Western Union admits to aiding wire fraud, to pay $586M
reuters.com
reuters.com
They really can't win here. If they allow anyone to send money anywhere, they get fined by the government for supporting criminals. If they try to make a judgment call, the public gets up-in-arms about it and thinks they are bigoted (and potentially lose customers or get involved in other lawsuits).
They could allow the transactions, but secretly support anything suspicious to government anti-terrorist agencies. They wouldn't get called racist because any transactions they block were at the behest of the government. They wouldn't get in trouble with the government because they're handing all their data to them. And customers wouldn't complain they're divulging private data customers people wouldn't know. It's a win-win-win.
Exactly: They report it to the authotities.
"Fraudsters offering fake prizes and job opportunities swindled tens of thousands of U.S. consumers, giving Western Union agents a cut in return for processing the payments, authorities said."
In other words, it's not that they are "allowing anyone to send money anywhere"; they didn't discipline their agents for taking a cut of known fraudulent transactions.
If it was just part of business, it would have been every agent right?
I don't see it. I'm reading the actual court documents now, which I found by googling and going to the FTC's website:
https://www.ftc.gov/news-events/blogs/business-blog/2017/01/...
https://www.ftc.gov/system/files/documents/cases/western_uni... - complaint
https://www.ftc.gov/system/files/documents/cases/western_uni... - final judgement, which includes way more than just the monetary fine.
https://consumermediallc.files.wordpress.com/2017/01/wufsi-a...
https://consumermediallc.files.wordpress.com/2017/01/western...
_________
And the related official DOJ announcement covering the agreement:
https://www.justice.gov/opa/pr/western-union-admits-anti-mon...
I either got skimmed at a gas pump or at a restaurant.
What I saw were 4 Western Union transactions on my card, each for $255 USD. Two per day with this string - "WU*XXXYYYZZZZ" - where XXXYYYZZZZ is a phone number.
My issuer shut down the card and issued me another one. I was not responsible for the charges.
Also, the issuer said the reason they did not send me a fraud message was because the charges were occurring around the holidays where large charges are commonplace.
You could always look for a less zealous credit card provider, but generally speaking, the entity that takes the liability should be able to set the bar for risk. Otherwise you get subsidized risk taking, which has a way of getting out of hand.
You may well find that credit card companies who are not very zealous about security are merely more successful at weaseling out of the liability that their customers assume they are taking.
At the end of the day, fraud creates costs, and you can be sure that SOMEONE is paying those costs. If your credit card company doesn't seem very zealous about preventing fraud, then it's more likely that you are the one who will ultimately pay when the bill comes due.
Disabling my card constantly doesn't help me at all, it's just a PITA. Imagine if any other service provider (webmail?) disabled your account frequently to "avoid fraud".
So you assume. Have you ever investigated credit card fraud? Perhaps there are edge cases that are more difficult than you imagine.
> Imagine if any other service provider (webmail?) disabled your account frequently to "avoid fraud".
Webmail is absolutely lousy with fraud. Webmail companies explicitly disclaim all liability... so... you kinda bolstered my point there. That is, you helped add the significant texture that companies that disclaim all fraud liability can be pretty lousy at preventing fraud.
To reiterate: The entity that accepts liability should be the entity that draws the line on what risks are acceptable.
Credit card companies are pretty unique in the types and magnitude of risk that they accept and manage. They already do quite a high wire act balancing fraud prevention against user convenience. And despite some things that seem inconvenient on the surface, they are typically still the most convenient way available, by a wide margin, to conduct most payment transactions.
THAT would cut fraud.
One out of three purchases was rejected, and I had to call them, wait in line like 10-20 minutes, and have them reactivate it. They kept saying it was "for my own protection", but I kept losing time constantly. This worse especially awful when I tried to catch an offer that ended by the time they fixed the issue.
Contrast this with American Express and Discover who both issue their own cards and handle the payment network. There's also third parties that issue AMEX cards (any maybe Discover, but I don't know of any)
So in other words, don't blame Visa, blame the bank.
If you really want to go hardcore there's card issuers that let you freeze and unfreeze your cards online/from their app, so you can keep it frozen until you are making a purchase.
It has helped me spot fraud last month, and it also acts as a quick check to make sure the amount charged was correct (very helpful in restaurants or the like).
Most banks, and most card companies offer this - for free. If yours doesn't, you might want to shop around for one that does.
They only accepted credit cards online and by phone. They required a ton of information in order to process it, often verifying items from your credit report. To pull it off you had to have a lot of info about the cardholder.
To those cheering here, you should remember this next time you try to open a bank account or make a payment, and your bank wants to see a thousand of proofs and certificates before moving a finger.
It's the KYC (CIP) and AML laws.
https://en.wikipedia.org/wiki/Know_your_customer
https://en.wikipedia.org/wiki/Customer_Identification_Progra...
https://en.wikipedia.org/wiki/Money_laundering#Anti-money_la...
> The Economist estimated the annual costs of anti-money laundering efforts in Europe and North America at US$5 billion in 2003, an increase from US$700 million in 2000.
> There is no precise measurement of the costs of regulation balanced against the harms associated with money laundering, and given the evaluation problems involved in assessing such an issue, it is unlikely that the effectiveness of terror finance and money laundering laws could be determined with any degree of accuracy.
> One commentator wrote that "[w]ithout facts, [anti-money laundering] legislation has been driven on rhetoric, driving by ill-guided activism responding to the need to be "seen to be doing something" rather than by an objective understanding of its effects on predicate crime. The social panic approach is justified by the language used—we talk of the battle against terrorism or the war on drugs".
https://en.wikipedia.org/wiki/Money_laundering
I'm curious if the drug war ended how much utility it would provide...
If thats the case, what might be easier is tell your bank "ok cancel the transfer", then get your brokerage's bank wire information, physically go to your bank, and initiate a "fed wire transfer" to your brokerage. Fed wire is like moving physical cash, it hits your account in minutes (not overnight like ACH usually is, and no "available balance" vs pending deposit bs)and is absolutely final. And if your bank refuses to move your money when you walk up in line and show them your ID, get a new bank.
My beef is with paypal: the company that wants to look and act like and do everything that a bank does, but without all those pesky bank regulations designed to protect the customer. I quit using them 10 years ago.
One model is that the authorities get all the info from Western Union and then do the filtering on their side. Then you need to trust the authorities to have all transaction data and use it responsibly. This is the model for, say, license plate reader data.
Another model is that filtering happens at Western Union's end, and only suspicious transaction data get reported.
I infinitely prefer the latter model, even if my bank ends up doing outsourced police work on the side, because at least it's my bank that has the data and not the cops.
Well, I think there is still a third option!
- Someone is still scanning e-mails, except now it's a judge and/or lawyers rather than cops or business
- Moving things to the legal system imposes potentially very high friction costs, since your bank/email provider presumably has context about their relationship with you that the judge (or law enforcement) doesn't have. As we all know, context switches are inherently expensive.
- Emails aren't exactly the same as transmitting money, because reading emails tends to violate more of your privacy than the metadata about who you send money to. Also it's illegal to, say, send money to finance terrorists, so some checking has to happen at some level no matter what. You can say 'get a warrant', but if cops don't have access to data, and banks can't look at who you send money to, then how can cops have sufficient data to find probable cause under which to ask for a warrant? You're putting law enforcement in a situation where it's impossible to lawfully fulfill their duties to the public, unless your model is literally that judges always get all data without a warrant, and a court decides what's suspicious.
You might think that the incremental improvement in liberty is worth the friction cost of having lawyers and judges run everything, but I'm not sure everyone would agree.
You are still starting from the assertion that every email has to be scanned for crime, that every financial transaction has to be investigated for fraud. I disagree with that. And where is the limit? Should the bank also check that the product you are trying to sell is compliant with the latest health & safety regulations and that you didn't violate environmental protection laws? The bank is potentially facilitating a crime if it isn't.
> Also it's illegal to, say, send money to finance terrorists
But it is not illegal to conspire to commit a terrorist attack by email or phone or mail?
> banks can't look at who you send money to
Banks always know who you send money to. Phone companies always know who you call. What banks do not need to know is why I am sending this money. What phone companies do not need to know is what I am discussing about.
> You're putting law enforcement in a situation where it's impossible to lawfully fulfill their duties to the public
Was it impossible to do their work before the internet when law enforcement had to get a warrant to open mail and tap phone lines?
> You might think that the incremental improvement in liberty is worth the friction cost of having lawyers and judges run everything
Again you are still stuck in the logic of either my phone company listens to my calls or the police listens to my calls. Well, neither unless they get a warrant. Same for my emails. Same for my mail. Same for my financial transactions. The content of my calls is none of the business of the phone company. The content of my emails is none of the business of my email provider. The reason for my transaction is none of the business of my bank.
The model of 'wait until someone complains, then get a warrant, then use that data to prosecute' simply doesn't work in practice, and the article notes exactly why. For criminal networks, by the time the judicial gears have started running, the criminals are long gone with their ill-gotten profits. For terrorist enterprises, it's easy and cheap to create puppet companies or non-profits to take donations, and prosecuting terrorists after they've used the money to commit violence is not acceptable to society.
> Should the bank also check that the product you are trying to sell is compliant with the latest health & safety regulations and that you didn't violate environmental protection laws?
No, because you can effectively punish companies that violate health and safety regulations after the financial transaction takes place. For scammers, that's not true.
You might think that having these crimes is simply the price of liberty, but I think many people would disagree. I don't think the rhetorical strategy of denying there is a problem, and claiming that policing strategies from 30 years ago will fix all the problems, is a reasonable one.
> Was it impossible to do their work before the internet when law enforcement had to get a warrant to open mail and tap phone lines?
Yes, because now criminals aren't communicating with mail and phone lines, they're using the internet, which is a completely different beast. You can't run a business like you did 30 years ago and succeed. You can't make a movie like you did 30 years ago and expect to succeed. What makes you so confident and sure that wiretap laws from 30 years ago can be perfectly and successfully applied to the internet today?
- Looking through financial metadata is a couple orders of magnitude less invasive than physically searching everyone's closet every week
All I'm saying here is there is actually a tradeoff between privacy and law-enforcement effectiveness. Of course we should think of ways to have both, but it is not always possible in every case. As engineers, that should be easy to understand.
If we're being honest with ourselves, we should admit that we're willing to pay a cost (perhaps even a substantial one) for greater privacy. We should then have a discussion about which costs we're willing to pay, for which particular forms of privacy, and how to get the most bang for our buck.
We should not simply pretend that the cost of upholding our liberal values is zero, as tempting as that might be rhetorically.
Yes, there are tradeoffs to be made, but existing due process, including warrants, is the legal manifestation of those very tradeoffs.
When police or FBI say that current laws and processes are insufficient to deal with a changed environment and they need help, I've seen that the left tends to demonize them, question their motivations (like of course cops want to set up a surveillance state), and then give a hand-wavy argument that 'well, getting a warrant worked in the past, so it must work fine today'. Basically accusing cops of lying about having problems, or lying about needing new tools and processes.
That doesn't seem very fair, and it's certainly not a way to have a constructive discussion. I mean, these two statements are basically the same:
1. You can't any trust climate scientists, because of course all they want is to scare you into giving them more funding and power
2. You can't any trust cops and the intelligence services, because of course all they want is to scare you into giving them more funding and power
IMHO both these statements are false. Even though they're imperfect, our cops and intelligence agencies by and large try to do right, and it'd be better to understand challenges from their perspective and come up with innovative, privacy-protecting ideas that work, rather than to blindly accuse them of malice when they suggest something that we disagree with.
If you think people are doing things wrong, first try help them do right.
- "We as a society" claims, painting your opponent as out of touch with society. I'd say instead that the ecosystem of recent U.S. politics has been favorable to actors gaining power on those grounds.
- Equating opposing surveillance to pretending the costs of liberty are zero. I didn't see anyone else claim that above, though maybe I should go back and reread it all.
You say "we as a society" but then posit something ridiculous. Regular everyday murderers kill orders of magnitude more Americans than terrorists. They are monsters of the same order and there are more of them. How is it that we have stood to tolerate them for centuries, but now this new threat (which is not actually new at all) suddenly requires a departure from our longstanding principles?
Terrorism isn't new, it isn't unique, it doesn't require an extraordinary response unlike that of every other category of bad in the world. It's just the boogey man du jour that has recently become highly profitable for a wide variety of fear mongers and demagogues.
Don't fear the terrorists. You're letting the terrorists win.
Jeffrey Dahmer wasn't a regular everyday murderer, he was a serial killer - a category which does not kill orders of magnitude more Americans than terrorists, and a distinction which is entirely apropos in this discussion because unlike regular everyday murderers, serial killers are generally quite hard to identify with usual police investigatory methods.
A cynic might speculate that politicians care more about terrorism because gangs kill predominantly poor people while terrorists often kill bankers and government officials.
It's not like they let the money sit around in the branch. Once it appears they send in the street rat to pick it up and run. These scams aren't just two bit crooks, they were straight up organized crime. It is an industry, one of the most productive in some areas.
To put it another way, just because terrorists could use unencrypted email to communicate doesn't mean we have to go and scan everyone's email for threats.
The logic is basically this: Terrorists now are communicating over encrypted p2p systems (or any new tech)! we need to backdoor encryption standards. Then! we will defeat the Terrorists (once and for all).
Crime works in a similar fashion. The police will never "solve crime" no matter how much power they have to invade your privacy. They will become great at catching criminals though.
Typical humans!
Good question.
I mean crime is going to happen right?
Evidence suggests so.
And the cops just trample all over your rights.
Indeed.
Why even bother having laws or society?
Agreed, especially considering that most of what passes for "law" these days is just statutory nonsense which has nothing to with the law[1] in the more general sense.
It just kills your freedom
Agreed.
How about a third way: rather than surveilling all of everyone's private data constantly, law enforcement gets warrants authorizing them to access private data in a limited manner for specific investigations.
They do have that data.
Most Western nations have financial intelligence agencies that require all bank transactions or money wires (if they're over $10,000) to be reported to them. I forget the American equivalent, but Canada has FINTRAC, where I interned a decade ago.
They have all the data. When you move any large sum of money anywhere, they get a report with your name, driver's license number, everything the bank knows about you basically. They can (and do) keep it for up to five years. Ever bought a house or car? A report is in their database, being scrutinized by analysts.
It's been like that for nearly two decades now. FINTRAC at least has seen some success and did major damage to the Montreal Mafia.
From the article, "wiring the money in smaller increments to avoid federal reporting requirements" means they knew why the customers were wiring $9999 twenty times rather then $200,000. They didn't care. That's why they're paying the fine.
I'd be curious to see whether or not the proliferation of retirement and investment funds that are geared to profit members in recent would have had an impact on that rising trend.
Did we read the same article?
>Western Union (...) admitted "to aiding and abetting wire fraud" by allowing scammers to process transactions, even when the company realized its agents were helping scammers avoid detection
Furthermore:
>Between 2004 and 2012, the Colorado-based company knew of fraudulent transactions but failed to take steps that would have resulted in disciplining of 2,000 agents, authorities said.
If the prosecutors were able to prove that WU was aware that the transactions were fraudulent your comment makes no sense. They didn't need to be "a quasi-law enforcement agency" because they already knew that the transactions were fraudulent.
I'm inclined to say on the record here that actively assisting and rendering aid to someone seeking avoid fraud detection kind of answers that question right off the bat
The prosecution will spin it as in cahoots, when it could have just been good customer service explaining a bunch of stupid rules.
It's not 100% clear they were able to prove anything versus being able to corner WU into a settlement.
Companies may very well be in the wrong and deserve punishing - but all they get are massive fines. Agencies like it because it looks good and money is always handy. Companies don't mind it as it removes risk (share prices often go up in the aftermath) and individuals don't get punished. That last part is the important bit, the individuals at fault here are able to continue to operate in regulated financial services roles, they can continue to be directors of companies etc.
If a few WU employees helped a few customers navigate the compliance hurdles, and some of those customers happened to be scammers, the press release would say the same thing.
Also last time I went to open a bank account, I did it online. No one wanted anything.
No not at all, they are guilty of willfully being a party to criminal enterprise. You might want to read the full DOJ brief:
"In its agreement with the Justice Department, Western Union admits to criminal violations including willfully failing to maintain an effective anti-money laundering (AML) program and aiding and abetting wire fraud.
Note the word "willfully."
Further:
"“Our investigation uncovered hundreds of millions of dollars being sent to China in structured transactions designed to avoid the reporting requirements of the Bank Secrecy Act, and much of the money was sent to China by illegal immigrants to pay their human smugglers,” said U.S. Attorney Decker.
“In a case being prosecuted by my office, a Western Union agent has pleaded guilty to federal charges of structuring transactions – illegal conduct the company knew about for at least five years
They structured transactions to avoid detection so they could continue to collect lucrative fees and knowingly did so for years.
Source:
https://www.justice.gov/opa/pr/western-union-admits-anti-mon...
Now, not all these criminals are violent or into drugs. Many were illegals sending money home. I get WHY they would use it, but it makes no sense for the US Government to even allow these services to exist.
Presumption of innocence, reasonable suspicion and burden of proof are core concepts of our justice systems for a reason.
if (source.isSuspicious() && destination in ('Ghana', 'Nigeria')) { investigateFurther(); }
What are the attributes of the source object that we need to determine if it's suspicious? That's the hard part.
Have you physically met and personally know the person you are sending money to? Are they a family member?
If you answered no to both of these questions STOP NOW IT IS PROBABLY A SCAM. If you wish to continue please consult with the teller.
At the end of the day though, scammers will be scammers and victims will be victims. You can't prevent everything but you can still try harder than WU.
I'm not particularly well versed in romances scams but I've heard they can start in the similar range and then escalate into 5 figures quickly.
If a company profits off of fraudulent transactions and is aware of the fraud, and the attorney general or equivalent stops viewing this as negligence, there is an incentive for the company to encourage this fraud to increase profits.
Correlation does not imply causation.
Ethically, I do not think it is correct to outright flag an entire country. It can be used as one factor, but that in itself is not enough.
Japan for example, a country that is not usually associated with crime, has one of the most profitable crime organizations in the world, the Yakuza. The UK might be where most transactions tied to money laundering are conducted, and so on so forth. In the grand scale of things, Nigerians are in a lower order of magnitude when it comes to dirty money.
Fraud detection, at scale, takes not one or two but many factors in consideration. That would produce a level of confidence that will translate into a suggested action. If the confidence is high, a fraud detection system will take an action without human intervention. If the confidence is low, a human needs to intervene and take action.
For example, you speak of "presumption of innocence" and "burden of proof" as "core concepts of our justice system". These are only core concepts of our criminal justice system; our civil justice system has very different rules for burden of proof, for example.
Some countries have much, much higher percentage of fraudulent transactions than other countries, and it's perfectly reasonable for Western Union to use country of origin as a factor in raising the fraud red flag. Western Union doesn't have the power to arrest anybody, and they have no reason to "presume innocence" for any one of their customers. If anything, when it comes to monetary transfers, I think it's safer to "presume guilt", that is assume all transactions have reason to be fraudulent, and then only let transactions through if you have strong reason to believe they are not fraudulent.
Presumption of innocence is even in the UN universal declaration of human rights.
What is considered burden of proof would be different, but it is still responsibility of the person forwarding the accusation. What you describe would be an accusation through "probable cause", described as reasonable grounds to conduct a search or investigation.
That being said I think country of origin are not reasonable grounds. Could be an individual sending money home, could be a merchant, could be anything.
300 people in a 173 million people country do fraud, flag them all?
The truly genuine customers can contact the company directly and deal with them directly, rather than buying through a site.
When your per-capita GDP is a few dollars a day, the odds that the order for a multi-thousand-dollar consumer electronics item is genuine gets awfully close to zero.
You call it discrimination against an entire country, I call it a sensible policy for a seller to enact. If you'd like to volunteer to police these fraudulent purchases, I'm sure they'd appreciate the help, but when you have an entire department that spends most of its time dealing with orders from two countries, orders which almost always turn out to be fraud, the most sensible way forward becomes nearly self-evident.
As others have mentioned, you seem to draw no distinction between constraints on governments, justice systems, and private policy determined by individuals and companies. I think until you stop confusing the two concepts (and the vocabulary thereof), you'll have a difficult time persuading anyone to come around to your thinking. (To say nothing of forming a coherent ethical argument for why you think this is some great injustice and what possible solutions might be.)
If only 1% of 173 million had a western-like middle-class+ purchasing power, that gives you? 1.73 million. A lot of people you can do business with. Like 4x that of Luxembourg.
This is just flat out, 100% wrong. Mainly because "innocence" and "guilt" aren't even concepts that apply in civil cases.
All of your responses still seem to assume that businesses somehow have the same level of responsibilities and restrictions of a government, and that is just not true.
I know firsthand that some retail businesses have found much better ROI by just presuming fraud (guilt, if you want to call it that) about certain countries (Nigeria and Romania frequently wind up on that list), and working to establish bona fides if someone from one of the banned locales contacts them directly to try to work out a purchase.
Which in one sense does sound horrible, but I'd imagine most personal eBay sellers would seek similar bona fides if the iPhone they're selling is purchased by someone reportedly from, say, Nigeria. It's hard to fault the risk mitigation instincts that humans have practiced for their entire history.
The reason these retailers developed the policies they did is because they were manually reviewing orders and very, very few–if any–were legitimate. Visits to the street markets in said countries turned up table after table full of highly discounted, almost certainly stolen goods. That's hard to ignore when setting corporate policy.
I'm not sure what the answer is, as one quickly gets into things like societal contracts, because we all pay some collective cost for the bad actors in our society, and at some point bear a non-zero degree of responsibility for not being either willing or capable of constraining those bad actors.
Country of origin discrimination is no worse than that. I do not think those are ethical business practices, and is morally no better than scamming via e-mail.
If someone owns their company and doesn't want to ship to Romania, is there an ethical way for me to force the owner to do so? There isn't one that I've heard. Many just won't sell internationally, partly because of the hassle, partly because of the lack of reasonable recourse systems. Does this kind of discrimination which bothers you become OK provided it's mass discrimination? Because that, to me, breaks down really quickly in the face of scrutiny.
Regardless, I take issue with your characterization of it. Deliberately trying to defraud someone is ethically the same as a good-faith effort to defend one's self against fraud? That's a moral equivalence that I think one would have a very difficult time building a system of ethics to justify.
Then... yes. Discrimination can be very harmful. Lack of health insurance for example can have fatal consequences, which can be more severe than scamming someone.
Is that correct? Because if so, what you're going to do is increase the cost of doing business, as the costs of both absorbing scamming, and increased anti-scamming efforts, increase. Which will eventually in some form or another impact either the employees of companies, the cost of goods, or both.
Increasing the cost of goods and suppressing wages can also have tragic consequences–somewhere, someone will starve to death. Or be unable to afford health care (the costs of which have been poorly mitigated by our attempts at doing so by way of changing the health care apparatus). Or be unable to afford an experimental procedure that might change their child's life, but isn't covered by insurers. Or lessen charitable contributions to organizations keeping people alive in impoverished places. Reduce taxable income thus reducing federal assistance program budgets. There are countless more similar scenarios.
If you equate increasing health insurance costs based on anything an insurer knows about the ones they're insuring with fatal consequences, then it isn't a stretch to see your idea also has fatal consequences.
One couldn't even discriminate to do more good, in such a system.
Except it would be using American law to improve the lives of Romanians and Nigerians (both the honest and dishonest, tho probably proportionally in favor of the dishonest, since the thing preventing Nigerian access to American exports has less to do with shipping policies and more to do with basic economics, and Romania is part of the Schengen Area, so they're hardly cut off from the world), at the expense of American voters, taxpayers, citizens.
Which strikes me as an awfully difficult thing to justify ethically, and a short slope away from a globalized system that would have to redistribute all benefits to everyone, regardless of whether they wanted them or not, would benefit from them or not, be corrupted by them or not, be weakened by them or not, and it would probably start with transferring wealth from developed nations to developing ones until parity is reached.
Which is a noble sentiment, but going from theory to implementation would be something between a train wreck and a blood bath.
Or, we allow people who make things to decide whether they want to sell things to certain countries.
Incidentally, I have a shipping insurance provider I use that won't allow shipping to certain zip codes in the US. Those zip codes tend to have high levels of theft of packages off doorsteps. Is that ethical for them to stipulate that I can ship to some zip codes, but not others, based on the effects of the behavior of some people in those zip codes? For the record, looking them up I saw no major correlation with race, gender, or poverty. But it's still discrimination.
I think your basic idea is noble and worthy, but I think it ignores the realities present in how policy shapes reality. Great ideas have sometimes resulted in horrifying human tragedy, and with the world improving in most places by most reasonable measures, I'm not inclined to throw out what's been elevating humanity pretty effectively for something that is akin to systems that have been shown to debase humanity pretty effectively, when practiced.
On one hand we want Bitcoin with no constraints on money transfers, on the other we want money transfer services to vet the recipient and allow or disallow the transaction.
Why do we desire homogeneity in service? Let the market offer a variety and we can choose the level of "transaction safety" we desire.
It's difficult to find someone both dumb enough to fall for a 419 scam, but smart enough to operate a bitcoin client and sign up for an exchange.
There are some really desperate and naive people in the world, and generally they're not that way by conscious choice.
Plus, it is often their family that suffers. People don't exist in a vacuum.
We tried to stop these payments but they would find other ways to send cash directly. Dealing with international wires is tough. When we stopped payments and tried to protect people, the story wouldn't end there. The people would find other means to screw themselves over. That's what loneliness and desperation do to gullible people.
So there were 2,000 Western Union employees in on this scam? That sounds like a huge number.
Also, a $586m fine for a company that makes $14b a quarter? Is that stardard?
Source: I worked at customer service at a grocery store and had to do that. There was (at the time, ~2006), no official training. The most I ever wired was about $12k to Africa for a family that was immigrating, most wires (90%) were to latin america for about ~$1-300 or emergency help to family for a few hundred as well.
It could be quite fair depending on the scope of the fraud. Fines at all levels in the U.S. are roughly based on the scope of wrongful activity, not income. Two people both speeding 10 mph over the limit don't get fined different amounts based on their income.
https://polisen.se/en/Languages/Laws-and-Regulations/Fines/
*) Except DUI. That's a "more serious crime". Prison/similar and/or a fine proportional to your income.
As far as the paying procedures go, the only thing I needed to check it's the recipients name. I couldn't pay a "John Doe" wire to a "Joseph Doe".
I also had a customer that sent a wire to a Cuban citizen / South American resident. The payment was rejected because of some US embargo against Cuba.
Reminds me of a story my SO told me once. For some reason I can't recall now her company was to get some money via Western Union. She was supposed to pick it up, but the sender refused because she had a polish character ("ł") in her surname and they believed that WU won't be able to handle such transfer. For that reason, the company had to send someone else to pick up the transfer.
Also, for what I remember, you can't send a wire to a company via WU. The recipient must always be a person.
Important to remember that fines should match the severity of the violation, not the wealth of the violator. The purpose of the fine is to discourage the behavior, so ideally the following holds:
(size of fine * chance of being caught) > profit from not being caught
If the above is true, rational people won't bother trying to do something illegal.
But that's precisely the problem, isn't it? How can you ensure the risk is too high for the company unless you take into account its financials?
* $x of fines for every $y of wire fraud
* $x of fines for every individual instance of wire fraud
The point is if a company that makes a billion dollars does $100k in fraud they should probably pay the same fine as a company that makes a million dollars and does $100k in fraud.Most of Scandinavia determines fines based on income, because they recognize that fines that constitute pocket change don't actually act as deterrent.
http://www.theatlantic.com/business/archive/2015/03/finland-...
Scaling up fines based on wealth might help reduce minor crimes like speeding. I'm not sure how effective that really is, though, since low income people still speed.
In this case the "profit" part of my equation would change based on individual circumstances.
The "profit" of speeding to your finance job where you make $500/hour is much higher than that of speeding to your minimum wage job at McDonalds.
I think that's why we punish serious crimes with time in prison, not fines.
Is this something we can really calculate so closely? What if it turns out the banks are better at such calculations than the government, and crime is profitable?
Personally, I feel there's a disparity here between punishment for the rich (make the fine slightly higher than the expected profit) and the poor (put them in a cage for years).
No he wasn't. He was arguing against scaling up fines based on a company's general profits. The formula given simply said that the fine and the chance of being caught should be greater than the profit from the illegal activity. How much greater was unspecified.
> Personally, I feel there's a disparity here between punishment for the rich (make the fine slightly higher than the expected profit) and the poor (put them in a cage for years).
I agree with that, but don't feel that scaling fines resolves the issue that poor criminals land in jail while wealthy criminals don't even pay their own fines (instead the corporation does). You don't fix this discrepancy by raising fines on the wealthy.
However great the difference between the expected profit and the fine, a purely financial penalty for crime will always encourage three things: gambling, trying outsmart the government by finding ways to make more profit or reduce the chance of being caught, and rich people ignoring the law and committing the crime for non-financial reasons (for example: thrill seeking, as a favor to someone, to enable another crime, or from pure malice) with no real penalty to them.
I think we both agree jail is a more appropriate punishment, though we're making the argument in different ways.
There are at least five classic purposes for punishment: (I'm assuming the felon is a company, not an individual for the examples)
1. Incapacitation. The company is banned or dissolved to prevent it from committing a crime again.
2. Deterrence. Other companies, seeing the punishment, will be less likely to commit a crime.
3. Restitution. The company compensates the victims.
4. Retribution. Because the company hurt society, society may now inflict harm on the company.
5. Rehabilitation. The company is required to alter its policies or practices to reduce likelihood of committing future crimes.
Pick one or more of the above. :-)
The person at the local Western Union actually warned them that it was a scam. I'm not sure if all of them would actually try to stop people from wiring money. In the end it's company police to wire the money if the client wants it tho.
EDIT: I guess it's not every state.[0]
I'm putting my cynicism aside, because that really does sound like a good thing.
The people who actually, knowingly (hard to prove) did the aiding and abetting committed crimes and conspiracy to- crimes. They should be tried. The managers who likely pressured these crimes for revenue should be variously fired, banned from the money industry, and tried.
But corporations get to buy their way out of jail.
Which is more important?
That being said, I think we ought to do both and don't see why we can't or shouldn't.
I guess when a big percentage of a company's profits come from fraud, they're not incentivised to fix the problem.
It's not their fault you used the default setting to minimize cost per click then turned on ads in places you weren't at all interest in.
Then, there's the problem of multiple (up to 10) clicks from the same IP within a couple of seconds.
Last, why in Nigeria they only stay on websites for a fraction of a second, even though they scroll to the bottom of the page (which regular users often don't do).
You get about 1.5% more money with them when you do a transfer.
Their low cost model is driven by using automated KYC checks and the kinds of fraud models you'd expect from a web startup
More here
https://transferwise.com/gb/compare/western-union-exchange-r... Disclosure - I'm an employee - but the hype in this case is warranted
I think the answer is that while Transferwise is a great product, Western Union serves a niche that Transferwise/PayPal/Web Startups aren't fulfilling. That is anyone even with low income can just go into a store and use it. No need for a bank account, a PC (even basic computer knowledge is not required which may hinder older people) or the internet.
Code written in Javascript by a fresh college graduate with no domain knowledge that you pulled from GitHub?
When evaluating a financial service the last thing I ever want to hear is that it's run like a "web startup".
While I hear your startup vs big guys point, I looked at the public companies in this industry before and was amazed at how much they do spent on compliance systems (much of which is for automated checks) and also of course on human checks/follow-ups.
Two things stood out: 1. How unprofitable the smaller of the public players in this space (e.g. Moneygram) were as a result of regulators pushing for ever-higher reductions in fraud, using threats of the kind of action that was taken against WU as a stick. WU spends $200m a year on compliance, and if remember correctly unprofitable Moneygram just completed an $80m IT system upgrade.
2. In addition to the large up-front fixed cost for systems, how much ongoing variable compliance cost these companies have to spend because fraudsters are notoriously good at figuring out how to beat automated KYC checks.
If Transferwise are just using automated checks and not the additional human reviews that WU uses (per the article 25% of their workforce are devoted to compliance) , aren't Transferwise just basically biding time until they get large enough to attract the attention of an attorney general due to the undiscovered fraudulent transactions going through the system? Then bam $586m fine like the one just handed to WU and you go out of business.
How can a startup that charges 25% of the revenue of the only profitable public player in the space hope to cover the variable compliance cost required to mitigate this risk?
I recognise that the argument often put forth is that the fintech startups match people on either side and hence take out the bid/ask spread on the exchange rate transaction, but doesn't this ignore that the largest money flows are uni-directional - i.e. remittance payments from immigrants in wealthy countries sending money back home? The matching breaks down if the money-flow is predominantly one-way.
Genuinely interested in the answers to the above - I passed on an investment in the industry because I couldn't get comfortable with the above.
So the reality is that - "moving money" costs - almost nothing.
Think about it. The process of doing a bank to bank transfer (what transferwise does) - involves one bank in one country, crediting another banks account in the originating country, and then the money turns up in a "correspondent"or "nostro" account in another country. The matching bit helps - but the real magic - is that monopolisitic incumbents have been charging spreads for years - TransferWise is different as they aren't greedy.
You are right - that fraud and KYC checks - are significant in the industry - but lets step through what these are.
I can share that we actually have pretty sizeable complaince and fraud teams - larger than many established financial services companies - but unlike them Fraud and KYC is part of the product - not a sign off team. The team understand our global regulatory responsibilities, and try to understand how tomeet them; whilst trying to figure out how to reduce customer and friction andcostin the process. There's been a complete lack of innovation in this domain for decades due to the dynamics you've outlined.
Forexample with KYC:
From KYC perspective - you have to verify that a customer is who they say they are - and check they aren't on any AML blacklists etc.
Different jurisidictions - have different thresholds (limits) at which they ask for KYC checks in place.
With Western Union Digital (and with transferwise) - someone may take apicture of their passport, driving licence, scan and upload. This then needs to be verified.
For its first few years - like other players in the industry - validated every single one of these documents individually - but over time got to a point where they had built up enough data to be able to validate these documents in an automated fashion. Inevtiably given how strict regulation is in this industry - the onus is still not on letting the bad guys through
I can't comment in public on transferwise's profitability - but can say the business has been operating sustainably for over a year - i.e. not losing money on a transaction - and investing sensibly on marketing.
Marketing is relatively small spend for Unicorn B2c startup - with over 80%+ of new customers coming in through WoM
However they don't support ALL currencies. Sometimes the support a currency one way only.
Chose to post this comment because I see a lot of people in the thread effectively asking "does this really happen" or "who are these stupid people that get scammed" and I figured letting the HN community know that at least one or our members has been personally affected might bring a different level of consideration to the topic.
Edit: Seeing this headline feels great. I can't describe the feeling of frustration at not being able to help my family solve the case when the fraud happened or the extreme anger I felt that the scammers pretended to be a grandchild calling my grandfather for help, using one of our names to legitimize the scam. Ever since, I introduce my self by name when I call my remaining grandmother and I worry when she tries to recognize me before I have a chance to introduce myself. I hope no one else has to experience this.
Still, this is a step forward.
I strongly believe that the most effective thing people can do is to help educate others about the existence of these scams and about the safe & secure use of technology. People can develop self-defense mechanisms and an intuition for when they may be getting scammed or phished.
http://locations.westernunion.com/search/romania/vl/r%C3%A2m...
How might that affect banking laws that require banks to flag suspicious transactions and restrict who can send and receive funds? Have the banking laws that restrict payments ever been challenged in court as a free speech issue?
Just wondering if these two dots are in any way connected. I am not pro-money laundering but also don't like the idea of government overreach. Thinking that since banks are non-government that the constitutional protections don't apply, but what about the laws that bring about the banking regulations?
What about if the expenditure is prohibited by mistake, is not fraud or money laundering, and it gets locked up in bureaucracy indefinitely? In that case it seems like protected speech could be restricted.
Anyone know if constitutional law can be applied to quasi-government private organizations? At what point is an industry such as banking so regulated by government that it can't be distinguished from government?
https://yro.slashdot.org/story/17/01/23/0658205/western-unio...
My elderly mother-in-law got scammed, and it was pretty ridiculous how WU allowed it to go through given the circumstances.
Just wondering if/how to potentially get some of the $ back via this lawsuit.
Apple should be next. Once I had an iPod stolen and Apple refused to help me recover it. They wouldn't give me the IP or geolocation of where it was or even tell me if it connected to iTunes and whos account it connected as.
From these two events, I always felt that Apple and Western Union aided and protected criminals and thieves.
So what is the point of all the Nigerian bashing here?
"the Colorado-based company knew of fraudulent transactions but failed to take steps that would have resulted in disciplining of 2,000 agents"
Western Union was already aware of fraud they were facilitating, but did not take steps to either report or prevent it.
It's one thing to not investigate suspicious behavior, it's another thing entirely to be aware of actual fraud, and ignore it.
/s
(Plus as others have noted, not everyone has a bank account.)
I think bitcoin will slowly seep in as the solution to many problems as they arise. I don't think cramming down everyone's throat is going to help, it comes off very scammy.
Unless your complaint is about the government stepping in to penalize Western Union. In which case, I misunderstood.
http://www.sciencemag.org/news/2016/03/why-criminals-cant-hi...
Online versions of the scam originate primarily in the United States, the United Kingdom and Nigeria, with Ivory Coast, Togo, South Africa, Benin, the Netherlands, and Spain also having high incidences of such fraud
I suggest the parent takes some time, do a little study and call a criminal act what it is, rather than lazily labelling 200m people as scammers.
Edit: grammar
Also, there's no citation for the "primarily in the United States, the United Kingdom and Nigeria..." claim. The reference to Encyclopedia Britannica is dead and presumably was for the "419" name since that's the sentence it's actually on.
AFAIK, the reason the country of Nigeria is frequently associated with advance fee scam probably has more to do with a particularly famous example of a scam phishing email, where the email writer claims to be a Nigerian prince cut off from his substantial family fortune due to political issues of some kind.
http://www.africamasterweb.com/AdSense/419NigerianTownScamme...
I have been requested by the Nigerian National Petroleum Company to contact you for assistance in resolving a matter. The Nigerian National Petroleum Company has recently concluded a large number of contracts for oil exploration in the sub-Sahara region. The contracts have immediately produced moneys equaling US$40,000,000. The Nigerian National Petroleum Company is desirous of oil exploration in other parts of the world, however, because of certain regulations of the Nigerian Government, it is unable to move these funds to another region.
You assistance is requested as a non-Nigerian citizen to assist the Nigerian National Petroleum Company, and also the Central Bank of Nigeria, in moving these funds out of Nigeria. If the funds can be transferred to your name, in your United States account, then you can forward the funds as directed by the Nigerian National Petroleum Company. In exchange for your accommodating services, the Nigerian National Petroleum Company would agree to allow you to retain 10%, or US$4 million of this amount.
However, to be a legitimate transferee of these moneys according to Nigerian law, you must presently be a depositor of at least US$100,000 in a Nigerian bank which is regulated by the Central Bank of Nigeria.
If it will be possible for you to assist us, we would be most grateful. We suggest that you meet with us in person in Lagos, and that during your visit I introduce you to the representatives of the Nigerian National Petroleum Company, as well as with certain officials of the Central Bank of Nigeria.
Please call me at your earliest convenience at 18-467-4975. Time is of the essence in this matter; very quickly the Nigerian Government will realize that the Central Bank is maintaining this amount on deposit, and attempt to levy certain depository taxes on it.
Yours truly,
Prince Alyusi Islassis
Which makes your English teacher's chagrin even more justified.
Similarly should gun manufacturers be penalized when their weapons are used in an illegal manner?
The analogy would be gun manufacturers helping customers avoiding detection after illegal usage of their weapon. In that case, yes. It's bad.
The fact that a manufacturer doesn't sell direct is another reason to think there's no relation to this case.
The $586M mentioned covers 8 years (2004-2012). So $73M/year.
In 2015 they moved $82B.
Edited:
This settlement is saying the amount of money they move fraudulently is less than 0.1% of their total money movements. This seems entirely implausible. 10% seems a lot more plausible.
What are you basing that on?
(And yeah, it's still an estimate, since no-one except WU has any possibility of knowing the truth. Still, 0.1% seems fraud seems like an awefully low estimate, doesn't it?)
You revised it down to 10% now; why? Don't get me wrong, 10 is a great number, much better than 11, but I still don't see any rationale.
To add a perspective: They paid about a penalty for about a 1/1000th of the money they move around. What's your guesstimate for how much of WU money is based on fraudulent transfers?
There are concepts such as "experience", "pattern recognition", extrapolation etc.
That said, I think arguing about how big the fine should be is accepting the faulty premise that a fine is an acceptable penalty. Wire fraud is a felony. I know someone who went to prison for it. The article says "[Western Union] agents were helping scammers avoid detection" and "Fraudsters [...were...] giving Western Union agents a cut in return for processing the payments". They willingly participated in felonies for personal profit. Shouldn't they—and all the supervisors who can be proven to have condoned their actions—be going to prison? Or is this okay just because everyone's doing it and they have a fancy corporation to hide behind?
I would say that's incredibly naive and refer you to this comment: https://news.ycombinator.com/item?id=13465310
"For example, a seven-state survey found that approximately 29 percent of Western Union money transfers to Canada in excess of $300 were fraud-induced."[1]
and
"The world’s largest money-transfer company reported a 27 percent drop in fourth-quarter profit, largely due higher costs linked to tightened regulations to prevent money laundering."[2]
Seems like something might be afoot there.
[1]http://www.mtraweb.org/state-attorney-generals-agreement-to-...
[2]http://www.huffingtonpost.com/2014/02/25/western-union-inves...
https://chargedaffairs.org/billion-dollar-industry-nigerian-...
"a follow-up study in 2013 found that the number had jumped to $12.7 billion. This would make the 419 ‘industry’ roughly the same size as the GDP of Botswana."
I believe the vast majority of this is transferred via Western Union.
> Percent of Americans who have been victims of credit card fraud--10%
0.1% seems very low. I suspect that companies wouldn't even bother with compliance departments if it were actually that low.
Interviews with Ebay execs suggest rates closer to the 3-5% range, and it takes a lot of work to keep it that low.
30% is probably high. But probably not by a huge amount.
I can make up numbers too! Western Union fraud is actually 1035% of all of their transactions. Seriously.
I speculate that Walmart thinks it's good business to make a minimal profit on the money transaction because a substantial portion of the money winds up being spent in the Walmart store where it's received.
However, the low overhead of the service probably contributes to the lower cost as well. This isn't their main business and Walmart already have TONS of locations, they don't have to pay rent or commission on physical locations nor do they have to pay for labor, the employees would be there anyways. It doesn't cost them hardly anything to add this service to their main business.
I get the sense that almost none of the fraud victims are themselves Nigerian or Ghanaian, while virtually all of the legitimate senders will be.