Wednesday, July 12, 2023

EMV: It's Always Been About Reducing Fraud


Silicon Valley Bank Plans to Expand Chip Card Program

Mikeknsah: Information Security News Update!

Repost:

The combined global effect of the identity theft fraudsters that swindled at least $9 million from 8,000 victims in a period of 15 years (Atlanta, GA) and a 16 month period ID theft crime costing over $13 million across Africa, Asia, Europe, the Middle-East, and the United States (Queens, NY) may cause those opposing the Europay, MasterCard, Visa (EMV) standard to rethink their stance on the chip and PIN card technology. According to Pradeep Moudgal, who oversees global cards and merchant services for Silicon Valley Bank (SVB) in California, chip and PIN card technology migration by U.S. financial institutions will be expensive. However, considering the cost already inflicted on the accountholders and the issuing banks, what more evidence is needed to convince the U.S. card issuers to support EMV and implement chip and PIN. No one knows.  

The vast majority of ID theft crimes are attributed to the magnetic stripes on the back of the cards, says Avivah Litan, a Gartner analyst. This Achilles heel of the global card industry could finally be eliminated with the implementation of chip and PIN card technology. As the first U.S. commercial bank to implement EMV, SVB is proving that fact as it rolled out EMV cards with its elite business cardholders. Following that will be SVB’s more affluent clienteles who travel overseas.

The embarrassment of card rejection overseas and increased global ID security vulnerability, in the long run, far outweigh the cost of chip and PIN card technology implementation. Moreover, the reduction of ID theft fraud, as evidenced in the U.K. and some parts of Europe and Asia, should be a strong motivating factor to those in the U.S. still gauging the cost and benefits of the new technology. If chip and PIN could become a positive tool to mitigate cybercrime, financial fraud, identity theft, information security threats, etc., why not give it a shot. Any takers?



Saturday, September 21, 2019

Stopping Fraud Before It Happens Saves Organizations A Ton Of Headache

Mikeknsah: Information Security News Update!


Stopping Fraud Before It Happens Saves Organizations the Headache of Cleanup Costs.

According to ACEF Staff writers, "Anti-fraud professionals know that while it’s best to catch fraud as soon as possible, it’s even better to stop fraud before it happens — which is why active fraud prevention is a critical part of anti-fraud strategies for organizations of any size."
With the advent of cyber fraud gaining so much press attention globally, the banking industry, in particular, is better served by paying great attention to what the unethical hackers are doing behind the scenes and who is their biggest target. Unfortunately, globalization has made the job of the fraudsters much easier than ever, and near impossible to detect. Even the best and robust network technologies are having challenges preventing the persistent attackers from gaining access into the banks core database to do exploits.
Therefore, the best approach to avoid spending millions of dollars to clean up the impact of fraud rests on doing whatever it takes to prevent it from happening at all. One of the best ways to achieve this is having continuous dialogue with the employees and providing cutting edge awareness training regularly. In the end, the greatest threat in the Cybersecurity space - the human connection - will be highly minimized and mitigate fraud risks, if strategic effort is made by C level management strive to raise employees awareness of the impact and cost of fraud before it happens opposed to after fraud has occurred.
Retrieved from:
September 21, 2019

Sunday, December 21, 2014

How Will EMV Implementation Protect the Consumers?

Alas, with the implementation of the EMV in the United States, the Credit Card industry and merchants can breathe some sigh of relief. At least it is better late than never as the wise saying goes. For the most part, Europe and other countries embraced EMV with open arms but the U.S. fought really hard to keep it from its shores. In the end, the cybersecurity threats, barrage of high profile breaches, and its impact on the average American pressured the U.S to finally accept EMV implementation.

According to PCI and Credit Card Fraud experts in the industry, EMV is the best way forward. However, Citizens Financial Group Tim Webb offered to the contrary that the chip-based cards and the usage of signature instead of PIN will not help protect the U.S. consumer from fraud. 

But with the success of the encrypted computer chips in nations that have EMV standard instead of magnetic stripes, the EMV acceptance will substantially grow in the U.S. within the next few years according to Eric Chabrow in his October 2014 article: EMV Rollout: Are PINs Essential? Most experts also contend that chip-based cards "provide far better security than magnetic stripes cards, but that the e-commerce will be a major front where fraud will substantially grow." 

Whatever the short-term outcome, the future of EMV globally is bright and the U.S will benefit immensely from its implementation.

See also:

Tuesday, November 25, 2014

Cyber Attack Is Real!

Anyone living on this planet would agree with the fact that Cyber Attack has become a daily occurrence impacting every facet of our lives.

Friday, September 28, 2012

U.S. Banks Hit with Massive and Intensifying Cyber-attacks


Cyber Attacks on U.S. Banks Expose Computer Vulnerability


Cyber-attackers are at it again. But this time, the magnitude of the attack is massive. The victims include the great and mighty banks in the US; namely JPMorgan Chase, Well Fargo, Bank of America, Citigroup, U.S. Bancorp, and PNC Financial Services Group. Rodney Joffe, senior vice president at Neustar, Sterling, Virginia-based security firm puts it very well by saying “the nature of this attack is sophisticated enough or large enough that even the largest of the financial institutions would find it difficult to defend against.”

According to cybersecurity specialists, the recent escalation of cyber-attacks has “overpowered some of the most sophisticated computer defenses of U.S. banks.” The extent of the impact of the threat also got the attention of not only the entire financial institutions, but also the White House, U.S. Congress, and every financially related enterprise. For example, sources close the Obama administration and security expert helping to trace the attack said “the attacks, which originate outside the U.S., have been the subject of several closed-door meetings at the White House.”

Could this incident have some connection with the You Tube video depicting Prophet Muhammad? That question is being sorted out by the authorities. However, the fact that “a group calling itself Izz ad-Din al-Quassam Cyber Fighters claimed responsibility for the assault in a statement posted to the website pastebin.com” may give some indication as to who is behind these well planned attacks. Also, banks are declining to comment for fear of premature conclusions. The banks major concern going forward is about what they could suffer if “an organization with more resources” should launch attacks. It is indeed a test of the banking industry computer networks and the integrity of their intrusion detection technology. Even though these banks were forewarned about the attacks, yet the banks were unable to handle the DDoS attacks, according to Atif Mushtag, senior staff scientist with California-based security firm, FireEye, Inc.

It is my hope that given the magnitude the impact of the attack on these banks and its effect of financial consumers’ confidence, more cyber-attack deterrent measures would be implemented within the financial institutions systems. It should also be a good lesson for the Federal authorities, such as the FBI, NSA, and the DoD.


Retrieved September 28, 2012, from
http://www.bloomberg.com/news/2012-09-28/cyber-attacks-on-u-s-banks-expose-computer-vulnerability.html
 

Monday, November 14, 2011

Time To Finish Up: Lessons Learned!

Information Security News Update!


My first experience blogging has been very exciting and rewarding. My final take: I plan on researching for an opportunity to be a regular contributor on cyber-security and cyber-crime issues in the financial sector.


The first couple of weeks were a little shaky due to the fact that I needed to get my feet wet in the blogging arena. Once the dust settled and the kinks were smoothened out, it became so much fun to read and blog on the various topics that I found interesting.


Throughout the blogging weeks I wrote about a variety of topics. However, most of my blog materials were about the financial/banking industry cyber-crimes from Bankinfosecurity.com website. The topics covered hacking, viruses, ID theft, credit card skimming, cyber fraud, information security threats and ways to combat them, etc.


Initially, I did not choose to write on these topics but cyber-crime in the financial sector picked my interest as I began to read about how it impacted my current field of work, and the millions of dollars being lost due to financial cyber-crimes around the world. Also, as the course progressed I gained better insight about cyber security issues. Another source that I used was Networkworld News website.


I feel that this type of blog is a very useful tool and a great learning experience for information security and banking industry professionals. One of the lessons I learned was that my materials sources kept me abreast of current issues in the cyber security & cyber-crime world. It also made me more aware about how the Federal, States, and local authorities are combating cyber security frauds and financial cyber-crimes.

Thursday, November 10, 2011

Skimming Stopped by Bank, Merchants


Pay-at-the-Pump Scheme Launches 10-Month Spree

Combating Pay-At-The-Pump Skimming

Some years ago, words like skimming, phishing, spamming, etc., were not common in the electronic world vocabularies. How the world has changed electronically is amazing. The more sophisticated technologies get, the men/women of the information age underworld get even super sophisticated at challenging the advancements and pose more cyber threats.

The financial/banking industry is one of the most vulnerable areas susceptible to different types of attack. Probably because “money is king” as the saying goes, therefore systems, devices, or persons that have access to it must be more prone to attacks.

Gray Taylor, a security and compliance expert for National Associations of Convenience Stores (NACS) says it bluntly; “the U.S. payment system is broken …, the magnetic stripe is the culprit.” Recently in Orlando, FL, a U.S. District court charged two suspected fraudsters for credit cards pay-at-the-pump skimming. The skimming fraud resulting in thousands of dollars spanned over 10 months of numerous fraudulent retail transactions with 175 credit cards at least. The good news is that the fraudsters were finally busted by a retail store’s surveillance and “banks’ transactional fraud-detection systems” when the suspects were making a $73,500 purchase. Other skimming crimes were committed at gas stations in Orlando suburbs.

Some of the banks that were victims included Chase and American Express. These cases are examples indicating that hacking and skimming U.S.-based magnetic-stripe accounts by criminals are growing. According to Jeff Lenard, NACS spokesperson, “pay-at-the-pump skimming is an issue the convenience-store and petrol industries are taking seriously.” To help retailers mitigate potential security breaches, NACS has launched WeCare Decals, tamper-evident labels for quick identification. They also recommended that retailers install video cameras for better surveillance, inspect pumps regularly to monitor tampering, and change pump dispenser locks because the older pump locks have same keys and inspection and collaboration are the best response to POS attacks. Hopefully the “WeCare Decal” mechanism and other recommendations would provide some desperately needed solution to curb magnetic-stripe cards skimming fraud.



Wednesday, November 2, 2011

EMV: It's About Reducing Fraud

Silicon Valley Bank Plans to Expand Chip Card Program

The combined global effect of the identity theft fraudsters that swindled at least $9 million from 8,000 victims in a period of 15 years (Atlanta, GA) and a 16 month period ID theft crime costing over $13 million across Africa, Asia, Europe, the Middle-East, and the United States (Queens, NY) may cause those opposing the Europay, MasterCard, Visa (EMV) standard to rethink their stance on the chip and PIN card technology. According to Pradeep Moudgal, who oversees global cards and merchant services for Silicon Valley Bank (SVB) in California, chip and PIN card technology migration by U.S. financial institutions will be expensive. However, considering the cost already inflicted on the accountholders and the issuing banks, what more evidence is needed to convince the U.S. card issuers to support EMV and implement chip and PIN. No one knows.  

The vast majority of ID theft crimes are attributed to the magnetic stripes on the back of the cards, says Avivah Litan, a Gartner analyst. This Achilles heel of the global card industry could finally be eliminated with the implementation of chip and PIN card technology. As the first U.S. commercial bank to implement EMV, SVB is proving that fact as it rolled out EMV cards with its elite business cardholders. Following that will be SVB’s more affluent clienteles who travel overseas.

The embarrassment of card rejection overseas and increased global ID security vulnerability, in the long run, far outweigh the cost of chip and PIN card technology implementation. Moreover, the reduction of ID theft fraud, as evidenced in the U.K. and some parts of Europe and Asia, should be a strong motivating factor to those in the U.S. still gauging the cost and benefits of the new technology. If chip and PIN could become a positive tool to mitigate cybercrime, financial fraud, identity theft, information security threats, etc., why not give it a shot. Any takers?


Reference:

Saturday, October 29, 2011

$9 Million ID Theft Scheme Alleged


Duo Charged in Retail Scam that Spans 15 Years



For 15 years, a pair of identity theft fraudsters swindled $9 million from 8,000 victims undetected. The arrests of the duo in Atlanta and Roswell, GA uncovered more than the authorities had bargained for. The collaboration between the U.S. Secret Service and the local Cherokee County Sheriff’s Office Criminal Intelligence Unit made it possible. This successful gigantic arrests demonstrate how due diligence and collaboration in the pursuit of perpetrators are key to solving information security or financial fraud crimes. As the scope of the arrests spans across so many years, another major or the “biggest identity theft takedown” by U.S. District Attorney’s Office in Queens, NY, spans across the globe. The NY case uncovered a 16-month crime period costing over $13 million across Asia, Africa, Europe, and the Middle East.

As indicated by McAfee’s Robert Siciliano, shared information between financial institutions and retailers enhances monitoring capabilities and create more understanding for merchants on how to mitigate financial losses. Shared responsibilities among all communities of interest, not just technological surveillance, will always be the greatest weapon against cybercrime, financial fraud, identity theft, information security threats, etc.

For more success in the future, Julie Ferguson, a board member of the Identity Theft Resource Center and co-founder of Merchant Risk Council buttressed the point by encouraging consumers to do better jobs of reporting incidents of identity theft. Moreover, the closeness of the timing between the two incidents in NY and GA would be attributed to the roles played by people not necessarily technology. Just as people are the greatest threat to information security and electronic related crimes, people are also the greatest asset needed for the mitigation and solving identity theft, financial fraud, cybercrime, and information security threats.   

Wednesday, October 19, 2011

Mobile: Combating Malicious Apps

ENISA Says Vendors are Key to Smartphone Security

  It is quite comforting to know, according to Giles Hogben of the European Network Information Security Agency (ENISA), that when comparing browsing risks, mobile security is still much better than other areas of cyber security threats. For example, for the number of malware risks it is something around 1,000 times less than the threats which are on PCs, he wrote. Nevertheless, Hogben also made it clear that, despite its lower risk level, more usage of smartphones will cause an increase in emerging threats of mobile malware.

 Hogben’s main concerns were basically focused on lack of encryption in smartphones data, and “loseability,” which he coined from the ease at which consumers lose their phones. Areas he discussed included “challenges of detecting and blocking malicious apps on mobile devices; conflicts between mobile OS and HTML permissions in mobile browsing; and what the market can expect If HTML 5 becomes the standard.” Public API, for example, involves image gallery, the accelerometer and the address book. The accelerometer data is used to grab peoples’ passwords by just observing the way the phone wiggles as different soft keys are pressed during usage. Sloppy coding, besides malware, also leads to data vulnerabilities.

 Furthermore, fingerprinting is another area of concern that must be addressed when considering mobile browsing risks. Users’ fingerprints were identified by the particular kind of headers they transmitted when they looked at headers coming from the browsers.

 With such exposures and various risks associated with smartphones, Hobgen concluded that vendors are the main key to smartphone security. But, the question remains, who bears the liability of legal implications of that responsibility? Is it the vendor or the consumer?
http://www.bankinfosecurity.com/articles.php?art_id=4140&opg=1

Thursday, October 13, 2011

Sony Discloses Attempts to Access Customer Accounts

Mikeknsah: Information Security News Update!


93,000 Accounts May Have Been Exposed


Sony’s CISO alerted the customers and the rest of the world to know that some 93,000 of its networks accounts suffered from unauthorized intruders. The number translated to less than one-tenth of one percent of Sony’s IDs and password authentication accounts. Upon detecting the breach, Sony decided to lock down the accounts and notify affected customers to reset their login information with hard-to-guess passwords.

To keep the minds of affected customers at rest, Sony assured them that credit cards associated with those accounts were not at risk. However, the next statement following the ‘assurance’ said that they “will work with any users whom we confirm have unauthorized purchases made to restore amounts in the PSN/SEN or SOE wallet.” Then, the question remains, why would Sony put the ‘cat before the horse?’ How could Sony claim that no credit card associated with users accounts were affected, and with the same breath say it will investigate to confirm any unauthorized purchases? Would it not have been better to investigate for fraudulent purchases first before asserting that no credit card accounts were at risk?

This disclosure about attempts to access customer accounts has, once again, put Sony’s networks and the company’s vulnerabilities in the global spot light. Given Sony’s size and industry, it would serve the company better if it makes aggressive pursuit and investment in more robust attack prevention tools the number one goal. Such tools should also be integrated with information security models (SSE-CMM), and lead in protecting information assets. Sony could be successful in achieving this goal by staying ahead of the ‘bad guys’ and stop playing catch up.


Tuesday, October 4, 2011

Mobile Security: Your #1 Threat

Mikeknsah: Information Security News Update!

New Trojan Targets Androids, But Experts Warns of Other Risks


What seemed like a happy marriage between Google and Android may be under attack by an outside force driven by “a new Trojan aimed at hijacking banking credentials from users of Google’s Android mobile device.” For example, the SpyEye Trojan known as SpitMo lured users to phony apps. After successfully installing the apps, users’ bank account information are stolen, and then financial transactions are directed by text messages. The world of mobile security has witnessed some assaults lately from all sides. According to Google officials, device-specific information of its Android users was hacked in March of this year. The attackers were able to publish numerous malicious apps on Google’s Android Market causing users some major concerns. Google down played it by saying that the company took steps to protect those users who download malicious application to prevent attackers from accessing other data.

Then, in September the hackers hit Android users again. This time Google blamed it on open-source apps. More specifically, it claimed that users browsing and texting behavior – social engineering - led to the mobile security compromise. Granted, the hackers may have relied on social engineering as their vehicle of operation, but is the users’ subscription and apps downloading fees not supposed to be used to create and build robust protection to shield users against such vulnerability attacks? Google says “it supports its open-source environment.” Of course, it would, because open-source drives the Android Market. It was indeed a wise move on Google’s part not to comment about the September attack except provide some general measures it has taken to protect the integrity of its mobile software, platform and apps. Technically, Google is protecting its image.

 Some experts say that giving consumers, with lack of disciplined mobile-use behavior, so much control should be “the industry’s biggest worry, not the proliferation of malicious apps.” But shouldn’t consumers control be the essence and joy of owning the device in the first place?





Thursday, September 29, 2011

The Worst Security Hack Ever

Mikeknsah: Information Security News Update!


The Worst Security Hack Ever

Breach Extends Beyond the Victimized Company


Hackers at their best yet! They stole the private key of trusted digital certificate issuer to fool internet website visitors.

“The Worst Security Hack Ever” sent some chills down my spine simply because it spanned beyond the usual territory of the victim’s environment. Now the long arm of the breach effect, like an octopus, is threatening the very trust of the e world. The far reaching impact of the hackers’ success is that the foundation of INFOSEC – confidentiality, integrity and availability – is being shaken to its roots. That the hackers could break into DigiNotar’s computers is nothing novel, but the sophistication of the hacker’s operation and the carefully selected extended victims (the CIA, British and Israeli intelligence services, Google, Microsoft, Facebook, Twitter, Wordpress, and Equifax) according to preliminary audit, makes it scary.   

 The question that remains is whether the perpetrators will ever be brought to justice. And how long will it take, and at what cost, to deter another disaster of DigiNotar’s magnitude. Especially disheartening at this juncture is that other hackers have been emboldened by the success of DigiNotar attackers. The hackers have gained global publicity by bringing DigiNotar to its knees. So, what and who is next?


Monday, September 19, 2011

US agencies making progress on cybercrime, officials say

Mikeknsah: Information Security News Update!

But criminals continue to target U.S. businesses, with the FBI currently investigating 400 wire transfer cases!

The rise in cybercrime and the level of sophistication of the crimes have caught the attention of the U.S. Secret Service, the FBI, the Department of Homeland Security, and the Congress due to high volume of cases being investigated by the FBI. Sources of the cases are mainly in the financial industry. Tops on the list are payment processing breaches, ATM skimming, stock trading, and mobile banking attacks. Despite the fact that the FBI has made combating cybercrime one of its top priorities over the past decade, cyber attacks continue to be a major threat globally. For example, as much as $388 billion has been lost in time and money in a period of one year compared to about $288 billion lost in heroin and cocaine trading combined. It makes one to wonder what the cost of would have been if all the government agencies were not as committed to fighting the war against cybercriminals. Also, with rising global internet usage and the ease of sharing information, is the amount of resource capital – human and monetary – sustainable? It seems like the more the government agencies improve on their information sharing amongst themselves, the more aggressive the attackers get.      

http://www.networkworld.com/news/2011/091411-us-agencies-making-progress-on-250908.html?source=nww_rss

Thursday, September 15, 2011

Pentagon unveils five steps for better cybersecurity

Mikeknsah: Information Security News Update!

In the fast and dynamic internet age, the only way to maintain a safe and secure information environment is by staying ahead of the bad guys. The United States Department of Defense (DoD) – Pentagon – is working overtime to ensure that the information age rouges will always be playing catch up. The DoD is working tough balancing act since it must guard the U.S. interest on land, sea, air, and space fronts. While attempting to defend the cyberspace, the DoD has to avoid being perceived as militarizing the cyberspace and violating the citizens basic freedoms, according to the department’s Deputy Secretary. But for how long can this balancing act be played with 100% success? One virtue that the bad guys always possess is the gift of patience.

http://www.networkworld.com/news/2011/071511-pentagon-unveils-five-steps-for.html?page=1