December 23, 2013

Weak security makes U.S. cards a target

Retailers, banks and credit card issuers can do more to protect against hackers, but don’t want to bear the costs.

By Jonathan Fahey
The Associated Press

NEW YORK — The U.S. is the juiciest target for hackers hunting credit card information. And experts say incidents like the recent data theft at Target’s stores will get worse before they get better.

click image to enlarge

A customer signs his credit card receipt at a Target store. U.S. credit and debit cards are easier to copy, experts say, because of the magnetic strip they use instead of digital chips.

2008 file photo/The Associated Press

click image to enlarge

U.S. Sen. Charles Schumer, D-N.Y., pictured through a Target shopping cart, holds a news conference in New York on Sunday about the massive credit card hack that has affected 40 million Target customers.

The Associated Press

Additional Photos Below

Related headlines

That’s in part because U.S. credit and debit cards rely on an easy-to-copy magnetic strip on the back of the card, which stores account information using the same technology as cassette tapes.

“We are using 20th century cards against 21st century hackers,” says Mallory Duncan, general counsel at the National Retail Federation. “The thieves have moved on but the cards have not.”

In most countries outside the U.S., people carry cards that use digital chips to hold account information. The chip generates a unique code every time it’s used. That makes the cards more difficult for criminals to replicate. So difficult that they generally don’t bother.

“The U.S. is the top victim location for card counterfeit attacks like this,” says Jason Oxman, chief executive of the Electronic Transactions Association.

The Target breach, still under investigation, exposed the credit card and debit card information of as many as 40 million customers who swiped their cards between Nov. 27 and Dec. 15, likely including thousands who visited Target stores in Maine. It’s unclear how the breach occurred and what data, exactly, criminals have. Although security experts say no security system is fail-safe, there are several measures stores, banks and credit card companies can take to protect against these attacks.

Companies haven’t further enhanced security because it can be expensive. And while global credit and debit card fraud hit a record $11.27 billion last year, those costs accounted for just 5.2 cents of every $100 in transactions, according to the Nilson Report, which tracks global payments.

Another problem: retailers, banks and credit card companies each want someone else to foot most of the bill. Card companies want stores to pay to better protect their internal systems. Stores want card companies to issue more sophisticated cards. Banks want to preserve the profits they get from older processing systems.

CUSTOMER INFORMATION RECORDED

Card payment systems work much the way they have for decades. The magnetic strip on the back of a credit or debit card contains the cardholder’s name, account number, the card’s expiration date and a security code different from the three or four-digit security code printed on the back of most cards.

When the card is swiped at a store, an electronic conversation is begun between two banks. The store’s bank, which pays the store right away for the item the customer bought, needs to make sure the customer’s bank approves the transaction and will pay the store’s bank. On average, the conversation takes 1.4 seconds.

During that time the customer’s information flows through the network and is recorded, sometimes only briefly, on computers within the system controlled by payment processing companies. Retailers can store card numbers and expiration dates, but they are prohibited from storing more sensitive data such as the security code printed on the backs of cards or other personal identification numbers.

Hackers have been known to snag account information as it passes through the network or pilfer it from databases where it’s stored. Target says there is no indication that security codes on the back of customer credit cards were stolen. That would make it hard to use stolen account information to buy from most Internet retail sites. But the security code on the back of a card is not needed for in-person purchases. And because the magnetic strips on cards in the U.S. are so easy to make, thieves can simply reproduce them and issue fraudulent cards that look and feel like the real thing.

(Continued on page 2)

Were you interviewed for this story? If so, please fill out our accuracy form

Send question/comment to the editors


Additional Photos

click image to enlarge

Target says that about 40 million credit and debit card accounts may have been affected by a data breach that occurred just as the holiday shopping season shifted into high gear.

The Associated Press

  


Further Discussion

Here at OnlineSentinel.com we value our readers and are committed to growing our community by encouraging you to add to the discussion. To ensure conscientious dialogue we have implemented a strict no-bullying policy. To participate, you must follow our Terms of Use.

Questions about the article? Add them below and we’ll try to answer them or do a follow-up post as soon as we can. Technical problems? Email them to us with an exact description of the problem. Make sure to include:
  • Type of computer or mobile device your are using
  • Exact operating system and browser you are viewing the site on (TIP: You can easily determine your operating system here.)