evolving fraud landscape and influence on identity, the consumer experience, and business strategies.

July 5, 2023 by Guest Contributor
Amid Banking Uncertainty, Fraudsters Strike

By leveraging an array of tools and technologies, businesses can tailor their fraud prevention strategies to suit the specific needs of their customers.

June 13, 2023 by Guest Contributor
Experian CrossCore® Recognized as an Overall Leader by KuppingerCole

CrossCore named Overall Leader, Product Leader in Fraud Reduction Intelligence Platforms, Innovation Leader and Market Leader in Fraud Reduction..

May 26, 2023 by Guest Contributor
Fraud Risk Management Strategies

As organizations look for ways to keep themselves and the consumers they serve safe in the digital era, many turn to fraud risk mitigation.

April 19, 2023 by Guest Contributor
How Does the Economy Impact Fraud Trends?

There’s an undeniable link between economic and fraud trends. During times of economic stress, fraudsters engage in activities specifically designed to target strained consumers and businesses. By layering risk management and fraud prevention tools, your organization can manage focus on growing safely. Download infographic Review your fraud strategy  

March 22, 2023 by Guest Contributor
Experian’s 2023 Future of Fraud Forecast

Experian's 2023 Future of Fraud Forecast examines rising threats impacting businesses and consumers and how best to combat them.

February 1, 2023 by Guest Contributor
Fraud Mitigation: Best Practices for the Digital Economy 2.0

Fraud mitigation is an ongoing process to identify suspected fraud quickly and manage any fallout without increasing risk.

September 19, 2022 by Chris Ryan
Future of Fraud Forecast: Digital Elder Abuse Fraud Will Rise

Financial elder abuse fraud occurs when someone illegally uses a senior’s money or other property. Previngting it requires a robust fraud solution.

September 15, 2022 by Guest Contributor
Fraudsters Playing the Long Game with Synthetic Identity Fraud

Between social unrest across the globe, the lingering pandemic, and the digital transformation brought on by the health crisis, the fraud landscape has expanded dramatically for businesses and consumers alike. According to Experian’s latest global identity and fraud report, 93% of U.S. companies have mid-to-high concern for fraud, and 81% say that their worries about fraud have increased over the past 12 months. Monitoring unused or dormant accounts for fraud is often a warning directed at consumers. However, it’s now advice an increasing number of businesses are wishing they’d followed, as growing synthetic identity (SID) fraud is fueling a dramatic increase in losses—SID related charge-offs ballooned to $20 billion in 2021 alone, according to the Federal Reserve Bank of Boston. The threat of SIDs SIDs are made to look like an actual consumer, combining both real and fake data to form a new composite identity. They typically evolve using a combination of tactics that include: Identifying and creating relationships with businesses that have a high tolerance for identity discrepancies. These include businesses whose products expose the business to low fraud risk and/or products offered to market segments where identity verification is expected to be challenging. Either of these enable an SID to be planted among consumer data sources. Attaching the SID to existing accounts and relationships that belong to other consumers. Often these existing accounts were established by collusive criminals or by using other SIDs, but there are also ways for legitimate consumers to collect ‘rent’ in exchange for adding other consumers to existing accounts. Either approach improves the SID’s appearance of credit worthiness. Progressively building the SID’s independent ability to access larger and larger amounts of credit until they spend quickly and default on all obligations, leaving no one for the victimized businesses to pursue. “They’re difficult to identify because of the combination of real and fake data and because there’s no actual victim reporting an identity theft. As a result, businesses typically have trouble separating SID losses from credit losses,” said Chris Ryan, Experian’s go-to-market lead for fraud and identity. “SID fraud isn’t committed haphazardly.  It’s carefully planned and executed—and it adapts to policy changes. Some businesses change their underwriting policy or focus on early-lifecycle account activity like purchases, payments, and requests for additional credit to reduce SID losses that occur immediately after an account is opened. SIDs can adapt to this. If six months of responsible account behavior earns a credit line increase or the ability to spend large amounts in a single billing cycle, the perpetrators are willing to wait,” Ryan said. “It’s something businesses and lenders need to be on guard for, especially with the fast-paced holiday shopping season ahead,” he said. Addressing SIDs Solving the increasingly complex problem of SID fraud requires a thoughtful approach. The institutions seeing success at preventing multi-faceted fraud are using a layered approach to identifying and mitigating fraud. Here are three steps lenders can take today to prevent SID fraud across your portfolio: Use data and analytics that extend beyond credit to evaluate identities and their histories more completely. Apply those analytics across the lifecycle from marketing and origination to portfolio management recognizing that SID risk is not restricted to a single lifecycle stage. Have a rigorous verification process that escalates to document verification or the Social Security Administrations Electronic Consent Based SSN Verification (eCBSV) process For more information on how you can leverage a multi-layered approach to fraud in your business, visit our fraud and identity solutions hub or request a call to discuss customizing a solution for your company.

September 14, 2022 by Jesse Hoggard
The Future of Fraud: Caught in a Bad Romance (Scam)

Reports of romance scams have spiked in the past two years, partly due to the rise in popularity of online dating and social apps while Americans were isolated at home. With more consumers looking for love online, fraudsters have jumped on the chance to build intimate, trusted relationships without the immediate pressure to meet in person. And these shams seemingly paid off: from January 1 to July 31, 2021, the Federal Bureau of Investigation (FBI) Internet Crime Complaint Center received over 1,800 complaints related to an online romance scam, resulting in losses of approximately $133 million. These romance scams carry financial and security risks that impact both the targets of the fraud and the businesses with which they interact. Experian predicts that romance scams will continue to rise in 2022, leaving consumers and businesses vulnerable to attacks and theft. What is a romance scam? According to the FBI, a romance scam occurs when “a criminal adopts a fake online identity to gain a victim's affection and trust." Typically, fraudsters seek out their marks in dating or socializing settings, such as online apps, and strive to build intimacy and trust as quickly as possible. To avoid suspicion, they may claim that they travel frequently for work or give other excuses about why they can't meet in person. Their attentions are in the context of love and dating, so it's not uncommon for romance scammers to offer marriage proposals or other commitments to intensify the relationship, but the whole point of this fraud is to get their targets to send money. Sometimes fraudsters simply ask for a “loan" to cover medical expenses, an unforeseen shortfall or even travel costs to see the victim in person. Other times, they might ask for gifts or gift cards. Requests for money ­– whether through direct deposit, gift cards or credit card payments – are all red flags. Increasingly, romance scammers have tried to lure people into investment deals, including cryptocurrency. Romance scams predate the internet by centuries, but the emergence of digital technologies has made them easier to accomplish – and easier to get away with, too. Romance scams are increasing In 2020, there were around 44 million users of online dating services in the United States and this increased to 49 million users in 2021, according to Statista Research Department. By 2022, two years into the COVID-19 pandemic, that number jumped to more than 50 million, and it's projected to rise to 53.3 million by 2025. More users mean more potential targets. According to the Federal Trade Commission (FTC), romance scams hit a record high in 2021, with consumers reporting $547 million in losses that year ­– up 80 percent from 2020. The median individual loss reported to the FTC from romance scams was $2,400. With the help of modern technologies, romance scammers have added new tactics to their grift. For example, in addition to usual requests for money, a target might be asked to participate in bogus investment schemes involving cryptocurrency. In these cases, the median loss was $10,000. According to the FTC, romance scammers have conned Americans out of an estimated $1.3 billion over the past five years. Worryingly, romance scams also present a serious data risk. Damage could spread beyond financial losses into even more hazardous territory if the scammer can gain access to a target's personally identifiable information (PII) or financial data. In these cases, fraudsters might engage in identity theft to create new accounts or take over existing ones. Breaking up with romance scammers Businesses may not be susceptible to the lure of love, but they're still vulnerable when it comes to the fallout from romance scams. Companies must ensure they have a layered solution that seamlessly recognizes returning customers, while monitoring for indicators that the user presenting an identity is not actually the owner of that identity. Some warning signs include logins from a new IP address nowhere near the user's registered physical address; unusual types or frequencies of transactions; and the addition of a suspicious new authorized user to a credit card account. Businesses also have access to fraud prevention help. Using vast data resources, decades of identity and credit risk management, consumer-permissioned data and industry-leading analytics, Experian enables businesses to detect and prevent fraud by identifying credible customers. This empowers businesses to apply the appropriate amount of friction to each interaction to protect their customers, their data and themselves. To learn more about how Experian is assisting businesses with their fraud prevention efforts, visit us or request a call. And keep an eye out for additional in-depth explorations of our Future of Fraud Forecast. Future of Fraud Forecast Fraud Prevention

August 18, 2022 by Guest Contributor
State and Local Agencies Shift to Digital Modernization

Experian’s identity, verification, and fraud solutions can help government agencies of all sizes on their journey to digital modernization.

August 4, 2022 by Guest Contributor
Three Key Tips for Increasing Payment Authorization Rates

Online transactions face a higher chance of being declined because face-to-face transactions come with a higher degree of confidence. Businesses who fail to address this problem run the risk of losing the customer permanently, damaging their reputation and bottom line. What can e-commerce marketplace merchants do to increase the approval rate of online payments without making fraud worse? Here are three tips: 1. Broaden access to data beyond what’s in the authorization stream. Merchants use a variety of solutions to prevent fraud and verify identities, but typically use very limited data to approve a transaction through the authorization stream between a merchant and issuer. The issuing bank often only compares the purchase data to the address listed on the card owner’s account, which can create discrepancies when a customer is trying to send an order to an alternate address from their primary home. That’s why it’s important for merchants to augment their decisioning with additional data sources to help inform the true customer risk profile. 2. Leverage capabilities that can assess risk for both the transaction and the individual behind it. Today, merchants leverage limited data including email address data, device information and other technologies in silos to augment their address verification capabilities. The challenge with these tools is that each judge the risk of a specific component of the transaction or the individual. Where integration is lacking, false positives are amplified. 3. Collaborate and share expertise and data across merchants and issuers. How can Experian help? Leveraging our multidimensional data, technical expertise and advanced analytics capabilities, we can help businesses frictionlessly authenticate valid customers, thus increasing revenue by increased approval rates, without increasing fraud or operating expenses. Only Experian Link™, our frictionless credit card owner verification solution can associate payment card with its owner. This solution combines Experian’s vast data assets – including over 500 million credit card account numbers on file in the U.S. across 250 million consumers – with our advanced analytics capabilities to match and assess the risk of the identity attributes presented to the merchant to the identity attributes contributed by the credit card’s issuer and to Experian’s network of credit and identity inquiries. The result: Experian Link’s patent-pending REST API simply and frictionlessly improves a merchant’s customer experience and helps increase revenue while reducing their fraud and operating expenses. Get started with Experian Link™ now. Experian Link

July 31, 2022 by Kim Le
The Financial Consequences of False Declines

A false decline is a legitimate transaction that is not completed due to suspected fraud or the friction that occurs during verification. Read more.

July 31, 2022 by Kim Le

Subscribe to our Newsletter

Enter your name and email for the latest updates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Subscribe to our Newsletter

Don't miss out on the latest industry trends and insights!
Subscribe