No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Featured

Does Increased Compliance Mean More Fraud?

Combatting the Unintended Consequences of Compliance

by Iftah Gideoni
October 24, 2019
in Featured, Fraud
man in silhouette with long nose; concept of lies, deceit

Regulations like GDPR and PSD2 are creating an attack shift for fraudsters and alternative methods for them to create havoc. Forter’s CTO Iftah Gideoni discusses how to fight back against fraud with similarly evolving fraud prevention measures.

Today, data is the most valuable asset for consumers, businesses and fraudsters alike. Thanks to the rise in technological innovations, including the cloud, remote work and e-commerce breakthroughs, we now have the ability to do anything, from anywhere, at any time. But there’s also a dark side to this constant connectivity: criminals seeking to exploit personal, sensitive information, ranging from bank account numbers, credit card credentials and even customer loyalty accounts. In fact, according to recent research, fraud attacks on loyalty accounts increased by 89 percent in the past year alone.

In parallel with this data evolution, we are witnessing a growing focus by consumers, enterprises and regulators on the privacy and security of data collected, stored and shared online. Legislatures and regulatory bodies are passing more wide-reaching and comprehensive privacy laws, including Europe’s GDPR, which became binding in May 2018, and the California Consumer Privacy Act (CCPA), which takes effect in 2020. We should expect this trend to only increase; any enterprise dealing with personal data must be able to stand behind its privacy compliance program.

In the European Union, the Second Payment Services Directive (PSD2) came into effect last month. This regulation is intended to democratize access to data and simultaneously protect it through strong customer authentication. Given the complexity of compliance and attendant business implications, the U.K. and several other nations have announced enforcement delays, which vary from country to country. And while this regulation is intended to better safeguard data and payments, it may create headwinds for customer conversion — in fact, as many as half of consumers (49 percent) are likely to abandon online/mobile purchases if faced with a multi-step authentication process as outlined by PSD2.

As regulatory and legislative bodies continue their efforts to protect consumers and personal data, businesses need to build compliance programs that still optimize user experience and customer satisfaction and that take into account the adaptability and ingenuity of fraudsters and cybercriminals.

The Unintended Consequences of Increased Compliance

While both GDPR and PSD2 are intended to protect data, in reality, today’s payments ecosystem is too complex for legislation to predict and guard against fraudsters’ next moves. Making matters worse, online fraudsters are only growing in sophistication. These criminals are shifting their focus from brute-force attacks, where a high quantity of attacks increased the likelihood of a payoff, to investing in higher-quality, targeted attacks, where one attack translates to a larger and more meaningful payoff.

In the case of PSD2, a potential unintended consequence of this regulation is the shift in fraudulent activities outside the EU. PSD2 may make fraud more difficult at the point of transaction in the EU, leading fraudsters to shift to other geographies and attack points outside of the region. Criminals who stop using European data won’t stop stealing; they’ll just start stealing elsewhere.

Privacy regulations like GDPR and CCPA are giving consumers more rights to access and request deletion of their data. This introduces the risk of fraudsters disguising themselves as legitimate actors and demanding all data on their personas be removed. The ability to identify fraudsters as returning bad actors is vital to all fraud-fighting efforts, and the loss of historical data would be a serious handicap to proper prevention.

Fighting Back Against Fraud: Understanding Your Ecosystem

One of the most effective ways to combat the unintended risks that regulations like PSD2 and GDPR bring is to develop a deep understanding of your organization’s ecosystem, as well as the users who are a part of it. This includes:

  • A full understanding of good and bad actors, as well as the connections between them, which can provide the necessary framework for protecting an online business.
  • Knowing how your fraud prevention system recognizes fraudulent behavior – for example, can your system detect fraudsters when they return in different guises?
  • Going beyond matching obvious data points such as addresses, names or even IP addresses to instead, match behavioral data and patterns, while using cyber intelligence to piece together unclear elements.
  • Lastly, in order to guard against the risk of geographical fraud patterns, it’s important that your fraud prevention system be sensitive to genuine behaviors within different geographical areas and be able to flag when a user does not match the expected norms for their location.

Fraudsters are becoming ever more sophisticated, so your organization needs to evolve in turn when it comes to fraud prevention. Add to this equation the ongoing challenges and changes that compliance regulations like PSD2 and GDPR bring, and it may create a recipe for disaster.

Make sure your customers and accounts are protected by a system that knows your customer base just as well as you do. It requires flexibility, continuous innovation and an ongoing effort to stay ahead of criminals and to keep up with the evolution in customer behaviors and expectations. However, with constant, accurate and informed protection, you can maintain compliance, security and customer trust.

Tags: California Consumer Privacy Act (CCPA)GDPR
Previous Post

CCPA Update: Changes, Clarifications, But no Major Overhaul Heading to Governor’s Desk

Next Post

Employers Must Carefully Navigate Using AI in HR Functions

Iftah Gideoni

Iftah Gideoni

Iftah Gideoni is CTO of Forter, a fraud prevention solution provider. He is an experienced executive with a diverse technology background. Prior to Forter, Iftah served as Chief Data Officer and VP of R&D at myThings. Before that, he led a portfolio of research projects for the Australian national research agency, CSIRO. In the past, he was the VP of R&D, CTO of B.V.R. Systems and CTO of Proxy Aviation Inc.

Related Posts

us flags on wall street

A Field Guide to Privacy Law for Companies Entering the US Market

by Kevin Coy and Erin Doyle
July 20, 2026

Businesses wanting to operate in the US have a variety of laws and regulations to consider

data privacy concept human figure padlock

Data Privacy Rules Built for Human Behavior Have an AI Agent Problem

by Srikanth Sallaka
June 8, 2026

Regulators are beginning to treat under-governed AI deployments as intentional conduct

internet of things and cloud devices

EU Data Act: Time for a Reality Check

by Zach Judge-Raza and Jamie Elbert
March 17, 2026

New rules could spark compliance tension: share too much personal data run afoul of GDPR, share too little and face...

small child using smartphone

The US Is Not Alone in Regulating Children’s Data Privacy. Here’s a Primer on the Global State of Play.

by Ceren Canal Aruoba
February 2, 2026

Emerging policies extend beyond data privacy into product governance and algorithmic accountability

Next Post
illustration of robotic arm selecting man from row of candidates

Employers Must Carefully Navigate Using AI in HR Functions

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights