• No results found

Card fraud

In document Future Trends in Cards and Payments (Page 50-69)

This section defines the various types of card fraud that are committed in the Western European region, including card-not-present, counterfeit, lost and stolen, mail non-receipt and fraud following identity theft.

Types of card fraud

Card-not-present fraud (CNP)

Card-not-present fraud (CNP) is fraud committed over the Internet or via channels such as mail order or the telephone (mail order and telephone order are often referred to as MoTo), where the cardholder is not actually present when the payment is processed. Consequently:

Merchants are unable to check that the individual making the purchase is actually in possession of the card. Nor can they check the physical security features of the card to determine if it is genuine, such as the signature or PIN;

Without a signature or PIN it is harder to confirm if the individual making the purchase is actually the genuine cardholder;

Card issuers cannot guarantee that the information provided in a card-not-present environment relates to the genuine cardholder.

In some instances card-not-present fraud is committed following the theft of a card. In other instances, however, it may be committed following the loss/theft of a receipt or other document carrying enough information about the cardholder for a purchase to be made. Card-not-present fraud can also be committed following a security breach of a merchant’s website (where it has been ‘hacked’). However, while it is high profile, due to press interest, this form of fraud is actually rare.

51

To protect themselves from card-not-present fraud consumers are advised to keep their cards safe, not to write down their card details and to discard receipts only once they have been ripped up or shredded. They are also advised to check every statement thoroughly. In circumstances where the card has not actually been stolen, a consumer will only find out that they have been a victim of card-not-present fraud when they check their statement.

Card-not-present fraud is being tackled by a number of initiatives

Fraud associated with online card-not-present transactions is currently being tackled in a number of ways:

Online card scheme security initiatives – such as Visa’s Verified by Visa and MasterCard’s SecureCode. These initiatives require that a cardholder making an online purchase enters a PIN as well as their account details and personal information. Although Verified by Visa and MasterCard SecureCode have not yet achieved universal implementation among merchants or wide understanding among consumers, both implementation and understanding is improving. Visa, for example, has revealed that 4,000 merchants are enrolled in the program worldwide.

Address verification systems – Systems that confirm that the address that has been supplied to the merchant matches the cardholder’s billing address.

Card Security Code (CSC) – A 3-digit code that features only on cards and not on statements or receipts. Merchants can therefore be provided with an extra level of assurance that the buyer is actually in possession of the card being used to make the purchase. Visa refers to the CSC as the Card Verification Value 2 (CVC2), MasterCard refers to it as the Card Validation Code (CVC2) and American Express refers to it as the Card Identification Code (CIC).

52

Counterfeit fraud

Counterfeit fraud has not traditionally been the most common form of credit card fraud. However, in recent years counterfeit fraud, often referred to as ‘skimming’, has become much more significant. Counterfeit fraud or skimming is ultimately the transferal of card data from the legitimate card to a counterfeit or cloned version. In most cases fraudsters skim card details by copying them from the magnetic stripe using a special device. The information is then transferred to the magnetic stripe of another card, which is then used as if it were the legitimate card. The counterfeit card can be used until the real cardholder cancels it.

To carry out counterfeit fraud criminals must obtain or produce cards on to which new details can be added. Intact cards that have expired and been thrown away by their owners are often valuable for this purpose. Fraudsters heat the card so that the embossed numbers can be flattened and then emboss new numbers onto the card.

They may also add new information to the card’s magnetic stripe or damage it so that it has to be processed manually.

Certain countries are skimming hotspots

Certain countries and certain locations are skimming ‘hotspots’. In 2003 it emerged that Commonwealth Bank had reissued cards used in Jakarta Airport and Citibank had reissued cards held by individuals who had stayed at a Marriott airport hotel in the US. Countries including Indonesia, Malaysia, Taiwan and Thailand are recognized as skimming ‘hotspots’. Skimming activities are largely carried out with the involvement of international crime syndicates, a characteristic that makes the crime very difficult to investigate. In most instances individuals with no knowledge of those leading the syndicate skim the cards while working at retail outlets. They then sell the information on to those who produce the counterfeit cards. Individuals, who again have no knowledge of those leading the syndicate, are then provided with the counterfeit cards and are instructed to use them to make a number of large purchases as quickly as possible. Items purchased are commonly resold quickly.

53

Skimming is becoming more sophisticated

Skimming has recently become more common as the equipment required to commit the crime has become cheaper and less conspicuous. Until recently, skimming devices were expensive and bulky and had to be hidden under the counter in a retail outlet.

Devices are now much cheaper, often costing as little as USD300, are widely available on the Internet and are smaller than a mobile phone. Fraudsters are now using more sophisticated means to counterfeit cards. These techniques include:

The interception of data after it has been sent from the merchant en route to the merchant acquirer. Fraudsters located at the merchant’s premises intercept the signals and record them. They are subsequently decoded and attached to a counterfeit card.

The replacement of legitimate card payment terminals with devices that look identical but which are able to store card details on an additional chip. Criminals break into a retail premises to switch the legitimate payment terminal with one of their own. They then return a few days later to replace their payment terminal with the terminal that was originally there or to download the stored details on to a laptop computer. Details are then instantaneously transferred to another location where they are attached to blank cards ready for use by fraudsters.

Counterfeit fraud is currently being tackled by the incorporation of chips into credit cards, which make the cards much harder to copy. Consumers are also now advised not to let their card leave their sight when using it to pay in a merchant’s premises or restaurant. In some instances restaurants are responding to this by introducing portable payment devices, allowing cards to be swiped at the cardholder’s table. Use of these devices is, however, uncommon.

54

Lost and stolen card fraud

Lost and stolen card fraud occurs on cards that are later reported lost or stolen by the legitimate cardholder. Lost and stolen card fraud is often the most difficult form of fraud to tackle. Minimizing the loss incurred as a result of lost and stolen card fraud also depends on how quickly the cardholder informs the issuer that their card is missing. Despite repeated warnings, it is believed that many cardholders do not take adequate care of their cards, for example by often leaving their cards unattended, and do not notify their card issuer immediately once they notice that their card is missing.

Lost and stolen fraud is being tackled by the introduction of PIN-based payment systems. Without entering a PIN it will ultimately become impossible to complete a transaction. ‘Hot files’ also exist that list lost and stolen cards. When a card is used to make a purchase it is automatically checked against those cards in the file. If the card’s details match any of those on file an alert is given and the transaction is declined. Finally, many card issuers now employ systems that use neural network systems to generate an alert if a card is being used in a way that does not fit with the legitimate cardholder’s usual spending behavior. Once such an alert has been generated the legitimate cardholder is contacted to confirm that they are still in possession of the card. If they are not, the card is cancelled. The most widely implemented fraud detection system software is Falcon.

Mail non-receipt fraud

Mail non-receipt fraud occurs following the theft of a card while in transit, that is, once it has been sent out by the card issuer but before receipt by the legitimate cardholder. This fraud can be perpetuated by corrupt postal workers, when the cardholder moves address and forgets the card issuer or when the card is posted into the wrong letterbox (common in communal properties such as flats or share houses).

Some card issuers are currently tackling mail non-receipt fraud by mailing cards to cardholders in an ‘inactive’ state. Once received the cardholder is required to call the

55

issuer to confirm receipt and to pass through a verification process based on date of birth, mother’s maiden name etc. Assuming the verification is successful the card is activated. Those institutions that have installed post receipt card activation programs report that they have resulted in a significant fall in losses incurred as a result of mail non-receipt fraud. Not all banks operate card activation systems, however, as they can sometimes be difficult to integrate with existing systems.

Fraud following identity theft

Identity fraud relating to a credit card can occur if a fraudster is able to obtain enough personal information about another individual to take out a credit card agreement in his/her name or to gain access to their credit card account. In the former instance, fraudsters may steal or forge utility bills, bank statements and other important documents and use them to take out a credit card in another individual’s name.

Documents used may be stolen from a letterbox or from a dustbin, a technique that has coined the phase ‘dumpster diving’. In the latter instance, fraudsters may use the same documents to convince the card issuer that they are the real cardholder and that they have moved address. They ask for their address to be changed and in subsequent phone calls inform the card issuer that their card has been lost. A new card is sent out to the new address, straight into the possession of the fraudster.

Fraud following identity theft is difficult to bring under control as tackling it largely depends on the care that consumers show towards their personal documents.

Individuals usually do not discover that their identity has been stolen until they make a credit application, which is turned down, or until they check their credit record (something that individuals seldom do). Victims then have to begin the long process of rebuilding their credit record.

56

An investigation by FTC shows how fraudsters use information from identity theft

An investigation conducted by the Federal Trade Commission (FTC) in 2003 provides an interesting insight into the use of information stolen through identity theft. In 60%

of identity theft cases stolen information was used to access an individual’s credit card account. This was by far the most common consequence of identity theft. In 32%

of cases where identity theft resulted in the opening of new accounts, accounts opened included a credit card account and 20% of cases included a loan account.

Cross-border fraud

A high percentage of card fraud is cross-border, in the sense that it is committed outside the country of issuance. According to Visa, 75% of counterfeit cards used in Australia were issued to cardholders resident in other countries. Similarly, according to the Nilson report, 50% of card fraud committed in Europe is committed outside the country of card issuance. In contrast, only 12% of card transaction volumes are outside the cardholder’s home country. Fraudsters commonly use counterfeit or stolen cards outside the country of issuance to lessen the chances of detection and to make it harder for police to track those running the scam. It is also true that the Internet has been a boon for cross-border fraud, allowing fraudsters to purchase goods from anywhere in the world with ease and anonymity. In response to the threat of cross-border fraud a number of online merchants have recently begun to apply special restrictions on these types of transaction or even to enforce outright bans on purchases from some countries.

Fraud at cash machines

Fraud committed at cash machines is not a type of card fraud but a place where fraud is committed. Fraud at cash machines can be committed in a number of ways:

Shoulder surfing – where a fraudster is able to look over the shoulder of an individual legitimately using a cash machine. They note the PIN and then steal the

57

card using it before the victim has realized that the card has been stolen and has had opportunity to report the theft;

Card retaining devices – where fraudsters fit a device to a cash machine that ensures that an individual using the machine has his/her card retained. The fraudster then approaches the individual offering to help and asking that they re-enter their PIN. This fails to return the card and the victim gives up. Once the victim has left the cash machine the fraudster retrieves the card;

Skimming – where fraudsters insert a device in a cash machine that enables them to collect enough details to make a copy of a card. They may also place a hidden camera on the cash machine to film victims as they enter their PIN;

Theft of a PIN – where an individual writes down their PIN and keeps the information in their wallet or purse along with their card. Fraud can occur if the wallet or purse is lost or stolen.

Fraud at cash machines is being tackled by design improvements that make cash machines harder to tamper with. Cash machine operators are also installing video cameras near machines, marking out areas where only the cash machine user should stand and using cash machine screens to post security awareness messages.

Prevalent fraud types

Of the different fraud types, counterfeit fraud, lost and stolen fraud and CNP clearly prevail in Europe. Identity theft and mail non-receipt are insignificant. According to Visa EU, counterfeit fraud, lost and stolen card fraud and CNP fraud on Visa-issued cards, as a percentage of all fraud, amounted to 35%, 31% and 26% respectively in 2003.

58

Figure 21: Types of fraud and losses to fraud in Europe and the US, 2003

CNP

Notes: The data relates to issued fraud. All data except UK are Business Insights estimates.

Source: Business Insights, APACS Business Insights Ltd

59

Combating card fraud – EMV is expected to reduce counterfeit fraud The introduction of EMV-compliant chip cards is one of the central components in the fight against card fraud in the European region, as well as elsewhere in the world. EMV is the industry abbreviation for the consortium of three card schemes - Europay, MasterCard and Visa. These aforementioned card schemes created a joint working group in 1994, sponsoring the global standard for electronic transactions. EMV also refers to the international technical specifications for bank cards produced by that consortium and adopted by all three schemes.

The consortium’s aim is to maintain a common standard as individual national markets introduce chip-card technologies, thus ensuring that there is interoperability between chip cards and payment terminals around the world, regardless of the terminal manufacturer, the card issuer or the country of issuance. Chip cards and terminals that meet this common standard are referred to as being EMV-compliant.

The adoption of the EMV standard is certainly not a simple task. It involves changes in the whole electronic payment chain. For instance, bank cards will have to be reissued and points of acceptance terminals – ATMs and EFTPOS – will have to be updated and, in certain cases, replaced. Clearly, migrating to EMV involves huge investments for different parties. For example, the investment required to implement the chip and PIN system is expected to cost UK banks and retailers approximately £1.1 billion.

The heaviest share of the burden is falling on the card-issuing banks, which face the cost of reissuing all credit, debit and charge cards, and upgrading the POS terminals leased to retailers and ATMs. Despite the work being done by credit card schemes, it seems that a common attitude among issuers is that EMV migration is a necessary but expensive evil forced upon them by the card companies in response to increasing fraud.

It is easy to see why such an attitude has prevented a wider global acceptance of EMV standards so far, especially in the markets where counterfeit card fraud presents less of a problem to the players concerned.

60

A big hurdle facing the EMV consortium is updating merchant acceptance terminals, as high costs associated with this process prevent many smaller retailers from implementing such an upgrade. This presents a major issue as, until all merchants have updated their terminals to read chip cards, magnetic stripes will still have to be used for transactions and counterfeit fraud will still be possible, thereby defeating the whole object of the EMV program.

Moreover, in order for the whole process to achieve the desired success, it is not only merchants who have to adopt the maximum collaboration approach. Visa and MasterCard’s competitors – JCB, Discover, American Express and Diners Club – have all been faced with the necessity of the EMV compliance for their own smart card programs.

Migration to EMV in Europe

In Europe all of the cards markets are making the transfer to chip cards under EMV.

Even markets that have had long had chip cards, such as France, must make the transition, as the type of chip cards currently used in these markets do not meet EMV specifications.

Card schemes Visa and MasterCard are maintaining a target of 2008 for full migration to EMV-compliant technologies in the European region. In January 2005 the liability shift has kicked in, a measure the card schemes have introduced to encourage EMV migration among issuing banks and retailers. Card-issuing banks assume liability for fraud committed when a non-chip-compliant card is used. Retailers are liable for fraud if a chip-compliant card is used at a non-chip-compliant payment terminal. Hence, retailers that have not converted their PoS systems to EMV have become liable for the cost incurred by fraudulent transactions on their premises.

Some European countries have been more aggressive towards EMV migration than others. Among the Big Five, the UK is the only country that looks set to complete the

Some European countries have been more aggressive towards EMV migration than others. Among the Big Five, the UK is the only country that looks set to complete the

In document Future Trends in Cards and Payments (Page 50-69)

Related documents