Online ATM/debit card fraud estimated at $2.75 billion

By
Follow google news

Internet fraud involving automated teller machine (ATM)/debit cards has victimized about 3 million U.S. consumers and generated losses of $2.75 billion in the past year, according to market-research firm Gartner.

The findings were collected from a survey of 5,000 adults in the U.S. and covered the 12-month period ending in May.


The study showed that online criminals are stealing banking account data and passwords through phishing and keystroke logging attacks, and using the data for online bank transactions or shopping, or to create counterfeit cards. The average loss was more than $900.

"Criminals sometimes counterfeit ATM/debit cards with just account numbers and PINs in hand, and they can use this stolen information at ATMs to withdraw cash from a cardholder's account," Avivah Litan, Gartner security analyst, said in a statement. "They succeed when the card-issuing bank is not validating security codes on the magnetic stripe of the card while authorizing transactions."

Those security codes are stored in Track 2 of the magnetic stripe and link the physical card to the customer's account number, she said. About half of U.S.-based financial institutions are not validating that data while authorizing bank debit transactions, she said.

Banks can prevent attacks by modifying their ATM host systems to check for the security data, according to Litan. The Track 2 data is unknown to bank customers so it cannot be phished, and criminals generally cannot duplicate it.

www.gartner.com

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Apple overhauls security with iOS and macOS 27

Apple overhauls security with iOS and macOS 27

ASD warns Aussie Adobe Commerce and Magento stores under attack

ASD warns Aussie Adobe Commerce and Magento stores under attack

OpenAI rogue agent activity wider-ranging than disclosed

OpenAI rogue agent activity wider-ranging than disclosed

Hundreds of old, vulnerable Exchange servers remain in Australia

Hundreds of old, vulnerable Exchange servers remain in Australia

Log In

  |  Forgot your password?