There's a lot of online fraud. We invest a ton in Radar, our payment surfaces, etc., to keep this as invisible as possible to businesses. (We don't always succeed, of course. But, despite the growing sophistication of the fraudsters themselves, we do generally get better every year.)
The intuition here is that the rules that block when CVC/ZIP doesn’t match necessarily happen after the bank already decided the transaction was okay, because that’s when Stripe learns whether CVC/ZIP match what the bank had on file.
So if you block on a mismatch, you’re throwing away an approved charge every single time since the bank already decided that other signals say the transaction is okay. The bank can block it themselves if they think it’s suspicious (which from my understanding wouldn’t increment this metric).
Out of curiosity do you share the suspected fraud with law enforcement? At that amount there are probably too many to chase down so I’d think this is just an unprosecuted crime?
Generally the bank will file a Suspicious Activity Report (SAR) with FINCEN for egregious cases. I don’t think intermediaries like stripe have any direct responsibility in this respect but I could be wrong. The volumes are huge and few SARs actually are investigated or prosecuted.
Um, no. Banks file a lot of those. If it’s me using my dads credit card number then sure, not a SAR. But most of that activity is systematic: either backed by organized crime or a semi-professional fraudster. Those most definitely would get a SAR
Can you estimate what proportion of fraud is automated/bot/scripted versus manual human interaction? Do you rely much on botnet detection or IP reputation?
I assumed stripe founders had offline business experience before stripe :) Online maybe increase it a little more and make it more risky to the business because of "card not present". But hardly new to online.
There's also a lot of false positives if you verify too much on data brokers, as you just mentioned you do, instead of talking to the issuing institution on fears of chargeback and rate hikes.