November 13, 2018
ThreatMetrix Digital Identity Intelligence Helps International Transfer Service OFX Accurately Differentiate Between a Legitimate User and a Bot Before a Transaction is Processed
OFX launched in 1998 in Sydney and is now a global business, having handled over $100 billion in foreign exchange transfers to date. The business has evolved to deliver fast and easy secure international payments for both individuals and businesses. With its unique service model and proprietary banking relationships worldwide, OFX offers competitive rates for international payments. The business employs around 300 people worldwide, with offices in Sydney, London, Hong Kong, San Francisco, Toronto and Auckland. OFX has been listed on the Australian Securities Exchange (ASX) since 2013. For more information, visit www.ofx.com.
With ThreatMetrix, OFX can:
- Better profile the behavior of good customers in order to identify and block anomalous bot activity
- Reduce instances of fraudulent money transfers from international criminal networks
- Ensure that good customers enjoy a more streamlined online experience with less friction
We work extremely collaboratively with the ThreatMetrix team in order to constantly improve the performance of our policies.
—Jason Nader, OFX
An Escalating Threat Landscape
The international transfer of funds is an essential requirement of global organized crime. Fraud syndicates with links to Europe, North America, Asia and Australia have elaborate and complex fraud schemes that rely on sending funds across international borders. Such schemes start with a fraudulent money transfer account creation, or a takeover of a good customer account. The “currency” that fuels this fraud is breached identity data that fraudsters purchase en masse from the dark web and validate via identity testing bot attacks.
The Power of Digital Identity Intelligence to Detect High-Risk Events in Real Time
As a global brand, OFX responds to fraud threats across six different countries and time zones – there is a local and a global aspect to their approach. The team are conscious of the responsibility that accompanies working in the international transfer space; the organization is tasked with keeping customer’s money and data safe, and also concerned to protect its own corporate assets. OFX harnessed intelligence from the ThreatMetrix Digital Identity Network to help better identify high-risk patterns of behavior before a transaction was processed. The ThreatMetrix Digital Identity Network crowdsources intelligence from millions of daily consumer interactions including logins, payments, and new account applications across thousands of global businesses.
Using this information, ThreatMetrix creates a unique digital identity for each user by analyzing the myriad connections between devices, locations, and anonymized personal information. Behavior that deviates from this trusted digital identity can be accurately identified in real time, alerting OFX to high-risk activity such as multiple account creation attempts coming from the same device / location in quick succession.
Key Features of the ThreatMetrix / OFX Partnership
- ThreatMetrix Smart ID identifies returning users that wipe cookies, use private browsing, and change other parameters to bypass traditional device fingerprinting tools. SmartID improves returning user detection and reduces false positives. Derived from the analysis of many browsers, plug-in, and TCP/IP connection attributes, SmartID generates a confidence score that detects multiple fraudulent account registrations from the same device.
- Deep connection analysis technologies give OFX a clearer view of suspicious events. Fraudsters attempting to open a new account from an unusual or high-risk location may attempt to hide behind location and identity cloaking services such as hidden proxies, VPNs and the TOR browser. With Proxy piercing technology, ThreatMetrix examines TCP / IP packet header information to expose both the Proxy IP address and True IP address.
- ThreatMetrix ID helps businesses go beyond simple device identification by connecting the dots between the myriad pieces of information a user creates as they transact online and looking at the relationships between these pieces of information at a global level and across channels/touchpoints. ThreatMetrix ID comprises a unique digital identifier, a confidence score and a visualization graph for each connecting user, which together act as a benchmark for the trustworthiness of current and future transactions.
ThreatMetrix helps us minimize friction for our good user base; passively authenticating trusted users while blocking fraudsters from the outset.
—Jason Nader, OFX