Media & Entertainment

Why Apple Pay Is Our Best Hope To Stop Online Fraud

Comment

Image Credits:

Pat Phelan

Contributor

Pat Phelan is CEO and co-founder of Trustev.

Heists used to be so much effort — you’d need a gang, machine guns, a getaway car and long, meticulous planning. Nowadays, all you need is a couch, a laptop and some stolen data. When the barrier to entry is so low, it’s no surprise that online fraud is a huge problem. In fact, according to the authoritative annual True Cost of Fraud report from LexisNexis/Javelin Group, fraud losses as a percentage of revenue for retailers grew to 1.32 percent in 2015, nearly doubling from 2014.

To make matters worse, the past year has been a perfect storm for online criminals, which will sharply escalate the rate of e-commerce fraud in the coming years. Hacks of T-Mobile/Experian, Ashley Madison, Chase, Anthem Blue Cross, OPM and many more released huge amounts of sensitive personal data like names, addresses, email addresses, phone numbers and social security numbers onto the dark web.

These PII (personally identifiable information) leaks were compounded by payment data leaks: millions of credit card numbers released in the Target and Home Depot hacks, plus other data raids. Together, fraudsters have more than enough material to paint a full picture of an individual’s financial identity, enabling them to apply for loans, lines of credits and other financial products, as well as order goods online, fraudulently, in someone else’s name.

With all these hacks, it makes sense that financial institutions are bolstering security. The EMV deadline is just that — now that the deadline has passed, brick-and-mortar retailers must have chip-enabled point-of-sale terminals, or be held liable for any fraudulent transactions that happen in their stores. The U.S. EMV liability shift is being hailed as a firewall against fraud; in reality, it’s nothing more than a half-measure taken by credit card companies and banks to protect themselves while leaving retailers holding the bag.

First, most point-of-sale terminals will require chip-and-signature, which is far less secure than chip-and-pin — a security shortcut chosen by the financial industry. And second, EMV will not fix the big growth area in fraud: the Internet. Past switches to EMV in countries like Australia and the U.K. show that fraud will simply migrate online as criminals look to exploit the next weakest target — sending a tidal wave of criminals straight toward unprepared online merchants.

When taken together, the situation for businesses looks bleak. To mitigate losses due to fraud over the long term, merchants and consumers alike need to move en masse to next-generation tokenized payment systems — which, like two-factor authentication to protect passwords, adds an extra barrier to the payment process, keeping sensitive data out of merchants’ fragile systems and safe from hackers.

And these payment systems haven’t been doing too well. Despite big promotion, use of Apple Pay is very low — a recent survey from the Aite Group found that it accounts for just 1 percent of all U.S. retail transactions. That’s still far above Android Pay (the product formerly known as “Google Wallet,” and now on its umpteenth rebranding) and Samsung Pay, which only launched recently.

This begs the question: What will it take to bring Apple Pay (or a similarly secure solution) mainstream, and save online merchants and banks from huge losses due to fraud?

Fix The User Experience

To change consumer behavior, it’s necessary to offer a product that is simpler than the most common option available. While this is something Apple has nailed in the past, they’ve yet to achieve this standard with Apple Pay. The March 2015 study from Phoenix Marketing International found that a whopping two-thirds of consumers who tried to use Apple Pay had issues paying both in-store and online, and only 48 percent decided to use the service again after their first try.

The SDK they’ve offered to developers results in inconsistencies to the user experience when used within third-party apps, leading many consumers to simply give up and stick with the simple practice of entering  their card digits instead. The problems are even more severe on computers — Apple Pay is not available in the browser, where the vast majority of online shopping takes place. This means that most e-commerce merchants aren’t benefitting from Apple Pay’s heightened security, leaving them susceptible to losses due to the avalanche of stolen credit card numbers.

These issues wouldn’t be as big of a problem if the incumbent payment methods hadn’t already nailed the simple user experience. Consumers have grown accustomed to the simple card swipe functionality at brick-and-mortar stores and credit card data entry for online purchases. But this process is hopelessly insecure.

Incentivize The Consumer

While wider accessibility and better user experience will certainly improve Apple Pay over time, it will be an uphill battle for the broader industry. Unfortunately, extra security isn’t enough of a selling point for the average consumer because, in most cases, they’re not liable for any fraudulent transactions that happen using their card or identity.

The reality is that consumers do not have a financial incentive to change behavior from the way things have always been done. Further, the banks have no incentive to change the status quo for online transactions as retailers are responsible for any fraud that happens there.

To drive adoption in the near-term, merchants need to incentivize consumers to use more secure payment systems. In addition, Apple should invest in strategies that mimic the popular options available with major credit cards. Options like cash back or rewards points will push consumers to use Apple Pay regularly, which will help drive adoption in the long run.

But this too has a problem. Apple’s margin on an Apple Pay transaction is reportedly 0.15 percent. Even if it rebated all that to consumers, it’s hardly a powerful incentive to switch.

These incentives don’t necessarily need to come from Apple alone. Merchants could offer discounts and rewards to customers who choose to pay with Apple Pay, rewarding them for using a more secure payment system. And Apple will apparently support this in the future. While it may marginally cut into their revenue in the short-term, they’ll see an impact on the bottom line due to lower fraud (and fewer chargebacks from banks).

Getting consumers to adopt secure payment solutions should be a priority for every online merchant in today’s fraud-heavy market. Apple Pay is an incredibly secure system that has serious potential to reduce online fraud — but that won’t matter if no one is using it. To stop the coming surge of fraud, it’s time for all parties to double-down on making secure payment systems work for the consumer.

More TechCrunch

The AI industry moves faster than the rest of the technology sector, which means it outpaces the federal government by several orders of magnitude.

Senate study proposes ‘at least’ $32B yearly for AI programs

The FBI along with a coalition of international law enforcement agencies seized the notorious cybercrime forum BreachForums on Wednesday.  For years, BreachForums has been a popular English-language forum for hackers…

FBI seizes hacking forum BreachForums — again

The announcement signifies a significant shake-up in the streaming giant’s advertising approach.

Netflix to take on Google and Amazon by building its own ad server

It’s tough to say that a $100 billion business finds itself at a critical juncture, but that’s the case with Amazon Web Services, the cloud arm of Amazon, and the…

Matt Garman taking over as CEO with AWS at crossroads

Back in February, Google paused its AI-powered chatbot Gemini’s ability to generate images of people after users complained of historical inaccuracies. Told to depict “a Roman legion,” for example, Gemini would show…

Google still hasn’t fixed Gemini’s biased image generator

A feature Google demoed at its I/O confab yesterday, using its generative AI technology to scan voice calls in real time for conversational patterns associated with financial scams, has sent…

Google’s call-scanning AI could dial up censorship by default, privacy experts warn

Google’s going all in on AI — and it wants you to know it. During the company’s keynote at its I/O developer conference on Tuesday, Google mentioned “AI” more than…

The top AI announcements from Google I/O

Uber is taking a shuttle product it developed for commuters in India and Egypt and converting it for an American audience. The ride-hail and delivery giant announced Wednesday at its…

Uber has a new way to solve the concert traffic problem

Here are quick hits of the biggest news from the keynote as they are announced.

Google I/O 2024: Here’s everything Google just announced

Google is preparing to launch a new system to help address the problem of malware on Android. Its new live threat detection service leverages Google Play Protect’s on-device AI to…

Google takes aim at Android malware with an AI-powered live threat detection service

Users will be able to access the AR content by first searching for a location in Google Maps.

Google Maps is getting geospatial AR content later this year

The heat pump startup unveiled its first products and revealed details about performance, pricing and availability.

Quilt heat pump sports sleek design from veterans of Apple, Tesla and Nest

The space is available from the launcher and can be locked as a second layer of authentication.

Google’s new Private Space feature is like Incognito Mode for Android

Gemini, the company’s family of generative AI models, will enhance the smart TV operating system so it can generate descriptions for movies and TV shows.

Google TV to launch AI-generated movie descriptions

When triggered, the AI-powered feature will automatically lock the device down.

Android’s new Theft Detection Lock helps deter smartphone snatch and grabs

The company said it is increasing the on-device capability of its Google Play Protect system to detect fraudulent apps trying to breach sensitive permissions.

Google adds live threat detection and screen-sharing protection to Android

This latest release, one of many announcements from the Google I/O 2024 developer conference, focuses on improved battery life and other performance improvements, like more efficient workout tracking.

Wear OS 5 hits developer preview, offering better battery life

For years, Sammy Faycurry has been hearing from his registered dietitian (RD) mom and sister about how poorly many Americans eat and their struggles with delivering nutritional counseling. Although nearly…

Dietitian startup Fay has been booming from Ozempic patients and emerges from stealth with $25M from General Catalyst, Forerunner

Apple is bringing new accessibility features to iPads and iPhones, designed to cater to a diverse range of user needs.

Apple announces new accessibility features for iPhone and iPad users

TechCrunch Disrupt, our flagship startup event held annually in San Francisco, is back on October 28-30 — and you can expect a bustling crowd of thousands of startup enthusiasts. Exciting…

Startup Blueprint: TC Disrupt 2024 Builders Stage agenda sneak peek!

Mike Krieger, one of the co-founders of Instagram and, more recently, the co-founder of personalized news app Artifact (which TechCrunch corporate parent Yahoo recently acquired), is joining Anthropic as the…

Anthropic hires Instagram co-founder as head of product

Seven orgs so far have signed on to standardize the way data is collected and shared.

Venture orgs form alliance to standardize data collection

As cloud adoption continues to surge toward the $1 trillion mark in annual spend, we’re seeing a wave of enterprise startups gaining traction with customers and investors for tools to…

Alkira connects with $100M for a solution that connects your clouds

Charging has long been the Achilles’ heel of electric vehicles. One startup thinks it has a better way for apartment dwelling EV drivers to charge overnight.

Orange Charger thinks a $750 outlet will solve EV charging for apartment dwellers

So did investors laugh them out of the room when they explained how they wanted to replace Quickbooks? Kind of.

Embedded accounting startup Layer secures $2.3M toward goal of replacing QuickBooks

While an increasing number of companies are investing in AI, many are struggling to get AI-powered projects into production — much less delivering meaningful ROI. The challenges are many. But…

Weka raises $140M as the AI boom bolsters data platforms

PayHOA, a previously bootstrapped Kentucky-based startup that offers software for self-managed homeowner associations (HOAs), is an example of how real-world problems can translate into opportunity. It just raised a $27.5…

Meet PayHOA, a profitable and once-bootstrapped SaaS startup that just landed a $27.5M Series A

Restaurant365, which offers a restaurant management suite, has raised a hot $175M from ICONIQ Growth, KKR and L Catterton.

Restaurant365 orders in $175M at $1B+ valuation to supersize its food service software stack 

Venture firm Shilling has launched a €50M fund to support growth-stage startups in its own portfolio and to invest in startups everywhere else. 

Portuguese VC firm Shilling launches €50M opportunity fund to back growth-stage startups

Chang She, previously the VP of engineering at Tubi and a Cloudera veteran, has years of experience building data tooling and infrastructure. But when She began working in the AI…

LanceDB, which counts Midjourney as a customer, is building databases for multimodal AI