Sift

shift

Loco Partners, Inc.

Detected hundreds of “signs of fraud” through trial implementation Utilizing Sift as a defensive key to revive inbound demand

POINT

In the travel industry, OTAs (Online Travel Agencies), which conduct transactions exclusively over the Internet, continue to grow. At the same time, OTAs are also causing more damage due to fraudulent credit card use, and the Japan Cyber Crime Control Center has issued a warning. "Relux" operated by Loco Partners, Inc. was also plagued by a large number of chargebacks for a while, but thanks to the trial introduction of the fraud prevention service "Sift", the amount of chargebacks decreased by about 60% in one year. Successfully discovered hundreds of fraudulent account registrations. Since then, the company has steadily achieved results in countering unauthorized use.

Mr. Tatsuya Kawaguchi

Loco Partners, Inc.
Corporate Headquarters Management Department
Manager/CPA
Mr. Tatsuya Kawaguchi

Domestic travel market showing signs of recovery

The online booking ratio in Japan's travel market already exceeds 40%, and this percentage is increasing year by year. In addition to major domestic Jalan, Rakuten Travel, and Ikyu.com Global, major overseas OTAs such as Expedia and Booking.com are also expanding their domestic services, and competition is becoming increasingly intense.

Among them, Relux, operated by Loco Partners, Inc., has established a unique position and continues to grow. In order to deliver a special travel experience where you can feel that relaxation is luxury, we provide accommodation reservation services by carefully selecting inns and hotels with high customer satisfaction. The number of members has continued to increase since the service began in March 2013, and currently exceeds 2.5 million members.60 to 70% of members are in their 30s to 50s, and the ratio of men and women is almost evenly split. According to an online survey conducted by Relux in January 2020 *, we surprisingly found that more than half of the respondents travel five or more times a year.'' (Mr. Kawaguchi)

The company is also focusing on inbound tourism, such as multilingual support for the site and a partnership with Skyscanner, a major overseas OTA, and the number of users from overseas is increasing. However, due to travel restrictions in various countries due to the spread of COVID-19 (COVID-19), it is difficult to make reservations from overseas as of July 2020. "However, just as people cannot come to Japan from overseas, they cannot travel abroad from Japan, so travel destinations are shifting to Japan. We feel firsthand the desire of our customers to relax away from their daily lives, and we are promoting various initiatives with the belief that this will be a tailwind."

*Results of an online survey conducted by Relux

<Investigation overview>

  • Survey method: Online questionnaire survey via Relux email newsletter
  • Target audience: Relux domestic customers nationwide, male and female
  • Accommodation period: January 1, 2019 (Tuesday) - December 31, 2019 (Tuesday)
  • Survey period: January 10, 2020 (Friday) to January 16, 2020 (Thursday)
  • Number of valid responses: 3,622

Risk of suspension of card transactions due to rapidly increasing chargebacks

At Relux, when making a reservation, you can choose between advance payment using a registered credit card and on-site payment. Compared to when the service first started, the percentage of users choosing to pay in advance by credit card is on the rise, both domestically and internationally. The first time we received a chargeback notice from a credit card payment service provider was at the end of 2017, but the number of fraudulent uses has rapidly increased since then. Hundreds of chargebacks occurred in 2018.

There are several methods of fraudulent use in the travel industry. One method is to register fraudulently obtained credit card information as a payment card in the created account and make a payment. The card information that is registered varies from leaked card information sold on the dark web to cases where store employees steal customer card information and misuse it. In June 2020, it was reported that a person fraudulently used card information stored at the cash register at his part-time job and fraudulently used the card information to pay for airline tickets, hotels, etc. on multiple occasions, totaling more than 10 million yen. Ta. "Although this incident occurred at another company, I think it is extremely rare for a large sum of money to be used repeatedly like this. This is a case of fraudulent use of an expensive room costing more than 100,000 yen." (Mr. Kawaguchi)

A method known as ``fraudulent travel'' is more damaging. A criminal pretending to be a travel agent accepts travel applications at a discounted price and receives payments from the bookers. They then create an OTA account on behalf of the reservation holder and make travel arrangements, but use fraudulently obtained card information to make payments. Since the reservation information sent to the OTA is correct, the reservation is successfully completed and the reservation user can receive the travel service, but the fraudulent use is discovered later and a chargeback is issued to the OTA.
``Inbound fraud damage was mostly caused by fraudulent travel, which accounted for approximately 80% of the total.We had been aware that chargebacks due to fraudulent use were a risk in e-commerce, but we never imagined that there would be so much fraud in travel products. To be honest, I didn't think it would be used.'' (Kawaguchi) This technique is rapidly increasing in the industry as a whole, and the Japan Cyber Crime Control Center issued a warning in July 2018. In addition, the "Credit Security Guidelines," which serve as practical guidelines for the Installment Sales Act, positions accommodation reservation services as one of the high-risk products for fraudulent use of card information, and has a deadline of the end of September 2020 to prevent unauthorized use of spoofing. We are requesting that the response be completed.

In 2018, when Relux saw a rapid increase in fraudulent use, it received a warning from its payment service provider that card transactions would be suspended. If advance payment by credit card is not possible, it will not be possible to meet the needs of users who do not want to carry large amounts of cash with them when traveling. In addition, the convenience for users from overseas will be greatly impaired. "Financial losses due to chargebacks and opportunity losses due to suspension of card transactions. I felt it was time to take serious measures to address these two risks." (Mr. Kawaguchi)

Machine learning is effective for serious criminals who hack the rules

First, we introduced 3D Secure for reservations made via the website, where unauthorized use occurs frequently. Currently, the vast majority of unauthorized use occurs via websites that are easily manipulated by bots and programs. "There was naturally a concern that regular customers would leave because a 3D Secure password was required during the payment process. However, if things continued as they were, card transactions would be suspended, so we had no choice." (Kawaguchi) (Mr.) At the same time, we are also conducting manual patrols (extracting suspicious transactions based on amount, etc., conducting phone calls based on user information, and canceling fraudulent reservations), and fraud detection tools provided by the payment service providers we currently use. A number of measures have been introduced, including:

As a further measure, while comparing several fraud detection solutions based on case studies from other companies, a company in the KDDI CORPORATION introduced me to Sift. “What I thought was different from other solutions was that it analyzes user behavior rather than using a rule-based system to identify suspected abuse.Since serious criminals hack the rules, a rule-based system However, from what I've heard, Sift improves accuracy through machine learning based on data accumulation and requires no man-hours, which is an advanced and advantageous solution. '' (Mr. Kawaguchi) Also, the products we were comparing had a reputation for slow API linkage depending on the time of day, which affected usability, so we decided to trial Sift.

Discovering fraudulent account creation that is a precursor to chargebacks

In the fall of 2019, we began trials of two services: Payment Protection, which detects fraudulent transactions, and Account Takeover, which detects account takeovers. At the end of 2019, when a certain amount of data had been accumulated, a Macnica technical representative pointed out at a meeting that hundreds of fraudulent accounts were being created from Vietnamese IP addresses. Fraudulent account creation is a common precursor to fraudulent card use and fraudulent travel, so if fraudulent account creation can be detected, it is possible to prevent situations that lead to chargebacks. “I realized the effectiveness of Sift in that it allows us to detect fraud before the actual payment occurs.” (Mr. Kawaguchi) As a result of the trial, we switched the service to be introduced to fraudulent account detection “Account Abuse”, and in May 2020. It officially began operation in February.
Currently, for membership registration via the website, people check the risk score returned from Account Abuse, and transactions with a high score are considered fraudulent and we take measures to confirm and suspend them. "If fraud is allowed, each transaction will result in a loss of tens of thousands of yen, so even if it takes a little more manpower, it's still profitable. Still, with the introduction of Sift, the number of man-hours required to search for suspicious accounts has clearly decreased." (Mr. Kawaguchi) We are able to discover dozens of fraudulent account registrations created from various countries every month, but we have never had a complaint caused by incorrectly identifying an account registration by a legitimate user. He says he is satisfied with the results.

  • Fraudulent travel methods and chargeback occurrences

It’s time to strengthen your defenses in preparation for the revival of inbound demand

"In the future, we would like to expand the scope of application of Sift. In the future, with the introduction of Payment Protection, we will be able to judge credit card transactions based on Sift scores, require 3D secure only for gray areas, and prevent unauthorized use. We would like to aim for a point where accounts that are judged as such will be automatically suspended.We also have high expectations for the API collaboration between Stripe and Sift, the payment processing services used by many OTAs.Approving only correct payments without sacrificing usability. By doing so, we hope to maximize the effects of introducing Sift.'' (Mr. Kawaguchi) Ultimately, the goal is to reduce the number of man-hours required to prevent unauthorized use to around 20-30% of the current level.

Currently, the number of unauthorized uses of Relux is decreasing due to the slump in inbound demand due to the spread of COVID-19 infection. "Nonetheless, if inbound demand recovers in the future, the same thing will definitely happen in the travel industry. Now is the time to strengthen our defenses in preparation for that. I believe Sift will be able to play a key role in this," said Kawaguchi. speaks.

User Profile

Loco Partners, Inc.
location 東京都港区東新橋二丁目14番1号 コモディオ汐留4階
URLs https://loco-partners.com

Inquiry/Document request

In charge of Macnica Sift Co., Ltd.

Mon-Fri 8:45-17:30