Speaker 0: The Payments Podcast from Bottomline. Owen McDonald (host): Welcome to The Payments Podcast. I'm your host, Bottomline Managing Editor Owen McDonald. We hear plenty about AI making fraud faster, cheaper, and more convincing, but banks cannot stop a headline. They stop specific activity by recognizing warning signs early enough to act. For this special episode, we've brought together insights from recent conversations with Bottomline fraud experts Eric Choltus, and Dalit Amitai. Their observations point to three fraud signals banks may be missing, and just as importantly, how to catch them before money moves. And before we count those signals, Dalit Amitai explains why the stakes have changed. Dalit Amitai: What's changed is really the threat landscape, the fraud landscape. Fraudsters have become much more sophisticated. Like you mentioned before, AI is accelerating the trend. Things like impersonation attacks, deep fakes, spoofed websites, super-highly personalized social campaigns are becoming so easy and cheap for criminals to execute. So banks understand that this is no longer a fight that they can win on their own. Fraudsters are collaborating, like you mentioned. It's a network. They share tools. They share techniques. And to get the upper hand back, banks need to do the same. Owen McDonald: AI is not merely adding new fraud techniques. It's making impersonation attacks easier to create, cheaper to deploy, and harder to distinguish from legitimate activity. That growing volume collides with weaknesses inside many banks. The evidence may already exist, but it is divided among systems that were never designed to tell one coherent story. Eric Choltus describes the problem. Eric Choltus: Banks have multiple solutions that they've accumulated over the years at multiple different points in the process, but they don't speak to one another; they're disconnected, and fraudsters can take advantage of that. I would say another area is relying on detection too late in the payment life cycle. If you do it too late in the process, yes, you can still detect, but it's more expensive and more difficult to claw back those transactions. Owen McDonald: That is the central issue. Banks may receive the signals, but receive them too separately or too late. So what should they be looking for? Signal number one is a mismatch between the person who normally uses the account and the identity now presenting itself. Choltus says those mismatches can appear in several forms. Eric Choltus: So I would say, there's a lot of reliable signals of digital impersonation, like fake websites, credential stuffing, remote access. You can look at device fingerprints and device intelligence to look for new or unfamiliar devices. You can look for location anomalies by looking at the geolocation of IP addresses, fancy term essentially. But really what you're looking for is, did Owen log in from New York, ten minutes ago and now is logging in from Tokyo? We call that impossible travel, for example. Owen McDonald: A new device or impossible travel does not prove fraud. It does give the bank a reason to ask whether the person inside the account is really the customer. That leads to an important solution. Authentication cannot be treated as a single gate at the beginning of a session. When risk increases, the bank may need to challenge the user again. Eric Choltus: The other thing that can be useful is different MFA methods. We know that fraudsters can bypass MFAs, but by incorporating them at different points in the process. MFA is multi-factor authentication. You can incorporate it at login, but you can also incorporate it later on in the process. If the person is executing suspicious actions inside the payment system or if they are approving a transaction, you can ask for another MFA or stepped up authentication. It's a powerful way to slow down a fraudster and also to challenge them, especially if you're giving them different MFA methods throughout the process. Owen McDonald: That's our first think point. Identity must be evaluated throughout the session, not simply accepted because somebody passed the original login. Signal number two is what happens after that login. Even when the credentials appear valid, the user's behavior may not be. Choltus points to behavioral biometrics, the patterns created by the way an individual ordinarily interacts with the device. Eric Choltus: Looking at behavioral biometrics, that's another fancy term, but a really powerful capability looking at a user's interaction to look at how they're moving their mouse, how they're typing on the keyboard, and does that match the normal patterns that we would expect for that user? Owen McDonald: The significant event may not be the payment alone. It may be the sequence, an unusual login followed by a changed payee account, followed by a payment that otherwise looks routine. Banks need to correlate those actions in real time and introduce friction when the combined risk warrants it. Sometimes the most effective safeguard is also one of the simplest. That's our second think point. The answer to AI is not always more AI. Technology can connect weak signals at speed, while a well-placed human control prevents one compromised user from acting alone. The third signal may not exist inside the bank at all. Fraudsters operate across institutions. A bank protecting only its own perimeter may therefore see one isolated transaction instead of the coordinated scheme behind it. Dalit Amitai explains. Dalit Amitai: The challenge is, Owen, that fraudsters don't think in terms of bank A, bank B, or bank C. They think about the entire banking system. Let me give you an example. The fraudsters will open a fraudulent account and then start targeting payers at multiple banks. Maybe bank A figures out that the account is bad, but bank B and C don't know that. If that information about the bad account isn't shared, payments can still be sent to the same account from another institution. Sharing such information across banks that an account is fraudulent will help all participants in the consortium. Owen McDonald: One fraudulent account can target customers at several banks. Knowledge held by one institution has little protective value if every other institution remains unaware of the threat. Amitai offers an even sharper example of how criminals exploit that limited field of view. Dalit Amitai: I want to give you another example. Fraudsters know how detection works. They are smart. So they are very good at staying below the radar. Let's say that a bank typically pays close attention to payments over $10,000. If I'm a fraudster and I'm trying to steal $100,000, I'm not going to take it from one customer at one bank. I'll take 10,000 from 10 different customers at 10 different banks and send it all to the same account. So, when every bank looks in their own system, nothing looks unusual. But if we zoom out and we look across the network, it's obvious that there's a coordinated attack happening. Owen McDonald: Each bank sees a payment below its threshold. The network sees 10 payments flowing into the same account. That distinction also helps solve another persistent problem. Better intelligence should not simply create more alerts. It should help banks separate genuine fraud from unusual but legitimate business activity. Dalit Amitai: Fraud detection usually comes with a lot of false positives. Just because a payment looks suspicious, it doesn't mean that it's fraudulent. And every time a legitimate payment is stopped or delayed, it creates a friction for customers that just want to run their business. If I'm buying a property and this is an unusual payment, it is suspicious, but it's legitimate. So this broader view helps separate real fraud from activity that might seem unusual at first but is actually legitimate. Because if the consortium is familiar with the account, if other banks saw the account and they see the account and familiar with it for, say, three years, and we know that six banks are familiar with it for six years, it gives the level of confidence that this is a valid account and removes the risk, reduces the number of false positives and the friction with customers. Owen McDonald: That is the other side of the signal question. More context can expose a bad account, but it can also establish confidence in a good one. The result is less disruption for customers and more productive work for fraud investigators. Dalit Amitai: So the other benefit is really an operational benefit. Most banks have highly skilled fraud analysts that spend their days investigating suspicious payments. The more false positives that the solutions generate, the larger those teams need to be, right? It comes with a cost. So if a consortium improves the accuracy of alerting, it will help investigators spend their time investigating the highest risk cases instead of reviewing a large volume of legitimate activity. Owen McDonald: This leads directly to a practical response. Commercial payment intelligence shared across institutions and converted into usable account risk indicators. Dalit Amitai describes how Bottomline's Fraud Intelligence Exchange approaches that challenge. Dalit Amitai: The main and first use case that we're planning to offer is what we call Payee Intelligence. So, like the first example that I gave, fraudulent accounts will definitely be shared across the participants in the network. But the other value is that we can provide what we call account insights or account risk indicators. Those will be around payment patterns, around the augmented legitimacy of the account, the pattern, the date range of activity. The more we know about the account, the better it is for the participants and the more confidence they can get about good accounts. So the value is not limited to, let's alert only on fraudulent accounts, but a good account that will help banks reduce the friction and improve operational efficiency. Owen McDonald: Of course, collaboration raises an unavoidable question. How can banks gain that broader intelligence without exposing sensitive customer information? Amitai draws the distinction that makes the model work. Dalit Amitai: None of those really work unless banks trust the way data is being handled. We need to have safeguards. Data should be shared in a way that will protect privacy. We have strong encryption, clear governance, and strict controls on who has access to the information. Banks are also asking for transparency into what data is being contributed and what data is being consumed. They need assurance that participants are operating within clear, well-defined regulatory and legal frameworks. That's super critical and super important. Because at the end of the day, banks do not want to share data. They want to share intelligence. This is the distinction. The goal is not to expose customer information. The goal is to help institutions identify risky accounts and suspicious patterns. Owen McDonald: That is our next think point. Banks do not need another uncontrolled pool of raw customer data. They need governed intelligence that makes dangerous accounts easier to recognize and legitimate accounts easier to trust. Put the three signals together, and the answer is not a single fraud model or another isolated alert. Banks must verify who is acting, understand what the person is doing inside the session, and compare the resulting payment with intelligence beyond the walls of one institution. Then they have controls capable of intervening before the transaction becomes a recovery problem. AI will continue to improve the disguise. Banks do not need to predict every new fraud scheme. They need to recognize the trail it leaves, connect the signals, and act before money moves. My sincere thanks to Bottomline's Eric Choltus and Dalit Amitai for their insights. To our audience, the smartest people in B2B payments, thanks for listening. Hit subscribe. Catch us again on your favorite podcast platforms, including Apple, Spotify, Blubrry, iHeartRadio, and YouTube. Bye for now. Speaker 0: The Payments Podcast from Bottomline.