CyberSource Online Fraud Report
10th Annual 2009 Edition
Download your copy of the 10th Annual Online Fraud Report – 2009 Edition Today!
Managing online fraud continues to be a significant and growing cost for merchants of all sizes. While the number of fraudulent orders have been relatively stable, total losses from online payment fraud in the U.S. and Canada have steadily increased as eCommerce continues to grow. What will the trend be this year? The industry's most respected online fraud study analyzes benchmark data and practices you can use including:
* Detailed fraud metrics (fraud, chargebacks & order rejection)
* Detection tools used/planned at each stage
* Manual review rates, staff turnover and training time
* Full process practice/metric mapping
* Budgets (overall and how allocated)
Expert analysis reviews aggregate data as well as cuts by company size. Over 20 pages of statistics, analysis, charts and graphs.
2. C Y B E R S O U R C E 1 0 TH A N N U A L O N L I N E F R A U D R E P O R T
Report & Survey Methodology Summary of Participants Profiles
This report is based on a survey of U.S. and Canadian online Online Fraud Survey Wave 2003 2004 2005 2006 2007 2008
merchants. Decision makers who participated in this survey Total number of merchants participating 333 348 404 351 318 400
represent a blend of small, medium and large-sized organizations
Annual Online Revenue
based in North America. Merchant experience levels range from
Less than $500K 29% 34% 50% 37% 29% 31%
companies in their first year of online transactions to the largest $500K to Less than $10M 43% 39% 24% 30% 35% 28%
e-retailers and digital distribution entities in the world. Merchants Over $10M 28% 27% 26% 33% 37% 41%
participating in the survey reported a total estimate of $60 billion
Duration of Online Selling
for their 2008 online sales. Survey respondents include both Less than One Year 10% 12% 14% 11% 5% 11%
non-CyberSource and CyberSource merchants. 1-2 Years 19% 14% 19% 11% 13% 12%
3-4 Years 44% 30% 23% 18% 18% 13%
The survey was conducted via online questionnaire by Mindwave
5 or More Years 27% 44% 45% 61% 67% 64%
Research. Participating organizations completed the survey
Risk Management Responsibility
between October 21st and November 11th, 2008. All participants
Ultimately Responsible 49% 50% 60% 54% 55% 58%
were either responsible for or influenced decisions regarding risk
Influence Decision 51% 50% 40% 46% 45% 42%
management in their companies.
Get Tailored Views of Risk Management Pipeline™ Metrics
To obtain customized fraud management benchmarks for your company’s size and industry please contact CyberSource at
1.888.330.2300 or online at www.cybersource.com/contact_us.
For additional information, whitepapers and webinars, or sales assistance:
• Contact CyberSource: 1.888.330.2300 or www.cybersource.com/contact_us
• Risk Management Solutions: visit www.cybersource.com/products_and_services/risk_management/
• Global Payment & Security Solutions: visit www.cybersource.com/products_and_services/global_payment_services/
2
4. C Y B E R S O U R C E 1 0 TH A N N U A L O N L I N E F R A U D R E P O R T
Executive Summary
Managing online fraud continues to be a significant Key Fraud Metrics
and growing cost for merchants of all sizes. To better
The percent of accepted orders which are later determined
understand the impact of payment fraud for online
to be fraudulent has also been relatively stable. In 2008
merchants, CyberSource sponsors annual surveys
merchants reported an overall average fraudulent order rate
addressing the detection, prevention and management of
of 1.1% in the U.S. and Canada. Over the past six years
online fraud. This report summarizes findings from our
the average percent of accepted orders which turn out
tenth annual survey.
to be fraudulent has varied from 1.0% to 1.3%. Among
industry sectors, Consumer Electronics reported the highest
Overview fraudulent order rate, averaging 2%.
Over the past three years the percent of online revenues
The share of incoming orders merchants decline to accept
lost to payment fraud has been stable. Merchants have
due to suspicion of payment fraud was down significantly.
consistently reported an average loss of 1.4% of revenues
Put more simply, merchants are accepting a higher
to payment fraud. However, total dollar losses from online
percentage of orders. In 2008 the overall order rejection
payment fraud in the U.S. and Canada have steadily
rate due to suspicion of fraud dropped to 2.9% compared
increased during this time as eCommerce has continued
to 4.2% in 2007.
to grow. In 2008, we estimate that $4 billion in online
As the growth of online sales has slowed during 2008, it
revenues were lost to payment fraud. Just two years ago,
appears merchants are now focusing even more attention
in 2006, payment fraud reached the $3 billion revenue
on sales conversion and reducing their order rejection
loss milestone (see chart #1).
1
Online Revenue Loss Due to Fraud
% Revenue Lost to Online Fraud $4B in 2008
4.0% $4.5
$4.0
3.5%
3.6%
$4.0
$3.5
3.0%
3.2%
$3.6
2.9%
$3.0
% Online Revenue Lost
2.5% $3.0
$ Loss in Billions
$2.8
$2.5
$2.6
2.0%
$2.0
$2.1
1.8%
1.5%
$1.9
1.7%
1.6%
$1.5
$1.7
1.4%
1.4%
1.4%
$1.5
1.0%
$1.0
0.5% $0.5
0% $0.0
2000 2001 2002 2003 2004 2005 2006 2007 2008 2000 2001 2002 2003 2004 2005 2006 2007 2008
n=132 n=220 n=341 n=333 n=348 n=404 n=351 n=294 n=399
Although the rate of revenue loss due to online payment fraud was stable in 2008, total dollars lost to fraud have increased
due to online sales growth.
4
6. C Y B E R S O U R C E 1 0 TH A N N U A L O N L I N E F R A U D R E P O R T
Total Pipeline View
and association limits), an end-to-end view is required to
Businesses that focus solely on managing chargebacks
arrive at the best possible financial outcome.
may not be seeing the complete financial picture. Online
payment fraud impacts profits from online sales in In 2008, these “profit leaks” in the Risk Management
multiple ways. Besides direct revenue losses, the cost of Pipeline™ impact as much as 40+% of orders for
stolen goods/services and associated delivery/fulfillment mid-sized merchants and as much as 19+% of orders
costs, there are the additional costs of rejecting valid for larger merchants—restricting profits, operating
orders, staffing manual review, administration of fraud efficiency and scalability. This report details key metrics
claims, as well as challenges associated with business and practices at each point in the pipeline to provide you
scalability. Merchants can gain efficiency by taking a total with benchmarks and, hopefully, insight. Custom views
pipeline view of operations and costs. While the fraud rate of these benchmarks and practices are available through
is one metric to monitor (and contain within industry CyberSource—see end of report for contact information.
Risk Management Pipeline
RETAINED
Automated Manual Accept Fraud Claim
1 2 3 4
ORDER
REVENUE
Screening Review Reject Management
Staffing & Lost Fraud Loss &
PROFIT LEAKS Scalability Sales Administration
Merchants review 32% of 2.9% Avg. Reject Rate 1.4% Average Fraud Loss
orders, on average for US/Canadian orders
(all merchants) 42% from chargebacks
51% of fraud management 58% from issued credits
budget is spent on review 10.9% Avg. Reject Rate
staff costs for Non-US/Canadian
orders (merchants who
81% of these merchants accept these orders)
have no plans to change
manual order review
staffing during 2009
6
8. C Y B E R S O U R C E 1 0 TH A N N U A L O N L I N E F R A U D R E P O R T
Company specific
3
fraud screens
Automated Fraud Detection Tool Current Usage and Plans
received the
Merchants $25M+ Online Revenue highest rating as
All Merchants
being an effective
VALIDATION SERVICES
tool by merchants
78% 11% 87% 6%
Address Verification Service
who use this tool.
74% 14% 80% 16%
CVN (Card Verification Number)
Half of the 42%
35% 9% 39% 9%
Postal address validation services
of large merchants
27% 18% 19% 11%
Verified by Visa/MasterCard SecureCode
who use custom
25% 12% 31% 10%
Telephone number verification/reverse lookup
fraud models
11% : 7% 21% 4%
Paid for public records service rated them as
one of their three
5% : 6% 3% : 1%
Credit history check
most effective
5% : 6% 7% : 6%
Out-of-wallet or in-wallet challenge/response
tools. These fraud
SINGLE MERCHANT PURCHASE HISTORY
screens are risk
47% 10% 58% 13%
Customer order history
scoring models
38% 12% 67% 10%
Negative lists (in-house lists)
which are tuned
using an individual
28% 15% 54% 17%
Order velocity monitoring
merchant’s
27% 11% 42% 20%
Fraud scoring model – company specific
historical data on
20% 9% 22% 13%
Valid customer behavior analysis
factors associated
18% 10% 30% 14%
Positive lists
with online orders.
PURCHASE DEVICE TRACING Since fraudsters
35% 19% 48% 27% learn over time and
IP geolocation information
vary their strategies
6% : 25% 7% : 47%
Device Fingerprinting
we typically find
MULTI-MERCHANT PURCHASE HISTORY
most risk scoring
14% : 14% 18% 24%
Shared negative lists – shared hotlists
models need
9% : 2% 9% : 9%
Multi-merchant fraud models
regular tuning
with new analysis
Current n=359; Future Plans n=194 Current n=101; Future Plans n=70
and data in order
Current
to maximize their
Planning to implement (next 12 months)
effectiveness.
Out-of-wallet or
in-wallet challenge systems, while used by only 7% of large
commonly used detection tool. The purpose of CVN in a
merchants today, was rated by 43% of these merchants
card-not-present transaction is to attempt to verify that the
as being one of their three most effective tools. The use
person placing the order has the actual card in his or her
of challenge systems tends to be limited to merchants
possession. Requesting the card verification number during
who have frequent repeat purchases by customers or bill
an online purchase can add a measure of security to the
customers on a regular schedule.
transaction. However, CVN numbers can be obtained by
fraudsters just as credit card numbers are obtained. CVN
Device Fingerprinting (also used by only 7% of large
usage by online merchants has significantly increased in
merchants today) was rated by 43% of these merchants
the last five years, rising from 44% in 2003 to 74% today.
as being one of their three most effective tools. These
favorable opinions may well contribute to the very high
Large merchants were asked to identify the three most
intention by other large online merchants to add this tool in
effective tools they use. To eliminate the bias that the more
the next twelve months.
commonly used tools have the potential to receive more
mentions, we normalize the data by looking at the percent
of merchants using a particular tool who cite that tool as
one of their top three choices.
8
10. C Y B E R S O U R C E 1 0 TH A N N U A L O N L I N E F R A U D R E P O R T
Stage 2: Manual Review
Automated Manual Accept Fraud Claim RETAINED
1 2 3 4
ORDER
Screening Review Reject Management REVENUE
Tuning and Management
Orders which do not pass the automated order screening Manual Order Review Rates
stage typically enter a manual review queue. During this
In what should be a highly automated sales environment,
stage, additional information is collected to determine if
most merchants are manually checking orders. In fact,
orders should be accepted or rejected due to excessive
during the past six years, overall, 1 out of every 4 orders
fraud risk.
transacted online have been manually reviewed (see chart
Manual review represents a critical area of profit leakage. #4). Over the same period, merchants who conduct manual
It is expensive, limits scalability, and impacts customer review typically reviewed 1 out of 3 orders they received.
satisfaction. For many merchants it represents half of
Merchants of all sizes use manual review to manage
their fraud management budget. Only 13% of merchants
payment fraud. Chart #5 shows smaller merchants review
say they have budget available to increase review
a higher percentage of orders (perhaps because lower
staff now or in the next twelve months. This presents
order volumes permit such practice) but even larger
significant challenges to profit growth since, even at a
merchants review a significant percentage of online
stable percent of orders sent to review, the total number
orders—and likely devote more resources to this task than
of orders that must be reviewed increases in step with the
is operationally scalable.
total increase of online sales.
One consequence of using more fraud detection tools
during automated screening is a greater chance of one
or more flags being raised, resulting in an order being
4
selected for manual review. Adding additional tools to
Manual Review Trends detect fraud may result in downstream impacts and
costs if these tools are not carefully integrated into a
merchant’s review process and tuned to a merchant’s
Over the past 5 years, on average, 1 out of 4 online orders were
manually reviewed. Merchants performing manual review have specific situation.
on average reviewed 1 out of every 3 orders received.
Merchants expecting increased online sales will need to
take at least one of the following actions: 1) divert more
40%
staff time to the order review process; 2) increase staffing
35%
levels; 3) allow more time to process orders and ship good
35%
34%
33%
ones; or 4) improve accuracy of initial automated sorting
30%
32%
and make the subsequent review process more efficient.
28%
25%
27%
27%
26%
23%
20%
22%
Review Tools & Practices
15%
Given the reported limitations on hiring additional manual
10%
review staff, there is increased focus on investing in tools
5%
and systems to increase the productivity and effectiveness
0%
of review staff. While the primary focus should be on
2004 2005 2006 2007 2008
improving initial automated sorting accuracy to decrease
% Orders Reviewed by Merchants Practicing Review
need for review, attention to streamlining the review
% Orders Reviewed Overall (Net Review)
process is also warranted.
10
12. C Y B E R S O U R C E 1 0 TH A N N U A L O N L I N E F R A U D R E P O R T
7 8
Time to Clear Orders in Manual Review (2008) Time Allowed for Customer Response
50% 50%
45% 45%
Over two-thirds of merchants clear
40% 40%
72% orders through manual review
in one business day.
35% 35%
37%
36%
30% 30%
25% 25%
26%
20% 20%
19%
18%
15% 15%
14%
10% 10%
11%
10%
10%
10%
8%
5% 5%
1%
1%
0% 0%
1 hour Half day
2-4 Same Next 2-3 4-5 6 or more Same Next 2-3 4-5 6 or more
or less or less
hours business business business business business business business business business business
day day days days days day day days days days
n=259
Source: 2008 CyberSource Fraud Report
9
Fraud Detection Tool Usage During Manual Review
Merchants $25M+ Online Revenue
All Merchants
VALIDATION SERVICES
69% 11% 82% 5%
Contact customer to verify order
56% 15% 74% 5%
Telephone number verification/reverse lookup
49% 10% 60% 14%
Contact card issuer/Amex CVP
45% 12% 46% 7%
Postal address validation services
23% 14% 45% 14%
Paid for public records service
9% : 7% 6% : 12%
Credit history check
SINGLE MERCHANT PURCHASE HISTORY
72% 8% 83% 5%
Customer order history
49% 14% 69% 12%
Negative lists (in-house lists)
35% 13% 37% 14%
Valid customer website behavior analysis
22% 17% 34% 30%
Positive lists
PURCHASE DEVICE TRACING
40% 20% 55% 28%
IP geolocation information
MULTI-MERCHANT PURCHASE HISTORY
11% : 28% 16% 35%
Shared negative lists – shared hotlists
Current n=265; Future Plans n=109 Current n=89; Future Plans n=43
% currently using
% planning to begin use (in 2009)
12
14. C Y B E R S O U R C E 1 0 TH A N N U A L O N L I N E F R A U D R E P O R T
Stage 3: Order Dispositioning (Accept/Reject)
Automated Manual Accept Fraud Claim RETAINED
1 2 3 4
ORDER
Screening Review Reject Management REVENUE
Tuning and Management
Post-Review Order Acceptance Rates
to find the 10% of the review queue they believe to be
Merchants who manually review orders indicated they
too risky to accept. Clearly, most merchants require better
ultimately accepted nearly ¾ of the orders they manually
methods to determine which orders are to be outsorted for
reviewed (see chart #13). This was similar to the
manual review, so only truly suspicious orders receive
proportion reported in 2007. 50% of merchants report
human attention.
they accept 90% or more of orders they manually review.
These merchants are incurring significant expense
13
% of Merchants Reporting This Level
Post-Review Acceptance Trends of Post-Review Acceptance
100%
2%
0%
90% Most orders that enter manual review are accepted 5%
1% – 9%
80%
5%
10% – 19%
75%
70%
73%
4%
20% – 29%
71%
69%
66%
66%
60% 3%
30% – 39%
1%
50% 40% – 49%
7%
50% – 59%
40%
3%
60% – 69%
30%
9%
70% – 79%
20%
13%
80% – 89%
10%
44%
90% – 99%
0%
2003 2004 2005 2006 2007 2008 50% accept 90%+
6%
100%
% of Orders Accepted in Review
14