• Support
  • Login
  • Contact
  • Blog
  • Support
  • Login
  • Contact
  • Blog
SecurityScorecard SecurityScorecard
  • Products
    PRODUCTS
    • Security Ratings
      Identify security strengths across ten risk factors.
    • Security Data
      Get actionable, data-based insights.
    • Security Assessments
      Automate security questionnaire exchange.
    • Attack Surface Intelligence
      NEW
      On-demand contextualized global threat intelligence.
    • Automatic Vendor Detection
      Uncover your third and fourth party vendors.
    • Cyber Risk Quantification
      Translate cyber risk into financial impact.
    • Reporting Center
      Streamline cyber risk reporting.
    • SecurityScorecard Marketplace
      Discover and deploy pre-built integrations.
    SERVICES
    • Active Security Services
      Test your security controls.
    • Cyber Risk Intelligence
      Partner to obtain meaningful threat intelligence.
    • Digital Forensics & Incident Response
      Prepare to respond to any threat.
    • Third-Party Risk Management
      Reduce risk across your vendor ecosystem.
    BUY NOW
    • Compare All Plans
      Choose a plan that's right for your business.
    • Try Free Account
      Make informed decisions with confidence.
    • Buy Pro Now
      Add automated event responses.
    • Buy Business Now
      Expand on Pro with vendor management and integrations.
    • Request Enterprise Demo
      See the capabilities of an enterprise plan in action.
    icon__SSClogoMark icon__SSClogoMark

    Understand and reduce risk with SecurityScorecard.

    Free account sign up
  • Solutions
    BY USE CASE
    • Compliance
    • Cyber Insurance
    • Digital Forensics
    • Due Diligence
    • Enterprise Cyber Risk
    • Executive-Level Reporting
    • Incident Response
    • Regulatory Oversight
    • Third-Party Risk
    BY INDUSTRY
    • Critical Infrastructure
    • Enterprise
    • Financial Services
    • Government
    • Healthcare
    • Insurance
    • Retail & Consumer
    • Technology
    Help your organization calculate its risk
    View All Solutions
  • Customers
    OUR CUSTOMERS
    • Customer Overview
      Trusted by companies of all industries and sizes.
    • Peer Reviews
      Find out what our customers are saying.
    SUCCESS AND SUPPORT
    • Customer Success
      Receive award-winning customer service.
    • Support
      Get your questions answered by our experts.
    COMMUNITY
    • SecurityScorecard Connect
      Engage in fun, educational, and rewarding activities.
    • Connect Login
      Join our exclusive online customer community.
    icon__SSClogoMark icon__SSClogoMark
    Understand and reduce risk with SecurityScorecard.
    Free account sign up
  • Partners

    Partner Program Overview

    Partner with SecurityScorecard and leverage our global cybersecurity ratings leadership to expand your solution, deliver more value, and win new business.

    Learn more
    • Locate a Partner
      Access our industry-leading partner network.
    • Value-Added Resellers
      Enter new markets, deliver more value, and get rewarded.
    • Managed Service Providers
      Meet customer needs with cybersecurity ratings.
    • ISAC Partner Program
      Learn more about the industries we support and ISAC member benefits.
    • Technology Alliances
      Access innovative solutions from leading providers.
    • SCORE Portal Login
      Use the SCORE Partner Program to grow your business.
    • SecurityScorecard Marketplace
      Find a trusted solution that extends your SecurityScorecard experience.

    Understand and reduce risk with SecurityScorecard.

    Free account sign up
  • Resources
    RESOURCES
    • Resource Center
      Explore our cybersecurity ebooks, data sheets, webinars, and more.
    • SecurityScorecard Blog
      Read the latest blog posts published weekly.
    • Research & Insights Center
      Access our research on the latest industry trends and sector developments.
    • SecurityScorecard Academy
      NEW
      Complete certification courses and earn industry-recognized badges.
    TOOLS AND DOCUMENTATION
    • Free Security Rating
      Get your free ratings report with customized security score.
    • Product Release Notes
      Visit our support portal for the latest release notes.
    • Free Account Signup
      Start monitoring your cybersecurity posture today.
    • Chrome Extension
      NEW
      Show the security rating of websites you visit.
    • Assessments ROI Calculator
      Calculate the ROI of automating questionnaires.
    Trust begins with transparency. Take a look at the data that drives our ratings.
    Learn more
  • Company

    Working at SecurityScorecard

    Committed to promoting diversity, inclusion, and collaboration–and having fun while doing it.

    Join our team
    • About Us
      SecurityScorecard is the global leader in cybersecurity ratings.
    • Leadership
      Meet the team that is making the world a safer place.
    • Press
      Explore our most recent press releases and coverage.
    • Events
      Join us at any of these upcoming industry events.
    • Policy Insights
      Raising the bar on cybersecurity with security ratings.
    • Careers
      APPLY TODAY
      Come join the SecurityScorecard team!
    • Contact Us
      Contact us with any questions, concerns, or thoughts.
    • Trust Portal
      Take an inside look at the data that drives our technology.
    • Help Center
      We are here to help with any questions or difficulties.
Request a demo
SecurityScorecard SecurityScorecard
  • Support
  • Login
  • Contact
  • Blog
  • Support
  • Login
  • Contact
  • Blog
SecurityScorecard SecurityScorecard
  • Products
    PRODUCTS
    • Security Ratings
      Identify security strengths across ten risk factors.
    • Security Data
      Get actionable, data-based insights.
    • Security Assessments
      Automate security questionnaire exchange.
    • Attack Surface Intelligence
      NEW
      On-demand contextualized global threat intelligence.
    • Automatic Vendor Detection
      Uncover your third and fourth party vendors.
    • Cyber Risk Quantification
      Translate cyber risk into financial impact.
    • Reporting Center
      Streamline cyber risk reporting.
    • SecurityScorecard Marketplace
      Discover and deploy pre-built integrations.
    SERVICES
    • Active Security Services
      Test your security controls.
    • Cyber Risk Intelligence
      Partner to obtain meaningful threat intelligence.
    • Digital Forensics & Incident Response
      Prepare to respond to any threat.
    • Third-Party Risk Management
      Reduce risk across your vendor ecosystem.
    BUY NOW
    • Compare All Plans
      Choose a plan that's right for your business.
    • Try Free Account
      Make informed decisions with confidence.
    • Buy Pro Now
      Add automated event responses.
    • Buy Business Now
      Expand on Pro with vendor management and integrations.
    • Request Enterprise Demo
      See the capabilities of an enterprise plan in action.
    icon__SSClogoMark icon__SSClogoMark

    Understand and reduce risk with SecurityScorecard.

    Free account sign up
  • Solutions
    BY USE CASE
    • Compliance
    • Cyber Insurance
    • Digital Forensics
    • Due Diligence
    • Enterprise Cyber Risk
    • Executive-Level Reporting
    • Incident Response
    • Regulatory Oversight
    • Third-Party Risk
    BY INDUSTRY
    • Critical Infrastructure
    • Enterprise
    • Financial Services
    • Government
    • Healthcare
    • Insurance
    • Retail & Consumer
    • Technology
    Help your organization calculate its risk
    View All Solutions
  • Customers
    OUR CUSTOMERS
    • Customer Overview
      Trusted by companies of all industries and sizes.
    • Peer Reviews
      Find out what our customers are saying.
    SUCCESS AND SUPPORT
    • Customer Success
      Receive award-winning customer service.
    • Support
      Get your questions answered by our experts.
    COMMUNITY
    • SecurityScorecard Connect
      Engage in fun, educational, and rewarding activities.
    • Connect Login
      Join our exclusive online customer community.
    icon__SSClogoMark icon__SSClogoMark
    Understand and reduce risk with SecurityScorecard.
    Free account sign up
  • Partners

    Partner Program Overview

    Partner with SecurityScorecard and leverage our global cybersecurity ratings leadership to expand your solution, deliver more value, and win new business.

    Learn more
    • Locate a Partner
      Access our industry-leading partner network.
    • Value-Added Resellers
      Enter new markets, deliver more value, and get rewarded.
    • Managed Service Providers
      Meet customer needs with cybersecurity ratings.
    • ISAC Partner Program
      Learn more about the industries we support and ISAC member benefits.
    • Technology Alliances
      Access innovative solutions from leading providers.
    • SCORE Portal Login
      Use the SCORE Partner Program to grow your business.
    • SecurityScorecard Marketplace
      Find a trusted solution that extends your SecurityScorecard experience.

    Understand and reduce risk with SecurityScorecard.

    Free account sign up
  • Resources
    RESOURCES
    • Resource Center
      Explore our cybersecurity ebooks, data sheets, webinars, and more.
    • SecurityScorecard Blog
      Read the latest blog posts published weekly.
    • Research & Insights Center
      Access our research on the latest industry trends and sector developments.
    • SecurityScorecard Academy
      NEW
      Complete certification courses and earn industry-recognized badges.
    TOOLS AND DOCUMENTATION
    • Free Security Rating
      Get your free ratings report with customized security score.
    • Product Release Notes
      Visit our support portal for the latest release notes.
    • Free Account Signup
      Start monitoring your cybersecurity posture today.
    • Chrome Extension
      NEW
      Show the security rating of websites you visit.
    • Assessments ROI Calculator
      Calculate the ROI of automating questionnaires.
    Trust begins with transparency. Take a look at the data that drives our ratings.
    Learn more
  • Company

    Working at SecurityScorecard

    Committed to promoting diversity, inclusion, and collaboration–and having fun while doing it.

    Join our team
    • About Us
      SecurityScorecard is the global leader in cybersecurity ratings.
    • Leadership
      Meet the team that is making the world a safer place.
    • Press
      Explore our most recent press releases and coverage.
    • Events
      Join us at any of these upcoming industry events.
    • Policy Insights
      Raising the bar on cybersecurity with security ratings.
    • Careers
      APPLY TODAY
      Come join the SecurityScorecard team!
    • Contact Us
      Contact us with any questions, concerns, or thoughts.
    • Trust Portal
      Take an inside look at the data that drives our technology.
    • Help Center
      We are here to help with any questions or difficulties.
Request a demo
SecurityScorecard SecurityScorecard
BLOG

5 AI Use Cases for Mitigating Fraud in Financial Services

01/15/2020

The financial services industry is no stranger to artificial intelligence (AI) and machine learning (ML). Even in eras where computers (as we know them today) did not yet exist, the financial services industry used automation technologies for number crunching and data processing. As new technologies enabled automated banking services, malicious actors kept pace, leading to automated fraud technologies such as malware, carding methods, and database attacks. To protect customers from fraud, financial services organizations began incorporating AI/ML as part of their cybersecurity and compliance strategies.

What does “financial fraud” mean?

To many, the difference between “financial crime” and “financial fraud’ appears to be an academic distinction. However, for financial institutions, the differing definitions come with business operation process and compliance differences. Financial crimes often involve actions such as bribery and money-laundering, generally covered under the Bank Secrecy Act/Anti-Money Laundering (BSA/AML) compliance requirements.

Financial fraud refers to crimes rooted in deception, such as forgery, scams, and insider threats. Many financial institutions, therefore, report the effects of these crimes as part of their loss liability calculations.

In other words, while institutions often consider “financial crimes” a compliance risk, “financial fraud” more directly relates to the organization’s overarching asset-liability reporting and financial strength.

What attack channels should financial services institutions worry about?

Implementing controls that mitigate fraudulent activities arising from cybercriminals, financial institutions need to engage in a risk analysis that aligns the customer banking service journey with the digital risks that exist at each step.

Identifying the types of data, data storage locations, and the manner through which the institution collects and transmits information. A 2019 McKinsey report identifies four attack channels and their associated fraud risks.

ATMs

Most often associated with skimmers, ATMs represent a significant cybersecurity and customer information breach weakness. ATM skimmers are card reader attachments that malicious actors attach to machines so that they can collect debit card numbers and PINs. In some cases, malicious actors inject the machines with malware to create a persistent attack.

Using these tools, malicious actors steal customer identities, enabling them to siphon money from user accounts or to create new accounts under the customer’s name.

Cards and e-commerce

Although most financial institutions must meet Payment Card Industry Data Security Standard (PCI DSS) compliance requirements, debit/credit cards remain a consistent data breach vector. Most financial institutions use credit/debit cards as a way to confirm their customers’ identities. When malicious actors obtain this data, the customers’ data integrity, accessibility, and confidentiality can be compromised.

E-banking and wire transfers

Gaining access to customer information can also occur as a part of regular transactions. Services such as new account generation and wire transfers historically required customers to be present in a physical branch. Online banking services enable customers to engage in these types of transactions via the internet. While this makes banking easier for customers, it also increases the cyber and fraud risks that financial institutions must mitigate.

In response to this, the Society for Worldwide Interbank Financial Telecommunication (SWIFT) released its cybersecurity framework to help financial institutions mitigate the risks inherent in these transaction types and ensure cybersecurity in banking.

Branches

Even though most financial institutions segregate their networks to protect customer data, endpoints and applications running on an institution’s networks become a potential threat vector. As the financial services industry increasingly adopts cloud-based infrastructures, financial institutions need to monitor their security controls’ effectiveness, including individual branch locations, which can become overwhelming as they scale their operations by adding more branches or purchasing other institutions.

What does a malicious actor do with customer information?

Each of the four attack channels leads to a singular purpose: using legitimate customer information to engage in fraudulent activities. Although some malicious actors may drain an account once they have the credentials, most prefer to use the customer data as a way to electronically disguise themselves. Most customers link their accounts to an email address to communicate with their financial institution or receive communications from the institution.

Malicious actors, therefore, often hijack systems or databases via one of the attack channels, then use customer email addresses to send the financial institution digital requests. In response to the increase in these activities, the Financial Crimes Enforcement Network (FinCEN) released the “Updated Advisory on Email Compromise Fraud Schemes Targeting Vulnerable Business Processes” in July 2019. The Advisory broadened the definition of “email compromise fraud” with the following updates:

  • Email Compromise Fraud: When malicious actors compromise a person’s email account to:
    • Create fraudulent payment instructions that misappropriate funds or value; or
    • Effect fraudulent data transmissions that can be used to engage in financial fraud.
  • Business Email Compromise (BEC): Targets financial institution accounts or customers that are operational entities such as businesses, non-profit organizations, non-governmental organizations, or government entities.
  • Email Account Compromise (EAC): Targets personal email accounts belonging to an individual.

The problem underlying the FinCEN advisory is twofold. First, it assumes that customers cannot protect their email addresses from cybercriminals. While this may be partially true, the Advisory also hints at financial institutions’ inability to protect customer data and prevent fraud.

Where financial institutions current AI/ML use fails

Financial institutions have long incorporated the newest technologies to protect their customers, and themselves, from fraud. Although often vigilant about protecting customers from fraud, financial institutions’ reliance on AI/ML may not be the most proactive approach.

Traditional fraud detection enabled institutions to check geolocation details. For example, an institution might correlate credit card or customer’s billing zip code with the geolocation and historical reputation of the purchasing IP address to mitigate online payment card fraud risk. If the geolocations do not match or the purchasing IP has a history of suspicious activity, the card is declined or frozen until the cardholder contacts the financial institution.

Problematically, these technologies led to a high rate of ‘false positives’, both inconveniencing the consumer and enabling attackers to bypass restrictions when they use tunneled proxy IP addresses located within the vicinity of the real cardholder zip code.

Next-generation AI fraud mitigation technologies incorporate context, taking the new attack channels into consideration. These technologies leverage significantly more data points when assessing a risk profile including factors such as IP reputation, geolocation, e-mail address reputation, typical user browsing patterns and login patterns, and hardware/software fingerprinting. These data points can give insight into the probability that a transaction is fraudulent as well as an indication that a user account may have been compromised as part of the fraudulent activity, such as when the malicious actors create a new “fake” account.

Analysis of the additional data points can help lower the false-positive alert frequency for legitimate transactions and increase the alerts’ legitimacy when notifying the institution of suspicious activity.

Unfortunately, both of these AI/ML use cases take a reactive, rather than proactive, approach to mitigating fraud. In both of these cases, as well as the recent Advisory’s use case, cybercriminals already exfiltrated customer information.

5 use cases for AI in finance that help mitigate fraud

Financial institutions need to be proactive about preventing fraud and ensuring financial cybersecurity. Although cybercriminals may be able to exfiltrate email login information directly via the customer, they may also be using one of the four above-listed channels.

With more customer data stored, transmitted, and collected in the cloud, continuous controls monitoring becomes a fraud risk mitigation imperative. As part of their risk analysis, most institutions assign customer names, birth dates, social security numbers, and/or account numbers a “high” risk level. As such, they segment the networks containing this information and mitigate the risks with the appropriate controls.

Imagine the following scenario. A cybercriminal obtains access to a branch network and exfiltrates a list of customer email addresses. This provides the cybercriminal with the only two data points necessary for engaging in email compromise fraud: an email and a bank whose customer has that email.

Another potential scenario might be a cybercriminal intercepting a money transfer. Many bank transfers no longer require senders to list a recipient’s account number; they only require the sender to use the email address attached to the recipient’s account. By gaining access to the money transfer information, the malicious actor, again, knows an email and a bank associated with the email.

In both of these scenarios, the cybercriminal obtained email information from one of the four attack channels and did not need account information. Both of these scenarios increase the potential for email compromise fraud.

1. AI-powered fraud detection

Machine learning platforms can enhance fraud detection by using data analytics to recognize fraud while also avoiding acceptable data deviations. This helps data scientists efficiently determine the likelihood of fraudulent transactions, reduce false positives, and leverage data insights to prevent fraud. This type of analytics also works to automate the discovery of patterns across transactions, and learns over time to enhance detection capabilities.

2. Ensuring regulatory compliance

Strict data regulations have pushed banks to seek cost-effective ways to ensure compliance and avoid fines. AI-powered regulatory technology focuses on helping organizations tackle data quality and protection issues and comply with requirements to avoid fines.

3. Continuous security monitoring

Financial organizations need continuous and complete visibility into their security posture in order to protect data and mitigate vulnerabilities. A single-pane-of-glass view into controls allows organizations to respond to vulnerabilities and risks in real-time and protect the network.

4. Algorithmic risk management

Financial institutions need to incorporate new AI/ML technologies as part of their continuous fraud risk management strategies. Machine learning technologies provide algorithms that strengthen financial risk management techniques by centralizing risks that may arise and offering recommendations for management and mitigation. Using data analysis and deriving insights from personal data, ML is able to reduce risks for banking and financial services customers. Managing cybersecurity hygiene and vulnerabilities and ensuring continuous control effectiveness is now a way to protect themselves from financial fraud and ensure data security.

5. Secure transactions

AI and machine learning algorithms have been developed to detect transaction fraud through smart data analysis and validation techniques. These algorithms can help secure transactions, reduce false rejections, and improve the speed of real-time approvals. This helps both financial institutions and their customers execute secure business practices and transactions.

How SecurityScorecard’s AI/ML enables a proactive fraud prevention strategy

SecurityScorecard’s platform enables financial institutions to continuously monitor their controls’ effectiveness. Our platform gathers information across ten groups of risk factors, including IP reputation, network security, web application security, endpoint security, patching cadence, DNS health, hacker chatter, leaked credentials, and social engineering.

Our platform provides visibility into a financial institution’s cybersecurity posture, as well as the posture of its business partners. Our easy-to-read security ratings use an A-F scale, with A being the highest rating, so that financial institutions can gain at-a-glance insight into their strongest and weakest controls. Using our platform, organizations can also prioritize their remediation strategies by focusing on the most important risks.

By taking a proactive approach to financial fraud prevention, institutions can mitigate asset loss risk and increase customer account security.

Return to Blog
Join us in making the world a safer place.
FREE ACCOUNT SIGN UP
Products
Solutions
Customers
Marketplace
Partners
Resources
Company
Trust Portal
Security Ratings
Login
Blog
Contact
Careers

SecurityScorecard
Tower 49
12 E 49th St
Suite 15-100
New York, NY 10017

[email protected]

United States: (800) 682-1701
International: +1(646) 809-2166
Social-linkedin Social-facebook Twitter Instagram Youtube