49
Catch Me If You Can: Tackling Financial Fraud in the 21 st Century ECIIA Conference, Stockholm 6 th of October, 2016

Catch Me If You Can: Fighting Fraud in the 21st Century

Embed Size (px)

Citation preview

Page 1: Catch Me If You Can: Fighting Fraud in the 21st Century

Catch Me If You Can: Tackling Financial

Fraud in the 21st Century

ECIIA Conference, Stockholm

6th of October, 2016

Page 2: Catch Me If You Can: Fighting Fraud in the 21st Century

these are my views

Page 3: Catch Me If You Can: Fighting Fraud in the 21st Century

they do not reflect the views and policies of my current

and former employers

Page 4: Catch Me If You Can: Fighting Fraud in the 21st Century

the main purpose is to share ideas and

facilitate discussion

Page 5: Catch Me If You Can: Fighting Fraud in the 21st Century

“Fraud control – in any profession – is a miserable business. Failure to detect fraud is bad news, and finding fraud is bad news, too”

Malcolm K. Sparrow, 1998

Page 6: Catch Me If You Can: Fighting Fraud in the 21st Century

speaker’s bio

Page 7: Catch Me If You Can: Fighting Fraud in the 21st Century

speaker’s bio

Page 8: Catch Me If You Can: Fighting Fraud in the 21st Century
Page 9: Catch Me If You Can: Fighting Fraud in the 21st Century
Page 10: Catch Me If You Can: Fighting Fraud in the 21st Century

Banking sector in LithuaniaSource: Lithuanian Banking Association

Retail banks Branches Cash machines Employees8 298 1 367 9 274

Page 11: Catch Me If You Can: Fighting Fraud in the 21st Century

bank crime

Page 12: Catch Me If You Can: Fighting Fraud in the 21st Century

Bank Robberies in the Baltics

Robbery Statistics* 2008 2009 2010 2011 2012 2013Lithuania 20 3 0 0 0 0

Latvia 3 2 4 22 6 3Estonia 1 6 3 n.d. 4 0

*European Banking Federation

Page 13: Catch Me If You Can: Fighting Fraud in the 21st Century

Bank robberies are on decline

Source: Svenska Bankföreningen

Page 14: Catch Me If You Can: Fighting Fraud in the 21st Century

Bank robberies are on decline

Source: Nederlandse Vereniging van Banken

Page 15: Catch Me If You Can: Fighting Fraud in the 21st Century

“Where did all the bank robbers go?”

Campbell, D., The Guardian, 2014

Source: ThreatGeek.com

Page 16: Catch Me If You Can: Fighting Fraud in the 21st Century

Another Attack of Cyber Criminals!FEARS are growing for the UKs financial security after cyber thieves hacked into a major European bank's computer, stealing thousands of pounds in savings.

Online criminals have targeted a top European bank, stealing more than £400,000.

The attack, which took place at the beginning of the year, compromised more than 190 personal accounts.

The thieves used a Trojan programme to hide dangerous information inside innocuous-seeming software.

This intercepted data and allowed the criminals to transfer money without the bank or its customers becoming aware.

It appears most of the victims were from Turkey and Italy with some customers losing over €39,000

Details about which bank has been attacked have not been released, or whether any UK customers have had any money stolen.

This latest attack is sure to send shock waves through the banking sector as it proves how vulnerable modern day technology is to attack from criminals.

THE DAILY NEWSwww.dailynews.com THE WORLD’S FAVOURITE NEWSPAPER - Since 1879

Page 17: Catch Me If You Can: Fighting Fraud in the 21st Century

#case study

the dynamics of telephone fraud

Page 18: Catch Me If You Can: Fighting Fraud in the 21st Century

“It’s me, mother/grandmother! Help me!”

fraud

Page 19: Catch Me If You Can: Fighting Fraud in the 21st Century

Not a perfect crime# limited gain# limited range of potential

victims# requires physical contact /

time# difficult to recruit couriers

Page 20: Catch Me If You Can: Fighting Fraud in the 21st Century

“Hi, I’ve a job for you” fraud

Page 21: Catch Me If You Can: Fighting Fraud in the 21st Century

“Hello, I’m a police investigator…” fraud

Page 22: Catch Me If You Can: Fighting Fraud in the 21st Century

Online Banking Facility

Page 23: Catch Me If You Can: Fighting Fraud in the 21st Century

Password Card

Page 24: Catch Me If You Can: Fighting Fraud in the 21st Century

“Houston, we’ve a problem!”

# everyone’s a potential target# significantly increases fraudsters’ gains# no physical contact and requires less time# abundance of money mules

Page 25: Catch Me If You Can: Fighting Fraud in the 21st Century

97 273 57 39 20

133,699 €

424,158 €

108,688 € 102,028 €

34,176 €

Telephone Fraud Statistics from SEB Bank

2012 2013 2014 2015 2016

Total486 victims802 749 Eur

Page 26: Catch Me If You Can: Fighting Fraud in the 21st Century

Police Statistics 2012

of fraudulent phone calls originate in

Lithuanian prisons

(Source: Lietuvos Rytas, 15th of May, 2013) (Source: Respublika, 12th of March, 2012)

95% 816

804 046 EUR

357 225 EUR

7 884confiscated phones in prisons

cost of investigations

estimated loss

telephone fraud reports

Page 27: Catch Me If You Can: Fighting Fraud in the 21st Century

Profile of a Victim# 95 per cent women # average age - 55 years old# average loss – 1 600 EUR# had heard about telephone fraud before# hardly ever see stolen funds# suffer loss of self esteem, because they

blame themselves for having been ‘so stupid’# the society labels victims as gullible or plain

stupid

Stupid cow!How on earthcould I fall for that!?

A fool and his money are soon parted!

Page 28: Catch Me If You Can: Fighting Fraud in the 21st Century

Anyone can become a victim of fraud

Page 29: Catch Me If You Can: Fighting Fraud in the 21st Century

Cross-border Crime

Page 30: Catch Me If You Can: Fighting Fraud in the 21st Century

Variations of Telephone Fraud in Other Countries

Page 31: Catch Me If You Can: Fighting Fraud in the 21st Century
Page 32: Catch Me If You Can: Fighting Fraud in the 21st Century
Page 33: Catch Me If You Can: Fighting Fraud in the 21st Century

The Fake President Fraud

Victim

Fraudster 1 Fraudster 2

Page 34: Catch Me If You Can: Fighting Fraud in the 21st Century

challenges for law enforcement agencies

Page 35: Catch Me If You Can: Fighting Fraud in the 21st Century

Dilemma of Contemporary Crime

“If a network of Nigerian scammers based in Amsterdam defrauds French, Australian and American credit-card holders, where does the crime occur?”

“Earning with the Fishes”, The Economist, 2014

Page 36: Catch Me If You Can: Fighting Fraud in the 21st Century

Source: BBC

Page 37: Catch Me If You Can: Fighting Fraud in the 21st Century

Godfather of “la fraude au president”

Source: Huffington Post, 2016

Page 38: Catch Me If You Can: Fighting Fraud in the 21st Century

Law Enforcement Agencies# cross border investigations are

often lengthy and complicated# often lack forensic and technical

expertise, resources and motivation

# mutual legal agreements vs. speed of cross border bank transfers

# do not always understand banking products

# often engage in blame the victim behavior

Page 39: Catch Me If You Can: Fighting Fraud in the 21st Century

challenges for the banking industry

Page 40: Catch Me If You Can: Fighting Fraud in the 21st Century

Pssst…keep it shtum!

Page 41: Catch Me If You Can: Fighting Fraud in the 21st Century

# Doesn‘t share fraud data# Doesn’t have the same fraud definitions# Doesn’t share data on known fraudsters# Rarely shares data on best practices# Lacks adequate

training/qualifications/resources for its counter fraud staff

# Finally, banking legislation doesn’t provide enough guidance on how banks should deal with fraud

Financial Services Industry

Page 42: Catch Me If You Can: Fighting Fraud in the 21st Century

challenges for customers

Page 43: Catch Me If You Can: Fighting Fraud in the 21st Century
Page 44: Catch Me If You Can: Fighting Fraud in the 21st Century

Security = inconvenience

Page 45: Catch Me If You Can: Fighting Fraud in the 21st Century

Well, it ain’t gonna happen to me!

Page 46: Catch Me If You Can: Fighting Fraud in the 21st Century

“less than one percent of [Dropbox] user base of 500 million registered users had chosen to turn on 2-factor authentication for their accounts”Head of Security @Dropbox

Source: KrebsOnSecurity.com

Page 47: Catch Me If You Can: Fighting Fraud in the 21st Century

So there’s never been a better time to … become a fraudster?

Page 48: Catch Me If You Can: Fighting Fraud in the 21st Century

# No physical contact# Victimless crime# Defraud globally vs investigate locally# Abundance and availability of… # Recycling of old fraud types# Anonymity# Crime as a service

Page 49: Catch Me If You Can: Fighting Fraud in the 21st Century

thank you for your

attention!