Solutions overview
Harness the power of your data
Support and investigations
Support services for Ravelin
Online payment fraud
Account security
Policyabuse
Marketplace fraud
3DSecure
Resource Zone
Deep dives on fraud & payments topics
API & developer docs
APIs, glossary, guides, libraries and SDKs
Global Payment Regulation Map
Track PSD2 & more with a full report
Blog
The latest fraud & payments updates
Insights
In-depth guides to fraud, payments & security
About Ravelin
Discover the story about Ravelin
Careers
Join our dynamic team
Customers
Read more about our happy customers
Press
Get the latest Ravelin news
Support & investigations
Accept more payments securely
Protect your customer accounts
Policy abuse
Stop policy abuse to protect your bottom line
Ravelin for marketplace fraud
3D Secure
Ravelin 3DS & SDKs
Resource zone
Global Payment regulation map
Read more about our happy custmomers
Blog / Account Takeover
We all know that social engineering fraudsters target customers, but how do they target your business? We chat with Senior Fraud Investigator at Just Eat, Shawn Colpitts, to find out...
Share this article:
Social engineering is on the rise, as more fraudsters target a common merchant security weak spot: customer services. Our recent survey revealed that 40% of merchants don’t monitor fraud for orders made via call centers, leaving the gate wide open to attacks.
We speak to Senior Fraud Investigator at Just Eat, Shawn Colpitts, to give his insights on social engineering against merchants and how to stop it...
“Social engineering is when fraudsters work the knowledge they have of you, against you. They use psychological manipulation to trick people into giving away sensitive information. There's loads of different methods - phishing, smishing, vishing, whaling and so on.
“Against merchants, fraudsters will contact customer services to try and access a customer’s account and often change the details. They may call from a spoofed, blocked, or private phone number. It's scary that people fall for these, but some fraudsters are really good.”
“Any kind of fraud that involves a customer’s account or personal details...
Card-not-present fraud: fraudsters manipulate customers to get credit card information. They might send you a link offering a discount deal, but once you input your details, they steal them and use your credit card online.
Account takeover: the same manipulation techniques can be used to take over accounts and order products or sell on customer data.
Identity theft: if fraudsters can scrape enough information, they can actually steal a customer’s identity to commit more crimes.”
“Absolutely yes, it's increasing. Since the start of the pandemic, more vulnerable people have been forced online who may be unfamiliar with social engineering tactics. So not only is the activity increasing, but there are more people to scam.
“All types of fraud have increased due to Covid-19. Since the volume of genuine account holders and transactions have gone up globally, fraudsters find it easier to hide suspicious activity.
“Fraudsters will manipulate people's fear of the virus too. Everyone has seen those fake vaccine texts and other Covid phishing scams. It feels so wrong to take advantage of something like this, yet they do.”
"We’ve seen an increase in fraudsters targeting the customer services of merchants. Customer service agents are vulnerable to social engineering attacks because they are trained to think the customer is always right! They are pushed to give great customer service and genuinely want to help, but fraudsters know that."
“Fraudsters have many social engineering tactics...
“Brand reputation is the big thing. If word gets out that customer service allowed an account takeover, the responsibility falls on the wider business. Want to stop fraud? Close the doorway to social engineering.
“Plus, revenue losses can be massive. A data breach at Apple cost the company $3 million, and that was accomplished by a phone call to their contact center.”
“If a fraudster contacts your customer services, you can always use multi-factor authentication to send a push notification or a text message - they should have the phone in their hand. People are now used to 2FA, it's part of our daily lives, so why not utilise it?
“Ask questions about the account, not the customer, so fraudsters can’t easily answer, like: what was the last thing you ordered? Be mindful that some good customers genuinely won't remember their history, so prepare options for the account holder to help them verify themselves.
“Familiarise the customer service team with fraud red flags. Encourage them to say ‘no’ if a customer asks for something abnormal. And beware of fraudsters using old details. A lot of fraudsters have information they've gathered that isn't relevant to that customer any more.”
For more insights from Shawn Colpitts on what social engineers can do with stolen credentials, watch our recent account takeover webinar.
Grace Proctor, Content Writer
Blog / Fraud Analytics
Fraud prevention is a delicate balance between stopping fraud and maintaining good customer experiences. But what is the most effective way to measure this outcome?
Ravelin Technology, Writer
Blog / Machine Learning
Online payment fraud is one of the biggest threats facing grocery merchants. And it’s only gotten worse. How are fraudsters using the cost of living crisis to take advantage of your business?
There’s a new fraud threat on the rise – and it’s your customers. First-party fraud is infamously tricky to catch and a huge revenue risk. How can you detect and deter criminal behavior in your customer base?