the credit union connection logo white

Outsmarting the Scammers: How AI Is Giving Credit Unions Chase-Level Fraud Defense

CUC podcast with Yinglian Xie - DataVisor

In today’s fast-moving financial world, “real-time” is the baseline.

But while instant payment rails like RTP, Zelle, and e-transfers make sending money as effortless as dropping a meme into the group chat, they also hand fraudsters a hyper-speed express lane for high-tech heists.

So how can midsize and smaller credit unions keep member funds safe without draining the budget or turning a routine login into Mission: Impossible?

In the latest episode of The Credit Union Connection podcast, host Sarah Snell Cooke sits down with Dr. Yinglian Xie, co-founder and president for technology at DataVisor. Together, they pull back the curtain on today’s rapidly evolving threat landscape, the rise of slick AI-driven impersonation scams, and why scammers love targeting midsize institutions as “soft targets” (spoiler: it’s time to prove them wrong).

Don’t let bad actors write the playbook. Tune in to learn how your credit union can stay two steps ahead, safeguard member trust, and make modern fraud detection a seamless teammate for your crew!

NOTE: This transcript may contain minor imperfections courtesy of our AI overlords-in-training. We’re not complaining. We’re definitely not complaining.

Sarah Snell Cooke: Hello, and welcome everybody. I am, of course, Sarah Snell Cooke, your host here at The Credit Union Connection. I’m joined today by Yinglian Xie. Welcome.

Yinglian Xie: Hi, Sarah. Yeah, it’s my great pleasure to be here.

Sarah Snell Cooke: Yeah, it’s great to meet you. You’re the co-founder and president for technology of a company called DataVisor. Can you tell us a little bit more about yourself and the company?

Yinglian Xie: Definitely. DataVisor is an end-to-end, AI-powered fraud risk platform that is helping financial institutions, including banks, credit unions, and payment providers, to protect against a variety of different types of financial crimes. We support onboarding fraud, ACH, all kinds of transaction fraud, as well as card payment fraud.

Regarding myself, I have a technology background, and AI technology has always been my passion. I had a tech background as early as being a researcher after obtaining my PhD and served in a research role at Microsoft fighting large-scale fraud and abuse issues. Afterwards, we started DataVisor with the mission to serve everyone with cutting-edge technology.

Sarah Snell Cooke: It sounds really cool from what I understand. You guys recently signed on Tru Cooperative Bank, which is actually a credit union from Canada, correct? So you’re going to provide real-time fraud detection across onboarding, login, profile changes, and all the stuff you mentioned a bit ago. Can you define what real-time is in practice and how that happens?

Yinglian Xie: Yeah. When consumers think about real-time, many times we take for granted that a lot of things should happen in real-time. This is, in fact, the growing demand of payments being real-time, in particular with what we are seeing from modern payment apps like Venmo, PayPal, and Zelle bringing that real-time experience.

From our lens, real-time means instantaneous. When it comes to banks and credit unions, there are still different types of payments that fall into different landscapes, and not everything is real-time yet. But everybody is moving forward faster to meet customer real-time needs.

From a transaction perspective, card payment, which we use every day, absolutely is real-time. From an ACH perspective, traditionally it was batched, but now they are moving toward same-day ACH, and some banks have started offering instant ACH experiences. In Canada, they have e-transfers or e-payments, which is similar to the US experience of Zelle payments or RTP. Those are newer forms of payment that banks are working together on to provide a better experience to customers.

As the payment industry advances, we are truly moving toward real-time payment transfers. On the other hand, if you look at the tech stack, particularly from the lens of fraud protection, historical and legacy solutions are still not catching up simply because these newer forms of payments are still coming to be adopted.

Sarah Snell Cooke: And the bad guys are using AI on their end as well, so the good guys have to keep up with them. Some of the common attacks are unauthorized transactions, and now we’re getting more into impersonation scams, whether voice or visual, stolen cards, and all that kind of stuff.

Credit unions don’t care what size institution you are; in fact, fraudsters are probably going to see smaller institutions as softer targets, putting on my fraudster hat. Since credit unions are member-first and entrusted with keeping financial information secure, each loss feels harder because you know the members. You’re only serving this tight group of people. How can smaller institutions level that playing field so that they have Chase-level security, but maybe not the Chase-level price tag?

Yinglian Xie: Yes, definitely. For credit unions, a big differentiator is exactly what you commented about: that personal connection feel with the members, where the member experience is ultimately very important. Coming to this, we’re now swamped with all kinds of scam attacks and phishing attacks. It is becoming increasingly challenging for these credit unions—who have fewer technology spending dollars in comparison to big banks—to really be harnessed to fight these modern types of attacks.

From an attacker perspective, credit unions are one of their favorite targets for the exact reason you talked about. The attackers’ hope is that perhaps credit unions are not as sophisticated as bigger banks. For credit unions, they are more member-friendly and likely want to reduce friction for their customers to make it easier for transactions to go through and provide a better member experience.

At the same time, they have fewer IT staff and fewer operational reviewers among staff members. Another important thing is that credit unions sometimes don’t have a large amount of data to quickly see the wide footprint of different types of attacks and learn from them.

That said, at DataVisor, our mission is to provide these credit unions and midsize financial institutions with both the best technology and tech stack to fight fraud effectively. Second, we provide industry benchmark knowledge and consortium signals to help these credit unions so that even though they don’t see all types of attacks, providers like us do. We can harness that knowledge so credit unions don’t have to fight this alone. We work with a broad set of customers—credit unions, banks, and payment providers—so we constantly see what’s coming up. We combine that into our technology stack to turn it into domain knowledge that credit unions can benefit from.

Another area we specifically focus on from a vendor perspective is making the solution easier to consume. We can develop out-of-the-box solutions that provide the type of experience credit unions typically anticipate. Giving them a set toolkit and modern technology that is pre-configured well enough for them to take and build on top of quickly helps credit unions fight off these sophisticated fraud attacks.

Not to mention, AI is another big factor. AI agents significantly bridge the gap when institutions say, “We don’t have a huge team of tech staff to deal with this.” AI agents come into play to mitigate that gap.

Sarah Snell Cooke: Absolutely. At the same time, consumers don’t even realize it’s all going on in the background. They just see their transaction go through, which is great. With some systems now, everything gets marked as fraud and it gets irritating getting notifications all the time asking, “Is this you?” Being able to better identify those is so much easier on the consumer side, to do it right then as opposed to bugging the consumer or holding up payment.

One of the things that you all have that I thought was really interesting is that you built a suite of conversational AI agents for financial crime prevention. How does that work?

Yinglian Xie: In today’s world, fraudsters act really fast. Whenever they find a vulnerability, they can share that information instantly. We talk about new AI models coming up like Mythos that make everybody scared because if they fall into the hands of attackers, it can be devastating how fast things go in terms of digging out vulnerabilities and breaking systems. Fraudsters today are absolutely leveraging technology, and if we don’t do that, you see an imbalance in the game of protecting everyone. As consumers, we would worry whether our banks and service providers are leveraging the latest technology.

That’s where we bring in conversational AI, serving two main purposes:

Number one is to fight AI with AI. Only when we are able to act almost in real-time as an attack happens—discovering, defending, and protecting—are we on a level playing field. In many cases, we want to do things proactively by predicting what could happen before an attack launches into something real. DataVisor has technology called unsupervised machine learning specifically for detecting new, novel attacks and predicting sleeper cells. Conversational AI agents can look at the data, see what’s going on, and quickly come up with predictive ideas.

The second part addresses usability when things happen so fast. Normally, you need someone with a tech mindset to investigate, pull the right data, and operate cutting-edge platforms effectively. Sometimes that requires data analytics or programming knowledge. Even though our UI interface is low-code/no-code, you still have to go in and operate it. With conversational AI agents, things can be as easy as typing your questions or talking to them. You can talk to this fraud detection platform to ask it to investigate, identify attack patterns, and test mitigations immediately. That level of user-friendliness combined with intelligence dramatically changes the landscape of fighting fraud by giving you an intelligent partner to work with.

Sarah Snell Cooke: Yeah, easier for the layperson to understand how to use. You’re finding fraud at step one when the consumer is starting a new account online or logging in, rather than cleaning up the mess afterward. What other ways are there that this is better for not only the credit unions, but also the members?

Yinglian Xie: When we talk about AI agents and fraud detection, this is broadly applicable across a spectrum of financial institutions. In fact, we’ve seen our technology adopted across many different industries, like airlines, e-commerce, and shipping. Fraud is everywhere, and we are targeted by all kinds of scams around all areas.

The whole industry needs to have a sense of protection parameters that go beyond cybersecurity across all chains where there is potential money movement. Ultimately, consumers are the ones who need to be protected. Wherever there are financial gains, bad actors will try to leverage them. That is why real-time decisioning and protection capabilities need to go across a broad spectrum everywhere. As consumers, we don’t want to constantly worry about being scammed; we want to feel safety and trust. Ultimately, it’s the customer experience we hope to protect.

Sarah Snell Cooke: Absolutely. I imagine for whoever used to monitor screens to protect consumers, there’s a savings in time, and maybe using that employee for something more human-facing rather than just watching screens for fraud patterns.

Why is it so critical now to have real-time fraud detection?

Yinglian Xie: As technology paces and consumer expectations change, the default assumption is that things are going to move toward real-time. That is a market trend and a need. At the same time, fraudsters are also working in real-time. When they launch attacks, they are large scale and massive before moving to the next wave.

Both legitimate customer expectations and fraudster activity pressure the need for real-time protection. When money is gone through real-time channels like Zelle, it can be gone instantly. Now with RTP, where the threshold of wire transfers is significantly raised, millions of dollars can go to fraudsters if we don’t have real-time protection. That notion can be quite scary, so we need to step up protection in real-time as well.

Sarah Snell Cooke: There are definitely a lot of credit unions that won’t send on those types of transactions—they’ll receive, but they won’t send.

I always allow my guests to have the final thoughts. What would you like to leave our credit union audience with today?

Yinglian Xie: The landscape is changing fast. I’ve worked in the fraud industry for nearly 15 to 20 years, and one thing I’ve seen is that we are facing active, constantly evolving adversaries.

For any of us fighting against this, we need to have the same mindset. We cannot be static; we need to constantly look at how we are going to evolve. If we don’t evolve, we are instantly behind. Only when we move as fast as we can and adopt more advanced technology can we sit on the other side and have the upper hand.

Sarah Snell Cooke: Thank you so much for your time and expertise today, Yinglian. Appreciate it.

Yinglian Xie: Thank you so much. It’s great to be here.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top