F5 threat researchers say attackers have found a new way to defraud organizations using digital transactions. They call it “collusion fraud,” and say that it cost one well-known food and beverage platform $1.5 million over a three-month period.
As all types of businesses move to digitize their services and processes, F5 Labs and Shape Security, which F5 acquired in 2019, watched fraud evolve from things like credential stuffing to more innovative ways of gaming the system. And that’s when threat researchers noticed two new scenarios in which cybercriminals used digital transactions to defraud businesses, said Shahnawaz Backer, F5 Labs principal security advisor.
They call it “collusion fraud” because it involves two or more parties working together to defraud a third using a single transaction that cuts across different organizations.
How Collusion Fraud WorksThe first scenario involved a food and beverage company. Its platform provides a way for customers to order and pay for food from various restaurants, and then also leave a tip for a driver not associated with the restaurant. Backer won’t name the customer, but it sounds akin to DoorDash or Uber Eats.
“So in this first case we saw a consumer — he’s not a good consumer — using a stolen credit card,” Backer explained. “He puts up an order of a massive amount in the $300-to-$500 range, and then leaves a very generous tip, around 30%, because it’s a stolen credit card.”
In this case, the consumer using the stolen credit card is colluding with the driver to defraud the platform. The driver received the generous tip upfront, maybe he splits it with the fake consumer, and then when the owner of the stole credit card notices the massive food charge on his card, he calls his bank.
The bank refunds the money and hits the food and beverage company with a chargeback. “That means it has to pay back the amount of money that was paid for the goods, plus any extra things like the services or the tip that was included,” Backer said. “They lose all the money.”
Over a period of three months, the threat researchers found about 3,000 of these collusion fraud orders with a cumulative value of $1.5 million and tips amounting to about $350,000.
The second case involved an online payment wallet that isn’t an F5 customer. In this scenario, the consumer colluded with a merchant to defraud the payment wallet platform.
It works like this: First, the consumer makes a large purchase from a merchant using the platform. The consumer then earns rewards points and uses those to purchase goods from a second merchant. After the consumer receives the cash back reward, then the first merchant refunds the original amount citing product unavailability.
This means the payment wallet refunds the original amount spent but it’s out the cash-back rewards.
F5 Recommendations to Detect CollusionCollusion fraud can happen to companies in any industry. Both of these cases highlight the importance of using a machine-learning based analytics engine that collects signals from the consumer side as well as the transaction, Backer said. “You should have machine learning models that can look into the data and analyze it for any malicious or abnormal behavior,” he said.
Plus, these fake accounts using stolen credit cards are likely created by bots, Backer added. “So the capability to identify bots or even human labor is very important in the fight against fraud.”
Comments