Feeds

Scammers say 'No' to drugs, 'Yes' to fraud

Path of least resistance

  • alert
  • submit to reddit

Providing a secure and efficient Helpdesk

RSA 2005 Better credit card fraud detection techniques are encouraging crooks to look for easier pickings elsewhere. "The path of least resistance is moving on from credit card fraud to checking [current] account fraud. Fraud on debit cards, ATM transactions and money transfers are all on the rise," said Avivah Litan, research director at analyst Gartner.

Gartner's research suggests that cheque forgery and account fraud often happens offline. By contrast, data disclosures that lead up to credit card fraud predominantly occur online. An April 2004 Gartner survey estimated that 9.4m US adults were the victim of ID fraud over the preceding 12 months.

Gartner puts losses at $1.2bn a year, the bulk of which finds its way to criminal syndicates in Eastern Europe and African states. "Banks do not move at lightening speed, but they are losing money. It's a sensitive subject. They don't like to talk about it, but they are hurting," said Litan. Credit card fraud is "less risky and more lucrative than drug dealing" so criminal gangs are expanding into the arena.

Addressing losses through phishing scams and the like is driving spending on security technology in the financial services industry. By 2007, Gartner predicts 70 per cent of banks worldwide (and 75 per cent in the US) would move on from using static passwords alone to protect online accounts. "Banks won't necessarily be using tokens but they will be using something stronger than passwords," Litan said.

The analyst also said that stronger authentication needs to be supplemented by intelligent back-end fraud detection. "Good fraud detection techniques are in place for credit card fraud, so consumers will get a call if suspicious transactions are put through their account. This needs to be replicated across the (financial services) industry," she said. ®

Related stories

Passwords? We don't need no stinking passwords
Tech industry puts phish on diet
Florida man sues bank over $90K wire fraud
ID thieves rip off 7m US adults a year (July 2003 survey

RSA 2005

All the Reg stories from this year's conference

Choosing a cloud hosting partner with confidence

More from The Register

next story
SMASH the Bash bug! Apple and Red Hat scramble for patch batches
'Applying multiple security updates is extremely difficult'
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
Hackers thrash Bash Shellshock bug: World races to cover hole
Update your gear now to avoid early attacks hitting the web
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.