Live data from Hacker News

E-commerce Fraud Facts

blog.siftscience.com

11–20 of 46 posts

Re: E-commerce Fraud Facts

#11
post #7

With domain name registration the factors that we have noticed that are almost certainly fraud orders are (in various combinations): 1) credit card payment is all lower case and/or obvious non understanding of how US addresses are formatted 2) domain name has "hack" or some foreign sounding word. Or is anything related to vietnam (get plenty from vietnam) 3) IP location doesn't match customers location 4) Multiple at…

Do you have this kind of ruleset codified or automated in any way? It looks like a great example of knowing your own market.

Re: E-commerce Fraud Facts

#13

Did anyone else find it odd that the 2am and 4am times weren't qualified? (US? East Coast/West Coast?)

I think they're actually quite sophisticated about it - they look at the time zone according to the shopper's browser. So they're looking at local-to-the-shopper.

Re: E-commerce Fraud Facts

#14
post #7

With domain name registration the factors that we have noticed that are almost certainly fraud orders are (in various combinations): 1) credit card payment is all lower case and/or obvious non understanding of how US addresses are formatted 2) domain name has "hack" or some foreign sounding word. Or is anything related to vietnam (get plenty from vietnam) 3) IP location doesn't match customers location 4) Multiple at…

Agree with Vietnam. As a % of fraud I'd say 70% is Vietnam. And few if any legitimate orders from Vietnam. In our experience.

Re: E-commerce Fraud Facts

#15
post #5

This is awesome stuff. Theoretically. But Sift doesn't actually make these functional/actionable right away through their service (even though they could). We signed up, love (LOVE!) the idea, but they keep asking for more data before returning meaningful results. Their home page says, "Get going in minutes: Integrate in just three steps: paste a Javascript snippet onto your site, log transactions from your servers t…

Hey Aaron, I'm the OP, and CEO of Sift Science. Sorry that your experience has been subpar. I'll follow up offline.

I think there's some confusion -- we actually do have a global machine learning model, which is what customers will start with if we haven't received any labels (training examples to learn from). But, your mileage may vary with the global model. We think it's a starting point, but that fraud differs from site to site in subtle ways, and to be truly effective you need to have your own model. This is why training examples are so critical. Once we receive enough training examples, we're able to build a model specific to your site.

That said, I'll be the first to agree with you -- we haven't done a great job setting the right expectations and messaging, especially on the point above (that your mileage may vary with the global model). We've been working hard to improve this, and there are now several reminders in the console, and an introductory tour, that emphasize the importance of a thorough integration with labels to achieve best results. With machine learning especially, bad data in = bad results out. Also, our first UI/UX designer started a month ago, and improving this experience is a top priority.

With regards to making fraud facts more functional and actionable -- we actually do provide reasons we think a user is suspicious in our web console and API (see https://siftscience.com/docs/getting-scores). But, there isn't an "aggregate learnings" page like what's presented in the blog post -- that's on the 3-month roadmap.

Again, sorry for the subpar experience, and I'll follow up with you separately. We have a very technical product -- we're working hard to abstract the complexity, while making sure we set customers up for success. We've also been overwhelmed with customer demand, and have been scaling the team to keep up (7 FT employees two months ago, 15 now). That said, no excuses. Just know that we're not happy to hear about experiences like yours, and are working hard to make it right.

Thanks, Jason

(EDIT) Aaron and I just had a good phone call -- we're going to make things right.

Re: E-commerce Fraud Facts

#16
post #13

Did anyone else find it odd that the 2am and 4am times weren't qualified? (US? East Coast/West Coast?)

I think they're actually quite sophisticated about it - they look at the time zone according to the shopper's browser. So they're looking at local-to-the-shopper.

Yep! We try to localize the time.

Re: E-commerce Fraud Facts

#17
post #7

With domain name registration the factors that we have noticed that are almost certainly fraud orders are (in various combinations): 1) credit card payment is all lower case and/or obvious non understanding of how US addresses are formatted 2) domain name has "hack" or some foreign sounding word. Or is anything related to vietnam (get plenty from vietnam) 3) IP location doesn't match customers location 4) Multiple at…

Do you have this kind of ruleset codified or automated in any way? It looks like a great example of knowing your own market.

No it's not automated. Although it would be possible to mechanical turk if you train in the rules.

One thing I forgot to mention is that in edge cases what you do is send off an auto email to the registrant with a challenge question or requesting additional information from them. Or you say that the bank has declined the charge.

So for example if the person says they are "Bob Wagner" a business owner living in the US but replies to the email using broken english or doesn't understand the question you know something is wrong. Of course you try and do it in a way that doesn't tip them off that you suspect anything (other than in the case where you tell them that the credit card has been declined (when it hasn't) to see how they respond). Someone who has committed fraud will of course be paranoid. In fact a kid using his mothers credit card will be paranoid and respond in a unique way that says "shit" in some way shape or form.

Edit: Auto email must be formatted and appear to have been personally written by a person just to the recipient. Otherwise many cases won't be responded to at all.

Re: E-commerce Fraud Facts

#18
post #10

This doesn't seem really smart since some of those apply to me. I am not from America and I sometimes order from there meaning it would seem like I'm ordering at 4am when its 2pm my time. Another thing is the email, I know a lot of people with their birth year inside their email. What about them?

Sift intern here.

We use the time zone of the customer rather than of the website for scoring riskiness. Sorry if that wasn't clear.

As for customers including birth years in their emails, you're correct that this would be counter to the general trend. However, a fraud detection system like Sift has many data points on which to score a customer. Hopefully, the person would otherwise look benign and thus not have a very high overall score.

Re: E-commerce Fraud Facts

#19

The patterns that emerge for fraudulent orders are amazing. And, as the article notes, often specific to a particular merchant. Fraudulent orders often come in waves lasting up to several months, and pattern recognition can be particularly helpful in identifying parts of those longer waves. I'm also working on a project in this space - http://www.merchantprotector.net

(I upvoted you but I might have clicked the downarrow instead).

On your site this phrase:

"We used to have a problem with fraudulent orders."

My suggestion is that the following is much clearer:

"We no longer have a problem with fraudulent orders."

Also the other info I would present in a less negative way. People tend to respond better (imho and experience) to a message presented in a positive way rather than negatively.

So for example rather than:

"Fraud can kill your business" I would say:

"Reduce Fraud and Make more money".

Instead of "Stop the cycle of worry" I would say:

"Sleep at night and make more money"

etc.

Obv. there are many twists to this that's just two examples.

Re: E-commerce Fraud Facts

#20
So for something like "fraudsters don't use capital letters," does your system discover a fact like this automatically, or do I have to think up these indicators myself and hope they are relevant?
Post reply on HN