We hope you found Michael Smith (MS) and Chris Gregory’s (CG) session on “Smart Automation: Revolutionising Fraud Prevention in the Loyalty Industry” at this year’s Loyalty Conference both insightful and engaging. We received many excellent questions, and we’re pleased to provide the transcript of answers below:
QUESTION: What is the funniest / quirkiest fraud you detected?
ANSWER:
(MS) The organised crime gang hacking into hotel loyalty accounts to redeem for free hotel nights….the rooms were being used for a prostitution ring!
(CG) Perhaps most disappointing rather than funniest, but training a customer’s fraud administrator in how to use Accertify’s fraud systems, who in the end, was the one committing the most of their gift card fraud!
QUESTION: Where should we focus to prevent ATOs occurring in the programme?
ANSWER:
(MS) This comes back to a couple of points, the first is that prevention. You’ve got to stop people getting into the accounts in the first place. Some of that is at a cyber level – and Chris can explain a bit more about how to do that – but it is also about having ATO/fraud on your radar screen when considering program design/enhancements. The second bit is Detection. So if the fraudsters get in, how do you find that out before the customer does so that you can lock down their accounts to prevent loss. It’s also worth bearing in mind, so call “”friendly fraud”” or “”1st Party Fraud”” as sometimes the member is in on the fraud. So whilst that isn’t one focus point, it is about knowing colleagues in cyber and in the fraud teams so that you can at least keep up with the fraudsters. Chris – I am sure you can add in some bits here in terms of software and the services you/others offer.
(CG) As a general answer, the best way to prevent ATO is to have automated event screening controls across all loyalty platform events, with carefully considered friction points so that CX can be optimised for good customers, whilst stopping bad actors from doing anything they shouldn’t. From the initial creation of the account, all the way through to things like account updates, points redemptions and/or payments etc., the tools should be able to look at patterns within the data, assess data against known good and bad values, as well as look at things like the device the event is coming from and record behavioural information associated with the event (things like pages visited, time spent on pages, typing speed, usage of copy/paste, mouse movement etc.) This helps build profiles of typical customer behaviour for your program specifically, and so when BOTS or bad actors armed with synthetic identities and other compromised information attempt to use them within your platform, the tools can automatically detect the anomaly, giving you the ability to apply the right friction to that event, at the right time. The value of this too is that if you can detect the ATO upfront, you not only stop the event, but you preserve the integrity of your client’s account and provide them the opportunity to resecure it before any damage is done.
In saying that, individual program needs do vary so it’s important to speak to a few different providers around their service capabilities / approach and invest the time to find somebody you feel you can trust and work in collaboration with to help tailor the right solution for your requirements.
QUESTION: Any insight into how they got around 2FA? That’s probably something as consumers and marketers that we think keeps data safe:is that no longer the case?
Here’s a link to one of the first websites that came up when you google how to get around 2FA. Lots more detail in here: https://www.bitdefender.com/en-gb/blog/hotforsecurity/content-creators-why-2fa-isnt-enough-how-hackers-bypass-basic-security
ANSWER:
(CG) The above article is a good one on strategies bad actors are using. I think the other important point to make here is that whilst 2FA isn’t infallible, that doesn’t make it irrelevant and this really is where the “”security in layers”” comes into it. Having the right security controls in place across your platforms (including, but not relying solely on, 2FA) means that you can:
– Prevent 2FA being bypassed as described in the article
– Be alerted early if somebody does manage to get around it
– Block any activity bad actors attempt to commit from within the loyalty account2FA/MFA remains an important piece of a holistic solution to these problems, but carries risk if relied upon in isolation.
QUESTION: How do organisations best manage this?
ANSWER:
(MS) One way is by measuring it and having a KPI that is held by someone at a senior level. What gets measured, gets done. One big loyalty program has the loyalty fraud team sitting within their overall cybersecurity group. They have a comprehensive dashboard that is monitoring not just attacks on the cyber systems, but measuring fraud in numerous different ways. The loyalty managers can then easily see how things are trending, together with the various costs associated with items.
(CG) Visibility across the organisation (measurements, KPI’s, cost of the problem etc.) are all important metrics. I also think trying to break down silos within organisations so that there is cross-disciplinary understanding of what the challenges are and the ways to tackle them, is important. These aren’t just IT problems or just Loyalty Team problems. It impacts Marketing, CX, Loss Prevention, Legal etc. so it’s important where possible for all these functions to at least be speaking about identified challenges and aligning on possible solutions.
QUESTION: How does fraud most impact B2B businesses?
ANSWER:
(MS) In much the same way as in B2C – someone losses value and there is time and effort (and the cost) associated with tracking, preventing and putting people back to where they were before the fraud occurred.
(CG) Agree with Michael here and it all comes down to what checks are in place to validate B2B events. We see a lot of fraud with people signing up for B2B accounts to get access to better pricing, when in fact they are just bad actors with stolen payment instruments and synthetic ID’s. Also, bad actors know that B2B accounts can have the potential for a great deal of stored value within them and coupled with the knowledge that in some organisations, the perceived threat of B2B events is (mistakenly) lower, ATOs emerge once again as a significant risk here.
QUESTION: How do you foster a culture of fraud prevention throughout the entire business? Across departments and all the way down to store staff?
ANSWER:
(MS) There is a real balance here. The overwhelming majority of customers are honest and you want the program to generate loyalty not be like getting into Fort Knox. The simple way to have no fraud is to have no loyalty program. So, it’s about recognising that fraud (especially with Account Take Over) is an issue, but measuring it and sharing those stats in a way that’s not about scaring staff but engaging them as often they will spot something that just doesn’t look right. So having systems to get that feedback – not just about fraud – is a starting point.
(CG) Agree with Michael’s thoughts. I also think it’s about internal education, beyond the annual IT Security compliance training. Communicate with colleagues regularly about threats they are likely to face, encourage them to be on the lookout for suspicious activity, talk to them about what the organisation is doing to protect them and their clients and teach them what to look out for:
– Unsolicited requests for sensitive data
– Out of the blue “”urgent”” requests that carry some sort of penalty for non-compliance
– Customers that become aggressive and try to bully agents into making them do somethingAll of these are red flags and agents should feel empowered to take that extra step to validate the request, and even terminate the interaction if deemed necessary.
QUESTION: What is the future watch outs? What will fraudsters do next???
ANSWER:
(MS) It appears that part of the Qantas hack – according to press reports – was a very simple “”vishing”” (almost identical to what Chris shared in his video, although it was a voice call, hence the “”vishing””) where a person within the Salesforce system let the hackers in (and by-passed 2FA). They were then able to download lots of data – not just Qantas – from that hack. So, AI just allow all these “”simple”” hacks to be done at much larger and larger scale. And quick and quicker – and with that the cost to the hackers gets less and less.
(CG) AI is rapidly changing the ease of which sophisticated social engineering attacks can be perpetrated, as well as the scale of these attacks (as Michael also talks about). Given social engineering has such as high success rate compared to other attack strategies, I think you’ll see continued focus on this from bad actors, with high adoption of AI tools to support the attack.
There was a fascinating attack last year in Hong Kong where deep fake videos played over a teams meeting convinced an employee to pay over $25M USD to the attacker. This happened about 18 months ago, so you can imagine how much better the technology is today (and will be tomorrow!). https://www.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk
QUESTION: You utilised AI to create the deep fake for this presentation, are you concerned about uploading your face and voice whilst playing with these type of free platforms?
ANSWER:
(CG) This is an important question and should give everybody pause for thought in terms of how they use AI, whether it be for work or personal reasons.
The short answer is, yes, I do have a level of concern with it and whilst there are no iron clad guarantees here, some of the considerations given to preparing such content include:
– Who is the AI company owned by (where is my data likely to end up)?
– How will content be transmitted, who will have access to it?
– Can I limit distribution of the content?It is interesting how governments are starting to respond to the threat too with Denmark exploring legislation allowing people to effectively have copyright over their identity including face and voice. It will be fascinating to see how other jurisdictions approach this issue in the future.
https://www.weforum.org/stories/2025/07/deepfake-legislation-denmark-digital-id/My advice to anybody using these tools though; if you choose to make a deep fake of yourself (even if it’s with good, productive intentions – which of course, it will be!), know who you’re making that content with (i.e. where is your data stored and who can access it) and do not share it anywhere where somebody could potentially download it and exploit it without your knowledge/consent. (You also need to accept that despite taking a cautious approach, a data breach occurring at any location where the content is stored could still result in the exposure and/or misuse of your material).
Interlocutors:
| Chris Gregory, Dir. Client Onboarding & Consulting APAC – Accertify
| Michael Smith, Managing Partner, AI Event – Airline Information