Wednesday, December 17, 2008

Terminal Disease Boosts Fraud

More terminals have been tampered with (toyed with?) at a Toys R Us in Sveedin.  2008 is coming to an end, and one of the buzz words of the year has got to be  card skimming.  

The tampering of these POS devices will undoubtedly erode the trust of consumers, which will contribute towards the acceptance of a personal swiping device such as the one devised by HomeATM.

Getting the PAN (personal account number) and PIN is so easy (with tampered  devices) it's like stealing candy from a baby.
  However, in these times, it's not the "sweet tooth" that's behind the stealing...it's the "Bluetooth."

It's a contributing factor towards the paradigm shift taking place with online  vs. retail shopping and part of the reverse matriculation we perceive as inevitable.  Here's yet another story, of POS terminals being toyed with.
"Swedish police are unraveling a scheme where criminals stole credit card details by tampering with a point-of-sale (POS) terminals at a Toys R Us store in Malmö.

One terminal was found to be equipped with a bogus keyboard overlay that could record PINs (personal identification numbers) as well as details on the card's magnetic stripe, said Detective Chief Inspector Harald Runge.

The case is similar to one revealed earlier this year affecting several U.K. retailers, where point-of-sale devices were hacked to record debit and credit card details for use in frauds. It also demonstrates the increasing technical knowledge cybercriminals have gained in order to perpetuate card fraud.

It's the second time police have discovered a tampered POS terminal at Toys R Us, Runge said. Three months ago, two compromised terminals were found, rigged with Bluetooth transmitters to send card details, he said. 

In that case, at least 500 to 600 cards were compromised. The case came to light after people reported fraudulent withdrawals on their cards, Runge said. The withdrawals were made in Romania, a country known as a haven for cybercriminals. "We know that usually those people who do these crimes in Sweden are usually from Romania," Runge said.

In some instances, the card details are transmitted via a wireless mobile chip installed in the POS device, Engelsman said. In other cases, the terminals have a short-range Bluetooth capability. A fraudster can come back into the store to transfer the captured data to another Bluetooth-enabled device."

With the help of Swedish banks, it was determined the cards had all been used at Toys R Us, Runge said. Swedish police are now carrying a technical investigation into how the POS terminals were compromised, he said. In Romania, the authorities have photos of people who were making the fraudulent withdrawals, he said.

The Swedish card numbers and details recorded at Toys R Us may already be showing up on illegal Web sites where card details are sold, said Frank Engelsman, a fraud expert with Ultrascan Advanced Global Investigations, a company based in Netherlands. Runge said people who shopped at Toys R Us should ask their bank to issue them new cards.

It appears cybercriminals are already trying to sell those details. Four hundred Swedish card numbers have turned up in one of the underground cybercriminal databases that is located in Russia, Engelsman said. The card details sell for US$1 to $6, he said.

Engelsman said Ultrascan has seen a sharp uptick in the number of credit card details that are being tested. In order to sell a credit card record, the buyer often wants to ensure the card number is valid and hasn't been canceled. To do that, cybercriminals will charge a very small amount to an organization such as political campaign, Engelsman said.
The charge can be as little as $0.26. Cybercriminals will tend to vary the amounts, since banks will often cancel cards if their anti-fraud systems notice, for example, 1,000 cards all being charged for $0.13, Engelsman said.

Lately, "we've never seen so much testing before," Engelsman said. "After testing, they are going to use them [the cards]."

Tampering with the point-of-sale terminals is getting increasingly sophisticated. Engelsman said he's heard of teams of professional "burglars" who carefully break into a store at night and install equipment to record card details. They leave without a trace.

Terminals are also being rigged to record credit card details at certain peak shopping times when the most details can be captured for the least battery power. For example, a POS device would only record details from 1 p.m. to 3 p.m., Engelsman said.

The devices can also be programmed to only record, for example, American Express cards rather than Visa or MasterCard, Engelsman said. That's because some fraudsters, such as ones in North Africa, prefer American Express since the cards are more widely accepted in the area, he said.






Reblog this post [with Zemanta]

Airline Payment Summit Downloads

The Travel Payment Summit has made available, free presentation downloads from their conference earlier this month.  If interested, take a peek at them here:

Travel Payment Summit - free presentation downloads

Presentations from the Travel Payment Summit (TPS) held 03-04 December 2008 in Bad Homburg (Frankfurt) are now posted online and available for download free of charge!  (Editor's Note: Bad Homborg is another name for Frankfurt?...ya gotta get a kick outta that.  Hamburger bad...Frankfurter good?) 

Along with the latest trends in travel payments, including the move by airlines and travel companies to cut payment costs with lower-cost alternative payment options, see how the credit crisis is causing a rise in payment fraud, cutting into the bottom-line of the airline and travel industries and find out what can be done about it!

Click here to view those presentations

"Payments: A Cost or an Ancillary Revenue Opportunity?" will be one of the topics covered at the Airline Sales Channel Forum and Airline A-La-Carte Pricing Seminar being held concurrently on 12&13 May 2009 in Miami, USA.  These events will take airline ancillary revenue generation and a-la-carte pricing to a whole new level. Airline delegates may register for just $99 through 15 January 2009!

For more details please visit: www.airlinesaleschannel.com


Reblog this post [with Zemanta]

Microsoft Critical IE Patch Today at 1:00 EST


Microsoft admitted last night that a serious flaw in security has left the majority of the world's Internet users exposed to attacks from hackers hoping to steal personal data and passwords.  As a result, they will release a "critical" patch later today.

The warning about the bug came last week, but has been exploited since the media reported about it, as "zero day" hackers seek to take advantage of the (window of opportunity?) flaw while it's there.

This has resulted in a flurry of activity at MS headquarters as they seek to devise a way to quell the threat.   Several engineering teams around the globe have been instructed to work 8 days a week until the fix is in.

According to one report I read;  MS said on Tuesday that in response to "the threat to customers" it immediately mobilized security engineering teams worldwide to deliver a software cure "in the unprecedented time of eight days." 

(Editor's note: Wasn't the world supposedly built in only seven?  What's that you say?  He rested on the 7th?)

In the meantime, they'll release an emergency patch today around 1:00 pm EST.   Every security expert is strongly recommending an immediate download.  Some background...a loophole in Internet Explorer (IE) allows criminals to commandeer victims' PCs by tricking them into visiting unsafe websites.   Once there,  they can be easily duped into giving up their personal information as they believe the situation is normal, but in reality it's all bleeped up.

Therefore, Microsoft has announced that they are releasing an emergency patch later today in the hope of fixing the security bug that allowed attackers to exploit the IE browser. The patch will be ready at 1 p.m. Eastern time via Windows Update, Windows Server Update Services and Microsoft Update.

The IE update will be labeled “critical,” which is the highest ranking update from Microsoft. This bug in IE has been all that people can talk about, some experts even warned that we should not use the browser until there is a fix. Microsoft as usual has been downplaying the threat.

Read full article



Reblog this post [with Zemanta]

Who's on Fifth Third? eBillme


Fifth Third Processing Solutions has announced a new partnership with eBillme to refer the payment alternative to its merchant processing customers.

"Extending payment option offerings at the online checkout is critical for online retail businesses to attract customers, increase orders and improve satisfaction and loyalty," says Donald Boeding, President of Merchant Services for Fifth Third Processing Solutions. "We believe our customers will see eBillme as a very appealing payment solution. We look forward to working with the eBillme team and to extending this payment option to our customers."

eBillme transactions occur securely, bank to bank, with no personal or financial information required or transmitted over the Internet. Because shoppers pay directly from their online bank account, they don't release any financial information online. This helps consumers manage their spending and debt, while better safeguarding themselves from identity theft and fraud risks.

eBillme's Buyer Protection Program takes security a step further. Provided at no cost to shoppers and retailers, the buyer protection features have the same or a better level of buyer protection than premium credit cards. Protection features include a return guarantee, price guarantee, in-transit protection, and fraud protection. Consumers can shop with confidence knowing their eBillme transaction is guaranteed and protected.

"The eBillme transaction model is uniquely designed to meet merchant demand under the current conditions of the economy to serve as a more secure way to pay cash online," says Marwan Forzely, President and CEO of eBillme. "We are very excited to be working with Fifth Third Processing Solutions to extend our payment alternative to their leading retail customers. eBillme gives merchants an opportunity to reach more customers and drive revenue while offering the industry's lowest transaction fees."
Reblog this post [with Zemanta]

Monday, December 15, 2008

Something Phishy About This



A recently published report dealing with phishing and crimeware trends in Q2 2008 indicates a marked increase in the activity of cybercriminals seeking to steal sensitive financial data from consumers who manage their finances online.

Phishing, essentially defined as a criminal mechanism designed to steal consumers’ personal identity data and financial account credentials, has two major components, which according to the report manifest conflicting tendencies. Social engineering-based phishing activities – which uses false emails to direct online customers to false websites which mimic legitimate business and agencies websites – have declined slightly; however, the report indicates that technical subterfuge phishing schemes – which download crimeware directly onto PCs to steal credentials and intercept consumers’ online account user names and passwords – have registered a sharp increase. The report thus indicates that the number of crimeware-spreading URLs at the end of Q2 2008 grew 258 percent compared to the end of Q2 2007. Also, the number of malicious application variants identified by the company which drew the report registered a record high of 442 in May 2008, up 105 percent from May 2007.

The report also highlights that the number of brands – that is, financial service providers – targeted by phishing attacks is on the rise, and that fraudsters are investing in advanced IT infrastructures and marketing tools in order to conduct targeted phishing campaigns. Favorite targets for phishers are the websites of distressed financial institutions, with criminals seeking to take advantage of the confusion surrounding various mergers and takeovers to trick consumers into revealing their account data. Finally, the report indicates that in Q2 2008, the industry sectors mostly targeted by phishing schemes were the financial sector (52 percent of phishing attacks), followed by the auction and payment service providers, which were at the receiving end of 25 percent and 18 percent of phishing attacks, respectively.

The Q2 2008 Phishing Activity Trends Report was drawn by the Anti-Phishing (APWG), an industry, law enforcement and government coalition focused on eliminating identity theft and fraud that result from the growing problem of phishing, email spoofing, and crimeware in general.




Reblog this post [with Zemanta]

Online Fraud Up...Down Under

Card Fraud is on the rise globally and Australia is no exception.  In the land down under, card fraud jumped 45 per cent to more than $131 million in 2007-08 with most of the growth coming from suspect online payments.   Figures released by industry body the Australian Payments Clearing Association (APCA) show 361,000 fraudulent credit card transactions occurred in the year to June 30. This translates to $50.19 in fraud for every $1000 spent on credit cards, up from $38.62 in the previous year.

Also, as is the case everywhere, the bulk of these were Card Not Present (CNP) transactions, "where the card holder and retailer do not meet face to face."  According to APCA, almost $63.5 million in 211,000 transactions was lost in this way, the APCA figures show.

If you’re the proprietor of Android's Dungeon & Baseball Card Shop.com, how do you know it’s Rod Flanders buying all those Itchy and Scratchy comics and not Bart?
  The short answer is "you don't."  (unless your customer is using HomeATM Personal Swiping Device)

The stee
p rise in fraud is a major worry for banks and credit card providers, which have been pushing for new security standards in Australia, including the recent introduction of PIN numbers for credit cards for over-the-counter transactions.  (see "More on Australia's PEN or PIN Program)

Water finds the path of least resistance and apparently, fraud, like water, has the same tendencies.  The crackdown on bricks and mortar fraud is believed to have driven more crime to the internet, where transactions are harder to police and fraudsters can remain anonymous.  It is of utmost importance secure online transactions as online shopping becomes the norm.  (see Australian eCommerce Enjoying Bonanza)

As I've stated myriad times, CNP transactions become CP (Card Present) transactions upon using HomeATM's Personal Swiping Device.  HomeATM's device also securely encrypts all  transactions and the HomeATM user NEVER needs to enter their PAN (personal account number) which, according to most users is a convenience aspect, (just swipe your card) but more importantly, is a security aspect as well.


People swipe their card in the store, (it's what makes it a CP transaction,) so if CNP transactions are mired in fraud, then it seems to be a no-brainer to have the consumer swipe their card at home.  I

In the past, part of the problem was the cost of a Personal Swiping Device.  HomeATM has gotten the price to a point whereby this is a non-issue.  The more secure the transaction, the lower the interchange rate.  CP is more secure than CNP, thus it has lower interchange.  Card Present/PIN, being even more secure, enjoys the lowest processing fees of all.





Reblog this post [with Zemanta]

Friday, December 12, 2008

Finextra Interviews PCI SSC

Finextra interviews Bob Russo, general manager of the PCI Security Standards Council (PCI SSC). Click here to go to Finextra and watch it or click the link below to launch it in your external player. Finextra video - Bob Russo, PCI SSC, 04 December 2008
Protecting payments data

Talks about the council's recent introduction of a quality assurance program for assessors, this month's global compliance mandate from Visa, and what the organization has learned from recent data security breaches at merchants and service providers.


The PCI SSC is a global, open industry standards body providing management of the Payment Card Industry Data Security Standard (PCI DSS), PIN Entry Device (PED) security requirements and the Payment Application Data Security Standard (PA-DSS). These standards aim to ensure that merchants and other organisations that process card payments prevent credit card fraud, hacking and various other security vulnerabilities and threats.

Launch in external player

Reblog this post [with Zemanta]

21 Million German Bank Accounts for Sale

Report: 21 million German bank accounts for sale | ITworld
IDG News Service —

Black market criminals are offering to sell details on 21 million German bank accounts for €12 million (US$15.3 million), according to an investigative report published Saturday.

Reporters for WirtschaftsWoche (Economic Week) managed to obtain a CD containing 1.2 million accounts after a November face-to-face meeting with criminals in a Hamburg hotel, according to the magazine.

Posing as buyers working for a gambling business, the journalists were able to strike a price of €0.55 per record, or €12 million for all the data. They were given a CD containing the 1.2 million accounts when they asked for assurances that the information they would be buying was legitimate.

That CD contained the names, addresses, phone numbers, birthdays, account numbers and bank routing numbers of the theft victims, they reported. In some cases, the victim's account balance was also provided. The data was most likely collected from call center employees, the magazine reports.

continue reading

Reblog this post [with Zemanta]

Dormant Accounts at Risk?

After reading this press release, I asked myself how many dormant accounts I might have.  According to a survey conducted by Ipsos Reid for Capital One, in Canada, there are more than 41 million abandoned online accounts, and they all have risk exposure to ID theft and/or fraud.

The Cap1 study shows that two out of the average of nine online accounts owned by Canadian adults (adding up to a total of 41 million accounts) have become inactive as a result of the lack of their use throughout 2007.

These abandoned online accounts, ranging from shopping and email to social networking and dating sites, become vulnerable to ID theft and fraud. This is due to the fact that even if customers do not use the accounts anymore, they still leave personal information available, including names, addresses, dates of birth or telephone numbers online.

According to the results of Cap1's survey, the main reasons for which Canadian customers pay little attention to inactive accounts are their lack of awareness or carelessness. (eh?)

Thus, 28 percent of them were not even aware of the fact that they had to close their inactive account(s), 23 percent stated that they even forgot about it, while 15 percent forgot the password.

When asked about how often they review their credit bureau report, 72 percent of Canadians answered "rarely" or "never". 20 of them gave the same answer when asked whether they check if a certain website is secure before making an online purchase. 12 percent of Canadians rarely/never look for unexpected or incorrect charges in their credit card statements.
The study was conducted by market research firm Ipsos Reid, on behalf of Capital One.
Reblog this post [with Zemanta]

Thursday, December 11, 2008

Trust 10x More Important than Price Online


VeriSign Survey Finds Nearly Ten Times as Many Consumers Feel Trust Is More Important Than Cost When Transacting Online

Even in Trying Times, Consumers Seek Safety Over Savings; Eighty Five Percent of Consumers Said Trusting a Site Is Most Important When Transacting Online

MOUNTAIN VIEW, CA--(Marketwire - December 11, 2008) - The findings of a recent consumer survey conducted by Synovate and commissioned by VeriSign (NASDAQ: VRSN), the trusted provider of Internet infrastructure services for the networked world, suggest that consumers may be willing to forgo gimmicks and spend a little more online if they know their identities are protected.

The survey results reveal that 85 percent of consumers state that trusting the site is most important when interacting on a Web site and sharing confidential information. In contrast, nine percent said competitive pricing was most important and five percent said ease of use was most important. Additionally, 93 percent of respondents said they would stop transacting on a site that's not secure.


Findings also concluded that 76 percent of consumers claimed that identity theft is a "major" concern for them. When asked how they felt about brands that did not protect their online identity, 56 percent felt "distrustful," 17 percent felt "disappointed," 13 percent felt "betrayed," six percent felt "indifferent," and four percent felt "let down." Finally, one in five engage in fewer online activities due to security concerns.

The survey uncovered other key findings on how consumers protect their identities today when conducting transactions online:
  • -- 86 percent use a simple user name and password to enter accounts
  • -- 62 percent look for the lock icon in the address bar
  • -- 55 percent look for a logo or seal from the firm providing Internet security
  • -- 52 percent look for https:// in the address bar
  • -- 26 percent look for a green address bar
When asked how much savings they'd expect before considering shopping on an unprotected site, one in three consumers said they would expect at least a 30 percent discount. This finding suggests that businesses that don't provide security measures to gain consumer trust cannot anticipate getting the same value for their goods.

"The best security for consumers is education and using the latest tools and technologies that are out there to help counter fraud," said Craig Spiezle, chairman and founder of the Authentication and Online Trust Alliance (AOTA). "As we move more and more of our lives online -- for example, banking, shopping, paying bills, communicating, registering, renewing, etc. -- fraud threats follow closely behind. The key is to keep one step ahead by knowing how to protect yourself online, embracing best practices and using the latest technologies. Today more than ever users need to update their browsers with integrated security and privacy features to help stay ahead of the criminals."

About the Survey

The survey, which polled 919 U.S. adults 18+ who spend at least three non-work hours per week online, explores the degree to which consumers are concerned about online security, seeks to understand the role that security plays in consumer perceptions of online brands, and gauges consumers' interest and familiarity with authentication services on the market today.


Reblog this post [with Zemanta]

Wednesday, December 10, 2008

Lost: $4 Billion Online

Results of the tenth annual CyberSource Corporation survey of eCommerce fraud, released today, show merchants expect to lose a record $4 billion to online fraud in 2008.   All  the news today is pointing towards how pragmatic it would be to bring PIN based transactions online.
Fraudsters Filch $4 Billion Online in 2008

Record fraud losses for U.S. eCommerce; 10th annual CyberSource survey shows merchants shift priorities in down economy

They go on to report on the key take-aways from this year's survey which included:
  • Projected dollar losses to U.S. eCommerce will hit a record $4 billion in 2008 (up from $3.7 billion in 2007).
  • Merchants expect to lose 1.4% of their online revenue to fraud--this rate has held constant for the last 3 years.
  • This year merchants accepted a higher percentage of orders--working more aggressively to boost top line sales.
  • Though eCommerce sales are still increasing, 87% of merchants say they must fight fraud with the same or less staff in 2009.
  • Merchants showed a dramatically increased interest in more sophisticated automation tools.
  • Contrary to popular view, eCommerce is hardly hands-off. For each of the past 6 years, approximately 1 out of 4 online orders have been manually reviewed.
  • International orders continue to have over 3 times the fraud risk of orders from the U.S. and Canada.
continue reading

Reblog this post [with Zemanta]

Paradigm Shift E-vidence


The graphic on the left suggests that a  paradigm shift is occurring when it comes to where US Internet users choose to shop.  Retail or e-tail.  See: "Paradigm Shift - Retails 70%-22% Lead Evaporates." 

To further underscore this viewpoint, new numbers from Goldman Sachs indicate that e-tail sales volume packs a mean punch  as it has left a huge dent in  chain store sales compared to the same period last year.

Apply the numbers released Monday from comScore and it translates as follows:

Online sales  volume growth enjoys 22.5 times the growth rate of sales at comparative chain stores
.

That sounds like some heavy shifting.  Here's further e-vidence, as reported by Internet Retailer: 

Sales at chain stores last week were virtually unchanged from the corresponding week a year ago, rising a minuscule 0.4%, reports the Goldman Sachs weekly sales index.

By contrast, online sales last week were up 9% over the same week a year earlier, comScore Inc. reported Monday.


For the week that included the Friday after Thanksgiving, the traditional start of the holiday shopping season, sales were up 1.3% over the year-earlier week. Sales fell 0.8% from Thanksgiving week to the following week, according to the Shopping Center Council/Goldman Sachs index.

The tough economic and retail environment, which continued into early December, is likely to dominate the full month`s sales performance as well, says 'Michael P. Niemira, the shopping center council's chief economist. Given this, ICSC Research expects monthly comparable-store sales will be flat to up 1% for December with late holiday shopping driving the month`s overall performance.

The index represents comparable store sales.

Signature Debit Wrestles Fraud, Get's PIN'd

After reading articles like this, which basically state what everyone already knows... signature debit is much less secure than PIN debit, I wrestle with the idea that there must be forces in play who want to keep online debit (PIN debit) offline... It makes absolutely no sense.

Think about it...offline debit for online shopping is oxymoronic.  "Online debit for Online shopping" is about as pragmatic as it gets.

Again, PIN debit is preferred by merchants and consumers alike, and,  because it's more secure, interchange fees are 50% lower. Combine those facts with the global movement against Visa/MC to lower interchange and "online debit" for "online shopping" appears to be a no-brainer. Obviously, Avivah Litan is correct in her analysis that it all comes down to the fact that the forces that be, want the fees they derive from pushing (and rewarding the use of) a less secure "signature" product. It's nuts to me. Why fight high interchange when you can switch to PIN Debit and cut interchange in half?  Are retailers, thus their online counterparts fighting the wrong fight?

Visa bids farewell to signatures | Australian IT

VISA Australia plans to replace signatures with electronic identification for credit card transactions in an attempt to combat fraud.

The use of personal identification numbers (PINs) is part of a seven-pronged initiative to tighten the security of payment systems within the next five years, the company said.

In mid-year some merchants began accepting PINs as an alternative authorization method.

According to Chris Clark, Visa Australia general manager, the introduction of PIN as the cardholder verification method will add another layer of security for card present transactions. In addition, all online merchants in Australia will be required to check the three-digit security code on the back of the card, Visa said.

Data security protection for merchants processing less than 20,000 Visa e-commerce transactions annually will also be strengthened. Visa will also ensure all automated teller machines are chip-enabled and activated by 2013.

"The initiatives planned for the next five years will help to combat further all types of fraud and make the system quicker and easier to use," Mr Clark said. "While these initiatives are being implemented, consumers can continue to use the system, as they have done for years, with confidence."

He said the introduction of PIN as the cardholder verification method will add another layer of security for card present transactions.

Editor's Note: Thus, also introducing it for "card not present" transactions, (for which there's exponentially more fraud) also seems to be nothing short of simply a pragmatic move.

Visa plans to have discussions with the financial and merchant communities to set deadlines for the implementation of its security initiatives. According to the Australian Payments Clearing Association, fraud on locally issued credit cards jumped to $111.5 million last year, up from $85 million in 2006. Fraud involving credit cards used on the internet or in phone or mail transactions, known as card not present, hit $53.5 million, up from $32 million during the same period.





Reblog this post [with Zemanta]

"Just Another Mega Monday" Followup

'Mega Monday' Lived Up To Its Billing Say Online Retailers | Business | Sky News

'Mega Monday' turned out to be just that for online retailers as consumers flocked to buy their Christmas presents.

With sales volumes up 18% to £320m it was the biggest online shopping day of the year so far. But it was not the busiest, according to electronic retail industry body IMRG.

Research from IMRG member Hitwise showed traffic to retail sites amounted to 12.32% of all UK online visits. That made Monday December 8 the third busiest day in the sector, despite the high sales volumes.

Analysts say this suggests consumers have been busy at weekends researching gifts both in stores and online before purchasing the items on the internet the day after.

James Roper CEO of IMRG said: "Online sales are holding up well, considering the economic conditions, with both volumes and values significantly higher than last year.

"The ratio of researching to buying is also much greater, and researching started earlier this year, as Christmas shoppers work hard to track down the best deals."

But Jon Prideaux of payments service provider SecureTrading said it was a day of mixed fortunes for traders.

"The averages conceal that a significant number of retailers are facing a bleak Christmas with sales below last year - for others it's a bonanza with sales up very sharply.

"It is the first time that anyone can really say that about the e-commerce space where things generally just seem to get better and better for everyone. This Christmas is sorting out the wheat from the chaff."

'Mega Monday' followed the busiest weekend of the year on the high street with retailers offering huge discounts.

An estimated 1.5 million people flocked to London's Oxford Street and Regent Street on Saturday after the area was closed to traffic for the day.
Reblog this post [with Zemanta]

Skimmers Arrested in Sin City

Obviously this is relevant to the blog as I've posted many times about skimming, but, in all honesty, there are underlying reasons for this post...not the least being that it gave me my first opportunity to post a picture of Jessica Alba... :)

LAS VEGAS – State and federal authorities said Tuesday they arrested nearly two dozen people, many with ties to Eastern Europe, in a credit card fraud and identity theft scheme that cost Las Vegas businesses and consumers about $1.5 million.

Greg Brower, U.S. attorney for Nevada, said 13 people were arrested on federal charges Monday in southern Nevada and Los Angeles. Las Vegas police said 10 were arrested on state charges, including forgery, credit card fraud and weapons and drug possession.

The arrests were the first for a Eurasian organized crime task force based in Las Vegas. The task force was formed two years ago in response to "the influx and influence and activity of Eurasian-based gang-type criminals" in southern Nevada, Brower said.

In five indictments unsealed Tuesday, prosecutors describe an operation using "skimming equipment" at restaurants, smoke shops and convenience stores to obtain credit card numbers and personal identification numbers. Cashiers involved in the scam would use the device, known as a "wedge," to scan the card and capture information in the magnetic strip. (not the Las Vegas strip) The information would then be used to create counterfeit credit cards, the indictment said.

Authorities said they were uncertain of the defendants' immigration statuses and could not name their nationalities. Authorities said no businesses were implicated in the scheme. More than 1,000 credit and debit cards were compromised. The indictments handed down last month accuse 13 people of charges including producing, using and trafficking counterfeit credit cards, identity theft and criminal forfeiture.



Women Dominate for First Time Online

openPR.com - Press release - Deutsche Card Services- Women Predominate in European Online Retail for the first Time
Pago Retail Report 2008 - published by Deutsche Card Services - reveals large-scale changes in purchasing and payment behavior

Women predominate in European online retail for the first time. 53.40% of all transactions were initiated by women, 46.60% by men.

This is the result revealed by the Pago Retail Report 2008, which was just published by Deutsche Card Services, a member of Deutsche Bank Group. In the preceding year men still had a lead of more than 11%. In contrast to other research, this report of "Purchasing and Payment Behaviour in Online Retail" is based on real-life purchase transactions and not on the analysis of polls and surveys. The Pago Retail Report is based on the evaluation of about 7.5 million retail purchase transactions processed through the Pago platform between October 2006 and September 2007. The data analysis of purchasing and payment behaviour and non-payment risk was supported by experts from the University of Karlsruhe.

Weekend has caught up in overall European retailing

German female online customers have increased their lead more than their counterparts in Europe as a whole. They dominate retail at a rate of 55% versus 45%. For comparison: Men lead in the UK (52% versus 48%) and the rest of Europe (64% versus 36%). There is also a gender imbalance in terms of the preferred days for online retail purchasing. Women prefer Wednesdays with 17.41% of their retail transactions while Mondays are men's favourite days (17.15%). This purchasing day has replaced Wednesday as number one in overall e-commerce. By the way, Saturdays are least attractive for both women and men, with a share of only 10% according to the Pago Retail Report 2008. Generally, however, the weekend has caught up in European retail. In fact, consumers buy more in German shops on Saturdays than on Fridays (13.37% versus 13.29% of all weekly transactions).

German consumers prefer working hours for online shopping

What is the favorite time of the day for shopping? German consumers accomplish most of their transactions (e.g. 59.74%) during working hours between 8am and 6pm - not only in retail but also in overall e-commerce. This figure beats its counterpart for overall e-commerce (53.10%), which also covers segments such as gambling (gambling and sport bets), services (telecommunications and internet) and travel & entertainment. In the UK the preference for office hours is even more obvious (64.48%). This was to be expected, as this period was also top in overall e-commerce according to the Pago Report 2008.

"Erika Mustermann vs. John Smith"

German consumers' purchasing behaviour in online shops considerably differs from UK consumers as the comparison of "the typical German" with "the typical Brit" demonstrates. For example, "Erika Mustermann" prefers ordering her new winter boots for about EUR 70 in a popular German online shop on a cold December Monday during her lunch time between noon and 2pm. Whereas "John Smith from Sheffield" searches an online shop for home entertainment on a Tuesday a few days before Christmas just between 2pm and 4pm and buys at least a portable music player for the equivalent of about EUR 135.

Dutch consumers surprisingly active in European retail

According to the Pago Retail Report 2008 Dutch people are most active in retail purchases as far as the rest of Europe is concerned, just behind German and UK consumers. They achieve a rate of 27.33% and rank ahead of the Austrian and French consumers, who are placed third in overall European e-commerce. A look at the infrastructural basis in the Netherlands shows that their good ranking is not astonishing: According to the ComScore analysis 2008, 82% of the Dutch aged above 15 are online - the highest proportion in all of Europe, 32.8% use DSL - the highest proportion all over the world.

Pago Retail Report 2008 is extending the results of the Pago Report 2008

The Pago Retail Report 2008 differentiates between consumers from Germany, the UK, the rest of Europe and countries outside Europe. Due to Deutsche Card Services' licensing area the merchants come only from European countries. That is why the first interpretation of newer payment methods such as giropay and Maestro becomes even more obvious. They achieve remarkable rates outside of Germany. Only retail shops which offer certain goods and resemble traditional mail-order businesses are included into the evaluation. So the Pago Retail Report is extending the Pago Report 2008, which deals with the overall e-commerce and was published earlier in 2008.

The Pago Retail Report 2008 is available at a price of EUR 250 (plus VAT). For more information please visit www.ecommerce-report.de.



Reblog this post [with Zemanta]

More on PCI and Tiers 1, 2 and 3

The Payment Card Industry (PCI) compliance regulation affects almost all merchants that accept credit and debit card payments, with the goal of securing cardholders against vulnerabilities to card data theft, misuse or loss. The driving forces behind PCI compliance policies are the major credit card payment processors -- Visa, MasterCard, American Express, Discover Card and JCB International -- which formed the PCI Security Standards Council to define how retailers should protect transactional data and monitor their data security performance.

Each PCI Council member has defined categories of merchants based on the number of transactions submitted per year, along with PCI audit and reporting requirements pertaining to each category. The precise definition of each category varies between the credit card companies, but we will use Visa's categories to illustrate the scale (MasterCard and American Express generally have lower thresholds for each category):

  • Tier 1: The highest volume merchants, which submit 6 million or more transactions per year.
  • Tier 2: Merchants that submit 1-6 million transactions per year.
  • Tier 3: Merchants that submit 20,000 to 1 million e-commerce transactions per year.
  • Level 4: Merchants submitting less than 20,000 e-commerce transactions per year, and all other merchants up to 1 million transactions per year
Rightfully, merchants submitting higher volumes of transactions face the most stringent PCI compliance standards and penalties, due to the risks associated with the quantity of data they possess.   However, Visa reports that cardholder data is compromised more frequently among Level 4 merchants than by Tier 1, 2 and 3 combined -- small wonder, because 99% of the merchants that accept Visa cards are Level 4 merchants. 
When we talk about PCI compliance, organizations are often misled by five common myths about becoming compliant with the Data Security Standard (DSS) as outlined by the Payment Card Industry (PCI). Here, we break some of these common myths related to the PCI DSS.
Myth 1: Varying degrees of compliance are required.

The most common misconception is that there are varying degrees of compliance required, depending upon a merchant’s particular level which is determined by their annual number of transactions. The reality is quite the opposite. All merchants, regardless of whether they are a Level 4 with less than 20,000 transactions per year, or a Level 1 merchant with over 6 Million transactions per year, are all ultimately required to be compliant with the PCI Data Security Standard, (PCI DSS) as established by the PCI Security Standards Council. However, it is true that the timing of when compliance is required can vary depending upon a particular merchant level. Regardless of the actual deadline for a merchant, the PCI DSS outlines a comprehensive set of requirements that are focused on the following areas:

• Build and maintain a secure network.
• Protect cardholder data.
• Maintain a Vulnerability Management Program.
• Implement strong access control measures.
• Regularly monitor and test networks.
• Maintain an Information Security Policy.

Read more about PCI Data Security Standard on the PCI Security Standards Council’s website.

Myth 2: Only Level 1 Merchants are targeted for attacks or security breaches.
According to Visa, “Large (Level 1) merchants and processor breaches account for the majority of compromised accounts, yet small (Level 4) merchants account for over 85 percent of compromise events.”

Myth 3
: PCI Compliance is something that only the IT Department needs to worry about.
Requirement 12 states that an Information Security Policy must be maintained, which can impact every level and function within an organization.

Myth 4
: All PCI Data needs to be retained.
Not all PCI data may need to be retained. All too often, access to sensitive credit card data is restricted within an organization, but the retention of that data is not well-defined based upon a true business need. Organizations routinely do restrict access, but still allow a few individuals complete access to all unencrypted PCI data, which opens a wide door for a security breach or potential for data theft.

Myth 5: Executives may view PCI Compliance as done after an annual audit or after the completion of the annual self-assessment questionnaire.
Adherence to the PCI DSS needs to be embraced as part of the ongoing monitoring processes within an organization. Organizations that acknowledge the fact that security must be incorporated into every process recognize that it’s much more than an annual exercise.




Reblog this post [with Zemanta]

Will NFC Answer the Call?


NFC no answer for mobile, but alternatives offer promise

Once, NFC (Near Field Communication) was the leading contender among technologies that could enable mobile payments. But NFC has developed more slowly than anticipated, and will not offer viable large-scale mobile payment solutions for at least six years. In the mean time three existing technologies - SMS, mobile Internet and downloadable mobile applications - have the potential to deliver what NFC (so far) cannot.

"About half of all purchases made by consumers last year were made with cash," notes ABI Research senior analyst Mark Beccue. "Consumers would in many cases prefer cashless transactions when away from home. So around the world solutions providers have leveraged SMS, mobile Internet and downloadable mobile applications to enable mobile commerce and payments. ABI Research calculates the potential revenue in 2013 from mobile transactions using these methods at about $18 billion: a significant opportunity for payment processors."

A new ABI Research study examines the potential for mobile payments in four key vertical markets that will drive adoption: taxis, parking, movies, and Internet shopping. While the latter is usually done using credit cards anyway, the first three are areas in which mobile payments could replace cash transactions. The research found that Internet shopping would account for almost three quarters of this mobile commerce revenue in 2013. A further 15% would come from parking, with the balance split about evenly between taxi fares and movie tickets.

Beccue concludes, "Companies already seizing this mobile payment opportunity include parking solutions provider Verrus, Bharti Airtel and movie theater operators in India, and notably eBay and Amazon - the world's largest e-commerce merchants - which have enthusiastically embraced mobile transactions with very comprehensive offerings."

The new ABI Research study "Mobile Commerce and Payments"
http://www.abiresearch.com/products/RR/MPAT examines several emerging markets in which consumers are or will be using their mobile devices to purchase goods or services using SMS and mobile Internet. I

t highlights important players within the space, suggests who should play and who will benefit, and outlines what MNOs, merchants, and financial services providers can do to take advantage of these opportunities.

ABI Research is a leading market research firm focused on the impact of emerging technologies on global consumer and business markets. Utilizing a unique blend of market intelligence, primary research, and expert assessment from its worldwide team of industry analysts, ABI Research assists hundreds of clients each year with their strategic growth initiatives.

For information, visit www.abiresearch.com , or call +1.516.624.2500.

Source: Company press release.

Reblog this post [with Zemanta]

China/Motorola Set Up m-Commerce Lab


Motorola, CIECC to Set Up M-Commerce Laboratory in China

Motorola has opened China's first M-Commerce Laboratory in Beijing by joining hands with China International Electronic Commerce Center (CIECC), an agency under China's Ministry of Commerce. The objective is to accelerate mobile commerce development in China.

The M-Commerce Laboratory, according to Motorola, is designed to bridge the gap among industry, government and academia to facilitate certain aspects in the M-Commerce environment such as research and commercialization of mobile applications, mobile payment and security, and enterprise mobile commerce application. By providing an environment to study, develop and promote projects in the mobile commerce domain, the laboratory can help to enhance end-to-end innovation capabilities, believes Motorola.

"M-Commerce will play an important role in China's economic growth, specifically when the country is focusing on driving domestic demand," said Liu Junsheng, general director of CIECC. "Our goal is to develop key enablers, nurture the M-Commerce practice and business environment, and provide services to help enterprises mobilize their business. The establishment of M-Commerce Laboratory will play a vital role in facilitating mobile commerce development in China."

The laboratory will create a platform for the industry players to communicate and cooperate with each other. In addition to regular workshops and forums, the laboratory will also help members to screen out and identify projects for further commercial operation, speeding up the transition process from theory to commercial applications with the help of industry experts and academic institutions.

These efforts, says Motorola, will not only cultivate the mobile commerce environments, but also create real business opportunities for all companies who want to leverage M-Commerce.

Reblog this post [with Zemanta]

Mercator Study on Japanese Payment Market

Mercator maps 2008 Japanese payment card market

Boston, Dec. 9, 2008 -- With close to 800 million credit and debit cards in circulation at the end of 2007, Japan is one of the countries with the highest payment card penetration. Japanese residents on average have 6.2 credit or debit cards per person, higher than their peers in most card markets around the world including the United States where an average resident has 3.6 cards. However, the usage of these payment cards is quite low compared to their large numbers. An average Japanese resident spent just about $30 (US) on their credit and debit cards in 2007 while the number was close to $180 (US) in the US. As a result, Japan remains a cash-centric society and the payment market opportunities remain largely untapped by electronic payments.

The relatively low card usage in Japan can be attributed to a variety of factors, including but not limited to culture, industry infrastructure, card acceptance, and regulatory environment, among many others. For Japanese consumers, however, the reason could be as simple as that: it just doesn't provide enough value in terms of service quality, convenience, and flexibility for consumers to change their preference of cash.

As a result, despite credit card's relatively healthy growth in the past 5 years, it still has a long way to go in terms of becoming Japanese consumer's preferred payment method at POS. The industry has been undergoing a series of major restructuring and consolidation to adapt to changes in the market, competitive landscape and regulatory environment. As for debit cards, the market struggled in the past three years after the initial high-speed growth in the first several years after it was officially introduced in 2000.

However, the emergence of electronic money, namely payment cards and devices powered by a contactless chip, could bring a fundamental change to the way Japanese consumers make payments. Backed by prepaid card accounts as well as credit card accounts, e-Money services, have quickly become the most popular payment method at POS (besides cash of course, at least for now).

Terry Xie, Director of Mercator Advisory Group's International Advisory Service and principal analyst on the report, comments,"The e-Money services will be key to tomorrow's Japan payment card market. Its impact on the increasing use of prepaid cards are well known. But its implications are much more far-reaching than many have realized. For the first time in the history of Japan payment card market, electronic payment methods have become a really viable alternative to cash for payment at POS with its un-precedent level of convenience and flexibility. This will fundamentally change Japanese consumers' perception of electronic payments and its importance cannot be over-estimated. It is the critical market for not just prepaid cards but also credit and debit card industries in Japan. Especially for debit cards, unless the debit card industry figures out a way to get a piece of the fast growing e-Money market, their current struggles will continue."

The most recent report from Mercator's Credit Advisory Service provides an update of the Japan credit card market since 2002, which is the last year discussed in our previous Japan report. Key issues discussed in the report include market growth, profitability, changes in regulation, competitive landscape, recent restructuring, and consolidation activities, plus increasingly active international players. Key market stats, key strategic issues, and their implications on the overall market development are also discussed.

Highlights from this report include:

* Cash remains king in Japan, but this situation could change if Japan's payment card industry could find a way to offer the value proposition of cash replacements in different scenarios.

* Credit cards enjoy the highest usage rate among electronic payment products in Japan, but profit margins remain relatively thin despite high merchant fees. Japanese consumers have been using credit cards like charge cards, thus limiting the interest income potentials. Recent changes in consumer lending law do not help the cause.

* Debit card usage rates have remained low in Japan despite initial rapid growth immediately after the J-Debit scheme was introduced. Unless the industry could improve services and offer more convenience, it could face significant challenges going forward.

* E-Money emerged as the fastest growing market segment and its implications are far reaching. At the same time, there are critical issues that still need to be addressed.

* Restructuring and consolidation in the industry, and the increasing roles of non-bank and international players will significantly alter the competitive landscape in the Japanese payment card industry.

This report contains 27 pages and 7 exhibits.

Reblog this post [with Zemanta]

Disqus for ePayment News