Threat models

Gary Kao

Payment Village @ DEF CON 33 · Day 1 · Payment Village

Overview

In his talk at Payment Village, Gary Kao provided a comprehensive exploration of the intricate relationship between risk and payments across diverse industries. Titled "Threat models," the presentation delves into how financial incentives fundamentally drive decision-making in these critical business functions, often shaping the very survival of companies. Kao highlights that while payments teams typically focus on increasing conversion and introducing new options, and risk teams aim to minimize fraud and chargebacks, their ultimate alignment must be on the overarching financial health and longevity of the business.

Watch on YouTube

Visual summary for Threat models by Gary Kao
Visual summary for Threat models by Gary Kao

Key moments

  1. 0:50 Risk and Payments: Two Distinct Teams with Differing Incentives
  2. 2:15 Speaker's Career Journey and Payment Industry Challenges
  3. 3:45 Payments Analyst Day: Increasing Conversion with Cacao Pay
  4. 5:50 Payments Analyst: Cost, Refunds, and Local Payment Benefits
  5. 8:00 Risk Analyst's Primary Goal: Right of First Denial
  6. 8:45 Essential Risk Metrics: Chargebacks, Fraud Loss, Precision, Recall

Threat models

Speakers: Gary Kao

Conference: Payment Village

YouTube: https://www.youtube.com/watch?v=FScM78TlEfU

Overview

In his talk at Payment Village, Gary Kao provided a comprehensive exploration of the intricate relationship between risk and payments across diverse industries. Titled "Threat models," the presentation delves into how financial incentives fundamentally drive decision-making in these critical business functions, often shaping the very survival of companies. Kao highlights that while payments teams typically focus on increasing conversion and introducing new options, and risk teams aim to minimize fraud and chargebacks, their ultimate alignment must be on the overarching financial health and longevity of the business.

Kao's perspective, drawn from extensive experience in banking, digital streaming, and marketplace environments, underscores that security choices inevitably translate into economic choices. The core message is that making fraud an economically unviable activity for bad actors is paramount. The talk systematically dissects the unique challenges and strategies employed in low-ticket recurring digital services, travel, marketplaces, and card issuing, demonstrating how each industry, despite its distinct operational characteristics, converges on a shared financial North Star to mitigate existential risks.

Background

▶ Watch: Risk and Payments: Two Distinct Teams with Differing Incentives (0:50)

Gary Kao initiated his presentation by framing payments and risk as two distinct teams within any business, often possessing conflicting incentives. A payments analyst might prioritize launching new payment options like a local wallet to boost conversion rates, as exemplified by the introduction of Cacao Pay in South Korea to improve a 20% conversion rate. Conversely, a risk analyst is driven by the imperative to reduce chargeback rates to zero and eliminate fraud rates, seeking a "right of first denial" to intercept suspicious transactions before they even reach a payment processor. This inherent tension requires a unifying framework: financial incentives.

Kao's career journey provides a rich backdrop for these insights. He began in banking, helping financial institutions hedge FX risk. His subsequent 15-year tenure at a US DVD company during its transition to streaming, particularly its challenging expansion into the Latam region (where payments were dominated by installments and vouchers before Pix in Brazil), exposed him to severe fraud and payment complexities. Most recently, his work at marketplaces — platforms adept at rapidly and securely moving money between parties — solidified his understanding of the intersection of speed, security, and financial viability.

Risk teams, Kao explained, operate with a multitude of metrics: refunds, chargebacks (which must stay below 100 basis points to avoid Visa/Mastercard remediation programs), fraud loss or fraud to gross (realized fraud divided by gross merchandise value), and the efficacy measures of precision and recall for risk models. He noted that historically, recall (catching true positives) has often been prioritized over precision (minimizing false positives) because every successful fraud attempt represents a direct financial loss. For credit programs, write-offs and delinquencies (a leading indicator of future write-offs at 200 days) are crucial. Ultimately, however, these metrics are secondary to the primary goal: reducing existential financial risk. Kao presented a stark graph showing a company's monthly revenue plummeting to zero due to a financial event, emphasizing that financial risk consistently trumps other concerns like compliance or operational risk. The focus, therefore, must always be on the actual dollar amount, ensuring revenues grow and costs and losses are minimized.

Key Findings

▶ Watch: Payments Analyst Day: Increasing Conversion with Cacao Pay (3:45)

The central and most impactful finding of Gary Kao's talk is that financial incentives unequivocally drive decision-making in the payments and risk sectors, superseding all other secondary Key Performance Indicators (KPIs). He meticulously illustrated how the ultimate goal for any business is survival, which translates directly into minimizing financial losses and maximizing revenue. This economic imperative serves as the essential "North Star" that should align the often-conflicting objectives of payments and risk teams.

Kao demonstrated this principle across four distinct industries:

  1. Low-Ticket Recurring Digital: The focus here is on maximizing subscriber lifetime value (LTV) and revenue. Projects like localizing payments (e.g., Venmo, Kini, OXO, Gcash, Balletto), controlling free trials to mitigate card testing, reducing account sharing (e.g., Netflix household policies), and optimizing payment retries (e.g., retrying on Fridays due to payday) are all implemented to directly impact the bottom line, even if they sometimes add friction for users. The shift from allowing mid-month cancellations for partial refunds to providing service until month-end to capture full revenue is a clear example of this economic driver.
  1. Travel Industry: Characterized by high dollar values and average margins, the travel sector’s key finding is the need to manage supplier relationships and substantial chargeback liabilities. Strategies like Credit Card Authorizations (CCAs), MCC controls (Merchant Category Code), and detailed monitoring of booking patterns (e.g., lack of price sensitivity, rushed bookings, risky regions) are all geared towards reducing financial losses from fraud and chargebacks, which are often directly borne by the travel platform.
  1. Marketplaces: The unique finding in marketplaces is their dual-sided nature, where the primary focus is ensuring timely and secure disbursement of earnings to suppliers (drivers, couriers, sellers). Initiatives like co-brand cards (e.g., Uber card), instant payouts (up to 4-5 times a day), robust manual onboarding for high-value suppliers, and financial products like wallets and lending (with careful management of defaults) are all designed to enable more supply and monetize the platform's ecosystem, directly impacting earnings and revenue share. Strategies like refunding as credit (a "closed-loop gift card" strategy) are direct financial plays to retain funds on the platform.
  1. Card Issuing: With the democratization of card issuing (e.g., Stripe, Adyen), the key finding is the critical importance of sophisticated underwriting, real-time transaction controls, and robust Know Your Customer (KYC)/Know Your Business (KYB) processes to combat high-velocity fraud, BIN attacks, and Account Takeovers (ATOs). The financial exposure from an ATO on a million-dollar spend limit account necessitates dynamic rules and stringent verification processes, as any loss directly impacts the issuer.

Kao synthesized these industry-specific insights into a heat map, visually representing the financial risk associated with different business models. He concluded that card issuing and marketplaces generally represent the riskiest businesses from a financial standpoint due to the higher potential for loss from events like account takeovers or synthetic ID fraud compared to, for instance, a digital subscription service. This overarching emphasis on the financial impact, rather than isolated security or payment metrics, serves as the talk's most critical takeaway.

Technical Deep Dive

▶ Watch: Payments Analyst: Cost, Refunds, and Local Payment Benefits (5:50)

Gary Kao's talk provided a granular look into the technical and operational strategies employed by payments and risk teams across various industries, all unified by their economic impact.

In the low-ticket recurring digital space, the technical implementation revolves around optimizing conversion while mitigating fraud. For instance, when expanding to South Korea, a payments analyst would identify popular local payment methods like Cacao Pay – an all-in-one app offering messaging and payments. Integrating such a solution, often involving local Payment Service Providers (PSPs) like Inysis or Korea Cyber Payment (alongside global players like Stripe, Adyen, or Braintree), is crucial. The technical benefits include simplified checkout flows, often incorporating Face ID or PIN for authentication, which inherently reduces fraud risk for the local payment method. From a cost perspective, negotiating rates (e.g., 15 cents plus 300 basis points), presenting in local currency (Korean Won) to increase conversion, and settling in the same currency to save on foreign exchange costs are key. Critically, local payment options like Cacao Pay often lack chargebacks, simplifying operations and reducing financial liability. Their 5-day settlement delay is also technically advantageous for risk teams, allowing time for investigation and transaction stoppage. Projects include integrating various local wallets (e.g., Venmo in the US, Kini and OXO in Japan/Mexico, Gcash in the Philippines, Balletto in Brazil) and implementing sophisticated logic for free trial management. This includes detecting card testing and enforcing rejoin policies (e.g., if a user streams for 10 minutes, they don't get another free trial), which are technical rules to prevent revenue loss. Retry optimization involves algorithms that intelligently re-attempt failed payments, for example, on Fridays when US users are typically paid, to improve approval rates for insufficient funds.

The travel industry employs technical solutions to manage high-value transactions and complex supplier relationships. Credit Card Authorizations (CCAs), historically paper-based, have evolved into one-time use virtual cards. While faxes remain a less secure option, securing email communication and digitizing the entire authorization process prevents card misuse. MCC controls are technically implemented rules that ensure corporate cards are spent only at specific merchant categories like hotels or timeshares, preventing unauthorized spending. Fraud detection in travel relies on analyzing booking metadata: lack of price sensitivity (suggesting a stolen card), bookings in known risky airports and regions, and rushed bookings (e.g., 1-2 days in advance vs. a corporate policy of two weeks). Advanced systems integrate travel policy rules directly into the payment flow, allowing for dynamic declines or flags based on flight duration (e.g., over six hours), department, or individual spending limits.

Marketplaces are technically complex due to their two-sided nature and focus on disbursement. The integration of co-brand cards (e.g., the Uber card) involves revenue-sharing agreements with issuing banks and networks. Instant payouts, delivering funds to suppliers four or five times a day instead of weekly, require robust real-time payment rails and reconciliation systems. Manual onboarding for high-value suppliers, while seemingly low-tech, is a strategic choice to secure the best talent who may not engage with digital-only processes. On the fintech side, implementing wallets for storing funds allows the marketplace to earn interest, necessitating secure fund management and regulatory compliance. Lending programs require sophisticated risk models to manage defaults. The strategy of refunding as credit (a closed-loop gift card) keeps funds within the platform's ecosystem, requiring internal ledger management. Furthermore, marketplaces often offer third-party gift cards (e.g., for Walmart, Amazon, Home Depot), earning a revenue share, which involves integrating with various gift card providers.

Finally, card issuing, now democratized by platforms like Stripe and Adyen, features sophisticated technical controls. Underwriting for businesses like a dental office involves authenticating bank and financial statements, requiring tools to detect doctored documents (e.g., an '8' changed to '88'). KYC/KYB processes are technically advanced, checking domain authenticity, individual risk scores, email validity, and cross-matching data points to ensure proper identity verification. Combatting BIN attacks (brute-forcing the rest of the PAN after identifying a BIN) requires real-time velocity checks and fraud detection algorithms. Protecting against ATOs on high-limit corporate cards (potentially million-dollar spend limits) is paramount, necessitating multi-factor authentication and continuous monitoring. Transaction controls and dynamic rules, akin to what American Express (MX) offers, allow for real-time risk assessment at the point of transaction, enabling high or no limits based on current risk posture. Expense policy enforcement is achieved through APIs or UIs that configure granular rules on the card itself, whether physical or virtual. Kao presented code snippets illustrating how these rules can be set: for example, locking a card for car rental agencies up to $8,000 per authorization or limiting spending at fast-food restaurants to $4,000 weekly. These programmable controls represent a significant technical advancement in preventing leakage and loss.

Demo / Proof of Concept

▶ Watch: Risk Analyst's Primary Goal: Right of First Denial (8:00)

While Gary Kao's presentation did not include a live, interactive demonstration or a traditional proof of concept (PoC) in the software development sense, it effectively used illustrative examples and visual aids to convey its technical points. The talk featured several real-world scenarios and data representations that functioned as conceptual "proofs" for his arguments.

For instance, Kao presented a chart of a real company's monthly revenue over time, vividly demonstrating how a single financial event could bring revenues to zero. This served as a powerful visual "proof" of the existential nature of financial risk. Similarly, the "heat map" illustrating the financial risk levels across different industries (low-ticket recurring digital, travel, marketplaces, card issuing) provided a clear, data-driven visualization of his key finding regarding the varying risk profiles.

Furthermore, Kao included two specific code snippets in Markdown format during the Card Issuing section. These snippets showcased how modern API-driven card issuing platforms allow for highly granular, programmatic control over card usage, such as setting spending limits by MCC (e.g., car rental agencies up to $8,000 per authorization) or weekly spending limits for specific merchant categories (e.g., fast food up to $4,000 weekly). While not a live demo, these code examples served as concrete technical illustrations of the configurable rules and dynamic controls he described, proving the feasibility and specificity of such implementations in real-world corporate card programs.

Therefore, while no traditional demo was performed, the presentation's use of real-world examples, data visualizations, and code snippets effectively communicated the practical application and technical underpinnings of his discussion points.

Defensive Implications

▶ Watch: Essential Risk Metrics: Chargebacks, Fraud Loss, Precision, Recall (8:45)

Gary Kao's talk offers crucial defensive implications for security and risk teams, emphasizing a holistic, financially-driven approach to protection. Defenders must first internalize that all security decisions have an economic impact and align their strategies with the business's financial North Star: survival and profitability.

  1. Holistic Financial Risk Assessment: Shift from siloed security metrics to understanding the direct financial impact of vulnerabilities and fraud. Prioritize defending against existential financial risks over lesser threats. The "heat map" presented by Kao indicates that card issuing and marketplaces generally carry higher financial risk, suggesting these areas warrant increased defensive investment, particularly against Account Takeovers (ATOs) and synthetic identity fraud.
  1. Optimize Payment Method Security and Conversion: For digital businesses, strategically integrating local payment options like Cacao Pay, Venmo, or Gcash can significantly reduce chargeback liability compared to card-not-present transactions. Defenders should collaborate with payments teams to ensure these integrations are secure, leveraging native authentication methods like Face ID or PIN where available, and understanding the operational benefits of longer settlement delays (e.g., 5 days) for fraud investigation.
  1. Robust and Adaptive Onboarding (KYC/KYB): For marketplaces and card issuers, strong Know Your Customer (KYC) and Know Your Business (KYB) processes are non-negotiable. Defenders need to implement advanced verification tools that check for the authenticity of bank documents, cross-reference domain, email, and individual risk data, and detect sophisticated fraud like synthetic identities. The importance of manual onboarding for high-value suppliers also highlights the need for secure, in-person verification processes where digital methods fall short.
  1. Advanced Fraud Detection and Prevention:
  • Real-time Scoring: Implement systems capable of making risk decisions within 200 milliseconds during checkout, allowing for immediate denial or escalation.
  • BIN Attack Detection: For card issuers, deploy sophisticated analytics to identify and block brute-force attacks on card numbers (PANs) originating from known BINs.
  • ATO Prevention: Invest heavily in multi-factor authentication, behavioral analytics, and continuous monitoring to detect and prevent ATOs, especially on high-limit accounts where losses can reach million-dollar figures.
  • Dynamic Rules: Utilize transaction controls and dynamic rules, similar to American Express, that assess risk at the time of transaction rather than relying on static limits.
  1. Granular Policy Enforcement: Leverage API-driven controls for corporate cards and travel bookings. Implement MCC controls, spend limits (daily, weekly, monthly, or per-authorization), and policy-based restrictions (e.g., flight duration, department budgets) to prevent misuse and reduce leakage. The ability to programmatically lock cards to specific merchant types or spending thresholds, as demonstrated by the code snippets, is a powerful defensive mechanism.
  1. Continuous Monitoring and Adaptation: Fraud vectors evolve rapidly. Defenders must continuously monitor for new patterns, adapt their risk models, and update their policies. The shift in free trial policies, account sharing enforcement, and retry optimization strategies are examples of businesses adapting to new fraud types and optimizing for revenue.

By integrating these defensive strategies, security and risk teams can move beyond merely reacting to threats, proactively shaping an environment where fraudulent activities yield a low Return on Investment (ROI) for attackers, thereby safeguarding the business's financial viability.

Key Takeaways

  • Financial Incentives Drive All Decisions: The paramount takeaway is that all security and payment choices ultimately translate into economic decisions. Businesses prioritize financial survival, which should be the guiding "North Star" for both payments and risk teams.
  • Risk and Payments Must Align: Despite their often conflicting immediate goals, risk and payments teams must align on reducing existential financial risk and maximizing profitable revenue. Secondary KPIs are less important than the direct financial impact.
  • Industry-Specific Risk Profiles: Different industries (recurring digital, travel, marketplaces, card issuing) have distinct financial risk profiles and require tailored defensive strategies. Card issuing and marketplaces generally present higher financial exposure.
  • Robust Fraud Prevention is Economic Survival: Implementing advanced fraud detection (e.g., real-time scoring, BIN attack detection, ATO prevention) and strong KYC/KYB processes is critical. The cost of not preventing fraud (e.g., million-dollar ATOs) far outweighs the investment in sophisticated defenses.
  • Leverage Technology for Granular Control: Modern payment platforms offer powerful tools like API-driven transaction controls, dynamic rules, virtual cards, and MCC-specific spending limits. Utilizing these technologies allows for precise management of financial exposure and policy enforcement.
  • Continuous Adaptation is Essential: The fraud landscape constantly evolves. Businesses must continuously adapt their payment strategies, risk models, and security policies (e.g., free trial management, account sharing controls, retry logic) to stay ahead of bad actors and optimize financial outcomes.

About the Speaker(s)

Gary Kao is a seasoned expert in the realm of payments and risk, with a career spanning over 15 years dedicated to understanding and mitigating financial threats within complex ecosystems. He began his journey in traditional finance, working at a bank where he assisted corporates and financial institutions in hedging their FX risk. This foundational experience provided him with a deep understanding of financial markets and risk management principles.

His career then transitioned into the burgeoning digital space, where he spent a significant period at a major US DVD company as it pivoted towards streaming services. Here, he played a crucial role in international expansion, notably tackling the challenging fraud and payment landscapes in regions like Latam, which presented unique complexities with installments and vouchers before the advent of modern payment solutions like Pix in Brazil. Most recently, Gary has applied his expertise to marketplaces, platforms renowned for their ability to move money quickly and securely between multiple parties. His diverse experience across banking, digital subscriptions, and marketplaces has given him a comprehensive perspective on how financial incentives drive the intricate dance between payments innovation and risk mitigation in today's global economy.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent practitioner survey of payments fraud economics across four verticals, delivered by someone who clearly lived these problems. Solid industry experience, but the talk is fundamentally a well-organized overview rather than novel research — the kind of thing that belongs in a payments onboarding curriculum, not a conference program.

Heather Calloway (CISO) — SOLID

Gary Kao delivers a practitioner's tour of fraud and payments economics across four industries, grounded in real operational experience. The financial-incentives-as-North-Star framing is useful, but the talk stays inside the operator layer and never reaches the governance or institutional accountability questions that would make it relevant above the team level.

→ Top-rated talks at Payment Village @ DEF CON 33

All talks from Payment Village @ DEF CON 33