Sep 2nd, 2020

California Circumvents CFPB, Fraudulent Fund-transfers Frazzle Government, Authorization Attrition

TL;DR

Jason and Hayden discuss California’s proposed Department of Financial Protection and Innovation and argue that consumer protection only works when regulators understand payments, merchant behavior, and how bad actors exploit weak processing oversight. They also unpack pandemic-related unemployment and stimulus fraud, including why government systems became easy targets for identity theft and fraudulent fund transfers. The episode closes with a look at EMV 3DS, explaining why modern biometric-backed authentication can reduce fraud, improve authorization rates, and avoid much of the checkout friction that made older 3D Secure implementations unpopular with merchants.

Consumer Protection Needs Payments People

This episode of Cents Chat starts with California’s plan to create a new financial protection watchdog agency, and Jason is not exactly throwing confetti.

His concern is not the idea of consumer protection. It is the execution. Too many enforcement models chase bad actors after enough consumers have already been harmed. That kind of whack-a-mole approach may make for nice headlines, but it does not stop the pattern before the damage happens.

Jason’s argument is that if California wants to protect consumers from predatory lenders, aggressive debt collectors, credit repair schemes, and other shady financial operators, the agency needs real payments expertise. The people writing the rules need to understand how bad merchants get processed, how they evade monitoring, and how dishonest payment providers help them stay alive.

The Frontline Defense Is the Payment Supply Chain

Jason puts a lot of responsibility on banks and third-party payment providers. In his view, they are supposed to be the frontline defense against consumer-harming merchants.

The signals are not mysterious. High chargeback ratios, unusual authorization-to-decline patterns, elevated ACH return rates, and other processing behavior can expose bad actors quickly. Best-in-class payment providers already monitor for these patterns. The problem is that some providers profit from risky merchants and help them work around card brand and Nacha thresholds instead of shutting them down.

That is where legislation could matter. If regulators create meaningful penalties for payment organizations that enable nefarious merchants, the economics change. The risk stops being worth the reward.

Government Payment Fraud Was the Low-Hanging Fruit

The second topic shifts to pandemic-related unemployment and stimulus fraud.

Hayden points to fraudulent unemployment filings, Scattered Canary, false claims across multiple states, and stimulus payments sent to deceased individuals. Jason’s reaction is blunt: fraudsters target the easiest systems to compromise, and government payment infrastructure looked embarrassingly easy.

The frustrating part is that the government has access to enormous amounts of identity data, yet many systems still failed to use basic identity validation controls. Jason argues that unemployment, PPP, and benefit programs should use out-of-wallet identity verification when accounts are created and multi-factor authentication before anyone can redirect funds.

The goal is not perfection. It is making the fraudster’s job hard enough that they move on to easier prey.

3D Secure Gets a Second Chance

The final discussion turns to EMV 3DS and e-commerce fraud.

Old 3D Secure implementations had a bad reputation for a reason. Redirecting shoppers to a bank login page created friction, confusion, and abandoned carts. Many merchants decided a little fraud was less painful than losing legitimate sales.

But Jason says modern 3DS 2.0 is different. Wallet-based payments like Apple Pay already use authentication flows built around the same basic idea: prove the cardholder is involved before the purchase is approved. With biometric authentication, better browser-based identity tools, and FIDO-style standards, the experience can be much cleaner.

The payoff is bigger than fraud reduction. When issuers receive stronger authentication data, they can approve more legitimate transactions. That makes 3DS 2.0 not just a risk tool, but an authorization tool.

The takeaway: regulators need payments expertise, government payment systems need basic identity controls, and e-commerce merchants that still ignore 3D Secure are leaving themselves exposed.

Featuring
  • Jason
    The Nerd
  • Hayden
    Guest Speaker
    Transcript

    Hayden: Welcome to this episode of Cents Chat with Jason and Hayden. Let's jump right in to make payments make sense. Happy Wednesday, Jason. It's another warm morning here in Newport Beach. And speaking of the warmth, we have some heat coming through this weekend, which is perfect because it is Labor Day weekend.

    Jason: You know what I've never understood about Labor Day weekend, Hayden? It says Labor Day. People should be in the office working. I'll be excited to see you here on Monday.

    Hayden: Sorry, Jason, but I am for sure taking my three-day weekend, and I know you can hold it down, so I know we're okay. Let's jump into today's topics. First, California circumvents CFPB, but will they get it right?

    Jason: Next, fraudulent fund transfers frazzle government. Big surprise.

    Hayden: And last, authorization attrition: how COVID crushes e-commerce. Jason, California is expected to create a new financial protection watchdog agency by the end of August. Under the Obama administration, CFPB was responsible for consumer protection in the financial sector. But under the Trump administration, as well as COVID adding some speed bumps, CFPB has been deemed useless. NPR reports that enforcement is down 80% from 2015, and money returned to consumers has dropped a whopping 96%.

    Jason: Those of you who know me personally know I'm not a big fan of governmental agencies. They're generally expensive, poorly managed, and in the case of payments, have no idea what they're doing. The CFPB was a disastrous organization that played whack-a-mole with merchants only when they received enough consumer complaints. This means they were always operating behind the eight ball with these nefarious businesses that were taking advantage of consumers.

    And rather than understanding an industry and how to weed out the bad players, they simply targeted them based on consumer complaints. In my opinion, the patterns of these nefarious merchants are so obvious to those of us that are in the payment space. We could see the bad actors a mile away.

    And if California is going to do anything that actually protects consumers rather than just wasting taxpayer dollars, they better make sure the group has payment professionals with deep industry experience as part of their watchdog agency.

    Hayden: Well, Jason, since the outbreak, California has seen a 40% increase in financial wrongdoings. And that's why Governor Gavin Newsom proposed the Department of Financial Protection and Innovation. This will make sure Californians are protected from predatory lenders, aggressive debt collectors, credit repair schemes, and other shady practices that, in a time of despair, can push somebody over the edge and into poverty. Lawmakers face an August 31 legislative deadline.

    Jason: Hayden, as I already said, unless this organization is structured correctly with the right people, it's going to be a disaster. It should really be the banks and third-party payment providers that are policing this. But the problem for these groups is that the nefarious businesses are also very profitable because the scammers are willing to pay egregious rates for their payment processing services to get them to turn a blind eye.

    I can tell you from experience that each one of these industries that you mentioned has telltale signs that they're bad actors. And it becomes even more evident after they start processing payments. The best-in-class banks and third-party payment providers already have controls in place to figure out who these bad actors are. Controls such as monitoring chargeback ratios, looking at authorization-to-decline ratios, return percentages on ACH transactions, and many others.

    However, rather than enforcing these types of controls, dishonest TPPs often help merchants circumvent card brand and Nacha thresholds so they can continue to profiteer from these bad actors.

    My perspective on this is that if California actually wants to make a dent in these industries that have a reputation for causing consumer harm, rather than going after them one at a time based on consumer complaints, they need to understand the dynamics of their behavior, how they circumvent card brand and Nacha rules, and draft legislation that requires more oversight from the banks and third-party payment providers that should be the frontline defense.

    In addition, creating stiff penalties for payment processing organizations that enable these nefarious merchants to continue to operate, the risk will no longer be worth the reward for them. And these bad actors will die the slow, painful death they deserve.

    Hayden: Jason, while we're on the topic of government inefficiency, due to COVID-19, it's no surprise the unemployment rate has gone through the roof. But what a surprise it would be if you filed for unemployment just to find out that somebody has been collecting your benefits under your name. Which sounds like fiction to me, but Nigerian hacker ring Scattered Canary has successfully lifted millions of dollars through scam unemployment filings in at least six different states.

    Pennsylvania alone has paid out nearly 60,000 false filings, and that does not include a whopping $4.1 billion in stimulus payments that Uncle Sam decided to send out to the deceased. Although the government claims they are going to be retrieving those funds, opportunistic fraudsters have already cashed in on the government's mistake.

    Jason: Hayden, I always say that fraudsters target the lowest hanging fruit when it comes to stealing money. They're going to focus their efforts on the easiest-to-compromise systems. And it's embarrassing to say that our state and federal government falls into this category. You would think they would have this process so buttoned up that they would be the model that banks and third-party payment providers strive to be. I mean, come on.

    The government knows more information about people than the banks and credit card processing companies do, but yet they fail to implement even the simplest of identity validation controls. It has been easier for fraudsters to get a PPP loan or unemployment benefits than it has for them to open a credit card in somebody else's name. And this is why we've seen such a drastic shift to fraudsters targeting governmental agencies.

    I also highly doubt the government is going to get a fraction of those funds recovered. The money at this point is already out of the bank and most likely already out of the country.

    Hayden: Jason, the global pandemic did not break the public payment system, but rather exposed the already broken system. Banks need to update how they mitigate risk and fraud as well as update their systems. In most states, there is no codified verification system for authenticating who they are sending money to, which is crazy to me. But Jason, in your professional opinion, where do you think a good starting place is to better update these systems in order to prevent fraud like this?

    Jason: Hayden, there are already so many tools that exist that would have prevented lots of this fraud. And it's up to the entire supply chain to make sure that we're providing the best technology, solutions, and most importantly, education to the merchants and the government. The merchants are ultimately the entities that have direct interaction with the consumers or fraudsters. And we need to make sure they're using the appropriate tools to verify identity and accounts.

    Government agencies should be doing out-of-wallet identification when new accounts are being created, going above and beyond just asking for a Social Security number and date of birth as a form of identification. They should be implementing out-of-wallet identity validations when accounts are established that ask consumers to verify information that the government already has or is on a credit report.

    You have to remember, it's not about being perfect in detecting identity theft and fraud, but being hard enough that the fraudsters are not going to spend the additional time to circumvent the controls. Sure, they could go obtain a credit report or dig on social media for answers to these questions, but it makes it hard enough that they're not going to waste their time. They're going to move on to easier prey.

    And additionally, I've talked about this a hundred times. Any system that enables financial transactions should require multi-factor authentication to prevent account takeover so that once an identity has been validated at the time of account creation, somebody can't compromise the account and simply redirect funds.

    Hayden: Jason, the Financial Crimes Enforcement Network issued a press release warning FIs and consumers about scams that are related to the global pandemic. Bad actors are currently engaged in fraudulent schemes that exploit the unexpected flaws created by COVID-19, as well as all-around confusion created by the pandemic. The release shed light on malware phishing schemes in which fraudsters talk about COVID-related aid like the CARES Act in an attempt to extract payments.

    Jason: You know, Hayden, Bank of America does a horrible job on both of these. I was recently watching a friend who receives California unemployment transfer money to their bank account, and the number of attack vectors to compromise that system and redirect funds is insane. The truth of the matter is none of these flaws are unexpected. The vast majority of the attack vectors being used have been around forever. It simply goes back to a lack of urgency for them to remedy them.

    Oftentimes, banks and third-party payment providers are aware of these exploits, but until they become the target of one of them, they let it slide by. Just about all of these attack vectors, from malware to phishing scams, are solved by multi-factor authentication and out-of-wallet identity validation. And these organizations just need to stop procrastinating and get it done.

    Hayden: So, Jason, I understand that in the past, selling an EMV 3DS product to a merchant hasn't always been an easy task. Merchants either weren't willing to hear about it or they weren't willing to learn about it. But now with COVID-19 driving the digital commerce shift into sixth gear and the invention of EMV 3D Secure 2.0, that will no longer be the case. Retailers have begun to find out that fighting off fraudsters in a physical store is a lot easier than fighting off fraudsters in an online ecosystem.

    With 3DS 2.0, beating the bad actors is a lot easier and actually works in the retailer's favor. Instead of having to rebuild authorization rails, 3DS 2.0 will facilitate the information to decide the legitimacy of a transaction.

    Jason: Yeah, Hayden, like many of our topics today, it's hard to convince an industry to tighten up security until they become a victim of fraud. And this is just another example of how the supply chain could have been better for COVID-related attack vectors. This technology has actually been around for quite some time. In fact, it's the rails that Apple Pay is built on top of. And the whole premise of it is to ensure that the cardholder is authenticated before making the purchase.

    What's new is the added buzzword of EMV in front of it. 3D Secure and 3D Secure 2.0 are nothing new. But merchants tend to run for the hills as soon as they hear the word 3D Secure because of how the initial versions were implemented. Initial implementations were not based on biometric authentication, but legacy solutions that required an e-commerce shopper to be redirected to their bank to log in and approve the transaction.

    And this implementation certainly deterred fraudsters, but it also created significant friction for real customers trying to make purchases. Oftentimes, consumers were not familiar with the process and thought it was an attempt to compromise their banking information. So it resulted in higher payment page abandonment and lost sales to the merchants. So much so that it was worth letting a few fraudulent transactions through the cracks to not lose hundreds of legitimate sales.

    Hayden: Well, Jason, EMV 3DS will be an industry standard in the coming years. It's already a requirement of the EU's Payment Service Directive 2, meaning any merchant that wants to transact in the EU needs to have EMV 3DS ready to go by January 1, 2021. The card networks have also confirmed that 3DS 2.0 will be mandatory worldwide on their networks for issuers this fall.

    But the gateways and processors still have work to do in order to get EMV 3DS certified and ready to go, meaning there is still some integration work to come.

    Jason: Yeah, Hayden, I personally love this technology. And at this point, if it's properly implemented, it has little impact on the checkout experience. Most wallet-based payment methods already use this solution. And any e-commerce merchant should be supporting at a minimum these wallet-based payment methods, such as Apple Pay.

    With the number of new cards that have been added to the mobile wallets based on COVID, there is a massive increase in the number of consumers who are making e-commerce transactions with biometrically authenticated wallets, for the simple reason that it's quicker than having to key in the card information. Browser-based adoption for this technology is also growing rapidly, and solutions like the FIDO Alliance, which are building identity validation directly into the browser, will propel it even further forward.

    Any player in the payment supply chain that doesn't already support transmitting this additional data needs to get it on their roadmap yesterday, because not only does it make a significant dent in fraud, but it also has a big impact on authorization rates. The presence of this additional data with the authorization assures the card issuer that the purchase has been authenticated by the cardholder, thus reducing traditional fraud checks that may have resulted in the transaction being declined.

    All in all, it's an amazing tool for reducing fraud and increasing authorization rates.

    Hayden: Alright, Jason, you know what time it is. It is time to make payments make sense. Give me those takeaways.

    Jason: Governor Newsom, if you need help building a team of payments experts for your new Department of Financial Protection, we're here to help. Supply chain, enough is enough. Let's start educating merchants and our government on how to protect their consumers. If you're not already strongly embracing 3D Secure 2.0, you're putting your merchants at a huge disadvantage.

    Hayden: Thanks for joining us today. And if you've got a topic you would like us to discuss, follow and message us on social media at Cents Chat. And as always, we would love your feedback.