Visa aims to halve its global fraud rate by 2025

It's been preventing US$25b in fraud annually with the help of artificial intelligence

Published Wed, Jun 19, 2019 · 09:50 PM

Shanghai

PAYMENTS giant Visa plans to halve its global fraud rate by 2025, having been using artificial intelligence to prevent an estimated US$25 billion in fraud annually.

Speaking at the Visa Asia-Pacific Security Summit 2019 held in Shanghai, Visa's group executive for Asia-Pacific Chris Clark announced on Wednesday plans by the payments firm to bring down its fraud rate further.

Visa this week said its fraud-prevention tools have helped to bring its global fraud rate currently to a historic low of less than 0.1 per cent.

Transactions on Visa cards go through machine-learning models to identify risks of fraud in about one millisecond, with account holders also tagged with a risk scoring that is passed on to the account holder's financial institution.

The efforts come as the estimated economic loss across Asia-Pacific due to cybersecurity breaches in 2017 stood at US$1.75 trillion, which is nearly equivalent to the total payment volumes processed by Visa in the region, said Mr Clark.

And to be clear, while overall fraud rates have been brought down, e-commerce fraud rates alone are on the rise as cybercriminals take their fraud attempts from offline to online. E-commerce transactions are also expected to surge in the years ahead with the proliferation of smartphones.

Joe Cunningham, head of risk for Asia-Pacific at Visa, told reporters that the percentage of merchant fraud attacks globally that come from e-commerce jumped to 76 per cent in 2017, a surge from just 27 per cent in 2015.

Amid this, Visa has launched three-year security roadmaps in regional countries - including in Singapore - to tackle fraud risks further.

Part of fulfilling that security roadmap will come from ensuring that a large number of merchants in each country use tokenisation technology to shield customers' credentials from cybercriminals.

The tokenisation service replaces the card number with a unique digital number, or the token, such that merchants see only this token, not customers' credit card numbers.

These tokens are effectively useless in the hands of criminals, as they are also tied to specific merchants' use.

The first large-scale use of tokenisation was rolled out with the proliferation of mobile payment services such as Apple Pay and Samsung Pay, which are used for contactless payments made on smartphones.

Now, Visa is working with large merchants and e-commerce platforms to tokenise customers' card details filed away by merchants.

Asia has experienced its share of aggressive e-commerce fraud. In 2018, a significant number of card details of Singapore, Taiwanese and Hong Kong customers were stolen by cybercriminals following a data breach at online travel agent Klook.

The Business Times (BT) understands that Visa later flagged suspicions of fraud with data analytics when the hackers tried - but failed - to use the stolen credentials to book flights on Japan's low-cost airlines Peach Aviation and Vanilla Air.

"More data is a problem. But data is also the answer to that problem," said Mr Cunningham.

Asked why tokenisation has yet to be adopted by more e-commerce platforms, he said the adoption of new technology comes around to "getting around to priorities".

In a recent interview with BT, Visa CEO Alfred Kelly Jr made a similar point, saying that there may be complacency from businesses focused on growing their core business. He had further said that tokenisation on its own is not a revenue stream for Visa.