Unmasking the automated threat: Defending the booking journey against bot and carding attacks

Tiqets on moving fraud detection upstream of checkout

Tiqets built its business on instant delivery and fast checkout. That speed comes with a tradeoff. The platform collects only a name, phone number, and email, with no account creation or billing address required, which makes it easy for anyone to fabricate the details needed to buy a ticket.

In this session, Anne Pauline Van Schagen from Tiqets and Vanessa Buisson from Riskified break down how bot attacks have evolved to mimic human behavior, from realistic checkout movements to email addresses built around real names instead of random strings. They cover how fraudsters use AI to construct full backstories and digital avatars that pass manual review, how bot traffic quietly skews conversion data and slows sites for real customers, and why fraud prevention needs to start at browsing, not checkout.

 Anne Pauline Van Schagen
Anne Pauline Van Schagen

Fraud Manager at Tiqets

You’re only as good at preventing fraud when you know your real customer, because then you can reward that customer and create friction for the fraudsters on your website.”