Saturday, June 6, 2009

List of Latest Phishing Attacks and How to Stop the Threat

Here's a compilation of the latest phishing attacks designed to "lure" online banking customers into providing their username and password to fraudsters. 

Of course, if banks would stop using username and password log-in, and graduate to a more secure, two factor authentication...one that requires users to swipe their bank issued card, and enter their bank issued PIN, (replicate what they do at an ATM machine) then they would, at the same time,  eliminate phishing altogether. 

With HomeATM's PCI 2.0 Certified Terminal and PIN Entry Device, Internet banking has never been more secure.

Banks can enhance their users onlineexperience and security with strong two-factor authentication per theFFIEC directive, guard against many forms of cyber attacks and malwareand reinforce the financial institutions’ brand. 

In addition, our terminal eliminates the threat of cloned cards, the threat of DNS Hijacking, the threat of cloned websites and "enables" online banking customers to securely transfer money, whether it be account to account (A2A) person-to-person (P2P), pay bills, and securely transact online. 

The 2 best reasons (besides E2E Encryption, 2FA and PCI 2.0 Certification) 2 choose HomeATM are:

1. There is no other authentication device on the market with a PCI 2.0 Certified PIN Entry Device (PED).
2. HomeATM's terminal, manufactured by HomeATM, "WITH a built-in PED" costs significantly less than competitors (i.e. Magento) who offer their product  "WITHOUT a PED."


For a limited time, you can get 2 of ours for the price of 1 Magenta.  For more information, please email us.




Here's the list of the latest phishing attacks, compiled by MillersMiles.com



Alliance and Leicester
6th June 2009
Alliance-Leicester Group

Wells Fargo6th June 2009
Notification of Account Suspension

Halifax Bank6th June 2009
Information - Access Suspended

Abbey6th June 2009
Please Update Your Account

Cahoot6th June 2009
Important Message:-

Aol6th June 2009
Dear valued Aol ® member

Abbey Bank5th June 2009
Overdraft Application Received

PayPal5th June 2009
Update Your Paypal Account!

Cahoot Bank5th June 2009
Payment Notification Update(customers Verification Required)

Halifax5th June 2009
Halifax Online Banking - Your contact details these have now been updated

Commonwealth Bank of Australia5th June 2009
Online Alert

Abbey Bank5th June 2009
Your online banking security.

Abbey4th June 2009
You have 1 unread message

Egg Bank4th June 2009
Protect Your Online Banking.

Abbey4th June 2009
IMPORTANT MESSAGE

Commonwealth Bank4th June 2009
Notification from Commonwealth Bank

Cahoot4th June 2009
Protect Your Privacy:1 New Message

Cahoot4th June 2009
Account Suspended

Cahoot3rd June 2009
Cahoot Online Security Service

Alliance and Leicester Bank3rd June 2009
Important Message: Your Account Has Been Temporarily Block

National Savings and Investmen3rd June 2009
Important: Your NSI Savings Account is Limited!!

Oregon Community Credit Union3rd June 2009
Personal Information Error!

Abbey Bank3rd June 2009
Abbey Instant Access Saver { Secure Your Account Access }






Reblog this post [with Zemanta]

Friday, June 5, 2009

Credit Card Fair Fee Act Introduced by House

 
Updated: D-Day for Visa/MC?



Legislationseeking to tighten rules on so-called "interchange fees" levied bycredit card companies could hurt transaction processors like TotalSystem Services Inc. and First Data Corp. if it becomes law, a MorganKeegan & Co. analyst said in a research note Friday.

The legislation would yield a mixed bag of results for various otherplayers in the credit card industry, with potentially significanteffects on payment networks like Visa Inc. and MasterCard Inc. as wellas "acquiring banks" like Global Payment Systems Inc., analyst RobertDodd said.


"While we believe the prospect for interchange regulation is real -though far from certain - we believe the impact on the sector would bemixed, generally positive for acquirers and modestly negative fornetworks," Dodd wrote.
(Continue reading at Forbes)




Is this the beginning of the end of the "fee ride" given to Visa and MasterCard? 

Has the Dynamic Duo(poly) finally met their match?  

Have Merchants finally seen a "bill" loaded with "Interchange Fees" that they actually like? 

Stay tuned to find out the answers to these and other duo-processing (due processing) questions, as the Federal Government takes on Visa, MasterCard for Round Two. 

First it was the consumers crying foul...

This time it's the merchants who are claiming they have been hacked, oops, let's change that to: this time it's the merchants who "get to go to the line" and shoot their Interchange "Fee Throws."  

They say things happen in three's, so after Visa and MasterCard lose Round Two, Round 3 might involve companies such as HomeATM.  

Why HomeATM?  Because, we offer the world's ONLY PCI 2.0 certified terminal with PIN Pad specifically designed for eCommerce use.  Even though our process cannot "get hacked," (because our data is never in the clear) we still  "jumped through their (PCI) hoops"...got certified, and thereafter, we get "slapped" on the wrist most every time we try and get the to the (shopping) "basket" on the web.  We've been told that Visa will NEVER allow PIN Debit on the web...which I find hard to believe, based on the recent gaffes in "card not present" security. (or the lack thereof)  Put another way...

Online (PIN) Debit for online shoppers is more secure, yet the duo(poly) pushes credit and "offline" debit transactions because of the higher interchange rates. (including the EFT networks pushing the infamous, "Card Not Present PIN Debit" solution offered by a competitor.) 


  • Higher interchange exists because there is higher risk
  • Lower Interchange exists because there is lower risk
  • Sotware PIN Debit ("Card Not Present PIN Debit Interchange") does NOT exist!!  

At the "rate" they are going, (or should I say at their going rate?) I don't see how the dynamic duo(poly) could argue there's a "free market" when it's obviously nothing but a "fee market."  Of course, we'd prefer to work "with" Visa than against them. That said, I must say: "Balls in their court...but we "got game!"


U.S. bill could help merchants cut credit card fees | U.S. | Reuters
U.S. bill could help merchants cut credit card fees
Thu Jun 4, 2009 3:53pm EDT

By John Poirier

WASHINGTON (Reuters) - Merchants and retailers would be able to negotiate with banks to reduce costs associated with credit card purchases, according to legislation introduced on Thursday by lawmakers in the U.S. House of Representatives.

The measure, called the Credit Card Fair Fee Act, focuses on the so-called interchange fee that restaurants, service stations and other stores pay banks for credit card-related purchases.


Merchants and some lawmakers have complained that merchants and retailers have been blocked from being able to negotiate a fee structure with credit card networks Visa Inc and MasterCard Inc, whose members are banks.

Visa and MasterCard set the fee structure and control almost three-fourths of the volume of transactions on general purpose cards. American Express Co and Discover Financial Services have their own systems.

Store owners and retailers have also complained that banks collude to set the fee structure and block them from being able to negotiate lower fees, even going as far as calling the practice anti-competitive.

Critics have said those fees are passed on to consumers.

Visa and MasterCard have said merchants and retailers do have the opportunity to negotiate lower fees.

"This legislation will give merchants a seat at the table in the determination of these fees," said House Judiciary Committee Chairman John Conyers in a statement.

"It is not an attempt at regulating the industry and does not mandate any particular outcome. This bill simply enhances competition by allowing merchants to negotiate with the dominant banks for the terms and rates of the fees."

Continue Reading at Reuters








Reblog this post [with Zemanta]

Windows XP ATM's Can Steal Your PIN

I blogged about this yesterday, (Malware Allows Complete Control Over ATM) but it's still big news today, so here's a refresher excerpt from today's iTWire:

iTWire - Windows XP cash machines can steal your PIN
Technology news and Jobs arrow Information Technology News arrow Windows XP cash machines can steal your PIN
Windows XP cash machines can steal your PIN E-mail
by Davey Winder | Friday, 05 June 2009

It is bad enough that the bad guys constantly try and phish your financial data via email and fake websites, now cash machines are getting in on the act.

The Trustwave SpiderLabs, an outfit that deals with everything from ethical hacking through to incident response and security forensics, is warning that the bank cash machine network is at risk from a malware attack that collects PIN numbers.

The SpiderLabs team reports that it has been able to perform an analysis of the malware, which had been discovered on compromised East European cash machines running Windows XP.

The malware was able to capture the magnetic stripe data from the private memory space of transaction-processing applications that were installed on these compromised ATMs, along with PIN codes for good measure.

Continue Reading


, , , , , , ,

Yet Another Online Banking Threat - Fake Digital Certificates

Virus and Spyware - New Fake Banking Cert Attacks In Play - eWeek Security Watch
Editor's Note: It dawned on me that I could devote this entire blog to stories about how insecure online banking is, but since we can fix it, I'll stay with the HomeATM PIN Payments Blog. Here's yet another serious threat, this time it's fake digital certificates, that HomeATM would eliminate with our PCI 2.0 Certified SafeTPIN device. Swipe Bank Issued Card, Enter Bank Issued PIN, and you're authenticated. And the data is encrypted and is NEVER in the clear. Keep It Simple indeed.

New Fake Banking Certificate Attacks In Play

Researchers with security training experts SANS Institute have reported the emergence of a new wave of attacks seeking to take advantage of trust in online banking sites and digital certificate e-banking security programs.

The involved attacks target customers of Bank of America, asking targets to click through from e-mail borne links to URLs where they are asked to upload new digital certs to protect themselves when e-banking.

Of course, once an end user has clicked on one of the links on the phony BoA pages they are instead infected with malware.

As SANS expert G.N. White highlights in a blog post on the topic, technologically savvy users may be even more likely to fall for the campaigns as they specifically target people who are to some extent educated about, and aware of, digital certs and the role they play in protecting e-banking applications.

At the same time, the example White touts in his post actually tips its own hand by warning users not to worry if after clicking on its links they receive any computer warnings about "potential scripting violations."

How industrious.

Continue Reading at eWeek



, , , , , , , ,

Should Banks Use Twitter?

Banks using Twitter need to proceed with caution, experts say
By Marcia Savage, Features Editor, Information Security magazine | SearchFinancialSecurity.com

Editor's Note:  This story is yet another reason why banks should discard the blatantly obsolete username | password login process and replace it with a secure two factor authentication end to end encrypted login.  They are two-thirds of the way there.  They issue a card, they issue a PIN, now they need to issue their online banking customers a card processing terminal which enables their users to Swipe their bank issued card, enter their bank issued PIN and voilla, all these potential threats are eliminated.  Since HomeATM designed, patented and manufactures the world's first and only PCI 2.0 certified PIN Entry Device, made specifically for online eCommerce use, the terminal of choice is a no-brainer.   So if banks want to eliminate phishing entirely (no data means no phish) cloned websites, DNS Hijacks, the threat spoken about below, etc. then who are they gonna call?  There's no place like HomeATM!  Here's an excerpt from the latest threat faced by online banking article:

"Banks are jumping onto the Twitter bandwagon but experts say financial institutions need to consider the fraud risk and other security issues associated with the micro-blogging site and other social networking services.

Bank of America, Wells Fargo and ING DIRECT are among the many financial institutions using Twitter for marketing, customer service, community outreach, and other activities. According to a recent study by Williams Mills Agency, an Atlanta-based public relations firm serving financial services, financial institutions of all sizes, including community banks and credit unions, are using Twitter to communicate with consumers.

Types of information shared on Twitter by financial institutions include promotions, replies to followers, personal finance tips, links to industry news, community event news, and personal comments on mundane topics like the weather, the study showed. William Mills looked at 1,176 "tweets" posted by 63 financial institutions in March.

However, banks moving into social networking should proceed with caution, said Jacob Jegher, senior analyst in the banking group at Celent, a Boston-based financial research and consulting firm. Jegher wrote earlier this spring about social networking risks for banks.

The biggest threat, he said, is fraudsters pretending they are a particular bank on Twitter or Facebook in order to steal online banking credentials. For example, a fraudster posing as a bank on Twitter could respond to a customer's question about an account problem by asking for account passwords, Social Security numbers, and other sensitive information. Unsuspecting customers, thinking they're on a legitimate bank Twitter page, could be duped.

"I see that as a huge risk – the social engineering of information out of people," Jegher said. "All it takes is a couple pieces of information and the fraudster can start piecing things together."

Continue Reading at SearchFinancialSecurity.com
(registration required)



, , , ,

That Was Stupid! $10k If You Can Hack This...Ooops!

Startup: We'll give you $10,000 if you can hack into our CEO's email.  Oops!  Already?

June 2nd:


A newly launched startup called StrongWebMail is aiming to add a new layer of secure authentication for its customers - phone verification prior to logging in and alert services for potential email compromises.


The company is in fact so confident in its approach that it’s currently offering $10,000 rewardto the person who breaks into the CEO’s email. To make things eveneasier, they have in fact provided his user name and password (CEO at StrongWebmail.com; Mustang85).

The catch? Aspired participants would have to figure out a way tointercept the 3 digit PIN send over SMS/phone call required for loggingin :

“StrongWebmail.com is offering $10,000 to the firstperson that breaks into our CEO’s email account…and to make thingseasier, we’re giving you his username and password.  There’s just onecatch: to access a StrongWebmail.com email account, the account’s ownermust receive a verification call on his pre-registered phone number. Soeven though you have our CEO’s username and password, you still havesome work to do because you don’t have access to his telephone.”

48 Hours Later... Ooops!
June 4th:

A Webmail service that touts itself as hack-proof and offered $10,000 to anyone who could break into the CEO’s e-mail has lost the challenge.

A trio of hackers successfully compromised the e-mail usingpersistent cross-site scripting (XSS) vulnerability and are nowclaiming the bounty.


[ SEE: Email service provider: 'Hack into our CEO's email, win $10k' ]


The hacking team of Aviv Raff, Lance James and Mike Bailey set upthe attack by sending an e-mail to the company’s CEO DarrenBerkovitz.   When he opened the e-mail, the team exploited an XSS flawto take control of the account.

They were able to follow the contest rules and record a calendar entry for one of Berkovitz’s task that’s due on June 26. Robert McMillan reports that Berkowitz confirmed the authenticity ofthe calendar entry but StrongWebmail has not yet confirmed thecompromise or pay the promised bounty.

The researchers are not sharing details of the vulnerability.  However, James has been posting screenshots of StrongWebmail’s XSS problems on Twitter.
Reblog this post [with Zemanta]

Nightline: Billions Snatched in Credit Card Theft

Nightline produced a story on Credit Card theft, which ran the night before last.  The story told of the billions of dollars stolen by fraudsters, but in my humble opinion, they left an important part of the story by the wayside.  

When fraudsters attack, who gets hurt the most...  Here's a quick excerpt from their story, followed by exactly what I mean by "who gets hurt the most."

Thieves Snatch Billions in Credit Card Identity Theft Scams - ABC News


'Nightline' Tracks Hackers in Underground Identity Theft Chatrooms; How to Protect Yourself

By ELISABETH LEAMY


Foryears, crimes have followed the same age old mantra: wrong place at thewrong time. For someone to commit a crime against someone else, theyhad to be physically in the same area. But that's no longer the case;it's now easier than ever to be victim of a crime, particularlyidentity theft, without even realizing it.

Identitythieves snatch tens of billions dollars a year through credit cardfraud, either outright, or by selling your card information to othercrooks across the globe. The perpetrators come from a loosely organizedinternational underworld working beyond the reach of the law andwithout limits.

"They can sit in an apartment in Kiev ... andsteal your identity and you're going to be in a world of hurt," saidDan Clements, founder of Card Cops, a company that has been trackinghackers who buy and sell people's identities. "They blatantly ... tradecredit cards. They trade social security numbers. They trade debit cardpin numbers."

Card Cops has been tracking hackers' activity fora decade. Crooks from all over the world meet in Internet chat rooms,in what almost looks like an underground stock market. "Credit cardsare commodity items," Clements said. "They can go for as little as $2or $3 for a regular credit card. If you have a platinum card, it may befor $10 or $20. It's big business. They make a lot of money. There arepeople here that claim to make $20,000 to $30,000 a month selling theseresources in these chat rooms."

The chat rooms operate like acommodity floor, where information is openly traded, and the hackerswho carry out identity theft usually live in another part of theworld.  "It's a global market," Clements said. "It's like a bazaarwhere you can buy anything at any time."  The Card Cops should know:They entered the business of protecting consumers and merchants fromidentity theft because many of them were scammed themselves when theyworked together at another Internet company.
To help understandhow fast a thief can siphon money from an account, ABC Newsexperimentally opened a Visa account. It only took 15 minutes before ahacker got hungry "

We had a hit from a retailer inMassachusetts," said Clements. The culprit used the credit card numberto buy Dominos Pizza. "So there is your charge for $39.76. It lookslike some kid might have found the card in this chat room and decidedto buy his buddies pizzas."

Continue Reading at ABC News


Editors' Note:  Regarding that $39.76.  Somebody lost $40 bucks.  Who was it? ABC News didn't take the hit...they are protected by the "Zero Liability" program...introduced by Visa...who also didn't take the hit.  Oh, and the bank that issued the card?  They didn't take the hit either. 

That leaves...Dominos, who got screwed out of not only their $39.76, (and as much as I'd prefer
not to call this the "domino effect" it is what it is) but they also got screwed out of the cost of the cheese, the sauce, the sausage, the onion, the mushroom, the pizza box, the labor and payroll involved in making the pizza, the gas to deliver the pizza etc. 

At the end of the day, they lost $40 plus an additional $20+ bucks.  So it's easily a $60 hit. 


There are several groups that have stood up to fight high interchange fees, but here's a suggestion.  Rather than bitch and moan about Interchange, start doing a little b&m'ing about the fact that Visa is pushing a less secure product (signature debit has up to a 15 times higher fraud rate than PIN Debit) which, not coincidentally, also carries a higher interchange fee.  Why would Visa's Signature product be the least secure of the two types (PIN & SIG) of debit products?  

I would make it a point to ensure that argument was all over the House Bill introduced yesterday.  (Credit Card Fair Act Introduced by House)

So the Big Question is simply this:  If Visa stands to "lose nothing" and Visa stands to "make more money" by pushing a "less secure" (Signature Debit) payment product, why on earth  would they be interested in pushing a more secure (PIN Debit) payment product? 

The short answer is "they wouldn't." 

So then the next Big Question becomes: Why is
PIN Debit outpacing Signature Debit by a nearly four to one margin
Have the merchants finally realized that there are virtually no chargebacks involved with PIN Debit and Interchange Rates are signifcantly lower?  Or have consumers become more savvy?  You tell me.  I'd love to hear your comments.      



Reblog this post [with Zemanta]

PIN Debit Growth Nearly 4 Times Higher than Signature Debit

Amid Recession, PIN Debit Growth Far Outpaces Signature

Editor's Note:  I don't see the connection between the recession and PIN Debit usage at all.  In fact, quite the opposite.  Think about it.  Visa and MasterCard attach rewards to "signature" debit, therefore, in a recession, you would think that consumers would want the rewards and SIGNATURE would be outpacing PIN.

Sure, I see the debit over credit recession connection, but cannot digest the PIN over Signature in a recession propaganda.  Now, had the article made the argument that consumers are becoming more wary, (is undesensitized a word?) about payments security, and thus are choosing PIN over SIG, I'd have to wholeheartedly agree.

But, according to research, released yesterday by the Pulse EFT Network, PIN Debit grew nearly four times the rate of signature debit between July and December which is when the recession kicked in.  Here's a blurb from DTN...


This, from John Stewarts' Digital Transactions:
"While the recession is making an impact on consumer spending generally, PIN debit card usage is faring considerably better than that of signature debit.

PINdebit transactions by consumers grew 15% between July and December, theperiod during which the economic downturn began making itself felt,nearly four times the rate of growth for debit transactions securedwith a signature, according to research released on Thursday by the Pulse electronic funds transfer network.

Thestudy, conducted for the Houston-based network by consulting firmOliver Wyman Group, also found that fraud rates on debit cardtransactions are falling; that usage of debit cards for bill payments,including online PIN-less payments, is registering significant numbers;and that awareness of a wide range of alternative-payment methods isvery high among bank card executives. Also, the study shows steadilyrising adoption by banks of mobile-banking technology.

Continue Reading at Digital Transactions


Reblog this post [with Zemanta]

Thursday, June 4, 2009

HomeATM FinovateStartup09 Demo (Video)


Here is HomeATM's 7 Minute Demo Conducted at FinovateStartup09





Reblog this post [with Zemanta]

You Get What You Pay For...But It Can Cost You!

In a post we did last May 1st we talked about the lawsuit brought by Alain Job against Halifax over Chip and PIN Security.  His attorney, Stephen Mason took on the case and represented Job "pro bono", hence the title of the blog post.  Well, they said a decision was expected in about a month, and it's in.  Finextra reports, but first a quick review of the case from the PIN Payments Blog:

FreeMason Job: Chip-and-PIN On Trial


'Phantom' withdrawal case concludes in U.K. court



A Halifax bank defends chip-and-PIN, while the plaintiff argues his cash card could have been cloned.  A one-day trial that raises questions about the security of cash cards used in the U.K. and Europe concluded Thursday, with a decision expected in about a month.


Alain Job sued U.K. bank Halifax in March 2007 over eight withdrawals made from his account in February 2006. Job maintains he did not withdraw a cumulative £2,100 ($3,100). He also maintains he did not authorize anyone else to withdraw the money .

Job decided to sue after the Financial Ombudsman Service (FOS), which mediates disputes between banks and customers, sided with Halifax.


Finextra: Court sides with Halifax in Chip and PIN clone case

A UK judge has ruled in favour of high street bank Halifax in the country's first ever phantom withdrawal lawsuit.

The case was brought by a customer who claimed that fraudsters cloned his chip-based card and withdrew £2100 from his account at ATMs.  The judge based his ruling on printouts from log files to show that Job's real card had been used for the transactions.

The suit was filed after two critical pieces of evidence once held by Halifax were destroyed, including the original ATM card and the Authorisation Request Cryptogram that could have proven that the card's chip had been read and authenticated by the machine. The plaintiff Alain Job says he is studying the judgment before deciding whether to appeal the ruling.




Reblog this post [with Zemanta]

2009 Bankcard Profitability Study: MasterCard Inc.

2009 Bankcard Profitability Study: MasterCard Inc.
Costly payouts to settle two long-running antitrust cases dampen profits while the economic slowdown begins to affect purchase volume.

MasterCard Worldwide continued to crank out overall debit card payment-volume growth in 2008, but legal issues and the U.S. economic slowdown hurt its overall performance.

In its second full year as an independent company following its initial public offering in 2006, MasterCard finally resolved some long-simmering legal issues.

The company in June reached an agreement to pay American Express Co. up to $1.8 billion to settle an antitrust case dating back to 2004. AmEx's suit, filed in 2004, alleged that MasterCard's and Visa's exclusionary rules prohibiting U.S. financial intuitions from issuing cards on its network hurt its growth opportunities. MasterCard said it would pay the settlement amount in quarterly installments over the next three years.

MasterCard and Visa Inc. reached an agreement to settle Discover Financial Services' similar antitrust suit dating back to 2004 and to share settlement costs. MasterCard's share of the $2.75 billion settlement was $827.5 million, including $35 million Morgan Stanley, Discover's former parent, agreed to pay MasterCard as part of the deal.

Continue Reading at CardForum


, , , , , ,

Merrick Bank vs. Savvis: Analysis from InfoSecSecurity


Editor's Note:  InfoSecCompliance LLC (”ISC”) is a law
firm dedicated to providing solutions for privacy and security legal
compliance and risk management and here's an excerpt from a recent post (yesterday) on
their blog. 

Merrick Bank v. Savvis: Analysis of the Merrick Bank Complaint



Posted on June 3rd, 2009 by David Navetta of InfoSecCompliance.com

The Merrick Bank v. Savvis lawsuit has the potential to change the liability
dynamic of the PCI regulatory system.  The Savvis case is one of the
first known instances of a payment card security assessor being sued by
a merchant bank ( the merchant bank is a third party relative to the
Savvis-CardSystems relationship).    The Merrick Bank compliant alleges
that it relied on Savvis’ certification of CardSystems  as Visa CISP
compliant (this matter pre-dated the PCI standard), and that
certification was false.  After CardSystems suffered a breach exposing
up to 40 million payment card records, Merrick allegedly incurred $16
million in payments to the card brands (which was ultimately
transferred to issuing banks who suffered losses arising out of the CardSystem breach).


If Savvis is held liable (or even if this case makes it past motion to dismiss or a motion for summary judgment) it has the potential to significantly modify the relative risk of PCI qualified security assessors, and in turn modify the PCI regulatory scheme.  This post discusses the two theories of liability alleged by Merrick:  (1) negligence; and (2) negligent misrepresentation.

Please note, while I am an attorney this post does not in any way constitute legal advice or a legal opinion, and should not be relied upon to take any action or be the basis for any inaction.  The law related to this case is complex and varies from jurisdiction to jurisdiction, and over time.  If you are interested in a full legal analysis of potential security assessor liability in a particular jurisdiction, please contact me directly at djn@davidnavetta.com




One further note, the basic rules and general information in this document was derived from various legal research sources.  However, one book in particular provided excellent information on the liability of service providers to third parties.  Please check it out, and purchase it: Professional Liability to Third Parties (Jay M. Feinman).

UPDATE:  Other bloggers/mags are putting together some nice analysis of this case as well:  here, here

Continue Reading at InfoSecCompliance.com


FBI Director Anticipates New Crime Wave Of Financial Fraud

By Kate Gibson | Wall Street Journal

The FederalBureau of Investigation is braced for a potential crime wave involvingfraud and corruption related to bank bailout money and the economicstimulus package, FBI director Robert Mueller warned Tuesday.

"These funds are inherently vulnerable to bribery, fraud, conflicts ofinterest and collusion. There is an old adage, that where there ismoney to be made, fraud ...
Reblog this post [with Zemanta]

JCB and China Minsheng Bank to Launch New Card

 
Contact: Deb Montner, 1-203-226-9290, dmontner@montner.com

JCB Cooperates with China Minsheng Bank to Launch
Credit Card with China Eastern Airlines:
Further enhancing JCB co-brand program in China


Tokyo, June 4, 2009
– JCB, the only international payment brand based in Japan, and its international subsidiary JCB International (JCBI) today announced that China Minsheng Banking Corp., Ltd (CMBC) has launched the JCB branded “CMBC - CEA Credit Card” in cooperation with China Eastern Airlines Corporation Limited (China Eastern Airlines).

Since 1982, JCB and JCB International have been expanding JCB card acceptance in China to increase convenience for JCB cardmembers. Currently JCB has alliances with eleven partner banks and financial institutions for merchant acquiring, and approximately 80,000 merchants now accept JCB cards.

JCB card issuing to consumers in China has also been expanding to meet the growing needs of the market for international credit cards. As of June 1, 2009, seven banks (Bank of China, Bank of Shanghai, China Everbright Bank, China Merchants Bank, Shanghai Pudong Development Bank and China Minsheng Banking Corp., Ltd., and Ping An Bank Co. Limited) have already launched JCB brand credit card issuing programs, and the cardmember base is more than two million in the country.

During CMBC’s development of the co-brand credit card with China Eastern Airlines, JCB provided the issuing bank with the expertise it has accumulated in the Japan credit card market, responding to CMBC and China Eastern Airlines’ need to strengthen service to customers through a credit card. JCB and JCBI are expanding partnerships for JCB brand card issuing with Chinese financial institutions by strategically utilizing the knowledge, skills and network built over 40 years in the credit card business, and are committed to developing and providing high-quality service to meet the diverse needs and lifestyles of China’s consumers.

The new CMBC - CEA Credit Card combines CMBC credit card services and the China Eastern Airlines mileage program, and also enables cardmember access to JCB global network and services, for an international card that earns China Eastern Airlines miles when used to purchase air tickets. The CMBC - CEA Credit Card has a lineup of standard, gold, and platinum card types. This is the first JCB branded platinum card to be issued in China.

CMBC - CEA Credit Cards


Platinum ---- Gold ---- Standard

About JCB
JCB is a major global payment brand and leading credit card issuer and acquirer in Japan. JCB launched its card business in Japan in 1961 and began expanding overseas in 1981. Its acceptance network includes 12.76 million merchants and over a million cash advance locations in 190 countries and territories. JCB cards are now issued in 19 countries and territories, with more than
60.2 million cardmembers. As part of its international growth strategy, JCB has formed alliances with more than 350 leading banks and financial institutions globally to increase merchant coverage and cardmember base. As a comprehensive payment solution provider, JCB commits to provide responsive and high-quality service and products to all customers worldwide. For more information, visit: www.jcbcorporate.com/english. Note: JCB statistics included in About JCB are as of the end of September 2008.

Reblog this post [with Zemanta]

JCB & Ping An Bank Sign Issuing Partnership



Contact
: Deb Montner, (203)- 226-9290, dmontner@montner.com (scroll down for card images)

JCB International and Ping An Bank Sign Issuing Partnership:

Seventh bank in China to issue JCB cards, further enhancing JCB brand

Ping An Bank to launch BE@RBRICK design JCB credit cards

Tokyo, June 4, 2009 -- JCB, the only international payment brand based in Japan, and its international subsidiary JCB International (JCBI) today announced that JCBI has signed an agreement with Ping An Bank Co. Limited (Ping An Bank), part of the major financial group Ping An Insurance (Group) Company of China Ltd., for issuing JCB cards in China. Starting June 1, 2009, Ping An Bank began promoting the new "Ping An Bank BE@RBRICK JCB Card" featuring the popular BE@RBRICK bear-shaped block-type figure owned by MEDICOM TOY CORPORATION, a Japanese toy maker.

Since 1982, JCB and JCB International have been expanding JCB card acceptance in China to increase convenience for JCB cardmembers. Currently JCB has alliances with eleven partner banks and financial institutions for merchant acquiring, and approximately 80,000 merchants now accept JCB cards.
JCB card issuing to consumers in China has also been expanding to meet the growing needs of the market for international credit cards. In addition to Ping An Bank Co. Limited, Bank of China, Bank of Shanghai, China Everbright Bank, China Merchants Bank, Shanghai Pudong Development Bank and China Minsheng Banking Corp., Ltd. have already launched JCB brand credit card issuing programs, and the cardmember base is more than two million in the country.

The new partnership with Ping An Bank announced today marks the seventh bank to start JCB card issuance in China. For JCB, the alliance is aimed to accelerate JCB brand growth in China, and for Ping An Bank, which is now aggressively building credit card business, it will expand their product line and further strengthen their customer base. JCB contributed expertise in co-brand program development to Ping An Bank for its launch of the Ping An Bank BE@RBRICK JCB Card.

JCB and JCBI are expanding partnerships for JCB brand card issuing with Chinese financial institutions by strategically utilizing the knowledge, skills and network built over 40 years in the credit card business, and are committed to developing and providing high-quality service to meet the diverse needs and lifestyles of China’s consumers.

Card designs
BE@RBRICK TM & © 2001-2009 MEDICOM TOY CORPORATION. All rights reserved.

About the Ping An Bank BE@RBRICK JCB Card
Overview Select from five card designs featuring BE@RBRICK, a bear-shaped block-type figure, loved by many collectors worldwide as well as in Japan, and now popular among China’s metropolitan youth. This is the first international credit card in the world to feature BE@RBRICK. The card offers attractive functions and services to BE@RBRICK fans, including original BE@RBRICK rewards for points earned with the card. Cardmembers enjoy both Ping An Bank credit card functions and services and JCB international brand functions and services.

Major functions and services
Available to Residents of China
Card types Standard only
Annual fee First year free. Annual fee of RMB100 in following years is waived if the card is used at least six times during the prior year.
Major functions and services Select from five card designs. Dual-currency (USD and RMB). Ping An Bank credit card functions and services. JCB international brand functions and services Points earned with the card can be exchanged for original BE@RBICK goods. Access to exclusive cardmember internet site.
About JCB
JCB is a major global payment brand and leading credit card issuer and acquirer in Japan. JCB launched its card business in Japan in 1961 and began expanding overseas in 1981. Its acceptance network includes 12.76 million merchants and over a million cash advance locations in 190 countries and territories. JCB cards are now issued in 19 countries and territories, with more than
60.2 million cardmembers. As part of its international growth strategy, JCB has formed alliances with more than 350 leading banks and financial institutions globally to increase merchant coverage and cardmember base. As a comprehensive payment solution provider, JCB commits to provide responsive and high-quality service and products to all customers worldwide. For more information, visit: www.jcbcorporate.com/english. Note: JCB statistics included in About JCB are as of the end of September 2008.

Reblog this post [with Zemanta]

It's Good to Be King

Report States That Cash Is Still King, But For How Long?
Jun 4 2009

Editor's Note:  Since HomeATM moves "cash" in "real time" as a PIN (online) Debit transaction, I suppose it really doesn't matter if Cash remains King, or if it's overthrown (overthrone?) by Debit.  Either way works for us...because either way works for you!  It's good to be King, but I'll settle for the title: KingPIN.

The payment industry's latest publication, The Way We Pay 2009: UK Cash & Cash Machines provides the latest data on how UK consumers are obtaining and using cash and how this is forecast to change.

The full Payments Council report issued this month (June 2009) includes data from Link and other industry sources.

2008 cash and cash machine data shows:


Whilst cash spending continues to remain relatively flat, the number of cash machine withdrawals continues to rise and is forecast to peak in 2011. Consumers are increasingly using cash machines for withdrawing cash, where previously they would have withdrawn money in bank branches or at post offices; five years ago only 54% of cash came from cash machines, last year 71% of cash was acquired that way. This shift has been driven by an increase in the availability and numbers of cash machines as well as the migration of payment for state benefits and pensions from cash and girocheque to automated methods.

Continue Reading



Reblog this post [with Zemanta]

Card Issuers Expect Debit Growth in 2009

2009 Debit Issuer Study Says Despite Recession, Debit Growth will Continue

HOUSTON - June 4th: (PIN Payments News Blog) The 2009 Debit Issuer Study, commissioned by PULSE, identified several positive trends for financial institution debit card issuers, including sustained debit transaction growth despite the recession. This edition of the comprehensive debit card industry study also
found that use of PIN debit has increased, while fraud loss rates have declined.

Issuers surveyed experienced debit transaction growth of 8 percent in the second half of 2008, composed of 15 percent growth in PIN debit transactions and 4 percent growth in signature debit. Survey participants predicted 7 percent growth each for PIN and signature debit in 2009.

“Although the economy is a challenge for debit card issuers, as it is for everyone, debit transaction growth remains strong,” said Cindy Ballard, PULSE executive vice president. “Debit card use is expected to continue to grow as the economy bottoms out and begins to recover, because consumers use their debit cards for a large portion of necessary everyday expenses.”

The 2009 Debit Issuer Study revealed that more than a quarter of all debit transactions (27 percent) in 2008 were for less than $10.

“In most cases, these transactions are replacing cash, highlighting a clear consumer preference for electronic payments,” said Ballard.

Debit card penetration – the percentage of eligible account holders who have a debit card – remained flat at 73 percent. Using an expanded definition of “active” debit cards, the number of issued cards used actively in 2008 was 66 percent.1

PIN debit accounted for 35 percent of debit transactions in 2008, up slightly from 34.2 percent in 2007. The average debit transaction value was $42 for PIN debit and $37 for signature. Both figures have declined by roughly $1 compared to the previous study. In addition, active debit cardholders performed 17.3 point-of-sale transactions per month, on average, compared to 16.6 transactions per month in the 2008 survey.

Debit card fraud losses at the point of use declined in all categories. PIN point-of-sale losses, as measured in dollars per card per year, fell to $0.15 from $0.19. Similarly, ATM losses declined to $0.56 per card per year from $0.61, and signature debit loss rates fell to $1.81 from $1.92. Although losses at all three usage points declined year-over-year, the survey did record an increase in share for ATM losses, to 38 percent of total debit fraud losses in 2008 from 25 percent in 2007.

Additional survey findings include:

* Active debit cardholders performed 3 ATM transactions per month, on average, down from 3.4 in the previous survey.
* More than half of issuers surveyed (53 percent) participate in a surcharge-free ATM network, down slightly from 56 percent in 2007. And 43 percent offer ATM surcharge reimbursements to at least some cardholders.
* Bill payments represented 10 percent of signature debit transactions in 2008, compared to 7 percent in 2007.
* The percentage of debit card issuers offering debit rewards programs continues to grow, rising two percentage points to reach 53 percent this year.
* Thirty-seven percent of issuers offer mobile banking, compared to 15 percent in 2008, while 38 percent plan to introduce it soon, up from 28 percent last year.

“The 2009 study uncovered several reasons for optimism among financial institutions that issue debit cards,” noted Tony Hayes, an Oliver Wyman partner, who served as project lead on the study. “Among them, debit card-based bill payments account for a small but rapidly growing share of debit card payments, a market with significant potential for growth in the coming years.”

The 2009 Debit Issuer Study results support PULSE’s view that debit cards still have considerable long-term growth potential.

“Despite the challenge of navigating through an economic downturn, debit card issuers have much to be encouraged about,” said Ballard. “Transaction growth remains robust, and issuers see further improvements in the performance of debit card portfolios as a key opportunity in 2009.”

About the Study

The 2009 Debit Issuer Study is the fourth installment in the study series. The series provides an objective fact base on debit card issuer performance and financial institutions’ outlook for the debit card business. Seventy-three financial institutions – including large banks, credit unions and community banks – participated in the 2009 study, which was conducted by Oliver Wyman. Collectively, the participants issue 94 million debit cards and operate 61,000 ATMs. The sample is representative of the U.S. debit market in terms of institution type, location and debit network participation.

About PULSE

PULSE is one of the nation’s leading ATM/debit networks, currently serving more than 4,500 banks, credit unions and savings institutions across the country. PULSE is owned by Discover Financial Services (NYSE:DFS). The network links cardholders with more than 289,000 ATMs, as well as POS terminals at retail locations nationwide. The company is also a valued resource for industry research related to electronic payments and is committed to providing its participants with education on evolving products, services and trends in the payments industry. For more information, visit www.pulsenetwork.com.

Media may request an executive summary the study by contacting Anne Rhodes.

1 In previous Debit Issuer Studies, the most common definition of “active” cards was those used to make any signature transaction in the last 30 days. By this measure, 56 percent of debit cards were active in 2008, a slight decline from 2007. An equal number of issuers now define active cards as those used to conduct any transaction in the last 30 days, resulting in the higher 66 percent card activation rate.

PULSE
Anne Rhodes, 832-214-0234
arhodes@pulsenetwork.com


Source: Press Release




Reblog this post [with Zemanta]

Disqus for ePayment News