News
[Security]| Wednesday 3rd August 2005 |
Gartner estimates some three million US consumers had $2.75bn stolen out of their bank accounts in the 12 months ending May 2005.
The theft was almost entirely down to criminals using online scams to con consumers out of account and password information through attacks such as phishing and key-logging.
Account information is being increasingly used in the manufacturing of fake cards that are subsequently used at ATM cash machines to withdraw money.
Yet banks are not taking sensible precautions on how their ATMs and others' check these cards, even though it is them that bears the brunt of the cost of these fraudulent withdrawals.
Avivah
ADVERTISEMENT |
|
'Surprisingly, perhaps as many as half of US-based financial institutions are not validating Track 2 security data while authorizing ATM and PIN debit transactions. Most of these institutions are unaware that they, or the outsourced ATM transactions processor they rely on, should be doing so.'
Withdrawing cash has benefits over online transactions for these criminals. Many of the gangs that use phishing attacks to access online bank accounts 'hire' mules through which the money is funnelled in an attempt to hide the trail to their own bank account. Taking cash out of an ATM has none of these drawbacks. But Gartner insists that 'Banks have the ability to stop these attacks' as the CVV code is not known to the customer and therefore not prey to phishing attacks - a key element for ATMs to check.
Submit to: Digg | Slashdot | Del.icio.us | Technorati

