Michael Jabbara, Visa | RSA Conference 2023
Fraud continues to evolve by the minute, with fraudsters targeting online and offline vulnerabilities as we blend in-person and e-commerce experiences. For instance, as cryptocurrency becomes more entrenched in our cultural and economic landscape, threat actors will increase their attempts to steal money and these digital assets by exploiting vulnerabilities. According to Visa’s Spring 2023 Biannual Threats Report, 2022 was a record-breaking year for cryptocurrency thefts, with over $3 billion stolen in on-chain thefts. Michael Jabbara discusses the key trends shifting threats to payments as blended commerce returns.
Transcript
This is texturung TV. Hey everyone. We're back here many thanks to my buddy Mitchell Ashley.
Did the last dinner with the last panel? But I'm back at the desk and we're really excited to be here at Tech strong. We are live.
It's the afternoon and our next guest is Michael Jabbara from visa and first of all, Michael, welcome to text strong TV, man. Thank you so much for having you to have you here. Absolutely.
So Michael, let's start with you. Yeah, tell us tell us about you. Yeah now absolutely so I lead our Global fraud services organization.
And so the the mission statement for that is to proactively identify and mitigate large-scale fraud attacks in data breaches across visas entire Global ecosystem. So we process 10 trillion dollars worth of payment volume. Annually, my teams are really annually good because your second right there.
You're gonna tell me daily and I was like that. I don't think that's the goal. That's that's the you know, that's the goal, right?
Okay, right. Yeah exactly or inflation. I think one of the other one or the other.
Yeah, but that's the idea so that the teams organization the team's mission is to really make sure that we're that first and last line of defense and make sure that our clients don't suffer kind of traffic for a losses. Excellent, and you are the head of the global. Fraud team on this, correct?
No, that's exactly right. You talk to us. What is that?
Oh. Does that really entail? Yeah, yeah, not so there is gonna four components of it that we put into place.
So the first thing and everything that we do starts with intelligence, so we have folks who are monitoring the dark web kind of understanding how malware ransomware is evolving and building capabilities that allow us to identify these vulnerabilities and these threats as soon as they start to pop up. From there. We have our 24 by 7 risk operations centers.
So they're the ones eyes on glass as soon as they see these alerts jump. They assess them figure out if it's a true positive and then put the right action in to make sure the the attack is stopped and its tracks are the next team is a global risk investigation. So if you think about the 24x7 folks as doing triage investigators come in figure out what went wrong.
What was the Gap? What can we learn from it and then talk about it to our clients globally to protect themselves. And then we also that the final component is we have a really robust law enforcement engagement function where we enable bi-directional exchange of intelligence and then refer cases over to them so that we can disrupt the frosters the source.
I love it. Yeah, great. So, you know, I there's some people watching here at home though.
We're gonna say, okay. I get you know, Visa is very interested in fraud friend detection blocking fraud. What are you doing in RSA though?
I mean now beyond the obvious. What do you view as your mission here at RSA the whole point? Is that core to Our Network the global economy really is trust.
Okay, if you don't trust that the money is going to go to the person that you've sent it to that. You're going to get the goods or services that you paid for everything can falls apart and it has Downstream implications on everybody involved. So I'm gonna for us to maintain build enhance that trust requires deep Partnerships collaboration across multiple players.
So we're here to really share with our audience what we're seeing as a network things that we're doing about it and then potential things that we can do together as partners to make sure that we're kind of constantly evolving that trust Journey. actually that Have you well, actually I already know the answer but people out there. Yeah, these has been a player at RSA conference for years and years and years.
Yeah. Absolutely. Yeah.
All right, let's pivot a little bit or move on. What about this year's conference? Is there any news from these?
You know, what what what's going on? Yeah, I think for us it's always around the Innovation that's happening on the fraud side. And I think we talk a lot about hey, look at all this cool Innovation that is making our lives easier building new products and capabilities.
I think that's great for me. Every time I hear about that. My first thought is how are The Fosters?
How are the threat actors going to use that same Innovation to carry out more complex more sophisticated products. So we're seeing that with things like the evolution of AI and the development of Chad GPT. We're seeing that coming down a little bit further down the pipeline with Quantum Computing and the potential implications that it has on cryptography.
But we're also seeing some really interesting Trends today in terms of how Fosters are behaving like a really good one is around data, right? So we've done a lot of work around making data value lists, like you you're able to breach an organization, but the data you get access to can be used anywhere else. So what our frosters now doing, they're moving further Upstream.
They're collecting personal information so that they can do account takeovers. They can create synthetic identities. They can do application fraud.
And so there's always kind of this cat Mouse game that is happening and that we're seeing kind of happen on a much more accelerated pace and we had seen before especially after the covid pandemic. Absolutely. You know what?
I find that fascinating but It's almost. It just sort of Blends if you know our audience and security practitioners devops digital transformation Cloud native. Yeah, but when you go to the consumer level, yeah.
People they they just want the anti-fraud that you know, they know when they use a Visa credit card. Yep. They're kind of immune from the financial.
Help, excuse me, the financial penalties of being a victim of fraud. Yeah, right because your Visa conversation for you. Yep.
They know everyone gets an alert now and then hey this looks like it's suspicious activity, press one for yes two for no or yeah, or is this really you yeah, you know that kind of thing. Yeah. It's become so good at doing it.
So commonplace that I think a lot of people take for granted. What goes into this? Oh, yeah, absolutely.
I mean, that's the magic of security right? You don't know it's working but that humor as a consumer, but that's so so It's a double-edged sword because that's one of the problems with security is when nothing happens you want and so it's very hard to say. Well nothing happened because I'm doing security well or nothing happened because I'm not the zebra that the lion shows to eat, right?
Yeah right now that's exactly right. And this is this is an issue in our in our world. And and that by the way that changes consumer security.
Yes be to be security. Yeah. What is I mean and you don't want to be blowing, you know, because frankly you don't want to tip the bad guys off to everything.
You're doing everything right? Anyway, yeah. How do you strike that balance?
I think it's really around creating infrastructures in place that allow you to the deploy that seamless consumer experience where you kind of take it for granted which kind of want it want that to be the case, but also gives you a level of agility so that you can respond really quickly. Right and so for us the way that we think about it is like what is our superpower? What is it?
That really makes us a leader when it comes to security. It's really around data, right? So we have an unparalleled view in terms of the transactions that we see and also the differences in behaviors across card holders Merchants Banks countries all that, right, but data, I'll buy itself is Not Really Gonna Get You insights right?
You have petabytes of data, but it only is impactful if you actually can do something with it. So then we're building this AI ml layer on top of it and we were invested over 500 million dollars. In in that piece alone so that we can start to create some really Dynamic rule some really Dynamic scoring so that we have a really nuanced view of this is legitimate.
We should let it through this is suspicious. We should send that alert and get that confirmation or this is just like downright fraud. We need to go ahead and decline it at the source.
And then having that. Operational Playbook be very automated a lot of folks do sock and 24 by 7 support but a lot of it is like humans on the screen we do that because that expertise is incredibly valuable. Like how do you automate that Journey for these 24x7 people so that you're giving them that superpower right?
You'll hear amplifying their impact. So those are the three core components like the data AI there is I'm sorry the data than the AI ML and then the automation orchestration layer on top of all of it. So you can't walk more than three feet without tripping over this AI.
Yeah, not only this show it seems like in the whole world of course. Yeah. Talk a little bit about how AI not just now what you because you know, we in the in the computer in the tech world we didn't working with AI ml for a long time.
Yeah, but you know, we're certainly entering a new era of a island called the generative AI era. Yeah, how do you think that plays in your mission? So there's a kind of a couple ways because that going back to the kind of the point.
Where as soon as I see an innovation like how are the frosters gonna use it? And so when we're thinking about Chad GPT as an example and the way that it can like generate very authentic seeming documents and emails. If you look at you know, where a lot of the products are happening today, it's you know business email compromise.
It's clicking on links through fishing emails and those emails right now. They're kind of crappy like it shouldn't be too hard for people today right for the most part. I've seen some good ones.
Oh, yeah. Absolutely. I'm not saying they're all garbage.
Yeah, but you would think at least a security professional that most people would be able to detect it. Well now bring in that llm component to it and all of a sudden you as a froster can generate. Customized personalized email messages that are very convincing and then send them out to hundreds of millions of people so your reach is broader, but then also your success rate is higher.
And so now the amplification of all the data breach is all the in-person impersonation is account takeovers gets exponentially higher. And so for us it's like wow. Well, hey, how do we kind of make sure that we are building models that are able to detect these fake fakely generated artifacts and then be how do we set up our processes and systems to be able to handle this increased volume of attempts on our end.
So it's like a two-sided problem that we're looking to solve and we're working on but those are kind of things that we see coming up and I mean they're here now right? It's not this is not good like sooner maybe in 12 months. Absolutely.
I mean they've only been around for well, it's only been General available generally available over. Yeah. Yeah.
Michael I want to thank you for Family Guy. Thank you for having me people who are Visa cardholders out there and that's pretty much everyone. com.
Can they go to find out like some of what you and your team are doing? com/security and you get to learn all about what we do. com/security check it out.
We're live here at RSA. We're gonna be back in a moment. standby





