credit card fraud - any ideas?

Status
Not open for further replies.
These credit card companies are stupid. If they would just require a 4 digit PIN with the card a lot of this theft would stop. But I was told (when my credit card info was stolen somehow on-line) that it's "too inconvenient" for customers to punch in a 4-diget PIN. What a joke.
 
In 10 years everyone will be right-hand micro-chipped and those cards will be useless. Only way for fraud-then will be cutting off the hand - then transporting the hand for use, or holding a gun to the victim's head, for his microchip to be used online.

Then a few years after that, the microchip will move to the forehead, for more secure use.
 
Originally Posted By: SubLGT
Been to a hotel recently? Consider this:
Quote:
According to Verizon‘s latest annual Data Breach Investigations Report (DBIR), malware attacks on point-of-sale systems used at front desk and hotel restaurant systems “are absolutely rampant” in the hospitality sector. Accommodation was the top industry for point-of-sale intrusions in this year’s data, with 87% of breaches within that pattern.

Quote:
"True, chip cards alone aren’t going to solve the whole problem. Hotels and other merchants that implement the ability to process chip cards still need to ensure the data is encrypted at every step of the transaction (known as “point-to-point” or “end-to-end” encryption). Investing in technology like tokenization — which allows merchants to store a code that represents the customer’s card data instead of the card data itself — also can help companies become less of a target."


Bingo, yes. In Vegas, at the Planet Hollywood hotel, 2013, was the only place I used the particular MasterCard, and fraud showed up quickly after there. They had my home address, and must have used that, or at least my zip code for the limited corroboration they used at merchants I guess. Desk clerk maybe. Or someone who hacked into or had access to their guest's data.
 
Originally Posted By: ZeeOSix
These credit card companies are stupid. If they would just require a 4 digit PIN with the card a lot of this theft would stop. But I was told (when my credit card info was stolen somehow on-line) that it's "too inconvenient" for customers to punch in a 4-diget PIN. What a joke.

That would work pretty well. Except for major database hacking where pin numbers are stored, but those should be encrypted and protected at the bank and not present in vendor's computers after a transaction, so PINs should work.

And, online vendors should almost never allow a product to be shipped to anywhere but the card holder's real home address. Or if they do allow that, the card holder should have to do something else to identify themselves.
 
The off shore scammers often use "pivot pigeons" in USA to receive packages bought online with breached card info, the pigeon relabels the box with prepaid label to off shore country and executes the re-ship. Often these pigeons are morons that fell for a "work at home" opportunity they "saw on Craigslist" and think they are working from home as "a shipping associate for an international company." I have personally witnessed a bedroom in an apartment so full of packages that it was difficult to find a pathway amongst it all.
 
I understood what you said. I simply replied that a physically stolen card or found card is not common at all (by stating the most common method and why they don't want your card). I had earlier stated that the lack of a pin is likely a transition state.

My stolen card info was taken to Apple and two purchases of $2k were attempted, with the card still in my pocket. What do you mean when you say "we see a lot of cases"? Is this in your professional life? I am basing my information purely on the media reports and from what I could find out after my card got copied.

Of course, a stolen physical card will probably become more prevalent in the future. They just aren't nearly as portable as a block of 100s or thousands of skimmed numbers. My card happened to have been done by an apparent local group in Houston that relied on the speed of use over avoiding risk of detection.

Now that I re-read your comment about the physical use of the chip card, I did "misunderstand" it. I missed the fact that you stated that the merchant is liable in the fraudulent chip situation. The liability since the changeover only lays with the merchant if they stick with using swipe. Chip transactions are on the bank dime.



Originally Posted By: LoneRanger
Originally Posted By: Coprolite
Loneranger, the most common physical fraud is skimming and then reproducing the magnetic encoding on a blank card. Duplicating chips is not easy at all...I haven't seen a news story that ever mentioned chip duplication as even being possible. Thieves don't want your physical card. If you dropped it, you would realize it quickly and cancel it. The big money was in duplicating the card and using it while the original owner still had the real card. Small charges could go unrecognized for quite a while. Now software is there with pattern analysis that can detect fraud quickly, but it isn't foolproof.

I understood that the main cost of the changeover was the hardware. I rarely see swipe only machines these days, with the majority of swiping happening on chip enabled hardware.. many fuel pumps could be swipe only, as I haven't seen one that uses a chip yet...


You either didn't read my posts or didn't understand. Perhaps I wasn't clear or was too wordy. Said that in USA the chip is useless for preventing fraud when you lose your card, because the person that has your card can do chip buys with it. Of course they can't once the bank kills it, but I assure you we see a lot of cases where the card is taken to a big box retailer within the hour and hit hard before the owner ever misses the card. Card dropped/lost, vehicle break-ins, kid/grandkid, is a drug user and lifts mom/dad's, grand parents, 's card and uses it.

Also said organized groups were doing cloning by mag strip re-encoding, which inherently states that the big profit is in card-present usage with cloned cards. Even "fraud tourism" by overseas groups.

Also included skimming in my replies by referring to "breached/skimmed/stolen card info."

Can't cash advance it? No problem, load up some gift cards and take 'em to the pawn shop where the crooked owner will give you 20 - 30 cents on the dollar for them then put them on the internet for 75 - 85 cents on the dollar. Or just boost the merch you got with it. Top brand power tools... super boostable. Plenty of cash to go buy some dope with.

Some banks and credit unions are still letting themselves get taken by the Fall Back Fraud cash advance scheme, usually between $3500 - $5000 a pop. I'll let Google be your friend on that one. Organized groups traveling in rental vehicles (usually nice SUV's) and not unusual to net five figures in a week or two.
 
Lone Ranger, I assume you are a LEO. I wouldn't be surprised if what you saw was mainly stolen or borrowed cards or the apprehension of the intermediary. I still maintain that the insidious larger number are the skimmed/hacked blocks of card numbers over the physical ones by a huge margin.

What was the seized value of the goods from the intermediary when compared to the other events that involved physical cards?
 
Funny this should come up at this time -- I got an e-mail from one of my credit card accounts confirming an address change that I didn't make. I log into my account and apparently I moved to Georgia (the state, not the country). Fortunately for me the jerk didn't change my userid/password so I was able to log in but everything including e-mail was changed. According to the company's fraud department, whoever called even had my SS# and the CCV code from the card so they had no reason to assume it wasn't me. There was already a $300+ charge on the account that I didn't make, and this is a chipped card.

My account now has a new card on the way and a phone password so future attempts won't be successful -- I hope.

Not quite sure where this happened because I hadn't used the account for a couple of months, but I did use it recently for an online purchase so I suspect that's where it happened -- that would explain how they got the CCV code but I don't know for sure if the vendor is where the breach happened since I didn't give them my SS#. I do have another card that I used with them so I'm watching that one now and if it gets hacked, then I'll have a better idea where to place blame.
 
Not always.
My debit card info got stolen and used that same day in New York City.
I am in Texas.I had used the card at a gas station and the clerk copied the card and sold it .
A month later NYC police busted a ring of thieves with over 300 fake cards.
The guy at the station got arrested
 
Just happened to me this last weekend. Have an app on my phone that notifies me with every debit card purchase. Saturday night, popped up with two declines for $20.95, and an accepted purchase for $50.95 at Marble Canyon Chevron in Arizona. I immediately locked the card via the app and called the Chevron. Whomever answered said, "nope! nobody's here!". Who knows if they where part of the theft or not. Went to the credit union to hand in paperwork by 9:30 AM on Monday and the teller said I was the 5th person so far that day to report a debit card number theft at that branch alone. It happens............A LOT.
 
Originally Posted By: 28oz
.. It happens............A LOT.


Based on the well-oiled machine that I dealt with this morning, I'd have to agree. The Fraud department had the process, including connecting me with one of the credit bureaus, down to a science.

Last year I had a different card hacked and someone in India took a lot of Uber rides before that bank's computers noticed. I suspect that they were very aware of the breach because for the first time, ever, I was asked if I would be willing to testify in court should a legal case come out of that hacking.
 
Status
Not open for further replies.
Back
Top Bottom