Friday, February 6, 2009

Strengthen Security of Online Payments - European Parliament

Security and safety of Internet transactions need to be strengthened, says European Parliament
Download the European Parliament Press Release in PDF format



More than half of EU citizens and nearly 1.5 billion people worldwide have access to the Internet. Yet, despite the fact that one out of three EU citizens conducts online purchases, only 30 million carry out cross-border shopping in the EU. In view of this, MEPs are demanding increased Internet security, simplified rules and specific measures for SMEs in a report adopted in Strasbourg with 562 votes in favour, 9 against and 10 abstentions.

In a report drafted by Giorgos Papastamkos (EPP-ED, EL), The European Parliament believes that lack of trust in the security and safety of transactions and payments "constitutes the most important danger for the future of e-commerce".

Editor's Note: HomeATM fully agrees with the assessment that the security of internet transactions need to be strengthened. It was the reasoning behind providing end-to-end encryption on our transactions since January '07. The lack of trust is a problem indeed, but in order to build trust, e-payments need to be End-to-End Encrypted. (E2EE) Without E2EE, another breach is imminent.

One guaranteed way to provide E2EE is via PIN Debit through a personal swiping device. Of course the PIN Entry Device (PED) would need to meet PCI 2.0 requirements by going through a series of rigorous testing. Upon completion of testing it would then need to be submitted through the proper channels in order to receive official PCI 2.0 certification. Should that happen, you have a game-changing platform. Which is why HomeATM was pleased to announce that it's SafeTPIN (T stands for Transaction) personal card swiper with built-in PIN Pad was deemed by Witham Labs to either meet or exceed PCI 2.0 standards. (HomeATM Meets PCI 2.0 Standards) In short, HomeATM has believed that the security of online transactions needed to be strengthened from day one, which was the basis for our approach to bringing safe and secure PIN-authorized transactions to the web.

MEPs call on the Commission to investigate the causes and to redouble its efforts to "create mechanisms for strengthening businesses' and individuals' trust in international electronic payment systems, as well as establishing suitable means for resolving disputes related to illegal commercial practices".

Combating counterfeiting, piracy and fraud


Illegal behaviour such as counterfeiting, piracy, fraud, breach of transaction security and violation of citizens' private space pre-existed in the "physical world", say MEPs, but these activities have been both "facilitated and exacerbated" by the abundant technological possibilities provided.

They stress the need to adopt and strengthen necessary and appropriate enforcement measures and for more effective and concerted coordination. This will permit the combating and elimination of existing illegal online commercial behaviour, without affecting the development of international e-commerce, MEPs say, especially with regard to cases liable to involve major public health risks, such as bogus medicines.

MEPs also believe that the regulatory deficiencies in the EU online market are hindering the development of a stable and strong European online industrial and commercial environment. This, they say, results in unsatisfactory levels of participation by European consumers in EU and international trade transactions and hinders creativity and innovation in commercial activity.

Improve regulatory provisions


MEPs deplore the regulatory provisions permitting or requiring geographic market partitioning, high Internet access charges, and any limits on the availability of delivery options in the EU.

The report calls on the Commission to improve the legal interoperability of Internet services through the development of model licences and other legal solutions compatible with jurisdictions. It also asks that existing European deliverables for legal interoperability be propagated in order to reduce both transaction costs and legal uncertainty for online providers.


The report points out that the inherently international character of electronic commerce calls for universal understanding and cooperation, and proposes that bilateral and regional trade agreements signed by the EU should contain explicit provisions covering broad and open use of the Internet for trade in goods and services. The fact that the Doha Development Agenda "does not mandate specific negotiations on e-commerce', is regrettable, it says.

Measures for SMEs


MEPs call on the Commission to develop a comprehensive strategy for removing the barriers to using e-commerce still affecting SMEs (access to ICT, costs of developing and maintaining e-business systems, lack of trust, lack of information, legal uncertainty over transnational disputes, etc.).

They ask the Commission to include policy recommendations, which offer incentives to SMEs to further participate in online trading products and services.

The report recommends the establishment of a database, designed to provide information support and management guidance to the new and inexperienced participants in online trading, and the conduct of a comparative economic analysis of the benefits of e-commerce and online advertising for SMEs, as well as case studies of successful EU SMEs trading online.

There is also a call for a detailed analysis of the influence of online trade upon conventional trading patterns and activities, in order to be aware of and consequently avoid potential adverse effects.

Increase investment for third-country Internet trade


Finally, MEPs believe that the participation of the least developed and other developing countries in international trade through the Internet has to be supported through increased investment primarily in basic infrastructure such as telecommunication networks and access devices. The report underlines the need for low cost and better quality provision of Internet services.

REF. : 20090204IPR48481

Source: Press Release






Reblog this post [with Zemanta]

Juniper on Mobile Money Transfer Market


Press Release: Contraction in Migrant Workers Impacts Mobile Money Transfer Market by 50%, down to $73bn by 2011

Hampshire, UK – 4th February 2009: A new study by Juniper Research indicates that the mobile money transfer market will be particularly vulnerable to the effects of the global recession. The rapidly changing economic downturn is forecast to have an immediate impact on the gross value of mobile money transfers, with the market in the worst case scenario reaching $73bn by 2011. This is some 50% less than previously forecast, although strong growth overall is still expected in the long term.

The Juniper Research mobile commerce report determined that the short term impact of the recession is likely to be felt most severely in this market owing to the effect of job losses in the migrant worker population.

Report author Howard Wilcox pointed out: "We are still in the early stages of the recession but we are already observing significant layoffs which will affect a market where the growth is fuelled by migrant workers sending remittances home to families. Workers from countries such as India, the Philippines and Mexico are likely to be hit in this way because of the sheer numbers working abroad as expatriates. However, we still see this market long term as a significant growth opportunity."

The Juniper report determined that all the mobile commerce market segments are still set to grow significantly over the next five years driven by a range of factors including user demand, but they will all be affected to a greater or lesser extent by the recession. The report includes a top level assessment of the impact of the global economic situation resulting from the credit crunch on the main mobile commerce market segments.

The Juniper Research mobile commerce study analyses the trends and issues affecting the mobile commerce market, across all the main segments providing forecasts of gross transaction values for digital goods and physical goods purchases, NFC (Near Field Communications), mobile money transfers, ticketing, coupons and banking. The report also presents the latest application and services examples and case studies from in excess of 60 mobile commerce companies pioneering in this developing market.

Mobile Commerce whitepapers and further details of the study, 'Mobile Commerce: Prospects for Payments, Ticketing, Coupons and Banking 2008-2013’ can be freely downloaded from www.juniperresearch.com. Alternatively please contact John Levett at john.levett@juniperresearch.com, telephone +44(0)1256 830002.


Reblog this post [with Zemanta]

Amazon Payments Taken Out of Beta

Amazon takes payments service out of beta

Amazon Payments, a subsidiary of Amazon.com, (NASDAQ:AMZN), today announced the General Availability of Amazon Flexible Payments Service (Amazon FPS) and the launch of Amazon FPS Quick Starts.

Amazon FPS Quick Starts aggregate various Amazon FPS APIs into a simplified set of APIs that substantially reduce the steps a developer must take to enable transaction processing on their websites. Now, developers can enable common payment transactions such as one time payments, recurring payments and pre-payments in hours rather than days.

Amazon FPS is the first payments service designed from the ground up specifically for developers. It is built on top of Amazon's reliable and scalable infrastructure and allows developers to accept payments from Amazon's tens of millions of customers.

Starting today, developers who sign up for Amazon FPS by March 15th and launch their applications by June 1, 2009 can take advantage of free payment processing for the first 90 days until total transaction volume reaches $500,000. To learn more about Amazon FPS, Amazon FPS Quick Starts, and the free processing promotion, visit amazonpayments.com/fps.

Amazon FPS Quick Starts include:

* Basic Quick Start enables one-time payments for e-commerce and digital goods, donations, and any other online service.
* Advanced Quick Start provides periodic or delayed payment features required by subscription and usage-based services such as digital music and online storage. Advanced Quick Start offers developers flexibility in specifying payment instructions by time period, amount, and frequency. For example, a user can make recurring payments for a specific amount at regular intervals or a sender might set a spending limit per week for a particular named recipient.
* Marketplace Quick Start is designed for building marketplace applications. Developers can facilitate transactions between a third party buyer and seller, take a cut of the transaction, and have control over who pays the transaction processing fees.
* Aggregated Payments Quick Start reduces processing costs by consolidating multiple transactions, including micro-payments, into a single, larger transaction. This Quick Start offers prepaid and postpaid mechanisms to aggregate transactions. You can enable your customers to create prepaid balances that can be used subsequently to make multiple smaller purchases on your web site or you can extend credit and charge them later for accrued usage. In both cases, the Aggregated Payments Quick Start enables you to programmatically track individual transactions and the aggregated amount.
* Account Management Quick Start simplifies integrating account activity, balance and transaction information into websites and existing applications.

"Developers have been excited about the flexibility that Amazon FPS offers and the wide range of innovative business cases it enables. Developers have asked us for an easier way to get started and tools that would enable them to make the most of the Amazon FPS feature set. This release incorporates this feedback by introducing Amazon FPS Quick Starts, which significantly simplifies integration while maintaining all the flexibility that Amazon FPS provides," said Mark Stabingas," General Manager of Amazon Payments. "Developers can now choose the Amazon FPS Quick Start that meets their unique business needs and monetize their innovations quickly."

"SocialGold's objective is to make it really simple and easy for users to buy currencies and goods in online games and social applications. Amazon FPS Quick Starts provide the most logical and easy-to-use interface we've seen," said Vikas Gupta, Co-Founder and CEO of Jambool, a virtual economy platform for online games. "With Amazon Quick Starts we could quickly zero in on the API we needed. The documentation is great, the API is lightweight and we believe Amazon FPS Quick Starts will be instrumental in helping us create a great experience for our users."

"Meetup is a worldwide network of local, offline groups," said Maya Voskoboynikov, Group Product Manager for Meetup. "By integrating with Amazon FPS, we are helping Meetup Groups develop their own economies in the form of membership dues, event tickets and sponsorship payments. Helping Meetup Groups grow their economies is key to supporting the growth of long lasting organizations. We chose Amazon FPS for its flexible and powerful API, which allowed us to build several custom solutions from one basic foundation."

"We needed to support hundreds of thousands of merchants across a vast network of boutique marketplaces," said Matthew Trifiro, CEO of 1000 Markets. "Amazon FPS was the only system capable of giving us a robust checkout experience across our network. We looked at other payment systems available and chose Amazon FPS because Amazon is the most trusted name in e-commerce and that leads to more sales."

Source: Amazon Payments, 06 February 2009

Reblog this post [with Zemanta]

Mobile Money Transfer Gaining Acceptance

Finextra: Monilink reports growing user acceptance of mobile money transfer
Monilink reports growing user acceptance of mobile money transfer

UK m-banking outfit Monilink is reporting a surge of interest in mobile payments, with over half a million pounds transferred by users in the past month.

The Monilink mobile money service is currently available to over half of UK adults including customers of Alliance & Leicester, first direct, HSBC, Lloyds TSB, NatWest, Royal Bank of Scotland and Ulster Bank.

Customer surveys indicate that the most requested new services are the ability to move money to third party accounts, such as topping-up travel cards, charging electricity and gas pre-payment accounts and paying-off credit card balances.

The vendor is currently expanding its portfolio to offer services for the most advanced smartphone devices, including the latest touch screen handsets. It says the ongoing development of services specifically designed for smartphones demonstrates the growing acceptance of mobile money services by consumers across the UK.

John Milliken, managing director of Monilink believes that big bank backing for the service is crucial to user acceptance.

"Consumers we talk to are still reluctant to give secure information to brands they haven't heard of before," he says. "In the UK the successful mobile money services are all presented to the consumer by the banks themselves which I believe is the crucial difference between the mass-market services here and some of those offered in some other places in the world."

Monilink recently introduced facilities for intra account transfer and international money mover services over recent months.

Says Milliken: "I look forward to continuing this trend with the announcement of our new payment services, including some of those that our customers have requested."

Reblog this post [with Zemanta]

X-Force Is With You...


IBM has released it's 2008 X-Force Security Report.  Since I've been detailing how unsafe it is to do e-commerce in a Web browser space (7 words - You should be SwipePIN instead of Typin') I thought I'd share some statistics to back it up.  (click graph on left to enlarge)

X-Force Trend Statistics Report

The X-Force produces the X-Force Trend Statistics report twice per year, once at the end of each year and once at mid-year. These reports provide statistical information about all aspects of threats that affect Internet security, including software vulnerabilities and public exploitation, malware, spam, phishing, web-based threats, and general cyber-criminal activity. The information in this report is for customers, fellow researchers, and the public at large and is intended to help others understand the changing nature of the threat landscape and what might be done to mitigate it.

First, let's flashback and take a look at their leading paragraph from last years release:

"ARMONK, NY - 11 Feb 2008:
IBM (NYSE: IBM) today released the findings of the 2007 X-Force Security report, detailing a disturbing rise in the sophistication of attacks by criminals on Web browsers worldwide. According to IBM, by attacking the browsers of computer users, cybercriminals are now stealing the identities and controlling the computers of consumers at a rate never before seen on the Internet.
"

Here are some personally selected highlights:
Web-Related Security Threats

• The number of new malicious Web sites in the fourth quarter of 2008 alone surpassed the number seen in the entirety of 2007 by 50 percent. Last year, China replaced the US as the most prolific host of malicious Web sites.
 
Browser-related vulnerabilities are still overwhelming the largest percentage of critical and high vulnerabilities affecting personal computers in 2008. (52 percent of all criticals and highs)

• Even good Web sites are facing more issues. Web applications, in particular, are increasingly vulnerable and highly profitable targets for helping the criminal underground build botnet armies

• Web applications in general have become the Achilles heel of Corporate IT Security. Nearly 55% of all vulnerability disclosures in 2008 affect Web applications, and this number does not include custom-developed Web applications (only off-the-shelf packages). 74 percent of all Web application vulnerabilities disclosed in 2008 had no available patch to fix them by the end of 2008.

• Last year, SQL injection jumped 134 percent and replaced cross-site scripting as the predominant type of Web application vulnerability.

• Exploitation of Websites vulnerable to SQL injection has increased from an average of a few thousand per day, when they first took hold early in 2008, to several hundred thousand per day at the end of 2008.

• In addition to these vulnerabilities, many Web sites request the use of known vulnerable ActiveX controls, which leave Web site visitors who do not have updated browsers in a compromised position.

• The majority of phishing – nearly 90 percent – was targeted at financial institutions. Over 99% of all financial phishing targets are in North America or Europe, with the majority of targets in North America (58.4 percent).  

• The days of amateurs, college students, or hackers taking joy rides on corporate information systems are largely over. Today’s attackers are economically motivated. They are international criminal organizations who make a living stealing financial information and identities.
 

Remotely Exploitable Vulnerabilities
The most significant vulnerabilities are those that can be exploited remotely, because they do not require physical access to a vulnerable system. Remote vulnerabilities can be exploited over the network or Internet, while local vulnerabilities need direct system access.

2008 marks the third straight year where the percentage of remotely exploitable vulnerabilities has reached a record high.

In 2008, they represented 90.2 percent of all vulnerabilities, up from 89.4 percent and 88.4 percent in 2007 and 2006 respectively.

A factor in the increase that has occurred over the past few years is the growing number of Web application vulnerabilities, which are typically remotely exploitable and an ever-growing percentage of the overall vulnerability count.  See figure 14 above. (click to enlarge)
To take a look at the full 106 page PDF, click here.
Reblog this post [with Zemanta]

Parking Ticket = Malware in Disguise

Here's a new angle on getting people to unknowingly and willingly visit a site which installs malware on their machines.  According to Christopher Null at Yahoo Tech, hackers put counterfeit "parking tickets" on the windshields of illegally parked cars.  The counterfeit tickets instruct the car's owner to go to a website and pay the fine.  Yes, you guessed it...the website installs malicious code.  Here's his story:

Parking tickets actually malware attacks in disguise : Christopher Null : Yahoo! Tech

The last place anyone would expect to face a computer security attack is on the windshield of their car in the form of a parking ticket.

But that's the latest -- and intensely clever -- way that hackers are attempting to goad people into visiting infected websites and willingly install malware on their machines.

The scam is instantly clever once you hear how it works: Hackers print up phony "PARKING VIOLATION" notices and plaster them on cars parked on the street. The phony ticket directs the car's owner to visit a certain website, and of course the website in question (which largely seems to comprise of photos of badly parked cars) is a hack site which attempts to install malware on your PC.

Essentially what we have here is a phishing attack that takes place in the real world instead of via email. The use of fliers on parked cars is what's truly ingenious: A similar attack sent via postal mail would probably have minimal effect, but people are incredibly protective of their cars, and I imagine these windshield fliers will actually have a pretty good percentage of people typing in the URLs typed on them.

Reblog this post [with Zemanta]

Thursday, February 5, 2009

UATP Processes Record $12 Billion in 2008

UATP Announces Record Charge Volume for 2008
UATP Announces Record Charge Volume for 2008
PR Newswire


WASHINGTON, Feb. 5 /PRNewswire/ -- Universal Air Travel Plan, Inc. (UATP), the low cost payment network privately owned by the world’s airlines, today announced record charge volume and profits for calendar year 2008. UATP CEO Ralph Kaiser stated, "UATP continues to prosper even in today’s economic environment. While we see challenges from an overall decrease in travel spending in the upcoming year, there are enough growth drivers in our business to continue to be optimistic about our performance in 2009."

UATP processed approximately US$12 billion in 2008, all with just 38 staff worldwide.

UATP has also been working hard to diversify its product offerings beyond its core corporate travel charge card business with great success. "UATP’s alternate form of payment processing business has taken off in 2008 much like our USS business did after its launch a few years back. Both lines of business are posting impressive growth rates," added Kaiser.

UATP’s alternate form of payment processing includes work for such online payment brands as Acculynk, BillMeLater, HomeATM, Moneta and PayPal.

USS is UATP’s in-house, proprietary settlement system which allows travel agency and low-cost air carrier payment processing to be conducted outside of normal channels. In 2009, in addition to offering air travel payment, with its industry leading data, UATP plans to expand its merchant base via USS to include hotels and rental car companies. This is expected to add significant charge volume to the network and greatly enhance the core product offering.

"Notwithstanding the current economic climate, 2009 will be a growth year for UATP. We are a dynamic and hungry company and we’re always looking for ways to save money for the airlines and their corporate customers while enhancing profitability for our shareholders," concluded Kaiser.

About UATP

UATP accounts are accepted as a form of payment for corporate business travel by airlines and travel agencies worldwide. UATP accounts are issued by: Air New Zealand (ANZFF.PK), American Airlines (NYSE: AMR), Austrian Airlines (AUALF.PK), Continental Airlines (NYSE: CAL), Delta Air Lines (NYSE: DAL), Japan Airlines (JALSY.PK), Northwest Airlines (NYQ: NWA), Qantas Airways, Ltd. (QUBSF.PK), United Airlines (Nasdaq: UAUA), and US Airways (NYSE: LCC). AirPlus International issues the UATP-based Company Account for: British Airways (LSE: BAY.L), Continental Airlines (NYSE: CAL), and Lufthansa German Airlines.

Contact:
UATP Corporate Communications
Wendy Ward, wward@uatp.com
+1 202 626 4077

SOURCE UATP

Paradigm Shift E-vidence Continues to Stack Up

In a continuing series of Paradigm Shift posts, I bring you this.   Earlier this week, Macy's announced they were cutting 7000 jobs amid reorganization.  Meanwhile, Amazon had it's best quarter ever. Something's going on here.  Let's take a closer look.

Yesterday Internet Retailer reported:

"Growth for the 110 e-retailers that have reported 2008 sales, so far, has reached 21.8% over 2007.  That's $33.50 billion for those same e-tailers in 2008 vs. $27.46 billion in 2007"

Let's just say that the bricks and mortar circuit didn't quite fare so well, and leave it at that. 

I was only joking back in December when I said that one November Thursday we'll turn on our TV to watch the Amazon Thanksgiving Day Parade...in fact, if I remember correctly, I think I may have even called that the "Parade-igm" shift.  Maybe I wasn't so off-base.

Speaking of shifts, there's an article out of the U.K. saying that more shoppers are preferring e-commerce over bricks and mortar.  It also says consumers prefer to "let their fingers do the shopping."  That's true, and there's a preponderance of mounting e-vidence pointing to that being fact, rather than speculation.

Apparently the Yellow Pages were way ahead of their time with their "let your fingers do the walking slogan, and that all well and good...

...until checkout time.  It's at that point whereby you should be taking out your card and putting those fingers on hold. Because if you are tempted to touch any keys when they ask for your card number, then here's  7 "key "words: 

"You Should be SwipePIN' instead of Typin'."


As the Paradigm Shifts into second gear, on the Internet Autobahn originally dubbed the information highway,  HomeATM will be there with our End Encrypted, Dually-Authenticated PIN Debit solution for the web.  (Did I forget to mention that by "SwipePin" instead of "Typin" we morph the transaction from "card not present" into a "card present" transaction?")  I didn't think so.
 

The Internet was originally called the  Information Highway for a reason.  When you "type vs. swipe", someone's going to be there to commit highway robbery...the information is out there  to be had.  If you don't want to be the one being "had, then simply stop being that "type" of online shopper. 

Would you not agree that if someone's going to be SwipePin' your card information, it should be you instead of the bad guys? 

Recent breaches/hacks at CardSystems, TJX, RBS Worldpay, and Heartland aren't a whisper...they're a shout!  Are they an anomaly?  If so, which one?  Sure, I understand that the V/MC, and EFT networks won't make as much revenue per transaction, but at whose expense are they making it anyway? 

I would suggest they take a closer look at the bigger picture...on the flip side, they just may save money by incorporating a PIN Debit approach to the web.  How you say?  Here's how...maybe, they'd avoid a 100 million card holder breach, which has the potential (at $202 per compromise) ,to put a major dent in the money they're making by keeping security low and interchange high. 

The inherent nature (and value) of PIN Debit's built-in security , when swiped, (what you have=card and what you know=PIN) would empower e-tailers to process transactions at rates up to 100 basis points lower than they are currently paying.  

Do the math on $33.50 billion dollars, (the figure Internet Retailer is reporting with only 22% of the results in, from last year) and multiply that  figure by 100 basis points.  That's money that would go back into the economy instead of into the coffers of lawyers defending Visa and MasterCard in court for Antitrust Violations
. 

So, in my humble opinion, the time has arrived for the inevitable to occur.  We need to protect consumers and we need to protect e-merchants.  A more secure transaction via dually-authenticated end to end encryption shouldn't be "explored", it's the way it should be done...and HomeATM has been doing it that way, with $0 fraud since January '07.  
Oh...BTW...I almost forgot...here's the story providing further e-vidence of that Paradigm Shift...


Retailers lacking e-commerce likely to perish - CBR

Retailers who do not provide an online sales option to their customers are going to lose out on their business, as more shoppers are preferring e-commerce to high street shopping.

Businesses which do not invest in e-commerce are 30% more likely to fail, says Tenon Recovery, a turnaround, restructuring, recovery and insolvency specialist. Online retail sales in the UK rose from £46.6 billion in 2007 to £53.2 billion in 2008.

The rise in online sales was simultaneously marked by the closure of several high street stores. According to Tenon Recovery, the high street casualties are increasing as the businesses are investing more in brick and mortar buildings but not in e-commerce sites.

Carl Jackson, national head of Tenon Recovery, says that the new-age consumers like to go shopping with their fingers rather than their feet, as it is easier for them to compare prices online than move around the high street. Businesses which do not enable their consumers to shop 24 hours a day are at a disadvantage.

Tenon Recovery’s estimates are in line with the IMRG Capgemini e-Retail Sales Index for 2008, which has found that the online sales in the UK in December last year increased by 14.2% from 2007.

In an excerpt from a related story, "Online Sales to Jump Next Christmas" the e-vidence in the shift from retail, bricks and mortar, high street, call it what you will, to online is also mounting...
"...of the 2,000 consumers surveyed, 37% did more than half of their shopping online, while 59.9% spent more online this Christmas than last year.

Research undertaken by Capgemini, as part of the IMRG Capgemini e-Retail Sales Index, also observed that online sales have been increasing in spite of a fall in the growth of high street, as shoppers are turning to e-tailers to beat credit crunch.  (Editor's Note:  You can replace "credit crunch" with Snow, High Price of Gas, Time, etc.)

Matthew Tod, CEO at Logan Tod, said: “With 53% of those surveyed intending to increase online purchases for Christams’09, online retailers can look to see a sustained growth level as consumers continue to adopt the habit of online shopping.”

continue reading original story at CBR eCommerce








Reblog this post [with Zemanta]

Visa/MC Shares Rise

Bloomberg.com: Worldwide
Feb. 5 (Bloomberg) -- MasterCard Inc., the world’s second- largest credit-card network, rose 6.3 percent in New York trading after the company beat analysts’ profit estimates by raising the price of processing international purchases.

Profit excluding a settlement charge was $1.87 a share in the fourth quarter, beating the $1.62 average estimate of 21 analysts surveyed by Bloomberg. Revenue rose 14 percent to $1.2 billion, MasterCard said, and price increases mostly tied to cross-border transactions made up more than half of the rise. The network climbed $8.81 to $148.96 at 9:42 a.m. in New York Stock Exchange composite trading.

Chief Executive Officer Robert Selander is cutting expenses to reach profit targets jeopardized by the U.S. economic slowdown. MasterCard, which collects fees to shuttle payments between financial institutions, may miss a 20 percent to 30 percent net income growth goal this year after the effect of a stronger dollar is factored in, the company said in November.

“Despite the significant economic turbulence around the world, we were able to achieve excellent fourth-quarter operating results while maintaining a healthy balance sheet,” Selander said today in a statement.

Visa Inc., the largest credit and debit card network, rose 8.6 percent to $53.34 in New York trading after saying yesterday fiscal first-quarter profit rose 35 percent to $574 million.

MasterCard had 36 percent of the U.S. credit and debit-card market in 2007, compared with San Francisco-based Visa’s 51 percent and 12 percent for New York-based American Express, according to the Nilson Report, an industry newsletter based in Carpinteria, California.


Click Here to Read the Entire Story at Bloomberg.com

Reblog this post [with Zemanta]

Citibank Launches Online Money Transfer


On 12/30, in a post entitled RBI to Allow Outward Remittances, I covered the fact that the central bank (Reserve Bank of India) had been approached by a number of players to enable outward remittance facilities on their money transfer channels.  It looks like Citibank was one of them...as Citibank has announced the launch of Citi Online Remit.

The new online money transfer service provides Non Resident Indians (NRIs) the possibility to transfer funds to India from any US Checking/Savings account.

Money transfer in the system is also possible through a US Credit/Debit Card as a direct transfer into the beneficiary’s Bank account or as a draft couriered to the beneficiary’s mailing address in India. The platform is powered by the
QuikRemit platform from Citi’s Global Transaction Services.

At the times when the average value of remittances is increasing, Paul Galant, CEO of Citi’s Global Transaction Services, highlighted that the service is aimed at offering “a fast, safe, and secure platform for cross-border money transfers.” This is being achieved through a wide range of built-in security features, including Online Identity Verification, Multi-Factor Authentication, Global IP tracking and Account authentication. Besides, an online tracking system enables NRIs to follow their transaction at every stage of the transfer process. Regular 24/7 customer service on phone and online are also offered.

The Citibank NRI Business offers a wide range of money transfer services globally with eight major regional hubs in USA, Canada, UAE, UK, Australia, Kenya, Singapore, and Bahrain. The service manages assets exceeding US$ 6 billion and has 200,000 customers. The NRI Business account domiciled in India is denominated in Rupees, under the aegis of Reserve Bank of India. To ease the life of global Indians who have been customers of Citibank NRI Business for more than two decades, the bank offers such services as the Citibank Rupee Checking Account, international ATM and Debit cards and an unparalleled service in draft delivery to beneficiaries in India. 
More

Reblog this post [with Zemanta]

H&R Block Signs Exclusive w/Debit MasterCard



MasterCard has signed an agreement with H&R Block Bank, owned by H&R Block Inc., on a contract extension and five-year Debit MasterCard signature and PIN brand exclusivity. According to the conditions of the agreement H&R Block Bank will participate exclusively in the MasterCard network.

H&R Block Bank is the issuer of the H&R Block Emerald Prepaid MasterCard® that provides H&R Block’s retail tax clients with a convenient and secure access to tax refunds, payroll funds and other direct deposits. It has been declared that the H&R Block Bank has issued over 2.6 million cards last year and is planning to increase the number to 3 million this tax season. The cards are available mainly through the company’s network of 13,000 offices. Cardholders can reload cash to their cards at more than 40,000 retail locations across the country. Moreover, the card supports direct deposit of payroll funds.

H&R Block Inc. is the world’s preeminent tax services provider.
 Source: Company Press Release


Reblog this post [with Zemanta]

Wednesday, February 4, 2009

Say it Aite So

Aite Says It Isn't...

Aite debunks unbanked, underbanked myths

Boston, Feb. 4, 2009 -- A new report from Aite Group, LLC debunks 10 myths commonly held by bank executives, regulators and consumer advocates about unbanked and underbanked consumers. The analysis is based on a 400-person survey with consumers at check-cashing stores, completed in November and December of 2008.

Among the myths debunked by the report is the belief that consumers are unbanked or underbanked because of cultural and attitudinal reasons. Instead, it reveals that people are unbanked for very practical reasons, including credit, pricing, cash flow and service issues. Fifty-three percent of unbanked consumers in Aite Group's survey are impeded by credit issues, while an additional 28% face pricing issues with checking accounts, 12% are impeded by cash flow issues, and 7% constrained by service issues.

"Consumers that are underbanked and unbanked often choose to be so for practical reasons rather than attitudinal ones," says Gwenn Bézard, research director with Aite Group and co-author of this report. "Greater education and marketing wizardry is unlikely to succeed in attracting this group to checking account relationships. The only way for banks to seriously compete is to deliver a better product and value proposition."

This 29-page Impact Note contains 22 figures. Clients of Aite Group's Retail Banking service can download the report by clicking on the icon to the right. Related Aite Group Research:

* Nine for '09: Opportunities and Challenges for Banks in 2009
* Mobile Banking for the Underbanked: Lessons from Africa
* Competing in Money Transfers

To purchase this report or for additional information, please contact: Aite Group Sales Tel: +1.617.338.6050 sales@aitegroup.com

About Aite Group, LLC Aite Group is a leading independent research and advisory firm focused on business, technology and regulatory issues and their impact on the financial services industry. It was founded by leading industry experts in Banking and Securities & Investments. Aite Group brings together a team of business strategy, technology and regulatory experts to deliver comprehensive, timely and actionable advice to financial institutions and technology vendors. It seeks to become a true partner, advisor and catalyst by exchanging ideas with and challenging basic assumptions of its clients, ensuring that they always stay one step ahead of the competition.

Source: Company press release.

10th Annual Online Fraud Report

Online payment fraud trends, merchant practices and benchmarks
This year's study found that online merchants estimate they lose 1.4% of their revenue to fraud or $4 Billion in annual sales.  Read about this and over 25 other fraud management benchmarks, trends and practices. 
The 2009 edition of CyberSource's Online Fraud Report is based on an independent survey of hundreds of web merchants.  This annual industry report is essential for finance, risk and eCommerce professionals.
 Download your copy of the CyberSource Online Fraud Report 2009 Edition today!
Get Your Copy
Contents:
  • Detailed fraud metrics (fraud, chargebacks & order rejection)
  • Detection tools used/planned at each stage
  • Manual review rates, staff turnover and training time
  • Full process/metric maping
  • Budgets (overall and how allocated) 

Reblog this post [with Zemanta]

KPG Ventures Funds Nat'l Payment Card


I wrote about National Payment Card earlier this year. Why $4.00 a Gallon Gas is More Appealing to NPS.   Now comes word that they've raised $2 million for expansion, so apparently KPG Ventures found something very appealing about their decoupled debit program.  Here's the press release:

KPG Ventures Funds National Payment Card Association With $2 Million for Expansion Into Supermarket and Chain Drug Verticals

SAN FRANCISCO--(BUSINESS WIRE)--KPG Ventures—a venture capital firm specializing in seed-stage disruptive technology companies, today announced it has invested $2 million in National Payment Card Association, an emerging company responsible for creating a large scale, low cost debit settlement system benefiting consumers and merchants with lower transaction fees. KPG Ventures’ investment will propel National Payment Card Association’s growth beyond the fuel and convenience markets and into supermarkets and chain drug outlets.

National Payment Card Association’s technology is currently being deployed in fuel and convenience stores across the country, allowing consumers to save money and merchants an alternative to the large transaction processing fees charged by traditional transaction processors.

“National Payment Card Association’s product is an innovative, money-saving concept that has already met with a great deal of success,” said National Payment Card Association CEO and Founder Joe Randazza. “In these difficult times, the support and vote of confidence we have received from a specialized venture capital firm like KPG Ventures is validation of our model and technology, and well positions us for future growth.”

“KPG seeks investments that can scale and solve a highly defined consumer problem and found both of them in National Payment Card Association,” said Dave Hills, a General Partner of KPG Ventures. “Joe and the team have built a great product and we’re happy to support them.”

National Payment Card Association first introduced its alternative payment solution in June 2006 and has earned much attention from industry insiders and consumers. The National Payment Card Association PIN based payment system processes transactions through the Federal Reserve Automated Clearing House (ACH), resulting in lower merchant fees and a self-funded loyalty program that can provide immediate savings to consumers. Specifically, the program benefits retailers by helping them shift away from the interchange fees credit card companies normally charge on each transaction by moving them to the lower cost ACH system. The merchant can then use some of the savings to change customers’ payment behavior by passing some of that savings along to them right at the pump.

Founded in 2006, KPG Ventures is a San Francisco-based venture capital firm. KPG focuses on the consumer Internet sector of technology-driven businesses, investing at the seed-stage cycle of a company’s development. With a proven track record of picking the right companies and teams who are focused on highly capital efficient opportunities that require little capital to reach profitability, KPG has launched many successful companies. The firm concentrates its efforts on a small handful of companies at a time so that it can leverage the strategic and operating expertise of its general partners.

For more information about KPG Ventures, please visit kpgventures.com. For more information on National Payment Card Association, please visit nationalpaymentcard.com or contact Shep Doniger at 561-637-5750.



Reblog this post [with Zemanta]

ATM Skimming Card News Video

In light of the previous post, whereby I mentioned that I knew how they got the PIN, I've dug up a news report from Cincinnati, (WCPO...not WKRP) called ATM Scam Targets Debit and ATM Cards.

I've embedded the video report below for your convenience:





Reblog this post [with Zemanta]

More ($9 million) on the RBS Breach (Video)

Below you'll  find a fascinating story by John Deutzman with Fox NY regarding the recent RBS WorldPay breach.  Didn't hear of it?  That's probably because they issued their press release concerning the breach during the busy Christmas season, December 23rd. 

To read about what I thought about it then, visit "Mother of All Hacks Coming?  from December 24th.

This incident happened after midnight on November 8th.  Now...I know how they got the PINs, (here's a hint, you're on candid camera), so the most intriguing part of this story, at least in my opinion, is the fact that the hackers were able to lift the daily limits on the cards, providing a larger payday. That's the coup de' tat. 

The coordination and scope of this effort is also amazing even causing the FBI to make comments to that effect.  130 different ATM machines in 49 cities with 100 cards in 30 minutes. 

As the story goes, no suspects, only mule drivers, but I think Clive Owens is going to be the guy behind it when they do the movie.  Speaking of movies, watch the video on the right if you have the time.


Reported by John Deutzman


A Fox 5  investigation   exposes a  worldwide ATM  scam that  swindled $9  million and  possibly  jeopardized sensitive information from  people around  the world. Law enforcement sources  told Fox 5 it's   one of the most frightening  well-coordinated heists   they've ever seen. (Watch video report at right.) 

Photos from security video obtained by Fox 5 show of  a small piece of a huge scam that took place all in one  day in a matter of hours. According to the FBI,   ATMs from 49 cities were hit -- including Atlanta, Chicago, New York, Montreal, Moscow and Hong Kong.


"We've seen similar attempts to defraud a bank through ATM machines but not, not anywhere near the scale we have here," FBI Agent Ross Rice told Fox 5.

These people in the photos are believed to be "cashers," low-level players, in a scheme devised from some mastermind -- a dangerous computer hacker or hacking ring authorities fear could strike again. Here's how it all came down, according to information Fox obtained from the FBI and law enforcement sources:

The computer system for a company called RBS WorldPay was hacked. One service of the company is the ability for employers to pay employees with the money going directly to a card, called payroll cards, a lot like a debit card that can be used in any ATM. The hacker was able to infiltrate the supposedly secure system and steal the information necessary to duplicate or clone people's ATM cards.

"We've never seen one this well coordinated," the FBI said.

Then shortly after midnight Eastern Time on November 8, the FBI believes that dozens of the so-called cashers were used in a coordinated attack of ATM machines around the world. "Over 130 different ATM machines in 49 cities worldwide were accessed in a 30-minute period on November 8," Agents Rice said. "So you can get an idea of the number of people involved in this and the scope of the operation."

Here is the amazing part: With these cashers ready to do their dirty work around the world, the hacker somehow had the ability to lift those limits we all have on our ATM cards. For example, I'm only allowed to take out $500 a day, but the cashers were able to cash once, twice, three times over and over again.

When it was all over, they only used 100 cards but they ripped off $9 million.
The RBS Web site says that card holders will not be responsible for any unauthorized transactions. But there is fear that the hackers might have had access to sensitive information used in identity theft for a potential 1.5 million customers -- including their including Social Security numbers.

"The number of machines that were accessed, the number of cities that were targeted, and the number of people that had to be involved in this is quite significant," Agent Rice said.

Investigators are hoping a break in the case may come from one of the cashers. The theory is they probably were recruited, paid a small fee to be solders in the scam, and might be likely to rat out the people who hired them.

There are millions of people out there these days with these payroll cards. RBS officials say they have sent out letters to anyone who might have been affected. They are also offering one-year credit protection for people whose Social Security number may have been jeopardized by this scam. However, the good news is that it doesn't look like any identity theft has occurred yet.

So far, the FBI has no suspects and has made no arrests in this scam. An attorney in Atlanta has filed a class-action lawsuit against RBS WorldPay for allegedly failing to protect personal information.

RBS WorldPay told Fox 5 the company has hired a security firm to try to figure out what happened and to prevent it from happening again.

VIEW DOCUMENTS:

Disqus for ePayment News