Showing posts with label fraud. Show all posts
Showing posts with label fraud. Show all posts

Tuesday, October 18, 2016

Annual Cost of Fraud and Cybercrime Tops £10.9bn in the UK




Barnet, United Kingdom, October 18, 2016 - According to Get Safe Online, the annual cost of fraud and cybercrime in the UK is £10.9bn – the equivalent of £210 per adult. The research shows examples of online fraud ranging from fraudulent phishing messages to extract the personal details of victims, to ransomware and the theft of data through hacking.

Commenting on this, Robert Capps, VP of business development at NuData Security, said “We’re saddened, but not shocked, to see these findings. In this study, the fact that online fraud costs the UK £10.9bn a year is a sad state of affairs for consumers who can often bear the brunt of the costs (especially with regard to account takeover and new account fraud). It’s absolutely no wonder that consumers are pushing back on companies to improve security, holding them accountable for it, yet still wanting to have a good experience going through the gates."

Financial fraud offers a lucrative source of income for cybercriminals, totaling £755 million in 2015 in the UK alone. Cybercriminals have grown in their sophistication, exploiting the human interest factor by posing as banks or suppliers and then duping consumers into revealing their personal details. These scams have also proved effective in targeting commercial organizations, as senior executives are tricked into revealing sensitive information which enables access to a company network.

The increasing volume of attacks globally can also be attributed to more fraudsters willing to commit the crime, more data available on the black market, and more financial institutions and merchants that are vulnerable to attacks. Plus, as more countries fully adopt EMV (Europay, MasterCard, and Visa), we'll see fraud continue its migratory path to all available online channels.

We have to remember; fraudsters know us better than we do in that they’ve pegged our vulnerabilities. It’s time we returned the favor. They are vulnerable because they must do very similar behaviors to be successful, and guess what? We can find them by their tell-tale signals.

In order to detect out of character and potentially fraudulent transactions before they can create a financial nightmare for consumers, we must adopt new authentication methods that they can’t deceive.  Solutions based on consumer behavior and interactional signals are leading the way to providing more safety for consumers, and less fraud in the marketplace.

To combat these types of attacks, consumers should always report emails to their banking provider. No legitimate organization will ask for security or banking details so consumers need to be suspicious of any email that requests this information.

Meanwhile there are steps that consumers can take to help secure themselves:
  • Shop with well-known companies online, or use safer payment systems such as PayPal, ApplePay, Android pay, to avoid providing your payment details directly to an unknown merchant.
  • Use strong, unique passwords on each site you register with.
  • Make sure to change your passwords regularly.
  • Don't use public computers or free, unencrypted Wi-Fi to conduct financial or retail transactions or interactions.
  • Don't fall victim to email and phone scams, where a consumer receives a call from "their bank" asking for personal, or financial account information. If it looks too good to be true, it most likely is.  When I doubt, call the bank directly, based on the number printed on the back of your card, or on a recent statement.

Wednesday, July 13, 2016

Fraud, Inc.

Fraud, Inc.
by Robert Capps, VP at NuData Security

July 13, 2016 - Eskenzi PR - While fraudsters are getting more sophisticated and organized, they are also growing in numbers. The relative ease in which an individual can commit credit card fraud, along with the sheer volume of cheap card account data available on the black market, makes it a highly lucrative business to be in. When combined with the number of vulnerable merchants, and the lack of accountability, well, every day is Christmas day.

Here's the math:
Ease of attack +
Bountiful cheap credit card data on the black market +
More opportunity to commit fraud +
Very lucrative +
Little down side of penalties/accountability
= more people who are willing to commit the crime.

So, why the US is the king of card fraud online? It's the ubiquity of eCommerce merchants that accept credit cards for payment, coupled with a lack of preparation on the part of most eCommerce merchants to combat fraud risks, and made worse by a lack of consistent cooperation between merchants, card brands, and issuing banks, to take a holistic stand against the card fraud risks.

Contrary to some reports, EMV adoption in the US is not currently driving the increase of Card Not Present (CNP) transaction fraud online, although in time it will eventually reduce CNP fraud from counterfeit cards being created and used in store.

Consumers as Unwitting Accomplices
Consumers are victims of financial/card fraud over and over, because they continue to shop at the same places, and use their cards in the same ways, even after cards have been replaced. Often, falling victim to the same ongoing skimming and data theft attacks against a compromised retailer.

Even our own devices are sometimes complicit in the theft, with malware and other threats often resident on them, leading to immediate re-compromise after a card is replaced by a financial institution.

We've seen that new account/application is fraud rising due to the ubiquity of rich consumer data available on social media, and via other sources. Making it easier for those with malicious intent to go out and apply for a loan or credit card in your name, or even engineering their way in to controlling your existing accounts. This puts good cards and accounts in the hands of the bad guy, allowing them more time, and greater access to the credit line of a legitimate consumer, often before the crime is detected and can be mitigated. In some cases, access may persist for months before it is detected, often because the overdue notices begin to arrive in the legitimate customer's mailbox.

Close the Door, for Good
There are solutions that protect merchants and consumers from identity and credit card fraud risks. One solution that is seeing broad adoption is based on the science of behavioral biometrics, which provides continuous, multi-factor authentication that goes beyond the typical static data matching used to identify consumers to their creditors, merchants, and banks.  Behavioral biometrics accomplishes this task, by evaluating the entire customer behavior profile, built up over time. Providing true insight in to how a customer behaves, and comparing these behaviors to other interactions by this user, it accurately identifies them in future interactions - all without adding friction to the user experience, and without opening up the legitimate user to impersonation and account takeover.

Studies like this continue to highlight what we’ve all been thinking for a long time, namely that true authentication demands a higher degree of scrutiny of the end user at the keyboard, not just device in use, or the static data entered into a web page.

Tuesday, October 20, 2015

Combating Account Takeover

Account takeovers are quickly becoming the new favorite fraud tactic for hackers. With personal data all at the top of the thieves' hit list, a small data breach can quickly expand into a wave of personal information that could cause problems for the fraud victim years down the track. This article discusses how small data breaches can mean big returns for criminals and hackers; why login details are key to fraudsters stealing your personal data; and how technology such as behavioral analytics can stop fraudsters before they acquire your details.

Monday, June 1, 2015

Why Insider Threats Are Succeeding


Why Insider Threats Are Succeeding

As corporate networks expand in scope and geographic area, it has become easier for insider threats to access sensitive data and inflict catastrophic damage. While the malicious insider comes with a different set of challenges than other security concerns, organizations can protect themselves with the right tools and mindset. In this article, Lancope CTO TK Keanini explains why early detection of these attackers can keep a security event from becoming a high-profile data breach.

Tuesday, February 14, 2012

Mobile payments will boost crime

Well, here's another "dog bites man" story. Is there any technical advance that won't boost crime? Don't all these advances become challenges to those with a criminal bent, or just curious? I'm not at ease with this, even though I use online banking. I'm still not sure how banks allow deposits based on a photo from a smartphone. Seems like that's ripe for abuse, too.