Showing posts with label Electronic Payment. Show all posts
Showing posts with label Electronic Payment. Show all posts

Sunday, March 2, 2014

How Your Customers Should Think About Bitcoin

Bitcoin reminds me of the Gold Standard or UN SDRs. They're great in concept, but probably needs to weather a good crisis or two before I'll trust it.

The first thing to understand is that it is a bearer-owned stored-value mechanism like gold, dollars, or bearer bonds. It's not a payment network like paypal. It's not a payment mechanism like a credit card. It's not an account. Whoever physically "holds" the bitcoins owns their value.

This leads to one great benefit: Unlike the USD or other national currencies, no politician can use them as a political tool by using inflation to ruin the value or using executive orders to inflate the value of Bitcoins. So, like gold, they should be safe stores of value, immune to a specific country's situation.

But the reality is far less sanguine or simple. There are problems:

  • The notion that it is outside the influence of governments hasn't been tested. I'm sure government lawyers are working on this. Every single time a bitcoin changes hands, its authenticity is verified at the central database. This means every transaction and transfer can be monitored. The amount of data is too juicy for the NSA to ignore. But will other parts of the government (executive branch, for example) also get ahold of the info? 
  • The way they determine the value of the currency. Bitcoin is based on supply and demand. Because it is a small market with relatively few traders, it is easily manipulated. The issuing company says they are increasing the supply steadily based on the size of the economy. The good news is that, since 
  • Counterfeit. Every computer system has weaknesses. Even the most secure networks have been attacked, and most of them have been compromised at some point. I don't trust that Bitcoin is secure enough, if for no other reason than because it hasn't been attacked hard enough. 
  • Fraud. There are system-administrators in the Bitcoin foundation who must have special system access in order to do their jobs. These people could certainly be bought off for the right price. We haven't invented a really technologically fool-proof way to avoid this yet. Mt. Gox is the obvious example of what can go wrong here.
  • and, of course, not many places accept bitcoins as payment (currently)

Sunday, February 13, 2011

Are You a Proud Dad?

My dad gave me one dollar bill
'Cause I'm his smartest son,
And I swapped it for two shiny quarters
'Cause two is more than one!
And then I took the quarters
And traded them to Lou
For three dimes -- I guess he don't know
That three is more than two!
...
And then I went and showed my dad,
And he got red in the cheeks
And closed his eyes and shook his head--
Too proud of me to speak!

- Shel Silverstein
People working in anti-fraud live and breathe money: losses, recoveries, write-offs. If it costs $1,000 to investigate and recover $500, we all intuitively know that would be a waste of time. We might as well just write off the $500 and move on. And yet...

The following conversation is hypothetical, but its strikingly similar to what I've heard from several clients in recent weeks:

Client: "Our detection systems are solid, but we're always on our back foot! We want to prevent fraud, not just detect and chase it! We need some sort of prevention system to cut our losses.”

Me: “You might not need a new system. Does your existing technology really ensure your team looks at the biggest risks first?”

Client: “Of course! We do the big transactions first. We have a ‘red’ queue for stuff that requires immediate action.”

Me: “So I imagine if there was a $50k wire, way out of normal for the customer, it would pop into the ‘red’ queue and get looked at right away.”

Client: “Right.”

Me: “And if, at the same time, your systems saw a different account with a series of unusual log-in and balance inquiry events, it would put that in a lower-priority queue?”

Client: “Yeah, unless it was linked to a financial transaction.”

Me: “What if those logins were for the CFO of a very profitable business banking client?”

Client: “Well, the system wouldn’t really know that. We’d see it during investigation.”

Me: “What if the CFO had online access to draw on a $1m revolving line of credit without secondary approval? What if he hadn’t logged in since 2008, but then one day logged in several times, browsed all over your Business Banking portal, and changed wire instructions for an approved beneficiary?”

Client: “Hopefully that would set off alarms! Probably not a ‘red’ alert, but we’d notice for sure. I know we get reports from the wire room every morning. We could call the client and verify the change.”

Me: “What if, at 3:55pm Eastern Time that same day, the CFO logged back in, drew down the line of credit and wired $1m out?”

Client: “NOW there would be a ‘red’ alert!”

Me: “And you'd be on your back foot. How much would you have to spend to drop everything and investigate in order to get the money back?”

Client: “Well it might not be our loss. We can't prevent the client from having a criminal at the CFO spot.”

Me: “How much would you spend to determine if it was really the CFO or an identity thief? No matter what, the client's not going to be happy. Odds are, they're going to close their account. What kind of heat would you get from the banker in charge of the client? Maybe they even drag you to court. What would that cost? ”

Client: “Welcome to my daily nightmare! It's the hassle of a lifetime!”

Me: “Wouldn't it be better if your systems could just prevent the wire in the first place? What if my team could get your existing technology to do that?”

Client: “When can you start?”

Just like Silverstein's "proud dad" in the poem, this client was a bit red in the face with frustration. His technology and teams clearly had some growing-up to do.

The problem is that, just like Silverstein's "son," nearly all of today's anti-fraud technologies and business processes misunderstand the real objectives ... through no fault of their own. They've been tasked with monitoring a narrow set of intermediate metrics like transaction size, out-of-profile behavior, or unknown IP address.

The key is to take the blinders off and refocus the technology on the true business metrics. Tell them what you're really trying to achieve. Is it minimized losses? Is is minimized operational cost? Is it minimized customer defection? Is it some balance of these? Then empower them with enough contextual data to make an intelligent determination of what's at stake, and what to do about it.

In upcoming blogs, I'll go "down in the weeds" to examine how technologies and business processes can be transformed in this way. Stay tuned!

Thursday, January 20, 2011

The World is Flat for Fraud

This blog entry describes a very common fraud pattern in which criminals, using the internet, can very easily and cheaply collaborate globally to reach halfway around the world ... and right into your customers' pockets.

If you're a Fraud Prevention Exec at a financial institution (FI), this story should sound like a thousand others you hear every day from your investigative staff. If it isn't, you might want to have a look at your defenses.

If you're NOT a bank Fraud Prevention Exec, this blog post is for you! As I discussed in a recent blog post, risk management must comprehensively address all types of risk, including identity theft, unauthorized access, and financial fraud. Read the story below and ask yourself whether your FI is addressing this holistically as a risk to the enterprise.

  1. A teenage hacker in Alabama (or Shenzhen China, for that matter) downloads the code for a Zeus, URLzone, or Champi trojan virus. He experiments and figures out how to secretly place it on a computer via email.
  2. He brags online about his feat, and soon is contacted by a more seasoned fraudster, who buys the virus for $100. The teenager is ecstatic! Party on!
  3. The fraudster sends it out to 1,000 random email addresses from an anonymous account. The virus takes hold on several hundred computers. It is structured to avoid most common virus scans.
  4. The fraudster then places an ad online offering to sell access to the infected computers (yes, there are Craigslist-like sites just for criminals) for about $30 to $300 for one month. He knows he has broken some laws, but feels his exposure is limited.
  5. A criminal in Eastern Europe buys access, allowing him to activate the trojan and receive the victims' balances, account numbers, usernames, passwords, pins, identifying info, and even secret questions.
  6. The criminal uses this real customer info to set up a series of "mule" accounts at FIs he knows are vulnerable. The real customer doesn't even know these accounts exist.
  7. The criminal then uses all the usernames and passwords he has gathered to set up funds transfers from the unsuspecting customer accounts to his mule accounts. He knows to do it quietly over a period of time in order to stay under everyone's radars. He probably knows, from anecdotes of other criminals (yes, there are fraudster blogs and chatrooms), exactly what patterns or thresholds the FI is looking for.
  8. The criminal opens anonymous or mule offshore accounts in countries with weak laws Anti-Money Laundering and Know-Your-Customer laws so he doesn't have to provide any of his own identifying info.
  9. The criminal places an add on Monster.com or Craigslist for a "work-from-home payroll analyst" who can naively move money for him without raising any alarms.
  10. He hires a person in the US who, based on the criminal's legitimate-looking instructions, transfers money from the mule accounts to offshore accounts over a period of weeks. By the time the "payroll analyst" realizes they're not getting paid for their work, it's too late. The criminal is gone and his tracks are covered. Once FIs and police investigate the fraud, the "payroll analyst" looks like the prime suspect.
  11. Meanwhile, the criminal launders the funds through a series of transfers, checks, debit card transactions, bill pays, and stored value card purchases. Once the money is clean, he puts it right in his pocket and takes a 6-month vacation with YOUR paycheck.