Fintech Guide to Payment Card Fraud | Lithic

Fintech Guide to Payment Card Fraud

June 27, 2022

Zach Pierce
Risk Ops Lead

Zachary Dearing
Business Operations

Gil Rosenthal
Risk Management

Eduardo Lopez
Product Marketing Lead

Fraud and economic crime rates are at record highs in the fintech space. Last year, the payment fraud attack rate across fintech increased by 70%. In 2020, global card fraud losses surpassed $28 billion and that number is expected to climb to $49.32 billion by 2030.

Recently, PayPal lost nearly $50 billion in market cap after disclosing that 4.5 million fraudulent PayPal accounts had been created to take advantage of its “$10 per account created” incentive program. But this is not an issue that’s unique to PayPal.

Fraud is a challenge that all companies offering financial services need to learn to deal with. In this guide, we explore card program fraud in detail.

Founder TL;DR

What is fraud?

Fraud refers to the use of intentional actions to generate unlawful gains from a target. It’s when a bad actor intentionally uses lies and deception to steal money (or some other store of value) from a company or individual. Notice the key word here is intent.

Under common law, three elements are required to prove fraud:

  1. A material false statement with an intent to deceive
  2. A victim’s reliance on the statement and damages
  3. Damages

Fraud is distinct from credit risk. Both result in a company ultimately not having the funds they deserve, but credit risk refers to a well-intentioned party’s inability to pay. Fraud instead involves an ill-intentioned party’s unwillingness to pay.

There is no such thing as an accidental fraud — intent is the only thing that separates error and credit risk from fraud.

Why does fraud matter to fintechs?

Fraud impacts a fintech’s bottom line and customer experience.

A poorly managed program commonly may have fraud losses north of 250 bps (or 2.5%) of total transacted volume. Even a well managed program may experience fraud losses around 50 bps. Fraud can meaningfully eat into interchange revenue, if not managed appropriately.

Ultimately, fraud impacts a company’s viability, both by drawing down its coffers and degrading the customer experience. As a result, it is important to be thinking about fraud early when building a card program.

Three different types of fraud

There are generally three different types of fraud that fintechs commonly encounter.

Fraud across the customer journey

At Lithic, we like to think about fraud vectors across the customer journey, categorizing fraud between onboarding fraud risk and transaction fraud risk.

Onboarding fraud risk

When opening a new account, there is a variety of ways a bad actor might try to start a relationship with the intent to ultimately defraud the company.

Stolen Identity

Synthetic Identity

Intentional Abuse

Transaction fraud risk

Once an account is open, criminals can defraud a company through a variety of means, including:

Card compromised

Account takeover (aka ATO)

Carding attack (aka PAN enumeration)

Merchant fraud

Friendly fraud chargebacks

Fraud fighting basics

Fraud fighting strategies are usually centered around balancing top-line goals (customer growth and transaction volume growth) and bottom-line metrics (profits and customer experience).

Friction is a key part of effective fraud fighting

Friction is a general term from the world of Product Management. Usually, it is attributed to anything that could cause customers to not complete their onboarding or transaction.

Some examples of what could be considered friction:

Fraud fighting teams use friction to both establish trust (confirm who is performing the purchase and that it is intentional) and to drive fraudsters away (creating product roadblocks they cannot bypass). Often the goal is to look for friction options that would be relatively painless for a legitimate user, but anywhere from hard to impossible for a bad actor to complete.

One of the first strategic choices fintechs should consider is how much friction they’d like to apply and where to apply it in order to create that Goldilocks “just-right” balance.

Investing in fraud fighting pays off

Because of this balance, it can sometimes be challenging to quantify the benefits of investing in fraud fighting. But there is a link between fraud prevention investment and reduced costs when fraud inevitably happens.

Companies with a dedicated fraud program spend 42% less on response and 17% less on remediation costs than those companies with no programs in place.

Fraud Fighting: Amusement park vs. shopping mall

If you find yourself stumped about how to go about this, consider this question: Are you building an amusement park or a shopping mall ?

The fundamental difference between the two is where the friction occurs.

Amusement Park

A classic amusement park has a gate at the entrance, whereby a patron pays for access. Once granted access, they can go on any of the rides or see any of the attractions they might want, typically without any further checks.

With an amusement park, friction comes up-front, similar to having an extensive onboarding process upon sign-up or login. Once a user clears that initial check (and establishes that initial trust level), the high level of trust established is used to meaningfully reduce future friction and interruption to the customer’s activity.

This results in a lower number of customers able to make it through the door, but for those who do, the experience after signing up is much smoother, and the value of each customer to the business tends to be very high.

Shopping Mall

A shopping mall is different. Usually, they welcome anyone in with open doors, yet individual stores have mechanisms and barriers to ensure folks pay (e.g., theft detection systems, cash registers, security guards).

Shopping malls have very low barriers to entry if any. Think of it as just an email and name upon initial product sign-up. But they also have incremental barriers at different points along the course journey.

Since there hasn’t been sufficient trust built “at the door” and there are no barriers to entry, attempts to control the level of fraud (in part using friction) are done at various instances throughout the experience.

This results in a much higher number of customers, but a more bumpy experience for those customers. The value of each customer to the business also tends to be smaller, though in the aggregate that can yield a meaningful net positive.

There is no “one size fits all” approach

Either approach (or a combination) can make sense for a particular product. There is no right or wrong answer. Discussing and having alignment on the approach can help ensure a consistent customer experience and adequate controls to manage fraud.

The way a company decides to approach and manage fraud is typically impacted by their risk tolerance, nature of the business, customer base, attractiveness of their product to fraudsters, the stage of their product build, financial wherewithal, etc.

Companies at any stage should think about and align internally on their approach to fraud, and should repeat this exercise periodically.