Showing posts with label fraud. Show all posts
Showing posts with label fraud. Show all posts

Tuesday, May 24, 2011

Enterprises will adopt layered fraud prevention techniques

Posted by Mark Brousseau

By 2014, 15 percent of enterprises will adopt layered fraud prevention techniques for their internal systems to compensate for weaknesses inherent in using only authentication methods, according to Gartner, Inc.

Gartner analysts say no single layer of fraud prevention or authentication is enough to keep determined fraudsters out of enterprise systems. Multiple layers must be employed to defend against today's attacks and those that have yet to appear.

"Malware-based attacks against bank customers and company employees are levying severe reputational and financial damage on their victims. They are fast becoming a prevalent tool for attacking customer and corporate accounts, and stealing sensitive information or funds," said Avivah Litan, vice president and distinguished analyst at Gartner. "Fighting these and future types of attacks requires a layered fraud prevention approach."

Litan explained that while the layered approach to fraud prevention tries to keep the attackers from getting inside in the first place, it also assumes that they will make it in, and that multiple fraud prevention layers are needed to stop the damage once they do. She said that no authentication measure on its own, especially when communicating through a browser, is sufficient to counter today's threats.

Gartner breaks down fraud prevention into five layers:

Layer 1

Layer 1 is endpoint-centric, and it involves technologies deployed in the context of users and the endpoints they use. Layer 1 technologies include secure browsing applications or hardware, as well as transaction-signing devices. Transaction-signing devices can be dedicated tokens, telephones, PCs and more. Out-of-band or dedicated hardware-based transaction verification affords stronger security and a higher level of assurance than in-band processes do. The technologies in this layer can be typically deployed faster than those in subsequent layers and go a long way toward defeating malware-based attacks.

Layer 2

Layer 2 is navigation-centric; this monitors and analyzes session navigation behavior and compares it with navigation patterns that are expected on that site, or uses rules that identify abnormal and suspect navigation patterns. It's useful for spotting individual suspect transactions as well as fraud rings. This layer can also generally be deployed faster than those in Layers 3, 4 and 5, and it can be effective in identifying and defeating malware-based attacks.

Layer 3

Layer 3 is user- and account-centric for a specific channel, such as online sales; it monitors and analyzes user or account behavior and associated transactions and identifies anomalous behavior, using rules or statistical models. It may also use continuously updated profiles of users and accounts, as well as peer groups for comparing transactions and identifying the suspect ones.

Layer 4

Layer 4 is user- and account-centric across multiple channels and products. As with Layer 3, it looks for suspect user or account behavior, but it also offers the benefit of looking across channels and products and correlating alerts and activities for each user, account or entity.

Layer 5

Layer 5 is entity link analysis. It enables the analysis of relationships among internal and/or external entities and their attributes (for example, users, accounts, account attributes, machines and machine attributes) to detect organized or collusive criminal activities or misuse.

Litan said that, depending on the size and complexity of the end-user institution, implementing the systems that support a layered fraud management framework can take at least three to five years, especially when it comes to the upper layers — Layers 3, 4 and 5. These efforts are continuous, because fraud prevention rules and models require ongoing maintenance, tuning and care.

"Organizations don't have years to wait to introduce fraud prevention while malware-based attacks proliferate. We recommend starting with the first layer of this fraud prevention framework, as well as the second layer, resources permitting, since these can be deployed relatively quickly," says Litan. "Enterprises that start by deploying lower levels of the layered stack can help to stave off immediate threats, with the assurance that these layers are part of an overall strategy that relies on basic fraud prevention principles, such as user and account profiling that have generally stood the test of time."

What do you think?

Monday, March 14, 2011

BAI attendees look for new approach to fighting fraud

Posted by Mark Brousseau

Combating fraud -- and more efficiently and precisely identifying suspect transactions -- was the hot topic at last week's BAI Payments Connect conference in Phoenix, said US Dataworks (www.usdataworks.com) Product Manager Leilani Doyle (ldoyle@usdataworks.com).

"Here is the issue: financial institutions have fraud systems that send alerts each time a suspect transaction is idenitified," Doyle explained. "Seventy-five percent of these suspects prove to be false positives. Financial institutions need a better way to prune out the false positives with a higher percentage of accurately identified fraud."

"By using an enterprise fraud hub -- which consolidates payments and related data from various channels -- banks can reduce the number of false-suspect alerts they receive by more than 50 percent, without the risk of letting a higher number of fraudulent transactions slip through," Doyle said. "One bank did a presentation at the BAI conference explaining how breaking down payments silos would allow banks to more easily 'connect the dots' to identify systematic fraud. If payments silos do not share information, the ability to identify organized fraud is far more difficult -- if not impossible."

Another bank did a presentation at BAI Payments Connect on how it has used modeling to monitor a higher number of transactions while reducing the staff required for this function by over 30 percent.

Beyond fraud, another theme of the event was how banks can regain a competitive advantage in the payments space. Doyle noted that Federal Reserve Bank executive Richard Oliver gave an insightful presentation on how banks have lost their edge in transaction processing to non-bank competitors. Banks have been too slow to react to changing market demands, and this dawdling could eventually cause them to be lose further ground to nimble competitors with more compelling products, she said.

The good news: Oliver said businesses still have tremendous trust in banks -- something that should not be discounted. But banks will likely have to partner with other entities to bridge their product gaps.

What do you think?

Monday, July 12, 2010

Economic risks of data overload

By Ed Pearce (epearce@egisticsinc.com) of eGistics (www.eGisticsinc.com)

When data pours in by the millisecond and the mountain of information builds continuously, professionals inevitably cut corners and go with their 'gut' when making decisions that can impact financial markets, medical treatments or any number of time sensitive matters, according to a new study from Thomson Reuters. The study indicates that when faced with unsorted, unverified "raw" data, 60 percent of decision-makers will make "intuitive" decisions that can lead to poor outcomes.

Many government regulators have flagged increased financial risk-taking, which can be traced in some degree to imperfectly managed data, as a contributor to the recent financial crisis. Moreover, the world is awash with data -- roughly 800 exabytes -- and the velocity of information is increasing, Thomson Reuters says.

The challenge is that the staffing and investment needed to ensure that information and information channels are trusted, reliable and useful is not keeping pace. In fact, it is estimated that the information universe will increase by a factor of 44; the number of managed files by a factor of 67; storage by a factor of 30 but staffing and investment in careful management by a factor of 1.4.

"The solution to data overload is to provide decision makers with what Thomson Reuters calls Intelligent Information: better organized and structured information, rapidly conveyed to the users preferred device," says David Craig, executive vice president and chief strategy officer.

Fortunately, as the Thomson Reuters study notes, the same technological revolution that has resulted in the explosion of information also opens the way to new and improved tools for providing intelligent information: better organized and structured information, rapidly conveyed to the user's preferred device.

"We must use the benefits of the information technology revolution to minimize its risks. This is a joint task that the private sector and governments must closely focus on if we are to avoid systemic crises, in the future, whether we speak of finance, healthcare delivery, international security and a myriad of other areas," comments Craig.

How is your organization managing information overload?

Wednesday, March 25, 2009

Fraud Hits Financial Services Hardest

Posted by Mark Brousseau

Banks and financial services companies were the most commonly victimized industry by fraud (15 percent), according to the 2008 Report to the Nation on Occupational Fraud and Abuse prepared by the Association of Certified Fraud Examiners. Banks and financial services companies are followed by government (12 percent) and healthcare (8 percent). The median loss for banks was $250,000 per case, according to the report.

What do you think? Post your comments below.

Sunday, February 22, 2009

School Revamps Computer Security

Posted by Mark Brousseau

An interesting item from this week's Palm Beach Post:

UF to revamp computer security systems after second breach
By KIMBERLY MILLER

Palm Beach Post Staff Writer
Thursday, February 19, 2009

The University of Florida is revamping its computer security systems following the second breach in less than a year that has left the personal information of thousands of students, faculty and staff vulnerable.

The Gainesville school announced Thursday that a hacker broke into its "Grove" computer system, which contained information, including social security numbers, for more than 97,200 people.

In June, 11,300 students and alumni were told that their personal information had been posted online and available to the public for several years.

School officials said in both cases that they have no proof personal information was taken from the sites.

"We know someone was in there, we don't know why they were in there and we don't know what they were doing there," said UF spokeswoman Janine Sikes, about the most recent incident. "We are stepping up our vigilance even more knowing that we've had these breaches."

The recent break-in was discovered Jan. 14 during a routine audit of the system. The program was immediately shut down and university police were notified.

Letters alerting people to the breach were mailed Wednesday.

Sikes said there was a delay in notification because it took two weeks to do the computer forensic work to see whose information may have been compromised. Preparing letters for more than 97,200 people and setting up a call center took another two weeks.

The information that may have been illegally accessed includes that of anyone who used the Grove computer system between 1996 and 2009.

About 3,075 Palm Beach County students attend UF. Another 412 are Martin County residents, and 345 hail from St. Lucie County.

The Grove system provided an online location for faculty to post course materials and class information. It also supported one of the few free e-mail services available on campus.

To verify identification, the system required students to enter their UF identification number, which until 2003 was also their social security number. Faculty records housed on the system also included student UF identification numbers.

Sikes said the system has now been retired.

University officials believe part of the reason for their vulnerability is that the school operates on a decentralized system where computer capabilities differ by college and department.

"We are moving ahead to centralize information technology functions so that we can create consistent approaches to security," Sikes said.

Monday, February 9, 2009

Identity Theft Up, Costs Down

Posted by Mark Brousseau

An interesting article from The Washington Post on identity theft:


Survey: Identity theft up, but costs fall sharply
By CANDICE CHOI
The Associated Press
Monday, February 9, 2009; 7:54 AM


NEW YORK -- The number of Americans ensnared by identity theft is on the rise, but victims are striking back more quickly and limiting how much is stolen.

In 2008, the number of identity theft cases jumped 22 percent to 9.9 million, according to a study released Monday by Javelin Strategy & Research. The good news is that the cost per incident _ including unrecovered losses and legal fees _ fell 31 percent to $496.

One reason for the spike in cases is likely the worsening economy. Just last month, 598,000 jobs were slashed across the country and unemployment jumped to 7.6 percent.

"The short story is that criminals are getting more desperate," said Jim Van Dyke, spokesman for Javelin, which started tracking identity theft cases in 2003. Last year marked the first time the number of cases rose.

Crimes of opportunity, such as stolen wallets, were linked to 43 percent of cases last year, up from 33 percent in 2007. That might be why women were 26 percent more likely to be victims of identity theft; they reported more cases of lost or stolen information during in-store purchases.

Online access accounted for only 11 percent of cases, according to the survey.

Despite the growing number of victims, the total fraud amount edged up just 7 percent to $48 billion over the previous year. That's because victims are uncovering cases faster to limit losses. Another reason is that financial institutions are taking more steps to thwart thieves, according to the Javelin study.

For instance, more banks now send change of address confirmations to the original address, Van Dyke said.

This prevents identity thieves from rerouting mail to different addresses and delaying victims' awareness that their accounts are siphoned off.

The Javelin study also found identity theft went undetected longer and cost twice as much when victims knew their attackers. More than 10 percent of victims knew their identity thieves.

Despite the rise in cases, there are simple steps people can take to prevent becoming a victim.

To start, leave personal checks and Social Security cards at home and be aware of who's around when giving personal information in public.

Some types of ID theft aren't preventable, however. Someone could get your personal information by hacking into a retailer's database, for instance.

So even if you're careful about protecting your information, monitor financial accounts regularly.

"Identity fraud is all about prevention and detection," Van Dyke said.

Thursday, October 23, 2008

Crooks Going Phishing

This summary is not available. Please click here to view the post.

Tuesday, October 14, 2008

Identity Theft: Not Dead Yet

Posted by Mark Brousseau

An interesting article from Fairfax Connection on the resiliency of identity theft crooks:

What’s in a Name?

Though national statistics are trending downward, millions of Americans still at risk for identity theft.

By Derek B. Johnson/The Connection
Wednesday, October 08, 2008

In nature, the early bird gets the worm.

Residents going through their bills one day and finding thousands of dollars worth of mystery purchases would be wise to follow a similar mantra: the early bird gets his identity back.

That is, at least, according to retired investigator Tom Polhemus of the financial crimes section of the Fairfax County Police Department. The sooner you act once you know your identity has been stolen, the more hours you save down the road dealing with police, banks, credit unions and bill collectors.

"The main thing that we advocate is you have a personal responsibility to keep on top of your own identity," said Polhemus. "You can’t expect the government, police or financial institutions to help you. If you don’t know, you don’t know."

Though national statistics are trending downward, identity theft remains one of the most prevalent crimes in the country. According to surveys conducted by the Federal Trade Commission and Javelin Strategy and Research, 8.4 million Americans reported being a victim of identity theft in 2007, with just over $50 billion being stolen. Those numbers were down significantly from previous years, with 10.1 million Americans in 2003 and 9.3 million Americans in 2005 reporting the same crime. However those statistics do not take into account victims who are unaware their identity has been stolen, and many cases may go unreported for months or even years until a victim hears from an out-of-state bill collector or a business looking for payment. Tammy Nealy is the director of public affairs for Lifelock, an Arizona-based personal fraud protection company. For those people still carrying their Social Security card in their wallet or purse, she has a message.

"Stop. You’re going to get pick-pocketed," said Nealy. "You never think your wallet or your purse is going to be stolen, but it happens."

In addition to providing information and education on keeping personal information safe, her company charges a monthly fee to contact each of the three major credit bureaus and put a fraud alert on a client’s account. Nealy said a victim of identity theft could spend up to hundreds of hours talking with police, creditors and other institutions in order to restore their credit back to its original state. The mean resolution time per victim, according to the 2007 FTC/Javelin survey, was 40 hours.

THE PROBLEM has become so prevalent because thieves have so many ways that they can use just a few pieces of personal information to impersonate their victim. Polhemus named writing personal checks was as one of the worst practices a person can do if they want to protect their identity.

"Paper checks are terrible. It’s too easy once you write a paper check, now I’ve got your routing and account number," he said.

Those numbers combined with a cellular phone number or other pieces of information are usually enough to rack up thousands of dollars in online gaming or purchases. Seniors and children are at a higher risk for fraud or identity theft than others, according to Nealy. Because most young children lack any pre-existing forms of identification and parents rarely check up on their children’s credit report, their identities are ripe for use. A child’s age does not matter, she said, because most children have no previously established credit.

As long as a thief uses the information to beat them to it, most children won’t discover they were victims until years later, while they’re applying for their first loan or checking account. If parents begin receiving catalogs or magazines in their child’s name, that’s usually a red flag signaling that identity is being used by someone else.

"It may be cute, but it can be damaging. That means there’s a credit report for that child and bank has sold that information to a marketing company," Nealy said.

Seniors, she said, tend to be more susceptible to phone or e-mail scams, giving out personal information to people impersonating police or government officials. While she called a person’s Social Security number the "key" to all other information pertaining to a person, the truth is very little information is required to steal an identity. E. Hunt Burke, president of Burke and Herbert Bank and Trust Company, said his bank deals regularly with such cases.

"The thing we see the most is people taking advantage of the elderly customers" Burke said. He also cited phone and e-mail scams as the preferred method thieves use when dealing with seniors.

In the case of a customer who has become a recent victim of identity theft, Burke and Herbert Bank has a 24-hour phone line to call into and will immediately freeze an account when identity theft is reported. The bank also provides secure e-mail accounts to their customers for sensitive information.

There is very little in the way of "too much" when it comes to protecting your identity, said Burke.

"Every week there’s a new technology or scam. I saw stainless steel wallets the other day and thought that was silly, but people really do have devices in their pockets that can read the [credit] cards in your wallet," he said.

Polhemus said as long as a victim is diligent in keeping track of their credit reports and notify the police and creditors within 60 days of the theft, the amount of damage and liability will be drastically curbed. Wait too long, and a person may double or triple the amount of time spent clearing his or her name. Victims may even be on the hook for some of the costs.

"If you open up a bank statement, look at it and see fraud, call the bank. They will take care of you," said Polhemus. "If you know you’re busy or the statement is depressing you and you throw it in the drawer, you are responsible for paying for it. You’re on the hook for that money."

Because fraud and identity crimes rely heavily on rapidly changing technology, state and federal laws are still catching up to the practices being put in place by the criminals they’re hunting.

Using information taken from a mailbox in Virginia, a thief can run up bills in Georgia, Wisconsin, California or any other state. That severely hampers the ability of investigators at the county level, like Polhemus, from pursuing all but the most serious and costly identity crimes.

"Our criteria, the things that we look at before we investigate a case of identity theft, is, first off, do we have a Fairfax County resident without money? Then we look at likelihood of successful prosecution," he said. "We could subpoena records and find out who was making those calls, but we’re not going to extradite him from Georgia."

Nealy said credit agencies should face tougher fines and regulations when their databanks of personal information are lost or stolen. "If there was a requirement for third-parties to have certain protocols in place, that’s really going to hold these companies accountable for information," she said.

Tuesday, August 19, 2008

Are We Vulnerable to Identity Theft?

Posted by Mark Brousseau

An interesting article from The Boston Globe about identity theft:

The breach

A loose-knit ring of hackers stole credit card data from unsuspecting US retailers. Though 11 people have been indicted, experts say the case shows how sophisticated identity-theft schemes have become.

By Ross Kerber, Globe Staff August 17, 2008

Five years ago, Albert Gonzalez allegedly used an unsecured radio link to tap into the computers of a BJ's Wholesale Club store in Miami and access customer credit-card numbers.

It was a simple trick, but it was only the beginning.

From that first break-in, Gonzalez and a ring of accomplices flew up the learning curve, prosecutors charge. They wirelessly broke into the computer networks of other stores including those operated by OfficeMax Inc., Boston Market Corp., Barnes & Noble Inc., and TJX Cos. And they apparently learned to decrypt customer PIN numbers, install sophisticated software, and park payment card data in offshore databases, in what the Justice Department on Aug. 5 called the biggest hacking and identity-theft case it has ever prosecuted - compromising more than 40 million credit and debit card accounts.

Court filings and interviews with investigators paint a picture of an international ring of 11 loosely knit conspirators from China to Ukraine, and show how quickly such criminal groups can graduate to increasingly sophisticated schemes to exploit the vulnerabilities that remain in the payment card network.

Despite the arrests, Gartner Inc. technology analyst Avivah Litan said it's too soon to relax. Though prosecutors tied the ring to some of the biggest breaches in this decade, their cases don't mention other intrusions such as one of Maine grocer Hannaford Bros. earlier this year.

Also worrisome, Litan said, was that the group allegedly was able to use fake ATM cards with real account numbers to withdraw money from bank machines, indicating they cracked the encryption of PIN numbers.

"The implications are ominous," Litan said. While many banks and retailers have begun using tougher encryption since then, some companies are still on the older standards that she called "inherently vulnerable."

Another technology analyst, Mary Monahan of Javelin Strategy & Research, said more stores have met data-security standards spelled out by Visa and MasterCard since the time of breaches like the one at TJX in 2005, which should make customers' card numbers more secure. Still, Hannaford met those standards at the time of its breach, illustrating how criminal tactics have evolved to stay ahead of defensive measures.

One lesson from this months' indictments, Monahan said, is how the hackers learned to become more sophisticated and global. "You can see that they're developing their skills over time, and transferring skills among one another," she said.

A defense attorney for Gonzalez, Rene Palomino, said his client will plead not guilty to the charges. He described Gonzalez, 27, as a self-taught computer consultant who first met several of the other defendants online.

Former informantIronically, the story of how the group of accomplices came to be begins with Gonzalez helping law enforcement officials. Though arrested in connection with theft from an automated teller machine in 2003, Gonzalez soon became a key Secret Service informant and even gave the agency security lectures, Palomino said. Gonzalez was best known for helping officials bring charges against a group known as the "Shadowcrew" after one of the online message boards that served as a marketplace for stolen payment card numbers - 1.7 million of them in all, prosecutors would charge.

Despite serving as an informant, the Justice Department claims, Gonzalez also began "wardriving" in the areas around US Highway 1 in Miami, according to this month's indictments. The term refers to the tactic of cruising in a vehicle with a laptop computer to spot unsecured connections to wireless systems maintained by various stores.

Gonzalez' partner in the wireless probes allegedly was another twentysomething, Christopher Scott, who Palomino said Gonzalez had met in online circles in Miami. Scott's attorney said he hasn't yet entered a plea.

According to the indictments, the pair first got lucky in 2003 at a BJ's Wholesale Club store, which wasn't using encryption software to protect customers' data, and accessed the account numbers of payment cards used by customers.

The next year Scott and another accomplice, described only by the acronym "J.J.," went further. Tapping into a similar access point at an OfficeMax store near the highway, they located data including customers' encrypted PIN numbers punched in when they used debit cards. They turned the data over to Gonzalez, who allegedly sent it to an unnamed coconspirator for decryption.

Filings and investigators say other stores hit by the ring included Barnes & Noble and Sports Authority, many in the Miami area. The indictments suggest the biggest breach began in July 2005 when Scott compromised two wireless access points of Marshalls' stores in the Miami area, both operated by Framingham retailer TJX Cos.

Soon the group was downloading payment card data from TJX's home servers. By the following May, in 2006, Scott had graduated to setting up a "virtual private network" connection to a TJX server, making it harder to detect the intrusion.

Next, Gonzalez brought in a Ukrainian, Maksym Yastremskiy, who prosecutors describe as an international trafficker of stolen card data who sold it on the Web. Via instant message in May 2006, Gonzalez allegedly asked Yastremskiy for help finding an undetectable "sniffer" program that would pick up customer card numbers and provide a feed of stolen data. Several days later, Scott, Gonzalez, and others installed sniffer programs onto a TJX server - likely provided by Yastremskiy, the indictment implies.

Craig Magaw, special agent in charge of the Secret Service's criminal investigative division, which led the probe of the hacker ring, said he had no evidence that Gonzalez and Yastremskiy ever met or spoke outside of their electronic communications. But their virtual connections, he said in an interview, were a common trait to criminal rings using web-based message boards.

"It's the usual M.O., where they can go to be anonymous and help each other further their activity," he said. "It's not just that they're selling the information but, if you go on these [message] boards, it's how to do compromises and giving advice. It's the criminals' playground."

Authorities arrested Yastremskiy in Turkey a year ago while he was visiting a resort. The US Postal Inspection Service confirmed to the Globe at the time that he was tied to the TJX probe.

Since then, neither the Justice Department nor Turkish officials have provided contact information for Yastremskiy or an attorney representing him.

Yastremskiy's laptop provided a trove of details including an e-mail tie to Gonzalez, Magaw said. Gonzalez was arrested May 7 at a hotel room in Miami in connection with a related hacking case to which he has also denied wrongdoing. Court papers show officials seized from him three laptop computers, and a Glock 27 automatic pistol.

Encoding blank cardsIn addition to showing how the group allegedly stole information, the indictments also shed light on how the ring may have used the data on the streets.

In 2005 and 2006, Gonzalez allegedly sold large amounts of payment card data to a person named only by the initials "J.W." This person allegedly encoded the information on the magnetic stripes of blank plastic payment cards, then used the cards to withdraw hundreds of thousands of dollars from ATMs and split the money with Gonzalez. Another unnamed San Diego purchaser also bought 100 blank payment cards from an individual in China connected to Yastremskiy in 2005, prosecutors charge.

Both examples recall cases in Florida last year in which state prosecutors won guilty pleas from six people who misused card numbers stolen from TJX. After obtaining blank cards magnetically encoded with the stolen numbers, they took the plastic to various Wal-Mart stores in Florida to buy gift cards that could be used like cash. In turn they used those cards to buy $8 million worth of expensive electronics, jewelry, and other items, officials said, returning some items for cash.

Details of how to encode blank cards with stolen account numbers are among the topics typically discussed on underground websites, security experts say; the Secret Service estimates there are 20 message boards or websites in the United States and overseas where criminals sell stolen numbers, trade tips, and form bonds like those between Gonzalez and Yastremskiy. Was theirs like an underground university? "I guess, but there's no diplomas coming out of there," Magaw said.

Or, as Massachusetts US Attorney Michael Sullivan put at a press conference announcing the indictments on Aug. 5: "There's no evidence that any of these people had PhDs."

Globe staff reporter Marion Schmidt contributed to this report. Ross Kerber can be reached at kerber@globe.com.

Monday, August 18, 2008

Ways To Help Prevent Fraud

Posted by Mark Brousseau

Deutsche Bank offers the following tips for proactively helping prevent fraud:

1. Know your customer
2. Create new account opening procedures
3. Never provide personal information in response to an unsolicited request
4. If you believe a contact may be illegitimate, get in touch with the financial institution yourself
5. Review account statements regularly to ensure all charges are correct
6. Know your employees
7. Employees need to be aware of and report any suspicious transactions or activity
8. Review hiring and mailroom procedures
9. Monitor activity (new accounts/establish thresholds)
10. Secure all check stock
11. Replace paper documents with electronic payments when possible
12. Move check disbursement activity to electronic payment
13. Conduct surprise audits
14. Understand the liability for fraud
15. Utilize positive pay (payee) services
16. Educate and train employees
17. Never share passwords or utilize them as generic passwords
18. Recertify users and access priveleges regularly
19. Do not write down passwords
20. Ensure segregation of duties
21. Assign priveleges based on job responsibilities, not convenience or availability
22. Do not deviate from procedures without a documented exception approval process
23. Carefully destroy papers with sensitive or identifying information
24. Ensure supervisory oversight by making managers accountable

For more information, you can access Deutsche Bank's Payments Fraud Prevention Webcast at www.highlinewebseminars.com/deutschebank or visit www.db.com/gtb.

Thursday, August 7, 2008

Shocking Internet Hack

Posted by Mark Brousseau

An interesting article from newsday.com about the incredible scope of a recent Internet hack case:

Feds astounded by volume, scope of Internet hack case
BY KEIKO MORRIS
mailto:keiko.morris@newsday.com?subject=Newsday.com
August 7, 2008

The sheer volume of the credit and debit card numbers stolen was astounding as was the far-flung cast of multinational characters in one of the largest Internet hacking and fraud cases federal prosecutors say they've seen in this country.

And while many credit card users are protected from full or partial liability, the scope of the impact of the mammoth case that snagged 11 people in the heist of more than 40 million card numbers is unknown.

For retailers, banks and credit card companies, Tuesday's announcement by federal prosecutors that they had unraveled a case stretching back years, highlighted the constant battle against Internet criminals. And although most consumers won't bear the burden immediately, the price of Internet fraud to banks and retailers could end up costing customers in the long run, technology security experts say.

"... The overall cost is high and you can bet your bottom dollar that that cost will get passed on to us, Joe Average card holder," said Ed Moyle, manager at CTG, an Internet technology firm in Amherst, N.H.

The unveiling of the ring and the numerous charges, including fraud and identity theft, was reason for retailers to rejoice, industry experts said. The conspiracy, allegedly led by Albert "Segvec" Gonzalez, 27, of Miami, hit some of the biggest retailers, including TJX Cos., BJ's Wholesale Club, OfficeMax, DSW and Barnes & Noble, among others."

This was a very targeted attack on our industry," said Scott Krugman, spokesman for the National Retail Federation. "It took a very sophisticated network to do this."

The incidents in which the defendants -- hailing from Belarus and China and Ukraine -- found wireless access points to steal credit and debit card numbers date to 2003. TJX Cos. Inc. based in Framingham, Mass., discovered its computer system allegedly had been attacked by the defendants in 2006. Shoe retailer DSW was hit in 2005. Most of the major credit card companies and banks contacted declined to comment about the case specifically but said they know of the investigation and they have procedures to secure information. For card issuers, the cost to reissue cards is significant and, eventually will get passed down to consumers, Moyle said.

"The sheer number of retailers attacked by these cyber criminals demonstrates the much broader challenges in protecting sensitive customer data from this increasing threat," Sherry Lang, a TJX spokeswoman, said in a statement. "... Broader action beyond retailers alone is required to protect consumer data. Banks and the U.S. payment card industry must join retailers and work together."

Technology security experts said retailers and credit card companies fight a constant battle against cyber crimes and have made strides over the years to comply with technical standards set by the PCI Security Standards Council, a group founded by five of the major credit card companies, to protect information systems.Retailers worry more about their credibility with consumers and their confidence in using the electronic systems, said Brit Beemer, chairman of the market research firm America's Research Group.

The idea that more than 40 million card numbers were stolen from major national chains will make consumers wary, but both retail and technology security experts said they were skeptical the case will change the way consumers used their credit or debit cards.

Both experts and prosecutors said consumers should check their accounts as well as their credit reports and set up fraud alerts if they believe their information has been stolen. Consumers face the hassle of requesting new cards or accounts but institutions' zero-liability policies mean that consumers won't suffer the losses.

"They have zero-liability protection so that definitely helps them get over those fears associated with data breaches," said Bruce Cundiff, director of payments research at Javelin Strategy & research in San Francisco.

What do you think is the solution to these types of hacks?

Post your comment below.

Tuesday, July 22, 2008

Cybercrooks Target Online Banking

Posted by Mark Brousseau

An interesting article from USA Today on the latest wave of cybercrime:

Russian cybercrooks target high bank balances online
By Byron Acohido, USA TODAY

Call them the Coreflood Gang. A ring of cyber bank robbers from southern Russia has quietly perfected a way to get a beachhead inside company networks.

Once inside, it infects every PC within reach with a custom-made data-stealing program called Coreflood. The goal: go rip off bank accounts online.

Over the past 16 months, the Coreflood Gang has infected swaths of PCs inside thousands of companies, hospitals, universities and government agencies, says SecureWorks researcher Joe Stewart, who has tracked and documented the spread of Coreflood over that period.

"It's spying on you, capturing your log-ons, user names, passwords, bank balances, contents of your e-mail," Stewart says. "It can capture anything."

Coreflood is part of a class of malicious software, called banking trojans, designed primarily to help crooks break into bank accounts online. The number of banking trojans detected on the Internet this month topped 24,800, up from 3,342 at the start of 2006, security firm F-Secure says.

An infection usually starts when you visit a Web page implanted with a snippet of malicious coding. By simply navigating to the tainted page, your browser gets redirected, unseen, to a hub server that downloads the data-stealing program onto your hard drive.

Dozens of gangs specialize in banking trojans. They have it much easier than phishing scammers, who must lure victims into typing sensitive data on spoofed Web pages, says F-Secure researcher Patrik Runald.

"This is very organized crime," Runald says. "These gangs are hiring people and making tons of money."

The Coreflood Gang is among the most sophisticated. Stewart recently analyzed 500 gigabytes of stolen data stored on a rented hub server. He pinpointed 378,758 Coreflood infections inside thousands of organizations, small and large.

A workplace PC can get a new infection each time someone logs on. The most infections: a county school district with 31,425, a hotel chain with 14,093 and a health care company with 6,744. About 230 networks turned up with 50 or more Coreflood infections, while 35 networks each had 500 or more.

Gang members cull the stolen data for log-ons and account statements, especially bank accounts online with high balances. Next, they log into the accounts and make online cash transfers into "drop" accounts they control.

After having two hub servers shut down by the tech security community in May, the Coreflood Gang rented two new hubs and picked up where they left off. Today, they continue operations unimpeded, says Stewart.

Companies infiltrated by the Coreflood Gang need to rethink how they do network security. Employees surfing the Internet on work PCs ought to take pause. "If you don't understand the threats that are out there, then you probably should not be banking online," Stewart says.