{"id":586254,"date":"2026-07-15T03:09:20","date_gmt":"2026-07-15T03:09:20","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/586254\/"},"modified":"2026-07-15T03:09:20","modified_gmt":"2026-07-15T03:09:20","slug":"mobile-wallets-cant-tell-a-privacy-guard-from-a-fraudster","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/586254\/","title":{"rendered":"Mobile Wallets Can\u2019t Tell a Privacy Guard From a Fraudster"},"content":{"rendered":"<p><a href=\"https:\/\/www.pymnts.com\/tag\/fraud\/\" target=\"_blank\" rel=\"noopener nofollow\">Fraudsters<\/a> and <a href=\"https:\/\/www.pymnts.com\/tag\/privacy\/\" target=\"_blank\" rel=\"noopener nofollow\">privacy<\/a>-conscious consumers have one thing in common. Neither wants to be easily found.<\/p>\n<p>For years, that overlap didn\u2019t matter much. Privacy-minded consumers wanted to limit their data exposure and control how merchants stored their credentials. Fraudsters wanted to hide stolen identities and card numbers. Different motives, different corners of the system.<\/p>\n<p><a href=\"https:\/\/www.pymnts.com\/tag\/digital-wallets\/\" target=\"_blank\" rel=\"noopener nofollow\">Digital wallets<\/a> pulled those two worlds into the same room. And they did it at the one point in the flow where the industry was looking the other way. Provisioning. The card gets added to the wallet before a single dollar moves, and that\u2019s where the two groups start to look identical.<\/p>\n<p>\u201cOnce the fraudster gets through the provisioning system, they look clean,\u201d <a href=\"https:\/\/www.lithic.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Lithic<\/a> CEO <a href=\"https:\/\/www.linkedin.com\/in\/boling\/\" rel=\"nofollow noopener\" target=\"_blank\">Bo Jiang<\/a> told <a href=\"https:\/\/www.pymnts.com\/\" rel=\"nofollow noopener\" target=\"_blank\">PYMNTS<\/a> CEO <a href=\"https:\/\/www.linkedin.com\/in\/karenwebsterboston\/\" rel=\"nofollow noopener\" target=\"_blank\">Karen Webster<\/a>. \u201cThat token looks legitimate to every provider downstream, and it\u2019s not really being scrutinized or checked in the same way. They have a longer lead time\u201d than they historically had.<\/p>\n<p>That is the shift the industry hasn\u2019t fully absorbed. Most fraud investment sits on authorization because for years the transaction was the risky moment. Wallets moved the risk earlier. A credential that clears provisioning wears a clean face for the rest of its life. The add-to-wallet decision is now as important as the purchase, and it\u2019s less examined.<\/p>\n<p><strong>Why More Data Doesn\u2019t Fix It<\/strong><\/p>\n<p>The obvious instinct is to collect more. Jiang said that doesn\u2019t work because the privacy-conscious customer and the fraudster generate the same signals. A new device, an unfamiliar location, a request to provision a card. For one person, that\u2019s Tuesday. For another, it\u2019s an attack. The surface data reads the same either way.<\/p>\n<p>Lithic learned this the hard way when building the first iteration of the brand, <a href=\"https:\/\/www.privacy.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Privacy.com<\/a>, the consumer service that lets people generate virtual cards, cap where those cards can be used, and share less with merchants.<\/p>\n<p>\u201cThe value proposition attracts privacy-conscious customers who happen to look exactly like fraudsters if you\u2019re just looking at the data,\u201d Jiang said. \u201cThat forced us to look at the problem through a new lens and separate out the intent from the surface level of the data.\u201d<\/p>\n<p>That intent is the whole game, and intent doesn\u2019t live in the wallet. It lives with the issuer, Jiang said. Banks and FinTechs are the ones who actually know the customer.<\/p>\n<p>\u201cThe issuer\u2019s own data in the room when you\u2019re making the decision around whether provisioning occurs or not,\u201d Jiang said.<\/p>\n<p>A request first clears Lithic\u2019s own fraud rules, then moves to the issuer\u2019s decisioning layer, \u201cwhere they can approve, decline or trigger a step-up using device history, behavioral patterns and customer context,\u201d Jiang said. \u201cThat\u2019s data no one else in the stack really has.\u201d<\/p>\n<p><strong>The Cost of Guessing Wrong<\/strong><\/p>\n<p>Both mistakes are expensive. Wave a fraudster through, and they now have a clean token and a long runway before anyone notices. Block a legitimate customer because a model mistook privacy for risk, and you don\u2019t look more <a href=\"https:\/\/www.pymnts.com\/tag\/security\/\" target=\"_blank\" rel=\"noopener nofollow\">secure<\/a> to them. You look broken.<\/p>\n<p>How do tighter provisioning controls stop fraud without shutting out the real customers who happen to look suspicious?<\/p>\n<p>Make the models sharper, not stricter, Jiang said.<\/p>\n<p>\u201cThere is no silver bullet,\u201d Jiang said. \u201cOur job is to give issuers the tools to stop fraud and the tools to validate how their custom logic is performing. We have shadow mode and backtesting, so an issuer can run these rules against live traffic without affecting real outcomes or against historical data to see what would have happened before going live. The hope there is that they can implement these controls without finding out about false positives by losing real customers.\u201d<\/p>\n<p><strong>The Wallet Becomes the Gatekeeper for Agents<\/strong><\/p>\n<p>This gets harder, not easier, as wallets stop being places to store credentials and start acting as permission layers for artificial intelligence-driven commerce.<\/p>\n<p>Consumers seem willing to let a wallet stand between them and an autonomous agent, but not to hand over control of how that agent spends, Webster said.<\/p>\n<p>\u201cConsumers still want the control, so they still want the ability to control lots of different things that are happening around the transaction, but the wallet is this trusted way of standing between an agent and the consumer,\u201d Webster said.<\/p>\n<p>Custom tokenization logic can de-risk agentic commerce as those controls offer guardrails before a payment, and not just protections during the moment of authorization, Jiang said.<\/p>\n<p>\u201cThe ability to say, \u2018I\u2019m going to give an agent a card,\u2019 and set a limit at the card level before any of this happens,\u201d Jiang said. \u201cThe key for all of this comes back to proactively giving the customer both a real feeling of control and the interface to do so.\u201d<\/p>\n<p>Which brings the problem back to where it started. The wallet can\u2019t tell the privacy guard from the fraudster by looking. It must know why. The only place that answer lives is with the issuer who already knows the customer, in the moment the card gets added.<\/p>\n<p>For all PYMNTS digital transformation coverage, subscribe to the daily <a href=\"https:\/\/pymnts.com\/subscribe\/\" rel=\"nofollow noopener\" target=\"_blank\">Digital Transformation Newsletter<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"Fraudsters and privacy-conscious consumers have one thing in common. Neither wants to be easily found. For years, that&hellip;\n","protected":false},"author":2,"featured_media":586255,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[257],"tags":[7436,18,13,12668,19,17,279,5,824,1351,983,82],"class_list":["post-586254","post","type-post","status-publish","format-standard","has-post-thumbnail","category-mobile","tag-digital-wallets","tag-eire","tag-featured-news","tag-fraud","tag-ie","tag-ireland","tag-mobile","tag-news","tag-privacy","tag-pymnts-news","tag-security","tag-technology"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ie\/116921798705608201","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/586254","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=586254"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/586254\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/586255"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=586254"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=586254"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=586254"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}