Archive for the ‘Fraud’ Category

 
Feb
13
Posted (db) in Fraud, PCI, PIN, Point of Sale on February-13-2009

images

 

My colleague Andy Orrock writes an excellent post, "Methodology for watching PIN Pad Switches" which discusses a detective control that we put in place in OLS.Switch to detect when a PIN Pad has been changed at the point of sale, along with real time alerting of the event.

 

Digital Transaction has an article here, that discuses this type of attack, another summary is here and quoted below:

Investigators say the men would enter supermarkets late at night, distract the cashier and swap a PIN pad with an alternate machine that recorded each customer’s financial data. They could swap the equipment in as little as 12 seconds, prosecutors said.

After a while, the men would return, retrieve the machines and harvest the credit and debit card information. At least six supermarkets in Rhode Island and Massachusetts were targeted, and 238 people lost money.

Another consideration to make, is the physical security of payment terminals and pin pads, such as bolting them down or using locking stands and regular inspections.  See Verifones PIN Pad Security Best Practices for more.



 
Feb
05
Posted (db) in Breach, Fraud, Visa on February-5-2009

The Merchant Account Blog has a great post and great diagrams on what is called Common Point of Purchase or Point of Compromise (POC), this is one method of how a merchant or processor can be identified as the breach point in a payment card fraud / compromise scenario:

Fraud Detection

(from Merchant Account Blog )

Visa also has a presentation on this here: