Combatting Fraud with AI: Insights from Trulioo’s Hal Lonas
Hal Lonas, CTO of Trulioo, highlights the growing sophistication of fraud, especially through AI. Trulioo focuses on identity verification to help businesses confirm individual identities. Recognizing fraudulent signals is vital for the economy. The company balances transaction integrity with user experience, adapting to risk levels. AI is crucial in identifying real versus fake identities, and collaboration among businesses is essential to tackle the trillions lost to fraud each year.
Transcript
Hey guys, thanks to the throw we're here with Hal Lotes is the CTO for Truly You. And we're talking about fraud and how it's getting more sophisticated, especially in the age of ai. Hal, welcome to show.
Yeah, thanks Michael. Thanks for, uh, having me. Fraud has always been with us.
It's kind of like death and taxes that way. But, um, I guess my first question is how is this changing? 'cause I, I'm assuming the bad guys have access to ai, but how clever are they getting and how challenging is all this getting?
Yeah, you know, uh, it it's getting more sophisticated all the time. You're exactly right. The bad guys do have access to, to tools and techniques and, and things they, they didn't before.
And so, so we're seeing some of that come through now in, in these fraud attacks that, uh, that that truly you see, and by the way, we see millions of transactions. So we see, we see a lot of good, uh, transactions and a lot of good things, but we also see, you know, a fair amount of bad things too. I don't think everybody watching this knows who you are.
So how is it that you're able to see all these fraudulent transactions? Yeah. Great.
Thank you. So, Tru you is, uh, identity platform specialist across, uh, people and businesses. So our customers use us to make sure that, that the people and businesses they are, they're dealing with or about to deal with are, are really who they say they are, and they're trustworthy, either individuals or businesses.
So that's where we play, As I understand at least, uh, the bad guys have gotten exceptionally good at impersonating various legitimate people, transactions, business partners, whatever it may be. So what are the signals that we should be looking for to identify this fraudulent activity? Uh, 'cause as I understand it, this is, uh, impacting the global economy into the two trillions of dollars.
Yeah, so, you know, I, I think most, uh, depend on, uh, partners like, like tru you to do this. Some very big entities take this on their own, but it's a very sophisticated business and, uh, that, that we're in and, you know, runs across payments and marketplaces and financial institutions and fin FinTech. And so it's gotten very sophisticated and, and really the, the kind of that specialty of knowing, uh, people and businesses are who they say they are does revolve around certain signals.
So, and some of this depends on how much, uh, you know, what we in the industry call friction, uh, that, that our end customer wants to sort of apply to the process. And what we mean by that is, you know, they can ask, uh, you know, very simple question or, or in some cases, no questions at all, and, and trust that people are who they say they are. But, uh, you know, as as things get more sophisticated, fraud gets more sophisticated, uh, the, the questions need to get more sophisticated and move beyond from, uh, you know, just, Hey, what's your date of birth and your address and your name, where you live, you know, to more sophisticated techniques like, Hey, uh, I'd like you to show me a, a government document or Id, uh, we're gonna take a picture of it, and then we're gonna match your yourself, your face, uh, your face, your selfie to, uh, to that picture on that document and, and make sure everything lines up.
And, and that's a very, very sophisticated, uh, test that's quite often used these days to verify individuals. And it's, it's, uh, you know, something that can be, uh, you know, attacked with, with, uh, the, the bad guys use AI to attack that, but it's also very, very hard to do, given all the sophistication we throw at checking those signals and making sure they're all correct. How much friction are people willing to tolerate?
Because it seems to me that's always been the issue is that, well, yes, we wanna check to make sure that this isn't fraudulent, but our patience level for that is really low. So how do we kind of balance the need for, uh, integrity of the transaction and the simplicity of the interaction that everybody seems to want no matter what? Yeah, that, that, that's a really good question.
And, and there's a bit of a, you know, it's complicated answer. So a lot of, a lot of players and a lot of forces kind of gather together to decide what's gonna be done. For example, uh, you know, regulators and compliance people, of course, they want a, a, a lot of friction.
Well, they don't want the friction, but they want a lot of assurance that, that the identity, uh, is who that person or business says it is. Um, uh, on the other hand, as you said, if you apply too much friction, then people are just gonna drop outta the process. They'll say, well, you know, I, I don't wanna, I don't want to, you know, do business with them that much, or I don't want to start up, uh, or, or kind of join this organization for, for that much friction, so they'll, they'll bail out.
So there's a balance to be struck. So what we've done at Tru U is actually enabled sort of very variable, uh, friction to come into play. So on a dynamic basis, uh, we can let our customers decide whether this looks like a risky person or transaction, uh, and then decide how much friction they wanna apply on a dynamic basis.
So it might be as simple as like, Hey, Michael, like, you know, tell me, you know, your name and date of birth and, and hey, hey, we're good to go. I, I've, I know you have seen you before you, you look low risk. Uh, on the other hand, someone like, you know, Hal Lonas might get in and they say, Hmm, that seems sketchy.
We don't like, we're you are, are applying for this, um, you know, transaction from geographically, or we think we've seen you before and seen bad behavior. So we're gonna actually put you through the whole gamut of, of tests and, and put a little more friction purposefully on that, as well as gather a little more information for compliance reasons. So, you know, today, actually the most sophisticated solutions allow you to sort of vary the friction even on a dynamic basis, rather than in the past where it was like a kind of a one size fits all.
You either decided not much friction or a lot of friction. Uh, we can now use, you know, facilities in our product line to decide case by case how much friction we wanna apply. Actually not us deciding, but our customers deciding how much friction they wanna apply.
Is there a sense of urgency in a lot of the fraudulent transactions, or there's usually some anomaly where there's somebody standing up and going, we need to do something different. And that's part of, uh, the way they trick everybody into, uh, sending them money essentially, whether it's millions or, or even just a small transaction. But as I think this through for a minute, um, is there another, is that a signal we should be tracking or are the criminals just very patient now and they'll pretend to be a user for a very long time and then they'll strike?
Uh, a another really good point. So there's these kind of sleeper accounts that get created, right, where it's like, Hey, you know, I don't really want to do many transactions. It's low dollar volume.
I'm just gonna create an account and sort of sit there while you forget about me, and then fire up six months later and say, Hey, I'd like to move $10,000, you know, in this account. Or I'd like to like to do something else that might look, uh, you know, a little more. But, but that's, that's a perfect example of sort of a step up, um, verification you can do, you say like, okay, let's let people on the platform and if, if they're sort of thin file or we dunno much about 'em, it's okay.
But then when they do a, a higher value transaction, if they ever do it, uh, you know, our customers can decide to do sort of a step up verification at that time. So let's take a, let's take what we know and then let's add a little more to it and get some surety that they are who they say they are, and I feel good about this transaction. So, so the sleeper account and, and, and definitely the sense of urgency is there too.
So, you know, we all see that and hear about it and, and experience that ourselves. So, you know, we need to make care. We need to be sure, you know, personally that we don't kind of fall for that.
And that's sort of, you know, best practices from a, from a cybersecurity standpoint, but, but absolutely true. We of course hear about the bad guys are creating digital fakes and they have entire personalities and histories that are harder and harder to detect. But how would the good guys use AI to kind of fort that and, you know, 'cause I'm assuming we fight F Fire and with fire Ab Absolutely true.
So y you know, best practices now is, you know, your identity verification provider. I know, you know, truly you is very well invested in this. You know, we, we, since we do see millions of transactions, uh, you know, good and bad, uh, we build very sophisticated models now using AI to recognize, you know, the the real people from the fake people and the, the synthetic from the, you know, the, the authentic.
So we, we do a lot of work to verify that. And the signals, because the AI is getting more sophisticated, are getting more and more subtle. So the AI is getting better at creating people that look like people, you know, synthetically or, or licensed documents that look like real licensed documents synthetically.
And, you know, used to be the old thing where, you know, a driver's license with the wrong background, right? Uh, it doesn't look like a, it doesn't look like a British Columbia driver's license or a, or a, you know, state of Illinois driver's license. And now, um, the AI's becoming very, very good at, at replicating those, those details all the way down to holograms and making sure that the MRZ on the back matches the data on the front.
There's just a lot of work involved in doing that, but the AI's getting better and better. So the sophistication of the detection side needs to get better and better too. And, and, you know, needs to be constantly retrained.
And with those, those feedback loops to make sure the machine is, uh, learning, you know, what, what the bad stuff is, Is this platform of yours really aimed at very large enterprises or can anybody kind of invoke this? And it just kind of depends on the level of risk and what they're trying to protect. Anybody can use it.
And, and we find that, you know, sometimes there's, I mean obviously very, very big enterprises use us, uh, you know, payments and marketplaces and, and, uh, you know, uh, uh, very, very sophisticated customers are using us, but we also wanted to make it accessible to smaller businesses and smaller customers as well. And you know, where, um, bigger customers might use us, let's say through like an API only type of arrangement where they, they send us data or, or images or embed, you know, document verification in, in their application. Smaller customers can also access us through, uh, even like drag and drop interfaces.
Uh, we have a facility called Workflow Studio that lets you build an onboarding process using simple drag and drop and filling out fields and putting you on your own logo and making it look like your business. So we, we really wanna make it accessible to a broad range of customers and, and a broad range of customers find it very, very useful, you know, from, from very high volume applications to, to lower volume app applications. Yeah.
And who makes up in the morning to drive this? Is it the finance team or is it the security people? Or who's kinda coordinating the response here?
Yeah, uh, you know, compliance people, uh, folks that are, uh, customers who are monitoring regulations have to keep up with the regulatory environment. Uh, we, we also have more and more product people involved. So the, the, the product managers and the product people get involved and they say, and there's a bit of a, you mentioned before that, you know, the kind of the yin and yang of, of friction.
So the, the product people wanna onboard people the platform, they want to grow their business. And the compliance and regulatory people tend to be the, you know, kind of kind of overwatch where they say, Hey, let's make sure we are onboarding the right people and performing the right transactions, and we know who our customers are. So even at our customers, there's a bit of a, uh, you, you know, kind of both sides of that coin that, that are looking at it trying to, trying to balance that out.
But those, those are the main drivers, compliance and regulatory people and, uh, product managers, product people. So what's the one thing you see folks still doing that just makes you shake your head a little bit? Go and go, folks.
We need to be a little smarter than that. Uh, uh, you know, a couple things I, I'd say one is, um, you know, just, just not in pulling any solution or thinking you can solve this manually. So it's very, very difficult and actually very expensive to have a review team.
And we still see a lot of customers who are using manual efforts to try to do onboarding or, or kind of waterfall to that if it's not a simple case. And that just gets very expensive. And, and then you have to build up expertise in that area.
And, and it kind of makes me shudder to think like how fragmented that can get and the bad guys exploit that. So, you know, they can launch millions of attacks with very little additional cost, you know, for, for one or a thousand or a million additional attacks. It's, it's easy for them to push a button.
So, you know, that, that worries me. Uh, you know, a little bit, the, the other side of it too that I get worried about Michael, is actual customer participation. Um, you know, we can really all help each other by kind of having this, uh, herd mentality, right?
Where we protect each other. And, and customers sometimes are reluctant to participate if they feel like their data, uh, or their kind of transaction patterns might be used, uh, to protect them or others. Everyone's pretty worried these days about AI and models and how they'll be used.
And certainly I think we all see examples of, you know, maybe kind of creepy ads, you know, where you think like, well, for sure someone's keeping track of what I'm saying and doing and kind of targeting me. You know, on the other hand, from a security standpoint, you know, we want to be the good guys and protect our customers, but if we've seen an attack at one place, we'd love to be able to protect everybody from that same attack. So we, we kind of hope that in the future companies will be more kind of, um, uh, you know, aware of, of different use cases for the data and different kinds of models where some are really used for sort of a, a a a a kinda a beneficiary for everybody.
And, and, and others might be used for other purposes, but we, you know, we certainly want to use that data to help protect the broadest, uh, possible swath of customers and people. Hey folks, you heard you here. The bad guys collaborate all the time, so maybe we should figure out how to work together to fort that.
'cause it's costing us quite literally trillions of dollars a year. Exactly. You right.
Hey Hal, thanks for being on the show, Michael. Appreciate it. Thanks.
And back to you in the studio.