Showing posts with label Credit cards. Show all posts
Showing posts with label Credit cards. Show all posts

Thursday, October 15, 2015

Know about Card Skimming and how to protect your card

Of late there are many reports about frauds related to  Credit/Debit/ATM cards. In many instances it is reported that the card details were obtained by the  fraudsters  using a technique called "Skimming". 


In this article, the modus operandi of skimming and the precautionary steps to be taken by the card holders are given for the benefit of card users.


What is Card Skimming?

Skimming is the unauthorised copying of information stored on the magnetic strip of a credit/debit/atm card.  It is typically an "inside job" by a dishonest employee of a legitimate merchant. The dishonest employee usually procures a victim's  card number using basic methods such as photocopying receipts or more advanced methods such as using a small electronic device (skimmer) to swipe and store hundreds of victims’ credit card numbers

The employee  sells the information through a contact or on the Internet, at which point counterfeit cards with your details on it are made. The criminals go on a shopping spree with a copy of the credit or debit card, and cardholders are unaware of the fraud until a statement arrives with purchases they did not make. 

Watch this video(from Youtube) on Credit card Skimming operations:






Skimming of ATM cards:


Instances of skimming have been reported where the perpetrator has put a device over the card slot of an ATM (automated teller machine), which reads the magnetic strip as the user unknowingly passes their card through it. 


These devices are often used in conjunction with a miniature camera (inconspicuously attached to the ATM) to read the user's PIN at the same time. This method is being used very frequently in many parts of the world, including South America, e.g. in Argentina and Europe, e.g. in the Netherlands 


Another technique used is a keypad overlay that matches up with the buttons of the legitimate keypad below it and presses them when operated, but records or transmits the keylog of the PIN entered by wireless. 


The device or group of devices illicitly installed on an ATM are also colloquially known as a "skimmer". Recently-made ATMs now often run a picture of what the slot and keypad are supposed to look like as a background, so that consumers can identify foreign devices attached. (Source:http://en.wikipedia.org/wiki/Credit_card_fraud).


Preventive steps to avoid fraud by skimming:

  • If you are in a restaurant or in a shop and the assistant wants to swipe your card out of your sight, or in a second machine, you should ask for your card back straight away and either pay with a cheque or cash, or not make the purchase.
  • Keep your credit card and ATM cards safe. Do not share your personal identity number (PIN) with anyone. Do not keep any written copy of your PIN with the card.
  • Check your bank account and credit card statements when you get them. If you see a transaction you cannot explain, report it to your  bank.
  • Choose passwords that would be difficult for anyone else to guess and keep your password secret.
  • If you are using an ATM, take the time to check that there is nothing suspicious about the machine like an unusual gadget or camera .If the ATM looks suspicious, do not use it and alert the bank which owns the ATM.

       FINALLY  HOPE THAT ALL WILL AGREE THAT PREVENTION IS BETTER THAN CURE!           






Read more ...

Monday, July 13, 2015

New Norms for Credit Cards :Reserve Bank of India



All new debit and credit cards to be issued only for domestic usage unless international use is specifically sought by the customer.


Reserve Bank of India (RBI) vide Circular dated 28.02.2013 on “Security and Risk Mitigation Measures for Electronic Payment Transactions” has directed banks to put in place the following safety measures for Credit and Debit Card Transactions :

• All new debit and credit cards to be issued only for domestic usage unless international use is specifically sought by the customer. Such cards enabling international usage will have to be essentially EMV Chip and Pin enabled. (By June 30, 2013).

                                   Sample of EMV Chip and PIN enabled card

• Issuing banks should convert all existing Magstripe cards to EMV Chip card for all customers who have used their cards internationally at least once (for/through e-commerce/ATM/POS) (By June 30, 2013).


Backside of Existing Megastrip card(Sample)

• All the active Magstripe international cards issued by banks should have threshold limit for international usage. The threshold should be determined by the banks based on the risk profile of the customer and accepted by the customer (By June 30,2013).

• Banks should ensure that the terminals installed at the merchants for capturing card payments (including the double swipe terminals used) should be certified for PCI-DSS (Payment Card Industry – Data Security Standards) and PA-DSS (Payment Applications – Data Security Standards) (By June 30,2013).

• Bank should frame rules based on the transaction pattern of the usage of cards by the customers in coordination with the authorized card payment networks for arresting fraud (By June 30, 2013).

• Banks should ensure that all acquiring infrastructure that is currently operational on IP (internet protocol) based solutions are mandatorily made to go through PCI-DSS and PA-DSS certification. This should include acquirers, processors/aggregators and large merchants (By June 30, 2013).

• Banks should move towards real time fraud monitoring system at the earliest.

• Banks should provide easier methods (like SMS) for the customer to block his card and get a confirmation to that effect after blocking the card.

• Banks should move towards a system that facilitates implementation of additional facilitates implementation of additional factor of authentication for cards issued in India and used internationally (transactions acquired by banks located abroad).

After discussions with Banks, the RBI had issued the above guidelines vide Circular dated 28.02.2013 on “Security and Risk Mitigation Measures for Electronic Payment Transactions”.

Read more ...