Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecurityCybersecurity News

Mobile application fraud & abuse: Four things you need to know

By Justin Lie
app-development-freepik.jpg
September 21, 2021

Every day a new app shows up for download. To be exact, the Apple store adds about 30,000 new ones each month. And around 3,700 each day are added to the Google Play store. And because developers want to encourage use and monetize their investment, many offer options such as e-commerce capabilities – from in-app purchases to shopping and more. With increased functionality so widespread, it’s no surprise that global consumers spend an average of 4.2 hours per day using apps on their smartphones. 

But there’s no rose without a thorn. Fast-growing apps can experience tremendous success. Meaning the growing popularity of mobile applications makes them a ripe target for fraudsters. However, expanding your business to include new features and products expands your attack surface and gives fraudsters more ways to target them. Remember when Uber was just a ride-hailing company? Now it offers food delivery, courier services and e-bike rentals to more than 75 million users. The more your app provides, the harder it is to secure, and if cybercriminals get access to an account, the damage can be devastating.

The truth is that most businesses are unprepared for rapid success, and what they certainly aren’t prepared for is to be a target. The first step is knowing that the problem exists. Today, a significant number of fraudulent transactions now originate in the mobile channel. Businesses need to understand how fraudsters are exploiting apps to build a comprehensive mobile fraud prevention strategy. If you don’t, you’ll be the one out of the game. But here’s the thing, this isn’t your mother’s fraud prevention. Traditional cybersecurity tactics don’t work in this environment. 

Here are four things you need to know about mobile fraud and abuse and what you can do to stop it: 

1.      The shortest path isn’t the most obvious one. Online fraudsters like to take the shortest route. Mobile fraudsters might not. Online fraud is typically associated with making a quick buck and cashing out fast. When an online fraudster gains access to an account and payment details, they tend to act quickly before the credit card gets blocked. But in mobile fraud, cybercriminals tend to use more elaborate processes like creating fake accounts to take advantage of referral promotions. These attacks are harder to detect and often underreported.

 

2.      Mobile fraudsters steal less, more often. Conventional online fraudsters target expensive items to quickly max out a stolen credit card, costing businesses hundreds to thousands of dollars. For mobile applications, the amount defrauded in an individual attack is usually much less, often a few dollars, but fraudsters will launch many attacks at the same time. When replicated at scale using automated tools such as bot farms, losses can quickly amount to six or seven figures.

 

3.      Incentives for users are an incentive for fraudsters. User acquisition is a core part of every mobile app’s business strategy. As a result, businesses spend heavily on campaigns to boost the base. The problem is that you aren’t just targeting the good guys. You’re also incentivizing the bad guys. DoorDash recently offered a $15 bonus credit for each referral. An excellent offer for winning market share and beating the competition, right? Wrong if the promotion gets exploited by fraudsters who can set up fake accounts and abuse them. The only thing you wind up acquiring is little ROI on marketing spend.  

 

4.      Easy in, easy out. Fraudsters find it easier to attack mobile apps. Anyone can access the tools used to abuse or commit fraud on a mobile app, and new ones emerge each day. These malicious tools can change device profiles, spoof IP addresses, clone mobile apps, and more, enabling fraudsters to appear as if they are in a different location and using another device. 

 Knowing how cybercriminals think and where they can hide is the first step. The next is to ensure that you have a robust mobile fraud prevention strategy. Your strategy should include investing in tools specializing in identifying risk, specifically at the mobile app level. Tools that can identify good users from bad ones quickly – moving at the same speed of cybercriminals versus waiting for them to leave their mark. In other words, fast. 

And while you want your app to be in heavy rotation with your users, you also need to keep it safe and secure and protect your business from loss. Because if you don’t, your app goes from most downloaded to most deleted. 

KEYWORDS: cyber security fraud detection mobile security risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Justin Lie is the Founder and CEO of SHIELD. With over 20 years’ experience in the industry, Justin is one of the earliest pioneers of fraud prevention technology. Whilst running a cross-border e-commerce business as a teenager, he created his own system to combat online fraudsters that were attacking his websites. Over several years of research and development, Justin successfully created the world’s first risk intelligence company for mobile apps - SHIELD.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Revised NIST Cyber Security Framework - Security Magazine

    5 Things You Need to Know about the Revised NIST Cybersecurity Framework

    See More
  • sick-enews

    How Health Issues Can Impact Business Continuity - 5 Things You Need to Know

    See More
  • mobile

    Mobile Credentials: Why Should You Adopt Them and What You Need to Know

    See More

Related Products

See More Products
  • 150 things.jpg

    Physical Security: 150 Things You Should Know 2nd Edition

  • CPTED.jpg

    CPTED and Traditional Security Countermeasures: 150 Things You Should Know

  • 9780367221942.jpg

    From Visual Surveillance to Internet of Things: Technology and Applications

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing