About The Blog

Debate at the intersection of business, technology and culture in the world of digital money, both commercial and government, a blog born from the Digital Money Forum in London and sponsored by Consult Hyperion

Advertisers

Technorati

  • Add to
Technorati Favorites

License

  • Creative Commons

    Attribution Non-Commercial Share Alike

    This work is licensed under a Creative Commons Attribution - Noncommercial - Share Alike 2.0 UK: England & Wales License.

    Please note that by replying in this Forum you agree to license your comments in the same way. Your comments may be edited and used but will always be attributed.

65 posts categorized "Crime & Fraud"

Prepaid could be, should be, great

By Dave Birch posted May 11 2011 at 10:51 PM

At the risk of turning into the Victor Meldrew of retail payments, I want to make a point about something. When I wrote about some bad experiences with contactless a couple of weeks ago, I did it because I genuinely care about this stuff, and I genuinely want the contactless experience to get better. I don't think the blog would be useful, particularly to my colleagues in the industry who read it, if it never contained criticism, so long as that criticism is well-founded and honest. Similarly with prepaid. I really like prepaid, I really want it to succeed and I really get upset when it doesn't work as well as it should.

Prepaid is growing. In the last five years, the volume of card transactions in Europe has grown about 9% per annum but the value has grown 7% per annum (because the average transaction size has fallen) and most of that growth has actually come from prepaid cards [F. Burelli. "Profitability dynamics of card payments" in Nordic Card Markets, Stockholm (Jan. 2010)]. Looking forward, the outlook appears to be pretty rosy. Yet I can't help feeling that prepaid isn't where it should be. My recent experiences with prepaid have been pretty good. I had a Visa prepaid card (which has just expired) that we were using as our "house" card at home: the kids used it when they needed to run to the supermarket or buy stuff for school. It had a simple web interface, I could see what they had been spending the money on and I could easily top it up from my debit card. Best of all, it didn't have a name on it, so if they lost it then no-one could use it in shops (because it's a chip and PIN card) or online (because they wouldn't know the name or address associated with the card). Now that it's expired, I got my eldest to go and get an Orange Cash card which annoyingly has a name on it (review to be posted shortly), so we'll see if that can take over as house card.

But I digress. Right now, I am annoyed with prepaid. Just as I was leaving for the airport, I remembered that I had less than $100 on my Travelex US Dollar prepaid card. As I was going to be in the US for a few days, I'd need a bit more to cover meals etc so I decided to load a couple of hundred more dollars. Now, obviously I wasn't going to bother to do that at the airport given the palaver I went through last time: I had £50 in cash in my pocket and I stopped at a Travelex booth in Heathrow to add it to my card and it took about a quarter of an hour and involved taking photocopies of my passport, the card, the receipt as well as answering security questions. The process was, presumably, designed to drive up the cost of prepaid cards to keep them beyond the reach of the poor.

Naturally, I thought that there would be some way to top up online, so I entered my 16-digit card number, my username and password and logged in to my cash passport account, only to find that there is no option for reloading (only for changing PIN and looking at transaction history). I went back to the home page and found that there's a separate option for reloading, I clicked that, and was asked to enter the first six digits of my card number. This took me back to the account screen. I went back round again, and somehow found another link (I can't remember what it was now) that asked my for the first six digits again and then took me to a reload screen. I entered the number of my Visa card, my address, the CVV and the amount, and was met with a screen saying tough luck.


Screen shot 2011-05-02 at 12.24.53

I wondered if it might be something to do with credit vs. debit, so I went round the loop again, this time using my Visa debit card instead. After typing in the amount, card number, address, CVV again, I got the same results. Much against my better judgement I decided to call, so I phoned the (mercifully) free phone number on the back of the card. I stupidly chose the option for speaking to an operator, and the line just went dead. So I dialled back and chose account services and then something else and then talk to an operator. I was shocked when a woman answered. After giving her my (I'm not making this up) card numbers, address, name, date of birth and a couple of other things, she put me through to another chap who said he would top up the card. I asked him if it was possible to do it via home banking and he said that it was and that he would e-mail me the details. After asking some more security questions, I started to give him my debit card number and he stopped me and said that he first had to check whether I was on the electoral roll at that address. I gave up, grabbed my BA Amex card and my John Lewis MasterCard and my Visa OnePulse and jumped in the cab.

All the way to the airport I was wondering why it was all so complicated. Why can't I load via the ATMs at the airport, or using an app on my iPhone or by PayPal. Prepaid should be a simple, inexpensive alternative to cash, not something that has you jumping through hoops! When I got the US, I decided to get another prepaid US$ card, but this time I would register it in the US so that I could have a US BIN and billing address (some stores, such as Levenger, will let you ship internationally but will only accept payment from cards with a US billing address). Although in the end I didn't have time, because I got sidetracked playing with my new Square, this does illustrate (once again) that there are lots of good reasons for wanting prepaid cards that are nothing to do with not being able to get a credit or debit card.

From the consumer side, prepaid allows consumers to test new opportunities and options without risking a lot of money or putting their bank accounts or credit cards on the line.

[From PaymentsJournal - When It Comes to New Payments Technology, Prepaid Will Lead the Way]

This is a good point, but I feel there's another reason for thinking that prepaid will be developing in interesting directions, at least in Europe. You don't need to be a bank to offer prepaid services: the combination of an Electronic Money Institution Licence (ELMI) and a Payment Institution Licence (PI) means that any company can offer a full service: an open-loop prepaid card. I suspect that many of the companies applying for these licences are doing so because they want to use new technology to deliver new services that need payment, if you see what I mean. That is, they don't expect to earn money from the payments themselves, but from the value-added services that need the payments to take place.

I'll be looking out for trends around value-added at this year's Prepaid Conference in London on 13th-15th June 2011. In an act of magnificent generosity, the wonderful people at Clarion have given me a delegate pass for the conference -- worth an amazing ONE THOUSAND FOUR HUNDRED AND NINETY FIVE POUNDS -- to give away on this blog as a competition prize. So if you are going to be in London on those dates and you'd like to come along to meet practitioners, thought leaders and me, then all you have to do is be the first person to respond to this post telling me what the conference sponsors MasterCard were originally called when they started in 1966.

In the traditional fashion, this competition is open to all except for employees of Consult Hyperion and members of my immediate family, is void where prohibited and has been designed to be carbon neutral. The prize must be claimed within three months. Oh, and no-one can win more than one of the Digital Money Blog prizes per calendar year.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

In all conscience

By Dave Birch posted Apr 14 2011 at 12:24 PM

I'm giving a keynote at the Smart Card Alliance conference in Chicago in a couple of weeks. It's going to be about EMV in the USA. I've just been mulling it over, and once again looked at Deborah Baxley's neat summary of the immediate future for the US cards business:

Banks scrambling to replace lost fee revenue will likely shift focus to credit and prepaid, impose DDA and other fees, along with new account services and comprehensive pricing packages.

[From Changing the Game in Cards - pymnts.com]

It's not just banks who have to rethink their strategies because of developments in the payment sector. I note that in the UK, according to the Centre for Economics & Business Research reported in Fraud Watch 6(18), nearly 100,000 people were victims of direct debt fraud last year, a direct consequence of the use of chip and PIN at retail POS. As card fraud has become more difficult, the criminals have shifted their focus. Direct debit fraud was one basis point of identity fraud cases a decade ago, now it is a tenth of all cases. Criminals have to adapt to chip and PIN just as banks and merchants do.

A GROUP of seven postmen intercepted letters containing credit cards, switched the microchips of the cards with fake ones and then delivered them to the applicants... the syndicate also had the help of a National Registration Department (NRD) officer who supplied them with the names of the mothers of the real credit card applicants

[From 7 M'sian postmen nabbed for credit card fraud]

It's interesting to think like a criminal. Well, sometimes. In Chicago, two men were shot by guards while trying to rob a cash transit.

The dead suspect was identified as Jimmy Townsend, 52... a convicted felon and was sentenced to 10 years in prison for two separate armed robbery convictions.

[From 2 suspects shot, one fatally, in armored truck heist - Chicago Breaking News]

Armed robbery is a bizarre crime. I think I'm right in saying that in the UK the average sentence is longer than that for murder. In the US, Mr. Townsend spent years in jail for it, and then got killed doing it again. How dumb did he have to be go back to trying to rob armoured cars. If only he read the Digital Money Blog, he would have known that there are much easier targets.

The heavily-armed gang made off with the tournament jackpot of 242,000 euros ($327,000; £217,000) in early March. Police said a 28-year-old Lebanese man, the fourth arrested in connection with the raid, had been detained on Sunday.

[From BBC News - German police arrest poker tournament heist suspect]

OK, so not all of them got away, but casinos are not a bad idea for enterprising criminals. They do have lots of cash, and often the people in them will not report cash as stolen.

Masked men have stormed a packed casino near the Swiss border city of Basel, making off with hundreds of thousands of francs, prosecutors say.

About 10 raiders pulled up at the Grand Casino in two cars just after 0400 (0200 GMT) and smashed their way in, brandishing machine-guns and pistols. The French-speaking gang ordered the 600 guests and employees to the floor while they emptied registers.

[From BBC News - Switzerland casino is robbed by armed gang]

Criminals follow the path of least resistance. I hope Bankerstuff don't mind me quoting from a marketing e-mail they sent me concerning a forthcoming webinar.

A Former Bank Robber Shares Security Insights During Live Webinar on April 28 from 2:00 - 3:00pm Eastern

Troy Evans pursued a career as a self-employed addict, drug dealer, gambler and thief for more than 15 years. Ultimately, his disregard of values and discipline resulted in a 13 year federal prison sentence. Facing the obstacles, pressures and violence of prison life, he was determined that his time behind bars would not be wasted... Having met and interviewed over 300 bank and credit union robbers he is able to give us a "look into the mind of the enemy". Troy answers questions such as... What can financial institutions do to deter a desperate criminal?

I would have thought than an obvious idea would be to not have any cash since, as another bank robber famously remarked, he went "where the money is"? When it comes to card payments, the money is in getting hold of card details and (because of the switch to chip and PIN) PINs. Here, the criminals soon adapted their strategies to deal with the new instruments.

Victorian Police believe international crime syndicates are bribing shop workers in return for access to EFTPOS terminals as part of an elaborate scam. They believe criminals have stolen as much as $80 million from Australian bank accounts over the past year...

The syndicates install cameras in ceilings to film people entering their identification numbers.

[From EFTPOS scam costs Australians $80m - ABC News (Australian Broadcasting Corporation)]

They're using these PINs (since they can't make counterfeit chip and PIN cards) with the card details to withdraw cash from ATMs. Once all of the cards and ATMs are chip-only, this avenue will be closed to them. Thus while chip and PIN isn't perfect, it's good enough to push criminals into other channels. So: a thought experiment...

Suppose we improve the security of payment systems to the point where they cannot, effectively, be broken. Theft, fraud and hacking are not possible. Where would criminals go next? I think they're spoilt for choice, so relatively small improvements in payment security would send them off to pasture news.

The poll of 533 firms shows that 55% experienced fraud in the last 12 months, with 61% of these hit more than once, a similar picture to the previous year. In total, 75% of the businesses participating in the study experienced online account takeover and/or online fraud.

[From Finextra: Account takeover fraud plaguing US small businesses]

SME account takeover seems much easier than armed robbery and much more profitable. The so-called man-in-the-middle attacks on OTP systems for remote access to baking accounts are an established attack vector.

According to BillingScore, 19.4% of the value of all transactions in the U.K. premium rate sector are fraudulent, or roughly £1 on every £5 spent. "With the premium rate sector in the U.K. mobile industry currently worth in the region of £700 million, this equates to £135.8 million per year being lost to fraud in the U.K. alone," the company said.

[From UK mobile operators 'hide' £136m annual fraud loss]

A fifth? As opposed to a few bp in cards? I predict that any forward-looking criminal in this scenario will be eyeing up the telecommunications opportunities. So let's look at what some forward-looking criminals are doing. I think criminals in eastern Europe are a useful barometer, because they tend to be well-educated and computer-savvy. And they get arrested for time to time so we can see what they get up to. Here's the stash of Romanian hackers arrested last year. You will, of course, note that it does not include low maximum balance prepaid cards or accounts.

77,350 euros, 49,000 U.S. dollars, 64,860 pounds, 60,645 lei, a luxury watch, a rifle, three pistols and 150 grams of gold. 70 laptops, 165 mobile phones, 35 desktop computers, 15 modems, new servers, 10 blank cards, 2425 SIM cards...

[From CyberCrime & Doing Time: Nicolae Popescu, Romanian hacker, at large!]

So not only the usual euros and dollars, but also gold (clearly the hackers were diversifying) and also two-and-a-half thousand SIM cards. Two-and-a-half thousand! Here are people taking the messages of convergence, future-proofing and cloud payments quite seriously. As Eric Schmidt said when still with Google, if you don't have a mobile strategy then you don't have a strategy. Now, if you're like me, you will wonder what on Earth they are going to do with these SIMs. Then I remembered something that I'd read a while ago.

Only days after almost two million Bulgarians registered their SIM cards, the Interior Ministry warns that new forms of abuse are appearing. According to the ministry, two cases had recently been uncovered in which telephone fraudsters had allegedly offered 50 leva to Romas for registered SIM cards, Bulgarian daily Standard reported... the Interior Ministry as saying that it expected a flood of SIM cards, registered to Romas and homeless people, to appear on the market in the coming weeks.

[From Interior Ministry warns of trade in registered pre-paid SIM cards - Bulgaria - The Sofia Echo]

Mystery solved. The answer to why there should be a significant value attached to SIM cards that you can buy for virtually nothing in any shop is, naturally, government policy. After pocketing their windfalls from selling their SIM cards, the homeless and Roma presumably went off to celebrate their good fortune, whereas the criminals went off to figure out how to create a mass supply instead of having to negotiate with individuals.

...only four months into 2010, and organised crime groups already have found ways of beating the system. In fact, there are unsuspecting people right now who are completely unaware that their mobile phones, or names and registration, are being used for serious criminal activities... Radio host Borislav Borissov found out that he was the "proud owner" of about 200 different SIM cards, all registered to his name and personal social security number.

[From Bulgarian criminals 'beating the system' of pre-paid SIM card registration - Bulgaria - The Sofia Echo]

I know where I'd invest my criminal dollars! Mobile is the future! No, of course, I'm just joking to make a point. If I really was going to invest dollars in a criminal enterprise, it would be in Somali pirates, except for one sticking point. I'm afraid my strict ethical position will not allow me to deal with these people.

The al Shabaab group, which professes loyalty to al Qaeda, said mobile money transfers (MMT) helped feed Western capitalism and were turning Somalia's Muslims against Islamic banking practices.

[From Somalia's al Shabaab bans mobile money transfers | Top News | Reuters]

I cannot do sufficient violence to my conscience to support a group who are against mobile payments.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

The fraud trajectory

By Dave Birch posted Feb 25 2011 at 3:33 PM

There's no doubt that chip and PIN is one of the key planks in the industry strategy to reduce card fraud to manageable levels (which is not the same as eliminating card fraud, note). One of the reasons why it is so secure is that is uses offline PIN verification, where the chip on the card checks that the PIN input at POS is the correct one. And since the PIN is known only to the cardholder, and they never divulge it, this provides validation that... no, wait...

Despite the strict recommendations from card providers about keeping your PIN confidential, research by shopping website VoucherCodes.co.uk has revealed that over half (59pc) of Brits are flouting the rules by sharing their bank card PIN codes and are putting their personal finances in jeopardy.

[From More than half of card users share their PIN - Telegraph]

Uh oh. But come on - anyone out there in the real world will know that it's impossible to get through life without giving your spouse your PIN. What happens when (to pick a hypothetical example) she can't remember what the hell she's done with her handbag and needs to get to Homebase to buy some paint? Or (to pick a hypothetical example) a husband may have stupidly left his wallet in his desk at work but needs to get cash out at an ATM on the way to a football game. Come on - we've all done it (except me, I should point out to the terms and conditions chaps at Barclaycard).

The poll of 3,000 people revealed that Brits are most likely to entrust their partners with this security information, but a surprising one in twenty (5pc) adults feel that it is safe to divulge this information to their children.

[From More than half of card users share their PIN - Telegraph]

What? Not in my house they don't. We have a Visa prepaid card for "house" use, so if the kids need to get some shopping, stuff for school or other supplies, they use that one, and I top it up online when necessary. It's a simple way to manage money, so I'm surprised more people don't do this: and it has the added benefit that it doesn't have a name on it, so if it gets lost or stolen it can't be used to start identity fraud.

Incidentally: 3 per cent of the people surveyed said that they wrote their PIN on a piece of paper and kept it in their wallet, which may account for at least some of the incidence of the ATM and POS chip and PIN fraud more plausibly than complex attacks on the unencrypted messages between the card and terminal.

There are plenty of other initiatives aimed at improving the overall level of card security. 3D-Secure has taken a long time to get traction but is now widely used in e-commerce. PCI-DSS is costing a fortune, but may reduce the industrial-scale counterfeiting of the magnetic stripe cards still widely used for retail payments in less-developed parts of the world.

In raids conducted Feb. 1, agents seized $300,000 in cash, three firearms and ammunition as well as equipment to make fake credit cards from the gang... The credit card details and stolen identity information was purchased from “online data traffickers via Web-based portals, and the purchasers would store the stolen credit card information in shared e-mail accounts, allowing several defendants to begin creating counterfeit credit cards,” prosecutors said.

[From US indicts 27 in Apple product credit-card fraud ring | MP3 Players | Macworld]

Anything that stops card details like these from falling into criminal hands so easily must be worth the money, right? Actually, on the costs of PCI-DSS, there may be some relief in sight for European retailers.

Visa last week announced a new programme which means European merchants will no longer need to prove they adhere to PCI DSS regulations on an annual basis, as long as 75 percent or more of their transactions originate from EMV-enabled chip and pin terminals. The programme will be introduced on 31 March, 2011

[From Visa PCI DSS exemptions send out mixed messages to merchants | Business Computing World]

So come on, it's not all bad. In fact the bottom line is that the fraud figures have been improving, and I expect them to improve further still over the next couple of years as we begin the integration of cards and mobiles. This is because even simple integration (eg, texting unusual transactions) delivers good returns and the impending integration of payments with handsets means that issuers will be able to go even further with 24/7 access to the "card". I won't rehearse the basic arguments, but I think there are many reasons for thinking that the mobile is a means to manage card fraud down, and line of thinking that we have presented frequently over the years.

So, are mobile payments safe or not? It's not a "yes" or "no" question, as we hope this discussion has shown. Let's ask another question instead: Can we make the risks of mobile transactions manageable? The answer to that is “yes”. In fact, in the particular case of mobile proximity payments, we happen to believe that there is more security overall in using a mobile than in using a card payment

[From TM Forum - Article: Mobile Payments - Safer than Cards?]

For one thing, as noted, we can use the mobile to provide information and as communication channel to report on and detect suspicious activity. Potentially more interesting, though, there are techniques that take advantage of the characteristics of the mobile channel, primarily location There are some practical problems to be overcome though.

ValidSoft [has] direct access to mobile networks, tables, and services around the globe and can provide mobile based location services without requiring that users opt in. Many financial institutions are interested in using these services for fraud detection but are concerned about the privacy implications and don’t want their customers thinking they are following them around.

[From Visa Europe sets trend with mobile location-based fraud detection]

Actually, I might well want my issuer to follow me around, but I might also want it to stop other people from following me around. Anyway, I'll be talking about this kind of thing -- including lessons from our practical experience advising leading payments organisations around the world and some of the things we are learning from the Ph.D in mobile handset security that Consult Hyperion is funding at the University of Surrey -- at the excellent UK Card Fraud Conference on 29th/30th March 2011 in London.

The magnificent people at DT Conferences have given me a delegate pass for the event -- worth an amazing ONE THOUSAND TWO HUNDRED POUNDS plus VAT -- to give away on this blog as a competition prize! So if you are going to be in London on those dates and you'd like to come along to meet some of the leading thinkers in the UK's fight against card fraud (and me) then all you have to do is be the first person to comment on this post with the name of the doomed precursor to 3D-Secure, the PKI-based online card payment security system developed in the 1990s: full name, please, not just the TLA!

In the traditional fashion, this competition is open to all except for employees of Consult Hyperion and members of my immediate family, is void where prohibited and has been gritted for your safety. The prize must be claimed within three months. Oh, and no-one can win more than one of the Digital Money Blog prizes per calendar year.

Why us?

By Dave Birch posted Feb 11 2011 at 11:18 AM

Our good friends at ACI Worldwide have just released their annual Global Card Fraud Survey, which contains some rather bad news: the UK has more card fraud than many other countries. We're up there with the US, with three times as many people affected than in Germany and the Netherlands. So a third of us have been victims of card fraud compared to only a tenth in Netherlands. Why? Are the Dutch more honest than Brits? Are their cards more sophisticated? No. I think there are two main reasons for this discrepancy.

First of all, while chip and PIN has cut fraud on the high street, card-not-present fraud is still a big problem. In the UK, cards still account for a big portion of online payments. In the Netherlands, and some other countries, they don't. More than two-thirds of Dutch e-commerce purchases are made with iDeal, a bank-based scheme that has no equivalent in the UK (or the US, or pretty much anywhere else for that matter).

Second, UK credit cards have high limits. In the last couple of weeks, both of my main card issuers have written to me raising credit limits (I didn't ask for this in either case). If you're going to steal some card details, you'd go for cards that are likely to be some way from their limit.

The survey wasn't all bad news, by any means. I found it interesting that the proportion of people who had been victims of card fraud but were satisfied with the response of their issuer had actually increased slightly, to almost four-fifths, which isn't bad. Personally, like the majority of people surveyed, the last time there was a strange charge on my card, the bank took off the charge then cancelled and reissued the card.

The agent informed me that new cards for me and my wife would be Fed-Ex’d, to arrive today or tomorrow. What followed were a series of texts from merchants that have my credit card on file for automatic billing, delighting me with the knowledge that I won’t be able to use such services as the Bay’s FasTrak toll lanes or uninterrupted cable service until I update my records.

[From I’m a five-time ID Fraud victim; How crazy is that? - Javelin Strategy & Research Blog]

Think how expensive this all this though: cancelling and re-issuing cards, call centre seats, letters and whatever else. So we still need to do better. Only around a third of people (fewer than before) said that they would switch financial institutions because of card fraud, which is bad news for people trying to sell anti-card fraud solutions to high street banks.

The poll of 970 UK adults, part of the bi-annual global Unisys Security Index, reveals that cyber-security is the public's chief concern, with 85% of respondents worried, and over 50% "seriously concerned", about bank card fraud and identity theft.

[From Finextra: Brits switching banks over security and privacy concerns - Unisys]

This is odd, I think. I couldn't care less about bank card fraud, since it's the banks' problem and not mine. I never use a debit card for anything, offline or online, so I'm totally protected by the legislation around credit cards. I'm more worried about identity theft, because it's more time consuming to put right, but that's a different issue (being discussed at the CSFI yesterday, as it happens).

The press release also noted that 81% of people have confidence in their issuer protecting them from fraud. I think that this may be a little simplistic, for that very reason: had I been asked for the survey, I would have said that I don't really care about Barclays' ability to prevent fraud on my splendid OnePulse credit card because it's their problem.

Are we bovvered?

By Dave Birch posted Sep 24 2010 at 2:35 PM

[Dave Birch] I was thinking that it might be fun to have a section on fraud at next year's Digital Money Forum, so that led to me to wonder about how card fraud is going at the moment and, more particularly, to wonder about the dynamics. Are consumers put off of e-commerce because they are worried about card fraud? It seems that it's not their priority.

Online consumers care more about convenience than card fraud,

[From Online card fraud not our problem? — Retail Fraud]

This is exactly what I told American Express when they phoned to offer me identity theft insurance yesterday. As I told the chap who called, I love my Amex BA card, but if someone steals the number and starts using it at Bolivian porn sites, I don't care, because it's Amex's problem and not mine. That's the beauty of credit cards. But does it lead to what economists term "perverse incentives" (which are nothing to do with Bolivian porn sites)? In other words, are people like me careless with their card details, thereby leading to more fraud, because we don't bear any responsibility for it? I certainly wouldn't pay for much in the way for fraud protection either.

A security vendor is trying to sell transaction monitoring services directly to consumers, a technology that until now has been offered primarily to banks.

[From service-mobile-phone-fight-fraud-targets-consumers - PaymentsSource Article]

This doesn't work for me, because if fraudsters use my credit card number to buy a car in Kazakhstan while I am in England, I don't care: it's the bank's problem, not mine, which is precisely why I value my credit card so highly and charge everything I possibly can on it.

Continue reading "Are we bovvered?" »

Is more e-crime actually identity crime?

By Dave Birch posted Sep 7 2010 at 12:44 PM

[Dave Birch] I was kindly invited along to a breakfast briefing on e-crime by the folks at International Business Wales. They are trying to develop the financial services business in Wales by bringing together business, academia and government to create a more effective infrastructure. Obviously, financial e-crime threatens this sort of development, so I can see why they would be interested in finding ways to avoid it. Naturally, I was mainly interested in the payments-related parts aspects of the discussion, but I was generally curious about the topic as a whole. Before I reflect on the presentation, an aside on the topic of financial e-crime. There's no doubt that financial e-crime is on the rise the world over: here is one just one case chosen almost completely at random:

Criminals have stolen more than $479,000 from a Pennsylvania housing development authority after infecting its computer system with the notorious Clampi Trojan. The crime is the latest in a rash of heists from small business banking users in the US, which has led some industry bodies to suggest radical lock-down procedures for companies banking online.

According to local press reports, the Trojan was installed through a fake Web site purporting to belong to Cumberland County Redevelopment Authority's bank, M&T.

Once installed, Clampi stole passcodes which were used to transfer the money to bank accounts set up by the hackers at 11 different financial institutions. About $109,000 has been recovered since the money was taken on 22 September.

[From Finextra: $479,000 heist from small business bank account lends weight to calls for online banking 'lock-down']

This is clearly recognisable e-crime, but there are many other forms. In the UK, the probably biggest single category of business fraud is VAT carousel fraud. Is this an e-crime or not? Even though the crime is perpetrated using computers, I wouldn't call it an e-crime, since exactly the same crime could be carried out in exactly the same way without computers. What about credit card fraud? That clearly needs computers to execute at scale, but again I wouldn't really call cloning magnetic stripes "e-crime". I'd give card fraud its own category.

Police in 12 countries have arrested 178 people accused of involvement in an international credit card cloning ring that is believed to have netted crooks around EUR20 million. According to the Spanish Interior ministry, the arrests come after a two-year investigation that culminated in 84 raids in Spain, Italy, Romania, France, Germany, Ireland, Sweden, Greece, Finland, Hungary, the US and Australia.

The raids turned up 11 cloning 'laboratories' with around 120,000 card numbers and 5000 fake cards found in Spain alone.

[From Finextra: Card cloning raids net 178 arrests]

What? $20m? That's peanuts. Some guy was just indicted for a fraud fifty times bigger than that.

Former South Florida lawyer Scott Rothstein was sentenced to 50 years in prison for using his law firm to run a $1.2 billion Ponzi scheme that financed a lavish lifestyle, bankrolled his firm and bought political influence.

[From Rothstein Gets 50 Years for $1.2 Billion Fraud (Update3) - BusinessWeek]

Card fraud is so last year. But on to the report.

Continue reading "Is more e-crime actually identity crime?" »

Prepaid preconceptions

By Dave Birch posted Aug 24 2010 at 4:09 PM

[Dave Birch] I've been involved in a few discussions about prepaid cards over the last couple of weeks. One of those discussions was about whether some prepaid products would remain viable under stricter regulatory conditions. Why would regulators want to increase the regulatory burden, and therefore cost, of products aimed at the unbanked? Well, in the US, prepaid cards are the focus on attention because of their supposed criminal use.

The "Stored Value Device Registration and Reporting Act of 2010" will close a loophole that has treated stored value cards differently than cash, money orders and traveler's checks..

  • Money stored in electronic devices would be considered the same as currency for regulatory purposes. Prepaid cards, cell phone chips and other electronic devices would be covered.
  • Stored value devices loaded with more than $10,000 would have to be registered with the Treasury Department.
  • The flow of money via stored value devices would be tracked. "There's no current data on how stored value devices are currently used" to smuggle funds, said Giffords.
[From Bills aims to snip cash-card money smuggling | Border]

Well, I'm sure there's lots of data on how stored-value is used, but it is of course private and the issuing banks would of course need a warrant to give it up. But I'm still curious to know whether criminal masterminds really are using prepaid cards instead of cash. My O2 Money card, for example, has a maximum balance of five hundred pounds unless you go through KYC/AML in which case it goes up to ten grand. So what criminal mastermind would want twenty O2 Money cards rather than a hundred $100 bills or twenty €500 notes? The article specifically mentions drug cartels, but when the police bust the Mr. Bigs, they don't find prepaid cards, they find cash.

"Don't trivialize this by calling these gift cards," Goddard said. "These devices can hold hundreds of thousands, if not millions of dollars."

[From Bills aims to snip cash-card money smuggling | Border]

No, they can't. The maximum you can put on a typical US prepaid card with going through KYC is $500-$1,000. But a drug-running master criminal might decide to get a hundred card and put $1,000 on each of them I suppose. Let's take a look at what we find in their treasure hoards.

The arrest of more than 2,200 persons and seizure of 74 tons of illicit drugs in 18 states in a massive nationwide undercover investigation by federal, state and local authorities has revealed that Mexican drug smuggling organizations are well entrenched in the United States... the operation accounted for $154 million in cash, 1,262 pounds of methamphetamine, 2.5 tons of cocaine, 1,410 pounds of heroin, 69 tons of marijuana, 501 weapons and 527 vehicles.

[From Massive bust nets suspects, drugs in 18 states - Washington Times]

But not, apparently, prepaid cards. Similarly, these ice men clearly prefer greenbacks to Starbucks' cards.

Authorities confiscated more than $200 million in U.S. currency from methamphetamine producers in one of this city's ritziest neighborhoods, they said Friday, calling it the largest drug cash seizure in history... Mexican officials said the cash seized was mostly in U.S. $100 bills and weighed at least 4,500 pounds.

[From Mexico meth raid yields $205 million in U.S. cash - latimes.com]

That's TWO TONS OF CASH. I suggest that the Senate turns its attention to the abolition of the $100 bill rather than imposing cost and inconvenience on my kids US$ "Cash Passport" cards that they have with them on vacation in California. Some more people who don't read my blog about the benefits of electronic payments over cash were uncovered last year.

Federal agents have rounded up more than 750 suspects in a wide-ranging crackdown on Mexican drug cartels operating inside the United States... The DEA seized more than 23 tons of marijuana, cocaine, heroin and methamphetamines; plus dozens of planes, boats and cars; more than $63 million in cash; and scores of weapons in the operation.

[From Feds Bust 750 In Mexico Cartel Crackdown - CBS News]

No mention again of their Sears gift cards or Walmoney. And, as an aside, the guy who owned the house that had the $200m in cash in it? He actually had $340m, most of which he spent in Las Vegas apparently, where the casinos assumed that he was legitimate businessman -- his mistress paid a million dollars in cash for an apartment, shouldn't that ring some alarm bells? -- unlike those Canadian casinos where the real criminals go to launder money.

Money laundering by organized crime groups is rampant at Canadian casinos but police are essentially doing nothing to combat it... "Since 2003, FINTRAC (the Financial Transactions and Reports Analysis Centre of Canada) has sent several disclosure reports to the RCMP on suspicious transactions involving casinos throughout Canada, with amounts totalling over $40 million," the 2009 report states.

[From Money laundering thrives at casinos: Report]

Come on. Prepaid cards don't make the slightest difference to criminals, tax evaders, drug smugglers or executive expense chats. But making them more expensive and more inconvenient does make a difference to people who are excluded from the financial system.

Continue reading "Prepaid preconceptions" »

Lolly Dolly

By Dave Birch posted Jul 23 2010 at 10:48 AM

[Dave Birch] I was leafing through the English newspapers on the plane the other day -- the usual kinds of thing, you know, men out on charity walk attacked and hospitalised by drunken yobs, public worker gets £80,000 payoff because new chairs cause backache, 18,000 Facebook tributes to murdering nutter and so on -- but it was the story of the thieving Air France stewardess that caught my eye. The light-fingered trolly dolly was arrested for stealing from sleeping first-class passengers. Her preferred pilfering plane route was Paris-Tokyo, apparently because Japanese tourists carry huge wads of cash around with them and, like any self-respecting criminal, she wanted cash.

Police have arrested French air stewardess Lucie R. (her identity is protected) in Tokyo on suspicion of stealing from First Class Air France passengers while they slept.

[From France24 - Air France stewardess stole from passengers while they slept]

Incidentally, I loved Air France's comment on this story, which was to say that only checked baggage is their responsibility and that theft from the cabin was a matter for travel insurance. Or, in English, "tough".

Continue reading "Lolly Dolly" »

The hole in the wall

By Dave Birch posted May 20 2010 at 2:25 PM

[Dave Birch] I've been thinking about ATMs this morning because of the news that

the man credited with being the inventor of the world's first hole-in-the-wall cash dispenser has died in hospital following a short illness. John Shepherd-Barron... died at Inverness's Raigmore Hospital on Saturday, at the age of 84.

[From BBC News - Inventor of cash machine, John Shepherd-Barron, dies]

It's astonishing, really, how quickly the ATM permeated society. Today it is taken for granted. But will it be around for long? There are some signs that the days of the ATM are waning.

SIGNS are emerging that Australia is moving towards a cashless society, with the number of consumers making ATM cash withdrawals dropping to the lowest point in more than six years.

[From Cash transactions on their way out | The Australian]

I shouldn't think the ATM manufacturers are throwing themselves off of buildings just yet. So long as people continue to use cash, the ATM is here to stay, and despite the best efforts of e-payment fanatics such as yours truly, they're going to be here for some time. But that wasn't what I was thinking about, because I'm in the middle of doing some work on trends in security technology for one of our UK customers, so what I was thinking was that ATMs will remain a focus for attack: the bad guys know that there is where the money is too.

Continue reading "The hole in the wall" »

Cash does have some unique properties

By Dave Birch posted May 10 2010 at 3:48 PM

[Dave Birch] The cost of cash isn't only the cost of the notes and coins, the ATMs and armoured cars, the night safes and counting machines. It's the lack of efficiency in the economy that goes with it. And economies that are stuck with cash are the worst off. So how much does cash cost in a developing economy? I happened across this figure while I was looking for something else in connection with a project that we are working on.

"The total cost of cash handling in Indonesia is Rp 6.13 trillion a year," she said.

[From More consumer purchases made in cash | The Jakarta Post]

It's hard to work out by calculating adjusted GDP and historic exchange rates, but I reckon this is about 0.5% of GDP, which is comparable to the UK. Considering that over 90% of all Indonesian retail transactions are in cash, this seems low to me, but who knows. Anyway, in discussion with someone else today, another point emerged. The real hidden cost of cash in developing countries is corruption.

A friend of mine just got shaken down by the Kenyan police in an excellent new scam. Watch out for this one next time you go to Nairobi! He got a approached by a man who wanted to talk to him: my friend ignored him and carried on walking down to the street. A few metres on he was stopped by two policemen who said that they had just seen my friend talking to someone who was a known terrorist and that they were going to arrest him and he would get five years in jail. Unless, that is, he could pay the fine for talking to known terrorists, which in Kenya is apparently $300. My friend was marched back to an ATM (the policemen were very specific that it had to be a Barclays ATM, connected to the Visa network) to get the money. If only, I thought, he had had been using the excellent M-PESA mobile money transfer! Then he could have paid the fine on the spot. That would have been much more efficient.

Continue reading "Cash does have some unique properties" »