Step-Up Fraud Prevention Made Easy - Low-Cost Implementation of an Identity Validation System
←
→
Page content transcription
If your browser does not render page correctly, please read the page content below
Step-Up Fraud Prevention Made Easy Low-Cost Implementation of an Identity Validation System
“ By leveraging the validation software 72% of previously suspicious actors dropped off when challenged to provide their ID ” Head of Risk, Namecheap.com
Executive Summary This whitepaper outlines the implementation of a (Personally Identifiable Information) security, and fraud prevention system that uses commercially increased the risk of fraudsters bypassing the available technology from Validation.com to step-up challenge. request ID for higher-risk transactions. Implementing the Validation system at Namecheap As the world’s second-largest domain registrar has been a strong fraud deterrent: 72% of fraud by domains managed, Namecheap is a target for suspects drop off transactions when challenged fraudsters looking to test stolen credit cards. for ID, with no revenue loss. Namecheap has Namecheap’s fraud process has a step-up identified serial fraudsters while improving PII challenge, which occurs when a transaction security and maintaining GDPR compliance. receives a high risk score from automated fraud detection tools. Validation’s patent-pending method of requesting a user’s image, photo ID, and credit card ‘proof of The old step-up challenge methodology involved possession’ helps Namecheap’s fraud team to uploading images via email, which had poor PII validate customers with their own eyes. Step-up challenge: A fraud prevention method where an ID request forms part of the fraud-prevention strategy. It can be implemented automatically or manually. Copyright 2019 Validation.com. All rights reserved 02
The Validation System Implementation Namecheap elected to implement the Validation a specific range after card authorization, but system using the manual integration method, as before charging the card, and delivering the this is the quickest time to market. It also requires goods, the next step is to issue a step-up ID minimal resources and technical expertise. verification challenge to the user. The existing fraud process uses commercial A step-up ID verification requests an official ID security tools to provide a risk score for every document (credit card, passport, driving license) individual transaction. If the risk score falls within and can potentially include a selfie. NEW ORDER NO YES IS RISK SCORE OK? REQUEST ID DID NOT COMPLETE COMPLETE NO YES STOP DOES COMPLETE ORDER ID PASS? ORDER At present, the Validation system requires no Clients who follow the link will receive a screen fundamental change in the pre-existing process. prompt outlining the ID upload process under Fraud agents log in to the system and generate GDPR legislation, which ensures informed submission links, and send them over to their consent by anyone interacting with the system. respective clients. Agents can then request multiple types of ID based on their pre-existing criteria. The client is then asked to submit their ID. Copyright 2019 Validation.com. All rights reserved 03
Submission screens Selfie Take a selfie and fill the circle with your face SELFIE On the submission screen, the client is presented with a central outline to help properly position themselves for the photo. The remainder of the screen is blurred. Because of this blur, fraudsters may inadvertently reveal the misuse of their phones, printouts, or screens while the Validation process takes place. Take a picture! After completing the submission, an agent receives notification via email that the client’s application is complete. SELFIE Fraud agents reviewing the ID submission can now see multiple pictures before the camera shutter initiation. They can now review a series of pictures and either approve, reject, or request a supervisory review of the submission. FAILED A submission approval would release the order within Namecheap’s systems. A rejection of the submission reasons of suspected fraud would result in the user’s transaction being denied. Copyright 2019 Validation.com. All rights reserved 04
Breakout Implementing a system that requires active use of on-device cameras creates an immediate deterrent effect, without a drop in sales. 28% 72% of fraud suspects Complete submission drop off Of the completed submissions transactions when asked for ID. 70% 30% passed stopped. Copyright 2019 Validation.com. All rights reserved 05
Catching a serial fraudster Since Namecheap implemented the Validation system, multiple fraud attempts have been prevented. Here’s an example of how our system has helped the company expose fraudulent behavior. The submissions below are illustrations of the review screens of user-generated submissions. SELFIE Submission 1 SELFIE PHOTO ID DRIVER LICEN SE 180º FAILED FAILED In the first submission reviewed, a Submission 2 transaction was flagged and subsequently failed as the man in SELFIE the selfie did not match his ID. In the second submission, the transaction failed as his selfie was fake – it was clearly a picture on his phone. FAILED Copyright 2019 Validation.com. All rights reserved 06
Submission 1 Submission 2 SELFIE SELFIE FAILED FAILED Also, his attempt to bypass the selfie submission stage was immediately spotted in the Validation timeline review. Submission 2 Visual comparison tools revealed that he was the same individual from the first submission. PHOTO ID I.D. PERSONAL When reviewing the ID submission, it was clear that his ID was a picture on his phone. PERSONAL I.D. PERSONAL I.D. 180º PERSONAL I.D. Submission 2 PERSONAL I.D. PERSONAL I.D. FAILED PHOTO ID Message: Order XUY-SV1-323 requires more information A review of the timeline revealed another transaction that was being conducted with Namecheap, and this transaction also failed as it was in conjunction with a known fraudster. Message: Order XUY-SV1-323 requires more information Message: Message: Order XUY-SV1-32 Order XUY-SV1-323 requires more information Message: more information Order XUY-SV1-323 requires more information Message: Order XUY-SV1-323 requires more information Message: Message: Message: Message: Order XUY-SV1-323 requires Order XUY-SV1-323 requires Order XUY-SV1-323 requires 180º Message: more information Message: Order XUY-SV1-323 requires more information more information Message: Order XUY-SV1-323 requires Order XUY-SV1-323 requires more information Order XUY-SV1-323 requires more information more information more information 180º FAILED FAIL Copyright 2019 Validation.com. All rights reserved 07
Submission 2 CREDIT CARD FRONT ONLY The credit card number associated with this transaction has now been added into the watchlist of another tool for future reference. FAILED Submission 3 SELFIE PHOTO ID 3 PERSONAL I.D. PERSONAL I.D. PERSONAL I.D. PERSONAL PERSONAL I.D. I.D. PERSON AL I.D. 180º PERSON PERSONAL AL I.D. I.D. PERSONAL I.D. FAILED FAILED Another fraudulent transaction was detected when a flagged card was used in conjunction with another account. Once again, a manual challenge was issued to this individual. In this case, the person submitting their ID was the legitimate credit card holder, but he was also responsible for previous fraudulent attempts. Consequently, the transaction was denied and his account was suspended in keeping with terms of service. The Namecheap fraud team can now identify this type of behavior more easily without process disruption. Conclusion When Validation.com becomes part of an in-depth fraud prevention strategy, its step-up challenge method has proven to be effective at exposing fraudulent behavior. As previously mentioned, since implementing Validation.com, Namecheap has prevented multiple fraud attempts without experiencing any drop in sales. Implementation as part of a fraud prevention strategy is seamless, requiring fraud agents only to generate submission links in the Validation system, and forward them on to clients. The client’s ID submission – a series of photos – can be reviewed quickly and easily for any suspicious activity. Setting up Validation is fast, with no additional resources or technical training required for fraud teams. This makes it an affordable measure for preventing fraud, chargebacks, and protecting customers. Copyright 2019 Validation.com. All rights reserved 08
About Validation.com Validation.com is custom-designed client document and takeover prevention, Validation.com is quickly management platform. With a security first focus, becoming a security tool of choice for well-known partners of Validation.com are able to engage companies across a number of industries. with their users to validate documents and manage them securely. Our goal is to bring our As a product of NC Labs, the R&D arm of Namecheap partners and their users face to face, allowing more Inc., Validation.com has carried forward the than just documents to be validated. values and pillars of trust, truth & transparency, With uses in the e-commerce space preventing fraud which have been core to nearly 20 years of its and chargebacks, KYC applications, account creation operation as a domain name registrar. Validate your customers not just their documents Prevent Chargebacks KYC / Identity proofing Stop account take overs Get in touch today Partners@validation.com or visit www.validation.com to find out more. About Namecheap Namecheap is an ICANN-accredited domain over 10 million domains under management, registrar and technology company founded in Namecheap is among the top domain registrars 2000 by CEO Richard Kirkendall. It is one of the and web hosting providers in the world. fastest-growing American companies according Namecheap offers a full selection of popular and to the 2018 Inc. 5000. Celebrating nearly two unique domains, along with fully featured hosting decades of providing unparalleled levels of packages, SSL security certificates, WhoisGuard service, security, and support, Namecheap has privacy protection, and more–all at some of the been steadfast in customer satisfaction. With lowest prices in the industry. Find out more about Namecheap products at www.namecheap.com Copyright 2019 Validation.com. All rights reserved 09
You can also read