Chip and PIN reader

Chip and PIN success drives criminals online

Firms must be wary of attempts to mine customer card data from back-end systems, say experts

Written by Phil Muncaster

Chip and PIN celebrated its first anniversary today but fraud experts have warned that the success of the high street initiative could be driving more criminals to commit online fraud and mine retailers' back-end systems for personal data.

According to payments association Apacs, chip and PIN has successfully reduced fraud on the high street – total card losses fell in 2005 by £65 million, the first decrease in 10 years, and the organisation predicts it will fall again when figures are released next month.

But although total card fraud was down by five percent in the first six months of 2006, card-not-present fraud, including online, increased by the same amount, and online banking fraud rose by 55 percent year-on-year.

To combat the threat of online fraud APACS is looking to coordinate the roll-out of two-factor authenticators, likely to be done initially by financial institutions for their customers, later this year. These will combine chip and PIN with Verified by Visa and MasterCard SecureCode technology to secure the payment process.

"The difference is that after accepting your PIN, the card reader generates a one-time passcode that will be useless for future transactions if a criminal intercepts it," said an Apacs spokesman.

He added that it could potentially encourage the take-up of the V by V initiative, which has so far seen poor take-up by retailers, despite absolving them from financial responsibility in the case of online fraud. "The banks will be the ones to send the devices out but whether it's something the retailers join in on in terms of distribution [remains to be seen]," he said.

But Ian White of data security specialist Cybertrust argued that although retailers should support mechanisms like Verified by Visa, the cost for rolling out two-factor devices could be prohibitive, and such as scheme would be unlike ly to get buy-in from all retailers.

"I'm not sure how much mileage there is in putting a twofactor authentication system iun the home; you can't have a one-size-fits-all [approach] if you're dealing with e-commerce," he explained.

CA's Steven Cox warned that firms cannot take their eyes of the ball, despite these increasing security measures and international PCI data security standards, which mandate that any firm handling payment card data must ensure it is secured.

"Fraudsters still want to make their money somehow and CNP fraud may be slowing but it's still going up," he added. "The merchants are getting a grip on the PCI standard now but few companies own all their IT systems; there are always third parties involved who are not always educated as to their responsibilities."

Tags:

reader comments

related articles

Chip and PIN reader

Online fraud steadies but dangers remain

Online fraud in the UK may have levelled off, but firms must continue to strengthen their defences 09 Mar 2006

 

Online banking hit by rising fraud levels

Online banking fraud has risen by 55 percent due to the impact of phishing attacks 07 Nov 2006

Banks mull customer liability for online fraud

Experts warn that banks may get tougher on consumers who do not do enough to protect themselves 12 Jul 2006

Online shoppers don't prioritise security

But consumer confidence could be misplaced, says Websense 07 Dec 2006

Industry lays into 3-D Secure

Verified by Visa and MasterCard SecureCode are flawed, say experts 11 Apr 2008

Online fraud rises again

Latest Apacs figures show drop in online banking fraud but big rise in card-not-present losses 05 Oct 2007

Apacs hails drop in online banking fraud

Losses fall by a third to just £22.6 million, according to the latest figures 12 Mar 2008

today's top stories

Analysis: The true cost of printing

Organisations need to get a better sense of how much they spend on printing before finding ways to reduce it 05 Sep 2008

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Looking to the future - exclusive Michael Dell interview

Dell's chief executive talks to Computing about the way the company continues to adapt to major changes in the industry 04 Sep 2008

Interview: Delivering power where it's needed at Betfair

The online gambling firm is putting its money on grid computing and virtualisation to underpin global expansion 04 Sep 2008

E-paper displays are an open book

A display revolution is on the way - but only once the user interface issues are solved 04 Sep 2008

Most commented stories

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use a mobile phone as an alternative to cash?

Would you use a mobile phone as an alternative to cash?

When mobile phones include inbuilt payment technology - would you use one instead of cash?

Previous poll results

Latest audio and video articles

BlackBerry BoldVideo

Video Review: BlackBerry Bold

Technology editor Daniel Robinson takes a hands-on look at the latest device from Research in Motion 01 Sep 2008

Podcast imageAudio

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Latest in-depth articles

A meetingAnalysis

Turning adversity into an advantage

IT chiefs under pressure to make cost cuts can turn the situation to their benefit 04 Sep 2008

CloudAnalysis

How to introduce cloud computing into your organisation

Best practice advice from Forrester Research 04 Sep 2008

Primary Navigation