By Ray Birch
ST. PETERSBURG, Fla.—Perhaps it’s now time for CSI: Credit Union Payments.
Fraudsters are becoming so clever with their attacks that payments processors and credit unions need to perform like agents from the TV show to stop them, asserts one analyst.
Brian Scott, SVP of sales and solutions consulting at PSCU, said the CUSO’s fraud team essentially dons their CSI hats every day, looking for the very smallest connections between incidents of fraud. The team uses a linked analysis tool, a form of machine learning, to pull out the “needles in a haystack” that may actually be signs of widespread fraud.
“Every fraud incident has the potential to be part of something larger,” said Scott. “I often hear credit unions say, ‘Oh, that’s just some random fraud incident.’ Well, it’s probably not. It’s probably part of something larger. And that is where we have to become like CSI investigators—fraudsters are getting smarter, so we have to get smarter, as do the tools we use to track down, prevent and monitor fraud.”
What’s changing, explained Scott, is crooks are moving away from large-scale attacks on any one institution or batch of cards. Instead, they are spreading their attacks across many institutions, picking accounts here and there to avoid detection.
Stopped Attack On 100-Plus CUs
Scott gave an example of how PSCU recently used linked analysis to spot and stop a fraud attack that targeted more than 100 credit unions across the country.
“We have three accounts from three different credit unions that we spot fraud on,” said Scott. “These are three, random incidents of fraud. We plugged them into our linked analysis tool, which looks at data and information from lots of sources. It’s not just payments data the tool looks at, it is data from our call center, HR data, and much more.”
The tool uncovered that in each of the three fraud incidents there was one similarity.
“We realized that those three accounts had experienced phone calls into our call center,” said Scott. “The caller did not speak to a live person, they just got to the IVR. That was the commonality we spotted.”
The team then uncovered that the calls had come from England and were from a disposable phone.
“We took that information and said, ‘What other accounts in our 900-credit union database had phone calls into our IVR from that same phone number,” explained Scott. “We found 100 more accounts. We blocked all those accounts and right after we did that we began seeing the fraudulent transactions come through.”
Scott noted that sometimes a fraudster will change an address on an account, take it over, and then later have new plastic sent.
“Again, we found a few accounts that had fraud on them and it turned out the common link was address,” said Scott. “All these accounts had the same address, a PO box in New York. So we searched our databases for anyone else who had the same PO box address and were able to stop fraud on those accounts, too.”
Scott emphasized that all of the incidents he described, taken individually, are not cause for one credit union to become overly alarmed, since it’s a single incident for them. But collectively, over hundreds of credit unions, the crooks’ score can be big.
Commonalities Among Fraud Incidents
The concept of looking for commonalities among fraud incidents is certainly not new, reminded Scott, noting that is how the big breaches are often first detected—when issuers begin seeing a lot of fraud coming from one retailer. What is new, and needed, is expanding the data net, he said.
“We are using a much broader database now, looking into data from not only transactions and call centers, but simple things like balance consolidations, lost or stolen card reports, geo-location, so all kinds of factors,” said Scott. “That is what has become so powerful for us.”
Scott added that PSCU is also pulling in data into its linked analysis program from its partnership with Pindrop, an expert in voice security and caller authentication. Pindrop does multiple things for PSCU’s call center, said Scott—it checks if the phone number the person is calling from is known to be fraudulent, the quality of the line, if it’s a robo dialer, all before a live agent takes the call.”
Pindrop’s platform analyzes 150 characteristics of a call to create a unique audio “fingerprint,” that reveals the type of phone the caller is using, such as mobile, landline or Voice over IP, the geographic location of the call’s origin and whether the caller has been “seen” before, explained Scott.
In February Pindrop stopped over $1 million in fraud among PSCU member credit unions, said Scott.
“The call center is one of the new places where fraudsters are heavily targeting. If I am a crook and I can authenticate into a call center, from that point I can perpetrate a lot of different types of fraud,” said Scott, who noted that thanks in part to the massive breaches like Equifax that compromise large amounts of personal data, account takeover fraud originating through a call center is rising.
