Friday, September 18, 2009

"Chat in the Middle" Phishing Attack





Online Banking just became even more dangerous than it already was with new phishing attack...

"Chat-in-the-Middle" Phishing Attack Attempts to Steal Consumers' Data via Bogus Live-Chat Support





A new, unique type of phishing attack targeted against online banking customers was recently discovered by the RSA FraudAction Research Lab. RSA has coined this as a "Chat-in-the-Middle" phishing attack and it is first executed through routine means but then presents a more advanced layer of perpetrating online fraud. The phishing attack may dupe bank customers into entering their usernames and passwords into an ordinary phishing site but the addition of a bogus live chat support window can obtain even more credentials via a live chat session initiated by fraudsters.



During the live chat session, the fraudster behind the attack presents himself as a representative of the bank's fraud department and attempts to dupe customers who are online into divulging sensitive information - such as answers to secret questions that are used for online customer authentication. This attack is currently targeting a single U.S.-based financial institution.





Upon detecting the attack RSA immediately informed the affected financial institution and commenced a standard phishing attack shut-down procedure through the RSA Anti-Fraud Command Center and its RSA FraudAction service. (RSA cannot identify this bank in order to protect its security and privacy.) The attack is hosted on a well-known fast flux network for "hire" from fraudster to fraudster, which hosts a wealth of malicious websites such as phishing attacks,

Trojans infection points, mule recruitment websites, and more.



The Design of the Attack


The phishing attack starts out as a normal phishing website that prompts customers for their usernames and passwords. Usually at this point, after providing access credentials, phishing victims are redirected either to the next page (or pages) of the phishing website or to the genuine bank website. However, this attack proceeds with a new, advanced technique for obtaining additional information on victims – instead of being redirected to the next page of the phishing kit or the genuine site, a fake live-chat support window appears launched by the fraudster as part of the attack .





Continue Reading 







Reblog this post [with Zemanta]

53% of German Companies Victim of Breach over Last 12 Months



PGP Corporation announced the results from The Ponemon Institute's third annual study on encryption usage in the enterprise - The 2009 Annual Study: German Enterprise Encryption Trends.



This year's study surveyed 490 IT and security practitioners, 27 percent of whom hold positions at managerial level or higher, and identifies the trends in enterprise encryption planning strategies, budgeting and spending, deployment methodologies and impact on data breach incidents.



The fundamental conclusion on the basis of study participants' responses is that data protection is a significant problem in Germany.





Fifty-three percent of all companies and organisations suffered at least one instance of data loss during the past twelve months, representing an increase of over 55 percent on the figure for 2008 (click graphic on left to enlarge)



Continue Reading at Help Net Security



Click Here to Download the Report



Reblog this post [with Zemanta]


Ebay Pushes EU to Change Competition Laws

ecommerce and shopping cart newsSeptember 17, 2009

By the ZippyCart Shopping Carts Content Team



Ebay wants to grow their market share in the European Union and, in an effort to help improve the laws to help them sell online, they had 750,000 Ebay users sign a petition. The petition handed to the European Parliament urges the government to reform the laws to prevent companies from blocking online sales.



Companies like Ebay and Amazon really want to expand their business operations into the European market, but these laws are preventing them from selling many brands via their online ecommerce stores.

The law in question, which Ebay feels is unjust, allows luxury goods manufacturers to decide who they want to sell their products online. The petition Ebay submitted says manufacturers should not be able to "insist that Internet retailers must have an offline retail store before they can sell online".



Continue Reading


Reblog this post [with Zemanta]

Splash and MoreMagic Solutions Offer Mobile Money Transfer in Sierra Leone











Available for Zain and Africell Mobile Phones; First Mobile Money Service in Sierra Leone



Freetown, Sierra Leone; Newton, MA, US, September 18, 2009 - PIN Payments News Blog: Splash Mobile Money Limited ("Splash"), a leading mobile payment system provider, and MoreMagic Solutions, a leading mobile transactions provider, announced today the availability of Sierra Leone’s first mobile money transfer system, enabled by MoreMagic Solutions industry-leading MWallet platform. Splash customers in Sierra Leone can now send money using just the mobile phone, quickly, easily, cheaply and without any requirement to have a bank account.



Splash customers use the service by visiting a Splash agent location, including branches of GT Bank. Customers transfer money by completing a free registration, purchasing SplashCash™ and sending it by text to any Zain or Africell mobile phone. The recipient then exchanges the SplashCash™ for cash at any agent location. Agents are currently concentrated in Freetown, Bo, and Makeni, with many more locations due to open throughout Sierra Leone before the end of the year.



"Splash promises to provide access to basic financial services to many Sierra Leoneans for the first time," said Ben Farren, Director of Splash. "Unbanked customers can now send money across the Country at the touch of a button."

"In Sierra Leone, mobile phone customers often travel far from home to support their families, and managing salaries in a secure way can be a challenge," said Pankaj Gulati, chairman and CEO, MoreMagic Solutions. "MoreMagic Solutions is pleased to support Splash in delivering SplashCash™, a truly innovative way for customers to manage their household money using the mobile phone."



Splash

Launched in early 2008, Splash Mobile Money Limited, designs and delivers mobile payment solutions in West Africa. www.splash-cash.com



MoreMagic Solutions

With deployments in more than 50 countries worldwide, MoreMagic Solutions offers transaction platforms for mobile operators, financial institutions, content providers, and distributors, enabling consumers to purchase goods and services on demand using a mobile phone, POS, or web.  The MoreMagic Solutions high-throughput payment engine and pre-packaged applications enable revenue-generating services, including mobile recharge and mobile money transfer, both domestic and international; mobile banking; bill payment; and mobile commerce; with integration into diverse network environments, languages, and currencies. Through MoreMagic Solutions worldwide distribution, MNO-branded services are available for out-of-country customers, enabling communications with relatives back home, and increased usage on mobile networks worldwide.



Contacts

Ben Farron

Splash

benfarren@mac.com

www.splash-cash.com

Carol J. Meier

MoreMagic Solutions

cjmeier@moremagic.com

www.moremagic.com



$32 Million Transcript of Heartland CEO Testimony





Heartland spends $32 million during first half on breach-related activities

Heartland Payment Systems Inc. spent about $32 million in the first six months of this year on forensics, legal work and other activities related to the December 2007 database breach that resulted in the theft of millions of credit and debit card numbers, CEO Robert Carr told the U.S. Senate Committee on Homeland Security and Government affairs this week.



Here's the entire transcript: 

Complete Testimony of Robert O. Carr Before Senate Committee

One in Eight Brits Hit by Online Fraud - Survey





Finextra - According to a survey commissioned by Internet security outfit VeriSign, one in eight of the UK's adult population have fallen victim to online ID fraud in the last year.



The YouGov survey of over 2000 Brits found that these fraud victims have had on average £463 stolen, with a quarter claiming to still be in dispute over compensation for the money taken. In total, £2.65 billion was stolen online from UK consumers in the last 12 months.



Despite the high proportion of victims, VeriSign says British Web users are conscientious when it comes to online shopping. Over three quarters (82%) of respondents claim to buy only from sites with enhanced security settings.



Young people are less likely to be hit by criminals, with only five per cent of 18 to 25 year olds stating that they have been online ID fraud victims, compared to 14% of people aged 45 to 54.



Continue Reading

eCrime Researchers Summit October 19th-21st



Cambridge, Mass., Sept. 17, 2009 -- The Anti-Phishing Working Group (http://apwg.org/ ) (APWG) announced it has opened registration for its eCrime Congress | Tacoma 2009 (http://apwg.org/events/2009_gm.html ), a three-day program beginning October 19, 2009.



The eCrime Congress program interrogates the current electronic crime threatscape that menaces online commerce today and tomorrow, and posits resources, tactics, and techniques to constructively engage them. APWG is the world's leading pan-industrial and law enforcement association focused on eliminating fraud and identity theft (http://apwg.org/events/events.html ).



No event combines the topical richness in exploring the electronic crime phenomenon and delegate heterogeneity like the fall APWG eCrime conferences, drawing thought leadership from technologists from many disciplines as well as from the financial services, retail and communications industries, law enforcement, and university research centers in the US, Europe and Australasia.



"No single sector holds the solution to electronic crime. At the APWG's conferences, all stakeholders can stand face-to-face and shoulder-to-shoulder to engage the eCrime phenomenon comprehensively, in ways that create dialog across affected constituencies - and inspire concerted action," said APWG Secretary General Peter Cassidy.



eCrime Congress | Tacoma 2009 will include a one-day, General Members (members-only) meeting on Oct. 19, followed by two days of open sessions on Oct. 20 and 21, examining such subjects as: crimeware's evolution, botnets' evolution, malvertising, Website vulnerabilities, business process logic abuse, telephony-based phishing, eCriminal tracking, counter-eCrime consumer safety instruction and the abuse of the Domain Name System by eCrime gangs.





The AWPG eCrime Researchers Summit (eCRS) on Oct. 20 and 21, held contiguously with the APWG General Members' meeting, will be presenting papers on counter-forensics, wireless network vulnerabilities,improvement of phishing-attack countermeasures, identification of vulnerable websites, phishing detection techniques, mechanisms for tracing the provenance of phishing attacks and much more. The eCRS, the world's only peer-reviewed technical conference dedicated exclusively to electronic crime research, is held every year with IEEE Standards Association (IEEE-SA) serving as the conference's Technical Sponsor.



The conference agenda and registration links are here:





http://www.antiphishing.org/events/2009_gm.html

Reblog this post [with Zemanta]

Finovate 2009 Reminder





Finovate 2009 is almost here and with it your chance to see the future of finance and banking before anyone else. In today's hyper-competitive market, finding and implementing the next great innovative idea (before your competition does) is critical.



Finovate will return to Manhattan on September 29, 2009 to once again showcase the best new financial and banking technology innovations from established leading companies and hot young startups. Finovate 2009 will showcase 32 of the most innovative ideas in financial technology (ideas you need to know about). Because of it's unique fast-paced format that is packed with value, the event is on pace to attract even more attendees than last year.



Handpicked from hundreds, the companies get a mere 7 minutes on stage to demo (no powerpoint allowed) their latest and greatest. Last year, almost 400 executives, entrepreneurs and industry experts attended the event’s action-packed day. Overwhelmingly, they said they’d come back. Will you join them?



Attendees from companies like American Express, Discover, Citi, Bank of America, ING Direct, Forrester, Wall Street Journal, NY Times, Fidelity, the Economist, RBC Venture Partners, Intuit, Microsoft, HSBC, Bloomberg Ventures, Visa, Lincoln Financial, CNNMoney, Money Magazine, PayPal, Ally, Canaan Partners, Yahoo!, Federal Reserve Bank, American Banker, The Hartford, USAA, AARP and many more.



Plus, don't forget to use your special offer code fan2009 to save an additional $100 on the ticket price. If you register before next Tuesday you can save a total of $200 off the last-minute ticket price! Register now.

Consumers Will Be Hurt By Interchange Regulation: 5 Articles of Proof



Yesterday I posted about the battle between the retailers and the banks over interchange fees. The Battle Has Needlessly Begun and Congress is Ready to Screw it Up.  Earlier today I posted the National Association of Convenience Stores Press Release on Interchange Fees.



Now I bring you the press release from the Electronic Payments Coalition...a release which dispels the theory put forth by the Merchant Payments Colation that they would pass the "swipe fee" savings on to the consumer. (common sense dictates that the merchants would pocket the savings) As I said in yesterday's post:
The study found that if American merchants paid the same swipe fees as those in Australia the past four years, the net savings would total $125 billion. Editor's Question: In whose pocket did that $125 billion go? I don't need a study to tell you it "wasn't the consumers"...



Here's the Press Release:



WASHINGTON, Sept. 17 /PRNewswire/ -- The Electronic Payments Coalition issued the following statement:



Today, the Electronic Payments Coalition released key evidence from several sources, demonstrating conclusively that consumers would be hurt by interchange regulation in the form of higher fees, fewer benefits, and zero savings at the cash register.



Despite the misleading claims of giant retailers who want to shift this cost, merchants themselves have confirmed that they would not pass savings on to their customers.



Representatives of the U.S. government, international economic experts, the Reserve Bank of Australia, and merchants themselves have acknowledged that consumers would see no savings from any interchange regulation.

It's simple: merchants don't want to pay their fair share, and they want consumers to foot the bill. And that's not fair.



CRA International




However, "there is no evidence that losses to consumers have been offset by reductions in retail prices." (pp. 1, 4, 13, 58) Neither merchants nor the RBA has presented any empirical evidence showing the extent to which the benefits of interchange fee reductions were passed onto consumers. Rather, "[o]ne of the main effects of the RBA's interventions has been a redistribution of wealth in favour of merchants." (pp. 1, 4, 13, 20, 58) In fact, the CRA study showed that since 2003, when that regulation was implemented, cardholder fees have risen by 22% for standard cards, between 47%-77% for rewards cards, and cardholders now pay AU$480 more in credit card fees each year. The value of rewards also fell 23% during that period.



Robert Stillman, William Bishop, Kyla Malcolm, and Nicole Hildebrandt, "Regulatory intervention in the payment card industry by the Reserve Bank of Australia: Analysis of the Evidence" (28 April 2008), available at
http://www.crai.com/ecp/assets/Regulatory_Intervention.pdf.



GAO Study




(p. 2) "Since Australia's regulators acted in 2003, total merchant discount fees paid by merchants have declined, but no conclusive evidence exists that lower interchange fees led merchants to reduce retail prices for goods; further, some costs for card users, such as annual and other fees, have increased. Few data exist on the impact of the actions taken in Mexico (beginning in 2004) and Israel (beginning in the late 1990s). Because of the limited data on effects, and because the structure and regulation of credit and debit card markets in these countries differ from those in the United States, estimating the impact of taking similar actions in the United States is difficult."

CREDIT AND DEBIT CARDS Federal Entities Are Taking Actions to Limit Their Interchange Fees, but Additional Revenue Collection Cost Savings May Exist (GAO-08-558)



Tom Robinson
, owner of Rotten Robbie's convenience stores, in testimony before the House Judiciary Committee



Mr. Keller
: Let me just be crystal-clear. Let's say you are paying 2-percent interchange fees now, and the Conyers bill passes, and you go to the arbitrator, and the arbitrator says 'I agree 100 percent with Rotten Robbie, and it is going to be 1 percent,' will Rotten Robbie customers get a discount when they go to buy donuts or gasoline or Coca-Cola as a result of that taking interchange fees from 2 percent to 1 percent?

Mr. Robinson: Well, I don't think the marketplace works exactly like that.

Mr. Keller: But your whole argument -

Mr. Robinson: But, ultimately, ultimately, the answer to your question, the consumer will benefit.

Mr. Keller: Okay. That is the $64,000 question, because your whole argument is you want lower interchange fees because it is better for consumers. And so that is why I want to give you the chance. He is saying it is not going to benefit consumers. Is it going to benefit consumers or not?

Mr. Robinson: There is not a businessman that does not attempt to keep the margin.



May 15, 2008




Credit Union Times,
May 15, 2009, reporting on a panel discussion at the Chicago Federal Reserve:



"A banking regulator from Australia acknowledged that there was no evidence [prices had been lowered as a result of regulation] in his country, which has dramatically lowered credit card interchange. 'That is a very hard question to answer,' said John Simon, chief manager for the Payments Policy Department of the Reserve Bank of Australia, responding to a question from an attendee at the Federal Reserve Bank of Chicago's 2009 Payments Conference. 'There are so many different things that might go into a price change of 98-cent can of Coke to a 96-cent can of Coke that it's impossible to say whether or not that reflected the lowered interchange rate or something else, a global economic downturn, for example.'"



"Review of the Reserve Bank of Australia and Payments System Board" for the Standing Committee on Economics, Finance, and Public Administration, June 2006




"The committee was concerned by evidence which suggested that some merchants are profiteering from the ability to surcharge. While the committee notes proposals for surcharges to be capped at a merchant's costs, it does not believe a cap would be entirely effective. Surcharging - and in particular excessive surcharging - occurs in markets not subject to high levels of competition. If merchants in these markets want to charge excessively, they could simply do so through the prices of goods and services. If surcharges were to be capped, it is possible that other prices would rise to compensate for the lost revenue."



For more information on this and other issues in the interchange debate, contact Trish Wexler of the Electronic Payments Coalition at trish@electronicpaymentscoalition.com.





SOURCE Electronic Payments Coalition


Banking Salaries Require Fed Approval



Fed plans to approve banking salaries: report

Want to read something really scary?  Here ya go...



Fri Sep 18, 5:04 AM  NEW YORK (AFP) - The Federal Reserve would be required to approve salaries for tens of thousands of US bank workers, as part of a plan to curb risk-taking at financial institutions, The Wall Street Journal reported Friday.



"The Fed's plan would, for the first time, inject government regulators deep into compensation decisions traditionally reserved for the banks' corporate boards and executives," the report said.  The proposal would see the Fed empowered to ban any compensation policies it believes encourage bank employees -- from chief executives, to traders, to loan officers -- to take too much risk.



"The US' largest banks, about 25 in number, would get especially close scrutiny.




A final proposal "is still a few weeks from completion and could be revised along the way," the report said citing unnamed persons familiar with the matter. The move requires a vote by the Fed board, but not a Congressional green light.



How scary is that?  The last line in the story states: France and Germany, Europe's leading economies, are lobbying for strict limits on executive's compensation.



Reblog this post [with Zemanta]

Brits Ditch Checks

BRITS DITCH CHEQUES AS FAST PAYMENTS GATHERS MOMENTUM



The total value of cheques cleared in the UK in the second quarter fell a massive 20% compared to the same period in 2008, as Brits continued to turn to debit cards and the Faster Payments Service.



According to the UK Payments Administration, the value of all cheques cleared, including those issued by companies, fell by 20.9% to £219.23 during the quarter. The actual number of cheques cleared was also down 13.7% on Q2 2008.

Cheques - which are set to be phased out in the UK by 2018 - accounted for just 7.8% of all non-cash payment volumes in the quarter, declining from 19.7% in Q2 2003....



More on this story: http://www.finextra.com/fullstory.asp?id=20516.   Editor's Note:  According to the Drudge Report, the Brits are not alone as Obama has also ditched czechs...



Reblog this post [with Zemanta]

Study: U.S. Pays More for Interchange Fees






More on the Merchant Payments Coalition and their New Study...





A new study by the Merchants Payments Coalition finds that Americans pay a much higher percentage for interchange charges than the rest of the industrialized world.









WASHINGTON, DC – A new study by the Merchants Payments Coalition (MPC) www.unfaircreditcardfees.com found that if U.S. consumers paid the same low credit and debit card swipe fees as consumers in Australia pay, then the net benefit would have totaled $125 billion over the last four years.



Interchange fees, or “swipe fees,” cost Americans an average of $2 on every $100 they spend with credit cards — a higher percentage than anywhere else in the industrialized world. Why? Because other countries and their governments have been able to negotiate with the big banks and credit card companies for fair rates and transparency, the MPC notes.



NACS is one of the founding members of the MPC
.





But, in the United States merchants and their customers are still forced to pay sky-high interchange fees.

Interchange fees started out in the 1960s as a way for banks to cover the cost of processing credit card transactions. But even as technology has dropped that cost dramatically, the banks and credit card companies have pushed swipe fees higher and higher, turning it into a cash cow. For many businesses, credit card fees are now their single-highest non-labor operating cost.



With almost any other equipment, supplier or service, retailers can comparison-shop, negotiate or otherwise influence its final cost of doing business. Store owners can conserve on energy usage and seek out the most competitive prices for merchandise, just to cite a few examples.



Not so with credit card interchange fees. Visa and MasterCard control more than 80 percent of the marketplace. They set the fees in secret, give businesses no ability to negotiate and virtually insist they be buried in the price of merchandise. Unfortunately, the card companies’ hidden fees get passed on to all consumers in the form of higher prices and lower value for nearly everything they buy.











“It’s bad enough that the credit card companies force these hidden fees on us and our customers when we can least afford it,” noted NACS Vice Chairman of Government Relations Tom Robinson, president of Robinson Oil Corporation.

“But when we are paying more than anywhere else in the world, and other countries have taken action to protect their citizens from abuse, it is inconceivable that our government would turn a blind eye to the issue. It is time for Congress to step up and defend the principles of the free-market economy by taking action on (interchange) fees.”



Though Congress and the White House have addressed other credit card reforms, the MPC is arguing that any fix will be incomplete without addressing interchange fees. Consider:



  • Banks raked in an estimated $48 billion in interchange fees in 2008 – an average of $427 per American household in just one year.

  • This $48 billion total is more than triple the amount collected as recently as in 2001.

  • Hidden interchange fees cost Americans more than all credit card annual fees, cash advance fees, over-the-limit fees, and late fees combined.

  • U.S. interchange fees are the highest in the developed world. The U.S. pays approximately 60 percent of interchange fees globally – about double the U.S. percentage share of global GDP.



Compared to the rest of the world, U.S. interchange fees are more than two times the rates in the U.K. and New Zealand, four times the rates in Australia and more than six times the cross-border rates recently agreed upon by MasterCard and the European Union.



Meanwhile, the payments industry hit back with its own “study.”



In a September 17 press release, Visa announced the findings of a new study that shows that “consumers believe retailers benefit far more from accepting credit and debit cards than they pay in costs.



The press release noted that consumers believe merchants see card cost acceptance as a part of doing business, much like paying for utilities such as electricity.  "



Among the survey's findings:



  • By a 2-to-1 margin, consumers say retailers should pay the cost of accepting credit and debit cards.


  • 78 percent of consumers believe the value and benefits retailers receive from accepting credit and debit cards outweigh the costs of accepting them.


  • 83 percent of those surveyed believe that any savings retailers realize will be used to increase their own bottom lines and will not be passed on to consumers.


  • 91 percent of consumers say they are more likely to shop at stores that accept credit and debit cards.

“Retailers and their well-funded trade associations have filed lawsuits and are aggressively lobbying Congress to allow them to shift their business costs to consumers by allowing merchants to charge checkout fees whenever consumers use credit or debit cards. At the same time, national convenience store chains have launched misleading, in-store petition campaigns to cover for their checkout fee efforts, noted Visa’s press release.



"The response is loud and clear: consumers aren't buying the message convenience store chains and big retailers are selling," said Bill Sheedy, group president of the Americas for Visa Inc., in the release. "This research demonstrates that consumers are well aware that legislation is a Trojan horse that likely will lead to higher prices for cardholders while retailers pocket the savings."



Reblog this post [with Zemanta]

Thursday, September 17, 2009

CNNMoney.com Takes a Look at Cybercrime





CNN Money.com has a great article on Cybercrime today.  Did you know that the number of NEW Web Security Threats Tripled this year? 



Yup...we are now looking at a mere 1.7 Million Threats. 
Let me put that in perspective for you...



If I were to do a unique post on each threat...assuming each post took 30 minutes...and assuming I worked 12 hours a day...7 days a week for 365 days a year...it would take me a mere 194 years before I was done.  (that would be me...pictured on the right...years before completion)



Put another way, if I actually had started this project on September 17th, 1815, I still would not be finished.  (What's that?  Oh...you are correct...I would've been done on September 17th 1815...considering the number of Web threats I would have needed to post about back then, but you get my drift) 



So don't be looking for me to even start...not gonna duet..not even one.  After all, it''s a hellava lot easier to surmise all 1.7 million threats with just one post, in "three simple words"..."








Don't Type...Swipe!



Here are a couple of excerpts...starting with a basic warning.  By the way, I wish the media would start calling "Enter" "Type"!  Don't Enter...Swipe! doesn't rhyme...





"Cybercriminals can see what you enter (TYPE!)

on your screen and steal your credit card information or bank account information."








Cybercrime: A (not so) secret underground economy





Cybercriminals are making a killing off of stolen identities, creating their own market for

buying and selling credit card and bank account information on the cheap.






Cybercrime has become a rapidly growing underground business built by savvy criminals, who buy and sell valuable stolen financial information from millions of unsuspecting Internet users every year in an on online black market.





"Most cybercriminals are very, very interested in financial gain by compromising customer accounts," said FBI special agent Austin Berglas, who supervises the Bureau's New York Internet crimes squad. "Believe it or not, there are people who fall victim to their scams, and we see it every day."





Because cybercriminals are so skilled at hacking into thousands of computers every day, the crime is potentially a billion-dollar business. If every stolen credit card and bank account had been wiped clean last year, that would have netted cybercriminals some $8 billion, according to data from Symantec, maker of the Norton antivirus software.

As a result of the lucrative payout, more and more online criminals are entering the game. In fact, the number of new Internet security threats rose nearly three-fold last year to 1.7 million.



Those cyber attacks mostly come from malware, or malicious software, that hands control of your computer, and anything on it or entered into it, over to the bad guys without you even knowing it. The most common forms of malware
include keystroke logging, spyware, viruses, worms and Trojan horses.







"Credit cards and bank account information made up 51% of the goods advertised on the underground economy last year, up from 38% in 2007. Credit cards are most popular because they're the cheapest stolen commodity."



Security software also helps, but it far from solves the problem. To avoid detection, many cybercriminals will send out just a handful of viruses before modifying the code and sending it out again.




"The truth is that 'fingerprint' security technology is no longer effective," said Rowan Trollope, senior vice president of product development at Symantec. "The bad guys that got involved are organized professionals, and they figured out how to get around our technology."




Editor's Note:  For those who have may have been thinking all along that I've been blowing this out of proportion (the fact that the web is not safe for financial transactions unless done "outside the browser space" and "instantaneously encrypted) " I've got three things to say to you.  "Don't Type"...Swipe.  (or if you are a member of the media) "Do Not Enter!" 



I assure you I'm not blowing this out of proportion.  I'm coming from help here.  In fact, I'd give you the "shirt off my back" to help you understand how unsafe it is to enter/type your card numbers into a box on a merchant's checkout...





What size do you need?

















Reblog this post [with Zemanta]

The Battle Has Needlessly Begun and Congress is Ready to Screw it Up!

Retailers, Banks Battle Over Credit Card Fees - washingtonpost.com
The battle is on. In one corner we've got a tag team consisting of the National Association of Convenience Stores, the National Retail Federation and the Merchants Payments Coalition who all seam to be "teeming" with anger.

In the other corner, you've got the infamous Dynamic Du(opoly).

Unfortunately, the referee of this bout is the Government Accountability Office.

I say both sides should team together and kick the referee out of the ring. When the bell sounds consumers can decide who the winner is.

My personal belief is that once Congress steps in, everyone will lose. The Tag Team, Teh Dynamic Duo(poly) and the Consumers. Seems to be their history. Lose Lose Lose situations always occur when the Con(gress)Man gets involved.

I say: "Let the people decide!" If consumers want to pay with their credit/debit card let them pay with their credit/debit card. If they want to pay with cash, let them pay with cash. If retailers want to offer a discount for cash, let them offer a discount for cash. It's called free will and it's called free enterprise.

Earlier I posted a press release from Visa stating that, "By a 2-to-1 margin, consumers say retailers should pay the cost of accepting credit and debit cards."

If the study is indeed accurate, then the solution is simple. Let the "TWO PEOPLE" pay with their credit and debit cards and let the "OTHER ONE" pay with cash. Everybody wins!
Who needs the (insert expletive here) con(gress)man or a congressional committee wasting hundreds of thousands, if not millions of tax-payer dollars, doing a study to determine which cry baby gets the bottle?

It's not really difficult to solve (unless of course, government sticks their noses into it...if they do, I say to both Visa/MasterCard and the Retailers...take a lesson from Mike Tyson...bite it off!) You 'ear what I'm sayin'?

Let's just KISS (keep it simple stupid) and Make Up. Both sides should agree to let the consumers decide how they want to pay. Both sides should agree to let the merchants decide if they want to discount the price to save on interchange. But by all means, let's try and keep the government out of this. Involving them is as stupid as typing your credit card or debit card numbers into a box on a website...


Retailers Battle Credit Card Fees - Banks Say Interchange Charges Are Fair
A battle is brewing over the processing fees that banks charge merchants each time a customer uses a credit or debit card.

Congress is considering three bills that would regulate the so-called interchange fees -- which generally amount to 1 to 2 percent of a total sale and totaled $48 billion in 2008. Meanwhile, the Government Accountability Office is doing a study of the fees, (oh please...let the people decide!) as required by a law signed by President Obama in May that bans many unfair credit card industry practices.


Merchants across the country and the card industry are waging a fight for public support. The merchants say the fees are excessive and eat into their already small profit margins, forcing them to pass on the cost to consumers. The card issuers say they are providing merchants a much-needed service as more Americans choose to pay for their purchases with plastic.

Both sides have created YouTube videos, bought newspaper ads and released studies to prove their points. Large national chains such as 7-Eleven have embarked on petition drives.

The Merchants Payments Coalition will release a study on Thursday of how European countries, Canada and New Zealand handle interchange fees. Merchants in those countries generally pay lower interchange fees. (Editor's Note: here's the PDF version of the Study)

The study found that if American merchants paid the same swipe fees as those in Australia the past four years, the net savings would total $125 billion. Editor's Question: In whose pocket did that $125 billion go? I don't need a study to tell you it wasn't the consumers...

Again...let the people decide.

Continue Reading at the Washington Post


Reblog this post [with Zemanta]

Web 2.0 Targeted by 2.0 out of 3.0 Hackers

Here's some more on the Websense Internet Security Report...



"Security software vendor Websense claims 95 percent of user-generated comments on blogs and message boards are either spam or contain malicious code."  (Editor's Note:  Please leave 5% of your comment below)


Social networking and user-generated content sites have become a haven for spam, spyware and phishers, according to the latest Internet security report from San Diego, Calif.-based security software maker Websense.



The report found that 95 percent of user-generated comments on blogs, message boards and chatrooms are either spam or malicious. Websense's Threat Seeker network scanned more than 40 million Web sites and 10 million e-mails every hour over the past six months to compile its research report. 
Reblog this post [with Zemanta]

ISTS Worldwide Press Release

Thanks to ISTS for following the PIN Payments News Blog on Twitter





Hi, PIN Payments News Blog.

ISTS Worldwide, Inc. (RETAILPAYMENTS) is now following your tweets on Twitter.

Fremont, Calif., Sept. 17, 2009 -PIN Payments News Blog- ISTS Worldwide Inc, a leading technology consulting organization, specializing in consumer and card processing systems, announces that it will extend its use of the Microsoft technology stack to deliver innovative payment processing solutions based on SQL Server 2008 and BizTalk Server 2009. The new solutions will provide ISTS customers with leading applications for payment switching, authorization, settlement, card-issuing and reporting. The ISTS solution competency also extends to gift and prepaid cards, loyalty, mobile payments, enrollment applications, promotions at POS, ecommerce and the mobile channels.



“At ISTS we seek to offer a fully integrated solution framework offering and believe that the advanced integration capabilities of BizTalk Server will provide the required interoperability and support for industry standards on a cost effective platform for our clients,” said Mustafa Shehabi, Sr. VP Sales & Marketing at ISTS Worldwide, Inc.



“At a time of cost-cutting and IT consolidation, the breadth of our platform and the commitment of ISTS and other payments technology leaders make Microsoft uniquely able to quickly enable participants in the payments value chain by connecting systems that drive new operational efficiencies and innovative customer experiences,” said Susan Hauser, vice president, Worldwide Financial Services, Microsoft.



Sequoia Retail Systems – an independent provider of point of sale, inventory control, mobility and ecommerce solutions for higher education institutions, contracted ISTS to implement a secure, token-based ecommerce application known as “ePOS”. The completion of this project means that its customers are assured of the highest level of security for all transactions on their site. The solution is based on Microsoft .NET 3.0 infrastructure



Sequoia CEO Jim Zaorski states, that while he appreciates the efforts of ISTS, “it is what I have come to expect from them in terms of their analytical, design, programming, and QA functions. In our view ISTS occupies a unique position among offshore contactors, they bring many years of experience focused entirely on payment and retail applications to any project on day one. Their experience with some of the largest players in the industry often make them a superior alternative to our own in house and off shore teams in terms of experience, price, and performance."



“ISTS and Microsoft will continue to partner to bring innovation in the world of consumer payments – innovation here is stifled because of legacy and archaic technology – ISTS sees a huge opportunity to extend Microsoft’s core platforms to influence back office and consumer facing applications for large and small customers alike,” said Viren Rana – CEO of ISTS Worldwide.



Source: Company press release.




Reblog this post [with Zemanta]

Introducting Google Internet Stats

Google Internet Stats



Google Internet Stats

Welcome to our collection of the latest Internet stats

This Google resource brings together the latest industry facts and insights. These have been collected from a number of third party sources covering a range of topics from macroscopic economic and media trends to how consumer behaviour and technology are changing over time.





Reblog this post [with Zemanta]

Heartland Named to Bank Technology News "FutureNow" List



Princeton, N.J., Sept. 17, 2009 -PIN Payments News Blog- Bank Technology News ranked Heartland Payment Systems(R) (NYSE: HPY), one of the nation's largest payments processors, as the #1 innovator in The FutureNow List, acknowledging the company for its work to further secure its systems and the payments ecosystem with end-to-end encryption. Heartland's new E3TM end-to-end encryption solution was described as "this year's biggest security invention."



Heartland's E3technology is being designed to safeguard cardholder data at rest and in motion throughout the lifecycle of payments transactions from the moment of card swipe ... to and through the payment processor's network ... and to the card brands.



According to the magazine, the company's E3 solution "has the greatest potential of any new product to impact the security of America's financial system in the coming year. And by bringing it to market just about seven months after the company announced the discovery of its massive data breach, Heartland wins kudos for reacting expeditiously to both save the company and set a standard for the rest of the industry to follow."



The FutureNow List is an annual security innovation ranking. It recognizes 10 companies that set themselves apart with their security innovations and the contributions these products will make to improving security within financial services organizations. Heartland was the only payments processor to make the list.



"We are honored to receive this acknowledgement from Bank Technology News in recognition of our E3 end-to-end encryption solution," said Bob Carr, Heartland's chairman and chief executive officer. "Our goal is to provide a secure and compelling solution that protects cardholders and merchants from the growing threat of cyber crime."



For more information on E3, visit E3secure.com.



Bank Technology News' FutureNow List ranking is available at: http://www.americanbanker.com/btn_issues/22_9/the-futurenow-list-1001433-1.html



About Heartland Payment Systems



Heartland Payment Systems (NYSE: HPY), the 5th largest payments processor in the United States, delivers credit/debit/prepaid card processing, payroll, check management and payments solutions to more than 250,000 business locations nationwide. Heartland is the founding supporter of The Merchant Bill of Rights, a public advocacy initiative that educates merchants about fair credit and debit card processing practices. For more information, please visit HeartlandPaymentSystems.com, MerchantBillOfRights.com and CostOfABurger.com.



Source: Company press release.



Reblog this post [with Zemanta]

NCR is First ATM Manufacturer to Receive PA-DSS Certification



NCR APTRA™ software meets requirements to protect sensitive customer data on ATMs



DULUTH, Ga. – NCR Corporation (NYSE: NCR), the global leader in ATM security, is the first ATM manufacturer to receive PA-DSS certification from the PCI Security Council. PA-DSS is a comprehensive standard intended to help organizations proactively protect customer account data, through requirements for security management, policies, procedures, network architecture, software design and other critical protective measures.



According to PCI, the goal of PA-DSS is to help software vendors and others develop secure payment applications that do not store sensitive data, such as full magnetic stripe, CVV2 or PIN data, and ensure their payment applications support compliance with the PCI DSS. Payment applications that are sold, distributed or licensed to third parties are subject to the PA-DSS requirements.



he latest version of NCR APTRA Advance NDC has been certified by PCI. APTRA Advance NDC makes it possible to drive a single application across multiple vendors’ hardware in NDC host environments. Providing many transactions “out of the box” as well as a platform for the rapid deployment of new functionality, APTRA Advance NDC drives transactions on more than 150,000 ATMs for more than 2,000 customers, making it the most popular self-service software in the world.


NCR also was the first ATM manufacturer to receive EMV certification.



“At NCR, ATM security is one of the pillars of our business, and we are committed to being at the forefront of the industry in order to protect the privacy and data of our customers and the consumers they serve,” said Michael O’Laughlin, general manager, NCR Financial Services. “More financial institutions turn to APTRA to run their ATMs than any other software, so it is critical that we work closely with PCI to certify this mission-critical software for PA-DSS compliance.”



NCR is a leading provider of hardware and software security solutions for ATMs. Among NCR’s ATM security portfolio:



NCR has sold more than 50,000 licenses of Solidcore for APTRA™, the only proven security solution to preserve system integrity and prevent malware on ATMs.



NCR’s latest family of ATMs, NCR SelfServ, is the first to introduce a protected USB architecture that is self-contained within the ATM, helping mitigate the risk of fraudulent connection of unauthorized USB devices.



Fraudulent Device Inhibitor (FDI) is an external illuminated hardware feature or kit that makes it difficult for criminals to attach foreign devices on or around an NCR ATM card reader.



Intelligent Fraud Detection (IFD) is a unique approach to countering ATM fraud. Designed to be flexible, NCR IFD can detect a variety of fraudulent devices that criminals may attempt to add to the ATM fascia. The deployer receives an instant alert as soon as a fraudulent device has been added to the ATM, even before any fraud has taken place.



About NCR Corporation

NCR Corporation (NYSE: NCR) is a global technology company leading how the world connects, interacts and transacts with business. NCR’s assisted- and self-service solutions and comprehensive support services address the needs of retail, financial, travel, healthcare, hospitality, entertainment, gaming and public sector organizations in more than 100 countries. NCR (www.ncr.com) is headquartered in Duluth, Georgia.



# # #



NCR is a trademark of NCR Corporation in the United States and other countries.

67% of Banks Say Fraud Losses Have Grown Over Past Year



Latest research from Norkom Technologies exposes banks’ increased vulnerability to fraud and diminished ability to prevent it



Dublin, Ireland -
250 financial crime professionals working in banks across the globe say measures taken by their organizations to reduce costs in the wake of last year’s financial crisis are leaving them and their customers increasingly vulnerable to criminal attack.

Respondents in Norkom’s annual survey of financial crime fighting activities in the world’s banks, say that cuts to their own departmental spending plans are weakening their ability to keep pace with a rising tide of criminal attack and that general cost cutting across their businesses is further weakening the banks’ defenses.

  • 71% of respondents say fraud attacks against their business have increased over the past year and it’s clear that, not only the number, but the severity of attacks is rising.



  • 67% say their financial losses to fraud have grown over the same period.  For almost a quarter (22%) that growth has been greater than one-fifth. 

At the same time, around a third have seen their financial crime prevention budgets reduced.  For some, those cuts have been dramatic. 12% say they’ve lost a quarter of their anti-money laundering (AML) budget.  The figure is only slightly lower for fraud at 9%. 50% agree that general cost-cutting across their organizations is weakening their defenses.

david_dixon

“It’s ironic that the very actions banks are taking to shore up their damaged finances may sabotage their chances of recovery,” says David Dixon, Norkom’s Director of Global Solutions. “However, we do see a path out of the dilemma. There is clear evidence that advanced crime fighting approaches, underpinned by consolidated technologies, can reduce fraud losses and, simultaneously, reduce operating costs in crime fighting departments.”



Last year’s research revealed that 64% of organizations had reduced operating costs by up to 30% by using consolidated crime fighting technologies.  66% also said their ability to detect crime had improved by up to 40%.  This year’s research reinforces those findings.  79% of respondents using a consolidated technology approach said that it had allowed them to improve their ‘percentage of fraud detected’ performance (the amount of fraud detected and prevented as a proportion of total fraud reported to them by their customers).  63% have also seen their operating costs decrease.



There is clear evidence, too, that technology can help in another way, directly in relation to fraud. 56% of all companies using common case and workflow management tools within their fraud technology solutions are achieving dramatic reductions in their fraud losses, thanks to the ability it gives them to take action quickly to stop crime in its tracks.



“In the final analysis, two lessons emerge from this research,” says Dixon. "First, that attempts to save money by cutting financial crime budgets are likely to be counter-productive. Second, that fraud losses can be reduced through the use of consolidating technologies which, in turn, allow business processes to be streamlined. So, if the twin imperatives are to cut losses and stem costs, there’s good news on both fronts.”

Norkom_whitepaper

42% of respondents say they now have a single software solution – deployed enterprise-wide – to detect and investigate AML; 17%, for fraud.  48% of the remainder have deployed an overarching technology that consolidates information from their different detection systems in order to enhance investigation management. A further 30% plan to implement such technology within the next 12 to 24 months.



For your free copy of Norkom’s research whitepaper, ‘
Fighting crime – defending the bottom line’, log onto www.norkom.com/press/whitepapers.html.



NOTES FOR EDITORS


Research methodology

This report is based upon original research conducted among senior executives from a representative sample of international financial services organizations.  The respondent group covered the full spectrum of financial services companies including retail banks, commercial banks and integrated financial services companies.  41% of the organizations polled had assets between US$10 billion and US$500 billion, while 12% had assets over US$500 billion.



About Norkom Technologies (
www.norkom.com)

Norkom Technologies (AIM: NORK.L, IEX: NORK.IE) enables financial organizations to take intelligent action, control defenses, and evolve strategies against fraud, money laundering, and other types of financial crime. By combining a unique investigative technology platform with deep domain expertise, Norkom has established a solid track record of reducing financial losses, protecting users’ reputations, improving operational efficiencies and lowering the cost of information technology.



For more information, please contact:


Fiona McLoughlin, Marketing Manager

T:                +35318739612       





Reblog this post [with Zemanta]

Disqus for ePayment News