By Ray Birch
ST. PETERSBURG, Fla.—All the positive things credit unions attempt to do in fighting fraud, including remaining friendly and reducing transaction friction, could lead to a negative—those steps can help pave the way for crooks, one expert is saying.
That’s due to a broader transition that is taking place as fraudsters shift their efforts from stealing card information to account takeover efforts, where the paydays can be even bigger, explained Karen Postma, managing vice president of risk analytics and fraud services at PSCU.
“A few years ago we're really looking at how do we prevent or stop fraud when it comes to credit and debit card authorization,” said Postma. “So, that means using neural networks, learning scoring…all those kinds of things which are still extremely valuable and needed. We continue to push for those kinds of things from a technology perspective. But, what we have found is that with advanced chip cards, contactless transactions, and the rollout of verification tools such as 3D Secure, we have really seen a major shift in fraud from authorization to authentication. That's really the loophole fraudsters are taking advantage of.”
Postma said the biggest fraud “gap” today within credit unions can be found in efforts to stop account takeover attempts.
“The biggest threat are the scams employed by crooks to bypass the authentication rails that we have put in place,” said Postma. “What we're seeing is a very high level of account takeover efforts.”
For example, criminals have become very effective at gathering enough information to authenticate themselves as the account holder to do things like change phone numbers on accounts to fight multifactor authentication, according to Postma.
“This allows them to bypass the authentication efforts by the credit union, and this has become the biggest area of concern from a financial institution perspective,” said Postma.
Very Good at Pretending
She said criminals have also become very good at pretending to be the credit union or a trusted merchant.
“They're convincing members to give them the OTP (one-time password) to give them access to their account,” said Postma.
This situation is very “dangerous,” Postma warned, because often the credit union has been removed from the fraud prevention loop, as opposed to when a crook fraudulently uses a members’ credit card data to purchase something, the CU is involved with its fraud detection solutions and can reach out to the member and ask if the transaction is legitimate, and then stop it if it is not.
“With account takeover, when the criminals are securing the OTPs, for example, there is less a credit union can do to prevent the crime,” said Postma, who added the losses from account takeover efforts are typically much larger than losses from card fraud.
Even More Dangerous
Account takeover in which the member becomes engaged is actually much more dangerous than the account takeover that does not, because the member is allowing the transaction to happen, having willingly provided the crook with their secure information.
“For example, in the case where the fraudster gains access to online banking without involvement from the member, there might be an opportunity for us to understand that engagement is fraudulent and we could alert the member and then shut down the account,” Postma told CUToday.info. “It's still very dangerous, and still extremely serious, but we are part of that engagement. We can ask the consumer, ‘Did you recently log in to your online banking account from somewhere in Europe?’ They would say ‘no,’ and we’d shut down the account.”
Some Recommendations
Postma said the best way for credit unions to battle account takeover fraud is with member education and staff training.
“Educate both your credit union staff along with your members about these scams. Advise members never to release their information, such as PINs, passwords, those kinds of things,” urged Postma, adding that communication should be stepped up and targeted to the demographics that are the most vulnerable to the threat, often older Americans.
“Empower your staff—your contact center, your tellers, your back office to challenge your members,” said Postma, who added asking tough and challenging questions can run counter to the nature of the friendly credit union employee. “That’s a bit contrary to where credit unions are. Credit unions like to provide the best service to their members and reduce friction. And we’ve always just relied on authentication. But now it's really authentication and validation—that's where we really needing to move as an industry.”
