Shownotes
I'm joined today by Sudhir Lanka, Associate Director of Fraud Strategy at GrubHub. Sudhir's team doesn't just cover GrubHub anymore. His scope recently expanded to include Wonder, GrubHub's new parent company, and Blue Apron, which means he's thinking about food delivery fraud across three genuinely different business models at once, and I wanted to dig into how that actually changes his approach.
We get into what makes a three-sided marketplace uniquely exposed to fraud, since GrubHub has to protect diners, restaurants, and drivers all at the same time, and a gap in protection on any one side eventually breaks trust for everyone else. Sudhir walks through the primary fraud vectors his team deals with, account takeover, payment fraud, refund abuse, and promo abuse, and gives some of the most specific, real-world detail I've heard on this podcast about how each one actually plays out, down to the exact excuses customers give to get a refund they're not owed.
What you'll hear in this episode:
- How Sudhir's career path through JP Morgan Chase, Discover, and GrubHub shaped his approach to fraud strategy at each stage of scale
- Why GrubHub, Wonder, and Blue Apron each carry different food delivery fraud risks despite serving the same underlying mission
- The three primary fraud vectors GrubHub tracks, account takeover, payment fraud, and refund and promo abuse, and how they show up differently across business lines
- A detailed walkthrough of restaurant account takeover, including how a compromised owner's email can lead to a redirected ACH payout and an expensive double payment for GrubHub
- Real examples of driver and diner collusion, including self-delivery loops and a surprising exploit tied to minimum wage laws in cities like Seattle and California
- Why refund abuse and first party fraud can't be predicted at the time of transaction, and Sudhir's framework for placing controls at the actual point of irreversibility instead
- How layered fraud controls work across account creation, checkout, and post-order stages, including multifactor authentication, 3DS authentication, CVV validation, and delivery PIN verification
- The difference between soft friction and hard friction, and why Sudhir intentionally reserves harder friction for a very small percentage of customers
- Why Sudhir sees fraud strategy as fundamentally pro-growth, not anti-growth, and how protecting trust across the marketplace translates directly into revenue
You should listen to this episode if you:
- Work in fraud strategy at a marketplace, food delivery, or platform business balancing multiple user types
- Are dealing with refund abuse, promo abuse, or first party fraud and want a real framework for controlling it without over-relying on prediction
- Want to understand restaurant account takeover and payment redirection fraud from the platform's side, not just the consumer side
- Are building or refining layered fraud controls and want concrete examples of where soft friction versus hard friction actually belongs
- Need language to make the case internally that fraud strategy is pro-growth, not a blocker to it