Criminals compromising online security checks

Cyber criminals find loophole in verification system

Crooks change card holder addresses to make transactions look genuine

Written by Dinah Greek

Fraudsters have hijacked a system designed to help protect retailers and consumers from credit card fraud, according to fraud protection specialists the 3rd Man.

The company claims that a serious flaw in the Address Verification System (AVS) used by retailers to check the identity and billing address of a card holder allows fraudsters to fake verification.

AVS is often used by internet retailers to check that the billing address the credit card holder gives matches the address on file at the credit card company.

It works by matching the house number and postcode numbers for each card issued. For example, 43 Crooks Close, B10 7GB would result in an AVS number of 43107.

But a 3rd Man investigator discovered that criminals are getting around this check to make fraudulent transactions look genuine.

Andrew Goodwill, director and fraud expert at the 3rd Man, said that fraudsters are compromising and using card details where the genuine cardholder’s address numerals exactly match the address they want delivery to.

“So, not only are they obtaining goods fraudulently, they have them delivered to their chosen address,” he said.

He told Computeractive that the company was initially seeing upwards of 50 fraudulent transactions in a day by criminals who had cottoned on to this loophole. However, Mr Goodwill warned that the the volume of these fraudulent transactions was bound to rise.

“This is serious. It is likely we will soon see this as the biggest problem during the last 20 years regarding card fraud. Fraudsters are starting to exploit the loophole in significant volume. Retailers relying on AVS, or where a retailer will only deliver to the billing address, are facing a potentially huge risk,” he said.

Mr Goodwill also told us that the fraudsters can also compromise the bank’s fraud prevention technologies, Verified by Visa or Mastercard Securecode.

“Criminals are also checking to see if the cardholder has registered their card with either of these security methods. If they haven’t then the fraudster registers the card details using a password of their choice, making it even harder for the retailer to know the card is being used fraudulently.

APACS, the payment industry body said it didn’t dispute the 3rd Man’s findings or that it was possible but said neither it nor the police had evidence that this fraud was happening.

“It is a rather complex way of getting a delivery address and we wonder if criminals would go to those lengths; they prefer easier ways of committing fraud.

"We have had discussions with the 3rd Man and police about criminals using this way of committing fraud. But retailers should never rely on one method of verification,” an Apacs representative said.

reader comments

related articles

 

Fraudsters exploit card protection system

Warning issued over flaw in Address Verification System 12 Jun 2008

Industry lays into 3-D Secure

Verified by Visa and MasterCard SecureCode are flawed, say experts 11 Apr 2008

3D Secure uptake soars to 25 million

Apacs claims major milestone for authentication standard 22 Sep 2008

related whitepapers

today's top stories

Body Shop rolls out PCI system

Retailer hopes to benefit from improved customer data analysis 07 Oct 2008

Where to offshore (and why not here?)

Tholons, the research firm founded by well-known offshoring guru Avinash Vashistha , has just published some new research in Global Services magazine... 07 Oct 2008

The future of Ethernet

Where is Ethernet going? We look at the future of the widely-used networking technology. 07 Oct 2008

The pIT stop Q&A: How can I measure the business success of IT applications?

Ou expert panel answers readers' real-life IT questions 07 Oct 2008

National Identity Fraud Prevention Week

Every Monday seems to mark the beginning of a new awareness drive and this week’s theme has particular importance to small businesses... 06 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you apply for a job that was advertised on Facebook or a similar social networking site?

Would you apply for a job that was advertised on Facebook or a similar social networking site?

The government is using Facebook to recruit IT staff - would you apply to such an ad?

Previous poll results

Latest audio and video articles

Ethernet cableVideo

The future of Ethernet

Where is Ethernet going? We look at the future of the widely-used networking technology. 07 Oct 2008

Podcast imageAudio

Computing podcast - Next-generation broadband Britain; and we report from Gartner's IT security summit

In our latest podcast, we discuss the hurdles that a national fibre-optic network must overcome, and look at the issues discussed at the recent IT security conference 02 Oct 2008

Latest in-depth articles

Features

How to ensure progress in programming

Best practice advice from Forrester Research 02 Oct 2008

BT workersAnalysis

Wanted: a viable model for fibre

While other European countries are pressing ahead with fibre rollouts, progress in the UK is being held back as the debate over who will foot the bill drags on, writes Dave Bailey 02 Oct 2008

Advertisement

Primary Navigation