APRP Emerging Payment Risks 5 — Questions and Answers
Question 1: What is 'synthetic identity fraud' and why has it become more prevalent with the shift to digital onboarding?
- Fraudsters combine real and fabricated PII to create fictitious identities that pass automated digital verification checks (Correct answer)
- Stolen physical IDs are used to open accounts in person at bank branches bypassing digital controls
- Malware intercepts identity verification selfies to replace them with deepfake images during onboarding
- Fraudsters use VPNs to appear in different geographies when applying for payment accounts online
Correct answer: Fraudsters combine real and fabricated PII to create fictitious identities that pass automated digital verification checks
Synthetic identities blend real SSNs (often from children or deceased individuals) with fabricated names and addresses, and digital onboarding's reliance on database checks rather than face-to-face verification makes detection harder.
Question 2: Under the FTC's INFORM Consumers Act, what new risk compliance obligation does it create for high-volume third-party marketplace sellers?
- Marketplaces must collect, verify, and disclose high-volume seller identity and bank account information to consumers (Correct answer)
- Sellers must register as money transmitters if they process over $10,000 monthly in marketplace transactions
- Marketplaces must escrow seller funds for 180 days to cover potential consumer fraud claims
- High-volume sellers must obtain a Payment Card Industry certification before listing products
Correct answer: Marketplaces must collect, verify, and disclose high-volume seller identity and bank account information to consumers
The INFORM Consumers Act requires online marketplaces to collect and verify government ID, bank account, and tax information from high-volume third-party sellers and disclose certain seller information to consumers.
Question 3: A neobank issues prepaid debit cards with pass-through FDIC insurance. Which risk scenario could cause that FDIC coverage to fail?
- The program bank fails to maintain properly segregated sub-accounting records identifying each cardholder's beneficial ownership (Correct answer)
- The prepaid card network (Visa/Mastercard) becomes insolvent before settlement occurs
- The neobank's mobile app suffers a data breach exposing cardholder PII to attackers
- The cardholder exceeds the prepaid card's monthly spending limit set by the program manager
Correct answer: The program bank fails to maintain properly segregated sub-accounting records identifying each cardholder's beneficial ownership
Pass-through FDIC insurance on pooled accounts requires the program bank to maintain accurate records of each beneficial owner's balance; without proper sub-accounting, the FDIC may treat all funds as one uninsured entity account.
Question 4: Which emerging fraud vector specifically exploits the 'Request for Payment' (RfP) feature in real-time payment systems?
- Fraudsters impersonate legitimate billers and send fraudulent RfP messages to trick consumers into authorizing payments (Correct answer)
- Hackers intercept RfP messages and modify the payment amount before the consumer approves
- Criminals flood the RfP system with requests to cause denial of service at financial institutions
- RfP messages are used to harvest account routing numbers for subsequent ACH fraud schemes
Correct answer: Fraudsters impersonate legitimate billers and send fraudulent RfP messages to trick consumers into authorizing payments
Fraudsters send RfP messages impersonating utilities, government agencies, or known contacts to manipulate victims into approving fraudulent real-time payments they believe are legitimate bills.
Question 5: What risk does 'super-app' payment ecosystems (e.g., WeChat Pay model) present that regulators are most concerned about in the US context?
- Concentration of financial, commerce, and social data in a single platform creating systemic and surveillance risks (Correct answer)
- Inability to process cross-border transactions under existing MSB licensing frameworks
- Super-apps bypassing EMV chip card standards by using QR code payments exclusively
- Consumer confusion over which entity holds FDIC-insured funds within the super-app
Correct answer: Concentration of financial, commerce, and social data in a single platform creating systemic and surveillance risks
Super-apps consolidate payments, social media, commerce, and communications, creating unprecedented data concentration risks, systemic failure exposure, and potential surveillance capabilities that concern US regulators.
Question 6: In the context of quantum computing threats to payments, which cryptographic standard used in current payment security is most immediately vulnerable?
- RSA and elliptic curve cryptography (ECC) used in TLS and EMV chip authentication (Correct answer)
- AES-256 symmetric encryption used for at-rest card data encryption
- SHA-3 hashing used in payment transaction integrity checks
- HMAC-based message authentication codes used in API security
Correct answer: RSA and elliptic curve cryptography (ECC) used in TLS and EMV chip authentication
Quantum computers running Shor's algorithm can break RSA and ECC asymmetric encryption, which underpins TLS connections and EMV chip cryptograms, making these the most urgent targets for post-quantum migration.
Question 7: A payment network mandates 3DS2 for card-not-present transactions. Which emerging fraud tactic has evolved specifically to defeat 3DS2's risk-based authentication?
- Device fingerprint farming where fraudsters condition devices to appear low-risk before executing fraud (Correct answer)
- SQL injection attacks against the 3DS server's authentication database
- Phishing attacks that steal the static 3DS password shared during enrollment
- Card skimming devices that capture the dynamic 3DS token during e-commerce checkout
Correct answer: Device fingerprint farming where fraudsters condition devices to appear low-risk before executing fraud
Fraudsters 'season' devices by using them for legitimate transactions over time to build a trustworthy device fingerprint, then exploit the low-friction frictionless flow when committing fraud.
What is 'synthetic identity fraud' and why has it become more prevalent with the shift to digital onboarding?