The real world poses as much of a threat as the online one, cybersecurity experts said in a Thursday webinar hosted by Bank Automated News. Synthetic identity fraud occurs when a criminal combines stolen identification, such as a Social Security number, with other identifying information to create a new, false identity.
“One of the significant challenges with cyberfraud is changes in not only technology, but the world around us,” said Matthew Miller, U.S. cybersecurity services banking industry lead at KPMG.
“The areas I think that have had significant impact on cyberfraud is the deep and dark web — areas where cybercriminals are able to create marketplaces to be able to acquire stolen identities — tax documents and pictures of driver’s licenses. We also have identities out in Facebook and social media that are able to be grabbed fairly easily, and there are markets for those identities” Miller added.
“There’s a good trade-off. They can purchase them for a little amount of money, and actually see a return on the investment,” he said.
Virtual currencies, such as Bitcoin, have had an impact too, Miller noted.
“The ability to be able to transact anonymously, for these transactions has made it difficult for people like us that are defending against synthetic identity fraud and account takeover,” Miller said.
True Brown, senior vice president of Financial Crimes Risk Mitigation at Simmons Bank, agreed that synthetic ID fraud has been a major problem for financial institutions.
“There’s a lot of vendor tools out there that can help identify, but nothing is perfect,” Brown said. “Everybody tries to build the best mousetrap; the fraudsters are also trying to beat those mousetraps and constantly find innovative ways around it.”
Brown said he relies heavily on third-party products to help secure the bank’s onboarding process. “It all starts at the onboarding of new accounts to ensure that it’s not a synthetic ID, or give us assurance that Social [Security number] or the information is associated with the real person.”
Rami Thabet, vice president digital product at the Royal Bank of Canada, described cyberfraud as not only a “chronic challenge, digitally and physically,” but a business challenge.
“This is not a cyber-challenge. We view it as a [know your customer issue] and a core obligation that you have as a financial institution,” Thabet said.
To that end, RBC has partnered with a network of data providers that help weed out ID theft, working with customers to improve security.
“We actually have set this up as an ongoing, evergreen program on the business side so the business is taking accountability for their protection … This is not a cyber challenge, not a technology challenge to do it; it’s a business challenge.
“Every financial institution has the obligation to know their customers and to provide proper [anti-money laundering] rendering. Just moving into the digital space where more of your volume is happening in a digital self-serve way … actually just puts a heightened importance to doing this in a more robust manner,” Thabet added.
The following is a transcript generated by AI technology that has been lightly edited but still contains errors.
Hello everyone and thank you for joining Bank Automation News for the special webinar on automation technology for exceptional bake cybersecurity and Id verification. I’m Loraine Lawson, deputy editor with Bank Automation News. If you’re here, you’re no doubt aware that the cybersecurity landscape is constantly changing. Today we’ll examine that landscape and discuss best practices in cybersecurity and identity, identity verification that can help financial institutions work fraud and other debts. With us today are True Brown, Senior Vice President Financial Crimes risk management persimmons bank, Matthew Miller, US cybersecurity services bank industry lead at KPMG and Rami Thabet. VP of digital product at RBC. Thank you. If each of you wouldn’t mind giving a brief introduction of yourself starting with True:
True Brown
Hey, good morning, everybody. Yes, my name is True Brown. I am with Simmons Bank. We are a regional financial institution based out of Arkansas, with a footprint in six states, primarily brick and mortar up to about a year or so ago and now we are have been heavily expanding our digital footprint. Prior to come into Simmons a year ago, I served as Director of Financial Crimes investigations at USA, which again, is a very large institution heavily heavily entrenched in the digital marketplace. And prior to that 20 years retired federal law enforcement with the FBI financial crimes. So again, and from there, I can easily say that I cut my teeth in investigations, looking at financial frauds, primarily identity theft matters. And 28-35 years later, is the same problem except now it’s done through digital channels. Thank you.
Loraine Lawson
Thank you True. Matt?
Matt Miller
Hi, Matt Miller. I’m a partner at KPMG in financial services, about 25 years experience in cybersecurity and really focused on the intersection between cybersecurity and fraud. Prior to KPMG, I was came out of industry where I ran the anti fraud programs focused on insider threat and cyber security for the banking industry, both federal regulators and banks on Wall Street.
Loraine Lawson
Thank you, Matt. And Rami?
Rami Thabet
I’m the Vice President of digital product, Bank of Canada. And my focus come at this not from the cybersecurity angle, but more from building client experiences and wonderful client experiences for both the digital and physical domain, and integrating things like identity and verification and security practices in great customer onboarding experiences.
Loraine Lawson
Thank you, Rami. Just a reminder today that if you have any questions for our panelists, you can submit those through the chat. The cybersecurity brand landscape are constantly changing, of course, Matt, can you give us an idea of what the big challenges are in the current landscape? And specifically, I’m hearing about synthetic identity fraud is a major challenges today. So maybe if you could explain a bit about that?
Matt Miller
Yeah, I think, you know, one of the significant, you know, challenges with with cyber fraud is is changes in not only technology, but the world around us. And so through the areas, I think that have had significant impact on cyber fraud. One is the deep and dark web. So areas where cyber criminals are able to create marketplaces to be able to acquire, you know, stolen identities, you know, tax documents, pictures of driver’s licenses, we also have identities out in Facebook and social media that are able to be grabbed fairly easily, and the markets for those identities. You know, there’s a good trade off, they can purchase them for a little about a month amount of money and actually see a return on the investment. The other area that has really had impact is virtual currencies. So the ability to be able to transact anonymously, for these transactions has made it difficult for people like us that are defending against synthetic identity fraud and account takeover.Loraine Lawson
True. Are you seeing anything similar to that?
True Brown
Well, I’m coming from a digital environment institution to one that is now really launching those products. I see it from both sides. I mean, I see I see it, the full landscape against synthetic ID has been a major problem. And again, there’s a lot of vendor tools out there that can help identify, but nothing is perfect. I mean, as everybody tries to build the best mousetrap. The fraudsters are also trying to beat those mousetraps and they constantly find innovative ways around it. Again, everything is available on the dark web. I mean, I think we’d be naive to think that our personal information isn’t out there from the various breaches, you know, and other other tools that the forces are using to get our data. Again, I rely heavily on third party products to help secure our onboarding process, it all starts at the onboarding of new accounts, to ensure that it’s not a synthetic ID, or give us assurance that social or the information is associated with a real person. And also, there’s been a lot of developments, as far as verifying the government IDs themselves, the driver’s license, per se, again, initially, it was sort of like one of the vendors out there would say, the ID fits a certain format it looks like and it works has all the earmarks of a valid driver’s license, there are now some services out there that are tied to the DMV, in certain states, and that gives us a little bit, a little bit more comfort that we are always dealing with a real person. Now, if the person is good or not good, what their intent is, you know, that’s, you know, that’s a totally different conversation.
Loraine Lawson
Sorry, I was just gonna say, I know you work with identification. So maybe you can speak to that and talk about what it means to automate, say, know your own customer, especially as it relates to identification.
Rami Thabet
Yeah, no, absolutely. I mean, I’m picking up where Matt and True left off. This is a chronic challenge both digitally and physically. We’ve seen the bad guys actually not be shy at presenting in a physical location in front of banking advisors with synthetic ID. So they’re not exactly shy. This is also a business challenge. This is not a cyber challenge. We view it as a KYC. And know your customer, and a core obligation that you have as a financial institution. And the path we’ve taken is exactly what Trudeau has said is we’ve partnered with an extensive network of data providers, we do ID verification, government ID verification, we leverage ID. So it’s not just scanning the ID looks, the way it looks at actually scans against attributes of government IDs to verify their legitimacy, we also actually scanned selfies, we asked our customers to do that for their own protection. So it’s not an invasive measure by any stretch. It’s a guided experience. And it’s all done with privacy in mind on the client’s device. So they are assured that it is all happening with privacy considerations in mind. And we’ve had nothing but stellar feedback from our clients, that we are literally looking after their security, privacy and true identity from the day they begin a relationship with us. Is that all third party driven? Or is that some custom bill? It’s a combination, actually, we view it as a combination. And for our from our perspective is we lean into many wonderful partners in the enterprise, but we also build our own proprietary capabilities and technology to augment where the market has simply not not been there yet, or has not matured yet, in that space. You know, secondarily, we actually have set this up as a ongoing evergreen program on the business side. So the business taking accountability for their protection, like I said at the beginning, this is not a cyber challenge is not a technology challenge. It’s a business challenge. And you know, every every financial institution has the obligation to know their customers and to provide proper PML rendering, just moving into the digital space where more of your volume is happening in a digital self serve way does not abdicate from those accountabilities, it’s simply actually just puts a heightened importance to doing this in a more robust manner.
True Brown
Rami, I think you bring up an excellent, excellent point when you’re talking about synthetic or ID theft in branch where somebody actually shows a count of a driver’s license or government ID. And it passes. I mean, inherently, people look at online and digital transactions as being riskier than in breach. And the inherent risk is much greater. But the residual risk if you have the right tools in place, could be as secure and in some cases more secure if you’re using those tools properly. So again, just because somebody walks in branch doesn’t mean they can’t open up a fraudulent account versus an on line. Same thing happens but again, if you use the right tools, you think you can get a similar level of comfort as having somebody standing there right in front of you with my opinion.
Loraine Lawson
Matt, have you seen any best practices along that regard when it comes to identification?
Matt Miller
We have so so um, one thing that we do is we actually scan a lot of the consumer banks in terms of understanding not only their identity proofing controls, but also their authentication mechanisms after someone has established an account. And you know, what you’ll see is dependent on the institution, there’s many different channels where the user experience requires them to authenticate, whether it’s the ATM, your mobile app, website, potentially in the branch or even through a call center. And there needs to be a convergence of in terms of best practice in terms of how you authenticate. And those those methods. Right now the attackers do go after the lowest common denominator, or the easiest point of access, whether it is through the call center, and and they use that to, you know, take over people’s accounts to be able to change some of the credential information or or even addresses and, you know, that causes risk for for everyone in the in those service areas. So, you know, we are seeing best practices where organizations are moving to having things like password list authentication, moving away from knowledge based questions for resetting credentials, or even moving away from SMS or per step up authentication for sensitive transactions. So those are the trends that we’re helping and guiding our clients down that journey.
True Brown
Excellent, because I know we’re here we’re talking about the digital threats. But even though there’s digital threats, you still bring it back to the human element. And social engineering at its most basic element, I guess, with the call centers, then makes the digital channels vulnerable, as the you know, customer information is changed, the passwords are changed, and so forth. And that’s that’s where we really have to have heightened authentication processes.
Rami Thabet
Yeah, to add to True and Matt commentary, tongue in cheek, we often say, you know, the bad actors, or the male actors in the system are have been omni channel for a long time, we need our, you know, they fraudsters have adopted omni channel behaviors, years before we’ve adopted the technologies and the practices. And so closing up this seems, across the organization, is the best practice that we have discovered through trial and error, which fundamentally means you have to look at this in an incredibly different way. From an organizational perspective, you really need, you know, wide sponsorship across the financial institution to, to really lean into the protection measures, you’re gonna need your branch colleagues, you’re gonna need your digital colleagues, you need your fraud colleagues, you’re gonna need your advice, central colleagues, and the collection of the totality. And it’s quite rare that all of those functions resolve up into the same senior executive. So this becomes really an all hands on deck leadership, call to action.
True Brown
And Rama, you’re exactly right. I mean, somehow these to be effective ministers will be effective in addressing these matters, you have to break down the silos. And from my experience, the larger the institution, the more difficult it is to break these silos. And again, and this is also what the regulator’s look at when they come in, they want to make sure that there is coordination and connectivity between IT security between the fraud groups between, again, call centers, frontline, the BSA areas, they are looking more and more to seeing that institutions have that open line of communication. And not only do they say they have that they can show and demonstrate that, that it is the actual practice.
Loraine Lawson
I have a a reader question or a viewer question. Sorry. That sort of relates to this, when do you estimate a wider rollout of blockchain based government issued and managed ID systems? Have you all heard anything about that?
Rami Thabet
Maybe I’ll jump in. So I would say I’d parse that question a couple of different ways. There’s three questions within that. I would say blockchain based digital identity is still very much in its early days in Canada, as some folks may be aware, the banks, the major financial institutions that bank, the majority of Canadians have rolled out a block chain based digital ID platform. It’s actually my team that’s been participating in now. And we’ve had some early successes, but it’s still very early days and excited by its capability excited by its likelihood for success. And frankly, its ubiquity and the promise of ubiquity. The question around government issued I block identity was just a government issued period anything very much depends. I think on the geography I’m not equipped to speak on the US landscape but within the Canadian lines. We have a number of provinces, we have a number of territories and government, federal government institutions, and they all have efforts underway. But timetables, I would say are, are still indeterminate. And we continue to work with them. So, you know, I would say Rami’s perspective, again, purely Rami’s perspective on this one, I hypothesizing into the future. I think we’re going to be in an environment of multiple digital identities. The question is, hopefully it resolves into a handful that is that are highly used highly ubiquitous, that have a tremendous amount of trust factor underneath them, but it is very much the next battleground of competitiveness is this digital ID space.
Loraine Lawson
Matt, True anything about it?
Matt Miller
I think I think we’ll actually start seeing blockchain use outside of identity proving probably earlier in the area, you know, transaction monitoring and fraud. We do already see other areas of API-driven security that allow, you know, banks to connect in kind of open ways where they can validate other identities. And even through the fintechs, being able to get access to you, either monitoring people’s accounts, converging data, doing analytics and the rest. So there is this notion of trust in financial solution systems working together. So we may even see something outside of the government that moves faster than government identities in this space.Loraine Lawson
True have anything to add?
True Brown
I have nothing beyond what they have provided.
Loraine Lawson
Well, I wanted to ask you drew, you work primarily with fraud and Bank Secrecy Act, which of course relates to money laundering, what are some best practices you can recommend? So banks can be sure they don’t run afoul of regulators?
True Brown
Well, if it’s a it’s a matter of the question, not running afoul of the regulators, I mean, there’s obviously very low hanging fruit, which is making sure that you know, you’re addressing everything timely, you’re meeting all the regulatory requirements for your, you know, your CTR GSR filing, so forth. But really what we, what we’ve experienced, so I’ve experienced, avoid, the last couple of exams, has been, you know, making sure that everything is so well documented, you have your procedures, you have your policies, but in the eyes of the regulators, if it’s not documented, it’s not tested, it doesn’t exist. So they’re not going to take your word for it. Everything has to be, you know, eyes dotted T’s crossed from a regulatory regulatory standpoint. Again, said earlier, what they’re really looking at now is the connectivity between the various business units. Again, I come from primarily a fraud background. So usually, when the regulator’s came in, you know, I, they took a look at us, but you know, he’s really heavily focused on the BSA side. But we’re seeing more and more emphasis in exams and the questions posed by the examiners, regarding again, that open documented connectivity between AML and fraud. And now also IT security regarding potentially cyber related incidents, are they being investigated? Or are they being reported properly, and so forth. So we see a lot of that connectivity. And also another big factor that the regulators are starting to really look at. And Matthew may be able to jump in on this is the internal threat. You know, I had not seen it before. But you know, over the last two or three years had I’ve had several questions asked us and presented to us regarding, you know, documenting our internal threat, our internal threat policy, and what our internal risks are. So again, to keep the regulator’s at bay, good policies, documented policies, your risk assessments, regular risk assessments, testing of your tools, the modeling, calibration, all those things need to be done on a timely basis, because those are the things the examiner is going to ask for when they walked in the door. No, that’s it. That’s all low hanging fruit.
Loraine Lawson
Matthew, do you have anything to add to that?
Matt Miller
Yeah, I mean, to comment on insider threat, we are seeing at least us regulators focus on insider threat and having our financial institutions have well established insider threat programs. You know, there’s plenty of examples where there have been, you know, cases and arrests, everything from insider trading to embezzlement of that involve true insiders. And and there’s real risk there. In So, you know, they are looking for people to build programs that use next generation technologies for behavioral modeling to try to identify who these individuals may be. There’s also you know good ways where you can just look at your common business practices and see where you may be adding risk into your environment. You know, we’ve had a lot of emphasis on segregation of duties and kind of toxic combinations being good, strong controls around things like financial statements, but they’re not necessarily a strong control in like the payment space, especially where you may have collusion. And you get two people together a segregation visa isn’t going to solve that problem.
True Brown
In a back to me, all of it is knowing our customers, they’re going to make sure that they will make sure that the institution’s know who their customers are, who has been designated as a high risk customer, and have we done the, you know, the required due diligence enhanced diligence on these customers. So I mean, that mean, those are all basic staples of a BSA program, part of the pillars, and, you know, those were we really need to be addressed when the examiners walk in the door.
Loraine Lawson
Rami are you facing in Canada that are similar?
Rami Thabet
Well, they’re very similar themes, I think, you know, insider threats are as prevalent have always been as prevalent as outside threats. And you need to establish robust controls internally, as well as programs. So, and many of the same capabilities and digital technologies that we use for external facing or client facing aspects can be focused internally. And I think that’s always in a promise, I think, you know, one of the areas I would flag as a best practice is pulling the fraud group, less out of the back office and more into the front office with the lines of business, and having it be an integrated function around the protection of the organization and reframing the dialogue, away from, you know, fraud, protection and cyber protection, something that happens in the shadows of the organization and is more thoughtful design, from the beginning from the get go. You know, if we framing protection as an amazing client experience, that establishes trust, you know, there’s no greater loyalty indicator, or loyalty driver of your customer than trust. And trust can really be anchored in a meaningful way by building protection and meeting client experience. So, you know, typically, we’ve viewed fraud as a point of friction, or fraud protection is a pointing of friction and experience, we got to reframe that entire discussion to say, it’s actually a point of loyalty and reducing client attrition in the longer term.
Matt Miller
guy would agree with that. And we’re seeing clients even, you know, notionally moving away from fraud, which was historically driven out of incidents or events that did occur, and needed to be reported and resolved and potentially recovered to building anti fraud programs. So getting into those preventative areas and making sure that fraud does not occur in the first place. And pushing that towards the customer experience, you know, imagine going to purchase a good at a store and all of a sudden, you get an embarrassment, because there’s a fraud alert in your card doesn’t work is a totally different experience, then all of a sudden, you go to purchase, and you get an automatic alert on your phone that says, Are you at this store? Is it you are you doing that, and you’re able to see in real time, let that transaction go through, you can now build real strong brand loyalty on to that that card that did work, not the one that gets denied. And so there’s awesome opportunity with technology as evolves to really create that user experience, that then becomes really the customer expectation for every type of financial mechanism that they leverage.
Rami Thabet
One thing to add to that map is its biggest moment of truth in a relationship, and how many programs and how many fraud groups along with their client experience in digital counterparts ask the question of what’s the experience wants the event campus, so we’re so focused on preventing it, but it will happen. It will happen to some, you know, unfortunate clients, and we, you know, we all work with them quite proactively. But the question is, what was that experience, and that experience can go from something incredibly traumatic to something incredibly traumatic, but that was mitigated and reinforced client loyalty value, something as simple as, you know, digital capabilities like you had just cited, but even something as simple as an outbound call, a month later or a week later, say, how are you doing? I hope everything is now settled and you’re on your way and you know, you have no lingering effects. Those go a long way for building long term client value. You know, you knew that a client is not going to leave you for life. You’ve got a client for life.
Loraine Lawson
I can agree with that. As someone who’s actually experienced fraud, that it can be a make or break experience for for a bank. Is there any regulatory actions Congress or lawmakers can do to make your job as cybersecurity specialists easier and have lawmakers put up any roadblocks.
Matt Miller
They there, I think they are very helpful, I think, you know, bring the toy climate today is really trying to push, at least my clients to move in the right direction and to really evolve their thinking. One good example would be the FFIEC just released guidance on on authentication controls. And it was very comprehensive in terms of looking at the consumer experience, as well as enterprise authentication and making sure that they’re continually evolving and trying to stay up above these, these threats that mature daily.
Loraine Lawson
True, do you have anything to say to that?
True Brown
Again, regarding the FFIEC guidance, I mean, it’s an it’s an excellent documentation regarding the authentication practices, transactional monitoring, best practices, I mean, not sure if it’s requirements, it’s really more more was best practices. But it does give a good roadmap for financial institutions, or actually any businesses that have a digital footprint on what they need to be doing and looking at to to ensure that they have a secure platform for their customers and for in house. I mean, it’s also addresses access to platforms internally, as well as external. But again, as far as, you know, guidance, or regulations, I mean, actually, I would have to Matthew, I think I would have a little bit of a different differing opinion that some of the recent regulations make it a little bit tougher financial institution, especially with fast pay and the faster payments going on with the P2P , and the, you know, the ACH channels regarding the responsibility of the banks, as they adhere to Reg E and investigating some of these matters. So I mean, the level of where they’re placing the responsibility, I think can be a little bit difficult on some of the financial institutions.
Rami Thabet
Yeah, I think, you know, say, both from a Canadian and US perspective, I would look at our regulatory partners at establishing crystal clear rules of engagement, accountabilities expectations, and setting the bar, I think leaning into the private sector for implementation and outcomes, and really holding the bar on that with with the banks is, is sort of the key ingredient for success, if I would have a single call to action is really more digital document and more understanding within the within the regulatory arms of the new landscape we’re all dealing with at this point, and I think we spend an, you know, an exorbitant amount of time on education, outreach, understanding and shared mutual perspective on what’s really happening. And, you know, that creates a good point of departure.
Loraine Lawson
I wanted to talk about credential stuffing, which has been in the news recently, it’s not necessarily a new thing, but cybersecurity firm Akamai says financial institutions face 3.5 billion attacks using stolen credentials in 2020. Are there ways in which new forms of identification verification can help with that? What’s the best automated defense? Matt, can you start us off?
Matt Miller
Yeah, so I mean, it’s definitely increasing. And what they are doing is they’re picking up passwords, in bulk, that they either harvest through malware or, or that they acquire through, dumps on on the dark web, and they just replay your credentials, you know, back to the bank that they’ve stolen. And so from a user, there’s definitely best practices in terms of not using the same password everywhere, having low risk passwords for certain things you do in your activities, like reading news, and, and having longer more complex passwords for, you know, financial transactions and those institutions. But really, the move needs to be towards some type of multi factor authentication or a passwordless model. And you know, those institutions that have not provided that type of service to their customers put their customers at risk, those institutions that offer it and know that, but their users have not fully adopted it because of the customer experience or also putting their their clients at risk and, and in turn, it puts the institution at risk. Because when someone does credential stuffing and does get to take over an account, that’s where you add additional money laundering risk to an institution for someone that may be using it as a money laundering funds. So, you know, technology needs to evolve users need to evolve as well in terms of their awareness and adopting some of these controls in order to really, you know, remediate that risk. You do see some things today that are helping. So if you go, you know, into an iPhone or other technology or even the Google platform, they start to identify for you, which of your passwords have been stolen. And so it’s up to those users to be able to go in and make those changes and protect.
Loraine Lawson
True, Rami, do you have anything to add to that? credential stuffing battle?
True Brown
Well, I was gonna, I was gonna ask Matt, a question regarding the credential stuffing, when the forces are successful, you know, with their scripted attack, and they have been able to your experience, when they have been able to match up a password to an online ID, are you seeing an account, you typically see an account takeover right away? Or is it again, is this just another business aspect where that now they are going to then package that up and sell that on the dark web?
Matt Miller
Yeah, it varies, you know, a lot of times, you will see them not use it right away that, you know, they’ll they’ll take over the account. And they’ll monitor it, and though they’ll keep pinging it, and you can use that to detect some activity, because in certain circumstances, yes, they hire people that actually log into these accounts and bypass the controls, and others that use bots and other types of things to be able to continue to potentially act, see if the account is accessed and still available and ready for that time when they need that money. So in sometimes they’re trying to collect multiple accounts with the money can link together in order to move money very quickly, with setup transactions. So it really it really does depend. But I think there’s probably a lot of accounts out there that have already been that are known to be compromised by malicious actors that, in turn are not being actively used for financial crimes today. But there’s also a lot that are.
True Brown
Well, I’m glad you I was waiting to see what your answer would be macro skin for my experience was when we actually did see scripted credential stuffing attacks, we would come back afterwards and said, well, nope, nobody did anything to the account. So people put their guards down. And again, we’d reach out to the customer if was identified and hopefully tell them, you need to change your password. But again, I think it was just being naive by the institution’s part not to think that information was not going to be then exploited sometime down the road by on an account takeover. And not everyone wants to launder money. I mean, some people will go and they’ll package up these accounts, and they’ll actually sell them. So that you know, it becomes a commerce for them as well. Yeah, you absorb experiences, when we have we saw these type of activities, and the accounts were taken over, it would have been for, you know, for not for money laundering, it would be to, you know, just, you know, empty out the accounts.
Rami Thabet
So, I mean, I think I’ll pick up a couple of threads that Matt and True have have jumped us off on. Make your you know, password reset on logging experience exceptional, make it easy, make it understandable, make it simple. You will need to operate with your clients knowledge and, and their digital capability. That’s sort of number one, communicate often and regularly. So, you know, the first thing I typically see in organizations is the first thing to get the scope is that, you know, email SMS notification to the client around, hey, somebody your password has been reset, did you intend to do this, it’s like the easiest feature to do scope. When you run out of money. Yet, it’s one of the most critical at inviting your clients to be as vigilant as you are. Build programs that monitor your entire lifecycle of your account opening process. And that does not mean once the account is open, and you’ve verified their ID that it’s legitimate for KYC and AML. That means four days later, are you starting to see large checks in and out or large cash amounts in and out? Are you What’s the activity is it’s starting to become normal. The other is start to know your clients digital devices. So the concept of the trusted device is something we use quite extensively. And we have had significant success with clients definitely some opting in wanting to wanting us to know their device so that we can protect them. All of these are multitudes of protections and capabilities, that they’re not going to make credential stuffing go away. But they make it less cost effective for the bad guys and, and the male actors and it’s just it’s a business case, the business case this as much as you know banks, business case initiatives, and often we talk about a you know, an iPhone is a very expensive device. And if you’re, you know false and you’ve picked up a bunch of iPhones and Android phones that are fraudulent over are being used by my actors, and they’re no longer usable in your enterprise. That’s a very expensive business case for the male actor. And eventually they move on to a softer target. And we hate to see fraud moves elsewhere. But that’s, that is a tactic around how we’ve protected ourselves. And the last is inter bank cooperation, I think it’s incredibly important to have inter ephi. inter organization cooperation, because you have a responsibility, if you see something, that you notify your colleagues and peers who have an opportunity to take action as well and protect the entire ecosystem.
True Brown
Rami, that is an excellent next one point, it’s something I think has really been developing over the last or expanding over the last three years or so the idea of consortium data, you know, entities that are happening again, unfortunately, it’s a pay to play, to receive the consortium data, you have to probably be paying for a service, or so forth. But this consortium data is an excellent tool to identify potentially bad actors by name or by device, and so forth. So again, I know in the past, we did a lot of device recognition, work from an investigative standpoint, and we would, again, we could see the same device fingerprint, touching, you know, 15, 20 different unrelated customers. So it’s not like one device in a house, touching all the family members. And we did take successful action and blocking the devices. And then they would, you know, again, occasionally would see a new device show up. But our thought is they left our institution and went to target another institution, you know, again, hate to push the fraud someplace else. But again, first concern is reduced my own fraud landscape.
Loraine Lawson
We have a question from a viewer that says they have been the victim of monies being stolen due to branch personnel, and notes that call centers are slammed. And the question is, are neural networks like chatbots evolved to help? Is it a balance of privacy versus security? Matt?
Matt Miller
Yeah, well, I know Romney was going to speak up, so let him go first. And
Rami Thabet
That’s probably the face was my tail on that one. I, I guess I probably overreact to to chatbots. I have seen so many chatbot use cases that have had not the greatest business impact, there are many out there that are incredibly successful. Technology has an opportunity, like neural networks, as you mentioned, in your question, an opportunity to really help manage and mitigate these types of risks, especially when capacity is a concern. You know, oldest game in the book is wait for the advice centers to get slammed and tried to sneak in due to cognitive load of advisors. And, you know, that’s prime time for social engineering when when everybody’s slammed and busy. And you’re in an abnormal event. And I think right now we are in an extended abnormal event. I would actually start with personally not the tech because I think sometimes we chase shiny objects pretty quick. I would start with what’s your control framework? What are your risk protocols and controls that exist both in your physical and your digital channels. Secondarily, I would love to add what we talked before, which is inter channel arbitrage, or omni channel. So look across the client treatment plan that occurs across your entire landscape, whether it be physical or digital, and understanding what the seams are. I know that that suggestion is incredibly hard, because it requires leaning into the width of an organization. And the larger the organization, the more difficult it is. But if you try to layer technology on top of sort of a weak control system, it’s probably going to do more to accelerating points of weakness, as opposed to mitigating them. So the technology definitely has a high propensity for success has a high probability of achieving great outcomes. But I would lean into first order principles around your control structure and your operating model first. Well, it probably just probably a strong view.
Matt Miller
Yeah, I think one thing that was interesting is, you know, over the past year and a half, we have seen an increase in in call center fraud. You know, we did some work with several institutions, when they push their call centers to be virtual. And many of the controls that we’re putting have historically been put in place around sensitive call centers, or physical so being able to monitor the people, you know, in person making sure that they don’t have cell phones on them to take pictures of screens. All these were impossible to do these physical controls when you have people in the call centers working from home. And so, in reading that visioning kind of the controls, how would you monitor someone when you’re not looking over their shoulder, we had to really get creative and really start to understand what those business processes look like and, and really build into the framework of the technology things like, are they pulling up a customer record that never even called into the call center? And so that’s where it can tie into into privacy, getting access to the data, you know, how do you prevent someone that’s at home, taking a picture of their screen, and collecting information. And there are some interesting things you can do with machine learning in detections to be able to understand, you know, different patterns of call center reps in the interaction model that they have to be able to detect when some of these kinds may be taking place.
Loraine Lawson
True, did you have anything to add to that?
True Brown
I not be good on that.
Loraine Lawson
Okay. Finally, I’d like to ask each of you, but perhaps Rami can kick us off, what’s the biggest mistake you see in dealing with fraud and cyber security, and maybe you can share a quick best practice to counter it
Rami Thabet
started become like a broken record on this one. Don’t silo, the amount of organizations have seen where cyber doesn’t talk to fraud, doesn’t talk to the business and says on cyber, I’m gonna protect the front door on fraud, it’s not a business, you can’t know my rules, etc. Organizations are inherently vertically optimized, I would stress upon the group to think about protecting your customer as a true horizontal, a true horizontal across the organization, it’s stuff, it’s hard to get going it is to be three years, three years of trying to convince and finally we got to going as a horizontal and work with incredible colleagues across our organizations, but you truly have the best shot at protecting your organization for the long term, if you do it that way.
Loraine Lawson
True?
True Brown
again, breaking down the silos that’s, that’s number one. Number two is I think it’s the planning, the planning aspect, when institutions are rolling out new platforms, new product lines, so forth, that they’re not aligning, or they’re not, they’re not working ahead or bringing in all the appropriate business partners at the planning stages. And that people have to play, try to play catch up, or do a plug in after the fact. So when a roll out, will say something with a faster payment platform, you need to bring in the BSA, you need to bring in the fraud, you need to bring in the IT security call centers, everybody needs to be brought on board. And again, the business units themselves just can’t push a product forward without engaging their partners. And again, it’s I think it becomes more expensive as you try to play catch up to make sure that you have all the right tools in place to you know, meet the regulatory requirements, and also to reduce the fraud landscape. I mean, again, it’s a matter of the business may decide that this is great for our customers, this will be a great product line. But again, what is that? What’s the impact as far as as far as the fraud landscape that needs to be addressed upfront?
Loraine Lawson
And Matthew?
Matt Miller
So I, I wouldn’t have started with fusion as well. So I think that’s, you know, bringing and breaking down the silos. But I think, you know, one of the areas I would say is eradicating, you know, legacy, bad business practices. So you know, we’ve seen a lot of even high value transactions be initiated with payment instructions through things like email, which is completely unauthenticated in institutions need to be willing to recognize that that’s and that no, no longer a safe method of doing voice callbacks is no longer a way to be able to just own people don’t know their customers like they used to, to be able to validate. And so being able to understand where risk exists in something that is very legacy, and to be able to move and adopt new methods to be able to reduce fraud is key.
Loraine Lawson
Thank you. That’s all the time we have for today. This was an excellent webinar. As a reminder, this event was recorded and we’ll be available for reviewing on Bank Automation News. A huge thank you to our panelists, true Brown, Matt Miller, and Rami Thabet for presenting this excellent webinar. And thank you to everyone who joined us today. Have a great day.
Matt Miller
Thank you.
True Brown
Thank you.
The real world poses as much of a threat as the online one, cybersecurity experts said in a Thursday webinar hosted by Bank Automated News. Synthetic identity fraud occurs when a criminal combines stolen identification, such as a Social Security number, with other identifying information to create a new, false identity.
“One of the significant challenges with cyberfraud is changes in not only technology, but the world around us,” said Matthew Miller, U.S. cybersecurity services banking industry lead at KPMG.
“The areas I think that have had significant impact on cyberfraud is the deep and dark web — areas where cybercriminals are able to create marketplaces to be able to acquire stolen identities — tax documents and pictures of driver’s licenses. We also have identities out in Facebook and social media that are able to be grabbed fairly easily, and there are markets for those identities” Miller added.
“There’s a good trade-off. They can purchase them for a little amount of money, and actually see a return on the investment,” he said.
Virtual currencies, such as Bitcoin, have had an impact too, Miller noted.
“The ability to be able to transact anonymously, for these transactions has made it difficult for people like us that are defending against synthetic identity fraud and account takeover,” Miller said.
True Brown, senior vice president of Financial Crimes Risk Mitigation at Simmons Bank, agreed that synthetic ID fraud has been a major problem for financial institutions.
“There’s a lot of vendor tools out there that can help identify, but nothing is perfect,” Brown said. “Everybody tries to build the best mousetrap; the fraudsters are also trying to beat those mousetraps and constantly find innovative ways around it.”
Brown said he relies heavily on third-party products to help secure the bank’s onboarding process. “It all starts at the onboarding of new accounts to ensure that it’s not a synthetic ID, or give us assurance that Social [Security number] or the information is associated with the real person.”
Rami Thabet, vice president digital product at the Royal Bank of Canada, described cyberfraud as not only a “chronic challenge, digitally and physically,” but a business challenge.
“This is not a cyber-challenge. We view it as a [know your customer issue] and a core obligation that you have as a financial institution,” Thabet said.
To that end, RBC has partnered with a network of data providers that help weed out ID theft, working with customers to improve security.
“We actually have set this up as an ongoing, evergreen program on the business side so the business is taking accountability for their protection … This is not a cyber challenge, not a technology challenge to do it; it’s a business challenge.
“Every financial institution has the obligation to know their customers and to provide proper [anti-money laundering] rendering. Just moving into the digital space where more of your volume is happening in a digital self-serve way … actually just puts a heightened importance to doing this in a more robust manner,” Thabet added.
The following is a transcript generated by AI technology that has been lightly edited but still contains errors.
Hello everyone and thank you for joining Bank Automation News for the special webinar on automation technology for exceptional bake cybersecurity and Id verification. I’m Loraine Lawson, deputy editor with Bank Automation News. If you’re here, you’re no doubt aware that the cybersecurity landscape is constantly changing. Today we’ll examine that landscape and discuss best practices in cybersecurity and identity, identity verification that can help financial institutions work fraud and other debts. With us today are True Brown, Senior Vice President Financial Crimes risk management persimmons bank, Matthew Miller, US cybersecurity services bank industry lead at KPMG and Rami Thabet. VP of digital product at RBC. Thank you. If each of you wouldn’t mind giving a brief introduction of yourself starting with True:
True Brown
Hey, good morning, everybody. Yes, my name is True Brown. I am with Simmons Bank. We are a regional financial institution based out of Arkansas, with a footprint in six states, primarily brick and mortar up to about a year or so ago and now we are have been heavily expanding our digital footprint. Prior to come into Simmons a year ago, I served as Director of Financial Crimes investigations at USA, which again, is a very large institution heavily heavily entrenched in the digital marketplace. And prior to that 20 years retired federal law enforcement with the FBI financial crimes. So again, and from there, I can easily say that I cut my teeth in investigations, looking at financial frauds, primarily identity theft matters. And 28-35 years later, is the same problem except now it’s done through digital channels. Thank you.
Loraine Lawson
Thank you True. Matt?
Matt Miller
Hi, Matt Miller. I’m a partner at KPMG in financial services, about 25 years experience in cybersecurity and really focused on the intersection between cybersecurity and fraud. Prior to KPMG, I was came out of industry where I ran the anti fraud programs focused on insider threat and cyber security for the banking industry, both federal regulators and banks on Wall Street.
Loraine Lawson
Thank you, Matt. And Rami?
Rami Thabet
I’m the Vice President of digital product, Bank of Canada. And my focus come at this not from the cybersecurity angle, but more from building client experiences and wonderful client experiences for both the digital and physical domain, and integrating things like identity and verification and security practices in great customer onboarding experiences.
Loraine Lawson
Thank you, Rami. Just a reminder today that if you have any questions for our panelists, you can submit those through the chat. The cybersecurity brand landscape are constantly changing, of course, Matt, can you give us an idea of what the big challenges are in the current landscape? And specifically, I’m hearing about synthetic identity fraud is a major challenges today. So maybe if you could explain a bit about that?
Matt Miller
Yeah, I think, you know, one of the significant, you know, challenges with with cyber fraud is is changes in not only technology, but the world around us. And so through the areas, I think that have had significant impact on cyber fraud. One is the deep and dark web. So areas where cyber criminals are able to create marketplaces to be able to acquire, you know, stolen identities, you know, tax documents, pictures of driver’s licenses, we also have identities out in Facebook and social media that are able to be grabbed fairly easily, and the markets for those identities. You know, there’s a good trade off, they can purchase them for a little about a month amount of money and actually see a return on the investment. The other area that has really had impact is virtual currencies. So the ability to be able to transact anonymously, for these transactions has made it difficult for people like us that are defending against synthetic identity fraud and account takeover.Loraine Lawson
True. Are you seeing anything similar to that?
True Brown
Well, I’m coming from a digital environment institution to one that is now really launching those products. I see it from both sides. I mean, I see I see it, the full landscape against synthetic ID has been a major problem. And again, there’s a lot of vendor tools out there that can help identify, but nothing is perfect. I mean, as everybody tries to build the best mousetrap. The fraudsters are also trying to beat those mousetraps and they constantly find innovative ways around it. Again, everything is available on the dark web. I mean, I think we’d be naive to think that our personal information isn’t out there from the various breaches, you know, and other other tools that the forces are using to get our data. Again, I rely heavily on third party products to help secure our onboarding process, it all starts at the onboarding of new accounts, to ensure that it’s not a synthetic ID, or give us assurance that social or the information is associated with a real person. And also, there’s been a lot of developments, as far as verifying the government IDs themselves, the driver’s license, per se, again, initially, it was sort of like one of the vendors out there would say, the ID fits a certain format it looks like and it works has all the earmarks of a valid driver’s license, there are now some services out there that are tied to the DMV, in certain states, and that gives us a little bit, a little bit more comfort that we are always dealing with a real person. Now, if the person is good or not good, what their intent is, you know, that’s, you know, that’s a totally different conversation.
Loraine Lawson
Sorry, I was just gonna say, I know you work with identification. So maybe you can speak to that and talk about what it means to automate, say, know your own customer, especially as it relates to identification.
Rami Thabet
Yeah, no, absolutely. I mean, I’m picking up where Matt and True left off. This is a chronic challenge both digitally and physically. We’ve seen the bad guys actually not be shy at presenting in a physical location in front of banking advisors with synthetic ID. So they’re not exactly shy. This is also a business challenge. This is not a cyber challenge. We view it as a KYC. And know your customer, and a core obligation that you have as a financial institution. And the path we’ve taken is exactly what Trudeau has said is we’ve partnered with an extensive network of data providers, we do ID verification, government ID verification, we leverage ID. So it’s not just scanning the ID looks, the way it looks at actually scans against attributes of government IDs to verify their legitimacy, we also actually scanned selfies, we asked our customers to do that for their own protection. So it’s not an invasive measure by any stretch. It’s a guided experience. And it’s all done with privacy in mind on the client’s device. So they are assured that it is all happening with privacy considerations in mind. And we’ve had nothing but stellar feedback from our clients, that we are literally looking after their security, privacy and true identity from the day they begin a relationship with us. Is that all third party driven? Or is that some custom bill? It’s a combination, actually, we view it as a combination. And for our from our perspective is we lean into many wonderful partners in the enterprise, but we also build our own proprietary capabilities and technology to augment where the market has simply not not been there yet, or has not matured yet, in that space. You know, secondarily, we actually have set this up as a ongoing evergreen program on the business side. So the business taking accountability for their protection, like I said at the beginning, this is not a cyber challenge is not a technology challenge. It’s a business challenge. And you know, every every financial institution has the obligation to know their customers and to provide proper PML rendering, just moving into the digital space where more of your volume is happening in a digital self serve way does not abdicate from those accountabilities, it’s simply actually just puts a heightened importance to doing this in a more robust manner.
True Brown
Rami, I think you bring up an excellent, excellent point when you’re talking about synthetic or ID theft in branch where somebody actually shows a count of a driver’s license or government ID. And it passes. I mean, inherently, people look at online and digital transactions as being riskier than in breach. And the inherent risk is much greater. But the residual risk if you have the right tools in place, could be as secure and in some cases more secure if you’re using those tools properly. So again, just because somebody walks in branch doesn’t mean they can’t open up a fraudulent account versus an on line. Same thing happens but again, if you use the right tools, you think you can get a similar level of comfort as having somebody standing there right in front of you with my opinion.
Loraine Lawson
Matt, have you seen any best practices along that regard when it comes to identification?
Matt Miller
We have so so um, one thing that we do is we actually scan a lot of the consumer banks in terms of understanding not only their identity proofing controls, but also their authentication mechanisms after someone has established an account. And you know, what you’ll see is dependent on the institution, there’s many different channels where the user experience requires them to authenticate, whether it’s the ATM, your mobile app, website, potentially in the branch or even through a call center. And there needs to be a convergence of in terms of best practice in terms of how you authenticate. And those those methods. Right now the attackers do go after the lowest common denominator, or the easiest point of access, whether it is through the call center, and and they use that to, you know, take over people’s accounts to be able to change some of the credential information or or even addresses and, you know, that causes risk for for everyone in the in those service areas. So, you know, we are seeing best practices where organizations are moving to having things like password list authentication, moving away from knowledge based questions for resetting credentials, or even moving away from SMS or per step up authentication for sensitive transactions. So those are the trends that we’re helping and guiding our clients down that journey.
True Brown
Excellent, because I know we’re here we’re talking about the digital threats. But even though there’s digital threats, you still bring it back to the human element. And social engineering at its most basic element, I guess, with the call centers, then makes the digital channels vulnerable, as the you know, customer information is changed, the passwords are changed, and so forth. And that’s that’s where we really have to have heightened authentication processes.
Rami Thabet
Yeah, to add to True and Matt commentary, tongue in cheek, we often say, you know, the bad actors, or the male actors in the system are have been omni channel for a long time, we need our, you know, they fraudsters have adopted omni channel behaviors, years before we’ve adopted the technologies and the practices. And so closing up this seems, across the organization, is the best practice that we have discovered through trial and error, which fundamentally means you have to look at this in an incredibly different way. From an organizational perspective, you really need, you know, wide sponsorship across the financial institution to, to really lean into the protection measures, you’re gonna need your branch colleagues, you’re gonna need your digital colleagues, you need your fraud colleagues, you’re gonna need your advice, central colleagues, and the collection of the totality. And it’s quite rare that all of those functions resolve up into the same senior executive. So this becomes really an all hands on deck leadership, call to action.
True Brown
And Rama, you’re exactly right. I mean, somehow these to be effective ministers will be effective in addressing these matters, you have to break down the silos. And from my experience, the larger the institution, the more difficult it is to break these silos. And again, and this is also what the regulator’s look at when they come in, they want to make sure that there is coordination and connectivity between IT security between the fraud groups between, again, call centers, frontline, the BSA areas, they are looking more and more to seeing that institutions have that open line of communication. And not only do they say they have that they can show and demonstrate that, that it is the actual practice.
Loraine Lawson
I have a a reader question or a viewer question. Sorry. That sort of relates to this, when do you estimate a wider rollout of blockchain based government issued and managed ID systems? Have you all heard anything about that?
Rami Thabet
Maybe I’ll jump in. So I would say I’d parse that question a couple of different ways. There’s three questions within that. I would say blockchain based digital identity is still very much in its early days in Canada, as some folks may be aware, the banks, the major financial institutions that bank, the majority of Canadians have rolled out a block chain based digital ID platform. It’s actually my team that’s been participating in now. And we’ve had some early successes, but it’s still very early days and excited by its capability excited by its likelihood for success. And frankly, its ubiquity and the promise of ubiquity. The question around government issued I block identity was just a government issued period anything very much depends. I think on the geography I’m not equipped to speak on the US landscape but within the Canadian lines. We have a number of provinces, we have a number of territories and government, federal government institutions, and they all have efforts underway. But timetables, I would say are, are still indeterminate. And we continue to work with them. So, you know, I would say Rami’s perspective, again, purely Rami’s perspective on this one, I hypothesizing into the future. I think we’re going to be in an environment of multiple digital identities. The question is, hopefully it resolves into a handful that is that are highly used highly ubiquitous, that have a tremendous amount of trust factor underneath them, but it is very much the next battleground of competitiveness is this digital ID space.
Loraine Lawson
Matt, True anything about it?
Matt Miller
I think I think we’ll actually start seeing blockchain use outside of identity proving probably earlier in the area, you know, transaction monitoring and fraud. We do already see other areas of API-driven security that allow, you know, banks to connect in kind of open ways where they can validate other identities. And even through the fintechs, being able to get access to you, either monitoring people’s accounts, converging data, doing analytics and the rest. So there is this notion of trust in financial solution systems working together. So we may even see something outside of the government that moves faster than government identities in this space.Loraine Lawson
True have anything to add?
True Brown
I have nothing beyond what they have provided.
Loraine Lawson
Well, I wanted to ask you drew, you work primarily with fraud and Bank Secrecy Act, which of course relates to money laundering, what are some best practices you can recommend? So banks can be sure they don’t run afoul of regulators?
True Brown
Well, if it’s a it’s a matter of the question, not running afoul of the regulators, I mean, there’s obviously very low hanging fruit, which is making sure that you know, you’re addressing everything timely, you’re meeting all the regulatory requirements for your, you know, your CTR GSR filing, so forth. But really what we, what we’ve experienced, so I’ve experienced, avoid, the last couple of exams, has been, you know, making sure that everything is so well documented, you have your procedures, you have your policies, but in the eyes of the regulators, if it’s not documented, it’s not tested, it doesn’t exist. So they’re not going to take your word for it. Everything has to be, you know, eyes dotted T’s crossed from a regulatory regulatory standpoint. Again, said earlier, what they’re really looking at now is the connectivity between the various business units. Again, I come from primarily a fraud background. So usually, when the regulator’s came in, you know, I, they took a look at us, but you know, he’s really heavily focused on the BSA side. But we’re seeing more and more emphasis in exams and the questions posed by the examiners, regarding again, that open documented connectivity between AML and fraud. And now also IT security regarding potentially cyber related incidents, are they being investigated? Or are they being reported properly, and so forth. So we see a lot of that connectivity. And also another big factor that the regulators are starting to really look at. And Matthew may be able to jump in on this is the internal threat. You know, I had not seen it before. But you know, over the last two or three years had I’ve had several questions asked us and presented to us regarding, you know, documenting our internal threat, our internal threat policy, and what our internal risks are. So again, to keep the regulator’s at bay, good policies, documented policies, your risk assessments, regular risk assessments, testing of your tools, the modeling, calibration, all those things need to be done on a timely basis, because those are the things the examiner is going to ask for when they walked in the door. No, that’s it. That’s all low hanging fruit.
Loraine Lawson
Matthew, do you have anything to add to that?
Matt Miller
Yeah, I mean, to comment on insider threat, we are seeing at least us regulators focus on insider threat and having our financial institutions have well established insider threat programs. You know, there’s plenty of examples where there have been, you know, cases and arrests, everything from insider trading to embezzlement of that involve true insiders. And and there’s real risk there. In So, you know, they are looking for people to build programs that use next generation technologies for behavioral modeling to try to identify who these individuals may be. There’s also you know good ways where you can just look at your common business practices and see where you may be adding risk into your environment. You know, we’ve had a lot of emphasis on segregation of duties and kind of toxic combinations being good, strong controls around things like financial statements, but they’re not necessarily a strong control in like the payment space, especially where you may have collusion. And you get two people together a segregation visa isn’t going to solve that problem.
True Brown
In a back to me, all of it is knowing our customers, they’re going to make sure that they will make sure that the institution’s know who their customers are, who has been designated as a high risk customer, and have we done the, you know, the required due diligence enhanced diligence on these customers. So I mean, that mean, those are all basic staples of a BSA program, part of the pillars, and, you know, those were we really need to be addressed when the examiners walk in the door.
Loraine Lawson
Rami are you facing in Canada that are similar?
Rami Thabet
Well, they’re very similar themes, I think, you know, insider threats are as prevalent have always been as prevalent as outside threats. And you need to establish robust controls internally, as well as programs. So, and many of the same capabilities and digital technologies that we use for external facing or client facing aspects can be focused internally. And I think that’s always in a promise, I think, you know, one of the areas I would flag as a best practice is pulling the fraud group, less out of the back office and more into the front office with the lines of business, and having it be an integrated function around the protection of the organization and reframing the dialogue, away from, you know, fraud, protection and cyber protection, something that happens in the shadows of the organization and is more thoughtful design, from the beginning from the get go. You know, if we framing protection as an amazing client experience, that establishes trust, you know, there’s no greater loyalty indicator, or loyalty driver of your customer than trust. And trust can really be anchored in a meaningful way by building protection and meeting client experience. So, you know, typically, we’ve viewed fraud as a point of friction, or fraud protection is a pointing of friction and experience, we got to reframe that entire discussion to say, it’s actually a point of loyalty and reducing client attrition in the longer term.
Matt Miller
guy would agree with that. And we’re seeing clients even, you know, notionally moving away from fraud, which was historically driven out of incidents or events that did occur, and needed to be reported and resolved and potentially recovered to building anti fraud programs. So getting into those preventative areas and making sure that fraud does not occur in the first place. And pushing that towards the customer experience, you know, imagine going to purchase a good at a store and all of a sudden, you get an embarrassment, because there’s a fraud alert in your card doesn’t work is a totally different experience, then all of a sudden, you go to purchase, and you get an automatic alert on your phone that says, Are you at this store? Is it you are you doing that, and you’re able to see in real time, let that transaction go through, you can now build real strong brand loyalty on to that that card that did work, not the one that gets denied. And so there’s awesome opportunity with technology as evolves to really create that user experience, that then becomes really the customer expectation for every type of financial mechanism that they leverage.
Rami Thabet
One thing to add to that map is its biggest moment of truth in a relationship, and how many programs and how many fraud groups along with their client experience in digital counterparts ask the question of what’s the experience wants the event campus, so we’re so focused on preventing it, but it will happen. It will happen to some, you know, unfortunate clients, and we, you know, we all work with them quite proactively. But the question is, what was that experience, and that experience can go from something incredibly traumatic to something incredibly traumatic, but that was mitigated and reinforced client loyalty value, something as simple as, you know, digital capabilities like you had just cited, but even something as simple as an outbound call, a month later or a week later, say, how are you doing? I hope everything is now settled and you’re on your way and you know, you have no lingering effects. Those go a long way for building long term client value. You know, you knew that a client is not going to leave you for life. You’ve got a client for life.
Loraine Lawson
I can agree with that. As someone who’s actually experienced fraud, that it can be a make or break experience for for a bank. Is there any regulatory actions Congress or lawmakers can do to make your job as cybersecurity specialists easier and have lawmakers put up any roadblocks.
Matt Miller
They there, I think they are very helpful, I think, you know, bring the toy climate today is really trying to push, at least my clients to move in the right direction and to really evolve their thinking. One good example would be the FFIEC just released guidance on on authentication controls. And it was very comprehensive in terms of looking at the consumer experience, as well as enterprise authentication and making sure that they’re continually evolving and trying to stay up above these, these threats that mature daily.
Loraine Lawson
True, do you have anything to say to that?
True Brown
Again, regarding the FFIEC guidance, I mean, it’s an it’s an excellent documentation regarding the authentication practices, transactional monitoring, best practices, I mean, not sure if it’s requirements, it’s really more more was best practices. But it does give a good roadmap for financial institutions, or actually any businesses that have a digital footprint on what they need to be doing and looking at to to ensure that they have a secure platform for their customers and for in house. I mean, it’s also addresses access to platforms internally, as well as external. But again, as far as, you know, guidance, or regulations, I mean, actually, I would have to Matthew, I think I would have a little bit of a different differing opinion that some of the recent regulations make it a little bit tougher financial institution, especially with fast pay and the faster payments going on with the P2P , and the, you know, the ACH channels regarding the responsibility of the banks, as they adhere to Reg E and investigating some of these matters. So I mean, the level of where they’re placing the responsibility, I think can be a little bit difficult on some of the financial institutions.
Rami Thabet
Yeah, I think, you know, say, both from a Canadian and US perspective, I would look at our regulatory partners at establishing crystal clear rules of engagement, accountabilities expectations, and setting the bar, I think leaning into the private sector for implementation and outcomes, and really holding the bar on that with with the banks is, is sort of the key ingredient for success, if I would have a single call to action is really more digital document and more understanding within the within the regulatory arms of the new landscape we’re all dealing with at this point, and I think we spend an, you know, an exorbitant amount of time on education, outreach, understanding and shared mutual perspective on what’s really happening. And, you know, that creates a good point of departure.
Loraine Lawson
I wanted to talk about credential stuffing, which has been in the news recently, it’s not necessarily a new thing, but cybersecurity firm Akamai says financial institutions face 3.5 billion attacks using stolen credentials in 2020. Are there ways in which new forms of identification verification can help with that? What’s the best automated defense? Matt, can you start us off?
Matt Miller
Yeah, so I mean, it’s definitely increasing. And what they are doing is they’re picking up passwords, in bulk, that they either harvest through malware or, or that they acquire through, dumps on on the dark web, and they just replay your credentials, you know, back to the bank that they’ve stolen. And so from a user, there’s definitely best practices in terms of not using the same password everywhere, having low risk passwords for certain things you do in your activities, like reading news, and, and having longer more complex passwords for, you know, financial transactions and those institutions. But really, the move needs to be towards some type of multi factor authentication or a passwordless model. And you know, those institutions that have not provided that type of service to their customers put their customers at risk, those institutions that offer it and know that, but their users have not fully adopted it because of the customer experience or also putting their their clients at risk and, and in turn, it puts the institution at risk. Because when someone does credential stuffing and does get to take over an account, that’s where you add additional money laundering risk to an institution for someone that may be using it as a money laundering funds. So, you know, technology needs to evolve users need to evolve as well in terms of their awareness and adopting some of these controls in order to really, you know, remediate that risk. You do see some things today that are helping. So if you go, you know, into an iPhone or other technology or even the Google platform, they start to identify for you, which of your passwords have been stolen. And so it’s up to those users to be able to go in and make those changes and protect.
Loraine Lawson
True, Rami, do you have anything to add to that? credential stuffing battle?
True Brown
Well, I was gonna, I was gonna ask Matt, a question regarding the credential stuffing, when the forces are successful, you know, with their scripted attack, and they have been able to your experience, when they have been able to match up a password to an online ID, are you seeing an account, you typically see an account takeover right away? Or is it again, is this just another business aspect where that now they are going to then package that up and sell that on the dark web?
Matt Miller
Yeah, it varies, you know, a lot of times, you will see them not use it right away that, you know, they’ll they’ll take over the account. And they’ll monitor it, and though they’ll keep pinging it, and you can use that to detect some activity, because in certain circumstances, yes, they hire people that actually log into these accounts and bypass the controls, and others that use bots and other types of things to be able to continue to potentially act, see if the account is accessed and still available and ready for that time when they need that money. So in sometimes they’re trying to collect multiple accounts with the money can link together in order to move money very quickly, with setup transactions. So it really it really does depend. But I think there’s probably a lot of accounts out there that have already been that are known to be compromised by malicious actors that, in turn are not being actively used for financial crimes today. But there’s also a lot that are.
True Brown
Well, I’m glad you I was waiting to see what your answer would be macro skin for my experience was when we actually did see scripted credential stuffing attacks, we would come back afterwards and said, well, nope, nobody did anything to the account. So people put their guards down. And again, we’d reach out to the customer if was identified and hopefully tell them, you need to change your password. But again, I think it was just being naive by the institution’s part not to think that information was not going to be then exploited sometime down the road by on an account takeover. And not everyone wants to launder money. I mean, some people will go and they’ll package up these accounts, and they’ll actually sell them. So that you know, it becomes a commerce for them as well. Yeah, you absorb experiences, when we have we saw these type of activities, and the accounts were taken over, it would have been for, you know, for not for money laundering, it would be to, you know, just, you know, empty out the accounts.
Rami Thabet
So, I mean, I think I’ll pick up a couple of threads that Matt and True have have jumped us off on. Make your you know, password reset on logging experience exceptional, make it easy, make it understandable, make it simple. You will need to operate with your clients knowledge and, and their digital capability. That’s sort of number one, communicate often and regularly. So, you know, the first thing I typically see in organizations is the first thing to get the scope is that, you know, email SMS notification to the client around, hey, somebody your password has been reset, did you intend to do this, it’s like the easiest feature to do scope. When you run out of money. Yet, it’s one of the most critical at inviting your clients to be as vigilant as you are. Build programs that monitor your entire lifecycle of your account opening process. And that does not mean once the account is open, and you’ve verified their ID that it’s legitimate for KYC and AML. That means four days later, are you starting to see large checks in and out or large cash amounts in and out? Are you What’s the activity is it’s starting to become normal. The other is start to know your clients digital devices. So the concept of the trusted device is something we use quite extensively. And we have had significant success with clients definitely some opting in wanting to wanting us to know their device so that we can protect them. All of these are multitudes of protections and capabilities, that they’re not going to make credential stuffing go away. But they make it less cost effective for the bad guys and, and the male actors and it’s just it’s a business case, the business case this as much as you know banks, business case initiatives, and often we talk about a you know, an iPhone is a very expensive device. And if you’re, you know false and you’ve picked up a bunch of iPhones and Android phones that are fraudulent over are being used by my actors, and they’re no longer usable in your enterprise. That’s a very expensive business case for the male actor. And eventually they move on to a softer target. And we hate to see fraud moves elsewhere. But that’s, that is a tactic around how we’ve protected ourselves. And the last is inter bank cooperation, I think it’s incredibly important to have inter ephi. inter organization cooperation, because you have a responsibility, if you see something, that you notify your colleagues and peers who have an opportunity to take action as well and protect the entire ecosystem.
True Brown
Rami, that is an excellent next one point, it’s something I think has really been developing over the last or expanding over the last three years or so the idea of consortium data, you know, entities that are happening again, unfortunately, it’s a pay to play, to receive the consortium data, you have to probably be paying for a service, or so forth. But this consortium data is an excellent tool to identify potentially bad actors by name or by device, and so forth. So again, I know in the past, we did a lot of device recognition, work from an investigative standpoint, and we would, again, we could see the same device fingerprint, touching, you know, 15, 20 different unrelated customers. So it’s not like one device in a house, touching all the family members. And we did take successful action and blocking the devices. And then they would, you know, again, occasionally would see a new device show up. But our thought is they left our institution and went to target another institution, you know, again, hate to push the fraud someplace else. But again, first concern is reduced my own fraud landscape.
Loraine Lawson
We have a question from a viewer that says they have been the victim of monies being stolen due to branch personnel, and notes that call centers are slammed. And the question is, are neural networks like chatbots evolved to help? Is it a balance of privacy versus security? Matt?
Matt Miller
Yeah, well, I know Romney was going to speak up, so let him go first. And
Rami Thabet
That’s probably the face was my tail on that one. I, I guess I probably overreact to to chatbots. I have seen so many chatbot use cases that have had not the greatest business impact, there are many out there that are incredibly successful. Technology has an opportunity, like neural networks, as you mentioned, in your question, an opportunity to really help manage and mitigate these types of risks, especially when capacity is a concern. You know, oldest game in the book is wait for the advice centers to get slammed and tried to sneak in due to cognitive load of advisors. And, you know, that’s prime time for social engineering when when everybody’s slammed and busy. And you’re in an abnormal event. And I think right now we are in an extended abnormal event. I would actually start with personally not the tech because I think sometimes we chase shiny objects pretty quick. I would start with what’s your control framework? What are your risk protocols and controls that exist both in your physical and your digital channels. Secondarily, I would love to add what we talked before, which is inter channel arbitrage, or omni channel. So look across the client treatment plan that occurs across your entire landscape, whether it be physical or digital, and understanding what the seams are. I know that that suggestion is incredibly hard, because it requires leaning into the width of an organization. And the larger the organization, the more difficult it is. But if you try to layer technology on top of sort of a weak control system, it’s probably going to do more to accelerating points of weakness, as opposed to mitigating them. So the technology definitely has a high propensity for success has a high probability of achieving great outcomes. But I would lean into first order principles around your control structure and your operating model first. Well, it probably just probably a strong view.
Matt Miller
Yeah, I think one thing that was interesting is, you know, over the past year and a half, we have seen an increase in in call center fraud. You know, we did some work with several institutions, when they push their call centers to be virtual. And many of the controls that we’re putting have historically been put in place around sensitive call centers, or physical so being able to monitor the people, you know, in person making sure that they don’t have cell phones on them to take pictures of screens. All these were impossible to do these physical controls when you have people in the call centers working from home. And so, in reading that visioning kind of the controls, how would you monitor someone when you’re not looking over their shoulder, we had to really get creative and really start to understand what those business processes look like and, and really build into the framework of the technology things like, are they pulling up a customer record that never even called into the call center? And so that’s where it can tie into into privacy, getting access to the data, you know, how do you prevent someone that’s at home, taking a picture of their screen, and collecting information. And there are some interesting things you can do with machine learning in detections to be able to understand, you know, different patterns of call center reps in the interaction model that they have to be able to detect when some of these kinds may be taking place.
Loraine Lawson
True, did you have anything to add to that?
True Brown
I not be good on that.
Loraine Lawson
Okay. Finally, I’d like to ask each of you, but perhaps Rami can kick us off, what’s the biggest mistake you see in dealing with fraud and cyber security, and maybe you can share a quick best practice to counter it
Rami Thabet
started become like a broken record on this one. Don’t silo, the amount of organizations have seen where cyber doesn’t talk to fraud, doesn’t talk to the business and says on cyber, I’m gonna protect the front door on fraud, it’s not a business, you can’t know my rules, etc. Organizations are inherently vertically optimized, I would stress upon the group to think about protecting your customer as a true horizontal, a true horizontal across the organization, it’s stuff, it’s hard to get going it is to be three years, three years of trying to convince and finally we got to going as a horizontal and work with incredible colleagues across our organizations, but you truly have the best shot at protecting your organization for the long term, if you do it that way.
Loraine Lawson
True?
True Brown
again, breaking down the silos that’s, that’s number one. Number two is I think it’s the planning, the planning aspect, when institutions are rolling out new platforms, new product lines, so forth, that they’re not aligning, or they’re not, they’re not working ahead or bringing in all the appropriate business partners at the planning stages. And that people have to play, try to play catch up, or do a plug in after the fact. So when a roll out, will say something with a faster payment platform, you need to bring in the BSA, you need to bring in the fraud, you need to bring in the IT security call centers, everybody needs to be brought on board. And again, the business units themselves just can’t push a product forward without engaging their partners. And again, it’s I think it becomes more expensive as you try to play catch up to make sure that you have all the right tools in place to you know, meet the regulatory requirements, and also to reduce the fraud landscape. I mean, again, it’s a matter of the business may decide that this is great for our customers, this will be a great product line. But again, what is that? What’s the impact as far as as far as the fraud landscape that needs to be addressed upfront?
Loraine Lawson
And Matthew?
Matt Miller
So I, I wouldn’t have started with fusion as well. So I think that’s, you know, bringing and breaking down the silos. But I think, you know, one of the areas I would say is eradicating, you know, legacy, bad business practices. So you know, we’ve seen a lot of even high value transactions be initiated with payment instructions through things like email, which is completely unauthenticated in institutions need to be willing to recognize that that’s and that no, no longer a safe method of doing voice callbacks is no longer a way to be able to just own people don’t know their customers like they used to, to be able to validate. And so being able to understand where risk exists in something that is very legacy, and to be able to move and adopt new methods to be able to reduce fraud is key.
Loraine Lawson
Thank you. That’s all the time we have for today. This was an excellent webinar. As a reminder, this event was recorded and we’ll be available for reviewing on Bank Automation News. A huge thank you to our panelists, true Brown, Matt Miller, and Rami Thabet for presenting this excellent webinar. And thank you to everyone who joined us today. Have a great day.
Matt Miller
Thank you.
True Brown
Thank you.






