Thursday, May 28, 2009

"Both Sides of the Mouth Syndrome Syndicated

Information Security Resources , an industry leading "InfoSec" blog shared the BSMS with their readers.   

Both Sides of the Mouth’ Security Analysis

May 27, 2009 by ADMIN · Comment

By John B. Frank, Marketing Strategist with HomeATM ePayment Solutions

It was nice that Javelin Strategy and Research took the time to write about HomeATM in their analysis of Finovate Startup09, but I’m a little confused about something they say in their report.

Maybe a reader might be able to clarify what they mean, because right now I’ve got  a kindova BSMS (Both Sides of the Mouth Syndrome) taste in my - for lack of a better word - mouth.

Why do I say BSMS?

Well, in the first portion of Javelin’s analysis of HomeATM, they say that our Safe-T-PIN device provides (the more secure) card present (vs. the less secure card not present) credit card transaction, and the even more secure PIN Debit transaction.

Here’s their quote:

Launched in April 2009, P2P Safe-T-PIN offers home-based “card present” credit card and PIN debit transactions online using a PCI-certified device attached to a personal computer through a USB port.


Users also could make online purchases by swiping their credit card or debit card and PIN at checkout. The device allows for secure real-time money movement with an option for delayed transactions.


Then, after stating that, the next thing they say is:


There is greater potential for HomeATM as a frequent high-value P2P solution such as a Western Union money transfer than for enabling e-commerce. Many consumers may be hesitant to swipe their ATM cards on hardware attached to their computer because of security concerns.

Therein lies my confusion.

First they state that our PCI certified device allows for “Card Present” and “Online PIN Debit” transactions, along with the statement that our device ALLOWS SECURE REAL TIME MONEY MOVEMENT, and then in their next breath they say that many consumers may be hesitant to use that very same PCI 2.0 Certified PIN Entry Device because of security concerns?

Did they possibly mean to imply that many consumers may be hesitant to swipe their ATM cards on hardware attached to their computer because they don’t want “improved” security?


Someone help me out here!  I’m not being sarcastic.  I’m being serious. Okay, I admit…I’m being totally sarcastic. But there’s good reason; in fact 117 good reasons. You may have noticed when you first visited the HomeATM site, there was a popup that appeared asking if you would please partake in our survey.


Well, I started the survey yesterday and already have 117 responses, and it doesn’t appear to me that very many consumers may be hesitant to swipe their ATM (or debit or credit) cards on hardware attached to their computer.  In fact, 117 said they would prefer to Swipe their Card and 117 said they would prefer NOT to Type in a Username/Password.


Click below to enlarge and read two questions pertaining to whether individuals would prefer to Type or
Swipe their Card information at a merchant website or Online bank:







The analysis did go on to say that two of the “differentiators” enjoyed by HomeATM is that we provide “end to end encryption” and our device is PCI certified, so I’m still left confused by what they meant about many consumers being hesitant because of security concerns… chime in if you know!


HomeATM Differentiators:


• A HomeATM Mobile device will be available for mobile phones with Web access, allowing transactions on the go
• PCI-certified device
• Hardware-based end-to-end encryption
• 100% acceptance with all bank cards

Author’s Note:  Plus our PCI 2.0 Certified PED also “encrypts” the Track 2 data and utilizes DUKPT key management as an additional layer of security.


HomeATM’s Engineering Team Designed and Manufactures the World’s FIRST and ONLY PCI 2.0 PIN Entry Device Specifically Designed for eCommerce. Our device provides “Card Present” rates on credit cards and “True PIN Debit” Interchange on debit cards as well as secure 2FA authentication for online banking sites and live, “real-time” money transfer from P2P, B2B, B2P, P2B and mobile.


To learn more about our product’s and services click here or email us at: info@homeatm.net


Stay Informed With RSS Feeds or Email Alerts Here: 










Reblog this post [with Zemanta]

Debit Card Transactions Grow 48%, Credit Cards 12.7% - RBI

Consumers prefer debit cards in slowdown
Consumers prefer debit cards in slowdown
BS Reporter / Mumbai May 29, 2009, 0:28 IST

The number of debit card transactions increased by 48 per cent in financial year 2009, compared to an increase of 12.7 per cent for credit cards in the year. Similarly, debit card volumes grew by 44.6 per cent, whereas credit cards saw a volume growth of 13.7 per cent for the same period, says the Reserve Bank of India’s data.

Sector experts attribute this surge in debit card usage to the ongoing economic slowdown and the cautious attitude towards spending money. Add to this the diminished focus of banks in issuing credit cards.

The pattern is starker in a quarter-on-quarter analysis by Venture Infotek, a transaction management company. Debit card transactions showed an increase of 88.6 per cent, against a rise of 34.5 per cent for credit cards for the March. In value terms, daily transactions through debit cards increased by 73.4 per cent vis-à-vis an increase of 24.8 per cent in credit card transactions.

“This shows the Indian consumer is behaving cautiously. Debit cards bring in the discipline of spending only the money you own. Besides, credit is scarce in a recession and credit card companies are vary of extending credit loosely,” said Piyush Khaitan, Managing Director, Venture Infotek.

The total value and volume of point of sale transactions through credit cards in March has declined by 11.9 per cent and 3.9 per cent, respectively, over April 2008, says the RBI data.

It also shows the number of credit cards in circulation has declined from 28.3 million cards in April 2008 to 24.6 million cards in March 2009. Whereas debit cards have registered an increase of 30.9 per cent, to touch 137.4 million in March 2009.


Emerging Bank Markets in the U.S. 2009

Emerging Bank Markets in the United States 2009

Mintel, March 2009, Pages: 56

Description

Since the last survey that we conducted of the unbanked and underbanked markets, two significant developments have taken place: the financial crisis and the election of President Barack Obama. These two events offer both good news and bad news for those looking to market to the underbanked. On the one hand, those distrustful of the banking system are now even more distrustful. On the other hand, as the majority of unbanked and underbanked consumers are immigrants, this poses a possible opportunity.

Due to problems in the banking industry, banking institutions will need to look towards new revenue streams. Though banks are more risk-averse, there is evidence that the underbanked are not necessarily high risk and are actually careful consumers. Given their population growth rates, it is a huge economic opportunity.

This report includes key information about the growing numbers of unbanked and underbanked consumers:

-What are the demographics of the unbanked and underbanked?
-What are the factors that lead to distrust and/or underuse of banks?
-Which segment(s) has the greatest growth rate?
-What are methods to market to the unbanked and underbanked?

Table of Contents




Reblog this post [with Zemanta]

US ATMs: Rebuilding the Foundation - Aite Report















A New Report From Aite Group
US Bank ATMs" Rebuilding the Foundation


In order to improve the overall ATM customer experience, banks must first make sure their
underlying ATM technology is up-to-date.


Boston, MA, May 28, 2009
– A new report from Aite Group, LLC examines how the ATM channel is
expected to evolve through 2010. Based on interviews with bank ATM
channel executives at 23 of the top 80 U.S. banks by number of checking
accounts, the report prescribes recommendations for banks and vendors
participating in the U.S. ATM market.


Today,
as banks embrace the potential to add additional features and
functionalities to ATMs, they realize that they must first update their
underlying technology. In five years, 91% of ATM executives indicate it
will be important or extremely important to their bank's strategy to
create a differentiated ATM experience through customer
personalization. If the foundation is not yet built, banks will not be
able to provide the level of personalization their peers are currently
starting to implement.


"Many banks are currently using outdated ATM technology, and see themselves as lagging behind the competition
when it comes to service at the ATM channel" says Kate Monahan,
analyst with Aite Group and author of this report. "Until updates are
made, service will continue to suffer at the ATM channel and areas of
opportunity for personalization at the ATM, such as marketing to
customers on a one-to-one basis, will not be possible."


This 39-page Impact Report contains 31 figures. Clients of Aite Group's Retail Banking service can
download the report by clicking on the icon to the right.



, ,

Western Union Option to Receive Funds via Online Banking

Press Release Source: Western Union
Western Union Offers Customer Option to Receive Funds via Online Banking at www.garanti.com

Service Launched with New Agent, Turkey’s Garanti Bank

ENGLEWOOD, Colo. & ISTANBUL--(BUSINESS WIRE)--The Western Union Company (NYSE: WU - News), a worldwide leader in money transfer services, announced today the launch of a service that allows online banking customers in Turkey to receive money transfers directly into their bank accounts. The service is offered through a new Agent, Garanti Bank, Turkey’s second largest private bank. Online banking customers can also send money from the website at any time to more than 334,000 Western Union® Agent locations in over 200 countries and territories.

The model may be applied further in Turkey and in other markets around the world.

“Western Union continues to drive industry innovation to meet a growing demand for convenient, reliable online services,” said Hikmet Ersek, Executive Vice President and Managing Director for Europe, Middle East, Africa, Asia Pacific. “This is the first time a Western Union customer in Turkey will be able to choose between the traditional method of receiving cash at an Agent location and having funds sent directly into his bank account, without having to go to a physical location or talking to a call center.”

Ali Fuat Erbil, Executive Vice President of Garanti Bank, said: “Garanti Bank is known for its dynamic business approach and commitment to technological innovation. We have achieved many firsts in Turkey and are delighted to be part of using the Internet to bring a new level of convenience and efficiency to our customers.”

The service is aimed at busy people who do not have time to visit an Agent location and is available 24 hours a day, seven days a week. Customers can send and receive funds using their online Garanti Bank accounts by following a few simple steps. The Western Union Money Transfer® service is available at more than 4,000 Agent locations in Turkey through Ziraat Bank, Turkish Post, Finansbank, ING Bank, Denizbank, Fortis, Türkiye Finans and TBank.

About Western Union

The Western Union Company (NYSE: WU - News) is a leader in global money transfer services. Together with its Orlandi Valuta and Vigo branded money transfer services, Western Union provides consumers with fast, reliable and convenient ways to send and receive money around the world, as well as send payments and purchase money orders. It operates through a network of more than 379,000 Agent locations in over 200 countries and territories. Famous for its pioneering telegraph services, the original Western Union dates back to 1851. For more information, visit www.westernunion.com.

About Garanti Bank

Established in 1946, Garanti Bank is Turkey's second largest private bank with assets reaching in excess of $63 billion as a result of its customer centric approach and innovative culture. As a universal bank with leading presence in all business lines, Garanti serves to over 8 million customers in corporate, commercial, SME, and consumer segments offering fully integrated financial services through its 9 financial subsidiaries that include payment systems, pension, leasing, factoring, brokerage and asset management. Committed to its customers, Garanti with over 16,000 employees operates an expanding distribution network comprising more than 730 branches including five foreign branches and four international representative offices, more than 2,600 ATMs, an award-winning call center and an Internet and mobile bank utilizing its state-of-the-art technology. Garanti supports its extensive branch network with centralized operations, exceptional data warehousing and management reporting systems, and the efficient use of alternative delivery channels. Garanti’s wide product variety combined with custom-tailored solutions is a key competitive advantage in its success as Turkey's largest lender providing more than $44 billion in cash and non-cash loans. For more information, please visit www.garantibank.com.





Reblog this post [with Zemanta]

LifeLock Fraud Service Ruled "Ilegal"

Judge Rules LifeLock’s Fraud Alert Service Illegal


lifelock_ceo_ssnumber_2
In a decision that has privacy advocates and others scratching their
heads, a federal judge has ruled that LifeLock has been
breaking California law for years by placing fraud alerts on its
customer’s credit profiles.


The decision is a blow to the burgeoning identify-theft protection industry, and means that companies that experience data breaches may no longer be able to offer victims free subscriptions to such services — a
standard damage-control tactic in recent years. Consumers can still place fraud alerts by contacting one of the three U.S. credit reporting agencies directly.


Bo Holland, founder and CEO of Debix, a competitor of LifeLock, called the ruling “dramatic and unexpected.”

“It causes a real shift in the industry,” he told Threat Level.

The pre-trial partial summary judgment comes in a lawsuit filed last year against LifeLock by Experian, one of the nation’s three credit reporting bureaus. Experian claimed LifeLock is trying to “game the system” of fraud alerts to make a profit.

LifeLock, a controversial company that gained notoriety for publishing its CEO’s Social Security number in advertisements
charges $120 a year to consumers to place fraud alerts on their credit profiles, among other services. The company also offers a $1 million guarantee to reimburse the expenses of any customer who suffers losses from identity theft while subscribed to LifeLock.

Continue Reading at WIRED




Reblog this post [with Zemanta]

Stolen Credit Card Data Published in Blog

Stolen credit card data published in blog | The Australian
Blair Speedy | May 29, 2009
Article from: The Australian

VICTORIAN police are investigating a massive identity fraud involving the personal details of thousands of Australians that have been available on an internet blog site for more than a month.

The data, discovered by The Australian, includes thousands of Visa, Mastercard and American Express numbers, including expiry dates, together with home addresses, phone numbers and email addresses.

The list was posted on a free blogging site, where it was copied by search engine Google as part of its routine cataloguing of internet sites on April 21.

Victoria Police Sergeant Dave Spencer said the list appeared to have been collected from a number of sources before being sold to criminals.

"Lists like this come up for sale on the internet, and this is basically the end product of skimming and hacking of ATMs and other point-of-sale systems," Sergeant Spencer said.


, , , , ,

80% of Phishing Attacks Use Hijacked Websites

I've blogged about this subject plenty of times over the last year, and my concern is specifically targeted towards the inherent weaknesses in the username/password systems used with online banking. If a consumer is tricked/phished into providing their username/ password, then the phisher is successful.

The average phishing attack results in a loss of $350 to a bank.

According to research firm,Gartner, banks, online payment organizations and other financial institutions are bearing most of the financial cost of phishing attacks. (A survey of nearly 4,000 US consumers revealed a 40% increase in the number of phishing victims in 2008 over the year before to five million.)

The average loss was $350 per phishing attack, but consumers said they had recovered 56% of their losses from the financial institutions involved. (That's $196 to the banks and $154 to the consumers) "The findings underline the fact that the war against phishing is far from over," said Avivah Litan, analyst at Gartner. (Yes, the very same Avivah Litan who says "never" enter your PIN on the Internet unless it's hardware based)
Guess what? The HomeATM "SafeTPIN" device would not only eliminate "phishing attacks" but it would also eliminate the threat of "cloned cards," "cloned bank sites", AND provide "True 2FA." for online banking customers.

HomeATM provides a very simple cure to this maliciousness. Use a PCI 2.0 certified SwipePIN device and require online banking users to swipe their bank issued card and enter their bank issued PIN. The data is encrypted and is NEVER in the clear. So, in the event a consumer is tricked into swiping and entering their PIN, as opposed to typing in their log-in credentials, the phisher has nothing.

And nothing is something banks should want phishers to have.

More Than 80% Of Phishing Attacks Use Hijacked, Legitimate Websites - DarkReading

More Than 80% Of Phishing Attacks Use Hijacked, Legitimate Websites
New research from the Anti-Phishing Working Group shows how phishers are better covering their tracks -- and what to do when phishers compromise your Website

May 27, 2009 | 04:23 PM
By Kelly Jackson Higgins
DarkReading

It used to be that researchers could sometimes track a phishing exploit by the notorious cybercrime ring behind it, like the Rock Phish gang, but no more: New research from the Anti-Phishing Working Group (APWG) has found that most phishers are setting up shop on legitimate Websites to be inconspicuous when they steal valuable information from victims.

In the second half of 2008, roughly 57,000 phishing attacks worldwide targeted a specific brand or organization, up from around 47,300 in the first half of 2008, according to a newly released report (PDF) from the APWG. The attacks were waged on 30,454 different domain names, only 5,591 of which were domains the phishers set up themselves. The rest were from legitimate Websites they had hijacked to carry out their exploits.

The average amount of time a phishing site was up: 52 hours, according to the report.

Continue Dark Reading


Reblog this post [with Zemanta]

Gartner Says Expect Jump in Mobile Payments Users

Jump in mobile payments users this year - Gartner
The number of people around the world making payments using their mobile phones is set to soar from 43.1 million in 2008 to 73.4 million this year, a 70% rise, according to analyst house Gartner.

By 2012, the company predicts the number of people making m-payments will hit 190 million - more than three per cent of total mobile users - as it becomes "mainstream."

However, security concerns, an inadequate 'ecosystem' and undefined areas in banking regulations remain challenges for the technology.

Continue Reading at Finextra




, , , , , ,

New Worm Could Attack 1000's of Twitter Users

Twittercut website spreads malicious links as page views rapidly increase

Dan Raywood | May 27, 2009
A new worm that could attack thousands of Twitter users has been detected.

PC Tools has detected a new scam that claims to drastically increase a user's Twitter followers by using a website called Twittercut. It takes advantage of the current trend of amassing Twitter followers in order to capture users' Twitter account details and self-propagate.

Twitter users may see a tweet in their stream that reads ‘OMG I just got over 1000 followers today from http://twittercut.com'. Once they click on this, the link takes them to a fraudulent Twitter website requesting their login and password details. It then sends out this tweet to all of their followers and directs users to a dating website, with the aggregate number of views resulting in affiliate revenue.

Continue Reading at SC Magazine



Reblog this post [with Zemanta]

Use PIN Debit at Gas Stations

I wrote about this last June, but it's making news again, so I thought I'd throw out a reminder.  Use your PIN when you purchase gas otherwise gas stations can put up to a $150 hold on your checking account resulting in overdraft charges. 

Here's a video from KATV 7 in Little Rock, Arkansas. 

ACH Network Should Compete with Debit Card Networks Says KC Fed Chief

Kansas City Fed Chief Espouses ACH for Debit Card Processing
(May 27, 2009) The Federal Reserve Banks should adapt the automated clearing house network to compete directly with private-sector networks for debit card processing, the head of the Federal Reserve Bank of Kansas City said this week. “The Federal Reserve could enhance competition in payment card markets by positioning ACH services as an alternative to debit card payment networks,” said Thomas R. Hoenig, president of the Kansas City Fed, in remarks delivered on Monday at a retail-banking conference held by the European Central Bank in Frankfurt, Germany.

Hoenig said he isn’t proposing the Fed issue cards or run its own card network. But he said the U.S. national banking regulator could “add enhancements” to the ACH that would allow the nearly ubiquitous network, which reaches virtually every bank in the U.S., “to become an alternative to running transactions over card networks.” He pointed to decoupled debit cards, in which banks issue debit cards that link to deposits held at other banks, as an example of the sort of adaptation he favors.

Continue Reading at DigitalTransactions.net



, ,

Wednesday, May 27, 2009

Barney Frank Easily Gaining Co-Sponsors

It is not taking Representative Barney Frank long to convince fellow lawmakers that the current laws regarding Internet gambling in the US are outdated. Late last week four new co-sponsors signed on to support the Internet Gambling Regulation, Consumer Protection, and Enforcement Act.

With the four new co-sponsors, the Bill now has twenty-three co-sponsors to date. All four of the new sponsors are Democrats, three from New York, and one from California.

Of course, California may actually beat Frank to the punch when it comes to legalized online gambling. State lawmakers are discussing a plan that would make online poker legal in California. It is a plan that has tremendous support among the citizens of California.


Continue Reading at New Online Casino's dot Org



, , ,

13 Hottest Fraud Schemes You Can Prevent

http://www.bankinfosecurity.com/articles.php?art_id=1490


The fraud fight is getting nastier by the minute, say experts familiar with the new schemes - and some old ones with new wrinkles -- being perpetrated by criminals against financial institutions and their customers. Here are 13 of the most prevalent ruses.


#1 - Credit Bust-Out Schemes


#2 - Customer Loan Account Takeover


#3 - Corporate Account Takeovers

#4 - Cross-Channel Call Center/Online CD Purchase Scam

#5 -- Wire Fraud Account Grooming

#6 -- In-Session Phishing

"A somewhat recent tactic being perpetrated by fraud rings --"in-session Phishing" -- has emerged as one of the chief threats to thebreach of secured online assets. These attacks utilize vulnerabilitiesin the Javascript engine found in most of the leading browsers,including Internet Explorer, Firefox and even Google's Chrome, notesEisen.


How it happens: Utilizing a host website that has been injectedwith malware acting as a parasite, this parasite monitors for visitorswith open online banking sessions or similar protected asset sites(such as brokerage or retirement planning sites).


Using the Javascript vulnerability, the parasite can identifyfrom which bank the victim has a session currently open by searchingfor specific sites pre-programmed in the malware itself. "There are nolimits to the volumes of URLs a website hosting the parasite can testfrom the victim's machine. The malware asks: 'is my victim logged ontothis XYZ bank website' and their browser replies either yes or no,"Eisen says.


Once any site from the list is confirmed to be "in session," apop-up claiming to be from the bank issues a warning. Most warningsappear as time-out messages stating "For security purposes your bankingsession has been terminated. To continue your session please re-enteryour username and password here (supplied link by fraudster)."

Once an unknowing victim complies, clicks the link and entershis/her credentials, the damage has been done and the attack wassuccessful and the game is over - right?

In most cases it would be devastating for a victim after theircredentials had been breached; expecting the fraud rings to quicklybegin selling off this information or pillaging through the victim'saccount. Since many financial institutions rely on cookies or tags todiscern one device entering user credentials from another, and thencount on fairly common (and easily answered by crooks) out of walletquestions - to validate a new device attempting access, this would betrue.


However, simply by utilizing a robust device ID technology -which creates the equivalent of a device fingerprint for every machineattempting to log on to a banks site, coupled with historical negativelists of known bad devices, "financial institutions could rendercredential breaches using in-session or any other type of phishingattack useless to the fraudster," Eisen says.


The power lies in knowing what a suspicious or fraudulentattempt looks like upon log-in. "If you know a legitimate customer mostalways uses a device configured for local New York time and thelanguage for this device is English, you would not provide unchallengedaccess to this account from a machine showing to come from China andhaving a default language set to Mandarin," Eisen says.


Further strengthening against future attacks, placing thedevice fingerprints gleaned from all known previous fraudulent attemptsinto a negative list effectively blocks the devices with a history offraud from ever gaining access to another user account. "


#7 -- ATM Network Compromises

#8 -- Precision Malware Strikes

#9 -- PIN-Based Attacks

For the past 10 years, Verizon Business has tracked metrics andstatistics from IT investigative cases, including incident response,computer forensic and litigation support, across the globe.

The VerizonBusiness' just-issued 2009 Data Breach Investigation Report, shows moreelectronic records were breached in 2008 than the previous four yearscombined, fueled by a targeting of the financial services industry anda strong involvement of organized crime, says Bryan Sartin, director offorensics and investigative response at Verizon Business.


Driving this explosion in compromised records are moresophisticated attacks, specifically targeting the financial sector. Infact, 2008 saw three of the world's largest known data compromises onrecord.


With many large individual compromises over the past twoyears, the value of payment card, check, and other forms of consumerdata on the information black market are on rapid decline, says Sartin." 

Just two years ago, magnetic-stripe sequences sufficient forcounterfeit were priced at an average of $14 per record, while todaythat cost has dropped to as little as 20 cents," he says. "Cybercrime,it seems, chases the almighty dollar."

Last year showed a sharp increase in attacks againstcounterfeit sequences plus the corresponding cardholder PIN value,leading to the direct theft of consumer assets, Sartin notes. "The leadindicators of these types of crimes were not based on the conventionalanalysis of signature-based counterfeit fraud patterns to find commonvalid transaction points within legitimate spending histories. Instead,bank customers were suddenly reporting zero balances in checking andsavings accounts, alleging fraudulent ATM withdrawals." As more andmore similar complaints surface, it became easier to pinpoint thelikely source of compromise, whether it be a bank, data processor, orpayment gateway, Sartin says.

Verizon Business tracked at least three different techniquesduring 2008. Until recently, many PIN-based attacks were known to bepossible but no credible evidence of them being used in real-worldincident has ever surfaced. That has since changed as attacks againstPIN information are on the rise, setting the stage for moresophisticated forms of identity fraud. 

#10 -- Account Manipulation
.
#11 -- Fraud Pattern Changes


#12 -- Foreclosure Prevention Schemes

#13 -- Builder Bail-Out Fraud



International Credit Card Fraud Ring Dismantled in NYC

Banking / Finance News
Source: Queens District Attorney's Office
Complete item: http://www.queensda.org/newpressreleases/2009/may/operation%20plastic%20pipeline_05_2009_ind.pdf

Queens District Attorney Richard A. Brown, joined by Police Commissioner Raymond W. Kelly, today announced that an international forged credit card and identity theft ring based in the New York metropolitan area and with roots in Nigeria has been successfully dismantled following the indictment this week of forty-five individuals.

The ring - which was comprised of three separate identity theft and forged credit card groups that employed multiple cells - is alleged to have been responsible for stealing the credit cards and personal credit information of thousands of American and Canadian consumers, costing these individuals, as well as financial institutions and retail businesses, more than $12 million in losses over the past year alone.

District Attorney Brown said, "Our investigation reveals that - in terms of just the sheer number of people indicted - this is one of the largest identity theft networks uncovered in recent history and is just possibly the tip of a much larger global credit card trafficking operation.

Besides draining the bank accounts of individuals throughout North America, we believe that the defendants - some of whom live in California, Illinois, Maryland, Pennsylvania and Toronto - also shipped stolen or fraudulently obtained credit cards to buyers around the world and that purchases were made in such far-off places as Japan, Saudi Arabia and Dubai. Particularly disturbing is that we have no way of knowing if any of these accounts have fallen into the hands of terrorists and are being used to finance their terrorist activities or to undermine the efforts of homeland security and other law enforcement officials intent on keeping our borders and citizens safe.

Such a serious threat to public safety cannot go unchallenged. We will continue to work closely with our law enforcement colleagues to stamp out such fraud and help to maintain our nation's safety and security."

ATM Skimminig Is Reaching Epidemic Proportions

ATM Skimming on the Rise

Source: The Frederick News-Post Online - Frederick County Maryland Daily Newspaper
ATM card skimming on the rise
Originally published May 27, 2009 By Ike Wilson | News-Post Staff

ATM card skimming on the rise

The PNC Bank automated teller machine at 191 Thomas Johnson Drive was rigged with a skimming device in April, Frederick police said.  It's called "skimming," and ATM users worldwide are losing millions. The ATM Industry Association describes skimming as one of the industry's most recurrent fraud threats.  The practice hit Frederick in April, when the PNC Bank automated teller machine at 191 Thomas Johnson Drive was rigged with a skimming device, Frederick police said.

The hardware recorded card numbers of customers using the ATM. Police think a video recording device was placed near the ATM to capture personal identification numbers entered into the machine.  PNC Bank spokesman Fred Solomon said bank policies prohibit him from speaking about security or theft matters, including details about how many were affected by skimming at the Thomas Johnson Drive branch.  Customers with unidentifiable transactions on their statements should contact their local branches, Solomon said.

Just over 4,500 of the 11,360 ATM crimes recorded by the ATM Industry Association Global Cognito crime data management system for 2005 through 2008 involve skimming, according to association CEO Mike Lee.

"It's probably the most widespread crime type we face," Lee said.  The association defines skimming as the unauthorized capture of magnetic strip information by modifying the hardware or software of a payment device, or through the use of a separate card reader.  Skimming is often accompanied by the capture of customer PIN data.

Skimming is one of the financial industry's fastest-growing crimes, according to the U.S. Secret Service, which investigates bank fraud.

The ATM Industry Association has reported more than $1 billion annually in global losses from credit card fraud and electronic crime associated with ATMs.  Last week, the ATM Industry Association launched an international Anti Skimming Forum to counteract the growing trend.  Skimming is a problem that will continue to increase until technology brings it under control, Lee said.  "The technology exists today to help defeat the problem," he said.

According to Bankrate.com, ATM skimming devices come in two types: ones that interfere with the ATM operation and ones that don't. The skimmers that interfere with the ATM operation are easier to detect, because even though customers insert or swipe their cards, it's not the ATM's card reader so the ATM isn't actually being used and the customer isn't getting any money.

In other skimming cases, the thieves don't interfere with the normal operation of the ATM. The skimmer is placed over the card reader but doesn't block off the reader, and the customer gets money when making a withdrawal.  Credit and debit card abuse may also happen at cash registers during purchases.  Pay a restaurant tab with a credit card and you have no idea what the waiter might be doing with the card when it's out of your sight, according to Bankrate.com.

The mission of the ATM industry's new forum is to measure the global impact of skimming through the pooling and analysis of data. It is also to write best practices for preventing and reducing skimming. This will include a global skimming classification system. Industry officials also want to increase sentences for skimming convictions to create a stronger deterrent. Lee thinks more can be done in terms of educating customers to protect their PINs by covering the hand used to key in the PIN at an ATM so someone cannot learn the code. This simple measure alone would significantly reduce the success rate of skimming attacks, he said.


, , , , , ,

Moble Phone Location Technology to Cut Into Card Fraud?

Source: Network World
Complete item: http://www.networkworld.com/news/2009/052609-mobile-phone-location-technology-fights.html

Description:
Ericsson is courting major banks with a security service the company thinks could cut down on credit card fraud as well as eliminate an inconvenience for travelers using cards overseas.

Banks are increasingly blocking credit card transactions in certain high-risk countries due to increasingly levels of fraud. A business traveler who lives in the U.K. but goes to Russia can likely have a transaction rejected if the person hasn't informed the credit card company of their travel plans. It's embarrassing and inconvenient.

Ericsson's IPX Country Lookup service uses a person's mobile phone to provide a confirmation that a person is actually in the country where the transaction is carried out, said Peter Garside, U.K. and Ireland regional manager for Ericsson's IPX products.

For the service to work, Ericsson's technology must be installed on a mobile operator's network. Once installed, Ericsson will pay the operator a "small fee" every time a bank wants to verify a certain transaction by one of their customer's mobile phones, Garside said. Ericsson will then put a margin on the lookup fee and charge that to banks, he said. The lookup fee hasn't been set yet.

Garside said that Ericsson has figured out how to extract the location information from operators worldwide. The technology only identifies what country a person is in and not where they exactly are in that country. It only works for GSM networks.

To allay privacy concerns, Ericsson is recommending that the banks should get consumers' consent prior to using the transaction verification service. Once a person's approximate location has been passed onto the banks, that data will not be held any longer, Garside said.

The service will work even if someone's phone is off, but as long as they've turned the phone on at least once when they're in a new country. Mobile phones will register with the local operator when turned on in a different country, so Ericsson will be able to query the last known location.

The service comes out of Ericsson's IPX product line, which enables third parties to bill for ring tones or other content via mobile networks.

Garside said operators won't incur any costs to integrate the service into their networks and can make money from the location information they hold. "The operators are sitting on some valuable assets," Garside said.


E-Secure-IT
https://www.e-secure-it.com


Reblog this post [with Zemanta]

Heartland's New Strategy - Segment Data into Jigsaw Pieces

Below is an interview with Evan Schuman the Editor at StorefrontBacktalk.com regarding Heartlands new strategy which is basically to segment the data into a jillion pieces to make it harder for hackers to to grab the data.  Read the original article by Evan Schuman at StorefrontBacktalk.com


Consumerist - Credit Card Processors Launch A New Strategy To Defeat Theft - heartland

This fall, credit card processors will being rolling out a new approach to preventing data theft, based on the assumption that it's impossible to thwart every attack. Instead of keeping 100% of criminals out, they'll segment and encrypt the data into such small chunks that it will no longer be a cost-effective crime.

We spoke with Evan Schuman, the editor and publisher of the blog StorefrontBacktalk.com, which broke the story earlier this month. Schuman has spoken directly with representatives of Heartland—which announced its own massive data breach a few months ago—and says they'll roll out this new approach around October of this year, and that other processors are working on similar solutions. It involves new point-of-sale hardware that can encrypt each day's batch of credit card numbers separately, then shuttle each daily pack off to Heartland's data centers for archiving.

It's a better approach than what we currently have. For one thing, retailers will no longer have any reason to store credit card numbers. But it's not an ideal solution and there are some definite costs, as Schuman points out below. In fact, there's a much better end-to-end encryption solution that we could already be using but aren't simply because it's not as profitable for card companies like Visa and Mastercard.

Consumerist:
So what is it that Heartland is proposing?

Evan Schuman, StorefrontBacktalk.com:
"Historically security has always been based on, 'You build a really good deadbolt, you keep the bad guys out. And if they come in you set it up so that you'll learn about it quickly and engage in pursuit.' What they're saying here is, you know as a practical matter, let's be a little smart about this. First of all we really can't keep the bad guys out. Trying to do that is futile. Might as well let 'em in, and let them steal a certain amount of data, and let them go. A, they're going to anyway, and B., if you do it that way, you make sure they don't get enough data that they can profitably sell. If you do that, they're not going to steal it, or at least not very often, because they're not going to make money that way.

"So it's really about segregating data, so instead of having 50 GB of data here, you've got in a thousand different locations small quantities of data. They may get through that. Fine. They're not going to make any money off of that, and it's not cost-effective to break in at 50 different locations. It's like instead of having a million dollars in your house, you've got 5 dollars in 200,000 houses. They'll have to break in that many times, and each time there's a risk of getting caught. It's not worth it.

"Right when we broke the story, [we found out that] two other major processors, including one that's larger than Heartland, were working on essentially the same thing, with their own proprietary angle."

"Proprietary" sounds expensive.

"What it means is that there are a variety of proprietary efforts out there. Today, it's pretty easy for a retailer, if you don't like your processor, you go to another one. It's really not that big a deal to switch. But with this, now they're going to have all this hardware that only works with processor 3, and now it's much more difficult for [retailers] to shift, particularly when multiple processors are doing it. So it's going to be a whole lock-in time for retailers where they're going to have to stay if they let this happen."

A commenter on your story points out that this will separate retailers from their own data.

"I checked with our people at Heartland and they said, 'Well, yeah, that's kind of true.' When a retailer uses their own credit card—for instance, when Sears uses a Sears credit card—they're going to have to pay a processor to unencrypt their own data. In other words, you'll be paying someone else to give you access to your own data. And if you start following through the logic of that, there are a lot of issues."

Heartland calls this an end-to-end solution, but you and your readers have pointed out that this isn't really true.

"This is not end-to-end, this is not even close to end-to-end. End-to-end really refers to, you take a credit card off the factory line, when they print the credit card, before the consumer gets it, before anyone can steal it, on the factory floor it's encrypted. And it stays encrypted all the way through to the processor and even beyond to the card brand. Now that's end-to-end encryption. You can steal it at any point—the consumer never has it unencrypted in their hand. Neither does the retailer, you completely bypass them.

"What these guys [Heartland] are doing is kind of, 'Well, a little bit to the right of middle, to the middle of middle'—which just doesn't have as much of a marketing tone."

So why isn't the end-to-end approach being pursued? Is it too technologically difficult?

"No, it's not difficult at all. First of all, in Heartland's defense, and any of the processors' defense, it's beyond their power to do it. They don't ave the ability to do that, they don't own the card.

It would have to be at the Mastercard or Visa level...

"Exactly. And Visa, among others, doesn't want to do this because they would have to pay for the technology to unencrypt at their end. They would rather have it unencrypted. They insist that you send it in the clear, unencrypted, across a proprietary network. That's they way they've done it for decades.

"The card brands, they don't want to pay for end-to-end encryption, they have not supported it. They say, 'Oh, we'll consider it, we'll talk about it,' but they don't want to do that. They can see that's the best way to go, but they don't feel like doing it, and no one in Congress is forcing them to do it. Even the latest credit card overhaul, they didn't even come close to security issues. It was all about interest rates. No one is forcing them to do anything in terms of security, so why should they. So the processors are saying, 'Well, we're doing what we can here.'

"This doesn't solve the problem, it won't even materially reduce the problem, but it's a definite improvement in security. It's safer, it's better than what exists today. It won't resolve everything, but it's better than today."

So, how likely is it that Heartland's approach will happen?

"As far as Heartland is concerned, this is definite, they're going to have it out by October.

"Now, retailers who are Heartland's customers have got to buy it. As far as I can tell, no one has bought this yet, so in theory if no one ever does... It's sort of like a car company that puts out a car. Is the car definite? Yes, it's going to roll off the assembly line and be in showrooms, assuming there are showrooms any more, but if no one buys it it won't be out there for long.

"So this will definitely be introduced by Heartland. Whether anyone buys it has yet to be seen. I'm guessing some will. Heartland can deeply discount it to the point where it will be easy for them to do. But the cost is not really in the cost of the hardware, although if it's a large chain, that can add up quickly. The cost is in making the change and then making it much more difficult for yourself to move later if you feel like it."

We're reporting on this on Consumerist because it reveals a little of the world of credit card processing and data security—the part of the retail chain that we never see, but that affects us at the register and after we leave the store. Schuman points out that whether the new data segmentation approach takes off or not, things won't change for the consumer experience—it's all pretty invisible from our side of the register.

What it could affect, however, is the cost of transactions for the retailer, and consequently it could impact prices at the register. Whether that's worth it to implement a better security approach remains to be seen.

If you're interested in how retailers approach the issue of data security, you should check out StorefrontBacktalk.com.


Security Experts Sound Alarm Over Insider Threats

Security Experts Raise Alarm Over Insider Threats
Economic troubles raising the stakes on potential threats, FIRST members say

May 26, 2009 | 06:18 PM
By Tim Wilson |DarkReading

Security researchers and other experts are turning up the heat on insider threats, warning enterprises that the problem is growing and could prove devastating for many enterprises.

In preparation for its meeting in Japan next month, the Forum of Incident Response and Security Teams (FIRST) issued a press release in which its senior officers urge organizations to step up their efforts to protect themselves from insider attacks, saying that many are "ill-prepared for an onslaught which could prove calamitous."

"One of the greatest security threats of our times is from insiders, as organizations lay off tens of thousands of workers," said Scott McIntyre, a FIRST steering committee member and representative of the Netherlands-based KPN Computer Emergency Response Team (CERT). "People know the axe is coming, and the longer employers prolong the swing of that axe, the more danger they expose themselves to, either from sabotage or data theft. An employee who thinks he or she is [going to be laid off] can start fouling up systems which are critical to the organization, or decide to take an unauthorized pay-off by stealing a mass of data."

Continue Dark Reading


, , ,

Aite Group Releases New Report on Mobile Transactions Landscape







A New Report From Aite Group

By understanding the various initiatives around the globe, and what failed and what succeeded, financial
institutions and other players can better tailor their own solutions.

BOSTON — A new report from Aite Group LLC examines mobile transaction initiatives that are currently happening around the globe. The report, based on quantitative and qualitative research of 69 mobile transaction initiatives internationally, explores the current range of services in development and the underlying technologies powering each initiative.

Following an initial wave of mobile transaction initiatives at the turn of the century, developers are again active in bringing mobile transaction services to market. The technological evolution of the mobile device and mobile networks, coupled with increased end-user savvy, has led to an increase in mobile transaction initiatives over the past five years. By understanding the various initiatives around the globe and what failed and what succeeded, financial institutions and other players can better tailor their own solutions.

"Card networks, financial institutions, mobile operators and industry associations can separate hype from reality by not focusing on mobile transaction initiatives that are purely vendor-driven," says Nick Holland, senior analyst with Aite Group and author of this report. "One of the most critical questions that any stakeholder can ask of a 'new' mobile transaction initiative is this: 'Who has done this already and what was the outcome?' Invariably, any mobile transaction initiative will already have been done elsewhere. To state that is has not, means that due diligence has not been performed adequately."

This 41-page Impact Report contains 32 figures. Clients of Aite Group's Retail Banking service can download the report
by clicking on the icon to the right.


Disqus for ePayment News