Online ATM/debit card fraud estimated at $2.75 billion

By
Follow google news

Internet fraud involving automated teller machine (ATM)/debit cards has victimized about 3 million U.S. consumers and generated losses of $2.75 billion in the past year, according to market-research firm Gartner.

The findings were collected from a survey of 5,000 adults in the U.S. and covered the 12-month period ending in May.


The study showed that online criminals are stealing banking account data and passwords through phishing and keystroke logging attacks, and using the data for online bank transactions or shopping, or to create counterfeit cards. The average loss was more than $900.

"Criminals sometimes counterfeit ATM/debit cards with just account numbers and PINs in hand, and they can use this stolen information at ATMs to withdraw cash from a cardholder's account," Avivah Litan, Gartner security analyst, said in a statement. "They succeed when the card-issuing bank is not validating security codes on the magnetic stripe of the card while authorizing transactions."

Those security codes are stored in Track 2 of the magnetic stripe and link the physical card to the customer's account number, she said. About half of U.S.-based financial institutions are not validating that data while authorizing bank debit transactions, she said.

Banks can prevent attacks by modifying their ATM host systems to check for the security data, according to Litan. The Track 2 data is unknown to bank customers so it cannot be phished, and criminals generally cannot duplicate it.

www.gartner.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

WhatsApp unveils high-security mode

WhatsApp unveils high-security mode

Microsoft releases fix for flawed January security update

Microsoft releases fix for flawed January security update

Fix out for remotely exploited Cisco enterprise UC suite bug

Fix out for remotely exploited Cisco enterprise UC suite bug

Microsoft patches single-click Copilot data stealing attack

Microsoft patches single-click Copilot data stealing attack

Log In

  |  Forgot your password?