credit card fraud - any ideas?

Status
Not open for further replies.
Originally Posted By: 04SE
I got a call today that my card had been used in Williamsport, TN. Mastercard and my account show a $6.13 charge to 'Worth House' what ever that is.

They obviously knew it was fraud as they cancelled the card before they called me. They lady at the card service company was great to deal with and had a sense of humor.

I can't find anything on Worth House via Google, any ideas?

No clue how/when my card # was stolen, I still have the card, it wasn't lost or anything.

First time I was glad that I answered a phone # I didn't recognize!


Hopefully you didn't give them any personal information, and were able to verify the false purchase while speaking with them. There ARE phishing scams that work like this.

If you are not sure, make a call right now to your CC company to verify they called you.

If their call was legit, then I'd recommend you to figure out where the card was used and who may have stolen the number. This happened to me last fall, two cards' information was stolen. I narrowed the places down to one where I had used both, and only use cash there now.
 
Originally Posted By: Donald
A charge for only $6 seems very low for fraud.

That was a test hit. There certainly would have been more to come.
Last time I was a victim, I was in DC. At the same time I was renting a car and seeing the sights, somebody was filling up with chicken wings at WingStop, renting movies, and doing a booty load of gambling and drinking in Saint Louis.
I had to get that straightened out via phone when my debit quit working in DC.
Doggone thieves... there should be a special place for them.
 
Thanks beanoil, that's what I was going to tell Donald. Test hit is a great way of putting it. An exploratory prelude to large charges to come.

Yes, thieves should be punished, in my opinion severely!
 
Originally Posted By: Garak
How are chip cards silly?


Because in the US the EMV chip is meaningless for fraud prevention. You drop your card in a parking lot anyone can go use it as a chip read transaction or do a traditional swipe. The only difference is who eats the fraud loss. October 1 2015 the rules changed when EMV chip cards began being issued in US. It used to be that merchants were golden on a card-present transaction-- if the card holder claimed fraud with the issuer (bank), then the merchant still keeps the money and the issuer ate the loss. No more. If the merchant accepts a card present transaction as a card swipe when they are equipped with a chip capable authorization kiosk, and the transaction later comes back as fraud then the merchant eats that loss, the bank is no longer covering it if it is a swipe method instead of chip insert. But still, anyone who gets hold of your chip card can go stick it in as a chip insert at the kiosk and walk out with the merchandise.

The chips only stop the putting of cloned card info onto the chips. The magnetic strip can still be re-encoded with your breached/skimmed/stolen card account data and used in a card-present retail store purchase by card swipe, as long as the merchant allows swipes to be done even thought they have the combo chip insert and swipe kiosk terminal at all their checkouts. Happens ALL THE TIME.

Overseas, card transactions are chip based AND pin number based. The US should adopt same. Card-present swipe transactions should be phased out completely, it should become chip only and in addition to chip only there should be a PIN entry required (like when you use an ATM). If/when that happens the retail sector will see a drop in fraud losses in the hundreds of millions if not a billion or three.

There are organized crime groups that travel and do card-present fraud with chip cards where the magnetic strip on reverse is re-encoded (cloned) with breached/skimmed/stolen card account number and data. The big box retailers are targeted and are taking it in the wahzoo on this. All because card swipe transactions are still allowed, and how easy it is to obtain breached/skimmed/stolen data and re-encode card mag stripes.

Eventually the hackers may succeed in cracking the current iteration of chip technology and be able to put breached/skimmed/stolen card info onto the EMV card chips, but until then the best way for the industry to combat card fraud is to shut down card-present transactions to chip insert only.
 
Originally Posted By: 04SE
I got a call today that my card had been used in Williamsport, TN. Mastercard and my account show a $6.13 charge to 'Worth House' what ever that is.

They obviously knew it was fraud as they cancelled the card before they called me. They lady at the card service company was great to deal with and had a sense of humor.

I can't find anything on Worth House via Google, any ideas?

No clue how/when my card # was stolen, I still have the card, it wasn't lost or anything.

First time I was glad that I answered a phone # I didn't recognize!


Likely what is known in the biz as a Collusive Merchant.
 
There is even "Fraud Tourism" occurring because the US system is so easy to exploit. Overseas persons, for instance let's say from Eastern Europe fly here and exploit ATM's with fraudulent re-encoded cards where they've obtained pin info with the breached data. They go on a spree draining cash from US ATM's then fly home.
 
Originally Posted By: LoneRanger
Originally Posted By: Garak
How are chip cards silly?

Because in the US the EMV chip is meaningless for fraud prevention.
Eventually the hackers may succeed in cracking the current iteration of chip technology and be able to put breached/skimmed/stolen card info onto the EMV card chips, but until then the best way for the industry to combat card fraud is to shut down card-present transactions to chip insert only.


The chip is not silly or meaningless, as merchants are supposed to be moving to requiring the chip to be used (not just swipe).
The chip isn't perfect, but merchants know they have to pay for the fraud if they don't read the chip, incentive for the merchants to do so.

All the card fraud I personally experienced in the last 5 years (3 incidents) would not have happened if the chip was there.

For specific other types of fraud, such as when the card itself is stolen, the stolen card can be used right away, UNTIL the owner stops (freezes) the card. My Discover Card I know has the ability to freeze the account from my smartphone, which works when an internet query happens at a fraudulent transaction point.

https://www.fastcompany.com/3049641/the-...-more-confusing
 
Last edited:
Originally Posted By: LoneRanger
Because in the US the EMV chip is meaningless for fraud prevention. You drop your card in a parking lot anyone can go use it as a chip read transaction or do a traditional swipe. The only difference is who eats the fraud loss.

Ahh, I see. We have the other system you mentioned, where the chip card and PIN entry are the norm. If you insert your chip card, you must enter your PIN. There are the RFID tap transactions, but those are limited in size and daily totals, as I recall. When it comes to swiping, certain merchant providers have, by software upgrade, simply disabled the magnetic stripe reader. In a lot of places, if your chip fails, you're finished. Similarly, if you have a prepaid credit card, you're finished before you start. So, as you pointed out, card-present swipe transactions are mostly finished up here.

Transactions with the card absent (aside from online transactions with the code on the back) are exceedingly difficult at most terminals, too, and then there is the liability shift you mentioned. It only gets more difficult with terminals asking clerks for more information and hiding the option behind more obscure menus and manager passwords. The main risk, if I lose my card, is someone using the tap feature, which I never use myself. The card providers claim there is no customer liability for that, but I'm not so convinced, at least in the long term. My view is if I simply never use tap, and someone steals my wallet and starts using tap, I at least have an historical record to point to. I never used tap for the last five years of having the card, so why would I start now?

oil_film_movies: I see the point being made, now. You guys are sort of in the place we were a couple years ago. At that point, a person could choose what to do at the terminal, assuming it had both a chip reader and magnetic stripe reader. If you had a credit card, you could swipe it and sign your invoice, or, you could use your PIN and insert the chip. With a debit card, it would be swipe and PIN or chip and PIN. Now, at many terminals, the swipe option is gone. In the current U.S. scenario, while merchants might prefer the customer use the chip and PIN, and the terminal is set up to allow it, and card providers may be doing some advertising campaigns, many will never switch their habit until forced. People still try to swipe regularly up here. Habits are hard to break.
 
It seems that credit card fraud is very common and that the credit card companies take care of the customer relatively easy. It's an annoyance and inconvenience, but what else am I missing? You get a new card, your account is repaired, and life goes on.

Are there other ramifications to your card getting scammed beyond this that I need to be aware of?
 
The liability being placed on the merchant is basically motivation for the merchant to join the modern world and convert to chip transactions. It is a free country, so they can continue with swipes if they accept the associated risk.

Chip and pin will likely follow at some point, but the swipes must go away first...chip only and tap only have proven to muchmore secure by far. I can't quote how much more secure the addition of a pin would make it on top of just the chip. implementation of applepay allowed apple to negotiate per transaction fees that are vastly lower than swipe. Of course applepay includes touchid along with the randomized tokens....a whole different class.
 
How are you guys figuring that chip without pin entry is any different in a card present scenario than just swiping the card? If I drop my chip credit card in the convenience store parking lot and some terd chooses to go use it, they can insert it as a chip read transaction and walk out with merchandise same as if they swiped the mag stripe. No difference other than by chipping it they've stuck the merchant with the loss instead of the bank that issued the card.

In the US right now there is no pin associated to the chip on *credit* cards. Debit cards issued by your bank where you maintain an account balance are a different story, but they can still be opted to be run as credit at the kiosk terminal as far as I know so then we're back to no pin entry on the credit side.

P.S. I only use credit cards, do not possess any debit card. Bank gave me one by default with account, I gave it back and had them issue me their ATM-only card which only works at ATM's w/ pin entry and will not work as a credit card or debit card. Using a credit card is using the bank's money, not yours. If the card gets jacked, it's the bank's money not yours. Your debit card gets jacked it IS your money the fraudster is spending and you get to spend a sleepless night or three waiting for your bank to make you whole again. In the meantime any ACH debits you have set up ricochet off your account if the fraud puts you beyond your overdraft protection thresholds...
 
Also, since I'm on my High Horse..... checks need to go away !! Checks are a huge weak link in the banking system that is being exploited big time. Once again, organized criminal syndicates are busy right now doing just that, mainly targeting checks written off business accts. Every time you hand out a check you are revealing everything about your account someone needs to exploit it, if they know what to do.
 
Loneranger, the most common physical fraud is skimming and then reproducing the magnetic encoding on a blank card. Duplicating chips is not easy at all...I haven't seen a news story that ever mentioned chip duplication as even being possible. Thieves don't want your physical card. If you dropped it, you would realize it quickly and cancel it. The big money was in duplicating the card and using it while the original owner still had the real card. Small charges could go unrecognized for quite a while. Now software is there with pattern analysis that can detect fraud quickly, but it isn't foolproof.

I understood that the main cost of the changeover was the hardware. I rarely see swipe only machines these days, with the majority of swiping happening on chip enabled hardware.. many fuel pumps could be swipe only, as I haven't seen one that uses a chip yet...
 
Originally Posted By: Coprolite
Loneranger, the most common physical fraud is skimming and then reproducing the magnetic encoding on a blank card. Duplicating chips is not easy at all...I haven't seen a news story that ever mentioned chip duplication as even being possible. Thieves don't want your physical card. If you dropped it, you would realize it quickly and cancel it. The big money was in duplicating the card and using it while the original owner still had the real card. Small charges could go unrecognized for quite a while. Now software is there with pattern analysis that can detect fraud quickly, but it isn't foolproof.

I understood that the main cost of the changeover was the hardware. I rarely see swipe only machines these days, with the majority of swiping happening on chip enabled hardware.. many fuel pumps could be swipe only, as I haven't seen one that uses a chip yet...


You either didn't read my posts or didn't understand. Perhaps I wasn't clear or was too wordy. Said that in USA the chip is useless for preventing fraud when you lose your card, because the person that has your card can do chip buys with it. Of course they can't once the bank kills it, but I assure you we see a lot of cases where the card is taken to a big box retailer within the hour and hit hard before the owner ever misses the card. Card dropped/lost, vehicle break-ins, kid/grandkid, is a drug user and lifts mom/dad's, grand parents, 's card and uses it.

Also said organized groups were doing cloning by mag strip re-encoding, which inherently states that the big profit is in card-present usage with cloned cards. Even "fraud tourism" by overseas groups.

Also included skimming in my replies by referring to "breached/skimmed/stolen card info."

Can't cash advance it? No problem, load up some gift cards and take 'em to the pawn shop where the crooked owner will give you 20 - 30 cents on the dollar for them then put them on the internet for 75 - 85 cents on the dollar. Or just boost the merch you got with it. Top brand power tools... super boostable. Plenty of cash to go buy some dope with.

Some banks and credit unions are still letting themselves get taken by the Fall Back Fraud cash advance scheme, usually between $3500 - $5000 a pop. I'll let Google be your friend on that one. Organized groups traveling in rental vehicles (usually nice SUV's) and not unusual to net five figures in a week or two.
 
It is common for thieves to "test" batches of card numbers for a very low purchase, until they get an approval.

Then they will continue on to larger purchases once they get a good card number.
 
On my latest debit card from Charles Schwab, which is chipped, I have to type a pin for every transaction. For online purchases, the zip code and billing address must match as well. So Donald Duck drive will not work on mine.

This is the bank, not the brokerage.
 
I've had at least a dozen CC hacked over the years. Debit card once too and the first. That was through my credit union and initially they wanted to ding me for the total loss and an over draft charge. But it was a Visa debit/credit card and after reminding the Credit Union of the Visa guarantee they covered all of it. I have never suffered a loss and all but two times the CC company or retailer caught it.

The last time was an over the phone purchase on a CC I had not used in a couple of years. Pretty easy to see where that info leaked out at.

Three times Walmart let the info out but each time I would get a cryptic message over the phone from them about it before the CC company closed the account.

Bottom line is if it's Visa or MasterCard they will cover the loss.
 
Originally Posted By: SHOZ
I've had at least a dozen CC hacked over the years. Debit card once too and the first.


Sounds like a lot, way above average. You might be living near some criminal merchants and/or employees more than the rest of us, the luck of the draw.
I think I went 20 years with no fraud, then had a rash of 3 or 4 in about 3 years. And I use my card a lot, constantly. I attribute the rash of fraud to Las Vegas, I'm guessing, since I suddenly went out there a lot for just a few years, and the fraud happened after. Vegas is known for extra amounts of criminal acitivity of all sorts.

Great stories above! Very illuminating on how all this works (or doesn't work!!).

I think we all agree the chip is a step in the right direction. A panacea? NO.

It does at least make it more challenging for theives. Slows them down, stops them sometimes.

As we speak, Russian, N. Korean, and Chinese spy services and criminal enterprises are working on cloning those embedded chips with the secret crypto algorithms inside to handshake with the point-of-sale.
 
Last edited:
It's a new world. There is no such thing as 100% financial security, or identity security.

Reading the reports at krebsonsecurity is a real eye opener.

Been to a hotel recently? Consider this:

Quote:
According to Verizon‘s latest annual Data Breach Investigations Report (DBIR), malware attacks on point-of-sale systems used at front desk and hotel restaurant systems “are absolutely rampant” in the hospitality sector. Accommodation was the top industry for point-of-sale intrusions in this year’s data, with 87% of breaches within that pattern.


https://krebsonsecurity.com/2017/07/trump-hotels-hit-by-3rd-card-breach-in-2-years/#more-39981

https://krebsonsecurity.com/2017/05/breach-at-sabre-corp-s-hospitality-unit/

Quote:
"True, chip cards alone aren’t going to solve the whole problem. Hotels and other merchants that implement the ability to process chip cards still need to ensure the data is encrypted at every step of the transaction (known as “point-to-point” or “end-to-end” encryption). Investing in technology like tokenization — which allows merchants to store a code that represents the customer’s card data instead of the card data itself — also can help companies become less of a target."
 
Last edited:
Status
Not open for further replies.
Back
Top Bottom