Using the Phone Channel to Detect Money Transfer Fraud

22
2015 Pindrop Security. Confidential. USING THE PHONE CHANNEL TO DETECT MONEY TRANSFER FRAUD Matt Garland Vice President of Research Pindrop Security October 14, 2015

Transcript of Using the Phone Channel to Detect Money Transfer Fraud

Page 1: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.

USING THE PHONE CHANNEL TO DETECT MONEY TRANSFER FRAUDMatt GarlandVice President of ResearchPindrop SecurityOctober 14, 2015

Page 2: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.

NOTE

These slides are from a webinar held October

14, 2015.

You may view a recording of the webinar at

www.pindropsecurity.com/webcast-archive

Page 3: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.2015 Pindrop Security™. Confidential.

Physical PhoneOnline

THE WEAKEST LINK

1995 2010

Page 4: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.

PHONE VULNERABILITIES

Page 5: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.

CUSTOMER SERVICE REPRESENTATIVES

• Human Element• Social Engineering• Customer Experience

Page 6: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.

KNOWLEDGE BASED AUTHENTICATION

• Social Media• Previous Data Breaches

• Online Black Markets• Failure Rates

Page 7: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.

CALLER ID / ANI

• No longer reliable• Spoofing

Page 8: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.2015 Pindrop Security™. Confidential.

THE THREAT IS GROWING

Page 9: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.2015 Pindrop Security™. Confidential.

FRAUD CALL RATES

Avg. Call Center

Banks Brokerages Credit Card Retail Money Transfer

1 in 22001 in 2650 1 in 3000

1 in 900 1 in 1000

1 in 490

Page 10: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.2015 Pindrop Security™. Confidential.

$800 - $1500Per Transaction

MissedOpportunities

FRAUD LOSS

Page 11: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.

PHONE CHANNEL ATTACKS

Page 12: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.

ATTACK STAGES

Reconnaissance Account Takeover Verification Intercept Monetize the Attack

Page 13: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.

RECONNAISSANCE

• Identify account holders• Collect or test KBA

answers

Page 14: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.

ACCOUNT TAKEOVER

• Change contact information• Reset password• Setup account

Page 15: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.

VERIFICATION INTERCEPT

• Verification Call Intercept• Preempting Verification

Page 16: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.

MONETIZING THE ATTACK

• The most direct way to monetize an attack

Page 17: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.

CONSUMER ATTACKS

Page 18: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.2015 Pindrop Security™. Confidential.

BEST PRACTICES

Track Phone Fraud

Page 19: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.2015 Pindrop Security™. Confidential.

BEST PRACTICES

Track Phone Fraud Detect Phone Fraud Authenticate Callers

Page 20: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.2015 Pindrop Security™. Confidential.

LOSS• Packet loss • Robotization • Dropped frames

SPECTRUM• Quantization • Frequency filters• Codec artifacts

NOISE• Clarity• Correlation • Signal-to-noise ratio

147 audio features

UniquePhone

Geo-Location Risk Factors

PHONEPRINTING™

Phoneprint™

Call AudioRequires 15 seconds

of call audio

Risk Score

Call Type

Page 21: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.2015 Pindrop Security™. Confidential.

CONCLUSION

• The phone channel is the “weakest link”

• Sophisticated criminals use the phone channel for reconnaissance, account takeover, and cross-industry attacks

• Best Practice• Use PhoneprintingTM to detect phone fraud and investigate attacks

Page 22: Using the Phone Channel to Detect Money Transfer Fraud

2015 Pindrop Security™. Confidential.

PINDROP SECURITYPhone Fraud Stops Here.

For more information contact [email protected]