Podcast episodes

Episode 43: Fraud prevention strategies for real-time, open banking and digital

This episode is an important conversation around financial crime prevention in a rapidly evolving landscape. Experts explore the paradigm shift toward unified decisioning, emphasizing advanced fraud controls and the deployment of actionable risk intelligence. 

Panelists examine the role of industry collaboration and trust in combating fraud effectively, particularly at the point of account opening. The discussion also addresses future-facing topics and emerging risks, including the security and regulatory implications of stablecoin transactions and the challenges and opportunities presented by open banking.

Guests:

  • Elizabeth Tripp, Director, Fraud Management, CIBC
  • Aaron McAllister, VP Fraud Threat Management, Scotiabank
  • Geoff Morton, VP Fraud Management, Royal Bank of Canada

Moderator:

  • Jas Anand, Value Engineering & Sales Enablement Lead, Feedzai (at the time of recording)

Share icon
 

ABOUT THE PAYPOD

The PayPod is Payments Canada’s multi-episode podcast which explores the trends and topics influencing payments in Canada and around the world. Hear Elizabeth Dempsey, Manager, Event Strategy and Engagement at Payments Canada and host of The PayPod, interview leading experts and respected thought leaders about the changing payment landscape, the needs of Canadians and the future of modern payments.

WHERE TO LISTEN

 

Spotify logo
Apple podcast logo

 

 

 

 

 

Transcript of the recording

Elizabeth (Liz) Dempsey:
Welcome back to The SUMMIT Summer Series, a special presentation by The PayPod, the podcast from Payments Canada that explores the trends and topics influencing payments in Canada and around the world. 

I'm your host, Liz Dempsey.

If you are just joining us, to extend the reach of our annual event, we are bringing our listeners the absolute best sessions from the deep dives and breakout stages at The 2026 SUMMIT. This summer, we’ve been releasing one new episode a week, giving you front-row access to expert-led conversations that were recorded live.

Today, you are listening to a highly in-demand session from this year’s event, entitled, 'Fraud prevention strategies for real-time, open banking and digital payments'.

As the fight against financial crime enters a hyper-speed era with the rise of deepfakes, SMS blasters and AI-driven scams, traditional defense mechanisms must evolve quickly. 

This expert panel is moderated by Jas Anand, who was a senior fraud executive at Feedzai at the time of this recording and brings together fraud leaders from three of Canada's largest financial institutions: Aaron McAllister from Scotiabank, Geoff Morton from RBC and Elizabeth Tripp from CIBC.

Let's dive right into today's featured panel.

Here’s our moderator, Jas Anand. 

Jas Anand:
Thank you. I just wanted to start with a quick intro. I'm Jas Anand and I've been in this fraud and financial crime payment space for over 25 years. I'm part of the Feedzai team based out of Toronto, Canada. I'll ask each of you guys to just do a quick intro and then we'll jump right into it. 

Aaron McAllister:
I lead a fraud threat management for Scotiabank. I've been at Scotiabank for a few years and another one of Canada's big FI's before that for seven.

Geoff Morton:
Good afternoon everyone. Geoff Morton. I lead the fraud management team at RBC, where I've spent my entire career of about sixteen years or so. 

Elizabeth Tripp:
Hi, I'm Elizabeth Tripp. I've been with CIBC for 27 years and I currently lead the fraud advisory team. We provide advisory services for commercial, business, banking, capital markets and wealth management. Rolls off the tongue real quick. 

Jas Anand:
No that's fantastic everyone. And we're going to talk to everybody and give them a chance to answer some questions in three of the themes that we've been hearing all day. Those of you who attended the conference, you know, we were talking a little bit about the fact that fraud lives in the gaps. And I think we talked about a single process where that occurs. But I think when you talk to practitioners in this space, they're constantly trying to fill the gaps. And we're going to give you a few examples of how that happens. 

Elizabeth, you mentioned multiple lines of business that you're covering in your intro there. Can you talk a little bit about what it's like trying to build that coverage across all of the different lines of business and all the different channels in which you guys operate? 

Elizabeth Tripp:
Yeah for sure. I mean, um, you know, uh, they may seem to be very different lines of business, but ultimately the fraud essentially is the same. The bones of the fraud are the same. How threat actors interact, maybe with these lines of business may vary a little bit, but ultimately the bones are the same. And so I think, you know, how we approach fraud prevention and risk management when it comes to having different lines of business is not treating them as different lines of business. The silo approach doesn't work. I think traditionally that's sort of been the structure that we've had, where you sort of, you know, manage fraud individually because the fraudsters are targeting those individual types of businesses in their own way, but that's no longer the case. And so there's definitely, you know, in a world now where we've got faster payment complexity, there's a need to be more interconnected, both internally as an organisation, but also, you know, advocating for more connectivity with industry partners as well. 

And so we need to break down those traditional barriers and being able to share information across, you know, internally and and across the industry. And the only way to do that is to do it safely. And the more you can do that, you get a better holistic view of what's happening with your client base, their payment activity, their client behaviour and then hopefully identify those emerging threats that, you know, you may not see in one part of the organization, but you see happening elsewhere. And think about how that can happen across, across your client base. And so if you're able to have that better holistic view, then you can respond to threats in a more real-time manner rather than sort of after the fact after the damage is done. So, you know, I think we can talk a little bit about actionable risk intelligence. And so that if you're able to get good insights and data really quickly, you can act on that a lot quicker. You can flag suspect transactions quicker, you can update models quicker and even start sharing that information across industry. 

And so, we know that fraudsters don't target a single product anymore. If they have a victim, they're going to try and target them in any way they can. They'll go after their bank account, they'll go after their social media accounts, they'll go after their telco. It's not, it's not just one and done. They'll exploit whatever they have to exploit. So being able to share that information across industry is I think for me, you know, I think we heard earlier about sort of the wish list of things to do. I think that one of the wish list things to do is to be able to share all of this intelligence across, because it's the same threat actor just attacking different vectors, but to the same victim, right? And so I think this is where summits like this are really beneficial because it brings all these industries together to have these conversations. 

Jas Anand:
Thank you very much, Elizabeth. So, you know, gaps exist in just the fraud departments and across products and channels and different technologies as well. But I love the idea of actionable risk intelligence, you know, kind of bridging those gaps, not necessarily having to do everything. 

I mean, we talk about gaps across, you know, the different threat vectors, you know, cyber and AML and fraud and fin-crime convergence. It's sometimes called. Can you talk a little bit about that? And you know, what Scotiabank is doing in that arena? 

Aaron McAllister:
That's right. And before everybody was asking about AI, it was fusion centers and the convergence. And that hasn't totally gone away. But, you know, the, the, when you talk about the convergence, particularly on, on cyber signals. I think that there's a lot of fraud that occurs as a result of opportunities, unrealized opportunities and customer identity and access management. And often that's owned within the cyber security realm. So looking at, at signals across device network intelligence going beyond cyber into telco signal intelligence and really taking an orchestrated approach to the various signals to respond and ensure a better customer experience where you can faster, enabling faster transactions, faster approvals, faster onboarding, but also having the depth of signals, including from our peers in the cyber security teams, capturing those signals so that we can be more precise, more surgical when it comes to identifying the fraud, the things that need friction.

Jas Anand:
Excellent. Thank you. So Elizabeth, trying to get signals across different products and areas, but also across, you know, cyber and other threats. I mean, if we think about it from a criminal's perspective, they don't know the difference between cyber fraud and money laundering. They're first stealing the credentials, then stealing the money and then laundering it. Right? So it does make sense that we start to share information across these groups. And I like the idea of trying to get to that left of boom. 

Geoff, thinking about moving from this transaction based view to a customer centric view, especially with the new threats that are coming along. Can you talk a little bit about that and what RBC is doing to get there? 

Geoff Morton:
Sure. Yeah. So I think whether it's gaps in internal fraud systems or across different lines of business, I think one of the things that's always true is there's a customer at the centre of it. And one of the areas that we're trying to move a little bit away from is detection being very much based on an event coming in and trying to stop it, right? Because the fraud has now happened, you've just detected it. And if you miss it, well, it goes out the door. And so what we're trying to do is leverage AI and try and find ways of becoming more preventative and more predictive of what is going to happen before it actually does happen. 

And I think we're still challenged by some of the fact that data can exist in many different places. But what's also really beneficial about this approach is because everything we do today has to be real time when it comes to transaction detection, you have to get it in the moment. Otherwise, it's gone. And that will only become more true as we shift to faster payments and other forms like that. And so I'm constrained to the data that's in my real-time system to make that decision. But I can offline cobble together significantly more data elements that come from cyber or AML databases, or from wealth platforms or wherever it happens to be, to really put together a good view of who that client is and what their particular behaviours look like. 

And then I can build a model to assess what is the risk that that client will become a victim of a fraud or a scam, or that they actually themselves may be the bad actor? Because if I can make that determination that they're likely to become a victim of fraud, I don't have to wait for it to happen. I can actually take action ahead of that. So if you think about a scam, maybe I can reach out proactively and educate them differently or give them different warning signs or in flow before they transact next time, pop up contextual messaging. If I think that maybe they are the fraudster, maybe I can take capabilities away or I can restrict their limits. There's different actions you can take that are not always just going to stop a transaction and decline it. Call the client, say, was this you? Yes or no? So I think getting to that client level helps us bridge a lot of the gaps that we've already talked about today, but also gets us into that more preventative state to left of boom, as you like to say. And so I think that's ultimately the goal. We're actively building it now. I don't have any stats to share around how great it works or anything like that yet. Maybe next year. But that's the goal right now is just to try and shift left now. 

Jas Anand:
Fantastic. So we've heard a little bit about some of the challenges and gaps that they have within their own teams. We've talked a little bit about some of the challenges and gaps and kind of bringing financial crime teams together and then also looking at the whole life cycle view, like how do we understand these customers and life cycle from the beginning to the end? And,you know, these are just three things that we've come up with really quickly. I'm sure if I, if I talk to you guys, there's probably a list of twenty others that you're working on. Thinking about this, this idea of shared intelligence. I know there's work going on with the Anti-Scam Coalition to kind of put together a classification model and some shared intelligence. Can you, can you provide any information on that or your involvement in those? 

Aaron McAllister:
Working with the Canadian Anti-scam coalition on various initiatives, you know, there's customer awareness. You mentioned taxonomy around scams and fraud. And that's important. I mean, it's important for a number of reasons. One is we've got a new mandate coming forward through the federal budget 2025 to do reporting to the Financial Consumer Agency of Canada around fraud. So making sure that we're talking apples to apples when we're looking at it, but also, um, getting the taxonomy right is important as we look at the models right. It's a different marking if you're trying to train a model for account takeovers versus scams and even based on subtypes. So it's important that we have the right understanding within our own institutions and the right tags within our own institutions and that we, as much as possible, can share that between our organizations and platform providers as well. It helps as we're sharing and benchmarking across sectors. Right. That's a big part of what the Canadian Anti-Scam Coalition is premised on, is that it can't just be one organization. It can't just be banking. It has to include other sectors where fraud and scams often start. Right. And unsolicited call or text, digital advertising networks, social media and making sure that we're engaging with folks in those sectors to talk about how fraud is happening, what we're seeing, what we can share with them and vice versa. 

Geoff Morton:
And I can just add on to that as well. I think data sharing is absolutely the answer. And it's challenged by the fact we have to go across industries. And I think some of the recent work that's been done in that space has shown there can be a desire to do it, but what do you actually share? Right. Because I think part of the challenge is we all have different third party data providers for things like device IDs. 

I think there's value in sharing the negatives, right? Like I saw fraud at this account. You should know that fraud went there. That's great. But it's very reactive. Like we have to figure out how to share actionable intelligence as well, right? It's not just sharing the bads, but it's sharing the real-time insights. How do we go across these networks? And it's also about finding what are the pieces of data that are common across all industries. My device ID may be very proprietary to me. It means nothing to either of you, but a phone number is a phone number and an address is an address and account is an account. So how do we find those pieces of data that we can share across the industry? Because I don't think it's going to be like one size fits all. This is our data sharing box for the industries that we just plug everything in. I think it's going to be a series of different solutions based on the individual piece of data that we want to share. Because a lot of these aggregators or third parties have expertise in a particular domain. And so I think trying to put it all in one big box and just say we're sharing data with each other. We have to make sure it's intentional about what we're going to get out of it, so that we can improve our models, we can improve our detection capabilities and our prevention capabilities. 

Elizabeth Tripp:
I think, you know, just, just to add, like the Canadian Anti-Scam Coalition, a huge fan. I love the fact that this is bringing all these different industries together to have these conversations and the fact that a lot of it is about putting the client at the forefront of it, because we know that the clients are the ones who have hands on keyboard, they're picking up the phone, they're falling for these, you know, these scams and to be able to leverage that type of bench strength with all of industry and making sure that we're all unified in this mission to try and educate and bring awareness to clients about scams. I mean, we're constantly reinforcing the language of stop, check, talk and everything that we do because we want to make sure that that message is consistent. And it doesn't matter if it's CIBC, if it's RBC, if it's Scotiabank, we're all speaking the same language. So no matter where the client goes, they see the same sort of language being used. 

And so hopefully that resonates with them so that when they do, you know, almost click on that link or pick up that phone and almost start to release some information. Maybe they remember something in the messaging that whether it's coming from the Canadian Anti-Scam Coalition or it's coming from, you know, their FI that they're, that's resonating with them before they do anything. So, you know, being able to do that, I think as a, as a huge industry, I think it's so important. 

Jas Anand:
Yeah. That's fantastic. So I think what I heard is we definitely need a taxonomy. We all need to be speaking the same language. We definitely see value in negative data sharing to be able to build supervised models to stop some of these scams. But that's not enough. That's just the beginning. We want to get to a point where we can actually share intelligence, and we don't know what that looks like yet, whether it's phone numbers or transactions or locations where things are happening. But, you know, just the negative data sharing and building models doesn't feel like enough. We've got to get this actionable risk intelligence. And then lastly, that intelligence cannot be just in the banking community. We need that cross sector support. Sounds fantastic guys. And that was our first topic gaps. 

Moving on to the next topic, which we've heard quite a bit a lot about. And today it's really about what's next. And I'd like to think about it in two ways, right? From a, from a fraud perspective, what are, what are, what are the next themes going to be? And do those offer opportunities for protection as well. And we heard agentic is close, but not there yet, but definitely on the way. And this is, you know, machines and robots making purchases and decisions on behalf of humans. We talked about one of the strongest controls being verifying it's really you conducting the transaction. And some of the controls look for that type of activity when it's not you and it's a bot to try and stop it. And I guess to start with, um, what are your thoughts on agentic, Geoff? And do you see any positive benefits of having that type of data and that information from a fraud detection perspective? 

Geoff Morton:
Yeah. So I mean, I'll start off by saying I'm absolutely not an expert in agentic commerce. I have a lot to learn, as I'm sure many people in this room do. And part of the challenge is we don't actually know what it's going to look like necessarily. I think there's some early signs and we've seen some interesting announcements recently. I think as a consumer, I get really excited about it. I absolutely will be an adopter of agentic commerce. I love that concept. But thinking about it from a fraud perspective, it's scary because I think it can show up in many different ways, right? You can have the good agent that has a stolen credit card inside of it. That's one form of fraud. But you can also have the rogue agent or the bad agent that's going out and using legitimate credentials in a way that it wasn't intended to be used for. But then on the other side of it, you also have good agents who are out there potentially negotiating with many other merchant agents. What's now the other angle of this is you have the bad agent on the merchant side who's just out there undercutting everybody and doesn't actually have a product to sell you, but is just taking, taking the information in harvesting those credentials or actually processing the transaction. 

Huge impacts for sure in the disputes world. And to your point, how do you verify that intent? That's going to be a whole new paradigm for how you have to talk to a client about, did you make that purchase? Yes or no? Did you authorize it? I heard a great example at one conference I was at where it was like, did you say that you wanted size ten Nike's or you wanted ten pairs of Nike's? Right. Like there's going to be all those like misinterpretations as well. So it's really interesting from that perspective. But I think it also is a great opportunity for us to figure out how do you accept the behavior appropriately, right? Because if we and I mentioned this in a talk yesterday as well, if you just say, no, I don't want to deal with agents, you're going to get worked around and they're going to find different ways of making the purchases happen despite your best efforts. 

And so I think the best path forward is to actually create the path for the agents to go down. Because now if you give them a pathway, not only does it make it more efficient, you can identify it. But now if they're showing up outside of that path, you can deal with it differently. And I think that's the challenge today is when these bots are showing up. We sort of assume bot is bad today. And maybe that's the case for most things, but in a few months or years, that's not going to be the case. There's going to be good bots and bad bots. And how do you identify them as one thing, right? You have to actually have the data points to be able to tell you, this is an agent. This is Geoff's agent and this is Geoff's Gemini agent. 

How do you deal with that from a policy perspective on that, that model, from that user? What authentication or authorization do you have from them? And so if you can route that down a particular path, then the exceptions become easier to deal with because those are the ones that don't conform. And that allows you to have different treatment plans and say, well, if you actually are a good agent, you need to go back over here. And if you're not following that path, well, I'm sorry you don't get to do this. So I think it's a great opportunity for us to really think through it from the beginning around what are the fraud controls that we need and merchants need and all the different parts of the ecosystem need to handle it properly. 

But the answer isn't to ignore the problem. We know it's coming. We actually have a decent idea of what it might look like. So how do we have those conversations now to get ahead of the problem that we all know is coming? 

Aaron McAllister:
Maybe I can add to that too. I think that there's some key things that we're having conversations about internally there, like, um, authentication authorization and then intent validation, right? So on our business banking platforms, we've all got multiple users. The idea of a super user, you know, delegated authority, you might have dual approval. So there's the concepts around authentication authorization and who's allowed to do what or verification of intent exists there. How do we make sure that both for open banking or consumer driven banking and agentic commerce that we're, we're adopting the right controls, building in the right controls that allow legitimate users to make those decisions for retail banking. So, you know, authorizing even if it's their accountant, like take, take it out of the open banking or a genetic space, they want their accountant to have read only access, but only to one account and not all accounts. How do you set that up? And maybe they have a password and multifactor authentication. And if it's for open banking, how do you authorize that access, that third party access? Or if it's an agent, how do you make sure that you can authenticate as Geoff and say, well, I'm going to allow this agent to transact in this way within these limits. And now that agent has access within the constraints that you've defined. Those are conversations that we're having now around both open banking or consumer driven banking and and agentic commerce. 

And there are some good models out there, I would say too, like. Geoff, I'm also very much learning along the journey. Like we don't, we don't have it solved by any means or, or know what perfect looks like. But, um, you know, we're looking at other models where there's agentic commerce protocol from Google that the large payment networks are participating in. American Express has launched a guarantee with regards to agentic commerce, to your point, as long as they've gone down the designated path. So there's, there's things like that we're in discussion on as well. 

Elizabeth Tripp:
I think, I'm also new to genetics, so I'm still learning all about this, but I think a different sort of flavor to it as well is how do you leverage agentic even to be able to, uh, you know, from an operational perspective, leverage it to be able to identify sort of scenarios where, you know, agentic can, can handle certain scam types or whatnot on its own through chat and then, you know, can agentic identify a client that might be into a scam that's very deep, maybe an investment scam or a romance scam, something that requires a little more in depth, you know, conversation. And can you use agentic to sort of identify that scenario and pull that client out and maybe transition them over to somebody who can have that in-depth conversation with that person about the situation they might be in that they don't even realize that they're in. I think this morning, um, Ryan Powell talked a little bit about break the spell. And so that's what that team is designed to do. And so if you can. But we know a lot of clients, sort of the, the, the, the crumbs or the clues that a client might be involved in. Something often happens very early on in the stage that if you have something that can sort of identify those clues, can you create something that now diverts that client over to a team like the break the spell team that can have that conversation with the client, try and break the spell and basically save them from themselves. So just, just another different use case for agentic, I think. 

Jas Anand:
Excellent. Thank you guys. Part two of what's coming up next. You know, we've talked about criminals using AI for deepfakes and, you know, effectively hitting every single channel and product. You can create cheques now. You can create realistic third parties, you can copy people's voices. So now the grandparent scam comes with your kid asking for help from jail, maybe even a picture of them behind bars with some nefarious looking characters, you know. You can buy kits that allow you to have a full video ID to bypass full verification. And these things are now ubiquitous. You don't have to be a, you know, a mastermind criminal to try and pull these things off. There's TikTok videos and others explaining to you step by step how to do this. There's fraud as a service available to people that can kind of start to commit these types of acts. You know, this sounds like it's, you know, it's doom and gloom and it's really bad. But you guys are living this today, what are you experiencing in terms of deepfakes? What really concerns you and what are you doing to try and address some of that? Maybe I'll start with Elizabeth. 

Elizabeth Tripp:
Yeah. So, that's the thing that keeps me up at night is AI and deepfakes and how fraudsters are exploiting these things. The realism of it all, the scalability, the ability of it to circumvent sort of traditional fraud monitoring is very, very real. And, in a lot of cases, it's outpacing our ability to detect when it's happening. Right. So, we're seeing the impacts of this through, you know, unsuspecting victims who are falling for, you know, videos of celebrities, videos of politicians, selling crypto and or misinformation. And, you know, again, taking advantage of sort of the, the climate and this, you know, sense of urgency, panic. These are all things that the deepfakes and the AI are designed to do. And so as you mentioned, it is becoming more widely available. I can't remember where I heard this, but, you know, fraudsters are even offering these kits at a discount, like it's Black Friday or something like, hey, fifty percent off. Here's a fraud kit if you want to purchase it. And it's easy to use, like you said, you don't have to be, a sophisticated user. Anybody can do it. The videos are there. The, you know, the walkthroughs are there and, you know, and they're creating very, very convincing, phishing campaigns, malicious sites that people are clicking on and inadvertently providing their credentials to log in with. 

The days of being able to identify, you know, phishing email with bad spelling and grammar are gone. It's AI versus AI now. And so you sort of have to be able to leverage the technology to our advantage to be able to detect when it's happening. Because it's definitely driving a lot of interesting behavior from clients. And the ability to detect these types of threats requires ongoing investment and threat detection and lots of employee training as well. You know, a lot of it can be gleaned through conversations and, um, that employees are having with clients as to whether they've fallen for something. So employee training, education, awareness and technology are definitely the things that we need to do in order to try and stay ahead of it. 

Geoff Morton:
And I think the sophistication of the tools that they're using is mind blowing. I know I see several people in this room who are at another conference recently where one of the presentations that we saw that was about deepfakes was showing a tool where from just a picture of a woman, within two minutes, they not only had, I think it was an Australian passport that was looked perfectly legitimate. They also generated the video of them turning their head this way and that way to pass the selfie check and then showed how for a particular crypto platform, they were then able to use that image in those videos to actually onboard through all the IDV checks. 

And that will only continue to get better. And so I think part of the challenge we have is we all try to detect it as we're always going to be a step behind. We have to continue to do it. We have to keep up. We have to not allow the low hanging fruit to continue to pass. But I think we have to recognize as well that we will never get ahead of them because we simply can't. They have bigger budgets. They have less regulation. They will always have more tools and technology than we can. So for us, I think what's really important is coming back to what are the things that always have to be true? You have so maybe you can pass the onboarding, but I don't have to give you access to everything, right? I can figure out what is my strategy to deal with new accounts. How do I limit the amount of money you have if I'm not 100 per cent certain that you are who you say you are, then maybe that's where the client experience has to be impacted a little bit until you can actually prove and validate your identity in another way.

I mean, if only there was a government organization out there that could actually validate these identities for us and say, yes, that's a legitimate driver's license. But since that's too hard, we have to figure out how to augment that ourselves. And I think that's the recognition that we have to sort of not accept that we're defeated in some cases, but know that we will always be a little bit behind. So then what's that additional layer? How do we limit the impact? How do you identify it once it's in? That's the other piece of it, which is we often see them work as networks, as rings, right? So whether that's the same device that's opened many different accounts or that same name. And this is the data sharing aspect we all talk about recently opened accounts at many different banks. How do we do that network analysis in the graph analytics to find those rings and shut them down. So there's a lot of things we can do beyond the actual decision at account open to limit the damage or proactively identify more accounts. But it's a very challenging space right now. 

Aaron McAllister:
I find it interesting, like there's convergence in the vendor space that provides services to us. In some cases, there might have been a vendor that just did device intelligence and that was it. And you know, then there's, they're doing behavioral biometrics and they're just doing the same thing. There's convergence in the crimeware as a service space. And so that's, you know, I found that fascinating. It's interesting to watch how innovative and adaptive the criminals are that work in this space. So, you know, in 2024, there was a phishing as a service platform lab host that got disrupted by international law enforcement effort. Immediately after thirty days, there was a replacement Shiba dot io that was launched. You know, since they've launched, they've incorporated AI templates. You can use a prompt to generate a phishing site. But more recently, there's been convergence there to where they're saying, you know, instead of just using our platform for phishing site and using another telegram OTP bot to capture OTP for multifactor, we offer you a service for that as well. So you can, you know, you can combine this together. You've got your one stop shop to be able to have the phishing site. But in case, you know, you need to capture OTP from your, from your victim, you can use our service for that too. And so I see a future where there's further convergence there where, you know, now you need synthetic speech as part of executing this, this broader social engineering effort that from the outside seems complex and it is complex, but the barriers to entry are just getting lower and lower for highly sophisticated cyber fraud. 

Jas Anand:
Yeah. And what I find really interesting is that they share data really well, right? You know, they will have every password you've had from every breach, you know, every piece of information they got that was compromised and left out there. And, you know, those are included in these kits and packages that are, you know, buy once and consume everything from us. So I never thought of it as convergence by fraud criminals. But I see what you mean now for sure. 

So we've talked about deep fakes and the natural progression is they're going to use deepfakes to attack financial institutions. Eventually we're going to get smart enough and we're going to kind of stop that. But that's just going to mean that they're going to use those same same techniques against humans, right? They're going to go after our customers. That's a larger topic of scams, right? Authorized payments. And so, you know, when they turn these capabilities like deepfakes against our consumers. And it doesn't even have to be deepfakes. I've actually heard examples of people going directly to victims houses and saying they're from the bank, and when the bank calls, they don't listen to them. I'm really from the bank and they have a t- shirt with a bank logo on it. The landscape of individuals getting compromised doesn't have to be deepfakes. It doesn't have to be a, it could be a simple phone call. It could be an email. 

But as we start to think about now, our victims bypassing our controls and authentication capabilities, even if they were strong, you know, how do you see us kind of defending against that and protecting victims from scams in Canada? I'll start with Aaron. 

Aaron McAllister:
Yeah, there's, you know, we have to make sure that we're adapting quickly to the threats that are out there. Um, you know, I think number one, we're trying to put in technology controls wherever we can to help inform consumers so that they can make the right decision. If they're empowered with more information, they'll make better choices. Like one example, just based on the type of scam you listed where someone claims to be from the bank. We've seen scams where as part of bank impersonator scams criminals are abusing the ability to book an appointment online. They'll claim, as you said, to be from the bank. You know, we're going to send someone to your house to pick up your bank card. Enter your PIN number here. And they add authenticity or a sense of authenticity or credibility to that by saying, you know, if you check your email based on the email address you just gave me or one that I collected from, from the internet, you'll see that I've just booked you an appointment to come into your local branch to pick up a new card and you get an email that comes from the bank that you then believe, okay, you know, this looks legit. 

So we've had to adapt and now there's a message on, on any email, if you book an appointment with Scotiabank that says the bank will never send someone to your home to pick up your card. You know, here's how this appointment was booked. Here's red flags to look out for. And so there's a combination of making sure that we've got technical controls in place that we can communicate to our customers what to expect and what not to expect from us. And then responding promptly when we see signals of abuse for sure. 

Geoff Morton:
Yeah. I think education still plays a very key part in scam prevention. I mean, stop, check, talk. It's a great, great education campaign. Great tagline. And we should all be shouting that from the rooftops. But in the moment that matters the most when they're actually like being scammed and transacting. Like it's the timely education that we really need to figure out. So part of that is the ability to actually detect that something is going on. So whether that's new signals or using the signals you already have in a different way. But it's not as simple anymore to just detect a suspicious transaction, call a client and say, was this you? Yes or no? Because the answer is yes. And it's you have a break of the spell team. And that's amazing that you have a team of dedicated people who have those conversations. But again, we've waited for the fraud to happen, right? You're now resolving an incident that has already happened to my first point about trying to predict what's going to happen. 

And so what we're also trying to do is give more context in the moment that matters the most if you're about to send that transaction. And I know enough that maybe that's out of pattern for you, but maybe I'm seeing where it's going. And that gives me an indication. Maybe it's like, I can tell maybe you're, you're falling for a crypto investment scam. Well, if I can give you specific education to crypto investment scams in that moment and help identify the red flags, that probably has a better chance than saying the generic like, don't click on links, we will not ask you for one time passcodes, etc. 

That's all great information and everybody needs to know that, but it's easy to forget it when you're under stress. The concern, I think you mentioned a couple of these in-person scams as well. I've seen that as well recently, where some of these impersonation scams are now bringing in an in-person element, which is really scary as well, because that's even more convincing for a client. And also there's a little bit more of that threatening side to it, which is very scary. So I think that's another element that we have to try and factor into these conversations as well. But it's also, again, scams are beyond just a bank's responsibility to be educating clients about. So when these interactions are happening through phone, email, text, social media, the list goes on and on. Everybody has a role to play to figure out how do we better educate clients about what they should be aware of, proactively put context in front of them and ultimately try and avoid it from happening in the first place? 

Elizabeth Tripp:
Yeah, I agree. And, we've been doing a lot more of that sort of in the moment messaging. So when it comes to certain transactions or you're adding a new payee, you know, the message comes up that says, you know, have you checked this, done this, confirm this, like all these, these pieces just to hopefully try and prompt somebody before they hit that submit button that they've done all these, you know, checks and balances before adding that payee and sending, you know, an e-Transfer. 

One of the interesting cases that did come through our break, the spell team was a client who, when the, the team was able to finally break the spell with this client, the client shared with us a, an email that they had received from the threat actor, basically outlining word for word, what your, what your bank is going to ask you when you go to the bank to do this transaction, they're going to ask you what it's for. And then you're going to say this, and then they're going to ask you this and you're going to say this. And you know, the bank is just doing this because they don't want you to take your money out. They want you to keep your money. But I have this really great investment. And so, you know, don't let the bank convince you that, you know, to, to not do this transaction. So they like, they shared word for word, exactly what to tell the victim to say to us when we would prompt them with these questions to try and figure out, you know, are they part of a scam or not? So they know and they're bold enough to send it in an email, you know, or they're bold enough to show up to somebody's house. Like they're very, very bold. The, you know, they're not doing — it used to be very anonymous. You know, they wouldn't want to show themselves or risk being caught on camera or anything like that. But they're getting bold. They're sending emails, they're outlining the exact thing that they want people to say and do and showing up to houses, picking up cards. It's pretty, it's interesting. It's very, very interesting. 

Geoff Morton:
And I think just maybe one other thought as well, because I know we have a lot of non-fraud people in the room. Like we talk a lot about frictionless payments and how to make things really, really simple and quick and easy, right? If you just have a click to buy button and there's no steps in between, a lot of what we just talked about isn't possible now, right? You have less opportunity to actually intervene in a payment. You have less opportunity to gather the signals required to know that behavior is out of pattern. A lot of what we rely on today are behavioral signals around how you're interacting with the device and all that. And if all you're ever doing is clicking one button and we make it too easy, this becomes easier as well. So I think that's when you're having conversations with your fraud partners. Like this is where we're coming from. Is that like we need the opportunity to actually intervene. And I know it's at the, at the end of the day, like these are huge problems, but the scale compared to legitimate volumes is still very tiny, fortunately. So it's that balance that we always talk about between client experience, operating cost and fraud loss. But like this, this is a critical piece of the scam conversation: you need that runway to actually have the ability to slow things down a little bit, because you can't stop Jack and talk if you're not allowed to stop. 

Elizabeth Tripp:
Right. Yeah. For sure. 

Jas Anand:
No. That's fantastic. So look, we've heard about the fact that the barrier is lowering, but the sophistication of some of the criminals is still there. The boldness is still there. They can still get out there and do these things, you know, with things like even business email compromises, we put in procedures like please verify from an outbound phone call. But the criminals know that. And they have an inbound phone call looking like it came from the CFO. And I don't think people know there's a difference between outbound and inbound. You can easily impersonate one from the other. So I think they play on the procedures that we have and try and you know, the phone call comes in and asks for our procedures. This is the CEO calling you to say, please move the money, you know, so I think they'll always take advantage of it. 

But we're also seeing this kind of mass use of I mean, in the paper recently, there were the SMS blasters that were driving around. Maybe I'll start with, could you guys tell us what SMS blasters are? And then what did you think about that? That was the first time I've seen something like that used in Toronto. And so, you know, I just want to get your perspectives on that before I jump into the next topic. And we'll go with Geoff. 

Geoff Morton:
I was going to let Aaron explain this one. Aaron told me about it. 

Aaron McAllister:
Yeah. Hey, hopefully that's a good example of intelligence sharing in the office. 

Jas Anand:
I was like intelligence deflection or whatever. 

Aaron McAllister:
But truly, if we see if we see items like this happening and somebody else mentioned earlier today that, you know, as was mentioned in the media, that this started in late November. But even and we'll describe what it is for those that maybe didn't hear in an earlier session, but is sharing with other FIS and sharing with telcos that, hey, we're seeing this, this is new. Here's what we've looked at so far. You might also want to look at this. It provides an opportunity, you know, if we're doing that to, to be more on top of things. There's more of a willingness that I'm seeing in the industry, including now across sectors, to share that type of information. And sharing in not real time is not the objective. That's not the target state. We need more real time, including data about legitimate accounts that are good. So we know the difference between good and bad. 

But in this case anyway, SMS blaster it's a device that mimics a cell tower. And so this has been used for fraud in the UK and elsewhere in the world, including in Europe previously, but it hadn't been seen in Canada before. And so in this case, the Toronto Police confirmed publicly that this was in a vehicle driving around. And this device mimics a cell tower takes advantage of older, cell phone technology, including 2G networks that don't have the same verification between the device, the network, the tower and would send out a message that appeared to be coming from whatever number they wanted, this number, this message to appear to be coming from, including impersonating banks, saying, you know, click on this link or whatever they wanted the message to contain. And it was specific to, to an area, it was localized to wherever the vehicle was driving around. Um, and that can prompt customers to go to phishing sites. 

Kevin mentioned earlier today that there was a very quick law enforcement response to that. Four months from the time that law enforcement first engaged to arrests being made is actually quite good. And there was lots that happened prior to that to disrupt the activity. Lots of work between financial institutions, telecom and more than one law enforcement or government institution to make that happen. And I totally agree with Kevin's earlier comments. That's an example of success. And we need to continue building on that. It's also an example where what was once sort of relegated to the world of espionage like that technology has been used. It's been documented to be used in state sponsored espionage cases, is now being used for financially motivated crime. And that won't be the only time we see more sophisticated tools being used by cyber criminals. 

Jas Anand:
Yeah. Wow. So we've got examples of extremely bold criminals knocking on doors, people using archaic technology and old telco infrastructure to attack that, you know, other gaps. And we've seen, you know, fraud sharing as a service. They seem to be ahead of us in that space. So, you know, I think the threats are real. And the next part of the topic was really about the ecosystem in Canada. You know, I think I heard some analogies around we're expanding the tent, we're adding more poles to the tent, we're adding new tents,you know, we're seeing this ecosystem expand and explore while we're challenged with these threats, and I'll hit on a couple of a couple of different things there. 

First, open banking is great. More data, more access, you know, greater opportunities for Canadians to be able to access greater services at a faster rate. And what are the implications of open banking to fraud? And Aaron, we'll stick with you? 

Aaron McAllister:
Yeah, there's significant implications, of course, like it's like anything else, you know, it's got a lot of advantages and there can be disadvantages too. And so, you know, I think Geoff talked about earlier that some of the controls, that you might otherwise have, are harder to apply if it is a good bot, right? That's, that's authenticating or a good agent that's authenticating. And so we have to make sure that we're providing the easy path to our customers to be able to use the services and the capabilities that they want to use. So that we can better differentiate between good and bad. I totally agree with your comments. And I think that, you know, this isn't new. You know, today there's legislation that's come forward to address consumer driven banking, open banking. But for years our financial institutions have seen like logins from Intuit, you know, Flinx you name it. Authenticating using customer credentials that customers have shared. Because they want a capability or a service and they're seeing that gap filled. So how do we make sure that we provide a path for them to do that in a more secure manner so that when we see malicious use, we can better identify that, as Geoff said, we can force them down the happy path. That's going to continue. You know, there's lots of good work that's happening in that space to ensure that we move away from screen scraping and credential sharing to something that's more API driven and secure. So that's all good news. 

Jas Anand:
Fantastic. Geoff? 

Geoff Morton:
Yeah, I don’t think I have too much more to add on top of that. I think what's interesting is we continue to add and add and add with complexity. And it was mentioned, one of the main stage talks today about how we've never really shut anything off. We're great at adding incrementally new payment capabilities. We've talked a lot about stablecoins and open banking and so really what we've done is just create a more complex environment for ourselves. And these topics also get much more sophisticated, right? Like we talked about agentic commerce and how none of us truly understand what that means yet. And we work in this space. Stablecoins. We were joking around this morning at breakfast around like, how would you explain that to a child to really, truly understand what it is? And so if we are in this space and we don't fully understand what it means, the technology itself may be great, but it's another opportunity for fraudsters to take advantage of people who don't understand. Right? If we’re thinking about open banking, right, when it launches, there'll be lots of great news articles and customers are going to be more aware of it. It's just another opportunity for fraudsters to spin it. Be like, hey, click on this link, sign up for open banking, enter your credentials once. You'll never have to do it again. Or when stablecoins come out, same thing. Here's an amazing way to save your money or invest your money. They'll find every opportunity. So I think as confident as we are in the technology itself, we just have to be aware of the impact surrounding it, especially as it relates to scams and what our clients are going to go through, because they're not going to understand it as well as we do. And it just creates a broader surface area for fraudsters to attack. 

Aaron McAllister:
Can we turn off cheques? 

Elizabeth Tripp:
Yes, please. 

Geoff Morton:
We're not allowed to. 

Elizabeth Tripp:
I vote for that. Can you turn off cheques? 

Geoff Morton:
No, that's a great example too, right? It's something like. I think generally people understand what a cheques is. But we've reached a point now where I don't think the younger generation understands what cheques are. And so we're seeing new scams around cheques. Like a friend of mine shared a story where his daughter was sent an image of a cheques through a school group app. And it was a scam at the end of the day. But they were like, oh, but it was just an image of some money that I put into my account. So even something as old as cheques is being recycled into new scams because it takes advantage of knowledge gaps. 

Elizabeth Tripp:
Yeah. I don't think my daughter has ever seen a cheques other than maybe I've written one for her and she'll look at it like, what the heck is this? What do I do with this? 

You know, I think the only thing I'd add as well is just, you know, I think that's where it becomes important that we take advantage of partnerships, um, you know, globally reaching out to those areas of the world that have already been on this journey that are already in the open banking space, they're already seeing what's happening from a fraud perspective. And then taking those lessons learned that they've gone through and saying, okay, so are we now going to see that here? How do we prepare for whatever those scams that end up manifesting themselves? How do we get prepared for it here? What are those fraud cues? What are those signs of, of, of signals that we need to embed within our monitoring to be able to detect that something's going wrong. 

I think maintaining those relationships, I know for us, we have regular touch points with a lot of banks in the world just to. Even if it's just a half an hour or 45 minute conversation, hey, what are you seeing? What are you seeing? And, you know, we've, we've gotten so much information just from maintaining those relationships. And definitely their experience has given us pause for thought in terms of what we need to be prepared for and what we should be looking at on our end to be able to manage through these, these, you know, even just the journey of open banking. 

Jas Anand:
No. That's fantastic. You're absolutely right. People have done this before. And I find usually people in the fraud community are happy to share like this. This could be, you know, human sharing and conversations, but it is extremely valuable to learn from what they've done. Um, so with everything that we're seeing, open banking, deepfakes, everything we've talked about, what do you think the new account journey is going to look like for customers coming in for the first time to your organization and kind of onboarding and where do you now see these controls? I mean, you talked about they are going to get through the front door sometimes, and they may even bypass some detection by staying on for a while. What does the future look like in a world where there's open data, open data sharing, and still the sophistication of the attacks from the criminals? Maybe. Geoff. 

Geoff Morton:
Sure. Yeah. I mean, we talk a lot about how fraud is not a space that we compete with each other in, but acquisition certainly is. And I think there's a lot of pressure across the industry around growth. And that's I think one of the more challenging conversations with our business partners is around that balance again, because it's great if we can onboard a lot of new accounts, but if you're just onboarding a lot of bad accounts, well, you're just causing a problem somewhere else. So the way that we're thinking about this more recently is how do we build more of this data together to make a holistic decision? 

And so it's a great example where you don't have a customer profile to base it off of, right? This is somebody showing up to your front door for the first time. So you can't look backwards and say, well, is this typical behavior for that person? And so the signals change a little bit. And there's a lot of great Third party vendors in this space as well that provide novel signals. I think this is where behavior plays a really interesting element around. Can I tell that you're copying and pasting something which is like your birthday? You should probably just know what your birthdate is. You should be entering that, right? So the long term memory and there's some interesting aspects there. Is it a bot? There's some good signals. But this is also, I think, where there's a really great opportunity to benefit from the data sharing, because what we also have seen is if somebody has had a fraud experience at one of the other banks, well, now they have to come somewhere else. They're going to show up at my front door. If I can take that piece of data and share it with the industry and say, hey, what do you know about this person or this address or this phone number or this email and learn from that network intelligence that can help me make a better decision at onboarding. 

But it's also even building better customer journeys based on the risk, right? Today, there may be a significant downside because of the drop off. To put every single person through a heavy IDV check. We know that those processes are not only cumbersome for a client to go through, but there's legitimate reasons why you maybe just can't get through it because of bad lighting or something. So it's not something that you want to put one hundred percent of your traffic through. But if you can aggregate all these different data signals together and say, okay, well, here's my risky population, I'm going to put them down that path. What it also allows you to do is make a more confident decision and actually opening an account that you are trusting and that's legitimate. And now you don't have to put them into a lower entitlement and not give them access to funds. You can actually give them the VIP package and welcome them in a different way. 

And I think that's where we've seen the shift as well with our conversations on the business side is to say, we don't just want to always say no to the bad ones. We actually want to tell you which ones we are very confident are good, and you can treat differently and accelerate and have a different business or value proposition for them. So I think that's a really critical piece or a critical event in the life cycle of a fraud, because you have a chance to stop it. But you have you have a business opportunity to accelerate the good. The challenge, though, is in, if you make a decision that's maybe somewhere in the middle, you're not quite sure. You may let it in. You may restrict the amount of access they have to funds and limits and things like that. But how do you then connect the account opening decision to what happens over the next three, six, 12, 24 months? Because we also know that a lot of these accounts sit dormant or semi dormant for quite a long time. And so being able to 12 months later come back and see maybe an odd deposit or some incoming funds that are suspect, maybe that on its own wasn't enough. But if you could look back at your onboarding decision to say, oh, and it was medium risk at onboarding those two things together, push it to high risk. I can treat it differently. The challenge, I mean, at least for us, is we tend to have a sliding window of time based on how our data aggregates and our futures aggregate. So getting to being able to connect those dots across the entire lifecycle allows you to make better decisions, not just at onboarding, but at every other transaction down the line as well. 

Jas Anand:
Excellent. Anything? Elizabeth. 

Elizabeth Tripp:
Yeah. I think, you know, like, definitely the assurance factor of knowing who's knocking at your front door and whether you're going to let them in or not is, is huge. I think too, there's an opportunity to not necessarily offer every product under the sun just because you're onboarding them as a new client doing something during the onboarding process that really does a good job of assessing what the client's banking needs are, are actually are, you know, does somebody who's never going to send a, a wire or global money transfer, do they really need that access to that product? You know, maybe they're only ever going to send e-Transfers. So maybe they get, you know, basic banking plus e-Transfer capability. And then if they decide down the road, they do have a need for another product. Add that later on, like mitigate the risk for both the client and also the bank as well, because then you're just not leaving that product open to be exposed in the event of account takeover, because we know maybe the client's not using it, but the fraudster will look at it as an opportunity. 

So, you know, if we do a better job at onboarding, you know, once we have the assurance factor on board. Okay, so what do you actually need? What are you actually coming to us for? What's your banking needs? And let's do that in a way that again, we're not opening up every product, every limit. We're just doing it in a smart and intentional way and just giving clients what they're actually looking for. And again, sort of mitigating exposure. 

Jas Anand:
Look, guys, we're getting close to the end. 

I have to say thank you first for being on the panel. And second, I'm very encouraged by the conversation. I mean, you often hear things like, you know, it's a liability thing and the banks don't care. I mean, you're hearing from three of the largest banks here that they care about scams and they're working actively on it, and they're working hard to protect the victims irrespective of liability. So, you know, I think that's very encouraging. And I think it is a little scary to hear all the challenges you have across products and channels and the sophistication of the crime. But I think it is also important to realize that it is being managed within your risk appetite. So you are working within the risk appetites of your organizations and continue to improve those. I love the friction for good. You know, let's add friction and give people more access. That's fantastic. We all live in a world of false positives, and we know that nobody makes a perfect decision here. So, you know, getting to a place where we can converge capabilities, share data and, you know, help people get access to money and movement and products and access faster is fantastic. With that, I think, I think we're at close, but Elizabeth, Geoff, thank you very much, because this is very beneficial. I thank you for being so open and candid and sharing your feelings with everybody. I appreciate it. Thank you all. 

Elizabeth (Liz) Dempsey:
And that concludes this episode of The SUMMIT Summer Series. 

A big thank you to our panel, Elizabeth Tripp, Aaron McAllister and Geoff Morton and our expert moderator, Jas Anand, for sharing such valuable insights on the complexities of modern financial crime. 

If you enjoyed this episode and want to hear more of the best conversations from this year's event, be sure to subscribe to The PayPod on your favorite podcast app.

I'm your host, Liz Dempsey. 

Thanks for listening. 

We’ll be back next week with more of the best sessions from The 2026 SUMMIT on The PayPod!

Keep reading