Brian Krebs, writing for the Washington Post, covered this morning's announcement that Heartland Payment Services was breached. He is calling it one of the largest breaches ever, and according to him, Avivah Litan, a distinguished analyst from Gartner criticized and questioned as deceptive, the "Inauguration Day" release, apparently suggesting that it wouldn't get the coverage it would otherwise.
Payment Processing Breach May Be Largest Ever
A data breach last year at Princeton, N.J., payment processor Heartland Payment Systems may have led to the theft of more than 100 million credit and debit card accounts, the company said today.
If accurate, such figures may make the Heartland incident one of the largest data breaches ever reported.
Robert Baldwin, Heartland's president and chief financial officer, said the company, which processes payments for more than 250,000 businesses, began receiving fraudulent activity reports late last year from MasterCard and Visa on cards that had all been used at merchants which rely on Heartland to process payments.
The data stolen includes the digital information encoded onto the magnetic stripe built into the backs of credit and debit cards. Armed with this data, thieves can fashion counterfeit credit cards by imprinting the same stolen information onto fabricated cards.
"The nature of the [breach] is such that card-not-present transactions are actually quite difficult for the bad guys to do because one piece of information we know they did not get was an address," Baldwin said. As a result, he said, the prospect of thieves using the stolen data to rack up massive amounts of fraud at online merchants "is not impossible, but much less likely."
Avivah Litan, a fraud analyst with Gartner Inc., questioned the timing of Heartland's disclosure -- a day in which many Americans and news outlets are glued to coverage of Barack Obama's inauguration as the nation's 44th president. "This looks like the biggest breach ever disclosed, and they're doing it on inauguration day?" Litan said. "I can't believe they waited until today to disclose. That seems very deceptive."
World's first biometric, waterproof mobile surfaces
Fujitsu has launched what it claims is the world’s first waterproof handset with an embedded biometric sensor. Fujitsu's F-01A: waterproof and secure.
The Symbian-based F-01A supports e-Wallet transactions.
Combine this AND our PIN debit mobile platform and there would be triple-authentication protection for the m-commerce sector...
Biometric sign-in (who you are) authorizes and activates use of our SwipePIN device, which verifies card present (what you have) by swiping said card, and triple-authenticates the transaction by asking the user to enter their PIN. (what you know)
For more information on the biometric sensor manufacturer visit: Authentec
Credit Card fraud rates are "jumping" faster than ever, not just here, but around the globe. In this article, the APCA announced that there's been huge rises in CNP transactions and that credit card fraud spiked to 50.2 cents per $1000, or almost 7 times higher than debit's 7.4 cents per $1000 transacted. Here's the article from Karen Dearne, who writes for Austrailian IT.
CREDIT card fraud in Australia jumped to $233 million in the last financial year, up from $157 million in 2006-07, according to the Australian Payments Clearing Association.
The losses are due to increased fraud across borders, and huge rises in card-not-present (CNP) fraud involving online, phone or mail transactions. Editor's Note: Huge rises in card-not-present fraud can be eliminated by morphing them into card-present transactions with the HomeATM SwipePIN device...)
Total fraud on Australian credit cards amounted to $132 million; of this, $73 million was obtained by criminals using the cards in other countries. More than $63 million was lost to CNP scams ($22 million within Australia and $41.6 million on locally-issued cards used overseas).
Skimmed and counterfeit cards accounted for $42 million in losses ($18 million within Australia, and $24 million on locally issued cards used overseas).
For the first time, losses due to fraud on cards originally issued overseas topped $100 million; criminals using foreign cards within Australia reaped almost $101 million, up from $66 million in 2006-2007. The number of local cases involving skimmed or counterfeit cards from overseas almost doubled: more than 155,000 incidents were reported, resulting in total losses of $65 million, compared with 82,000 and $40 million the previous year.
At the same time, fraudsters used overseas cards to steal nearly $25 million through CNP transactions locally, up from $16.5 million.
APCA chief executive Chris Hamilton said credit and charge fraud now cost 50.2 cents in every $1000 of payments transacted, up from 38.6 cents previously.
Debit card fraud increased only slightly, from 7.1 cents to 7.4 cents in every $1000 transacted, reflecting the greater security of Eftpos and ATM networks.
In yesterday's last post: "Hackers Affect Debit and ATM Networks" I provided information from a story published by "The Times Tribune" that the STAR debit network had seen some suspicious activity and in a response to the situation, STAR said "the debit card issue we were alerted to could affect not only STAR but also other debit networks."
Earlier this morning, came news that one of the nations bigger processors, Heartland Payment Systems has been breached. Are they related or was Avivah Litan, distinguished analyst with Garnter spot-on when she said, "payments and funds transfer processors, rather than retailers are now the one's being targeted by hackers."
Is the "Mother of All Hacks" coming? In that post, when speaking of the recent Royal Bank of Scotland breach, I said: "There is a disturbing development brewing in the payments world. It's bad enough when a retailer's computer security is breached but now we've got us a completely different ballgame. When hackers penetrate the computer systems of major acquirers and processors, well to use a famous quote, "We've got a problem Houston."
This could turn out to be a "Royal pain in the ***" for Visa and Mastercard themselves because acquirers like Royal Bank of Scotland link directly into their networks. On the surface, this appears to be "one small step for hackers but it's "one giant step" for hack-kind."
In that post I quoted Ms. Litan as saying: “It’s very bad news,” says distinguished analyst Avivah Litan. Unlike retailers’ computer systems, processors’ systems connect directly to the networks of Visa Inc. and MasterCard Inc. “An attacker that breaks into a processor conceivably can get into the heart of the system,” and attacks on acquirers and processors are increasing."
Did she say "get into the Heart of the system?..." Man, she's like the Nostradamus of the payments world...stay tuned...
Heartland Payment Systems Uncovers Malicious Software In Its Processing System No merchant information or cardholder Social Security numbers compromised.
PRINCETON, N.J., Jan. 20 /PRNewswire-FirstCall/ -- Payments processor Heartland Payment Systems has learned it was the victim of a security breach within its processing system in 2008. Heartland believes the intrusion is contained.
"We found evidence of an intrusion last week and immediately notified federal law enforcement officials as well as the card brands," said Robert H.B. Baldwin, Jr., Heartland's president and chief financial officer. "We understand that this incident may be the result of a widespread global cyber fraud operation, and we are cooperating closely with the United States Secret Service and Department of Justice."
No merchant data or cardholder Social Security numbers, unencrypted personal identification numbers (PIN), addresses or telephone numbers were involved in the breach. Nor were any of Heartland's check management systems; Canadian, payroll, campus solutions or micropayments operations; Give Something Back Network; or the recently acquired Network Services and Chockstone processing platforms.
After being alerted by Visa(R) and MasterCard(R) of suspicious activity surrounding processed card transactions, Heartland enlisted the help of several forensic auditors to conduct a thorough investigation into the matter. Last week, the investigation uncovered malicious software that compromised data that crossed Heartland's network.
Heartland immediately took a number of steps to further secure its systems. In addition, Heartland will implement a next-generation program designed to flag network anomalies in real-time and enable law enforcement to expeditiously apprehend cyber criminals.
Heartland has created a website - www.2008breach.com - to provide information about this incident and advises cardholders to examine their monthly statements closely and report any suspicious activity to their card issuers. Cardholders are not responsible for unauthorized fraudulent charges made by third parties.
"Heartland apologizes for any inconvenience this situation has caused," continued Baldwin. "Heartland is deeply committed to maintaining the security of cardholder data, and we will continue doing everything reasonably possible to achieve this objective."
Forcht Bank disabled 8,500 customer debit cards this week after learning they could have potentially been hacked into by persons creating duplicate cards.
Eddie Woodruff, chief operations officer for the bank, confirmed that 8,500 of the bank’s roughly 22,000 total debit cards had been deactivated, but the move was primarily a precaution.
“Right now, none of our customers have reported any fraudulent activity on the cards,” Woodruff said. “We’re just trying to take every precaution.”
The cards were comprised when a retail merchant’s computer system was hacked, Woodruff said. The breach affected customers of multiple banks and multiple debit and ATM networks.
“Our debit card processor, which is a company called STAR, they had a retail customer, we’re not exactly sure who the retail customer was, and the information we believe may have been compromised,” he said.
First Data Corporation, which operates the STAR Debit and ATM Network, would not comment on how many other banks were affected, but did release in a statement Monday that "the debit card issue we were alerted to could affect not only STAR but also other debit networks."
The STAR system is used by 2 million ATM and retail locations across the country, according to its Web site.
“While we do not comment on specific matters pertaining to our customers, we can tell you this situation is not related to any First Data processing systems or practices,” stated Nancy Etheredge, spokesperson for First Data. “We are working with our clients, the card associations and card issuing and acquiring banks to monitor and help mitigate the issue and protect consumers.”
Minneapolis, Jan. 19, 2009 -- MoneyGram International (NYSE: MGI) today announced that in 2008 the company added 13 countries and territories and more than 33,000 locations to its global network, helping people and communities around the world by providing more convenient choices for safe and reliable money transfer services.
"Our continued growth--both international and domestic--is a reflection of growing consumer demand, fueled by ongoing global migration trends and our ability to deliver value to our customers and agents across the globe," said Tony Ryan, MoneyGram chief operating officer and executive vice president.
"MoneyGram's diverse, global agent network is our competitive advantage," said Ryan. "We will continue to invest in strategic growth by adding agent locations in key growth areas as well as expanding existing agent relationships, and growing our owned-retail presence."
In 2006, in response to business and market needs, MoneyGram launched its owned-retail strategy in France and Germany, and today operates more than 50 stores and kiosks in high-traffic areas in immigrant communities. Half of the countries joining MoneyGram's network last year are French-speaking, reflecting the company's commitment to serving the needs of France's large immigrant population. According to the World Bank, France is a top-five immigration country with 6.5 million immigrants.
"Our growth in France was vital to adding Algeria, which according to the World Bank, produced the largest influx of immigrants into the country," Ryan said. "Today, we have stronger prospects in the country for expansion through more traditional agent locations."
Germany is a similar success story for MoneyGram. The company established service to Serbia this year, which produces a high volume of immigrants to the country. MoneyGram has 30 owned locations strategically located in Germany.
"Network breeds network and feeds both expansions to new countries and increased locations in key areas around the globe," Ryan said. "The more we grow, the more interested retailers, post offices and financial institutions are in seeking our service to expand and grow their own businesses and offer more services to their customers."
Countries and territories added to MoneyGram's global network include the French-speaking Algeria, Central African Republic, Comoros, French Polynesia, Gabon, Madagascar and New Caledonia. Other countries include Angola, Bermuda, Bhutan, Czech Republic, Serbia, and Slovenia.
About MoneyGram International, Inc.
MoneyGram International, Inc. is a leading global payment services company. The company's major products and services include global money transfers, money orders and payment processing solutions for financial institutions and retail customers. MoneyGram is a New York Stock Exchange listed company with approximately 176,000 global money transfer agent locations in 180 countries and territories. For more information, visit the company's website at www.moneygram.com.
LONDON -(Dow Jones)- Planet Payment, a multi-currency and data processor, announced Monday that its Pay in Your Currency service, known in the industry as Dynamic Currency Conversion, is now being offered at Dillard's, a fashion apparel and home furnishings retailers in the United States.
The Pay in Your Currency service provides international shoppers paying for their purchases with Visa or MasterCard payment cards with the choice to pay in their home currency at the point of sale, rather than allowing their issuing bank to perform the conversion after the sale has been completed. The service provides greater clarity and certainty to international purchases by allowing the customer to pay in the currency that he or she knows best - their own. The service is being offered through Fifth Third Processing Solutions, (Cincinnati, Ohio) Dillard's current credit card acquirer. (END) Dow Jones Newswires 01-19-09 0327ET Copyright (c) 2009 Dow Jones & Company, Inc.
In an effort to reduce credit card fraud, HSBC announced it is going to analyze each and every transaction. This will result in both consumer frustration and inconvenience because a higher percentage of legitimate transactions will be declined. In addition, further inconveniences include the fact that consumers need to provide travel plans to banks, and banks are recommending the use of cash and travelers checks along with credit cards when traveling. It certainly appears that convenience has taken a back seat to security and our so-called "cashless society" has been put on hold a while. This from the BBC over the weekend....
Card fraud crackdown accelerated - Holiday makers are advised to take several different payment methods
A leading bank is introducing new technology which will mean that every credit card transaction will be scrutinized for fraud. HSBC is introducing the program, which will affect 10 million card accounts and millions of transactions. The banking industry has warned that more legitimate transactions will be queried or canceled as a result. Card fraud is rising - up 14% in the first half of 2008 - and fraud abroad now accounts for 40% of all card crime.
Travelers are being advised to take several different payment methods, including cash, credit cards and travellers' cheques when they go abroad.After several years of falling numbers, card fraud started rising again in 2007. Latest figures show that card fraud could have exceeded £600m in 2008, and banks are using increasingly sophisticated systems to try to outwit fraudsters.
HSBC previously checked 25% of card transactions but is currently rolling out a system that means all card transactions will be screened in real time, with a decision made in a fraction of a second.Bart Patrick of SAS UK, which is providing the software system for HSBC, said: "When you put your card in the machine it's carrying out an automatic check against your pattern of normal use - and making a decision about whether that is real or fraudulent."
He said banks were constantly battling with fraudsters to reduce the levels of crime."Card fraud is an arms race. The banks will come up with one way of dealing with it, the fraudsters will come up with a way round it."
"What we have seen with chip and pin - it was successful for 18 months, two years - the fraudsters have worked a way round it, so we are now looking at more sophisticated means."
However as the banks become more proactive in targeting fraudsters, more people could find their legitimate transactions are declined or queried.When Sally Wiber went on holiday to Borneo, she followed industry advice and told her bank where she was going. (See: Wanna Get Away?)
But her credit and debit cards were blocked when she tried to use them on her first day."I spent much of the first day trying to deal with my bank and getting internet access, and then had a rather frustrating phone call trying to make sure that I could use my cards for the rest of my holiday," she said.
The owner of a Redmond, WA tobacco shop was sentenced to less than three years in prison for skimming $300,000 off more than 300 credit cards. That's a little harsher than $200 bucks and get outta town" (see Saturday's post) but not as harsh of a sentence as the same crime will see in the future.
Here's the U.S. Attorney's Office news release:
HRANT "MIKE" ASLANYAN, 38, of Redmond, Washington, was sentenced today in U.S. District Court in Seattle to 33 months in prison, five years of supervised release and over $214,000 in restitution for Bank Fraud. ASLANYAN, the owner of a small tobacco and convenience store, pleaded guilty on June 13, 2008, admitting that he skimmed the debit and credit card numbers of more than 300 of his store customers. Those stolen numbers were used to steal money or incur credit from seventeen different banks. At sentencing U.S. District Judge Ricardo S. Martinez said, "This type of crime victimizes totally innocent people who are just going about their daily business." Judge Martinez ordered ASLANYAN taken into custody immediately to begin serving his sentence.
According to the Seattle Times Police Blotter: In late 2004 though early 2006, law enforcement investigated a rash of reports of compromised credit and debit cards. Dozens of people had their credit and debit cards used, without their permission, to withdraw money in the Las Vegas, Nevada and Los Angeles, California areas. Some seventeen financial institutions were hit for about $300,000. Some 300 Redmond area accounts were accessed. (Editor's Note: Just think how much more he could've made if Bill Gates was a smoker!) The place where each of the victims had used their credit or debit card, was "Smokers Choice" a small tobacco and convenience store in Redmond. Thirty-five of the victims specifically identified ASLANYAN as the person who had run their credit or debit card. The skimmer that records credit or debit card information was never recovered.
ASLANYAN has refused to assist law enforcement by identifying his co-conspirators who used the information to incur credit charges or raid victim bank accounts.
In asking for 33 months of imprisonment, Assistant United States Attorney Vince Lombardi argued that the victims go beyond the banks that lost money, to the people whose accounts were violated. "It is difficult to overstate the feeling of victimization felt by individuals who find their identity and account information stolen, merely because they chose to entrust Defendant with their debit or credit card when buying cigarettes or other items... Identity theft and related fraud crimes have been an epidemic in this judicial district ... this particular crime impacted hundreds of individuals," Mr. Lombardi wrote in his sentencing memo.
The case was investigated by the U.S. Secret Service, the Redmond Police Department, the Bellevue Police Department, and the Duvall Police Department.
Comment:
January 17, 2009 at 9:43 AM
$300,000 stolen, yet only $214,000 restitution ... how come not the whole $300,000 ?.. only 33 months in prison?? must have been some pretty heavy plea bargening going on here.. this sleeze should be made to pay back the WHOLE thing and do at least 10 years.. especially since he refused to co-operate with the investigators in naming his partners.. something here has gotta change in our "justice" system...
The Pulse Index is an annual tracking of online shopping activity during the holiday season. From November through January, Chase Paymentech monitors the daily activity of 25 of the largest 150 Internet retailers. The data includes the total number of payment transactions and total dollar value processed. The data is taken from transactions crossing Chase Paymentech's global processing platform. Final Results for Cyber Holiday Pulse Index
"The Pulse Index was remarkable this year," said Mia Shernoff, marketing executive for Chase Paymentech. "Because it tracks actual transactions on a daily basis for such a large number of major e-commerce merchants, the Index provided unique insight into the behavior of online shoppers and how the economic climate affected their buying patterns." Online Holiday Shopping 2008 - A Mixed Bag
For the 2008 holiday shopping season, the Pulse Index results represent online purchases beginning on November 1, running through December 31. While sales volume and transaction count both show an increase, the average ticket, or amount per sale, declined.
The statistics indicated:
Sales volume for the holiday season was up a modest 4.5 percent versus 2007.
Transaction count was up a significant 16.5 percent.
Average value per transaction was down an unanticipated 10.3 percent.
According to Forrester Research Principal Analyst Sucharita Mulpuru, the mixed e-commerce news highlights the environment faced by retailers this year. "This holiday season challenged all retailers," she said. "Web transaction volume was up significantly from last year, but the relatively lower revenue numbers point to aggressive discounting by retailers and eager deal-hunting by shoppers."
The tough shopping season, however, was an opportunity for some e-commerce merchants. Said Mulpuru, "A few branded retailers with very favorable pricing strategies were able to take advantage of the holiday season's circumstances and increase their market share. There should be a shakeout of Web retailers, but that will leave the remaining players more favorably positioned for growth into 2010 and beyond."
Additional highlights of the 2008 Pulse Index included:
The peak shopping season (the period between Thanksgiving and Christmas) sales were down 4.5 percent, but transaction volume was actually up 5.2 percent - this despite five fewer shopping days during this period versus 2007.
The largest day for transactions was Tuesday, December 16, with 3.96 million transactions. This was only slightly higher than Wednesday, Dec 17, which saw 3.95 million transactions.
The largest day for sales was Tuesday, December 2, with more than $218 million, topping Wednesday, December 17, which saw more than $217 million.
Said Aaron Press, director of market research for Chase Paymentech, "The practical lesson we took from this year's Pulse Index is that all of the hype surrounding Cyber Monday, is just that: hype. Merchants looking to capture additional sales or attract new customers should consider focusing their discounts and promotions on the middle of the week. Tuesday through Thursday is the peak shopping time for online consumers."
Mia Shernoff concluded, "There is a lot of value in being able to see the information and trends reflected in an index representing actual transactions among e-commerce merchants. It helps companies with everything from allocating resources to scheduling promotions during a crucial time."
Data and charts are updated daily, with weekly commentary to explain any trends, offer historical insight and provide context. Guest commentary will be provided by Sucharita Mulpuru from Forrrester and Aaron Press, Director of Market Analysis for Chase Paymentech. Visit the Pulse Index every business day at 2:00 P.M. EST to see the daily numbers, or subscribe to our weekly commentary via RSS. Media inquiries should be directed to James Wester, Director of Corporate Communications for Chase Paymentech at 877.843.5631 www.chasepaymentech.com
Back on November 11th, in a post I called "Short Circuit in Gift Cards?" I stated:
"If You've got a Circuit City Gift Card, Use it Now!
...Circuit City tried to reassure shoppers that it would be business as usual despite its Chapter 11 bankruptcy filing. I wouldn't be the least bit surprised, if and when the Circuit City gift cards do indeed short-circuit, to see the gift card landscape vastly affected forever. There needs to be either new regulation introduced or someone will have to come up with an improved program... otherwise consumers will shy away, from, especially the "closed loop" gift cards. So if you have a Circuit City gift card use it immediately..."
Hope you did, because yesterday Circuit City announced they are "shuttering" all 567 stores. If you haven't used them, there's no rush...you can shop at CircuitCity.com through tomorrow. (January 18th) Store liquidations begin as early as today and last until...?
According to the Chicago Tribune, "The sooner consumers use their gift cards, the better. Circuit City's group of liquidators have agreed to honor gift cards for at least the first few weeks. Deadlines for gift card use are expected to be posted in stores within the next couple of days."
"We are extremely disappointed by this outcome,” said James A. Marcum, acting president and chief executive of Circuit City Stores. He called the liquidation “the only possible path” for the 60-year-old company."
The NY Times writes: "The demise of Circuit City, while not surprising given its declining sales, is part of a radical shift (Editor's Note: call it "radical" but I say "paradigm") taking place in retailing. Weak chains — unable to weather the freeze-up in consumer spending and choked by tight credit markets — are closing.
Hmmm, I always thought that age-old line was "Don't do the crime if you can't do the time." Apparently that's not true in West Vancouver.
"Don't Refrain if You Can Gain" seems to be more applicable..
$200 bucks? Heck, go 72 mph in a 65 zone here and you'll be penalized more than that...
Here's a story from CTV British Columbia where they tell the tale of a PIN Pad thief who got fined $200 bucks and has to leave town by "high noon." Unbelievable. I've reproduced the comments from their site, and as you can read, people are getting fed up with these types of crimes. As I've posted in the past...why rob a bank? That's 20 years...this is $200 bucks. If he didn't get caught "red-handed" what would his take be? IMHO, the judge got this one "way wrong." At least the message he's sending is...
Here's the story: CTV British Columbia- PIN pad thief gets $200 fine and deportation order - CTV News, Shows and Sports -- Canadian Television
PIN pad thief gets $200 fine and deportation order Updated: Fri Jan. 16 2009 18:32:54 Darcy Wintonyk, ctvbc.ca
Police in West Vancouver have caught a PIN pad thief red-handed -- and kicked him out of the province. On Tuesday night, the owner of a Park Royal area juice bar called police after someone stole the PIN pad from the counter. He had just serving two customers and noticed that the device was missing.
Editor's Note: Notice the pic of the PIN Pad (below right) with a steel tether to prevent it from getting stolen...
Police apprehended the men shortly after near Marine Dr. and 14th St. after being alerted by a transit operator. After a brief investigation, police recovered the pad from a rental car parked nearby. On Thursday, 23-year-old Quebec native Jonathan Ramirez-Dionne pled guilty to theft under $5,000 in a North Vancouver courtroom.
"He was sentenced to one year probation and a $200 fine," says Const. Jeff Palmer.
But that's not all. The judge has also given the unusual order for him to leave the area. "An interesting aspect of his probationary requirement the judge has ordered him to leave British Columbia by four o'clock Friday afternoon and he's not to be found in British Columbia during the term of his probation."
The owner of the juice bar doesn't think the penalty is heavy enough. "It's funny because if I was caught speeding, it would be a bigger fine, and you know it's less of a heinous crime per say, and they get $200 which is a little bit bizarre," says Blake Goddard.
Police advise merchants to securely attach pin pads to counters at and to train staff to regularly check the devices. This isn't the first time Park Royal mall has been hit by debit thieves. Last March, police warned customers to change their PIN numbers after two La Senza's and an Aldo store had their PIN pads stolen. PIN pads don't normally record PIN numbers, but the devices can be modified to take in personal information. In August 2007, phony PIN pads turned up at four retail stores, including and thieves used the stolen information to withdraw money from hundreds of accounts.
Please Add Comments(7) Don I like that the judge told him to get out of BC. I think 200 dollars is pretty light as a fine for this type of crime though. Pat in the Valley What kind of justice is this - first he breaks the law, can steal potentially mega bucks and all he gets is the boot from the Province. When will the Justice System finally get it? and hand out appropriate sentencing and not just another "slap on the wrist". Christine That is ridiculous! $200 fine, what a joke! How will we know that the guy is actually leaving the Province and who is going to keep track of him? Ashley What a joke that is! Apparently in BC and in Canada it pays to lead a life of crime. Wasn't too impressed to be watching this story on the 6pm news on CTV and watched the report show the viewers exactally how to remove it. I know its not rocket science but come on.. C Umm... I agree with your statement "PIN pads don't normally record PIN numbers, but the devices can be modified to take in personal information." but your on-air story is misleading viewers that PIN pads ARE storing information when they DO NOT. Only counterfeit PIN pads store/steal information. Aden Thats awsome thats what you get when you steal from our province Au revouir frenchy Bangedup what a joke - time to change the laws
According to CardTrak.com credit card balance payments saw their largest drop ever, from October to November. (Guess December's data hasn't arrived yet...)
The amount that consumers pay on their monthly credit card balances dropped like a rock in November to a record low. Generally cardholders, including those who pay the minimum due and those who pay the full balance off each month, pay on average, about 18% to 20% of their monthly outstanding balances.
During October cardholders paid 18.42% of their balances which collapsed to 15.96% in November, Clearly, the credit squeeze that began in mid-Septembertrickled down much faster than expected. The impact of job losses cannot be understated. In December, the number of unemployed persons increasedby 632,000 to 11.1 million and the unemployment rate rose to 7.2%. Since the start of the recession in December 2007, the number of unemployedpersons has grown by 3.6 million, and the unemployment rate has risen by2.3 percentage points.
PAYMENTS June 08: 19.54% July 08: 19.54% August 08: 19.21% Sept. 08: 18.57% Oct 08 18.42% Nov 08: 15.96%
eMarketer reports that the recession may be contributing to increasing usage of the Internet among leisure time activities.
Of course, by the same token, one could argue that the recession, which has cause many job losses, could "reduce" the percentage of "leisure time" spent online, as people would be an additional 10 hours per day of leisure.
That would equivocate to needing to spend an additional 3 hours per working day (15 hours per week) online in order to retain the 30% level that US Internet users are now at. When looking at the chart on the right, I'd be interested in hearing theories behind the 72% spike in usage from 2006 to 2007. Internet Users Spending Even More Time on Web - eMarketer (click to read entire story)
"According to eMarketer, US adults are not world leaders in spending leisure time online. That distinction goes to Internet users in China, who spent 44% of their leisure time on the Internet in 2008, according to TNS Global. The company found that Americans ranked fifth worldwide, at 30% of leisure time spent online virtually tied with Italy (31%), Spain and Australia (29% each)." (Click Graph on Left, To Enlarge)
The study also found that many activities which we traditionally did in our spare time are now being done online. Three-quarters of Britons have used the internet for banking in the past month and two-thirds have also paid bills online. Seventy-five per cent of British respondents had read news online in the past month, while 62% had checked the weather. More Britons (55%) had watched a video clip on sites like YouTube than had listened to audio (44%) or participated in an online auction (39%). Social networking sites had been visited by 37% of people, while 32% had downloaded music.
Seven per cent of Britons called themselves bloggers, with 16% saying they had "viewed or contributed" to a blog, compared with 88% of Chinese respondents.
The poll of more than 27,500 people in 16 countries found that housewives in the UK spend 47% of their leisure time on the web, compared with 39% for students and 32% for the unemployed. Globally, the average across all occupations was 29%.
Of the 16 nationalities surveyed, Scandinavians seemed the least inclined to while away their free time in front of the computer - Danes spent an average of 15% of their non-work hours on the net, with Swedes at 18% and Norwegians at 22%.
Arno Hummerston, managing director of TNS Global Interactive, said: "If our leisure time is so precious, then why do we on average spend almost a third of it using the internet? We believe it is because we are making more efficient use of our valuable time, specifically by using the internet - thereby allowing us to fit more into our lives...
On Monday, in a post entitled "Gaza Strip(s) PC of Financial Data" I talked about a new(s) attack. "Using mainstream news headlines regarding recent events in Gaza, it lures people to a site that appears to be CNN. The bad news is, it isn't CNN...it's a clone, and there is nothing which clearly indicates that you've been duped." It then downloads a trojan which sweeps your hard drive looking for data relating to financial institutions.
In a post, earlier this month, (E-Commerce and Browsers Don't Mix) I talked about browser weaknesses. With the emergence of these two "new attacks" (the other one being "in-session phishing"...see "Phishing 2.0 - PAN Fried, not even 15 days into the New Year, it's becoming clearer that financial transactions need to be done outside the browser space.
Last night, I noticed that Gartner's Avivah Litan did an analysis on the Gaza Cease-Fire Trojan. Based on the title of her post, (and her bullet point, both of which I outlined in yellow) it's safe to assume that she feels along the same lines as we do, regarding the weaknesses inherent in web browsers.
Avivah Litan VP Distinguished Analyst Potomac, MD USA
Avivah Litan is a Vice President and Distinguished Analyst in Gartner Research. Her area of expertise includes financial fraud, authentication, identity theft, fraud detection and prevention applications and other areas of information security and risk. She also covers payment systems and financial flows in the business-to-consumer and business-to-business markets.
A new trojan attack shows that seemingly "safe" Web sites can be used in financially targeted attacks. Enterprises need to take a layered approach to these attack vectors, which mostly lie outside their control.
Event
On 7 January 2009, the RSA FraudAction Research Lab discovered a trojan attack, identified as the Cease-Fire Trojan Attack, that used phishing e-mail supposedly offering Al Jazeera video on CNN of the war in Gaza to divert recipients to an imposter news Web site. Recipients who clicked on a "video" link were told they need to update their media players to run the video. When they tried to do so, a "Secure Sockets Layer (SSL) stealer" trojan was downloaded to their desktops.
"The trojan resides in the end user's Web browser, waking up when SSL encryption is invoked via the HTTPS protocol typically used for online financial transactions such as payments and banking. The trojan then tracks the user's keystrokes to steal transaction information."
RSA reports that it shut down the attack, which was staged at a registrar in China, and that it discovered and took down a second wave of attacks — staged on five other domains on 9 January — within four hours.
Analysis
Trojans delivered via phishing attacks are certainly not a new phenomenon, and security providers report that the frequency of these attacks is increasing rapidly. This particular attack is significant because it offers a clear demonstration of:
A comparatively new type of combined phishing/trojan attack that uses social engineering to prey on sympathies and interests (in this case, promising graphic images of war)
An attack using brands (for example, those of news organizations) that attackers rightly believe are less likely to be the targets of phishing attacks than financial service providers and therefore less likely to take proactive action against them
Criminals' ability to place programs inside browsers, making it possible to bypass the security protections offered by SSL encryption and by strong authentication techniques going through a user's browser
It is important to note that RSA shut down this attack as a public service, and that there is no guarantee that security providers will perform such services in the future. Enterprises must take action to protect themselves and their customers, clients, partners and other stakeholders against attacks of this type. Recommendations
Enterprises that store customer information, financial accounts, transaction information or other sensitive data:
Recognize that customer account credentials can be compromised and that many criminal attack vectors are outside your domain and your control.
Deploy a layered security strategy that includes fraud detection, stronger user authentication and out-of-band transaction verification for high-risk transactions.
Deploy browser-based "on demand" desktop security services to your customers, because these can, when used in conjunction with better local browser rules and recognition of high- assurance certificates, help to protect customers accessing your Web sites.
Internet infrastructure and security providers:
Consider pooling your resources and launching a joint phishing/malware detection and site-takedown service that can be offered on a pro bono or as-needed basis. This approach would make it possible to quickly block attacks against real or fictitious brands that are detected in the course of normal "cybersurveillance" services, even if no specific financial incentive to do so exists.
In an attempt to dispel myths regarding Interchange, MasterCard has put together a brochure (PDF) designed to show how priceless Interchange is.
They have also created several documents trying to "discount" charges that interchange is too high.
It all makes for some interesting reading. Below I have included links from their website, followed by their press release.
From MasterCard.com
Every business establishes a price for the goods and services it provides, and the electronic payments business is no exception. As one element of the cost of acceptance, interchange is a small fee in relation to the enormous value merchants receive for accepting MasterCard payment cards.
For almost 40 years, MasterCard has established default interchange fees that have proven to be the most efficient way to balance costs in the system and promote a strong, competitive payments industry that benefits cardholders, merchants and financial institutions. Today, some 25,000 financial institutions provide the cards and services that allow hundreds of millions of consumers and 25 million merchants around the world to benefit from the convenience and security of electronic payments.
Learn more about interchange from the information below:
MasterCard dispels myths, highlights benefits of payment networks
Purchase, N.Y., Jan 15, 2009 -- In light of the ongoing discussion and debate about the role of credit in today's economic environment, MasterCard Worldwide has issued a paper that dispels misperceptions (Editor's Note: shouldn't it be "misconceptions" or am I "misperceiving" this?) about payment systems and explains the tremendous economic value that electronic payments bring to the economy as a whole and their role in advancing commerce.
The paper, entitled "Benefits of Open Payment Systems and the Role of Interchange," underscores the enormous benefits delivered by electronic payments, which have become so ingrained in everyday life they are often taken for granted or misunderstood. Few people ever stop to consider the complex and sophisticated system that allows transactions to occur within seconds, almost anywhere in the world.
"Perhaps the easiest way to grasp the value of electronic payments is to envision a world without them. Clearly, if electronic payments came to a sudden halt, many facets of commerce - travel, trade and the Internet just to name a few - would face dire consequences," MasterCard President and CEO Robert W. Selander says in the introduction.
The paper also discusses the role of interchange - a relatively small fee paid for the benefits merchants get from card acceptance. Interchange is critical to ensuring the system provides maximum benefits to all participants, including consumers and merchants in a fiercely competitive marketplace.
MasterCard Worldwide advances global commerce by providing a critical economic link among financial institutions, businesses, cardholders and merchants worldwide. As a franchisor, processor and advisor, MasterCard develops and markets payment solutions, processes over 18 billion transactions each year, and provides industry-leading analysis and consulting services to financial institution customers and merchants. Through its family of brands, including MasterCard®, Maestro® and Cirrus®, MasterCard serves consumers and businesses in more than 210 countries and territories. For more information go to www.mastercard.com .
Google Checkout adoption is dropping. Maybe they ought to start "searching" for ways to increase market share. Maybe a globally patented PIN debit application from HomeATM would help...
The adoption of Google Checkout by online retailers is stalling, according to a study by interactive agency Rosetta.
The report states that 37% of 100 leading online retailers surveyed currently offer alternative payment methods, a 23% increase since November 2007.
Of those, Bill Me Later is most popular at 26%, with PayPal now nearly tied at 25%. Google Checkout showed a tiny increase from 10% in 2007 to 11%. Only 7% of the retailers examined offer all three methods.
“Even though it boasts high consumer confidence, Google Checkout is struggling in retailer adoption,” said Adam Cohen, a partner at Rosetta's consumer goods and retail practice, which conducted the study last month. “Adoption of the service started out very strong last year, but has stagnated in the last 12 months."
The discontinuation of incentives for retailers during the holiday season is likely to negatively impact Google Checkout adoption on an ongoing basis, he said.
CreditCards.com has provided an interactive guide to show how merchants and banks process cards purchases. For the interactive guide click here, (or the graphic on the left)
For a printable version, click the PDF link at the bottom of this post.
How credit card transactions work Interactive guide shows how merchants, banks process card purchases
By Tyler Metzger - CreditCards.com
More than 23 billion credit cards transactions were processed in the United States in 2007, and they are projected to grow by 26 percent over the next five years, according to the Nilson Report. But have you ever wondered what exactly happens after your card is swiped? Use this guide to to find out how your credit card transactions are processed. PDF
On November 24th, I posted about Symantec's release of a detailed report called the "Internet Security Threat Report." That report is now available to anyone who wishes to download the whitepaper.
This from their website. For your convenience, I have included links to more detailed information. Click any of the graphics to enlarge.
The Symantec Report on the Underground Economy examines activity on underground economy servers observed by Symantec between July 1st, 2007 and June 30th, 2008. It includes analysis and discussion of the goods and services advertised, advertisers participating in the economy, the servers and channels that host the trading, and a snapshot of piracy activity observed.
As I previously stated, this report, is now available to the general public for free download.
Symantec Weblog: Postings on the Underground Economy Learn more
Report Highlights
"The underground economy has matured into a global market with the same supply and demand pressures and responses of any other economy. There are a great many servers and channels available to advertisers to market their wares, which they do, and often. Most people associate identity theft with money because most reported cases involve criminals using the identity for activities such as obtaining credit cards, applying for loans, obtaining expensive medical or pharmaceutical treatments, or even stealing house titles. Symantec estimates the value of total advertised goods on underground economy servers was over $276 million between July 1, 2007 and June 30, 2008.
During the reporting period, Symantec monitored 44,752 unique samples of sensitive information publicly posted on underground economy servers, which accounted for 10 percent of the total distinct messages. Sellers often publicly post samples of their goods in the channels on underground economy servers. These samples serve several purposes: to prove that sellers actually have the goods in their possession; to show potential buyers the quality of goods they can expect; to enhance their credibility, and; to allow users to validate the information. The table (above left) identities the top samples of information posted:
Credit card information may rank high because there are many ways it can be obtained and used forfraud. This includes phishing schemes, monitoring merchant card authorizations, the use of magnetic stripe skimming devices, or breaking into databases and other data breaches that expose sensitive information.
Another explanation may simply be that there is a high frequency use of credit cards.
For example, the 22 billion credit card transactions in the United States in 2006 represent a growth of eight percent over the previous year. High frequency use and the range of available methods for capturing credit card data would generate more opportunities for theft and compromise and, thus, lead to an increased supply on underground economy servers.
Credit card information may be in such demand because using fraudulent credit card data for activities such as making online purchases is relatively easy. Online shopping can be easy and fast, and a final sale often requires just credit card information. Someone knowledgeable enough could potentially make many transactions with a stolen card before the suspicious activity is detected and the card is suspended.
The second most common category of goods and services advertised was financial accounts, with 20 percent of the total. This category includes bank account credentials, magnetic stripe skimming devices, online payment services, online currency accounts, and online stock trading accounts. This category ranked third for advertised requests, with 18 percent of the total. By far the major contributor to the popularity of the financial accounts category was bank account credentials, which accounted for 18 percent of all goods and services advertised for sale.
Financial accounts are attractive targets because of the opportunity to withdraw currency directly. Although this may involve more steps than using stolen credit card data to make online purchases, the process of cashing out financial accounts can be easier than retrieving cash from credit cards because criminals would require a PIN for the card. Also, most ATMs have security cameras, which may deter criminals from using this medium. In addition, withdrawing currency from a bank account has the advantage of a more immediate financial reward than with online purchases, which would need to be sold to realize a purely financial reward.
Credit card information includes credit card numbers, credit cards with CVV2, and credit card dumps; financial accounts includes bank account numbers, magnetic stripe skimming devices, online payment services, online currency accounts, and online stock accounts; spam and phishing information includes email addresses, email passwords, scams, and mailers; withdrawal services include cash outs and drops that are used to withdraw money and items from purchases; identity theft includes full identities and Social Security numbers; server accounts are for file transfers and virtual networks; compromised computers includes hacked computers, bot-infected computers, and shells; website accounts include online accounts for access to specific websites such as social networking sites; malicious tools includesWeb-based attack tools and malicious code; and retail accounts includes gift cards for online stores and online auction accounts.
Magnetic stripe skimming devices are small machines designed to scan and retain data contained in the magnetic stripes on credit and debit cards. To cash out bank accounts, individuals can either use a reliable cashier or can assume the identity of the bank account owner to withdraw funds. Since many bank accounts can only be cashed out from within the issuing country, criminals may prefer the use of cashiers that specialize in extracting currency from these accounts. Such cashiers use a variety of methods to convert the information into true currency, transferring money either through wire transfers or to online currency exchange accounts. They can also hire an intermediary to receive the transfer in person using a fake identity. Symantec observed requests on underground economy servers for cashiers in specific locations and of a particular gender (as matchingthe cashier’s gender to the identity of the bank account holder is essential to not raise suspicion when withdrawing funds).
January 17, 2009 at 9:43 AM