IBJNews

U.S. credit card info is easy pickings for hackers

Back to TopCommentsE-mailPrintBookmark and Share

The U.S. is the juiciest target for hackers hunting credit card information. And experts say incidents like the recent data theft at Target's stores will get worse before they get better.

That's in part because U.S. credit and debit cards rely on an easy-to-copy magnetic strip on the back of the card, which stores account information using the same technology as cassette tapes.

"We are using 20th century cards against 21st century hackers," says Mallory Duncan, general counsel at the National Retail Federation. "The thieves have moved on but the cards have not."

In most countries outside the U.S., people carry cards that use digital chips to hold account information. The chip generates a unique code every time it's used. That makes the cards more difficult for criminals to replicate. So difficult that they generally don't bother.

"The U.S. is the top victim location for card counterfeit attacks like this," says Jason Oxman, chief executive of the Electronic Transactions Association.

The breach that exposed the credit card and debit card information of as many as 40 million Target customers who swiped their cards between Nov. 27 and Dec. 15 is still under investigation. It's unclear how the breach occurred and what data, exactly, criminals have. Although security experts say no security system is fail-safe, there are several measures stores, banks and credit card companies can take to protect against these attacks.

Companies haven't further enhanced security because it can be expensive. And while global credit and debit card fraud hit a record $11.27 billion last year, those costs accounted for just 5.2 cents of every $100 in transactions, according to the Nilson Report, which tracks global payments.

Another problem: Retailers, banks and credit card companies each want someone else to foot most of the bill. Card companies want stores to pay to better protect their internal systems. Stores want card companies to issue more sophisticated cards. Banks want to preserve the profits they get from older processing systems.

Card payment systems work much the way they have for decades. The magnetic strip on the back of a credit or debit card contains the cardholder's name, account number, the card's expiration date and a security code different from the three or four-digit security code printed on the back of most cards.

When the card is swiped at a store, an electronic conversation is begun between two banks. The store's bank, which pays the store right away for the item the customer bought, needs to make sure the customer's bank approves the transaction and will pay the store's bank. On average, the conversation takes 1.4 seconds.

During that time the customer's information flows through the network and is recorded, sometimes only briefly, on computers within the system controlled by payment processing companies. Retailers can store card numbers and expiration dates, but they are prohibited from storing more sensitive data such as the security code printed on the backs of cards or other personal identification numbers.

Hackers have been known to snag account information as it passes through the network or pilfer it from databases where it's stored. Target says there is no indication that security codes on the back of customer credit cards were stolen. That would make it hard to use stolen account information to buy from most Internet retail sites. But the security code on the back of a card is not needed for in-person purchases. And because the magnetic strips on cards in the U.S. are so easy to make, thieves can simply reproduce them and issue fraudulent cards that look and feel like the real thing.

"That's where the real value to the fraudsters is," says Chris Bucolo, senior manager of security consulting at ControlScan, which helps merchants comply with card processing security standards.

Once thieves capture the card information, they check the type of account, balances and credit limits, and sell replicas on the Internet. A simple card with a low balance and limited customer information can go for $3. A no-limit "black" card can go for $1,000, according to Al Pascual, a senior analyst at Javelin Strategy and Research, a security risk and fraud consulting firm.

To be sure, thieves can nab and sell card data from networks processing cards with digital chips, too, but they wouldn't be able to create fraudulent cards.

Credit card companies in the U.S. have a plan to replace magnetic strips with digital chips by the fall of 2015. But retailers worry the card companies won't go far enough. They want cards to have a chip, but they also want each transaction to require a personal identification number, or PIN, instead of a signature.

"Everyone knows that the signature is a useless authentication device," Duncan says.

Duncan, who represents retailers, says stores have to pay more — and banks make more — on transactions that require signatures because there are only a few of the older networks that process them, and therefore less price competition. There are several companies that process PIN transactions for debit cards, and they tend to charge lower fees to stores.

"Compared to the tens of millions of transactions that are taking place every day, even the fraud that they have to pay for is small compared to the profit they are making from using less secure cards," Duncan says.

Even so, there are a few things retailers can do, too, to better protect customer data. The most vulnerable point in the transaction network, security experts say, is usually the merchant.

"Financial institutions are more used to having high levels of protection," says Pascual. "Retailers are still getting up to speed."

The simple, square, card-swiping machines that consumers are used to seeing at most checkout counters are hard to infiltrate because they are completely separate from the Internet. But as retailers switch to faster, Internet-based payment systems they may expose customer data to hackers.

Retailers need to build robust firewalls around those systems to guard against attack, security experts say. They could also take further steps to protect customer data by using encryption, technology which scrambles the data so it looks like gibberish to anyone who accesses it unlawfully. These technologies can be expensive to install and maintain, however.

Thankfully, individual customers are not on the hook for fraudulent charges that result from security breaches. But these kinds of attacks do raise costs —and, likely, fees for all customers.

"Part of the cost in the system is for fraud protection," Oxman says. "It costs money, and someone's going to pay for it eventually."
 

ADVERTISEMENT

  • PCI DSS Compliance
    Sean, many merchants do not take security seriously. Many merchants who accept credit/debit card payments are not PCI DSS compliant which means they don't adhere to even the minimum suggested measures for how best to handle credit card information given their particular business environment. Being PCI DSS compliant does not ensure a merchant will never be breached but does reduce the probability. There are different measures based on whether the card is present or not present, whether a card is transmitted over an analog or data connection. When a breach happens to a small business, it potentially could put the merchant out of business either due to the fines or due to the time period of the investigation or both. Merchants - do the right thing. Become PCI DSS compliant and take it seriously.
  • Cyber Liability
    It is incredible how many business owners ignore this exposure in terms of purchasing insurance. The theft of credit card data and private information is not the only exposure. Hackers can take down a network or someone elses network using a business owners site as a launching point causing business interruption and losing large amounts of income or they can take over a social media site and promulgate misinformation, etc. All these issues bring exposure to liability to the business owner but most businesses do not purchase cyber liability and privacy breach insurance leaving them to deal with this exposure on their own. In the Target example, 40,000,000 cards were stolen. If they take just $1 per card, their is $40,000,000 stolen and Target is liable....most likely with very little insurance relatively speaking. Business owners need to wake up to this threat and protect themselves and their assets.
  • Fraudulent Processing Accts.
    And...the crooks can set up fraudulent merchant credit card processing accounts. I know because my business name and (now former) EIN were stolen and combined with the SSN of an 83 year old woman to set up fraudulent accounts that processed stolen credit cards. So, it's not just using a stolen card; the processing can also be fraudulent. It's not been a happy story.

Post a comment to this story

COMMENTS POLICY
We reserve the right to remove any post that we feel is obscene, profane, vulgar, racist, sexually explicit, abusive, or hateful.
 
You are legally responsible for what you post and your anonymity is not guaranteed.
 
Posts that insult, defame, threaten, harass or abuse other readers or people mentioned in IBJ editorial content are also subject to removal. Please respect the privacy of individuals and refrain from posting personal information.
 
No solicitations, spamming or advertisements are allowed. Readers may post links to other informational websites that are relevant to the topic at hand, but please do not link to objectionable material.
 
We may remove messages that are unrelated to the topic, encourage illegal activity, use all capital letters or are unreadable.
 

Messages that are flagged by readers as objectionable will be reviewed and may or may not be removed. Please do not flag a post simply because you disagree with it.

Sponsored by
ADVERTISEMENT

facebook - twitter on Facebook & Twitter

Follow on TwitterFollow IBJ on Facebook:
Follow on TwitterFollow IBJ's Tweets on these topics:
 
Subscribe to IBJ
  1. Uh, sorry Johnnie, but you are incorrect. Despite the assertions by yourself and various defenders and captains, sports attendance is NOT off significantly at most sporting events in the US. Variances in attendance has been in the range of single digits, both + & - for years now. MLB has had most of its best overall attendance nubers in the last decade, and that trend has been consistent for most major sporting events. The number one issue cited by most fans when asked about attendance is the overall cost of attending. The presence of HD and big screen televisions in home doesn't even register, as a factor for not attending an event. VALUE in the product is the key, and apparently is something lacking in the current ICS. What other explanation is there when with what is routinely touted as the "best" racing on the planet, fans are staying away in DROVES. A "close" title battle into the last event at Fontana, with the "cars and stars" of the ICS, and who showed up? MAYBE 8K. Sorry, but HD TV isn't to blame for that kind of fan apathy.

  2. Do you need finance to establish your business ? Are you interested in getting a loan at 3% from our private company? If so please Email: suntrust_oil@blumail.org

  3. If she was worth the $ the public outcry over direct tv dropping them would have kept them on their dishes as we have seen with other companies. I too quit watching channel 13 after she showed up since I left channel 8 because of her all show rather than production results. When Randy on 8 corrected her she had a big head and incorrectly challenged his correction for pronunciation of a city. Other antics while she matures was too much for me with her very inaccurate forecasts. All the forecasters were predicting rain until Thursday except Chris. They predicted sunny on Thursday but instead of rain until Thursday upon which the sun would finally make it out in full glory Chris was right on the money just as I too predicted looking at the radar on weather.gov. One thing I love about Angela is the fear you can see in her every time it thunders in the winter. It far exceeds the entertainment value of her body language (high heel noise drags, depression, etc) when her forecasts are so incorrect. Her hair stands on end, you have to see it!!!

  4. Good Day, Apply For A Loan I am Mr Fernadez Antonio, a private Loan lender and a cooperate financial for real estate and any kinds of business financing. I also offer Loans to individuals, Firms and cooperate bodies at 3% interest rate We offer any kind of loans. email us via fernadezloaninvest@outlook.com LOAN APPLICATION FORM First name:......................... Middle name:......................... Last name:........................................ Date of birth (yyyy-mm-dd):....................... Gender:........................................... Marital status:................................... Total Amount Needed............................... Loan Duration.................................... Address:.......................................... City:............................................. State/province:................................... Zip/postal code:.................................. Country:.......................................... Phone:............................................ Fax:.............................................. Mobile/cellular:.................................. Monthly Income.................................... Occupation:....................................... Best Regard, Mr Fernadez Antonio.

  5. i will love to share my testimony to you all the people in world i got married to my husband about 2 year ago we start having problems at home like we stop sleeping on the same bed,fighting about little things he always comes home late at night,drinking too much and sleeping with other women out side i have never love any man in my life except him. he is the father of my child and i don't want to loose him because we have worked so hard together to become what we are and have today .few month ago he now decided to live me and the kid,being a single mother can be hard sometimes and so i have nobody to turn to and i was heart broken.i called my mom and explain every thing to her,my mother told me about DR.okoro how he helped her solve the problem between her and my dad i was surprise about it because they have been without each other for three and a half years and it was like a miracle how they came back to each other. i was directed to DR. okoro on his email:okorospell@gmail.com and explain everything to him,so he promise me not to worry that he will cast a spell and make things come back to how we where so much in love again and that it was another female spirit that was controlling my husband he told me that my problem will be solved within two days if i believe i said OK So he cast a spell for me and after two days my love came back asking me to forgive him i Am so happy now. so that why i decided to share my experience with every body that have such problem contact Dr okoro the great spell caster on his email addresses spellcasterforlove@outlook.com

ADVERTISEMENT