Automated bot cyberattacks are on the rise, while human-initiated attacks are down.
Bot attacks increased by about 100 million last year, Kimberly Sutherland, vice president of fraud and identity strategy for data analytics company LexisNexis Risk Solutions, tells Bank Automation News in this episode of The Buzz. Human-initiated attacks, by comparison, were down by about 200 million, she said.
Subscribe to The Buzz Podcast on iTunes, Spotify, or download the episode.
But it’s complicated; when LexisNexis Risk, which specializes in risk management and cybersecurity, looked at the last half of 2020, bot attacks were down globally, with an 8% decline in bot attacks against financial institutions, except for in the U.S., where attacks are actually on the rise.
“Europe, especially saw a significant decrease, in Latin America as well, in bot attacks within our network,” Sutherland notes, adding that the opposite was true in the U.S. and Canada.
Sutherland also shares in this discussion some advice and insights from the security vendor’s most recent biannual report, “The new cybercrime landscape: Global risks, trends, industry opportunities,” which looks at risk trends in the second half of 2020.
The following is a transcript generated by AI technology that has been lightly edited but still contains errors.
Good day. I’m Loraine Lawson, an associate editor with Bank Automation News. Welcome to the Buzz. Recently, I spoke with Kimberly Sutherland, vice president of fraud and identity strategy for LexisNexis Risk Solutions. We discussed what banks need to know about the firm’s most recent cybercrime report, “The new cybercrime landscape: Global risks, trends, industry opportunities.”I guess the best place to start maybe is if you can tell me what you’ve learned about where fraudsters are targeting their efforts. I noticed that it mentioned new account creation and new lines of credit but what can you tell banks about where fraudsters are going to go after them? Kimberly Sutherland
So one of the things that, you know, is consistent year after year with fraud is that fraudsters will always adapt to the areas that are the easiest to attack they’re going to end so what we’re seeing is in this cybercrime report that was focused on the second half of 2020 so from July to December we saw that from a demographic standpoint individuals under the age of 25 and over the age of 75 were the highest target attack targets of attack so the younger population number one and that older population is number two and I think it’s really interesting because
around helping their you, their customers, just be more vigilant that attacks are on the rise so that’s the first thing common the second thing is just that the whole move to mobile is continuing to become even more prevalent so there’s always been a mix between desktop transactions that are online or even mobile browser but we’re seeing a real strong adoption of mobile apps overall and that’s really great but that also means that fraudsters are gonna drive there as well Lorraine Lawson
so when they go after people with these attacks where they’re creating a new account for instance or targeting a credit new line of credit do they go directly to the bank or do they try to go through the user like to get the user to create a fraudulent account or how does that Kimberly Sutherland
well there’s yeah the easiest thing for the foster is actually to be the one to create the account themselves so when we see a lot of fraud attacks and new account creation a lot of that is driven by the attempted use of stolen stolen information information that’s been accessed during data breaches and so there now is a plethora of data available often enough to be able to create a new account rather than having foster solely focus on account takeover efforts where they’re trying to take over an existing account fraudsters have also gotten heavier into the business of just creating new accounts on their own and that also goes to synthetic identity fraud which is something that may not be as focused on in the digital channels but the idea of being able to create a completely fictitious identity and let that nurture over time and continue to build up credit and other things before they cash out is an initial a fraud attack that we’ve seen over the years and it continues to growLoraine Lawson
now one thing i thought was interesting was attackers are using bots that’s not exactly a new trend but I was a little confused because on page seven it shows that attacked by attacks were down but on the page before it said that they were 2.1 billion bot attacks up 2 billion from 2019 so are there more attacks or less or what’s going on with botsKimberly Sutherland
yeah so you know about attacks are complicated you know one of the best ways to address fraud and also to address cybersecurity is with layered approaches of layered defense. So many of our customers that at the have transactions that come into our network, already have a perimeter defense. So a lot of those bots are already caught at that phase. But then there are many bots that still can make it through seem very much like a human. So from a number standpoint, for the full year, we actually saw bot attacks increase by about 100 million, which is the opposite of what we saw for human-initiated attacks, which was closer to being down about 200 million. So we saw an increase overall, for the second half of the year. However, it’s interesting that we actually saw about a 2% decrease globally, and bot attacks and a further 8% decline for financial institutions with bot attacks. That’s a global perspective for the second half of the year. Now, let me just add one more area of complication on that in the US, that was not the case. Even in the US the second half of the year, we saw an increase in attacks. So I think it’s really important when we look at the statistics that many of our financial institutions are reviewing is that they might need to make sure that they’re paying attention to is this a global statistic? Is it a regional statistic? And what is it you know, how does it really apply to my particular business? Because we often see trends, very different in regions amea. So Europe, especially saw a significant decrease in Latin America as well in bot attacks within our network. But we did not see that in the US and Canada.
Loraine Lawson
And the idea why that would be why the US is a hotspot for attacks and other countries solid decline?
Kimberly Sutherland
Well, one thing I’m not the most proud of is that we often say that the US, Canada, and actually the UK, are the top three in initiating bot attacks. So we’re getting attacked, but we’re also the attacker as well. And so I think that many people often assume that malicious attacks, you know, from bots are coming from, you know, countries all over the world. And, and that’s true. But guess what the US is at the top of the list, often
Loraine Lawson
unnoticed Russia was missing from the list. Is there not data from Russia? or?
Kimberly Sutherland
Yeah, that’s a great question. I would say Russia and China, which we often hear in news, are not as represented within our data. So I can’t really speak to that. But you’re absolutely right. I mean, I think that as while we are very much have a global footprint, we don’t have as much traffic in Russia and China. From a customer standpoint, however, we would still be able to see transaction volumes, or transactions originating from Russia or China or other high profile countries that are often in the news. And we did not see that as much in our data.
Loraine Lawson
Interesting. So I said, the reports of large North American financial services networks bear hallmarks of mule activity, what is mule activity? And you tell me about this broad network that you detected?
Kimberly Sutherland
Yeah, so meal activity is when a fraudster is able to recruit other individuals to assist in the fraudulent act. This another is another one of those things that is highly targeted at young adults, college students, especially that are may see this as a quick way to make a little extra money. So I know in the UK, and some of our European countries that we see even advertisements online on television, about making sure that they’re not accepting to deposit a check, for example, from a stranger with a promise that they can keep a certain percentage of it and then just give you know, the rest to the to the fraudster. It may seem fairly innocent, and it can even be positioned as a job right that on a job posting, where you’re depositing funds, and then temporarily to be able to send them to your new employer. So that is what a mule attack approach is, where you have multiple individuals and and those types of fraud rings will see multiple targets, often across multiple countries, where the the financial institution is receiving funds that will most likely have the risk of even not being legitimate, legitimate check. And the fraudster is hoping that they can have more innocent, I’ll use the term of victims in the process to be able to cash that check. And then the fraudster gets to get away with the fact with the funds in the end. Oh,
Loraine Lawson
clever. So you talked about the layered defense, what is the layered fraud defense looked like? And what role does automation play in it?
Kimberly Sutherland
So layer defense means that you’re paying attention to not just, for example, the data that’s being shared, but the device that that that data is coming from the location of the device, you’re looking at things like a verification step to ensure that the data that is shared is, goes together as valid. And then even adding in things like fraud analytics, and authentication, where automation comes into play is pretty much in almost any of those steps, right? automation can be used for orchestration of the different layers, it’s very common to have multiple products that can be used in a platform to automate workflows, so that way advanced decision can be made. And you can start to build out a risk based authentication method. So for lower risk transactions, you’re going to have maybe less need for active active authentication, where you’re having the consumer engage in the process, maybe passive authentication is enough. And then in maybe higher risk scenarios, maybe you even have to ask an individual to supply a driver’s license or passport, even in a digital environment, to be able to ensure that you are reducing your risk profile, or maybe sending something that’s common for people like a one time password, or even a push notification within within a mobile app. So that’s the concept, you know, layered authentication or layered approaches to fraud detection, and fraud prevention goes hand in hand with developing a risk based model for fraud mitigation.
Unknown Speaker
So the other
Kimberly Sutherland
other thing with automation is that one area that often is not talked about a lot is the need for manual review. That happens in financial institutions, as well as retail and e commerce. And it’s a very costly thing to have a lot of individuals manually addressing those high fraud or high risk indicators. And that’s a great spot for automation, as well, to be able to take some of the manual nature out of those approaches.
Loraine Lawson
Where do banks need to be targeting their defenses right now? Are their efforts, where’s the where’s the big sort of payoff for them to, to focus their defenses on?
Kimberly Sutherland
banks definitely need to think about their mobile customers and their mobile apps. And that is, you know, I think, because we are seeing such a high volume, but I would tell them to not forget that an omni channel approach paying attention to branches are open, you know, call centers are receiving calls, so paying attention to all of the channels that they’re receiving transactions from their customers, because the fraudsters will find the area that is not being manned. As much right, though, the area that doesn’t have the same equivalent types of fraud defense mechanisms. So I think that, you know, for the most part, financial institutions are very much aware of the importance of this. And I think also that, you know, we’re seeing more and more need to increase your risk signals. So things like behavioral biometrics, that is an amazing solution that has very little impact, no impact to the customer experience, because it’s passive in nature, but it is very effective at detecting a human versus non human. So like a bot or a good customer versus a fraudster that may be cutting and pasting information, or spending time on a screen much quicker than normal. Navigating in a way that’s very different. So we’re seeing a lot of interest in the usage of things like behavioral biometrics, incorporating that into traditional workflows.
Loraine Lawson
That’s good because I’m hearing a lot about you know, automating loan origination and some of this account opening and that’s it’s a big trend right now. And I wonder if they are remembering the security aspects of that so that’s good to know i did have another question i probably won’t put this in the podcast but my boss wanted to know so when these people are attacking and using bots to attack how do they where do they get their bots like did they set up their own system like in their basement or where are the butts
Kimberly Sutherland
located you know fraud is a business right you know fraudsters have become more and more sophisticated and there are built about tools there are rent about tools it’s not that difficult now to be able to create these automated scripts right because really all about is is an automated script of some nature so to be able to have to have instead of an individual going and make an attack it’s so much easier to have a series of scripts going out to try to you know make those attacks instead so bots are not that difficult to create and fraudsters are very aware of ways to create rent share the bots in their processes
Loraine Lawson
and they go on to the cloud and launch their bots from their moms i would absolutely do they just
Kimberly Sutherland
yeah i mean you know some things can be added through malware that’s one way to execute or to make perla flick poor if i can’t even say the word sorry flourish from the litho right a series of attacks through malicious piece of malware but i think that the situation is that it’s very common now for automated attacks the same way that we’re talking about automated fraud detection
Loraine Lawson
it doesn’t take as much computer powers maybe i thought sounds like
Kimberly Sutherland
and computer power is cheap right buying multiple servers is not as expensive as it used today.
absolutely so the concerns that you mentioned earlier about individuals wanting to open up new accounts loans get an auto auto an automotive loan or mortgage loan those things we hope continue to increase in 2021 and the risks that exist around trying to take a process and make it as convenient for the consumer can still be very safe for a company if they apply the right types of fraud detection techniques like for example scanning the id document authenticating that the document is real using things like facial recognition to compare the image of the photo on the id to the individual that is of submit getting the id and applying likeness detection there that is a really important step that we’re seeing more and more financial institutions adopting and then things like e signature there are many approaches to e signature and electronic notary processes that add in additional security into those as well so i think that a remote loan application can now be very secure and convenient for consumer.
Loraine Lawson:
You’ve been listening to the Buzz, a Bank Automation News podcast. Thank you for your time, and be sure to visit us at Bank automation news.com for more automation news. You can also follow us on Twitter and LinkedIn. Please don’t hesitate to rate this podcast on your podcast platform of choice.
Automated bot cyberattacks are on the rise, while human-initiated attacks are down.
Bot attacks increased by about 100 million last year, Kimberly Sutherland, vice president of fraud and identity strategy for data analytics company LexisNexis Risk Solutions, tells Bank Automation News in this episode of The Buzz. Human-initiated attacks, by comparison, were down by about 200 million, she said.
Subscribe to The Buzz Podcast on iTunes, Spotify, or download the episode.
But it’s complicated; when LexisNexis Risk, which specializes in risk management and cybersecurity, looked at the last half of 2020, bot attacks were down globally, with an 8% decline in bot attacks against financial institutions, except for in the U.S., where attacks are actually on the rise.
“Europe, especially saw a significant decrease, in Latin America as well, in bot attacks within our network,” Sutherland notes, adding that the opposite was true in the U.S. and Canada.
Sutherland also shares in this discussion some advice and insights from the security vendor’s most recent biannual report, “The new cybercrime landscape: Global risks, trends, industry opportunities,” which looks at risk trends in the second half of 2020.
The following is a transcript generated by AI technology that has been lightly edited but still contains errors.
Good day. I’m Loraine Lawson, an associate editor with Bank Automation News. Welcome to the Buzz. Recently, I spoke with Kimberly Sutherland, vice president of fraud and identity strategy for LexisNexis Risk Solutions. We discussed what banks need to know about the firm’s most recent cybercrime report, “The new cybercrime landscape: Global risks, trends, industry opportunities.”I guess the best place to start maybe is if you can tell me what you’ve learned about where fraudsters are targeting their efforts. I noticed that it mentioned new account creation and new lines of credit but what can you tell banks about where fraudsters are going to go after them? Kimberly Sutherland
So one of the things that, you know, is consistent year after year with fraud is that fraudsters will always adapt to the areas that are the easiest to attack they’re going to end so what we’re seeing is in this cybercrime report that was focused on the second half of 2020 so from July to December we saw that from a demographic standpoint individuals under the age of 25 and over the age of 75 were the highest target attack targets of attack so the younger population number one and that older population is number two and I think it’s really interesting because
around helping their you, their customers, just be more vigilant that attacks are on the rise so that’s the first thing common the second thing is just that the whole move to mobile is continuing to become even more prevalent so there’s always been a mix between desktop transactions that are online or even mobile browser but we’re seeing a real strong adoption of mobile apps overall and that’s really great but that also means that fraudsters are gonna drive there as well Lorraine Lawson
so when they go after people with these attacks where they’re creating a new account for instance or targeting a credit new line of credit do they go directly to the bank or do they try to go through the user like to get the user to create a fraudulent account or how does that Kimberly Sutherland
well there’s yeah the easiest thing for the foster is actually to be the one to create the account themselves so when we see a lot of fraud attacks and new account creation a lot of that is driven by the attempted use of stolen stolen information information that’s been accessed during data breaches and so there now is a plethora of data available often enough to be able to create a new account rather than having foster solely focus on account takeover efforts where they’re trying to take over an existing account fraudsters have also gotten heavier into the business of just creating new accounts on their own and that also goes to synthetic identity fraud which is something that may not be as focused on in the digital channels but the idea of being able to create a completely fictitious identity and let that nurture over time and continue to build up credit and other things before they cash out is an initial a fraud attack that we’ve seen over the years and it continues to growLoraine Lawson
now one thing i thought was interesting was attackers are using bots that’s not exactly a new trend but I was a little confused because on page seven it shows that attacked by attacks were down but on the page before it said that they were 2.1 billion bot attacks up 2 billion from 2019 so are there more attacks or less or what’s going on with botsKimberly Sutherland
yeah so you know about attacks are complicated you know one of the best ways to address fraud and also to address cybersecurity is with layered approaches of layered defense. So many of our customers that at the have transactions that come into our network, already have a perimeter defense. So a lot of those bots are already caught at that phase. But then there are many bots that still can make it through seem very much like a human. So from a number standpoint, for the full year, we actually saw bot attacks increase by about 100 million, which is the opposite of what we saw for human-initiated attacks, which was closer to being down about 200 million. So we saw an increase overall, for the second half of the year. However, it’s interesting that we actually saw about a 2% decrease globally, and bot attacks and a further 8% decline for financial institutions with bot attacks. That’s a global perspective for the second half of the year. Now, let me just add one more area of complication on that in the US, that was not the case. Even in the US the second half of the year, we saw an increase in attacks. So I think it’s really important when we look at the statistics that many of our financial institutions are reviewing is that they might need to make sure that they’re paying attention to is this a global statistic? Is it a regional statistic? And what is it you know, how does it really apply to my particular business? Because we often see trends, very different in regions amea. So Europe, especially saw a significant decrease in Latin America as well in bot attacks within our network. But we did not see that in the US and Canada.
Loraine Lawson
And the idea why that would be why the US is a hotspot for attacks and other countries solid decline?
Kimberly Sutherland
Well, one thing I’m not the most proud of is that we often say that the US, Canada, and actually the UK, are the top three in initiating bot attacks. So we’re getting attacked, but we’re also the attacker as well. And so I think that many people often assume that malicious attacks, you know, from bots are coming from, you know, countries all over the world. And, and that’s true. But guess what the US is at the top of the list, often
Loraine Lawson
unnoticed Russia was missing from the list. Is there not data from Russia? or?
Kimberly Sutherland
Yeah, that’s a great question. I would say Russia and China, which we often hear in news, are not as represented within our data. So I can’t really speak to that. But you’re absolutely right. I mean, I think that as while we are very much have a global footprint, we don’t have as much traffic in Russia and China. From a customer standpoint, however, we would still be able to see transaction volumes, or transactions originating from Russia or China or other high profile countries that are often in the news. And we did not see that as much in our data.
Loraine Lawson
Interesting. So I said, the reports of large North American financial services networks bear hallmarks of mule activity, what is mule activity? And you tell me about this broad network that you detected?
Kimberly Sutherland
Yeah, so meal activity is when a fraudster is able to recruit other individuals to assist in the fraudulent act. This another is another one of those things that is highly targeted at young adults, college students, especially that are may see this as a quick way to make a little extra money. So I know in the UK, and some of our European countries that we see even advertisements online on television, about making sure that they’re not accepting to deposit a check, for example, from a stranger with a promise that they can keep a certain percentage of it and then just give you know, the rest to the to the fraudster. It may seem fairly innocent, and it can even be positioned as a job right that on a job posting, where you’re depositing funds, and then temporarily to be able to send them to your new employer. So that is what a mule attack approach is, where you have multiple individuals and and those types of fraud rings will see multiple targets, often across multiple countries, where the the financial institution is receiving funds that will most likely have the risk of even not being legitimate, legitimate check. And the fraudster is hoping that they can have more innocent, I’ll use the term of victims in the process to be able to cash that check. And then the fraudster gets to get away with the fact with the funds in the end. Oh,
Loraine Lawson
clever. So you talked about the layered defense, what is the layered fraud defense looked like? And what role does automation play in it?
Kimberly Sutherland
So layer defense means that you’re paying attention to not just, for example, the data that’s being shared, but the device that that that data is coming from the location of the device, you’re looking at things like a verification step to ensure that the data that is shared is, goes together as valid. And then even adding in things like fraud analytics, and authentication, where automation comes into play is pretty much in almost any of those steps, right? automation can be used for orchestration of the different layers, it’s very common to have multiple products that can be used in a platform to automate workflows, so that way advanced decision can be made. And you can start to build out a risk based authentication method. So for lower risk transactions, you’re going to have maybe less need for active active authentication, where you’re having the consumer engage in the process, maybe passive authentication is enough. And then in maybe higher risk scenarios, maybe you even have to ask an individual to supply a driver’s license or passport, even in a digital environment, to be able to ensure that you are reducing your risk profile, or maybe sending something that’s common for people like a one time password, or even a push notification within within a mobile app. So that’s the concept, you know, layered authentication or layered approaches to fraud detection, and fraud prevention goes hand in hand with developing a risk based model for fraud mitigation.
Unknown Speaker
So the other
Kimberly Sutherland
other thing with automation is that one area that often is not talked about a lot is the need for manual review. That happens in financial institutions, as well as retail and e commerce. And it’s a very costly thing to have a lot of individuals manually addressing those high fraud or high risk indicators. And that’s a great spot for automation, as well, to be able to take some of the manual nature out of those approaches.
Loraine Lawson
Where do banks need to be targeting their defenses right now? Are their efforts, where’s the where’s the big sort of payoff for them to, to focus their defenses on?
Kimberly Sutherland
banks definitely need to think about their mobile customers and their mobile apps. And that is, you know, I think, because we are seeing such a high volume, but I would tell them to not forget that an omni channel approach paying attention to branches are open, you know, call centers are receiving calls, so paying attention to all of the channels that they’re receiving transactions from their customers, because the fraudsters will find the area that is not being manned. As much right, though, the area that doesn’t have the same equivalent types of fraud defense mechanisms. So I think that, you know, for the most part, financial institutions are very much aware of the importance of this. And I think also that, you know, we’re seeing more and more need to increase your risk signals. So things like behavioral biometrics, that is an amazing solution that has very little impact, no impact to the customer experience, because it’s passive in nature, but it is very effective at detecting a human versus non human. So like a bot or a good customer versus a fraudster that may be cutting and pasting information, or spending time on a screen much quicker than normal. Navigating in a way that’s very different. So we’re seeing a lot of interest in the usage of things like behavioral biometrics, incorporating that into traditional workflows.
Loraine Lawson
That’s good because I’m hearing a lot about you know, automating loan origination and some of this account opening and that’s it’s a big trend right now. And I wonder if they are remembering the security aspects of that so that’s good to know i did have another question i probably won’t put this in the podcast but my boss wanted to know so when these people are attacking and using bots to attack how do they where do they get their bots like did they set up their own system like in their basement or where are the butts
Kimberly Sutherland
located you know fraud is a business right you know fraudsters have become more and more sophisticated and there are built about tools there are rent about tools it’s not that difficult now to be able to create these automated scripts right because really all about is is an automated script of some nature so to be able to have to have instead of an individual going and make an attack it’s so much easier to have a series of scripts going out to try to you know make those attacks instead so bots are not that difficult to create and fraudsters are very aware of ways to create rent share the bots in their processes
Loraine Lawson
and they go on to the cloud and launch their bots from their moms i would absolutely do they just
Kimberly Sutherland
yeah i mean you know some things can be added through malware that’s one way to execute or to make perla flick poor if i can’t even say the word sorry flourish from the litho right a series of attacks through malicious piece of malware but i think that the situation is that it’s very common now for automated attacks the same way that we’re talking about automated fraud detection
Loraine Lawson
it doesn’t take as much computer powers maybe i thought sounds like
Kimberly Sutherland
and computer power is cheap right buying multiple servers is not as expensive as it used today.
absolutely so the concerns that you mentioned earlier about individuals wanting to open up new accounts loans get an auto auto an automotive loan or mortgage loan those things we hope continue to increase in 2021 and the risks that exist around trying to take a process and make it as convenient for the consumer can still be very safe for a company if they apply the right types of fraud detection techniques like for example scanning the id document authenticating that the document is real using things like facial recognition to compare the image of the photo on the id to the individual that is of submit getting the id and applying likeness detection there that is a really important step that we’re seeing more and more financial institutions adopting and then things like e signature there are many approaches to e signature and electronic notary processes that add in additional security into those as well so i think that a remote loan application can now be very secure and convenient for consumer.
Loraine Lawson:
You’ve been listening to the Buzz, a Bank Automation News podcast. Thank you for your time, and be sure to visit us at Bank automation news.com for more automation news. You can also follow us on Twitter and LinkedIn. Please don’t hesitate to rate this podcast on your podcast platform of choice.


