Monday, July 20, 2009

Credit Card Rewards May Fuel Debt: Study


Credit-card reward plans may fuel debt: study

Last Updated: Monday, July 20, 2009 | 4:21 PM ET
'As rewards programs have become increasingly popular and generous, interchange fees charged to merchants have also increased.'—Andrew Ching and Fumiko Hayashi
Many Canadians collect such rewards, typically travel points or cash rebates, and many merchants grumble about paying for them through transaction fees.

"As rewards programs have become increasingly popular and generous, interchange fees charged to merchants have also increased," said the study, which focused on U.S. data.

"A merchant pays different interchange fee rates for credit-card transactions: non-rewards cards have the lowest fee rates, while high-end rewards cards have the highest rates," it added.

The authors — Andrew Ching, an assistant professor of marketing at the U of T's Rotman School of Management, and Fumiko Hayashi, a senior economist at the Kansas City Fed — conclude that "removing rewards today would cause a small percentage of consumers to switch from electronic payment methods (credit/debit cards) to paper-based methods (cash/cheques) at five types of retail stores.

"The majority of consumers who currently receive rewards on credit/debit cards would continue to use credit/debit cards, even if rewards were no longer offered."

An example from Australian policy on card fees

This conclusion is "consistent with the experiences in Australia, where the three major credit-card networks, Bankcard, MasterCard and Visa, were mandated to reduce their interchange fees in 2003," the study says.

"Although the value of the rewards points for these three networks has been reduced dramatically since the reform, we observed that the usage pattern of credit cards has remained essentially unchanged."

Even so, they conclude that eliminating credit-card rewards would have a bigger effect than eliminating debit-card rewards.

"We also find that rewards encourage consumers to use credit cards even if they carry balances," the authors say.

"This suggests that removing credit-card rewards could have some effects in reducing consumers’ credit-card debts. This could increase consumers’ welfare, but reduce credit-card issuers’ revenue from interest charged on their balances."



Torpig (Sinowal/Mebroot) Trojan Just Got Nastier for eBanking

Here yet is more alarming e-vidence and another reason to not trust the web when it comes to either e-banking or e-payments.   ALL financial transactions MUST be done OUTSIDE the web browser.  Yesterday in a post entitled: "Online Banking Data Fed to the Phishes"  there was a quote (pictured on left) which, in no uncertain terms, sums up the potential for "creating a large-scale secure transaction system on the web."  Here's another quote from the same article:

"Internet banking experts say without coordinated global action by governments, financial institutions will have to "give up on the internet" because they are losing their war against hackers and criminal fraudsters."

So, based on those two statements of fact, it would seem that we need to replace "typing" with "swiping."  The hackers are getting better, and the "type" system we use is an "ideal" format. 

But it gets nastier...as we learn that: (from Finextra blogs)

 The nastiest ebanking trojan just got nastier


On Friday, the team at TrustDefender Labs releaseda report on one of the nastiest pieces of malware which has just becomeeven nastier.

Now you may think that some of the older malware is badenough, the bad guys have released a new version of one of the mosthighly successful e-banking Trojans but this time with majorenhancements. And the 'bad news' is that they changed the lot!

Basically, these guys have been busy over the last few months with anew version of Mebroot/Sinowal/Torpiq that performs the same tasks anddoes the same badness as the previous versions (for more informationsee www.trustdefender.com/blog),however the big difference is that this Trojan is hiding in the systemwith improved stealthiness than ever before, to make sure:

1.    it can infect your system without you knowing
2.    collect as much information as possible and
3.    stay there undetected as long as possible


To reiterate in plain English: Everything that was previouslywritten on how to detect Mebroot/Sinowal/Torpiq is now invalid anddoesn’t apply anymore… No rg4sfay file in Windows\temp anymore, noreference to  \!win$… No detection with GMER’s special mbr.exe programand GMER itself only lists a couple of detached threads… Nothing reallysuspicious…

The troubling issue is that the research team found this new versionand noted it has the most exhaustive list of banking and brokingwebsites they have seen – with virtually all major financialinstitutions in UK, Australia, USA, Spain, Italy, Germany and more.
Butinterestingly, more and more non-bank websites are part of this list,like partycashier.com (the online payment from a popular poker site)and government sites (FED to the Phishes) like pay.gov (electronic payments to the US Govt).

The challenge now for the 'good guys', when will they catch up and can they stop this nasty e-banking Trojan?

Editor's Note:  Yeah, just "stop typing." Trojans work because people are still inexplicably "typing" their Primary Account Number (PAN) or online banking authentication (username/password) into boxes on websites. 

Until they start swiping we will be boxed in by the bad guys.  It really is that simple. 

The cardholder data/authentication credentials MUST be encrypted "outside" the browser space.  We swipe our card and enter our PIN to get cash in real-time at an ATM, so the encryption standards used by the banking industry are safe. (it's the skimming devices and camera's that put ATM's at risk) 

Thus, considering that HomeATM 3DES encrypts and utilizes DUKPT key management, (and is PCI 2.0 certified with imminent TG-3 certification) I stand by my belief that instead "typing" puts fraudsters at a level playing field, whereby "swiping" with end-to-end encryption puts them at a disadvantage they cannot overcome. 

Take a look at some of the related articles to read more on the subject of online banking insecurity



Reblog this post [with Zemanta]

SPVA Builds Membership to Accelerate Enhanced Security Guidelines

SPVA Builds Membership to Accelerate Enhanced Security Guidelines

Atos Worldline, Heartland Payment Systems, Moneris Solutions,
Radiant Systems, Inc. and Witham Laboratories join SPVA

ATLANTA
– July 20, 2009 – Five electronic payment companies have joined the non-profit Secure POS Vendor Alliance (SPVA), created by Hypercom (NYSE: HYC), Ingenico S.A. (EURONEXT: ING) and VeriFone (NYSE: PAY) to foster widespread compliance of existing security standards to protect cardholder information and defend merchants and acquirers against security breaches.

“Membership in the SPVA reinforces our commitment to advancing security within our industry, enables us to gain first-hand knowledge of current security threats and proactively shape future security guidelines,” said Antoine van Diem, general manager technologies & products, Atos Worldline.

The SPVA’s expertise includes education and a focus on best practices,” said Steven Elefant, executive director of end-to-end encryption at Heartland Payment Systems®. “It is vital that we as stakeholders continue to innovate so that ultimately, we enhance the security of our industry as it grows.”

SPVA members provide the key security elements among consumers, merchants and transaction acquirers and issuers. Members of the SPVA deliver a unique experience with security guidelines, ensure best practice implementation and continue to evolve security enhancements and interoperability required to reduce fraud and lower risk for all participants in card payment transactions. Membership is open to all vendors that develop secure POS payment systems or have products or solutions that interact with secure POS payment devices such as retailers, acquirers and banks.

New members that have signed up with the SPVA since May 2009 include:

Joining as a General Member, Atos Worldline is the European leader in electronic payments and transactions delivering innovative solutions to advance its clients’ businesses. It specialises in end-to end payment services (issuing, acquiring, payment solutions and card processing), services for financial markets as well as CRM and eServices (Internet, voice and mobile solutions). Every year Atos Worldline wins prestigious market awards in recognition of its continuous commitment to research and development of leading edge solutions. Awarded solutions cover expertise in areas such as mobile payments, secure IPTV, online CRM, ticketless solutions. A 100% subsidiary of Atos Origin, Atos Worldline generates annual revenues of around €800 million and employs over 4,800 people in Europe. www.atosworldline.com

Heartland Payment Systems, Inc., a NYSE company trading under the symbol HPY, delivers credit/debit/prepaid card processing, payroll, check management and payments solutions to more than 250,000 business locations nationwide. Heartland is the founding supporter of The Merchant Bill of Rights, a public advocacy initiative that educates merchants about fair credit and debit card processing practices. www.heartlandpaymentsystems.com

Moneris Solutions, one of North America's largest providers of payment solutions. Moneris offers credit, debit, wireless and online payment services for merchants in virtually every industry segment and processes more than 3 billion transactions annually. Through its Ernex division, Moneris offers electronic loyalty and stored-value gift card programs. With more than 350,000 merchant locations, Moneris provides the hardware, software and systems needed to improve business efficiency and manage payments. For more information please visit www.monerisusa.com.

Headquartered in Atlanta, Radiant Systems, Inc. (Nasdaq: RADS) is a global provider of innovative technology to the hospitality and retail industries. For more than two decades, Radiant's point of sale hardware and software solutions have helped to redefine the consumer experience in more than 100,000 restaurants, retail stores, stadiums, parks, arenas, cinemas, convenience stores, fuel centers and other customer-service venues. Radiant has offices in North America, Europe, Asia and Australia. www.radiantsystems.com

A leading provider of specialist payment security evaluation services, Witham Laboratories is accredited to perform evaluations and audits against local and global security standards including all PCI standards (PCI PED, PCI DSS, and PA DSS). With its head office in Melbourne, Australia, Witham Laboratories has clients around the globe and works directly with vendors of POS and PIN entry devices, merchants, and acquirers and card schemes, to assist in their understanding of compliance to the payment standards. Witham Laboratories is an active member of many industry standards bodies, and uses its intimate knowledge of these standards to provide the best possible service and advice to its clients. http://www.withamlabs.com
To learn more about membership opportunities, visit www.spva.org.
 ###

About Secure POS Vendor Alliance
(www.spva.org)                                                                                                    The Secure POS Vendor Alliance (SPVA) is a non-profit organization that works with the multiple stakeholders of the payment value chain. Its aim is to develop an end-to-end security framework and to enhance security elements of payment solutions which protect cardholder information and defend merchants and acquirers against security breaches, while helping reducing fraud and lowering risk for all electronic payment stakeholders.

About Hypercom (www.hypercom.com)                                                                                                             Global payment technology leader Hypercom Corporation delivers a full suite of high security, end-to-end electronic payment products and services. The Company's solutions address the high security electronic transaction needs of banks and other financial institutions, processors, large scale retailers, smaller merchants, quick service restaurants, and users in the transportation, petroleum, healthcare, prepaid, unattended and many other markets. Hypercom solutions enable businesses in more than 100 countries to securely expand their revenues and profits. Hypercom is a founding member of the Secure POS Vendor Alliance (SPVA) and is the second largest provider of electronic payment solutions and services in Western Europe and third largest provider globally.

About Ingenico (www.ingenico.com)
Throughout the world, banks and retailers rely on Ingenico for secure and expedient electronic transaction acceptance. Ingenico solutions leverage proven technology, established standards and unparalleled ergonomics to provide optimal reliability, versatility and usability. This comprehensive range of products is complemented by a global array of services and partnerships, enabling businesses in a number of vertical sectors to accept transactions anywhere their business takes them.
About VeriFone Holdings, Inc. (www.verifone.com)
VeriFone Holdings, Inc. (“VeriFone”) (NYSE: PAY), a global leader in secure electronic payment technologies, provides expertise, solutions and services for today with a migration strategy for tomorrow. VeriFone delivers solutions that add value to the point of sale, resulting in improved merchant retention and the generation of new sources of revenue for its partners and customers. VeriFone solutions are specifically designed to meet the needs of vertical markets including financial, retail, petroleum, government and healthcare.
Safe Harbor Statement under the Private Securities Litigation Reform Act of 1995

This press release includes statements that may constitute forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995, including statements regarding the development, adoption, implementation, interoperability, performance and effectiveness of electronic payments industry security standards, the development of future security standards and guidelines intended to
reduce and prevent fraud and other threats to electronic payment transaction integrity, and lower risk for all participants in card payment transactions. These forward-looking statements are based on current expectations and beliefs and are subject to risks and uncertainties that could cause actual results to differ materially from those described in the forward-looking statements. In particular, factors that could cause actual results to differ materially from those in forward-looking statements include: the ability of the Alliance to attract significant industry membership and participation in its activities and adherence to its policies and guidelines; industry, technological and regulatory changes; industry and market acceptance of and compliance with new security standards and guidelines; compliance with disparate certification requirements and government regulations;  the state of the U.S. and global economies in general and other risks detailed in the companies’ filings with the Securities and Exchange Commission, including the companies' most recent 10-K and subsequent 10-Qs and 8-Ks. Forward-looking statements speak only as of the date made and are not guarantees of future performance. We undertake no obligation to publicly update or revise any forward-looking statements.
Editorial Contacts:
Candace McCaffery/Carol McEntee
SPVA
404.816.2037
678.640.7822 Mobile

candace@cookerly.com                     

National Arbitration Forum Pulling from Business in Minnesota

In a followup to a post I did on July 15th entitled: "Firm that Settles Credit Card Disputes Accused of Fraud" the state of Minnesota announced that the nation's largest arbitration firm, used by Bank of America, JP Morgan Chase, Citigroup, Discover Card, and American Express is pulling out of the business.  So what's Minnesota's backup plan?  How will consumers address issues in the future?  Well, they're on their own now.


American Consumers to Lose Affordable Access to Justice through Nation's Largest Administrator of Consumer Arbitration Disputes

BusinessWire -- The National Arbitration Forum (FORUM), the largest U.S. administrator of consumer arbitrations, today announced that it will voluntarily cease to administer consumer arbitration disputes as of Friday, July 24, 2009, as part of a settlement agreement with the Minnesota Attorney General.

"The National Arbitration Forum remains committed to consumer arbitration as the best and most affordable option for consumers to resolve disputes quickly and efficiently. However, the FORUM lacks the necessary resources to defend against increasing challenges to arbitration on all fronts, including from state Attorneys General and the class action trial bar," said Forthright CEO Mike Kelly. "Mounting legal costs, a challenging economic climate, and increased legislative uncertainty surrounding the future of arbitration have prompted the FORUM to exit the consumer arbitration arena. At this time, the costs of providing consumer arbitration services far exceed the revenue generated. Until Congress resolves the legal and legislative uncertainty the cost is simply too high for users and providers of consumer arbitration."

Legislative proposals pending in both houses of Congress threaten to eliminate pre-dispute arbitration as an effective means of alternative dispute resolution. The Arbitration Fairness Act of 2009 (S. 931/H.R. 1020) would invalidate every pre-dispute contractual arbitration agreement that is part of a consumer, financial or franchise dispute – in effect, every contract. The Fairness in Nursing Home Arbitration Act (S. 512/H.R. 1237) would eliminate pre-dispute mandatory arbitration in all nursing home contracts. Legislation before the House to create a new Consumer Financial Protection Agency (H.R. 3126) addresses arbitration and would give broad regulatory authority to restrict or eliminate all consumer arbitrations.

"The National Arbitration Forum provides fair and affordable access to justice to American consumers regardless of size of their claims. Without access to arbitration, consumer disputes will now be forced into an overcrowded and underfunded legal system, where many consumers who cannot afford attorneys will have to navigate complex court procedures," continued Kelly. "The consequence to American consumers is that there will be no meaningful alternative to costly and unpredictable litigation."

Notably, nothing in the Minnesota Attorney General’s complaint alleges that arbitration proceedings administered by the FORUM are unfair; the fairness of arbitration is ensured by the independence of the neutral arbitrators.

National Arbitration Forum consumer arbitration claims are decided by an independent panel of more than 1,600 highly experienced and impartial legal professionals, including former judges and experienced attorneys. FORUM neutrals are bound to a code of professional ethics, and decide cases outside of any influence from the FORUM or the other parties.

About the National Arbitration Forum (FORUM)
Founded in 1986, the National Arbitration Forum (FORUM) is a world leader in arbitration and mediation services. The FORUM provides accessible civil justice through the recruitment, selection, and management of a highly experienced and distinguished panel of over 1,600 former judges and seasoned lawyers. Now optimized by Forthright, the FORUM is the faster, lower cost, and superior alternative to litigation, that ensures parties receive the same outcomes they would in court. www.adrforum.com





Waitress Who Stole Credit Card Info Gets Probation

Waitress who stole credit card information gets probation - ContraCostaTimes.com

Waitress who stole credit card information gets probation
Daily News Wire Services

A waitress who stole credit card information from customers at a West Los Angeles restaurant has been sentenced to five years probation and fined about $3,000.

April DuBoise, 29, used a "wedge" -- a small skimming device that reads and stores data from a credit card for downloading to a computer -- over a 1 1/2-month period while working in early 2006 at the Hamburger Hamlet restaurant at 2927 Sepulveda Blvd. in West Los Angeles.


DuBoise, who had no previous criminal record, sold the information to an unidentified man, resulting in unauthorized charges being made on credit cards, according to former City Attorney Rocky Delgadillo.

She was initially charged with misdemeanors but eventually pleaded no contest to 34 felony counts of identity theft and credit card fraud, according to Deputy District Attorney James Toro.

Prosecutors had estimated losses of around $28,000, but in court papers filed Thursday, Toro said that figure "appears to be a gross underestimation of the true damage caused by the defendant."  According to the director of operations for the Hamlet Restaurant Group, the case received nationwide publicity, forcing the Hamburger Hamlet to close due to lack of business, costing 50 employees their jobs.





Reblog this post [with Zemanta]

Sunday, July 19, 2009

Online Banking Data Being Fed to the Phishes



BANKS and bank customers face an array of threats to their security as international criminal groups roll out a new generation of viruses, malware, fake websites and sophisticated phishing emails.

Internet banking experts say without co-ordinated global action by governments, financial institutions will have to "give up on the internet" because they are losing their war against hackers and criminal fraudsters.
Editor's Note:  That's what I've been saying for the last 15 months on this blog.  It was (not safe) safer to type your card numbers into a box at a merchant checkout center a year ago than it is today and it's (not safe) safer to do it today than it will be tomorrow. 

It's satisfying to see "Internet Banking Experts" start to to publicly admit there is an inherent weakness in the system. 

HomeATM's device (pictured above) is a secure solution to the phishing, DNS attack and cloned web site threats which permeate the online banking world.  Our solution exactly replicates how one would access their cash at an ATM.   1. You swipe your card, and 2. You Enter your PIN.  It's called 2FA (two-factor-authentication) and it would virtually eliminate phishing overnight.  The Track 2 data is "instantaneously" encrypted upon the swipe of the card and the PIN is also 3DES Encrypted and protected by DUKPT (Derived Unique Key Per Transaction).  Our unique end-to-end encryption methodology provides the most secure authentication and payment application available today. Period. 

Early next week, HomeATM expects to become the only eCommerce Payment company in either hemisphere to be both PCI 2.x Certified and TG-3 certified.  Swipe don't Type.  It's how retailers and consumers have been doing it at brick and mortar locations since the early 80's and it's how it should be done online.  Until now, there wasn't an affordable way to get consumers there very own SwipePIN device.  But HomeATM has gotten the price down to the point that banks could literally give them away...thus empowering their online banking customers to not only log-in securely but pay bills in real-time, send or receive money in real-time and conduct safe, secure online transactions.  I've stated that it is as simple as 1-2-3.  Two are already done.  The bank issues the card, the bank issue the PIN...now the bank can issue the HomeATM Internet POS terminal.   The story continues... 

Almost one-quarter of the entire Australian population has been affected by identity theft crimes, according to a recent survey by Veda Advantage and that number keeps growing each year.   "Last year some 450,000 Australians were the victims of fraud," NSW Attorney-General John Hatzistergos said last weekend as he announced new laws that effectively duplicate Queensland's cyber crime laws.

"Nearly a billion dollars was taken from people and confiscated by criminals, using a variety of different techniques, trading in people's personal information, such as passwords, pin numbers, names and addresses.


The state based approach to the problem will not work says Professor Bill Caelli from Queensland University of technology's Information Security Institute. Prof Caelli says only co-ordinated global action by governments can secure the net.
Speaking to the Sunday Mail from a major IT conference in Paris where the issue of securing the net is high on the agenda, Prof Caelli claimed "banks were simply not capable of providing secure internet banking."
There is a big discussion happening globally about web services such as internet banking. The question is, "Can you create large-scale secure transaction systems on the web – and the answer is coming back as no."

Already this year, two of Australia's biggest banks have reported significant attacks on their internet banking portals. Both attacks came after significant investments by the banks to upgrade their online banking platforms.

"The criminals tend to target one bank and when that institution shuts them down they move to another bank so it goes in circles," said Gary Gill, head of forensics at KPMG.

Australia's biggest bank, the Commonwealth Bank, reported that a malicious attack had probably contributed to its banking website, Netbank, crashing on the busiest days of the year – the two days before the end of the financial year.

Steve Batten, the media spokesman for the Commonwealth Bank, said that Netbank was designed to handle 13,000 customers online concurrently.   Last Monday, 18,500 customers were logging in concurrently and 1.59 million hits were registered in the 24-hour period.  Mr Batten said that the bank suspected that some of that traffic was malicious.

In February ANZ Bank reported a sophisticated scam that led to a fake web page appearing to customers after they logged in to the ANZ internet banking site.







Reblog this post [with Zemanta]

Saturday, July 18, 2009

Millions Stolen as Scam Put's Banks in One Helluva SMS



By Lavern de Vries



Gauteng police are working with Vodacom to trace the victims of a
multimillion-rand SMS banking authentication scam, described by a top
security firm as the first of its kind.



Police spokesperson Superintendent Lungelo Dlamini said on Thursday
that members of the Joburg Commercial Crimes Unit were liaising with
commercial crime units across the country to determine how many people
had been affected by the rip-off.



Security experts have billed the scam as a world first.








"This incident is, as far as we know, a world first, which only
enforces our opinion that SMS-based authentication, while, slightly
more secure than the simple username-password combos, is, outdated, and
in our fast-paced and highly evolving cyberworld no longer sufficient
by itself."



Costin Raiu, chief security expert at
Kaspersky Lab, suggested that banks deploy better and more advanced
technology to stay ahead of criminals.



"This incident is, as far as we know, a world first, which only
enforces our opinion that SMS-based authentication, while, slightly
more secure than the simple username-password combos, is, outdated, and
in our fast-paced and highly evolving cyberworld no longer sufficient
by itself."



He advised readers to check their online accounts often and notify the bank immediately if suspicious transactions are found.



Banks should be able to recover clients' money if they were notified promptly, Raiu said.



It is not known which banks were involved in the scam.



Dlamini would not be drawn on how much money was allegedly siphoned by
a Vodacom engineer and his accomplice through an elaborate scam
involving the blocking and delaying of SMS banking alerts to Vodacom
clients.



A Gauteng newspaper had reported that the Vodacom engineer and his
partner allegedly stole R2,4-million. Other media reports said that
when the pair appeared in the Johannesburg Commercial Crimes Court on
Monday, the State prosecutor received another docket for another R3,3m.



Dlamini said the docket was with the court and police would not comment on the issue.



On Tuesday Vodacom released an internal letter informing employees of
the scam and asking them to "convey the facts to our families, friends
and customers".



Signed and sent out by Vodacom chief communications manager Dot Field,
it explained that the alleged fraud was committed with the help of
fraudulently created temporary dual SIMs.



A customer's internet bank account would be logged into, and the
one-time password from the bank would be sent to the temporary dual
SIM, which enabled the transfer of money out of the customer's internet
bank account to their own account. When the transaction was successful,
the temporary dual SIM would be deleted.



The email also implied that customers would have to compromise their
PIN and password via phishing (when fraudsters get hold of sensitive
information such as usernames, password and credit card details by
masquerading as a trustworthy entity) for this type of fraud to occur.



Dlamini said police suspected a syndicate was behind the scam, and more arrests were expected.










    • This article was originally published on page 1 of The Star on July 17, 2009







Reblog this post [with Zemanta]

Almost 90% Don't Trust/Wouldn't Use Mobile Banking







We can see here that almost 90% of Smartphone owners said that they didn't trust mobile banking security 
or saw noneed to manage their finances from a mobile device.

Source: Compete.com Blog

Mob Steals Data - Lexis-Nexis Breach Linked to Bonanno Crime Family

Lexis-Nexis Breach Linked to Crime Family
Analyst: 'Days of Amateurs Committing Breaches are Well Behind Us'

Excerpts from BankInfoSecurity.com

How it Happened


According to the indictment, Lee Klein, one of eleven people charged in the indictment,  worked for the criminal "crew" ofThomas Fiore, an associate of the Bonanno organized crime family.

The indictment alleges that Klein illegally used "informationobtained from computer databases in order to acquire identificationinformation regarding potential victims of extortion" and peoplesuspected by Fiore's criminal organization of being involved with lawenforcement.

Klein allegedly provided Fiore with "corporation names,addresses and account numbers to facilitate the manufacture andnegotiation of counterfeit checks."  In addition, the indictment alleges that members of thecriminal crew used threats of force and violence, including conspiracyto commit murder, to advance the objectives of the enterprise.

Security Experts React to Mob Ties


"Althoughsensational in its headline 'Mob Steals Data,' we perhaps should focuson how the data was accessed and what was contained in theinformation," says information security and privacy expert Kevin Nixon,CISSP, CISM, CGEIT.

"We are experiencing some most extraordinary eventsrelated to global businesses, economics and confidential informationmovement via the merger and acquisition of companies, networks,databases and entire systems."

Analyst Nick Holland sees this case is indicative of the waythat data breaches are becoming the work of organized crime syndicates,both overseas and domestically. "The relative ease with which sensitivedata can be acquired by either high tech (malware) or low tech (placinga criminal within an organization) means makes it attractive fororganized criminals that have the resources to execute such attacks,"says Holland, of the Aite Group.

The Bonanno crime family was making money from the sale ofunauthorized identification documents (including social securitynumbers and health and life insurance applications). "If the mafiaconsiders that selling sensitive information is a legitimate line ofbusiness, then clearly the days of just amateurs committing breachesare well behind us," Holland observes.

Read the Article in it's Entirety


Reblog this post [with Zemanta]

Redecard's Internet Processing being Probed



Brazilian antitrust regulators areinvestigating Redecard SA, the local processor of payments forMastercard Inc., after the national internet association saidthe company impeded competition with conditions on onlinepayments.  Sao Paulo-based Redecard changed its contracts to requireonline payment systems such as EBay Inc.’s PayPal unit toprovide lists of clients and use its Komerci platform to processtransactions, the antitrust arm of Brazil’s Justice Ministrysaid in an e-mailed statement late yesterday. The antitrust bodybanned the contract changes as a preventive measure, accordingto the statement.  Redecard denied any wrongdoing and said it will cooperatewith authorities, according to a regulatory filing.


By Guillermo Parra-Bernal

SAO PAULO, July 17 (Reuters) - The antitrust unit of Brazil's Justice Ministry said it has opened an investigation into credit card operator Redecard (RDCD3.SA), sending the company's shares down 2.56 percent.   The Economic Law Secretariat at the Justice Ministry said Redecard would be investigated for imposing terms on online payments that might hamper free competition.

The probe comes as Brazil, Latin America's most populous country, moves to heighten competition in the $190 billion credit card industry, where customers and merchants complain about exorbitant costs and a dearth of options.

The Brazilian Internet Association, an industry guild based in Sao Paulo, asked regulators to investigate whether Redecard modified contractual terms to have online payment processors provide lists of clients.  Under the changes, Redecard would require Internet companies to provide a list with their customers and online stores.

As a preventive measure, the secretariat, known as SDE, banned the contractual changes, which were to take effect on Aug. 1. The association said the use of the MasterCard (MA.N) brand by Internet-based companies such as PayPal and Mercado Livre in Brazil would have become more restrictive, keeping consumer fees from falling.

Redecard, which has an exclusive contract with MasterCard, authorizes merchants, issuers and transactions and acts as a clearinghouse.



Reblog this post [with Zemanta]

Friday, July 17, 2009

UK Article Says Time To PIN Down Banks in Fraud Battle


It's time to PIN down the banks in the prolonged battle against card fraud

Despite chip and pin technology becoming compulsory in 2006, figures released by the UK payments association Apacs show that last year, phone, internet and mail order card fraud increased to £300m and counterfeit fraud to £170m. However, banks often take a hard line when customers try to obtain refunds for fraudulent transactions.

Typically, banks claim the customer acted irresponsibly and so is not entitled to a refund. For example, in a case I recently dealt with, a bank refused to accept a customer had reported her card stolen until she produced mobile phone records proving she had placed the call. In light of this attitude, how can you get your money back?

First, you should trigger the bank's formal complaints procedure. Point out that under paragraph 12.12 of The Banking Code, banks must refund all funds withdrawn fraudulently where the customer retains the card, and all but £50 where a card is lost or stolen. You can access The Banking Code at http://www.bankingcode.org.uk/pdfdocs/PERSONAL_CODE_2008.PDF

There is one exception: where a customer has acted fraudulently or without reasonable care. So make sure you do not write down your pin or tell anyone what it is. Also, be quick to report lost or stolen cards or fraudulent transactions. Build up a paper trail – keep copies of letters and emails, and write down details of telephone calls. The more accurate the detail you can provide to the bank, the better.

If this doesn't work, you have six months to contact the Financial Ombudsman Service for an independent adjudication. This is a free service utilised by filling out a simple form. It can result in a negotiated settlement, or a decision by the ombudsman to which the bank will adhere but which does not bind you. For guidance on how the ombudsman may approach your case, see http://tinyurl.com/ ombudsmancashmachine

Finally, you can go to court. If your claim is for £5,000 or less, use the small claims process. It is designed to be used without the need for lawyers and results in a county court judgment.

http://www.guardian.co.uk/money/2009/jul/18/credit-card-fraud-refund-stolen-citizens-advice

Billeo Study on Online Bill Payment Behavior



Billeo study reveals consumer online bill payment behavior

Santa Clara, Calif., July 17, 2009 -- In an effort to retain some financial control in uncertain economic times, consumers are using tools to stay on top of bill payments. Billeo, Inc., the company that gives consumers unprecedented choice, control and convenience when paying bills online, conducted a 2008 customer behavior study focusing on online bill payment trends. The results show that consumers are utilizing free online tools to track, manage and organize their transactions. Three quarters of those who pay bills and shop online save electronic receipts of their transactions and identified ease of “tracking online purchases and payments” as a top motivator.

“The most important thing we glean from this study is that a growing number of consumers are not only more comfortable doing a variety of transactions online, but they prefer it,” said Murali Subbarao, founder & CEO of Billeo, Inc. “We believe that the new economic situation will make them more savvy about how and when they spend their money and how they manage and store their online shopping and bill payment information. In uncertain times, they have the ability to exercise more control over how and when they pay bills, as well as how they track and evaluate expenses. To stay in control, consumers simply need to have some very basic online tools.”

Billeo’s survey revealed that more than half of people who transact online never pay late fees.

The study found that more than 31 percent of those who transact online are baby boomers, and more than 58 percent are over the age of 45. The study also showed that more than 56 percent of those who transact online have attended college with more than half acquiring a graduate degree. In terms of credit cards, 90 percent have credit cards and 47 percent carry no debt on their cards.
“Currently, more than two-thirds of online consumers pay at least one of their monthly bills with a credit or debit card. As the growth rate for non-card based online bill payment slows, Aite Group believes that banks will find their highest rate of growth in online bill pay from card-based payers,” said Ron Shevlin, Senior Analyst for Aite Group. “There is an opportunity for banks and billers to acquire an attractive set of consumers - consumers that are relatively affluent, are a low credit risk and actively engaged and loyal to the firms with which they do business.”

In other research, Billeo found that credit card bills are the most popular bill paid online by consumers in terms of number of bills paid. Other categories in order of number of bills paid online were: Utilities, Telephone, Cable/Satellite Television, Wireless, and Insurance. In terms of average transaction amount, credit card bills were the highest with $602 per bill. Other categories in order of transaction amount include: Insurance (with $319), Utilities (with $217), Cable/Satellite Television (with $162), Wireless (with $159) and Telephone (with $143).

Billeo is a popular, secure web-based tool that streamlines the online transaction process by helping consumers pay their bills and shop online using their checking account, credit cards and several alternative methods. Billeo offers one-step password log-on to one-click completion of online shopping and bill pay forms. With Billeo, payments are directed to billing company and shopping websites, payments are instantaneous, and electronic receipts are automatically captured, saved and filed. Additionally, the Billeo Biller Directory provides links to over 7,000 companies that accept online bill payment across 26 categories, including utility, cable and credit card companies. It is the largest Biller Directory and defacto industry standard.

Splendid Search, a tool developed by Billeo to automatically save and categorize electronic copies of bill payment and shopping receipts, is available now to consumers. Splendid Search allows the search of financial transaction records by the retail store or company name, amount paid, credit card used, or even by date. Whether you want to save all of the records around the online booking of an airline ticket, hotel or car, are looking at all online transactions for a month, want to print a receipt for a rebate or in-store return, or want to file a warranty claim, Billeo automatically saves the full receipt, categorizes it and allows you to locate the right record in seconds. It takes all the work, frustration and clutter out of paying bills and shopping online.

Billeo’s award-winning toolbar for managing and tracking bill payments and online purchases recently received the Editor’s Choice award and a Four Star rating from PC Magazine, and is available at no charge at http://www.billeo.com/page/homepage.jsp?sitename=Billeo .

Billeo has a close working relationship with Visa and Discover Network and the service is featured at over 40 of the top US based card issuers, including: Bank of America, Wells Fargo, Wachovia, Chase, and Target.

About Billeo, Inc.


Billeo gives consumers a fast, easy and intelligent way to exercise choice and control over their online purchases and payments. Billeo functions as the catalyst to make online purchases and bill paying as easy and financially rewarding as possible. Billeo was founded by experts from the EBPP, card issuer, banking, ecommerce and technology industries. Over 40 banks, 6 of the top ten card issuers and over 7,000 companies across 26 categories are part of the trusted Billeo network.

Source: Company press release. 


Reblog this post [with Zemanta]

APAX Expanding to Latin America


APAX Global Payment expanding services to Latin America & Caribbean

Panama City, July 17, 2009 -- After servicing the Latin American and Caribbean market from its London office for several years, on the 1st of July, APAX opened up an office in Panama City to facilitate the huge demand for its credit card processing and electronic payment products from merchants in that area. The Panama office is specialized in offering card processing and electronic payment solutions to merchants selling mostly digital goods online in that region of the world.

APAX CEO Peter Arnold states, "APAX has a worldwide credit card processing network that operates through our processing banks to provide merchants with reliable credit card processing services. We have become one of the most competitive card processing companies in the industry without compromising quality. Our organization is also a leading provider of electronic payment processing services (e.g., checks, EFT) to corporations and fulfillment companies. Within the last five years we have seen a steadily increasing demand for our products especially from online merchants of various industries. Panama and Costa Rica have become a hub for those merchants. It is a logical step for APAX to open an office in that region in order to better service our customers."

APAX Global Payment & Technologies AG is one of the leading international providers of electronic payment and risk management solutions. APAX is dedicated to serving cardholders and their merchants by facilitating payment anywhere and anytime. Worldwide, we support processing for more than 100,000 cardholders and their merchants from various industries a day. APAX provides accounts and credit card services both for business and private customers. For further information, please contact www.e-apax.com .

This press release was issued through 24-7PressRelease.com. For further information, visithttp://www.24-7pressrelease.com .

Source: Company press release.

Euronet Rebrands as ePay




Euronet launches new name, brand identity for prepaid division

London, July 17, 2009 -- Euronet Worldwide, Inc. (“Euronet”) (NASDAQ: EEFT), a leading electronic payments distributor, today announced the rebranding of its global Prepaid Division under the name epay. Previously operating under six different names worldwide, the change reinforces the distinct, but related strength of Euronet’s Prepaid subsidiaries across all regions. The new identity will provide the Division with a worldwide retail brand that is known for quality service and consistent products.

Currently, Euronet’s Prepaid Division is one of the largest international distributors of prepaid mobile airtime. The establishment of a single brand signifies the division’s transformation from a prepaid mobile top-up distributor to a leading provider of payment services and technology. The credibility and success of Euronet’s individual brands provide a strong platform for the newly created global brand to ensure the Division remains an exciting and rewarding partner for service providers and retailers worldwide.

The new epay logo design embraces existing strong elements from the logos of its parent company and sister subsidiaries to create one distinct, yet synergistic brand that stands for professional, innovative and spirited values. The design is channeled toward creating a visual impact in a crowded retail space.

“Our new name, epay, now unites all of our best-in-class companies under one brand to further promote our position as the leading worldwide payment and cash collection network provider,” said Gareth Gumbley, Euronet senior vice president and managing director, epay Division. “Just as our business strategy has evolved over the years to meet the needs of our customers, so must our brands. The new brand identity is a reflection of that evolution to deliver brand leadership and enhanced value to our customers. It brings together our successful elements — local market knowledge, operational expertise and international distribution reach — required by multinational retailers and global consumer brands."

Several Euronet prepaid subsidiaries already carry the epay name. The remaining companies: PaySpot, Telerecarga, Movilcarga, Brodos and Transact will now adopt the new branding. Working with some of the world’s largest retailers and consumer brands, Euronet’s prepaid division has experienced tremendous success within the prepaid industry. The new identity affirms the company's commitment to leading innovation in the ‘e’ payment market while providing a platform for further growth and expansion.

About epay

epay, a Division of Euronet Worldwide, Inc. (NASDAQ: EEFT), is a global business with a retail network of approximately 227,000 locations across a number of international markets including the UK, Germany, Spain, Italy, Australia, New Zealand, USA, Poland, Romania, Austria, Switzerland and Ireland. epay enables service providers to deliver electronic payment products and services to consumers through an extensive worldwide retail network. epay’s proprietary payment technology is backed by a cash collection service that manages the payment of funds back to the service providers and a range of marketing solutions to assist both the retailer and service provider to maximize their sales opportunities.

In 2008 epay processed over 700 million payment transactions with a total face value of $11 billion. epay’s product portfolio includes top-up or recharge services for prepaid mobile airtime, prepaid debit cards and e-wallets; payment services for bills, road tolls and money transfer; and marketing and distribution services for gift cards, digital content and transport tickets. epay’s commitment to customers is supported by a strong roadmap of innovative new e-payment products to bring to market. epay’s corporate headquarters is located in London, United Kingdom. For more information, please visit the company’s Web site www.epayworldwide.com .

About Euronet Worldwide, Inc.

Euronet Worldwide is an industry leader in processing secure electronic financial transactions. The Company offers payment and transaction processing solutions to financial institutions, mobile operators and retailers which include comprehensive ATM, POS and card outsourcing services; card issuing and merchant acquiring services; software solutions; consumer money transfer and bill payment services; and electronic distribution for prepaid mobile airtime and other prepaid products. Euronet operates and processes transactions from 42 countries.


Euronet's global payment network is extensive — including 9,205 ATMs, approximately 56,000 EFT POS terminals and a growing portfolio of outsourced debit and credit card services which are under management in 24 countries; card software solutions; a prepaid processing network of approximately 421,000 point-of-sale terminals across approximately 227,000 retailer locations in 20 countries; and a consumer-to-consumer money transfer network of approximately 77,100 locations serving more than 100 countries. With corporate headquarters in Leawood, Kansas, USA, and 35 worldwide offices, Euronet serves clients in approximately 140 countries. For more information, please visit the Company's Web site at www.euronetworldwide.com .

Source: Company press release.
Reblog this post [with Zemanta]

Disqus for ePayment News