CNP, Malware & Physical Attacks; The Future of Fraud in an EMV World.

Slides:



Advertisements
Similar presentations
AN ATM WITH AN EYE THE FUTURE,S TECHNOLOGY
Advertisements

Identity theft Protecting your credit identity. Identity Theft Three hundred forty three million was lost from consumers in 2002 The number of complaints.
Current Fraud Trends Kathy Druckenmiller, CFCI, CIRM, ACT Specialist April 29, /29/2014.
PRESENTED BY: FATIMA ALSALEH Credit Cards Fraud - skimmers -
BARBADOS 2013 RESPONSE OF INTERNATIONAL COMMERCIAL BANKS TO CARD PAYMENT FRAUD Presenter: Denver Frater Regional Director & Chief Security Officer Eastern.
2.7.1.G1 © Family Economics & Financial Education – December 2005– Get Ready to Take Charge of Your Finances – Electronic Banking Bonanza – Slide 1 Funded.
Fraud Trends and Organized White Collar Crime Presentation by Jeff Wahl, CFE.
CEL: Computers in Banking and Retail
The Third International Forum on Financial Consumer Protection & Education “Fostering Greater Consumer Protection & Education” Preventing Identity Theft.
Credit Card Fraud. Credit card fraud - situation when an individual uses another individual’s credit card for personal reasons while the owner is not.
1.7.2.G1 © Family Economics & Financial Education – Revised May 2005 – Financial Institutions Unit – Electronic Banking Funded by a grant from Take Charge.
© 2015 Fair Isaac Corporation. Confidential. This presentation is provided for the recipient only and cannot be reproduced or shared without Fair Isaac.
Electronic Commerce Semester 1 Term 1 Lecture 22.
Holley Myers CSCI101 Lab Lecture Thursday 2:00 10/25/07.
Credit Card Fraud PRESENTED BY THE VIRGINIA OFFICE OF THE ATTORNEY GENERAL June 2013.
Why Comply with PCI Security Standards?
E-Banking is the use of electronic means to conduct banking business, such as telephone, Internet, cell phone, or other device by way of secure internet.
It could be you! Or is it?  Identity theft is when someone uses your personally identifying information, like your name, Social Security number, or.
1 CUNA Mutual Group Proprietary Reproduction, Adaptation or Distribution Prohibited © CUNA Mutual Group 2010 Alaska Credit Union League Annual Meeting.
3.1.G1 © Family Economics & Financial Education – Revised October 2004 – Consumer Protection Unit – Identity Theft Funded by a grant from Take Charge America,
Members Ashley-Gail Wright Jade Mills Sami-Jo Bryant Ruth-Ann Robinson Kimberly Grey.
2.7.1.G1 © Family Economics & Financial Education – December 2005 – Get Ready To Take Charge of Your Finances – Electronic Banking Bonanza Funded by a.
© 2014 CustomerXPs Software Pvt Ltd | | Confidential 1 Tentacles of Fraud #StarfishBanks CustomerXPs Software Private Limited.
Protecting Yourself Against Identity Theft By Sierra Monif Next.
Hawk card (ID) Higher One card Hawk Card Vs. HigherOne card.
Getnationwide.com Let’s Talk about EMV Danielle Rourke.
Identity Theft.
ICT and Banks Banks use mainframe computers to maintain customer accounts. They store a record of each customer’s withdrawals and deposits. Each bank mainframe.
Indiana Department of Financial Institutions BANK ON IT Money Smart Course.
United States payments update Howard N. Forman, AAP Senior Vice President Electronic Payments Consultant © 2011 Wells Fargo Bank, N.A. All rights reserved.
Identity Theft How it happens and how to avoid it.
Identity Theft: Prepare and Protect Yourself. What is Identity Theft? Identity theft occurs when someone uses your personal information, without your.
Security A Payments Perspective Terry Dooley EVP & CIO SHAZAM Network.
Computer Vulnerabilities & Criminal Activity Identity Theft & Credit Card Fraud 6.1 March 1, 2010 Identity Theft & Credit Card Fraud 6.1 March 1, 2010.
Midsouth User Group Annual Conference
Stop cybercrime, protect privacy, save world. Chris Monteiro Cybercrime, dark web and internet security researcher Systems administrator Pirate / Digital.
Identity Theft!!! Bill Ketjen Matt Grodhaus Two forms of crime IDENTITY THEFT  Using personal information for deception IDENTITY FRAUD  Using personal.
1.7.2.G1 © Family Economics & Financial Education – Revised May 2005 – Financial Institutions Unit – Electronic Banking Funded by a grant from Take Charge.
5.6- Demonstrate how to be a responsible consumer in the 21 st century Roll Call Question: Something that you learned in this unit.
U.S. Department of Homeland Security United States Secret Service MCPF PRESENTATION Evolving Financial CrimeTrends & The Gateway ECTF ASAIC Doug Roberts.
ATM WITH AN EYE. An automated teller machine (ATM) or automatic banking machine (ABM) is a computerised telecommunications device that provides the clients.
ATM Fraud. Lost/stolen cards The Lost or Stolen physical card is becoming less of a target The data that can be skimmed is much more valuable and any.
How to Write Checks and Balance Accounts. Checking Account An account at a bank against which checks can be drawn by the account depositor Check – A document.
The Future. What will Change Fraud will not go away It will become more sophisticated and clever We have to step up to beat it June 16Caribbean Electronic.
EMV Operation and Attacks Tyler Moore CS7403, University of Tulsa Reading: Anderson Security Engineering, Ch (136—138), (328—343) Papers.
WHAT NEW, WHAT NEXT IN PAYMENT PROCESSING. EMV WHAT IS EMV? 3  An acronym created by Europay ®, MasterCard ® and Visa ®  The global standard for the.
Warm Up: Identity Theft: Quick Write 1. What is Identity Theft? 2. What is Fraud?
CNP, Malware & Physical Attacks; The Future of Fraud in an EMV World.
EMV.
Presented By: Mark Jordan
Take Charge of your Finances
Emerging Payments Market Developments: Trends and Risks James Van Dyke, President and Founder Presented at the Federal Reserve Bank of Atlanta, November.
Banking.
ATM WITH AN EYE Suresh kumar.
EMV & Parking – 6 Months On
SECURITY FEATURES OF ATM
Take Charge of your Finances
Discover the Boom in Electronic Banking!
Depository Institution Essentials
U. S. Payments Landscape Perspective
Inserted Shimming Device
ELECTRONIC PAYMENT SYSTEM.
Depository Institution Essentials
Identity Theft.
Discover the Boom in Electronic Banking!
Take Charge of your Finances
“Credit score vocabulary”
A Secret Service Perspective on Credit Card Fraud
New Jersey Gasoline C-Store Automotive Association
NCUCA Fraud and Risk Education April 17, 2019
Presentation transcript:

CNP, Malware & Physical Attacks; The Future of Fraud in an EMV World

How Will EMV Affect Fraud In the U.S.?

Fraud After EMV  Continued Skimming of Chip card for mag stripe data Chip Card will still contain Mag stripe data for foreseeable future  Non Chip Location Cash-outs & International Cash-outs of stolen Mag Stripe Data Mag stripe data will have to be used at non chip location  ATM Shimming Device Designed to Capture Chip Data and then is converted to mag stripe data  The GOOD NEWS: Eventual & Significant Decrease in card present fraud (5+yrs)

The EMV “Ripple Effect” on Fraud  Significant Increases in Card Not Present Fraud Online & telephonic purchases No more pictures of our suspects!!  Significant Increases in ID Theft to Conduct Account Takeover Fraud Network Intrusions to obtain PII and password information  Increase in Physical Attacks on ATMs Card Trapping / Cash Trapping / Gas Attacks & Malware Attacks  Revert to Traditional Financial Institutional Fraud  Counterfeit checks/Account Takeover/Wire Fraud/Cracking Cards/Loan Fraud/Synthetic ID Fraud

Card Crackin’ / Crackin’ Cards  Got it’s name from Chicago area.  Activity Started by “Gangster Disciples”  Also known as “Drops” or “Doing Drops” or “Dropping Paper”.  Organization recruits younger individuals and college aged students with good banking credit new debit accounts at financial institutions.  Accountholder turns over debit card and PIN number to member of organization.  Other individuals deposit counterfeit/stolen checks into the account via the ATM.

Instagram Video of Davey Hines

Adina Been CashinOut (CT Investigation)

How Much as EMV Affected Skimming (ATM Attack Statistics - EAST)  ATM Skimming makes up 36% of all ATM Fraud but accounts for 90% of all ATM fraud loss.  Card Trapping – 3.2 Million in losses  Logical (Malware) attacks – 11.7 Million in losses  Gas Attacks – 21 Million in losses  Skimming – 2.4 Billion in losses

State of ATM Attacks Current (U.S.)   1 st Generation Skimmers (Digital Skimming)   2 nd Generation Skimming (Analogue)   Cash Forking/Trapping   Shoulder Surfing/Chaining Attacks   POS Skimming Current (Europe)   2 nd Generation (Analogue Skimming   3 rd Generation (Stereo Skimming)   Virtual Skimming   Malware Attacks   Cash Forking/Trapping   Gas Attacks   EMV Pos Skimming   ATM Shimming

Current U.S. Trends in Skimming

Card Reader Tapping/Eavesdropping

Insert (Throat) Skimmers Photos provided by NCR

Deep Insert Skimmers Captures Mag-Stripe No Storage on Device – wireless Transmitter

Deployment of POS Skimming Evolving Fraud Trends In the U.S.

Walmart Skimmers

Ingenico i3070 tampered and legitimate device EMV POS Skimming (For Mag Stripe Data) | 57

Compromised Chip Terminal

Inserted Shimming Device

ATM Cash/Card Trapping/Forking

Malware Attacks on ATMs  Malware takes control of the ATM PC to:  Control communication between PC and cash dispenser.  Or captured stored card data contained on drive of ATM PC

Jackpotting

Malware Circuit Board Injection Attack Macau (Chinese Territory)  Malware Injection into ATM to capture/store card data and PIN

Criminals will not surrender….They will just adapt to the circumstances!

Detective Mark Solomon Greenwich Police Department CT Financial Crimes Task Force ATM Skimming Intelligence Network Coordinator IAFCI CT Chapter President (203) (cell) Questions?????