Marqeta, a card-issuing company that works with Affirm, Instacart and DoorDash, is working on a new product to combat digital fraud amid a reported 238% surge in cyberattacks on banks, according to a recent study by research firm VMware.
“While moving to digital payments during COVID has been essential … it also means that the imperative to prevent fraud is even more important,” said Vidya Peters, chief marketing officer at Marqeta.
The Oakland, Calif.-based company plans to release its customizable “3 Domain Secure” (3DS) protocol around Aug. 18 to fend off online fraudsters, Peters said. The 3DS is an industry protocol created by card networks like Visa and Mastercard for secure online transactions and Marqeta’s new model aims to be more customizable in adding additional checks and balances to authorize a transaction made by the user.
Financial institutions and fintechs have been ramping up their cybersecurity measures as one in six people in the U.S. were reported to be victims of digital fraud in the past 12 months, according to a Marqeta study. The report noted that 33% of American respondents affected by digital fraud lost more than $500 in that same timeline.
Marqeta’s customizable 3DS protocol connects three domains: merchants, card issuers and networks, such as Visa or Mastercard. The three authenticate the cardholder prior to payment authorization in real time. The company has raised more than $500 million to date, most recently raising $150 million in May, and has a market cap of $4.3 billion. According to reports, Marqeta is looking into an initial public offering.
“If the card issuer believes that the transaction is low risk — or maybe it’s the same card that’s been used in the past, maybe it’s a long-standing customer who always shops at that merchant — they can allow that cardholder to skip extra verification,” Peters said. “But if the card issuer sees potential for fraud, such as an unusually high transaction amount from an unauthorized device, they can ask the cardholder for additional information, with a user-friendly authentication.”
With 3DS, the card issuer sends users a one-time password via email or text message, or uses biometric identification like a thumbprint to verify the transaction, Peters said, noting that the authentication will be useful to provide secure online transactions.
While he 3DS process is available for online transactions only, the company is currently working on 3DS 2, a similar authentication product which can share data faster on multiple devices and is updated for payments using smartphones.
Since the start of the pandemic, phishing attacks, identity theft and account-takeover transactions have been on the rise, Peters said.
The new Marqeta cards backed by 3DS will allow card issuers to authenticate transactions that were placed with a level of granularity that wasn’t possible before. The protocol gives card issuers a more customizable control on asking for authentication on a specific transactions and how they would prefer that authentication to be done.
If an online payment is successfully authenticated with 3DS, the merchant is not liable for subsequent fraud-related chargebacks on that transaction, and if a transaction is disputed by the cardholder as fraudulent, “liability shifts from the merchant to the card issuer,” according to the company’s guide for developers.
The 3DS product gives Marqeta’s customers the flexibility to decide when they want to challenge the cardholder for additional verification, Peters said. Businesses can build their own risk rules within the Marqeta’s open API platform and decide when a transaction by the customers is to be challenged, and how the transaction is to be verified, she added. Marqeta offers multiple ways to authenticate the cardholder and can enable customers to use their own custom method such as biometrics within their mobile app.
Banks are increasingly turning to behavioral biometrics to profile customer activity and flag suspicious activity online. Banking solutions companies like Neocova and BioCatch are developing behavioral biometrics products to meet the demand and better secure customer bank accounts, especially as banking activity shifts online.
“Banks evolved in the past couple of years by providing biometric scanning for payments and transactions, but so did the criminals,” Uri Rivner, chief cyber officer at BioCatch, recently told Bank Innovation. As banks look to bolster cybersecurity, they’ll need to keep up with evolving and rising levels of fraud, which are poised to grow in the next year, according to a TransUnion report.
Bank Innovation Build, which takes place Sept. 9-10 as a virtual experience, is a must-attend industry event for professionals overseeing financial technologies, product experiences and services. Register here.






