
Risk and Reason · 2025-12-10 · 36 min
Key moments - from our scoring
Substance score
68 / 100
Five dimensions, 20 points each
Ryan Hunter brings a decade of fraud and identity experience from Upstart and Deserve to his role at Bilt Rewards, offering a comprehensive look at how fraud inflates costs across the entire lending ecosystem. He breaks down why even non-lenders pay a fraud tax: lenders embed fraud losses and prevention costs directly into APR pricing, meaning higher borrowing costs for everyone. The conversation traces fraud's evolution - from unsophisticated tactics like fake IDs (which Hunter recognized from high school classmates) through synthetic identity fraud (which peaked around 2016-2017 before tools like ECBS-via reduced its prevalence) to today's dominant threat: first-party fraud. Hunter explains how fraudsters exploit well-intentioned systems like credit disputes for "credit washing," and how friction in user experience - update restrictions, payment delays, SSN verification - exists specifically because of fraud. He also details the technical history of Social Security numbers: originally issued sequentially and sent on postcards, they were randomized in 2011 partly because millions of children were fraudulently claimed for tax deductions. The discussion emphasizes the arms race between sophisticated fraud rings using residential proxies and fraud prevention teams, and highlights cases like "bust-out" schemes where criminals establish clean credit profiles with no intent to repay.
Lenders price fraud losses and prevention expenses directly into APR calculations for their entire portfolio, meaning everyone who borrows pays higher interest rates to cover fraud losses and tools that large issuers spend millions annually to maintain.
Credit washing involves disputing legitimate trade lines on credit reports; while disputes are pending, those negative items are temporarily removed, allowing fraudsters to appear creditworthy (high FICO scores) and obtain credit, then the true negative items reappear after funding.
The SSA randomized SSN issuance in 2011 to prevent predictability and synthetic fraud; previously, the first five digits revealed the state and year of issuance, allowing fraudsters to generate valid-looking numbers, and sequential issuance made enumeration attacks easy.
Friction is intentionally built into account updates because fraudsters can enumerate personally identifiable information; allowing easy updates without verification would let attackers guess and modify account details for accounts that aren't theirs.
Synthetic identity fraud uses a mix of real and fake information (like a real name with a fake SSN) to create a false identity, while first-party fraud involves legitimate borrowers intentionally defrauding the lender by defaulting without intent to repay or manipulating their credit profile.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers solid substantive insights about fraud evolution, specific schemes (synthetic identity fraud, credit washing, bust-out rings, mule accounts), and technical implementation details (SSN issuance history, ECBSV validation, residential proxies). However, there are notable stretches of filler - the extended SSN historical tangent about sequential numbering and the woman's fraud victim story, lengthy childhood questions, and the game-show ending segment dilute density. Most insights cluster in the first two-thirds.
they're hiding their true IPs and and they're you can't tell where they're coming from
in 2011, the SSA started randomizing social numbers...when you start seeing uh randomizing social security it means one of two things
The guest offers solid practitioner perspective on fraud trend evolution (third-party → synthetic → first-party fraud narrative) and unusual tactical details (credit washing mechanics, ECBSV, residential proxies vs. old VPN detection). However, the core framing - fraud as a systemic cost, arms race metaphor, technical cat-and-mouse - are familiar in fintech/fraud discourse. The SSN historical deep-dive is interesting but tangential. Limited contrarian or first-principles thinking; mostly confirmatory expertise.
Back in the day, it was all third-party fraud when I first...very little, you know, synthetic identity fraud. And then it sort of shifted
credit washing...disputing all their...trade lines and then applying for credit. Their credit looks really good
Ryan Hunter is a strong practitioner hire: 10+ years in fraud/identity, director-level role at Bilt Rewards, prior experience at Deserve (6 years running fraud/identity) and Upstart (public company). He has demonstrated hands-on experience detecting and analyzing real fraud cases, relationships with credit bureaus, and deep technical knowledge. Not a marquee CEO or VC, but credible, relevant operator with substantive track record in the exact domain being discussed.
I'm Ryan Hunter, I'm the director of identity and fraud over here at Built Rewards. I've been uh in the fraud and identity space for about 10 [years]
I joined Deserve uh and I was there for six years. Uh Deserve did uh credit cards as a service, and I also ran fraud and and identity over there
The episode contains concrete examples: credit washing case with FICO scores (9003 exclusion, 550 true FICO), SSN randomization timeline (2011), specific vendors (ECBSV, ECOS-AR), mule account patterns in checking/DDA products, phishing text examples (Coinbase, Robinhood), and carrier-level fraud mechanics. However, specificity is uneven - many claims lack named companies, precise dollar figures, or quantified loss data. The geopolitical fraud ring discussion (pig butchering, Myanmar, 2022-2023) is mentioned but vague. Some high-value specifics offset by hand-waving elsewhere.
this person in uh this is a previous job, was uh basically they had trade lines and they were disputing these trade lines...FICO exclusion score, like a 9003 or something like that
in 2011, the SSA started randomizing social numbers
The host (Eli) asks reasonable exploratory questions and shows genuine curiosity about the guest's background and evolution of fraud tactics. However, he rarely pushes back, challenges claims, or forces deeper reasoning. The conversation meanders into tangents (childhood memories, SSN postcard stories, the host's own geopolitical interests) that dilute focus. The game-show segment at the end feels forced and adds little substantive value. Some good follow-ups ("Can we go back four years ago?") but mostly reactive rather than incisive.
Can we go back four years ago? You said you noticed a rise of synthetic fraud. How do you notice that?
Now you bring up an interesting point around things that well-intentioned and taken advantage of by fraudsters
Computed from the transcript - who did the talking, and the words that came up most.
Ryan Hunter (Director of Identity & Fraud Strategy at Built Rewards) joins Eli to unpack how fraud is evolving fast - from synthetic identities to first-party scams and global fraud rings that operate like real businesses. They dig into why legacy ID systems keep failing, where the biggest vulnerabilities live today, and what it will take to actually shift the playing field.
Transcribed and scored by The B2B Podcast Index.
Fraud is a tax on everybody. Can you explain why it's actually impacting them and why actually raises costs? Basically, when people are determining what an APR for a line of credit and their pricing risk, the portfolio is being priced into that as well. And so every portfolio will have fraud losses.
People may say, why do I care about fraud? I'm not running a lending company. It's not impacting me. The cost of things goes up because of how much people have invest to prevent the bad guys from winning.
If you turn off your fraud rules for sometimes as short seconds, you will get hit with fraud because people are always basically pen testing your system. APRs would be lower because delinquency would be lower. People could price risk way better. If it wasn't for fraud, the user experiences can be so If it wasn't for such prevalent fraud, we can do so many things.
This week, I'm very excited about our guest. Uh Ryan, I've known for some time by now. He has uh been kind enough to sit through footprint We've gone on walks in the park. I've always said that I think identity is a romantic uh And we've walked around Washington Square Park in different seasons.
More so he is one of the sharper people, truly, who I've met who has not just been in this space for a long time, but I I've always really appreciated is that I think you're open to meet with new companies. And normally you're you're probably at the top of my of people who will put me onto new tools that I had not heard of. Normally I feel it to the other way around. But you I think you bring like a very healthy skepticism just from many years in this phase of what can actually be done not.
So we have a lot to cover. I'm really excited, but maybe to start off, do you want to yourself? Yeah, well, thanks for that that introduction. Uh I agree, fraud very romantic.
Uh and uh romance scams are in. That's true. I love meeting with uh with new vendors uh just to kind of what people are working on, sort of see new approaches. And uh, like you said, like you never know what what fraud you're gonna need in the future.
And so the only way to do that is to take meetings. So um yeah, I'll go ahead and introduce myself. I'm Ryan Hunter, I'm the director of identity and fraud over here at Built Rewards. I've been uh in the fraud and identity space for about 10 Started my career over at Upstart, which was a peer-to-peer lender.
Now it's uh rebranded as an AI lender. They went public in 2020, I believe, 2021. Um and and then I joined Deserve in before that, but I joined Deserve uh and I was there for six years. Uh Deserve did uh credit cards as a service, and I also ran fraud and and identity over there.
And now over here at Built, kind of doing the same thing. It's a little bit of a different space, kind of doing stuff around onboarding, but kind of uh looking at different sorts of fraud around the loyalty and points and gaming and uh you know login and all kinds of different events. So kind of looking at all sorts of different aspects of the of the call fraud life cycle for all the way from but throughout. So yeah, it's been it's been a fun career, and I couldn't asked uh for a better career to fall into.
Now let's talk about that. Growing up, were you were you doing escape rooms? Uh did you watch Sherlock Holmes? You know, uh when did you first start getting interested?
Like what skills do you think that you you always had up that's like this this could come together pretty nicely? But and then when you got to upstart, was it a you're in lending and they're like we need someone to work on or was it I want to join a company that will let me work on fraud? I didn't I don't know if anything from my childhood really prepare me for this career. What was your first childhood memory, Ryan?
Oh god, I don't know. Good question. Great question. It was not nothing fraud related, I I don't think.
But uh yeah, I think that when I was uh when I was at Upstart, I sort of started working there as basically in operations. And I was fresh out of college. I was just taking sort of like the first job I could get. I studied finance in college, but I wanted to, I took off after college to travel and took the first job I I got back.
And I was working there and I uh was quickly promoted doing a couple different things, and there was I kept I kept recognizing that certain loan applications had fake licenses on them. And the way I was sort of recognizing this was because in high school, a lot of my friends had fake IDs. Not me, but a lot of my friends did. And because of that, I was able to recognize what a fake ID looked like, and I was sort of able to catch fraud that and I quickly was put as one of the early uh members of the fraud team.
So that's kind of how I fell into it. I sort of fell into the lending side of the lending world, then I sort of fell into the fraud world. And I guess maybe you said what sort of things from my maybe having friends that had fake IDs, that was probably the biggest uh preparation for for a uh a career in fraud. Yeah, it I guess that is every not everybody's, but a lot of people's first introduction to uh identity theft as they grow up.
Uh first party fraud, you could say. Um it's become over a decade in the industry. Have you seen sophistication evolve from your pop fake ID to get into a college bar to more sophisticated? Uh what's that and what's that been like in terms of you know, we talk about arms races.
Uh we talk about it in let's say sports. Of your rival goes out and gets big players, you need to. The fraudster versus fraud team one's interesting in that not as open. It's the fraudsters are professional and they're spending and they will figure out what they want to do next, and you have to respond very quickly.
What has that been like over a decade? I feel like when I first started, the the fraud schemes have gotten way more sophisticated with time. And so you used to see stuff, and some of these like fraud still have similar things where it's like, oh, you know, if you flag the IP for a VPN, that's like high risk. It's like, I haven't seen a fraud ring using a VPN that a VPN on an IP address in years, right?
The fraud rings are all using super sophisticated, you know, residential proxies and and sophisticated networks like So they're hiding their true IPs and and they're you can't tell where they're coming from. So I I think that things have gotten way more sophisticated with time. Back in the day, it was all third-party fraud when I first very little, you know, synthetic identity fraud. And then it sort of shifted when I started maybe that or so, 2017, when I started noticing synthetic identity I'm sure it existed before then, but that's really when noticing it.
And and then, of course, vendors came into the space to sort of solve that problem. And you don't see very much synthetic identity fraud, at being a problem anymore in the lending space, primarily. I mean, most people, you know, there's ECBSV, there's really good vendors that can help you, you know, stop synthetic fraud. And so then in the last maybe call it four to five years, I definitely think in the lending space it's shifted more first party fraud, which has uh just gone absolutely rampant in the industry because it's extremely hard to detect, very hard to stop, and uh it's it's hard to tell, it's hard to it before it happens.
It's sort of like a minority report, I think of it like crime, right? Where it's like we're trying to, we're trying to, the we're trying to you know figure out who these people are on the way in. And it's usually not shown in their credit data because purposely obfuscating it. And but yeah, that's sort of I sort of seen this transition.
And of course, we see the fraud rings today, the third-party fraud rings, are doing extremely sophisticated things with phone numbers, uh, you know, uh, and just sort of like where their devices and things like that. So you see a lot of really sophisticated things now that know if they were happening back in the day. I certainly wasn't recognizing them. Uh now, now I I can recognize them a little more easily.
But yeah, those that's sort of how I've seen the evolution on. Can we go back four years ago? You said you noticed a rise of synthetic fraud. How do you notice that?
Because it it is that, you know, you go back and you look the people who committed fraud and you say we reached out for more information, they couldn't provide a driver's license. Synthetic fraud for those who don't know, it's essentially me taking some of my actual information and then Ryan's social security number, made up social security number, creating an account somewhere, nurturing that into the bureaus. They're now tools like you said that do some pretty math to figure out what's synthetic.
But how do you, as someone on a team, look at your say, oh, this is synthetic? Yeah. So a lot of the times, especially when you're thinking SSNs, uh, you can tell the SSN was either issued prior to date of birth, which is an obvious massive tell, um, or that the individual identity has multiple SSNs associated with So those are all easy tells that you can figure it out. But of course, in 2011, the SSA started randomizing social numbers.
So when you start seeing uh randomizing social security it means one of two things. It means they either got their SSN issued after 2011, which means they're probably a uh you know, a recent immigrant or something like that. Or uh on the flip side, it could be that the individual is this randomized social security number to try and get And so that's really in 2011 is when you saw synthetic really s fraud really start. But I didn't notice, I didn't even notice a thing until 2016, 2017.
And, you know, as of I will call it 2020, it's maybe not a problem, but you know, there's authoritative sources with ECBS via, which is electronic consent-based SSN which is basically where fraud vendors, credit issuers can direct connections with the SSA to sort of validate SSNs. And so we've seen that uh I the just the prevalence of social security uh synthetic identity fraud has really gone down. They still attempt it, uh, but you don't see it in lending much. Uh you know, obviously you still get onesie twosies, but don't see it as as prevalent.
And that's because of these tools that that exists in the today. Now you bring up a pretty interesting point around before you could somewhat guess what an SSN would be associated Can you expand on that a bit more and how I think people may think that the SSA and SSNs are these great sources, but they're almost a bit too predictable from a fraud Yeah. So SSNs were issued uh basically the first five digits of SSN, you can basically tell where what state and what year was issued within a certain level of tolerance.
And you know, they're they're basically issued in tranches you can see where it was. So like you if you know that you know when I was born and I was born and where my SSN was issued, you can sort of when my SSN of like the first five digits within a reason, It's less, it's harder to work backwards, but if you give me the first five, I can tell you where it was from. So basically we have uh, and then in 2011, they stopped doing that because the social security number was never supposed be this sort of private identifier for people.
The social security number was just supposed to be a so you can collect social security. And so no one used to get their SSNs until they got a job. So my mom, for instance, didn't get an SSN until she started receiving a paycheck in her whatever late teens or something like that. Whereas now there was a change that was made before.
So the I believe it was you cannot claim uh a deduction for children unless you have an SSN associated with that person. And so that was a change that the uh that the tax authority made, I believe. And when they did that, millions of children, I'm putting it in quotes, millions of children disappeared because parents were claiming they had all these children uh to claim the deduction and dependence uh on their tax returns. And so that is now that's why SSNs are issued right when born, because parents want to get that deduction on their So that is sort of like a little history of the SSN.
Uh and you know, it basically now that all the SSNs are when they're given out, uh, we don't know where they're they could be anywhere, which is probably a good thing for But it's also makes it so it's harder to tell when SSN was or if this truly belongs to the individual. Because before it was like, oh, this person is 35 and the was issued in 1960. Well, that's impossible. That cannot have happened, which means there's a fraud, something like that.
Um, so that's all changed with the randomization. It's a really interesting history. I mean, it it's a good case study of I think the other are intentional where they issue a national ID number, want it to be an identifier. The SSM was never supposed to be that, but everybody's tried to force it into that bucket.
Exactly. They and this was all because there was such a pushback assigning numbers to citizens, I believe, which is funny then they're like, okay, we're not gonna give citizens like a number, and then they just made this social security that. So it really was like counter counterproductive, and it was never most supposed to be secret. They used to send it out on a postcard.
Uh, they still send it in a really terrible, like little piece of paper, but at least it's in a sealed envelope. In the past, they used to send it just on a uh open like uh postcard where anyone could see it. The mail carrier could look at it, etc. They don't obviously don't do that anymore, but it never meant to be private.
It's also not a unique number. In that there are some people that have the same SSN. I think I don't know that to be. Is that true?
I didn't know that. I believe I believe that's true. They stopped, they they issued we'll have our footprint fact checkers go back and film this. I want to be at the bottom if a little disclaimer.
We'll we'll do a disclaimer. I believe that they stopped at some point, they made a where they would no longer do this, but to your point at beginning, it was less of a unique identifier. So I believe there are some overlapping SSNs. And also something funny about SSNs, they used to just give them sequentially.
So, like my dad and his siblings have the sequential SSN, that doesn't exist anymore, obviously. But uh, I just think it's funny that like back in the day they didn't really care, they would just give sequential SSNs. Um Yeah, I have a funny story about social security numbers, actually, from my first job. I used to work on the phones in my very first few months and a woman called and she said, I have like sort of this story.
Looking back, was this a scam? I don't know, but let's just let's just suspend disbelief a little bit and just pretend it's real. Uh that she wasn't trying to scam me. She said, I have been a victim of fraud.
My social security number was leaked. It was leaked all over the the country. I had hundreds of credit applications taken out of my name, thousands of attempts. She said, I froze my credit, it would get unfrozen.
People got married under my SSN, they filed taxes with my She said it was so bad that I have petitioned, I think it her senator or something crazy. I petitioned my senator, and he had to petition the Social Administration to reissue my SSN to get a brand new SSN. So she said, I have credit history associated with this and I have no credit history associated with this new Is it a real story? I don't know.
But I like I think it's a very interesting one where you can get a reissued Social Security number, perhaps. Now, and the footprint fact checkers have gone back to me. And it so before 1972, they were manually SSNs were issued. So there were a couple thousand that were duplicately due to clerical errors.
Once they went to a computerized system in 1972, they no have this issue. But they found that about 0.01% of SSNs issued before 1972 dupes. Uh which is yeah, which is a real number.
That's probably why the sequential SSNs happened, because just going down the list of their whatever, their their block of numbers. And if you if you get your kids at the same time, you they give you sequential uh SSNs. You would be able to guess the person in line in front of the SSN. But kind of exactly.
Yeah, there you go. Now, let's talk about first party fraud. Uh you say that that's the biggest thing you're looking at From let's take an outside perspective, somebody may following two things. I'm curious how you respond.
The first is, Well, how are you supposed to know this is This is psychology, there, this is an identity. And the second is, well, that's unfortunate, but you can then offboard the person, and you know, if you've conned third at any theft, at least they're only gonna hit you once. So that's not ideal, but it's one time. How do you respond to those claims?
I think that so it is very hard to determine who is doing It is, I will say, like geographically concentrated often, to certain high-risk areas. It's also you can sometimes get some indication from reports about things that are not credit related, but kind of may indicate that. Uh, and also from consortium fraud vendors where you of see some of the stuff as well. So I'll say that there are signals.
I'll say the signals aren't as strong as maybe the fraud signals are today. I don't know if that's because it's such a new, relatively type of fraud, uh, or if it's because they're purposely to obfuscate it. I mean, all this information is known at the at the bureau level, right? Like I'll give you an example.
Like um, this was a like a credit washing case I had. And could you could you explain what credit washing is? Yeah, basically, like people were uh this person in uh this is a previous job, was uh basically they had trade lines and they were disputing these trade lines as even though they were almost certainly not. And they would, while you dispute a trade line, that trade while it's being researched by the issuer, is deleted credit report.
So basically, they say you have a 90-day delinquent trade Someone comes in and they dispute that trade line with the The issuer, the credit bureaus will remove it while the is taking place. The e-oscar, which is the technology layer between the credit bureaus and the issuer, goes to the issuer and says, like, this person's disputing it for fraud. Do you accept or not? And between the time, that falls off your credit report.
So what people are doing is basically disputing all their and then applying for credit. Their credit looks really good because they have no and then they go through and they go through with like a 700 FICO. Then when those things get added back in, the next month have a 550 FICO, which is probably their true risk. And I had this case where I had this person, I forget exactly the details of it, but I had never seen a credit report like it where they had like a FICO exclusion score, like a 9003 or something like that.
But they had like indications that they previously had had trade lines. And I called a friend at a credit bureau, and the cred guy at the credit bureau is like, look, I'm gonna tell you off the record. Uh I'm not gonna say which credit bureau this was, uh, friend. Uh I'm gonna tell you something off the record.
You should not lend to this guy. He's he has disputed every single trade line he's ever given over the last twenty five years. He's never kept a trade line, none of it's fraud, they're falling off. He's probably litigious, you know, like suing the issuer or whatever.
Or threaten, threatening whatever. He's like, you should definitely not lend to this guy. Uh won't say what we did with that one, but that was a job. Uh and that was just kind of an interesting case where uh the bureaus can see all the disputed and deleted trades, but the issuers cannot.
For good reason, right? Like that's a that's a protection for customers where, if someone steals your identity, you can delete that and it won't impact you on a go for it. It's it's meant to be good. But it's being abused by first-party fraudsters to delete and manipulate their credit profiles to sort of uh you know get access to credit.
And on a larger scale, it's like, you know, these bust-out rings where they're just have no and they're just getting with no intent to pay back. Uh and you know, they have very strong credit profiles, typically will get very high credit lines, and then they'll just uh first party uh or first payment default without ever even looking to pay the line. So we see that a lot. Uh I used to see that a lot.
And again, like we don't do that kind of stuff is you know, we have a co-brand with with Wells, it's not really my neck of the woods anymore, but that's what I used to see a lot of when at my last job. Now you bring up an interesting point around things that well-intentioned and taken advantage of five fraudsters. I feel as a result, we often, when we think about building have to do the inverse. One example I'll give is we often have customers say, hey, are fat fingering an SSN.
Why can't you tell them that like it's off by one? And we say, well, there are definitely a lot of people that that's good for, but like there are people who would abuse and figure out, oh, I'm one away from getting somebody's So we have to build a worse experience for fraudsters as a How how much do you think about those trade-offs? Oh my god. I was just laughing about how I would just use that to or some, you know, you could enumerate someone's SSZ pretty easily.
But yeah, the uh it's it's all it's very unfortunate if there wasn't fraud, uh lending credit APRs would be lower because delinquency would be lower, people could price risk way better. Uh if it wasn't for fraud, the user experiences can be If it wasn't for such prevalent fraud, we can do so many things. But because of fraud, you have to exactly to your point, you have to design experiences that sometimes just lot of sense. Where it's like, why can't I just update my name?
Why can't I just update my phone number? Like, why can't I just update my email? Why do I have to do this? Why is there any friction involved with doing something, Why can't I just, you know, make a payment this in this It's like you have to design these safeguards uh because these bad actors.
So unfortunately, uh for the user experience and probably the APR's fraud uh uh makes it a worse experience, but perhaps for you and me, Eli, maybe maybe it's okay that or else you you maybe wouldn't have a I wouldn't have a certainly, uh, you know, if it wasn't for the fraudsters. No, that's true. Without KYC, I'd be a very lonely man. Yeah, it's it's a good point.
Um I I think that you know you you let's maybe suspend for a second and say we eliminate fraud and we get to have a nice ceremony for it. What becomes better? Give me because I uh you you bring up this good example of become cheaper, right? Like you could argue that fraud is a tax on everybody.
So people may say, why do I care about fraud? I don't commit fraud and I'm not running a lending company, so it's not impacting me. Can you explain why it's actually impacting them and why actually raises costs? Like is it's an inflationary event.
Yeah, for sure. I mean, like basically when they're when people are what an APR for a certain line of credit and their pricing the oftentimes the overall risk of the portfolio is into that as well. And so every portfolio will have fraud losses. And and if you not even talking about fraud losses, the expenditure that large issuers have to deal with, the fraud tools, there's so many different fraud tools that people to use that lenders are using to onboard people, and they have to spend, I mean, for a big bank, millions and of dollars on this.
Whereas if they didn't have to do that, they could be uh the the lowering the APRs, maybe improving the uh experience of the card, right? So if you get a credit card and you swipe it and it gets Well, that's because they think it's fraud, even though it's not, right? They should the fraud models, if you're talking about fraud, are flagging that transaction, you're having a bad uh at or getting declined uh at a restaurant, perhaps. So it's things like that that uh are definitely taxes and poor customer experience for good people.
Um, but certainly like the the cost of things goes up of how much people have to invest to prevent the uh the bad guys from winning. And it's not like, oh, we're in a good fraud time now. If you tune your if you turn off your fraud rules for as short as five seconds, you will get hit with fraud because people are always basically pen testing your system. So it's one of those things where uh yeah, we like you you can't switch off the fraud, uh the fraud rules and things like that.
So it's always on. Yeah. Uh Ryan, we we're going to try something new today. We want to play a bit of a game uh as we get to the end here.
So we have a bit of a twist of a classic game uh that has kind of abbreviation of letters. Uh we call this one uh past manual review or fail. Uh so I'm gonna give you a couple scenarios uh and I want you to tell us, you know, which ones you find the most which ones you'd be on on the lookout for. So the first is uh fishing techs.
So we we there was a big Reddit thread this week on Robinhood Techs and people getting techs uh for for kind of that those people were getting that. The second uh that I want to go for is you brought up uh like changing your phone number. So account recovery scams, uh, and and kind of people that. And then the third, let's do mule accounts.
That's like uh people like throwing out the term, it fancy. So I want you to give me pass, manual review, and fail. And this is not you doing that, but it's more so you saying kind of what are the ones that you think people need a lot controls on versus what are some that maybe bit out of the Okay, so the phishing uh what we had phishing scam tax, text, uh account recovery from account recovery, and then mule accounts. Mule accounts.
I think mule accounts, there needs to be more uh uh stuff mule accounts. I think that's a big thing that's happening. Where uh I think especially in like DDA account demand deposit account opening, like regular checking um, I think there's actually a significant amount, a ton fraud that people are opening. I remember seeing uh legitimate good bank accounts, uh statements from all the big guys, and the underlying of that individual is completely fake.
The the ID was completely fake. And what I've determined was that they these people have fraud rules on the checking account opening because not experiencing losses on these accounts, and so it's very hard to flag what's a true bad account. And so I think a lot of people are opening bank accounts, not committing fraud, especially not right away. It's in this person's name, maybe there's even money in I've seen these people put some cash in it, and then cycling money and doing very bad things with that account in someone else's name.
So uh I think that mule accounts is something that probably people need to look at more. Um, the phishing text is I mean, this is just a difficult to solve. I don't exactly know because you can it's like right? It's like how many times have you received the toll text, And that's just the toll text if you like or the Coinbase or the Robin Hood text or whatever.
I don't even have a Coinbase account, you know what I And you know, it's like, but you can imagine if you did how frightening that would be. And I know that that individuals who do have this, oh shit, my Coinbase, I got a like a new account login And it's like, yeah, that's from like a plus uh whatever, plus 4.4, like 19 digit phone number. Like that's not that's not legit.
You don't have to worry about it. But I think that's a hard problem to solve. I don't know what exactly what the pass fail or manual review. I would say that that's maybe pass.
We don't have to do very much on it. Is that the right response? Yeah, okay. And it's a it's a made-up game that we're we're trying to rock with.
So we appreciate you even attempting the categories. Okay, good. I never got the rules before this, but I I already won the Uh and the last one was what? The uh account recovery.
Account recovery. Because you bring you brought up earlier that people say, know, why can't I just change my phone number? And the reason is that's it, that's a pretty sneaky way to an account. And like that's how people take over your account too, Where it's like if you somehow have some sort of your second factor is often your phone number.
And so if they can somehow change the phone number, have access to the underlying account. And so changing the phone becomes a really powerful thing, and especially as you know, a lot of different companies use this uh phone number as an identifier and things like that, it a really powerful thing to control. So like phone changes, email changes uh are things that I have always been a problem, and I think different have gotten better at it. I think that no one's perfect, but yeah, the the phone changes and things like that are things that people need to uh keep an eye on, for sure.
Now we as we get to the end here, we've spoken about a lot difficult things of working industry. What gets you excited about it? Why why do you still really enjoy doing it? I think it is the most interesting career I could have into in the sense that it is such a you know cat and mouse with the fraudsters that I find to be extremely exciting.
And it's uh trying to unpack how a fraudster is uh taking of your system, what are the gaps? It's very fun because it's hard to see it before it because the the level of sophistication some of these fraud schemes have are it's multiple levels where it's not just very simple failure that like you failed to recognize. It's like they compromised this at the carrier They did like some sort of uh you know um uh scam on on else, and they did some uh you know social engineering on and then they got access to this account, and then they a Mule account, and he was like untangling the web is fun.
And I find that you know, kind of trying to keep up with all the new techniques is is something that I find to be fun. Um and it's been a it's been a great uh learning experience for me too, where it's uh a mix of it's technical enough where I am learning something new every day. I learned a lot about devices and IPs and how the phone how the telcos operate, how all these different things work, but it's also I'm also not writing code all day. So it's kind of a nice blend between the two where it's uh have to you have to learn a lot of technical things, but you also don't have to have a computer science degree.
What about you? Yeah, I might flip the I'm gonna flip the script. What do you like about Frud? I think a couple the thing that I start with is that I it very unacceptable for us to let it exist.
But I'm I'm irked by the concept that to me conceptually this should be solvable. And I may be wrong, but a big part of why we like why I wanted to start the company is I just thought that it was very unfair and silly that we weren't able to identify people and that it really impacted people in this negative way. I think I was though equal parts excited by the upside of we actually had a more trusting society where instead of afraid of data, we were excited by what it could do, what we could then leverage and what we could give people access to.
So that's what that that's what I found really and I think it's what I still am very passionate about, is as you said, the digital financial experience, which most digital experiences, would be better for everybody if we could actually solve this in a scalable way. So I uh and then I I to your point, I think there are a lot of interesting geopolitics that don't even get it comes to fraud, just as fraud syndicates have become so more sophisticated, and the amount of money that they're away from countries, something I always find fascinating the golden triangle in Southeast Asia and how they were so much money from China through pig butchering that it's that she started funding juntas to go after them and then redirected their attention to the US.
And this was in 2022, 2023, and there's been a huge spike pig pig butchering in the US since. So to me, it's this really interesting space too, where if you work in DevTools, totally cool. My guess is that the Civil War in Myanmar won't impact business. And I'm a huge history nerd, so I just think that's really I I I find that interesting because I would say that all the sophisticated fraud rings, the most sophisticated rings, I am I'm not positive, but are state funded uh sponsored.
And I I because I can trace it back to certain adversarial uh or adversarial regions, we'll say. Uh and so you can see that, and you can see it's been something that I've seen in my career too, where it used to be like two dudes trying to make some money, and now like these people have are professionals, they're they have a lot of people, blah, blah, blah, like all things. So I agree. It is it is crazy.
And and to your point around how is this tolerated? I find it bewildering to me that we will have a manhunt the block for a guy who steals $200 out of a cashier, but who steals $50,000, $100,000, $200,000 from I get it, bank, but uh as someone who's lending, and you can't get from a law enforcement agency to even pick up the phone or about it. And I've had cases where I have the person who's committing the fraud, the identities that he stole, all these things dead to rights, everything locked and loaded, sent it to uh, you know, never got a response, never they said thanks, never heard back, they didn't care.
And it just it seems it's very frustrating to me that that is where we're at, where it should be something that people care about, where this is where this is where crime is. The crime is not guys stealing TVs anymore, it's guys money from banks, fintechs, and and these different e-commerce, fraud, all this stuff. That's where the crime is, right? It's not like guys robbing banks anymore, although I'm that still happens.
But no, I love the fashion. We completely agree. Uh, and it's a good way to end that if you're a company and you want to make sure that people know that you care about you can sponsor the Risk and Reason podcast because there's no better way to show that you care than by getting that read. Ryan, thank you so much.
This was a ton of fun. This was super interesting. I learned a ton. And uh I look forward to seeing you soon.
Absolutely. Thanks for the time, Eli. It was great. Thank you.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.