Feeds

Chip and PIN fraud hits Lloyds TSB

Foreign ATM fraud loophole exposed by crooks

The Power of One eBook: Top reasons to choose HP BladeSystem

Lloyds TSB has admitted that flaws in the new Chip and PIN system recently introduced for debits cards in the UK open up the system to fraud. Conventional fraud may be down because of the system but crooks are still able to use cloned debit or credit cards in foreign ATMS.

Instead of authorising debit card transactions by signature Chip and PIN means that customers use a four digit PIN code to give the go-ahead to purchases.

Although cloned cards won't have a forged chip the PIN associated with this microchip is the same as that associated with a magnetic stripe. Foreign ATMs only read this magnetic strip and not the microchip. So providing fraudsters obtain the data on the magnetic strip, along with the associated PIN, they are able to make withdrawals overseas using a conventionally cloned card, something that wouldn't work on a UK high street. Delays in identifying foreign ATM cash withdrawals as potentially fraudulent are compounding the problem.

One Lloyds TSB customer had £3,000 withdrawn from an account via a series of 19 withdrawals in the Netherlands, the Daily Mail reports. Similar scams involving cash machines in France, Thailand and Hong Kong have hit other Mail readers. Lloyds TSB told the paper that it is updating its procedures in a bid to clamp down on a rise in fraudulent transactions from overseas bank accounts.

"In recent weeks, we have identified an increase in fraud via overseas cash machines," a Lloyds TSB spokesman told the Daily Mail. "We have reviewed the way we operate to protect our customers. We are always updating our many measures to prevent and detect fraud."

A spokeswoman for APACS, the banking association overseeing the introduction of Chip and PIN in the UK, said that victims of the fraud would get their money back but accepted that this may take some time. She defended the overall integrity of the system. "We never said there would be no card fraud. There has always been a difference between the banks' level of security and fraud detection. Some include monitoring cash withdrawals as part of their fraud detection systems," she said. ®

Designing a Defense for Mobile Applications

More from The Register

next story
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
Four fake Google haxbots hit YOUR WEBSITE every day
Goog the perfect ruse to slip into SEO orfice
Putin: Crack Tor for me and I'll make you a MILLIONAIRE
Russian Interior Ministry offers big pile o' roubles for busting pro-privacy browser
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.