A report in the Wall Street Journal features remarks made by Katherine Hutchinson, senior director of global risk management at PayPal. She reportedly told the Web 2.0 Expo in San Francisco that the online fraud industry was so lucrative that an "underground community" existed where fraudsters offered their specialist skills to others.
She also warned that the use of IP addresses for determining a customer's location were no longer a suitable method of combating online fraud - IPs addresses can be easily masked for one thing, and fraudsters often use "zombie" computers. She also warned that all the confusion in the banking sector caused by the current economic crisis left the door open for phishing attacks by fraudsters asking customers for bank account details.
Showing posts with label Internet security. Show all posts
Showing posts with label Internet security. Show all posts
Friday, 3 April 2009
Tuesday, 24 February 2009
Online retailers fight "recession fraud"
A survey conducted by Vanson Bourne indicates that online retailers are fighting back against the increased threat of "recession fraud".
The research conducted on behalf of SPSS, a predictive analytics software provider, shows that 37% of online businesses had implemented new measures such as customer behaviour analysis, restricting purchases from "high risk" locations or countries and reducing the number of payment methods available, to help reduce online payment fraud.
The 2009 UK Online Fraud Report estimates that UK online retailers lost up to 5% of total revenues to fraud in 2008, however, while retail sales on the high street are declining, online sales are increasing (up 14% in December 2008 compared to the previous year), so retailers cannot afford to be complacent about fraud.
One in four retailers surveyed by Vanson Bourne indicated they are using customer analytics, which focus on unusual behaviour patterns, to detect fraud. Eighteen percent said they had also reduced the number of payment methods in the belief that it reduced the opportunities for fraudsters.
The research conducted on behalf of SPSS, a predictive analytics software provider, shows that 37% of online businesses had implemented new measures such as customer behaviour analysis, restricting purchases from "high risk" locations or countries and reducing the number of payment methods available, to help reduce online payment fraud.
The 2009 UK Online Fraud Report estimates that UK online retailers lost up to 5% of total revenues to fraud in 2008, however, while retail sales on the high street are declining, online sales are increasing (up 14% in December 2008 compared to the previous year), so retailers cannot afford to be complacent about fraud.
One in four retailers surveyed by Vanson Bourne indicated they are using customer analytics, which focus on unusual behaviour patterns, to detect fraud. Eighteen percent said they had also reduced the number of payment methods in the belief that it reduced the opportunities for fraudsters.
Wednesday, 11 February 2009
Balancing fraud and profit
I received an interesting email from an Amsterdam-based company, Directness, which is running a Risk v Reward: Balancing Fraud and Profit conference for retailers in Amsterdam tomorrow.
Organiser, Adam Dorrell, said that the event was triggered by retailers such as Nike, Philips and Sony getting fed up with the cost of fraud. The problem for many retailers is that they have to invest considerable sums in automated solutions for combating credit card fraud, but the return on investment is uncertain in that they may be spending more to acquire customers, only to lose them to fraud or "charge-backs".
Do the risks outweigh the rewards? Well if you believe what you read in the newspapers and various surveys that are published, the risks, particularly in the online shopping world appear to be significant. This appears to have convinced a significantly large proportion (41%) of the UK population not to shop online, according to CyberSource's latest annual survey of more than 150 merchants and 1000 consumers.
Security was an issue for the 41% of UK consumers that said they did not shop online. Out of the total sample, including those that did shop online, 66% said they were concerned about the level of risk. Given that most online shopping sites now carry a secure padlock icon or the green VeriSign bar which demonstrates that the web site has met more stringent standards around web site integrity, this is still a surprisingly high number.
Some of the other basic precautions online shoppers can take is signing up to the MasterCard SecureCode or Verified by Visa programmes, which adds an additional authentication layer by asking for a password, but not all shopping sites carry this and arguably it is still open to abuse if the password is easy to guess or replicate.
CHIP and PIN while reducing fraud when the card is presented, has only served to increase the incidence of fraud in card-not-present transactions (online or over the telephone). Some security vendors suggest that one-time passwords are more secure, but there has been no uptake of this by the card companies.
Another problem is that the cost of fraud is borne by the poor retailer who has to foot the cost of charge backs and fraud in general, as well as investing in anti-fraud measures. It will be interesting to hear what comes out of the event in Amsterdam tomorrow and whether retailers can come up with a joint industry solution to combat fraud. We hope to provide you with coverage after the event.
Organiser, Adam Dorrell, said that the event was triggered by retailers such as Nike, Philips and Sony getting fed up with the cost of fraud. The problem for many retailers is that they have to invest considerable sums in automated solutions for combating credit card fraud, but the return on investment is uncertain in that they may be spending more to acquire customers, only to lose them to fraud or "charge-backs".
Do the risks outweigh the rewards? Well if you believe what you read in the newspapers and various surveys that are published, the risks, particularly in the online shopping world appear to be significant. This appears to have convinced a significantly large proportion (41%) of the UK population not to shop online, according to CyberSource's latest annual survey of more than 150 merchants and 1000 consumers.
Security was an issue for the 41% of UK consumers that said they did not shop online. Out of the total sample, including those that did shop online, 66% said they were concerned about the level of risk. Given that most online shopping sites now carry a secure padlock icon or the green VeriSign bar which demonstrates that the web site has met more stringent standards around web site integrity, this is still a surprisingly high number.
Some of the other basic precautions online shoppers can take is signing up to the MasterCard SecureCode or Verified by Visa programmes, which adds an additional authentication layer by asking for a password, but not all shopping sites carry this and arguably it is still open to abuse if the password is easy to guess or replicate.
CHIP and PIN while reducing fraud when the card is presented, has only served to increase the incidence of fraud in card-not-present transactions (online or over the telephone). Some security vendors suggest that one-time passwords are more secure, but there has been no uptake of this by the card companies.
Another problem is that the cost of fraud is borne by the poor retailer who has to foot the cost of charge backs and fraud in general, as well as investing in anti-fraud measures. It will be interesting to hear what comes out of the event in Amsterdam tomorrow and whether retailers can come up with a joint industry solution to combat fraud. We hope to provide you with coverage after the event.
Tuesday, 10 February 2009
Lloyds warns against phishing attacks
Newly-merged UK-banking group Lloyds TSB and HBOS have taken the unusual step of warning customers that fraudsters may take advantage of their merger to launch phishing attacks.
In recent years, phishing scams which typically involve the sending of "official-looking" emails asking customers to confirm bank password, security and account details, have been steadily rising. Banks and other security providers have cautioned customers not to respond or open emails sent to them asking for such information.
However, in an effort to head off a potential attack as it goes through a long and protracted merger with HBOS, Lloyds TSB said customers should be on their guard and that it would not email them requesting account, PIN or security information.
In recent years, phishing scams which typically involve the sending of "official-looking" emails asking customers to confirm bank password, security and account details, have been steadily rising. Banks and other security providers have cautioned customers not to respond or open emails sent to them asking for such information.
However, in an effort to head off a potential attack as it goes through a long and protracted merger with HBOS, Lloyds TSB said customers should be on their guard and that it would not email them requesting account, PIN or security information.
Friday, 30 January 2009
Card fraud stats - who do you believe?
Various organisations produce statistics on the incidence of credit card fraud, but the UK payments association, APACS, has hit back at a recent survey published by "life assistance" group CPP, which claims that 12 million people were victims of card fraud in 2008 and that the average loss was £650.
APACS says CPP's stats are "spurious" and that according to its own data, which is drawn from stats provided by its member banks, 2007 figures indicate there were just over a million reported cases of card fraud; and although card fraud increased in 2008 (APACS will publish figures in March), APACS says CPP’s suggestion that there were 12 million victims in 2008 is "wildly out of line".
Is it a case of CPP, which provides protection and insurance against identity theft and card fraud, talking up the incidence of card fraud in order to scare consumers into thinking the problem is much bigger than it really is? There is no question that some organisations may be talking up fraud to benefit their own cause, which is not helpful as card fraud remains a persistent problem for online merchants and exaggerating the levels of fraud, only serves to suggest that none of the solutions deployed so far to combat it are actually working.
Having said that more certainly needs to be done, as CHIP and PIN may have reduced "over-the-counter" fraud, but most reports indicate card-not-present fraud is on the increase, particularly online. Some providers have suggested the use of one-time PINs and passwords to "toughen up" existing security.
APACS says CPP's stats are "spurious" and that according to its own data, which is drawn from stats provided by its member banks, 2007 figures indicate there were just over a million reported cases of card fraud; and although card fraud increased in 2008 (APACS will publish figures in March), APACS says CPP’s suggestion that there were 12 million victims in 2008 is "wildly out of line".
Is it a case of CPP, which provides protection and insurance against identity theft and card fraud, talking up the incidence of card fraud in order to scare consumers into thinking the problem is much bigger than it really is? There is no question that some organisations may be talking up fraud to benefit their own cause, which is not helpful as card fraud remains a persistent problem for online merchants and exaggerating the levels of fraud, only serves to suggest that none of the solutions deployed so far to combat it are actually working.
Having said that more certainly needs to be done, as CHIP and PIN may have reduced "over-the-counter" fraud, but most reports indicate card-not-present fraud is on the increase, particularly online. Some providers have suggested the use of one-time PINs and passwords to "toughen up" existing security.
Thursday, 29 January 2009
Online fraud continues to rise despite countermeasures
Despite ongoing investment in tackling fraud, online merchants continue to see their losses from fraud increase, according to a survey of 150 online retailers conducted by Cybersource Ltd.
The overall rate of fraud increased 2.6%, which does not sound like much, however, Cybersource says for approximately 13% of merchants, the rate of fraud increased by more than 20% and 37% of merchants experience losses due to fraud of 1% or more. These increases are in spite of the fact that in the UK at least, approximately 60% of merchants now deploy Verified by Visa and MasterCard SecureCard schemes, which require the purchaser to type in a private code known only to them and their bank.
But it is perhaps the indirect costs of fraud that are more telling. According to the survey, 20% of merchants reject more than 5% of orders because they suspect fraud, although some of these orders may be authentic.
Despite the increasing sophistication of automated fraud screening software, Cybersource's survey indicates that 10% of merchants still reviewed every order manually, which is deemed costly and inefficient. It begs the question, do merchants see automated fraud screening as too costly or difficult to implement?
The overall rate of fraud increased 2.6%, which does not sound like much, however, Cybersource says for approximately 13% of merchants, the rate of fraud increased by more than 20% and 37% of merchants experience losses due to fraud of 1% or more. These increases are in spite of the fact that in the UK at least, approximately 60% of merchants now deploy Verified by Visa and MasterCard SecureCard schemes, which require the purchaser to type in a private code known only to them and their bank.
But it is perhaps the indirect costs of fraud that are more telling. According to the survey, 20% of merchants reject more than 5% of orders because they suspect fraud, although some of these orders may be authentic.
Despite the increasing sophistication of automated fraud screening software, Cybersource's survey indicates that 10% of merchants still reviewed every order manually, which is deemed costly and inefficient. It begs the question, do merchants see automated fraud screening as too costly or difficult to implement?
Wednesday, 26 November 2008
"Underground" online economy is flourishing
While growth in the real economy is being hit hard by the global credit crisis, there appear to be no signs of a recession in the "underground" online economy, which is flourishing with millions of pounds being exchanged to buy stolen goods and "fraud-related services".
These are the findings of online security firm, Symantec's Report on the Underground Economy, which it compiled based on data gathered by its Security Technology and Response (STAR) organisation, from underground economy servers between July 1, 2007 and June 30, 2008.
According to Symantec, the potential value of total goods advertised in the "underground" online world was more than £184 million ($276 million). No prizes for guessing what was the most popular item for sale, and no it was not a Nintendo Wii or an iPhone but stolen credit card details.
Symantec said that credit card information accounted for 31% of the total goods for sale and that the potential worth of all credit cards advertised during the reporting period was £3.53 billion ($5.3 billion).
Stolen bank account information (20% of total goods advertised) was the second most popular item for sale with prices ranging from £6.50 ($10) to £650 ($1,000). According to Symantec's report, most of the underground activity was hosted by North American (45% of the total) servers, followed by EMEA on 38%. Asia Pacific was only 12% and Latin America 5%. "The geographical locations of underground economy servers are constantly changing to evade detection," said Symantec.
These are the findings of online security firm, Symantec's Report on the Underground Economy, which it compiled based on data gathered by its Security Technology and Response (STAR) organisation, from underground economy servers between July 1, 2007 and June 30, 2008.
According to Symantec, the potential value of total goods advertised in the "underground" online world was more than £184 million ($276 million). No prizes for guessing what was the most popular item for sale, and no it was not a Nintendo Wii or an iPhone but stolen credit card details.
Symantec said that credit card information accounted for 31% of the total goods for sale and that the potential worth of all credit cards advertised during the reporting period was £3.53 billion ($5.3 billion).
"The popularity of credit card information is likely due to the many ways this information can be obtained and used for fraud; credit cards are easy to use for online shopping and it’s often difficult for merchants or credit providers to identify and address fraudulent transactions before fraudsters complete these transactions and receive their goods," said Symantec. "Also, credit card information is often sold to fraudsters in bulk, with discounts or free numbers provided with larger purchases."
Stolen bank account information (20% of total goods advertised) was the second most popular item for sale with prices ranging from £6.50 ($10) to £650 ($1,000). According to Symantec's report, most of the underground activity was hosted by North American (45% of the total) servers, followed by EMEA on 38%. Asia Pacific was only 12% and Latin America 5%. "The geographical locations of underground economy servers are constantly changing to evade detection," said Symantec.
Wednesday, 22 October 2008
Phishing attacks rise as banks are distracted
With banks focused on shoring up liquidity and preventing runs on their shares, it seems online fraudsters are taking advantage of this opportunity to launch an ever increasing number of phishing attacks.
Brand monitoring specialists, Envisional identified almost half a million (460,000) separate phishing emails sent to bank customers in the six month period from April to September, with more than 170,000 in June alone (up 117% on June 2007).
According to Envisional, overall volumes of phishing emails sent to bank and insurance company customers were up 40% compared to 2007. It reports that one bank was hit by 350 separate attacks in one day.
Phishing emails which try to trick customers into giving away passwords and PINs, also demonstrated different targeting strategies, with 135,000 phishing emails targeting one specific bank in June. Phishers then changed tactics in July targeting two banks.
Brand monitoring specialists, Envisional identified almost half a million (460,000) separate phishing emails sent to bank customers in the six month period from April to September, with more than 170,000 in June alone (up 117% on June 2007).
According to Envisional, overall volumes of phishing emails sent to bank and insurance company customers were up 40% compared to 2007. It reports that one bank was hit by 350 separate attacks in one day.
Phishing emails which try to trick customers into giving away passwords and PINs, also demonstrated different targeting strategies, with 135,000 phishing emails targeting one specific bank in June. Phishers then changed tactics in July targeting two banks.
Who should be liable for online fraud?
Posted by Anita Hawser
Who should be liable/responsible for personal internet security? It is a subject that has stimulated much debate in the UK Houses of Parliament with the House of Lords Science and Technology Committee publishing its damning Personal Internet Security report last year.
Highlighting the increasing incidence of online fraud, ID theft and phishing, the report recommended establishing a framework for collecting and classifying data on e-crime, and “more rigorous and co-ordinated analysis” of the incidence and costs of such crime. The latest APACS figures show that online banking fraud losses increased 185% to £21.4 million in the six months to June.
It also talked about deployment of security software at ISP level, the need for a dedicated regulator for the online world, and for Government to increase banks' fraud liability. In essence the report said that instead of the weight of responsibility for online security falling on individuals, responsibility should be "distributed".
More than a year since the committee published its report, there is talk of a specialised e-crime police unit being established. Other recommendations such as the passing of legislation to ensure banks take responsibility for losses incurred by electronic fraud and rules forcing software companies to accept culpability for damage caused by security flaws, which would allow individuals to report online fraud to the police rather than to their bank, have not been implemented.
With banks already having to receive a lifeline from the government just to finance their normal operations, it seems unlikely that the government (who is now a shareholder in UK banks) will pressure them into incurring liability for losses resulting from online fraud.
It comes back to that all important question I asked at the beginning - who should be culpable? And as responsibility for online fraud is distributed - amongst banks, ISP providers and hardware and software vendors - who is the most liable or culpable at any given point in time?
Phil Hickman, chairman of ValidSoft – internet security and transaction verification experts – argues that service providers should take responsibility for the security of users:
With the banks already focused on anti-money laundering and issuing customers with one time only password generators for online banking,it seems that UK politicians favour raising "the bar of expectation" on software vendors, either voluntarily or at the EU level.
Surely more needs to be done around giving the Data Protection Act more teeth, and in the case of government leakages or breaches of personal customer data imposing hefty fines equivalent to those imposed on private companies?
This is likely to become more of an issue given that the UK government wants to compile a huge centralised database containing personal details of people's communications in order to supposedly combat terrorism.
Who should be liable/responsible for personal internet security? It is a subject that has stimulated much debate in the UK Houses of Parliament with the House of Lords Science and Technology Committee publishing its damning Personal Internet Security report last year.
Highlighting the increasing incidence of online fraud, ID theft and phishing, the report recommended establishing a framework for collecting and classifying data on e-crime, and “more rigorous and co-ordinated analysis” of the incidence and costs of such crime. The latest APACS figures show that online banking fraud losses increased 185% to £21.4 million in the six months to June.
It also talked about deployment of security software at ISP level, the need for a dedicated regulator for the online world, and for Government to increase banks' fraud liability. In essence the report said that instead of the weight of responsibility for online security falling on individuals, responsibility should be "distributed".
More than a year since the committee published its report, there is talk of a specialised e-crime police unit being established. Other recommendations such as the passing of legislation to ensure banks take responsibility for losses incurred by electronic fraud and rules forcing software companies to accept culpability for damage caused by security flaws, which would allow individuals to report online fraud to the police rather than to their bank, have not been implemented.
With banks already having to receive a lifeline from the government just to finance their normal operations, it seems unlikely that the government (who is now a shareholder in UK banks) will pressure them into incurring liability for losses resulting from online fraud.
It comes back to that all important question I asked at the beginning - who should be culpable? And as responsibility for online fraud is distributed - amongst banks, ISP providers and hardware and software vendors - who is the most liable or culpable at any given point in time?
Phil Hickman, chairman of ValidSoft – internet security and transaction verification experts – argues that service providers should take responsibility for the security of users:
“Traditional security provisions employed online have been shown time and time again to be ineffective at protecting users from the threats presented by advanced fraudulent techniques. Authentication techniques used by financial institutions, for example, have so far proved unsuccessful at preventing identity theft and electronic fraud. Defence techniques currently used are simply not sophisticated enough to counter Man-in-the-Middle/Man-in-the-Browser attacks or information stealing techniques like phishing.”The Parliamentary Committee has debated the idea of a "code of conduct" or "kite mark" for ISPs, this may be difficult to enforce and could increase costs for internet access. And given the "layered" nature of the internet, attribution of liability is problematic.
With the banks already focused on anti-money laundering and issuing customers with one time only password generators for online banking,it seems that UK politicians favour raising "the bar of expectation" on software vendors, either voluntarily or at the EU level.
Surely more needs to be done around giving the Data Protection Act more teeth, and in the case of government leakages or breaches of personal customer data imposing hefty fines equivalent to those imposed on private companies?
This is likely to become more of an issue given that the UK government wants to compile a huge centralised database containing personal details of people's communications in order to supposedly combat terrorism.
Subscribe to:
Posts (Atom)