Pedro Bizarro on How AI Is Transforming Both Fraud and Fraud Prevention
In this Techstrong.ai Leadership Insights video, Pedro Bizarro, chief science officer for FeedZai, dives into how artificial intelligence (AI) is being used to both commit and prevent fraud as these types of crimes become more sophisticated.
Transcript
ai Leadership Insight series. I'm your host, Mike Biza. Today we're with Pedro Bizaro, chief Science Officer for feedzai, and we're having a little chat about how gen AI is being used to perpetrate fraud and what to do about it.
Pedro, welcome the show. Oh, it's my pleasure. Thank you so much for having me.
I don't think it comes as much as a surprise that the bad guys have figured out how they use Gen ai, but to what extent are they using Gen AI to perpetrate fraud, and what should we be on the lookout for? Well, they are actually quite creative, and they're using gene AI a lot in multiple ways, and they, they are very organized. So basically what what they are doing is that they are making, with gene ai, they are making it easier to commit, uh, these phishing attempts and scam attempts.
So with Gen ai, they are able to create, uh, for example, email messages that are much more realistic. The tone and the language and what you refer to is, is much easier. So because of that, they are lowering the barrier of entry for other frauds.
They, uh, also using gene ai, uh, scaling up their attacks. So they are doing not one attack, but multiple attacks at the same time, sometimes hundreds, thousands with little variations, and in essence, testing whatever works better. So if they end up discovering that one message works better than the other, they start using that message more.
So they're basically doing what already some, uh, tech companies do when they're putting their ads. When they're posting their ads, they're trying out many different variations, and they're looking to see which one tracks better for, for their cases. They're also using, uh, gen AI to enable personalized attacks.
So they are able to get information from people that they share online on LinkedIn, on social networks, and they're able to target their attacks in a way that are much more efficient because now they know their company, their title, maybe their boss, their colleagues. So the attack is much more targeted. And if you're not on the lookout, you're gonna get food.
And of course, they're also using almost like sci-fi types of attacks in a sense that they are creating voice avatars. And in some cases, even video avatars. There are examples of people that are, they think they are in a Zoom meeting with, uh, with their colleagues, but they are in a zoom meeting with, with avatars create white fraudsters.
So all of this is becoming, of course, a huge problem. The losses are now on, on the hundreds of billions worldwide, uh, because of this type of fraud. I think the one thing a lot of these fraud attempts seem to have in common is there's usually some sense of urgency attached where somebody needs to do something quickly, but that assumes that somebody on the receiving side of that is gonna catch that and kind of raise a red flag.
Is there something from a technical level that we could be doing to identify these attacks so that we can maybe preempt them without having to rely so much on humans? Uh, there are in fact many things. Uh, we ourselves, uh, at, we have differences, all these type of attacks.
Um, we have, for example, a product, uh, called, uh, scam check, um, that we'll analyze the message and will show to us the red flags, for example, that these URL would not match or that this person using, uh, a request for, um, economic transfer, or there's an urgent tone on their voice. So it'll raise the alert, stop, uh, flag so that the people can be more on the lookout. And then we also have behind the scenes products like what we have.
So, uh, as you, as you know, uh, Xi, um, is a platform that protects, uh, Ian institutions and, and people, uh, worldwide. And basically we are running behind the scenes every time that you are doing a, a payment or a transfer, a transaction, when you put your credit card on the machine or make a payment online, there's just a few milliseconds, um, where we are called by the bank, uh, to check, is this transaction a really a good transaction or not? Is this suspicious or not?
And we are running machine learning algorithms to see if this matches your usual behavior or not, and we we're gonna flag it to the bank. Mm-hmm. It does seem like a lot of these attacks now are being launched by syndicates that are highly organized.
Are there things that governments around the world and law enforcement agencies should be doing to combat this? Because it does feel like it's become a global problem, Is indeed become a global problem. And the many times the frauds are taking advantage of multiple geographies and multiple, uh, countries.
And part of companies because they start an attacks, say on a social network, and then they jump maybe to a telecommunications operator, and then they jump maybe to a bank. And maybe all of these players are in different countries and they don't have a common legal way of sharing data. So they take advantage of the fact that they are touching many organizations that do not communicate between themselves.
One thing that governments and law enforcement agencies and regulators to do is promote ways for these companies to share information, uh, in a private way, uh, to detect fraud, to realize that, okay, this person is sending, uh, dozens, thousands of SMSs. Maybe this is a little bit suspicious, or this accounts may sending too much, um, messages that look the same and they are looking for money. This looks suspicious.
So it should not be just, um, an issue that is affecting the financial institutions. It must be something that is addressed at a global level, including financial institutions, but also tele communication, uh, companies and certain networks and governments so that the, this information can be shared in a, in a safe way and an efficient way. Mm-hmm.
Of course, there's a lot of different types of fraud being committed. Um, are there particular vertical industries where you're seeing who are more impacted than others? I mean, obviously financial services, but what else are the bad guys after?
Well, uh, I normally say there is money, there is fraud. So, uh, all types, all types or, or sometimes even what's called pai money. Quasi money is things like, uh, miles points and things like that.
So e every time there's, um, money or something that it can be transferred to money, eventually it could be a gift card or something like that, they will be f fraud. Uh, and this, as you say, they are very organized and they shift quickly. And normally it's almost like a game of guacamole.
So you, you stop them on one side, they start doing something on the other side. Something that is really important is our ability as on, on this side, the good guys to protect in a way that is very quickly. So we need to be very quick because the, the, the frauds are also adjusting very quickly.
It also seems like there's a lot more activity surrounding various cryptocurrencies. And I think maybe that's because there aren't as many protections there. If we want crypto to become something of a mainstream currency, do we need to kind of figure out all these fraud schemes?
I, I think indeed. Uh, so, um, cryp two I think has lots of good promises about, uh, removing, uh, bottlenecks and allowing instant payments person to person. But at the same time, sometimes auto removes, uh, somewhat protections.
Uh, and in order for us to really trust crypto, we, the consumers want to feel that there's somehow some sort of protection, right? These days. Uh, if a person commits, uh, a mistake, uh, in a traditional bank, normally there's some sort of mechanism to, to re recover, at least sometimes partially, but recover something of their, of their funds that are actually, uh, legal requirements in most countries to do that, to protect consumers.
But, uh, it is not yet the case in crypto, right? So if you, if you make a mistake, if you share your password, if someone gets old of your account, if someone hacks your computer and steals your, your crypto login, you your toast. So yes, I, I think we should have more protections for digital currencies as well.
You mentioned lowering the bar, and I think that is also gonna make it harder to, uh, disrupt and prosecute these gangs or syndicates. 'cause it seems like almost every three days or so you'll see an article about somebody got caught doing something, but, um, it feels like these entities just reconstitute themselves pretty quickly and launch again, and we're as far off as we ever were. It it is indeed, uh, uh, good that in some cases these entities are in, um, other region, sometimes even promoted by their own countries, uh, or supportive, uh, or sometimes ignored, just letting them do what they wanna do, which makes persecuting these types of criminals much harder, uh, because they are in, in far away regions with other legal systems, sometimes even protected by their own governments.
Uh, so what this means is that we need to protect ourselves on this side. We need to find ways to be able to, even in the presence of organized crime, we need to assume that they're always going to be there and, and protect the, the accounts and the transfers and the payments on our sites is going to require on, on some cases, education of consumers, but also using AI to fight ai, right? We, we are the good guys, and we also need to use AI to fight these AI being used by, by the criminals.
Do we need to make sending money harder? And I'm asking the question because if I went back 25 years ago and I went down and send somebody, you know, a hundred thousand dollars, it was a process and it took time and there were checks and balances in that. com and we made it simple to give people money and transfer money through Venmo and whatever else.
But I wonder if we've gone too far, because that's what helps the fraudsters just kind of take the money and run. Well, for qui there's a balance, and there's always been the case that on one hand, we are trying to remove friction. We're trying to make the system smoother and easier for people to use.
And on the other hand, as soon as we remove friction, the first people that take advantage of that reduce friction normally are the fraudsters. They move very quickly, uh, when we allow realtime payments fraud, take advantage of realtime payments to, to make fraud faster and get their money faster. But I am honestly an optimistic person, and I do believe that it's possible.
And we've seen that it's possible to reduce eviction without incurring the losses. For example, we protect, um, hundreds of millions of, of people in, uh, other countries like, uh, Brazil for example, that has a very, uh, dynamic market of real time payments where people can pay with their phone almost e uh, everywhere. Uh, more than, uh, 75% of all payments in Brazil are now learning real time, uh, by phone using their peak system.
And we have been able to protect, uh, this country, uh, although you'd think that, okay, we reduce friction so much, it's going to be, uh, much more dangerous. But in fact, it, it has not been. So, I, I truly believe that possible to reduce friction and do a good job and protect people.
Um, you mentioned new technologies and deep fakes and various things that these folks are using. Um, as you look into the coming year, is, is that gonna become a lot more commonplace, do you think? And what are you expecting the next thing the bad guys to do?
Well, yes, I, I'm, I'm expecting that these attacks are going to become, uh, more and more common. Um, we have seen sites that are totally devoted to fraudster there, things like fraud, GPT and warm GPT, that the, these are sites that fraudsters use and they have, um, uh, black markets and dark web, um, channels, uh, like telegram channels to share with themselves, techniques to do broth. And so they are learning and sharing with others very quickly.
So every time that something like this works, I expect that it's going to spread. And we see that, we see in our clients that if something appeared in one country, and if it works, then it's going to appear in other countries. Mm-hmm.
So I imagine that they are going to target more and more people. 'cause in most places, people are going to be the weakest link. The the systems are protected, the computers are protected, but people are the ones that are sometimes more easy to fool.
Um, so I, that's what I expect. So let me ask you this. Where's the outrage?
'cause when I look at the world out there, there's, there's probably trillions of dollars being lost to fraud if I added it all up. And yet, um, there isn't this sense of, um, we need to go tackle this today. There's usually a report from the World Bank or the UN or somebody like that, but, um, it doesn't feel like it rises to the top of the agenda.
And so what are we gonna do to get everybody focused? That's, that's a really question. Well, actually, in the, in the places where I work, this is actually top of mind.
Uh, so, uh, almost all regulators in all countries or international institutions, they are very, very aware of the rise in scams and crime. And in many countries, Australia, UK and, and, and others, there are already, uh, enforcements for companies to share information across, like, like I was saying before, social networks and telcos and, and banks on purpose to prevent this. There are also situations where the, the blame is being shared not only from the standing bank, but also from the receiving bank.
So that both need to check. So increasing the, the, the number of people checking if a transfer makes sense or not. So I, I think it's very much top of mind, at least in the financial world, that this is a, a rising problem.
Maybe it's not, um, top of mind across, across the globe for other people, uh, outside of, of the financial world. But it's very much one of the, of the biggest problems here. Folks you heard of here, ai, we've talked about it in the past.
It's a double-edged sword and the bad guys are using it for all kinds of things. So you gotta be careful out there. Pedro, thanks for being on the show Course.
My pleasure. All right. And thank you all for watching the latest episode of the Techstrong AI Leadership Series.
You can find this episode and others on our website. We invite you to check all those out. Until then, we'll see you next time.