Monday, January 19, 2009

Hackers Affect Debit and ATM Networks

TheTimesTribune.com, Corbin, KY - Hackers affect debit and ATM networks

Forcht Bank disabled 8,500 customer debit cards this week after learning they could have potentially been hacked into by persons creating duplicate cards.

Eddie Woodruff, chief operations officer for the bank, confirmed that 8,500 of the bank’s roughly 22,000 total debit cards had been deactivated, but the move was primarily a precaution.

“Right now, none of our customers have reported any fraudulent activity on the cards,” Woodruff said. “We’re just trying to take every precaution.”

The cards were comprised when a retail merchant’s computer system was hacked, Woodruff said. The breach affected customers of multiple banks and multiple debit and ATM networks.

“Our debit card processor, which is a company called STAR, they had a retail customer, we’re not exactly sure who the retail customer was, and the information we believe may have been compromised,” he said.

First Data Corporation, which operates the STAR Debit and ATM Network, would not comment on how many other banks were affected, but did release in a statement Monday that "the debit card issue we were alerted to could affect not only STAR but also other debit networks."

The STAR system is used by 2 million ATM and retail locations across the country, according to its Web site.

“While we do not comment on specific matters pertaining to our customers, we can tell you this situation is not related to any First Data processing systems or practices,” stated Nancy Etheredge, spokesperson for First Data. “We are working with our clients, the card associations and card issuing and acquiring banks to monitor and help mitigate the issue and protect consumers.”

Reblog this post [with Zemanta]

Money Transfer Network adds 33,000 locations


Minneapolis, Jan. 19, 2009 -- MoneyGram International (NYSE: MGI) today announced that in 2008 the company added 13 countries and territories and more than 33,000 locations to its global network, helping people and communities around the world by providing more convenient choices for safe and reliable money transfer services.

"Our continued growth--both international and domestic--is a reflection of growing consumer demand, fueled by ongoing global migration trends and our ability to deliver value to our customers and agents across the globe," said Tony Ryan, MoneyGram chief operating officer and executive vice president.

"MoneyGram's diverse, global agent network is our competitive advantage," said Ryan. "We will continue to invest in strategic growth by adding agent locations in key growth areas as well as expanding existing agent relationships, and growing our owned-retail presence."

In 2006, in response to business and market needs, MoneyGram launched its owned-retail strategy in France and Germany, and today operates more than 50 stores and kiosks in high-traffic areas in immigrant communities. Half of the countries joining MoneyGram's network last year are French-speaking, reflecting the company's commitment to serving the needs of France's large immigrant population. According to the World Bank, France is a top-five immigration country with 6.5 million immigrants.

"Our growth in France was vital to adding Algeria, which according to the World Bank, produced the largest influx of immigrants into the country," Ryan said. "Today, we have stronger prospects in the country for expansion through more traditional agent locations."

Germany is a similar success story for MoneyGram. The company established service to Serbia this year, which produces a high volume of immigrants to the country. MoneyGram has 30 owned locations strategically located in Germany.

"Network breeds network and feeds both expansions to new countries and increased locations in key areas around the globe," Ryan said. "The more we grow, the more interested retailers, post offices and financial institutions are in seeking our service to expand and grow their own businesses and offer more services to their customers."

Countries and territories added to MoneyGram's global network include the French-speaking Algeria, Central African Republic, Comoros, French Polynesia, Gabon, Madagascar and New Caledonia. Other countries include Angola, Bermuda, Bhutan, Czech Republic, Serbia, and Slovenia.

About MoneyGram International, Inc.

MoneyGram International, Inc. is a leading global payment services company. The company's major products and services include global money transfers, money orders and payment processing solutions for financial institutions and retail customers. MoneyGram is a New York Stock Exchange listed company with approximately 176,000 global money transfer agent locations in 180 countries and territories. For more information, visit the company's website at www.moneygram.com .

Source: Company press release.

Reblog this post [with Zemanta]

Dilllard's to Use "Planet Payment" Service


Edited Press Release

LONDON -(Dow Jones)- Planet Payment, a multi-currency and data processor, announced Monday that its Pay in Your Currency service, known in the industry as Dynamic Currency Conversion, is now being offered at Dillard's, a fashion apparel and home furnishings retailers in the United States.

The Pay in Your Currency service provides international shoppers paying for their purchases with Visa or MasterCard payment cards with the choice to pay in their home currency at the point of sale, rather than allowing their issuing bank to perform the conversion after the sale has been completed. The service provides greater clarity and certainty to international purchases by allowing the customer to pay in the currency that he or she knows best - their own.  
The service is being offered through Fifth Third Processing Solutions, (Cincinnati, Ohio) Dillard's current credit card acquirer.

(END) Dow Jones Newswires
01-19-09 0327ET
Copyright (c) 2009 Dow Jones & Company, Inc.

Reblog this post [with Zemanta]

Battle Against Card Fraud Heats Up

In an effort to reduce credit card fraud, HSBC announced it is going to analyze each and every transaction. This will result in both consumer frustration and inconvenience because a higher percentage of legitimate transactions will be declined.  In addition,  further inconveniences include the fact that consumers need to provide travel plans to banks, and banks are recommending the use  of cash and travelers checks  along with credit cards when traveling.   It certainly appears that convenience has taken a back seat to security and our so-called  "cashless society" has been put on hold a while.  This from the BBC over the weekend....

BBC NEWS | Business | Card fraud crackdown accelerated
Card fraud crackdown accelerated - Holiday makers are advised to take several different payment methods

A leading bank is introducing new technology which will mean that every credit card transaction will be scrutinized for fraud.  HSBC is introducing the program, which will affect 10 million card accounts and millions of transactions. The banking industry has warned that more legitimate transactions will be queried or canceled as a result.  Card fraud is rising - up 14% in the first half of 2008 - and fraud abroad now accounts for 40% of all card crime.

Travelers are being advised to take several different payment methods, including cash, credit cards and travellers' cheques when they go abroad. After several years of falling numbers, card fraud started rising again in 2007. Latest figures show that card fraud could have exceeded £600m in 2008, and banks are using increasingly sophisticated systems to try to outwit fraudsters.

HSBC previously checked 25% of card transactions but is currently rolling out a system that means all card transactions will be screened in real time, with a decision made in a fraction of a second.  Bart Patrick of SAS UK, which is providing the software system for HSBC, said: "When you put your card in the machine it's carrying out an automatic check against your pattern of normal use - and making a decision about whether that is real or fraudulent."

He said banks were constantly battling with fraudsters to reduce the levels of crime. "Card fraud is an arms race. The banks will come up with one way of dealing with it, the fraudsters will come up with a way round it."

"What we have seen with chip and pin - it was successful for 18 months, two years - the fraudsters have worked a way round it, so we are now looking at more sophisticated means."

However as the banks become more proactive in targeting fraudsters, more people could find their legitimate transactions are declined or queried.  When Sally Wiber went on holiday to Borneo, she followed industry advice and told her bank where she was going.  (See: Wanna Get Away?)

But her credit and debit cards were blocked when she tried to use them on her first day. "I spent much of the first day trying to deal with my bank and getting internet access, and then had a rather frustrating phone call trying to make sure that I could use my cards for the rest of my holiday," she said.

Continue Reading at BBC   Watch Video at BBC


Reblog this post [with Zemanta]

Skimmer "Sentenced in Seattle"

Skimmer Now Jail Bird
The owner of a Redmond, WA tobacco shop was sentenced to less than three years in prison for skimming $300,000 off more than 300 credit cards. That's a little harsher than $200 bucks and get outta town" (see Saturday's post) but not as harsh of a sentence as the same crime will see in the future.

Here's the U.S. Attorney's Office news release:

HRANT "MIKE" ASLANYAN, 38, of Redmond, Washington, was sentenced today in U.S. District Court in Seattle to 33 months in prison, five years of supervised release and over $214,000 in restitution for Bank Fraud. ASLANYAN, the owner of a small tobacco and convenience store, pleaded guilty on June 13, 2008, admitting that he skimmed the debit and credit card numbers of more than 300 of his store customers. Those stolen numbers were used to steal money or incur credit from seventeen different banks. At sentencing U.S. District Judge Ricardo S. Martinez said, "This type of crime victimizes totally innocent people who are just going about their daily business." Judge Martinez ordered ASLANYAN taken into custody immediately to begin serving his sentence.


According to the Seattle Times Police Blotter: In late 2004 though early 2006, law enforcement investigated a rash of reports of compromised credit and debit cards. Dozens of people had their credit and debit cards used, without their permission, to withdraw money in the Las Vegas, Nevada and Los Angeles, California areas. Some seventeen financial institutions were hit for about $300,000. Some 300 Redmond area accounts were accessed. (Editor's Note:
Just think how much more he could've made if Bill Gates was a smoker!)

The place where each of the victims had used their credit or debit card, was "Smokers Choice" a small tobacco and convenience store in Redmond. Thirty-five of the victims specifically identified ASLANYAN as the person who had run their credit or debit card. The skimmer that records credit or debit card information was never recovered.

ASLANYAN has refused to assist law enforcement by identifying his co-conspirators who used the information to incur credit charges or raid victim bank accounts.


In asking for 33 months of imprisonment, Assistant United States Attorney Vince Lombardi argued that the victims go beyond the banks that lost money, to the people whose accounts were violated. "It is difficult to overstate the feeling of victimization felt by individuals who find their identity and account information stolen, merely because they chose to entrust Defendant with their debit or credit card when buying cigarettes or other items... Identity theft and related fraud crimes have been an epidemic in this judicial district ... this particular crime impacted hundreds of individuals," Mr. Lombardi wrote in his sentencing memo.

The case was investigated by the U.S. Secret Service, the Redmond Police Department, the Bellevue Police Department, and the Duvall Police Department.


Comment: 


January 17, 2009 at 9:43 AM

$300,000 stolen, yet only $214,000 restitution ... how come not the whole $300,000 ?.. only 33 months in prison?? must have been some pretty heavy plea bargening going on here.. this sleeze should be made to pay back the WHOLE thing and do at least 10 years.. especially since he refused to co-operate with the investigators in naming his partners.. something here has gotta change in our "justice" system...

tsgt - ephrata,WA



Reblog this post [with Zemanta]

Final Results for Cyber Holiday Pulse Index



The Pulse Index
is an annual tracking of online shopping activity during the holiday season. From November through January, Chase Paymentech monitors the daily activity of 25 of the largest 150 Internet retailers. The data includes the total number of payment transactions and total dollar value processed. The data is taken from transactions crossing Chase Paymentech's global processing platform.


Final Results for Cyber Holiday Pulse Index


"The Pulse Index was remarkable this year," said Mia Shernoff, marketing executive for Chase Paymentech. "Because it tracks actual transactions on a daily basis for such a large number of major e-commerce merchants, the Index provided unique insight into the behavior of online shoppers and how the economic climate affected their buying patterns."

Online Holiday Shopping 2008 - A Mixed Bag

For the 2008 holiday shopping season, the Pulse Index results represent online purchases beginning on November 1, running through December 31. While sales volume and transaction count both show an increase, the average ticket, or amount per sale, declined.

The statistics indicated:

  • Sales volume for the holiday season was up a modest 4.5 percent versus 2007.
  • Transaction count was up a significant 16.5 percent.
  • Average value per transaction was down an unanticipated 10.3 percent.

According to Forrester Research Principal Analyst Sucharita Mulpuru, the mixed e-commerce news highlights the environment faced by retailers this year. "This holiday season challenged all retailers," she said. "Web transaction volume was up significantly from last year, but the relatively lower revenue numbers point to aggressive discounting by retailers and eager deal-hunting by shoppers."

The tough shopping season, however, was an opportunity for some e-commerce merchants. Said Mulpuru, "A few branded retailers with very favorable pricing strategies were able to take advantage of the holiday season's circumstances and increase their market share. There should be a shakeout of Web retailers, but that will leave the remaining players more favorably positioned for growth into 2010 and beyond."

Additional highlights of the 2008 Pulse Index included:

  • The peak shopping season (the period between Thanksgiving and Christmas) sales were down 4.5 percent, but transaction volume was actually up 5.2 percent - this despite five fewer shopping days during this period versus 2007.
  • The largest day for transactions was Tuesday, December 16, with 3.96 million transactions. This was only slightly higher than Wednesday, Dec 17, which saw 3.95 million transactions.
  • The largest day for sales was Tuesday, December 2, with more than $218 million, topping Wednesday, December 17, which saw more than $217 million.

Said Aaron Press, director of market research for Chase Paymentech, "The practical lesson we took from this year's Pulse Index is that all of the hype surrounding Cyber Monday, is just that: hype. Merchants looking to capture additional sales or attract new customers should consider focusing their discounts and promotions on the middle of the week. Tuesday through Thursday is the peak shopping time for online consumers."


Mia Shernoff concluded, "There is a lot of value in being able to see the information and trends reflected in an index representing actual transactions among e-commerce merchants. It helps companies with everything from allocating resources to scheduling promotions during a crucial time."

Data and charts are updated daily, with weekly commentary to explain any trends, offer historical insight and provide context. Guest commentary will be provided by Sucharita Mulpuru from Forrrester and Aaron Press, Director of Market Analysis for Chase Paymentech. Visit the Pulse Index every business day at 2:00 P.M. EST to see the daily numbers, or subscribe to our weekly commentary via RSS. Media inquiries should be directed to James Wester, Director of Corporate Communications for Chase Paymentech at 877.843.5631  www.chasepaymentech.com 

Source: Presss Release



Reblog this post [with Zemanta]

Saturday, January 17, 2009

Circuit City Shorts Out



Hope you used your gift cards...

Back on November 11th, in a post I called "Short Circuit in Gift Cards?" I stated:
 
"If You've got a Circuit City Gift Card, Use it Now!

...Circuit City tried to reassure shoppers that it would be business as usual despite its Chapter 11 bankruptcy filing.  I wouldn't be the least bit surprised, if  and when the Circuit City gift cards do indeed short-circuit, to see the gift card landscape vastly affected forever.  There  needs to be either new regulation introduced or someone will have to come up with an improved program... otherwise consumers will shy away, from, especially the "closed loop" gift cards.

So if you have a Circuit City gift card use it immediately..."

Hope you did, because yesterday Circuit City announced they are "shuttering" all 567 stores. If you haven't used them, there's no rush...you can shop at CircuitCity.com through tomorrow. (January 18th)  Store liquidations begin as early as today and last until...?

According to the Chicago Tribune, "The sooner consumers use their gift cards, the better. Circuit City's group of liquidators have agreed to honor gift cards for at least the first few weeks. Deadlines for gift card use are expected to be posted in stores within the next couple of days."

"We are extremely disappointed by this outcome,” said James A. Marcum, acting president and chief executive of Circuit City Stores. He called the liquidation “the only possible path” for the 60-year-old company."

The NY Times writes: "The demise of Circuit City, while not surprising given its declining sales, is part of a radical shift (Editor's Note:  call it  "radical" but I say "paradigm") taking place in retailing. Weak chains — unable to weather the freeze-up in consumer spending and choked by tight credit markets — are closing.

Look for that "Amazon Thanksgiving Day Parade" by 2011, eh?


PIN Debit Payments Blog





Reblog this post [with Zemanta]

$200 Bucks and Get Outta Town

Hmmm, I always thought that age-old line was "Don't do the crime if you can't do the time."  Apparently that's not true in West Vancouver. 

"Don't Refrain if You Can Gain" seems to be more applicable..

$200 bucks?  Heck, go 72 mph in a 65 zone here and you'll be penalized more than that...

Here's a story from CTV British Columbia where they tell the tale of a PIN Pad thief who got fined $200 bucks and has to leave town by "high noon."   Unbelievable.  I've reproduced the comments from their site, and as you can read, people are getting fed up with these types of crimes.  As I've posted in the past...why rob a bank?  That's 20 years...this is $200 bucks.  If he didn't get caught "red-handed" what would his take be?  IMHO, the judge got this one "way wrong."  At least the message he's sending is...

Here's the story: CTV British Columbia- PIN pad thief gets $200 fine and deportation order - CTV News, Shows and Sports -- Canadian Television

PIN pad thief gets $200 fine and deportation order
Updated: Fri Jan. 16 2009 18:32:54  Darcy Wintonyk, ctvbc.ca

Police in West Vancouver have caught a PIN pad thief red-handed -- and kicked him out of the province.  On Tuesday night, the owner of a Park Royal area juice bar called police after someone stole the PIN pad from the counter. He had just serving two customers and noticed that the device was missing.

Editor's Note:  Notice the pic of the PIN Pad (below right)  with a steel tether to prevent it from getting stolen...

Police apprehended the men shortly after near Marine Dr. and 14th St. after being alerted by a transit operator. After a brief investigation, police recovered the pad from a rental car parked nearby. On Thursday, 23-year-old Quebec native Jonathan Ramirez-Dionne pled guilty to theft under $5,000 in a North Vancouver courtroom.

"
He was sentenced to one year probation and a $200 fine," says Const. Jeff Palmer.

But that's not all. The judge has also given the unusual order for him to leave the area. "An interesting aspect of his probationary requirement the judge has ordered him to leave British Columbia by four o'clock Friday afternoon and he's not to be found in British Columbia during the term of his probation."

The owner of the juice bar doesn't think the penalty is heavy enough.  "It's funny because if I was caught speeding, it would be a bigger fine, and you know it's less of a heinous crime per say, and they get $200 which is a little bit bizarre," says Blake Goddard.

Police advise merchants to securely attach pin pads to counters at and to train staff to regularly check the devices.  This isn't the first time Park Royal mall has been hit by debit thieves.  Last March, police warned customers to change their PIN numbers after two La Senza's and an Aldo store had their PIN pads stolen.
PIN pads don't normally record PIN numbers, but the devices can be modified to take in personal information.  In August 2007, phony PIN pads turned up at four retail stores, including and thieves used the stolen information to withdraw money from hundreds of accounts.

Please Add Comments(7)
Don
I like that the judge told him to get out of BC. I think 200 dollars is pretty light as a fine for this type of crime though.

Pat in the Valley
What kind of justice is this - first he breaks the law, can steal potentially mega bucks and all he gets is the boot from the Province. When will the Justice System finally get it? and hand out appropriate sentencing and not just another "slap on the wrist".

Christine
That is ridiculous! $200 fine, what a joke! How will we know that the guy is actually leaving the Province and who is going to keep track of him?

Ashley
What a joke that is! Apparently in BC and in Canada it pays to lead a life of crime. Wasn't too impressed to be watching this story on the 6pm news on CTV and watched the report show the viewers exactally how to remove it. I know its not rocket science but come on..

C
Umm... I agree with your statement "PIN pads don't normally record PIN numbers, but the devices can be modified to take in personal information." but your on-air story is misleading viewers that PIN pads ARE storing information when they DO NOT.  Only counterfeit PIN pads store/steal information.

Aden
Thats awsome thats what you get when you steal from our province Au revouir frenchy

Bangedup
what a joke - time to change the laws


Reblog this post [with Zemanta]

Friday, January 16, 2009

Largest Drop in Card Balance Payments Ever

According to CardTrak.com credit card balance payments saw their largest drop ever, from October to November.  (Guess December's data hasn't arrived yet...)

CardTrak.com - News - Wallet Squeeze
The amount that consumers pay on their monthly credit card balances dropped like a rock in November to a record low. Generally cardholders, including those who pay the minimum due and those who pay the full balance off each month, pay on average, about 18% to 20% of their monthly outstanding balances.

During October cardholders paid 18.42% of their balances which collapsed to 15.96% in November,
Clearly, the credit squeeze that began in mid-Septembertrickled down much faster than expected. The impact of job losses cannot be understated. In December, the number of unemployed persons increasedby 632,000 to 11.1 million and the unemployment rate rose to 7.2%. Since the start of the recession in December 2007, the number of unemployedpersons has grown by 3.6 million, and the unemployment rate has risen by2.3 percentage points.

PAYMENTS
June 08:     19.54%
July 08:       19.54%
August 08:  19.21%
Sept. 08:     18.57%
Oct 08         18.42%
Nov 08:       15.96%


Source: CardWeb.com
 Related articles by Zemanta
Reblog this post [with Zemanta]

People Spending More (Time) on the Web


eMarketer reports that the recession may be contributing to increasing usage of the Internet among leisure time activities. 

Of course, by the same token, one could argue that the recession, which has cause many job losses, could "reduce" the percentage of "leisure time" spent online, as people would be an additional 10 hours per day of leisure.

That would equivocate to needing to spend an additional 3 hours per working day (15 hours per week) online in order to retain the 30% level that US Internet users are now at.   When looking at the chart on the right, I'd be interested in hearing theories behind the 72% spike in usage from 2006 to 2007. 


Internet Users Spending Even More Time on Web - eMarketer
(click to read entire story)

"According to eMarketer, US adults are not world leaders in spending leisure time online. That distinction goes to Internet users in China, who spent 44% of their leisure  time on the Internet in 2008, according to TNS Global. The company found that Americans ranked fifth worldwide, at 30% of leisure time spent online virtually tied with Italy (31%), Spain and Australia (29% each)."  (Click Graph on Left, To Enlarge)

In a related article, from "The Guardian" in the U.K states:

The study also found that many activities which we traditionally did in our spare time are now being done online. Three-quarters of Britons have used the internet for banking in the past month and two-thirds have also paid bills online. Seventy-five per cent of British respondents had read news online in the past month, while 62% had checked the weather. More Britons (55%) had watched a video clip on sites like YouTube than had listened to audio (44%) or participated in an online auction (39%). Social networking sites had been visited by 37% of people, while 32% had downloaded music.

Seven per cent of Britons called themselves bloggers, with 16% saying they had "viewed or contributed" to a blog, compared with 88% of Chinese respondents.

The poll of more than 27,500 people in 16 countries found that housewives in the UK spend 47% of their leisure time on the web, compared with 39% for students and 32% for the unemployed. Globally, the average across all occupations was 29%.

Of the 16 nationalities surveyed, Scandinavians seemed the least inclined to while away their free time in front of the computer - Danes spent an average of 15% of their non-work hours on the net, with Swedes at 18% and Norwegians at 22%.

Arno Hummerston, managing director of TNS Global Interactive, said: "If our leisure time is so precious, then why do we on average spend almost a third of it using the internet? We believe it is because we are making more efficient use of our valuable time, specifically by using the internet - thereby allowing us to fit more into our lives...





Reblog this post [with Zemanta]

Gaza Cease Fire Trojan Shows No Sites Are Safe From Attack


On Monday, in a post entitled "Gaza Strip(s) PC of Financial Data" I talked about a new(s) attack. "Using mainstream news headlines regarding recent events in Gaza, it lures people to a site that appears to be CNN.   The bad news is, it isn't CNN...it's a clone, and there is nothing which clearly indicates that you've been duped."  It then downloads a trojan which sweeps your hard drive looking for data relating to financial institutions.

In a post, earlier this month, (E-Commerce and Browsers Don't Mix)  I talked about browser weaknesses.  With the emergence of these two "new attacks" (the other one being "in-session phishing"...see "Phishing 2.0 - PAN Fried,  not even 15 days into the New Year, it's becoming clearer that financial transactions  need to be done outside the browser space.

Last night, I noticed that Gartner's Avivah Litan did an analysis on the Gaza Cease-Fire Trojan.  Based on the title  of her post, (and her bullet point, both of which I outlined in yellow) it's safe to assume that she feels along the same lines as we do, regarding the weaknesses inherent in web browsers. 

Here's her analysis...
 
 


Avivah Litan
VP Distinguished Analyst
Potomac, MD USA
 
Avivah Litan is a Vice President and Distinguished Analyst in Gartner Research. Her area of expertise includes financial fraud, authentication, identity theft, fraud detection and prevention applications and other areas of information security and risk. She also covers payment systems and financial flows in the business-to-consumer and business-to-business markets.

A new trojan attack shows that seemingly "safe" Web sites can be used in financially targeted attacks. Enterprises need to take a layered approach to these attack vectors, which mostly lie outside their control.

Event 
On 7 January 2009, the RSA FraudAction Research Lab discovered a trojan attack, identified as the Cease-Fire Trojan Attack, that used phishing e-mail supposedly offering Al Jazeera video on CNN of the war in Gaza to divert recipients to an imposter news Web site. Recipients who clicked on a "video" link were told they need to update their media players to run the video. When they tried to do so, a "Secure Sockets Layer (SSL) stealer" trojan was downloaded to their desktops.

"The trojan resides in the end user's Web browser, waking up when SSL encryption is invoked via the HTTPS protocol typically used for online financial transactions such as payments and banking. The trojan then tracks the user's keystrokes to steal transaction information."


RSA reports that it shut down the attack, which was staged at a registrar in China, and that it discovered and took down a second wave of attacks — staged on five other domains on 9 January — within four hours. 

Analysis
 

Trojans delivered via phishing attacks are certainly not a new phenomenon, and security providers report that the frequency of these attacks is increasing rapidly. This particular attack is significant because it offers a clear demonstration of:
  • A comparatively new type of combined phishing/trojan attack that uses social engineering to prey on sympathies and interests (in this case, promising graphic images of war)
  • An attack using brands (for example, those of news organizations) that attackers rightly believe are less likely to be the targets of phishing attacks than financial service providers and therefore less likely to take proactive action against them
  • Criminals' ability to place programs inside browsers, making it possible to bypass the security protections offered by SSL encryption and by strong authentication techniques going through a user's browser
It is important to note that RSA shut down this attack as a public service, and that there is no guarantee that security providers will perform such services in the future. Enterprises must take action to protect themselves and their customers, clients, partners and other stakeholders against attacks of this type.

Recommendations


Enterprises that store customer information, financial accounts, transaction information or other sensitive data:
  • Recognize that customer account credentials can be compromised and that many criminal attack vectors are outside your domain and your control.
  • Deploy a layered security strategy that includes fraud detection, stronger user authentication and out-of-band transaction verification for high-risk transactions.
  • Deploy browser-based "on demand" desktop security services to your customers, because these can, when used in conjunction with better local browser rules and recognition of high- assurance certificates, help to protect customers accessing your Web sites.

Internet infrastructure and security providers:
  • Consider pooling your resources and launching a joint phishing/malware detection and site-takedown service that can be offered on a pro bono or as-needed basis. This approach would make it possible to quickly block attacks against real or fictitious brands that are detected in the course of normal "cybersurveillance" services, even if no specific financial incentive to do so exists.





Reblog this post [with Zemanta]

Thursday, January 15, 2009

MC Discounts Charges "Interchange is Way Too High"

In an attempt to dispel myths regarding Interchange, MasterCard has put together a brochure (PDF) designed to show how priceless Interchange is. 

They have also created several documents trying to "discount" charges that interchange is too high.
 

It all makes for some interesting reading.  Below I have included links from their website, followed by their press release.



From MasterCard.com

Every business establishes a price for the goods and services it provides, and the electronic payments business is no exception. As one element of the cost of acceptance, interchange is a small fee in relation to the enormous value merchants receive for accepting MasterCard payment cards.

For almost 40 years, MasterCard has established default interchange fees that have proven to be the most efficient way to balance costs in the system and promote a strong, competitive payments industry that benefits cardholders, merchants and financial institutions. Today, some 25,000 financial institutions provide the cards and services that allow hundreds of millions of consumers and 25 million merchants around the world to benefit from the convenience and security of electronic payments.

Learn more about interchange from the information below:





MasterCard dispels myths, highlights benefits of payment networks


Purchase, N.Y., Jan 15, 2009 -- In light of the ongoing discussion and debate about the role of credit in today's economic environment, MasterCard Worldwide has issued a paper that dispels misperceptions (Editor's Note: shouldn't it be "misconceptions" or am I "misperceiving" this?) about payment systems and explains the tremendous economic value that electronic payments bring to the economy as a whole and their role in advancing commerce.

The paper, entitled "Benefits of Open Payment Systems and the Role of Interchange," underscores the enormous benefits delivered by electronic payments, which have become so ingrained in everyday life they are often taken for granted or misunderstood. Few people ever stop to consider the complex and sophisticated system that allows transactions to occur within seconds, almost anywhere in the world.

"Perhaps the easiest way to grasp the value of electronic payments is to envision a world without them. Clearly, if electronic payments came to a sudden halt, many facets of commerce - travel, trade and the Internet just to name a few - would face dire consequences," MasterCard President and CEO Robert W. Selander says in the introduction.

The paper also discusses the role of interchange - a relatively small fee paid for the benefits merchants get from card acceptance. Interchange is critical to ensuring the system provides maximum benefits to all participants, including consumers and merchants in a fiercely competitive marketplace.

MasterCard has created this brochure as a resource for all those interested in the payments industry. To access the paper, please visit, http://www.mastercard.com/us/company/en/ourcompany/interchange.html .

About MasterCard Worldwide

MasterCard Worldwide advances global commerce by providing a critical economic link among financial institutions, businesses, cardholders and merchants worldwide. As a franchisor, processor and advisor, MasterCard develops and markets payment solutions, processes over 18 billion transactions each year, and provides industry-leading analysis and consulting services to financial institution customers and merchants. Through its family of brands, including MasterCard®, Maestro® and Cirrus®, MasterCard serves consumers and businesses in more than 210 countries and territories. For more information go to www.mastercard.com .

Source: Company press release

Reblog this post [with Zemanta]

Google Checkout "Searches" for Way to Increase Adoption

Google Checkout adoption is dropping.  Maybe they ought to start "searching" for ways to increase market share.  Maybe a globally patented PIN debit application from HomeATM would help...

The adoption of Google Checkout by online retailers is stalling, according to a study by interactive agency Rosetta.


The report states that 37% of 100 leading online retailers surveyed currently offer alternative payment methods, a 23% increase since November 2007.

Of those, Bill Me Later is most popular at 26%, with PayPal now nearly tied at 25%. Google Checkout showed a tiny increase from 10% in 2007 to 11%. Only 7% of the retailers examined offer all three methods.

“Even though it boasts high consumer confidence, Google Checkout is struggling in retailer adoption,” said Adam Cohen, a partner at Rosetta's consumer goods and retail practice, which conducted the study last month. “Adoption of the service started out very strong last year, but has stagnated in the last 12 months."


The discontinuation of incentives for retailers during the holiday season is likely to negatively impact Google Checkout adoption on an ongoing basis, he said.

Reblog this post [with Zemanta]

How Cards Are Processed

CreditCards.com has provided an interactive guide to show how merchants and banks process cards purchases.  For the interactive guide click here, (or the graphic on the left)
For a printable  version, click the PDF link at the bottom of this post.
How credit card transactions work
Interactive guide shows how merchants, banks process card purchases

By Tyler Metzger - CreditCards.com

More than 23 billion credit cards transactions were processed in the United States in 2007, and they are projected to grow by 26 percent over the next five years, according to the Nilson Report. But have you ever wondered what exactly happens after your card is swiped?

Use this guide to to find out how your credit card transactions are processed.  PDF

"Underground Economy Booming" - Followup

Symantec Report on the Underground Economy

On November 24th, I posted about Symantec's release of a detailed report called the "Internet Security Threat Report."  That report is now available to anyone who wishes to download the whitepaper.

This from their website.  For your convenience, I have included links to more detailed information.  Click any of the graphics to enlarge.

The Symantec Report on the Underground Economy examines activity on underground economy servers observed by Symantec between July 1st, 2007 and June 30th, 2008. It includes analysis and discussion of the goods and services advertised, advertisers participating in the economy, the servers and channels that host the trading, and a snapshot of piracy activity observed.

As I previously stated, this report, is now available to the general public for free download.

Symantec Report on the Underground Economy
Executive Summary: Symantec Report on the Underground Economy:

Symantec Weblog: Postings on the Underground Economy Learn more

Report Highlights


"The underground economy has matured into a global market with the same supply and demand pressures and responses of any other economy. There are a great many servers and channels available to advertisers to market their wares, which they do, and often. Most people associate identity theft with money because most reported cases involve criminals using the identity for activities such as obtaining credit cards, applying for loans, obtaining expensive medical or pharmaceutical treatments, or even stealing house titles. Symantec estimates the value of total advertised goods on underground economy servers was over $276 million between July 1, 2007 and June 30, 2008.

During the reporting period, Symantec monitored 44,752 unique samples of sensitive information publicly posted on underground economy servers, which accounted for 10 percent of the total distinct messages. Sellers often publicly post samples of their goods in the channels on underground economy servers. These samples serve several purposes: to prove that sellers actually have the goods in their possession; to show potential buyers the quality of goods they can expect; to enhance their credibility, and; to allow users to validate the information. The table (above left) identities the top samples of information posted:

Credit card information may rank high because there are many ways it can be obtained and used for fraud. This includes phishing schemes, monitoring merchant card authorizations, the use of magnetic stripe skimming devices, or breaking into databases and other data breaches that expose sensitive information.

Another explanation may simply be that there is a high frequency use of credit cards.

For example, the 22 billion credit card transactions in the United States in 2006 represent a growth of eight percent over the previous year.  High frequency use and the range of available methods for capturing credit card data would generate more opportunities for theft and compromise and, thus, lead to an increased supply on underground economy servers.

Credit card information may be in such demand because using fraudulent credit card data for activities such as making online purchases is relatively easy. Online shopping can be easy and fast, and a final sale often requires just credit card information. Someone knowledgeable enough could potentially make many transactions with a stolen card before the suspicious activity is detected and the card is suspended.

The second most common category of goods and services advertised was financial accounts, with 20 percent of the total. This category includes bank account credentials, magnetic stripe skimming devices, online payment services, online currency accounts, and online stock trading accounts. This category ranked third for advertised requests, with 18 percent of the total. By far the major contributor to the popularity of the financial accounts category was bank account credentials, which accounted for 18 percent of all goods and services advertised for sale.

Financial accounts are attractive targets because of the opportunity to withdraw currency directly.  Although this may involve more steps than using stolen credit card data to make online purchases, the process of cashing out financial accounts can be easier than retrieving cash from credit cards because  criminals would require a PIN for the card. Also, most ATMs have security cameras, which may deter criminals from using this medium. In addition, withdrawing currency from a bank account has the advantage of a more immediate financial reward than with online purchases, which would need to be sold to realize a purely financial reward.

Credit card information includes credit card numbers, credit cards with CVV2, and credit card dumps; financial accounts includes bank account numbers, magnetic stripe skimming devices, online payment services, online currency accounts, and online stock accounts; spam and phishing information includes email addresses, email passwords, scams, and mailers; withdrawal services include cash outs and drops that are used to withdraw money and items from purchases; identity theft includes full identities and Social Security numbers; server accounts are for file transfers and virtual networks; compromised computers includes hacked computers, bot-infected computers, and shells; website accounts include online accounts for access to specific websites such as social networking sites; malicious tools includes
Web-based attack tools and malicious code; and retail accounts includes gift cards for online stores and online auction accounts.

Magnetic stripe skimming devices are small machines designed to scan and retain data contained in the magnetic stripes on credit and debit cards.  To cash out bank accounts, individuals can either use a reliable cashier or can assume the identity of the bank account owner to withdraw funds. Since many bank accounts can only be cashed out from within the issuing country, criminals may prefer the use of cashiers that specialize in extracting currency from these accounts. Such cashiers use a variety of methods to convert the information into true currency, transferring money either through wire transfers or to online currency exchange accounts. They can also hire an intermediary to receive the transfer in person using a fake identity. Symantec observed requests on underground economy servers for cashiers in specific locations and of a particular gender (as matching
the cashier’s gender to the identity of the bank account holder is essential to not raise suspicion when withdrawing funds).





Reblog this post [with Zemanta]

Financial Institution Breaches Up 47%


US financial institutions were hit by 78 reported data breaches last year, a 47% increase and now own a 70% larger piece of the pie. 

Reported data breaches in the US during 2008 were up 47% on the previous year, to 656, of which 78 affected financial institutions, according to a study from the Identity Theft Resource Center (ITRC).

Financial services accounted for 78 breaches, which is 11.9% of the total.  Whereas last  year, Financial services accounted for 7% of the total in 2007 it's 11.9% total this year represents a 70% bigger piece of the pie than they had last year.

According to Finextra
, ...

"The ITRC says at least 35.7 million records were potentially breached but the true figure is likely to be far higher because 41.9% of cases went unreported or undisclosed.

Financial services accounted for over 18.1 million compromised records, 52.5% of the total.


This is largely down to the biggest single breach last year, which saw BNY Mellon Shareowner Services losing around 12.5 million records - including social security numbers, names and addresses - when a box containing unencrypted customer data tapes went missing in transit in February.

In addition, RBS WorldPay was hit by a breach affecting 1.5 million records and Countrywide had two million compromised last year.

Most of the financial sector breaches were the result of hacking, followed by insider theft. Of all breaches across all sectors, 3.5% are attributable to hacking at financial firms, 2.4% to insider theft, 1.7% to data on the move, 0.8% to accidental exposure and 0.8% to subcontractors.

Electronic breaches account for 82.3% of the total, compared to 17.7% for paper. Despite this, just 2.4% of all breaches had encryption or other strong security methods in use and only 8.5% even had password protection." - Finextra

For those interested, I have included links to the following 2008 Year End Reports from the ITRC website:


Reblog this post [with Zemanta]

Hacker Thai'd to TJX Breach Arrested

M'sian nabbed in Bangkok over US$150m credit card fraud
BANGKOK: A Malaysian man wanted in the United States for credit card fraud amounting to US$150mil (RM540mil) was arrested by Thai authorities and US Secret Service agents in Nonthaburi on the outskirts of Bangkok on Tuesday. Local media reported that the 43-year-old man had a warrant of arrest issued for him by a US court for illegal possession of data access device, hacking into computers and stealing data.

Crime Suppression Division police chief Supisal Pakdinaruenar said the man was a prominent member of a credit card fraud gang operating in the United States for the past three years and was believed to have fled to Thailand to evade arrest. He was arrested in a house in the Pak Kret district where he was staying with his Thai wife.

The group is believed to be involved in stealing credit card transaction data from people patronizing major restaurants and retail outlets like TJX, WalMart and Office Depot, and selling the information to other groups making counterfeit cards.

According to Supisai, the man had denied all the charges and was currently facing extradition to the United States. - Bernama
Reblog this post [with Zemanta]

Disqus for ePayment News