- Banks and card companies prevented £2 in every £3 of attempted unauthorised fraud in 2017.
- Unauthorised fraud losses fell 5 per cent to £731.8 million in 2017.
- New 2017 data shows £236.0 million lost to authorised push payment scams.
- Deception and impersonation scams continue to be a key driver of both unauthorised and authorised fraud.
- Finance industry calls for new information sharing powers to prevent more fraud.
Banks and card companies prevented £1,458.6 million in unauthorised financial fraud last year, equivalent to £2 in every £3 of attempted unauthorised fraud being stopped, the latest data from UK Finance shows.
In 2017, fraud losses on payment cards fell 8 per cent year-on-year to £566.0 million. At the same time, card spending increased by 7 per cent, meaning card fraud as a proportion of spending equates to 7.0p for every £100 spent – the lowest level since 2012. In 2016 the figure stood at 8.3p.
For the first time, annual data on losses due to authorised push payment scams (also known as APP or authorised bank transfer scams) has also been collated. A total of £236.0 million was lost through such scams in 2017.
The unauthorised fraud data on payment cards, remote banking and cheques for 2017 shows:
- Combined total losses fell by 5 per cent to £731.8 million.
- Losses due to unauthorised transactions on payment cards fell 8 per cent year-on-year to £566.0 million. The industry helped prevent £984.9 million in attempted unauthorised card fraud.
- Losses due to unauthorised remote banking fraud totalled £156.1 million, a 14 per cent rise on 2016. Banks prevented £261.4 million of unauthorised remote banking fraud, 27 per cent more than last year.
- Cheque fraud losses fell 28 per cent in 2017 to £9.8 million. This is the lowest annual total on record. £212.3 million of attempted unauthorised cheque fraud was prevented.
- There were 1,910,490 reported cases of unauthorised financial fraud, a rise of 3 per cent compared to the year before.
The new authorised push payment scams data, collected for the first time in 2017, shows:
- There were 43,875 reported cases of authorised push payment scams with a total value of £236.0 million. 88 per cent of this total were retail consumers, losing an average of £2,784, and the remainder were businesses who lost on average £24,355 per case.
- Financial providers were able to return £60.8 million (26%) of the authorised push payment scam losses in 2017.
Katy Worobec, Managing Director of Economic Crime at UK Finance, said:
“Fraud is an issue that affects the whole of society, and one which everyone must come together to tackle. The finance industry is committed to playing its part – investing in advanced security systems to protect customers, introducing new standards on how banks respond to scam victims, and working with the Joint Fraud Taskforce to deter and disrupt criminals and better trace, freeze and return stolen funds.
“We are also supporting the Payment Systems Regulator on its complex work on authorised push payment scams, providing the secretariat for its new steering group. It’s a challenging timetable, but it is important that we get it right to stop financial crime and for the benefit of customers.”
The finance industry is responding to the ongoing threat of all types of fraud and scams by:
- Helping to prevent customers being duped by criminals by raising awareness of how to stay safe through the Take Five to Stop Fraud campaign, in conjunction with the Home Office.
- Working with government and law enforcement to deter and disrupt criminals and better trace, freeze and return stolen funds, while calling for new powers on information sharing to allow banks to share data to detect and prevent financial crime better.
- Implementing new standards to ensure those who have fallen victim to fraud or scams get the help they need, including around-the-clock availability of fraud teams, to make it easier and better for the customer, and, where possible, improve the likelihood of their funds being recovered. UK Finance will also be the secretariat for the PSR’s new steering group on authorised push payment scams2.
- Working with government on making possible legislative changes to account opening procedures to help the industry act more proactively on suspicion of fraud and prevent criminals from accessing financial systems.
- Rolling out the Banking Protocol – a ground-breaking rapid response scheme through which branch staff can alert police and Trading Standards to suspected frauds taking place – to every police force area in the UK. In 2017, while it was still being introduced across the country, the Protocol prevented £13.3 million of fraud and led to 129 arrests.
- Sponsoring the Dedicated Card and Payment Crime Unit5, a specialist police unit which tackles the organised criminal groups responsible for financial fraud and scams. This has led to a combined value in savings and disruptions in criminal activity of close to £30 million in 2017.
- Exploring new ways to track stolen funds moved between multiple bank accounts.
To help everyone stay safe from fraud and scams, Take Five to Stop Fraud urges customers to follow the campaign advice:
- A genuine bank or organisation will never contact you out of the blue to ask for your PIN, full password or to move money to another account. Only give out your personal or financial details to use a service that you have given your consent to, that you trust and that you are expecting to be contacted by.
- Don’t be tricked into giving a fraudster access to your personal or financial details. Never automatically click on a link in an unexpected email or text.
- Always question uninvited approaches in case it’s a scam. Instead, contact the company directly using a known email or phone number.
Tony Blake, Senior Fraud Prevention Officer at the Dedicated Card and Payment Crime Unit, said:
“With criminals using social engineering to target people and businesses directly, it’s vital that everyone follows the advice of the Take Five campaign. Always stop and think if you are ever asked for your personal or financial details. Remember, no bank or genuine organisation will ever contact you out of the blue and ask you to transfer money to another account.”
In an unauthorised fraudulent transaction, the account holder does not provide authorisation for the payment to proceed and the transaction is carried out by a third-party.
In an authorised push payment (APP) scam, the account holder themselves authorises the payment to be made to another account. If a customer authorises the payment themselves, current legislation means that they have no legal protection to cover them for losses – which is different for an unauthorised transaction.
Banks will always endeavour to help customers recover money stolen through an authorised push payment scam but customers typically only approach their bank after the payment has been processed, once they realise they have been duped. By this time the criminal has often withdrawn the stolen funds and the customer’s money has gone. Alongside the extensive work already underway through the Joint Fraud Taskforce, UK Finance is also currently working with the Payment Systems Regulator on its proposals to tackle these scams.
Behind the data
Fraud intelligence points towards criminals’ use of social engineering tactics as a key driver of both unauthorised and authorised fraud losses. Social engineering is a method through which criminals manipulate people into divulging personal or financial details, or into transferring money directly to them, for example thorough impersonation scams and deception.
In an impersonation scam, a fraudster contacts a customer by phone, text message or email pretending to represent a trusted organisation, such as a bank, the police, a utility company or a government department. Under this guise, the criminal then convinces their victim into following their demands, sometimes making several separate approaches as part of one scam.
Data breaches also continue to be a major contributor to fraud losses. Criminals use stolen data to commit fraud directly, for example card details are used to make unauthorised purchases online or personal details used to apply for credit cards. Stolen personal and financial information is also used by criminals to target individuals in impersonation and deception scams, and can add apparent authenticity to their approach.
The value of digital identity in payments
By Vince Graziani, CEO, IDEX Biometrics ASA
In ever more challenging times, the payments industry needs to maintain trust by finding a way to protect consumers from the constant threat of payment fraud and theft. Consumer’s wishing to limit physical contact during the current pandemic has led to the popularity of contactless payments which has accelerated in multiple territories.
In the US, one in five shoppers have made a contactless payment for the first time during the pandemic according to research published in August by the National Retail Federation and Forrester. The bad guys have unfortunately taken note. This has led to a real need for the industry to fight back with enhanced security.
At the 2019 Money2020 Europe conference, there was a universal call for a comprehensive form of digital identity (ID) to enable digital payments. A form of digital identity that would make cashless payment interactions – secure, intelligent, efficient and private. The feeling was unanimous: without functioning digital ID, the payments revolution will stall.
Unlocking the payment ecosystem
In an increasingly connected world, consumers find themselves needing to authenticate their identity daily. Whether that be with financial institutions, retailers, government departments or healthcare providers. Yet, it is rarely known where consumer data is stored, how secure it is or how it may be traded. Privacy regulations such as the European Union’s General Data Protection Regulation (GDPR) have attempted to restore some trust, but the industry still has a way to go.
Currently, authentication is fragmented and unwieldy. It requires a mix of hardcopy documents, online login credentials and digital wallets. This is not only frustrating for consumers but leads to the reuse of passwords and PINS that make the user vulnerable to fraud. Mastercard believes there is a clear need for a verified identity that is accepted globally and across multiple digital touchpoints and doesn’t involve aggregating more information in potentially vulnerable data stores, but instead gives the individual control over their identity data.
An integrated digital ID scheme would enable the payments industry to fight fraud on a global scale. It would also meet the pressing need for a payment authentication system that consumers can access anytime, anywhere, and on any device. This joined-up approach is vital to ensure no consumer is left behind as the world continues its digital transformation.
Providing access to a singular, unified digital ID will not only streamline the identity process, but also unlock new and enhanced consumer experiences during this digital transformation. Particularly in the new breed of smart buildings and cities, where everything from travel to payment systems will be connected to a user’s identity.
What form should our digital ID take?
While the need for digital ID is well established, the form it will take is less clear. There are two main challenges that payment providers need to overcome with a potential new identity solution: onboarding new users and ensuring the digital ID is compatible with all transactions.
Placing individual consumers at the centre of their own digital interactions will ensure confidence and broader adoption of new technology payments and services. Yet, for this to be successful, the payments industry must adopt a process that is simple, familiar and easy to understand.
Fingerprint biometrics as a digital identity
The use of fingerprint authentication to unlock a smartphone is now deeply entrenched. As far back as 2016, 89 percent of users with compatible iPhones were using fingerprints to unlock their devices. The solution for a frictionless onboarding has been at our fingertips the whole time.
Payment providers can incorporate fingerprint biometric sensors directly into their new breed of smart payment cards. A biometric payment card may be a new concept, but payment providers and retailers across the world are already using contactless card technology in the payment process, so it is the next logical step. Consumers are now used to carrying a card and tapping it for contactless payments. Plus, as we have seen, consumers are used to using their fingerprint as an authentication mechanism. Perhaps biometric cards could be the catalyst for financial inclusion desired by the World Bank, as they don’t require the ownership of expensive smartphones in developing nations.
Building a chain of trust with biometrics
Continuous developments in payment regulation mean that secure authentication is imperative. Under the second Payment Service Directive (PSD2) European banking regulation, all payment transactions will soon require Strong Customer Authentication (SCA) to validate users at the point of transaction to reduce fraud and increase security for customers. SCA requires two forms of authentication for every transaction above the contactless limit. While one is generally something you have like a smart card, the second can be something you are like a fingerprint. Using a fingerprint means that it can be used across multiple platforms and is always at hand. There should be no trade-off between convenience and privacy and fingerprint biometrics delivers on that expectation.
Biometrics can play an essential role in digital ID, significantly limiting exposure to potential fraud and criminality. The addition of a biometric sensor onto a payment card creates a secure ‘chain of trust’ that indelibly connects the user to the card. Furthermore, digital ID has the scope to be extended far beyond payments and used as a unique identifier in areas such as access, government ID and even across IoT devices.
Securing the future of the payments industry
While the world is becoming ever more cashless, commentators and analysts all agree – without a fully functioning digital ID, the payments revolution will stall. As Tony McLaughlin, Emerging Payments and Business Development at Citi put it recently: “If we fix digital identity, we fix payments”. I couldn’t agree more. Both consumers and the payments industry need a user-centric digital ID that is owned and managed by the individual, so they can unlock the full advantages of a transformative digital payment ecosystem.
Using fingerprint biometrics as a digital ID in a payment card will transform the way people authenticate transactions. This integration would enable consumers to confirm their identity wherever they are, on any device, and across every transaction. It will change the face of digital identity as we know it.
We believe that digital interactions should be privacy-enhancing, secure, intelligent, and efficient. To facilitate this, consumers require a user-centric digital identity that is owned, managed, and controlled by the individual. It is time to place individuals at the heart of their digital interactions globally.
It’s time to press ‘reset’ on travel and expense processes
By Rudy Daniello, EVP of Corporations, Amadeus
Travel & Expenses(T&E) is a large spend category for companies across the globe. In fact, for many firms, T&E is the second largest indirect spend category. While we all know the inherent value personal, face-to-face meetings bring, it’s important to quantify and manage the cost, especially in today’s climate.
While business travel has slowed due to COVID-19, many companies have accelerated their digital transformation during this period, especially in the way their teams work. One area that is under the spotlight as organisations look to transform digitally and control costs and processes better, is T&E.
Poor business travel spend management can frustrate staff, and lead to cost and productivity inefficiencies. Within the context of COVID-19, controlling T&E spend is likely to be even more important, so companies need a clear strategy around their travel and expenses.
To understand how organisations were assessing their T&E at this extraordinary time, Forrester Consulting conducted research on behalf of Amadeus, surveying more than 550 key decision makers involved in T&E solutions at large organisations worldwide.
The report, titled Digital Transformation For Travel & Expense: Balancing Process Efficiencies, Compliance, And Employee Experience highlights the challenges organisations face as they assess their T&E systems and processes before business travel picks up again.
The good news is that nearly three quarters (74%) of respondents agree that the improvement of T&E management processes and tools is critical to reducing costs, increasing efficiency, improving employee engagement, and forms part of their digital transformation.
All of these factors are key business objectives, so how can organisations address their T&E?
Focus on Systems
The research found that a lot of organisations are still relying on outdated systems to manage their travel and expenses. More than one in five (22%) of centralised companies still use spreadsheets to track expenses and just 15% of organisations use a cloud-based T&E solution.
Many decentralised companies also still rely on manual processes – either fully or partly – for their T&E. These outdated processes and systems add pressure on staff, managers, auditors and accountants. Reassess T&E Processes
Having the right systems in place will help rethink T&E processes, from researching hotels and appropriate transport, to making expenses claims post-trip. Travel managers surveyed difficulties around compliance-related expense tracking, reconciliation and auditing as a key challenge.
Three quarters (74%) of travel management leaders want to increase automation to reduce their reliance on manual processes. However, one in five (20%) organisations do not feel they are getting the analytical and reporting capabilities they need, despite data being a core priority.
The research shows that Human Resources (HR) and IT have key roles to play in redefining their organisations’ T&E processes.
Enable Smarter Booking
The research also finds that T&E leaders want to be able to manage the huge amount of content out there so that they can make clear decisions when making travel bookings. Multinational organisations need a global solution so that they can access the best deals and make more informed business travel booking decisions.
Integrated T&E solutions deliver cost and efficiency benefits
According to the research, those organisations that use an integrated T&E tool are much less likely to receive complaints from their traveling staff. More than a quarter (27%) of organisations that use an integrated T&E solution reported zero complaints from employees.
Integrated T&E solutions are essential for companies as they help their employees, take advantage of the best offers for the business trip. They also streamline expense processes, making it quicker and easier to claim and have their expenses approved and paid back.
Firms that do not have integrated T&E solutions report a 29% increase in delays in reimbursing expenses. Almost all (96%) of organisations interviewed that use integrated tools are satisfied with their T&E processes. Nearly three quarters (73%) of them even plan to expand or upgrade further.
Improving T&E is a team effort
What the Forrester Consulting research demonstrates clearly is that there is consensus across the board that T&E systems and processes can be improved.
Three quarters (74%) of IT leaders are focused on improving end-to-end experience of T&E processes, and 73% are committed to improving integration between T&E tools and other systems (73%).
And it’s not just IT leaders who see the value in integrated T&E solutions. More than four out of five procurement managers see improvement of T&E tools and processes as a key part of their organisation’s digital transformation, the highest of any group interviewed by Forrester.
While online conferencing has become the norm for many organisations, nothing can replace the value of face-to-face meetings. When business travel picks up again, companies with integrated T&E systems and processes will quickly see the benefits.
Covid-19 and the rise of remote payment fraud: how do we catch a digital thief?
By Evgenia Loginova, co-founder and co-CEO of Radar Payments
Covid -19 is finding different ways to hurt our finances – and like the virus, the threat is invisible.
Each time we tap our payments cards or make a purchase online, there’s always a risk of getting caught out by a digital fraudster. Yet during the global pandemic, the issue has not only escalated, but the ways in which people are conned have changed to reflect new social distancing and lockdown behaviours.
Indeed, the crisis has transformed the way we buy and shop – and those that are being targeted most are the millennial generation.
What are we doing differently?
It’s all down to the way we are interacting with service providers.
Since the World Health Organisation issued a pandemic in March, global payment fraud went up 5% with 100 million suspected fraud attempts from the period between March – April.
According to TransUnion, the firm analysing the data, billions of people around the world have been forced to spend time at home, which has led to industries such as financial services, ecommerce and healthcare to experience disruption in ways that have not been seen for generations.
This is due to the spike in online transactions, as more people adjust to the new normal of spending less time at the shops and more time doing everything on their digital devices. And with so many transactions shifting online – fraudsters are spending more time there too. These culprits are fully remote and are always on the lookout for vulnerable victims – as well as vulnerabilities within the payment systems.
Digital savvy criminals
Businesses that come to grips with the problem will manage to stay afloat – but they won’t be able to do it without fraud prevention tools that can identify suspicious activity without adding friction to the customer payment experience. In other words, customers must be protected from theft – as well as the truth. They shouldn’t even know that they’re under attack in the first place. It’s all about prevention- or at least as much as what technology can provide.
Without some technological intervention, there won’t be prevention, as companies simply cannot keep up with the proliferation of digital thieves. Culprits are operating individually or in criminal gangs or both – and usually in countries that are often forgotten by global leaders. For example, the telecommunications sector witnessed a 76% increase in card fraud a month after the global pandemic was declared – and the top country for suspected fraud origination was Timor-Leste – how many people even know where that is? (East Timor – formerly part of Indonesia, if you must ask!). Financial services saw an 11% increase in identity theft that same period – with most suspected culprits based in war torn Syria.
Despite their location, fraudsters are quickly adapting to consumer behaviour, and finding ways to attack. With less in-person transactions taking place, criminals are doing things like infecting online points-of-sale with malware that enables them to skim credit card details of previous customers.
From our experience with our fraud detection networks the numbers point out that missing card fraud, in particular, has shot up by 70% over the past few months. This is where people’s card details are being used by criminals to make purchases, when they are not in possession of the card. They’ve just stolen the numbers and additional critical security information such as expiry date and CVC2/CVV2.
Identity theft is also on the rise, as well as phishing and social engineering attacks. For example, in the UK alone there’s been a rise in criminals impersonating trusted organisations like the NHS or HMRC to trick people into going online and paying for services that are fake or giving away their money and information to charities and other organisations that are fake.
Local councils in Britain have noted a 40% increase in reported scams since the start of the pandemic, while Citizens Advice believes one in three people have been targeted by a Covid scammer.
This is a problem that is too big to ignore. The moment the fraudsters have your payment details – whether they’ve stolen it or you’ve given it to them under false pretences, the problem leads to losses for the victim and the businesses and organisations too.
With Covid and lockdown, fraud has gone fully remote and everything from e-commerce and digital banking has been a target for abuse.
In this ‘new normal’ world we find ourselves, the prevention of suspicious transactions through customer profiling and enhanced analytics, use of AI and machine learning models becomes very important.
Fortunately, digital theft is now being taken seriously. Spending on security has skyrocketed in recent years, and the sector supplying protection predicted to grow by $6 Trillion by 2021.
Businesses that survive the pandemic must be able to anticipate and strive to block 100% of the digital theft they encounter. But to win the war against these online criminals they require a robust security strategy.
Here are some tips to consider.
Security policies should be enforced internally and across payment channels and distributed networks. This includes the core and cloud networks as well.
Security gaps should be closed. A lot of risk can be mitigated by performing regular checks and plugging security holes, settling on a unified security framework based on interoperability, centralising visibility and control, segmenting the network to restrict the fluidity of malware and high performance, and deep integration.
Invest in AI capabilities. Artificial intelligence possesses the sophisticated power to replicate the analytical behaviour of human intelligence, as well as enable decision-making in real time and offer predictive security notifications.
Investing in AI based security systems can significantly reduce digital attacks and spot suspicious activity. The best ones are integrated with artificial neural networks (ANN), which combined with deep-learning models, can speed up data analysis and decision-making. It also enables the network to nimbly adapt to new information it encounters in the network.
Prevent fraud in online and then investigate. It is crucial to stop fraud before it happens. As most of the payments became remote, reaction should be super fast: high-risk transactions should be declined, low-risk passed with no friction and suspicious challenged. This raises the importance of finding the balance between customer experience and risk mitigation as never before. And even with AI and enhanced analytics for complex cases an expert with natural intelligence should be equipped with all needed information for relevant and adequate decision-making.
Digital crime won’t disappear as long as there’s an opportunity that criminals can exploit. As the world braces for a new wave of lockdown measures, businesses operating in the online sphere must remain vigilant and prepare for more attacks – or face losses that could be impossible to recover from during these challenging economic times.
Reconnecting the retail brain: learning from the octopus
By John Malpass, Retail Consultancy Practice Lead at Teradata An octopus has nine brains: one for each tentacle and plus one at...
How robotic technology will disrupt the manufacturing industry
By Marga Hoek, author of The Trillion Dollar Shift Robotics technology has the potential to disrupt industries across all sectors...
RPA, the software robots that finance and banking professionals need to hear about.
By Rory Gray, Vice President of Sales at leading software automation firm, UiPath, explains what role Robotic Process Automation (RPA)...
The rise of nomadic work: how to turn your remote team into a creative force
By Paige Erickson, EMEA MD, Workfront During the first stage of the lockdown in the spring, almost half of Brits...
The value of digital identity in payments
By Vince Graziani, CEO, IDEX Biometrics ASA In ever more challenging times, the payments industry needs to maintain trust by...
Consumers in the COVID era can learn to embrace strong customer authentication
By Ed Whitehead, Signifyd managing director, EMEA The changes that COVID-19 has caused in rapid succession make it hard to...
How NatWest used social media to better target its communications
By DuBose Cole, Head of Strategy, VaynerMedia London For banks, it is imperative to reach their existing – and potential...
It’s time to press ‘reset’ on travel and expense processes
By Rudy Daniello, EVP of Corporations, Amadeus Travel & Expenses(T&E) is a large spend category for companies across the globe....
Covid-19 and the rise of remote payment fraud: how do we catch a digital thief?
By Evgenia Loginova, co-founder and co-CEO of Radar Payments Covid -19 is finding different ways to hurt our finances –...
Effective financial planning will secure businesses a certain future
By Simon Bittlestone, CEO of financial analytics company Metapraxis 2020 has been an unpredictable year, bringing further volatility to already...