Protecting the business and its customers.
WHAT THE CATEGORIES ARE
First-party fraud, where the customer is the perpetrator Third-party fraud, using stolen identity or credentials Account takeover Social engineering of customers Internal fraud
WHAT SOCIAL ENGINEERING LOOKS LIKE LOCALLY
Callers impersonating the institution, persuading customers to disclose codes or approve transactions.
WHY IT IS DIFFICULT
The customer authorises the transaction themselves.
WHAT REDUCES IT
Clear statements of what you will never ask for Warnings at the moment of a risky transfer Delays on first payments to new recipients Confirmation of recipient name
WHAT ACCOUNT TAKEOVER REQUIRES DEFENDING AGAINST
Credential reuse SIM swap Device compromise Recovery process abuse
WHY RECOVERY IS THE WEAK POINT
Attackers target the easiest route, which is frequently account recovery.
WHAT TO IMPLEMENT
Phishing-resistant authentication where possible Detection of recent SIM changes Step-up verification for sensitive actions Cooling periods after credential changes
WHAT TO MONITOR
Login anomalies Device changes Recipient changes followed by transfers
WHAT TO MEASURE
Fraud losses, and customers wrongly blocked.