Ga naar content

The fight against phishing: why collaboration is key

If you still associate phishing with clumsy emails full of typos, it is time to update your perspective. Today, phishing is driven by professional, organized criminal groups that operate on a massive scale, automate their processes, and continuously test and optimize their tactics. That's reason enough to dedicate an extra episode of the POMcast to the topic. Benoît Craenenbrouck and Stijn Loosveld discuss this with Gert-Jan Ceyssens, Information Security Officer at Bancontact Company.

Gert-Jan Ceyssens from Bancontact during a POMcast episode about phishing

Who is responsible when a phishing attack succeeds and someone falls into the trap? How can banks, payment providers, and other players in the chain work together to keep fraudsters out? And how is AI changing the way phishing is carried out and the way we defend ourselves against it?

One thing quickly becomes clear during the conversation: fighting phishing is not the responsibility of a single party, but a challenge for the entire chain.

Phishing has become a business model

The days when phishing was the work of an individual sending out random messages are behind us. According to Gert-Jan, we are now dealing with organized criminal groups that run their phishing activities much like a legitimate business.

Messages are sent out on a large scale to identify potential victims. A large part of that process is automated. Only when someone clicks a link or responds does a victim move further into what Gert-Jan describes as a phishing funnel.

From that point on, fraudsters work in a highly professional manner. The enormous volume of messages they send provides them with a wealth of data on what does and does not work. They use that knowledge to constantly adjust their approach. Just as companies optimize their marketing, phishing gangs engage in A/B testing: successful messages are refined to achieve even better results in future attempts.

That professionalism makes phishing messages increasingly difficult to recognize.

Anyone can become a victim

According to Gert-Jan, placing the responsibility solely on the victim is too simplistic.

Of course, vigilance remains important. Consumers must look closely at what is being asked of them and know when to stop when something doesn't add up. But technology and payment providers also have a responsibility to make it as clear as possible what is happening during a payment.

Furthermore, fraudsters are increasingly able to target their victims more precisely. They often have access to much more than just a phone number or email address. Personal data stolen elsewhere can be used to build a credible story and gain their target's trust.

The idea that phishing only affects a specific group of less vigilant people is therefore incorrect. Anyone can be targeted with the right message at the wrong moment.

Even if you spot a phishing attempt in time, you can still help. By reporting suspicious messages to, for example, Safeonweb or the bank involved, organizations gain valuable information about the techniques currently being used, which can then be used to improve security systems.

Make phishing less profitable

Since phishing is so professionally organized, we need to rethink how we combat it.

In our conversation, Gert-Jan makes an interesting point: phishing gangs ultimately think in economic terms, too. Finding and convincing victims costs time and money, and they need to see a sufficient return on that investment.

The challenge for banks, payment providers, and technology companies is therefore not just to block individual phishing attempts, but to make the business model behind phishing as difficult to sustain and as unprofitable as possible.

This means creating as many hurdles as possible for fraudsters without making things more complicated for consumers. No single player in the chain can achieve that balance alone. That is precisely why effective collaboration is essential.

No single player sees the full picture

A single online payment can involve several different parties. What seems like one simple action to a consumer actually consists of an entire chain behind the scenes.

Every party in that chain has access to different information. The party sending the invoice knows the context of that invoice. A payment provider has visibility into different aspects of the transaction. A payment scheme like Bancontact has access to yet other transaction data.

But no single player sees the full picture.

According to Gert-Jan, this is a key factor in combating phishing more effectively. By sharing relevant information and signals across organizational boundaries, different parties can collectively build a more complete picture.

This allows for a better response to the phishing tactics currently in circulation.

Combating phishing is therefore not just a matter of better security within each individual organization. The better the various links in the chain work together, the stronger the whole becomes.

POM, Bancontact and itsme® join forces

That same philosophy underpins the partnership between POM, Bancontact and itsme®.

Together, we ensure that invoices can be delivered directly to the Bancontact Pay app. This allows invoices to, as it were, to reach a safe harbor, where consumers can receive and pay them in a trusted environment.

This creates a secure and direct route from invoice to payment and sidelines fraudsters, while keeping the process simple for the consumer.

Facturen rechtstreeks bezorgen in de Bancontact Pay-app

It's a great example of what becomes possible when different parties in the chain combine their technology and expertise: increased security without additional friction for the end user.

AI is changing the playing field on both sides

Meanwhile, the technology behind phishing continues to evolve. AI in particular can further accelerate its sophistication and automation.

In the POMcast, Gert-Jan cites a striking example of a social engineering competition at DEF CON. While participants used to try to extract information over the phone themselves, AI systems were allowed to compete last year as well. AI that makes calls independently and tries to persuade someone: it shows how quickly the technology is evolving.

For phishing gangs, this means another part of their process can be automated. Tasks that still require human intervention today may increasingly be performed by AI in the future.

But fortunately, this evolution works both ways.

Technology and payment providers can also use AI to better detect fraud, recognize new patterns, and develop new defense mechanisms. The question, therefore, is how both sides will deploy this technology and how quickly the capabilities will continue to evolve.

Gert-Jan does not necessarily see regulation as a hindrance today. According to him, technology companies have plenty of tools at their disposal to combat phishing.

Winning the fight against phishing is a team effort

Phishing is not a black-and-white issue. Consumers have a role to play, but the same applies to banks, payment providers, technology companies, and all other players that are part of the chain.

At the same time, the adversaries are becoming increasingly professional. They automate, experiment, and use new technology to constantly refine their approach.

That is why a key part of the sollution lies in collaboration: sharing relevant signals, combining technology and expertise, and creating secure routes that leave as little room as possible for fraudsters to intervene.

___

➡️ Watch or listen to the full POMcast episode (in Dutch) on YouTube, Spotify or Apple Podcasts.

No items found.