0 Comments

From card compromises and identity theft to network-security breaches and the potential for encryption hacks, mainstream media reports have flooded the airwaves and headlines with stories of high-tech breaches that have compromised ATMs and POS devices. But experts agree it's the relatively low-tech external attacks that consumers and deployers should be wary of.

Keep up-to-date on the latest ATM news.

Sign up for free, twice-weekly e-mail alerts

The tried and true methods of ATM attack are still the most popular among the fraudsters.

Skimming is still No.1


Story continues below...
Phoenix Interactive

Engage Customers with Strategic ATM Marketing
So, you’ve taken the plunge and launched one or more targeted offers at the ATM.  But, are you getting those 20% take-up rates you were hoping for?  Phoenix customers are. Find out five ways to drive more revenue with ATM marketing.

Anna Istnick, senior product marketing manager for North Canton, Ohio's Diebold Inc., says card-skimming is by far the world's No. 1 ATM-related crime.

In the United States, Boston-based TowerGroup estimates that FIs lose almost $1 billion annually to stolen card and skimming at the ATM and POS. And regardless of efforts to combat skimming, U.S. Secret Service estimates that fraud losses from skimming cost about $350,000 a day in the United States. (TowerGroup: "Turning Phishing into Cash: Criminal Convenience at the ATM?" August 2005.)

Andreas Pollklaesener, a banking security specialist for Paderborn, Germany-based Wincor Nixdorf International, says card-skimming at the ATM and point-of-sale continues to grow throughout the world. And as long as use of the magnetic-stripe lingers, card compromises will continue to grow.

"This crime is increasing all over the world," he said. "Many in the world still use the magnetic stripe at the POS and ATM to get consumer data and the PIN. And the two together can be used to create cards which are being sent over the Internet and can be used at any type of ATM to get money. This kind of crime is still growing, so skimming has a major effect."

Why is skimming so prevalent? Because it's easy, Pollklaesener said.

Fraudsters have learned how to manipulate the system by leaving a skimming device on an ATM for only 30 to 45 minutes. By the time an FI detects anything, the skimming device and the criminals are long gone.

The dawn of the Internet age has only fueled the problem.

"It used to take one or two weeks for the duplicated card data to be transferred to another country - now it takes only one to three days," Pollklaesener said. "And then the data is only used one to two months, so it's hard for networks to track. The trend is copy it fast, use it fast."

Manufacturers have responded to skimming problem with security features like "jitter" or "enhanced card drive," which varies the direction and speed of the card as it's read by the ATM. The varied motion scrambles the magnetic-stripe data as its read so that only the FI can read it. If the information is copied, it's illegible.

But opinions about jitter's effectiveness are divided.

start quoteJitter is a security feature, but it helps only for simple skimmers. With motorized skimmers or extended skimmers, only a sensory solution will protect them.end quote

- Andreas Pollklaesener,
Wincor Nixdorf

Even with the jitter, says Wincor's Pollklaesener, cards can still be skimmed.

"Jitter is a security feature, but it helps only for simple skimmers," he said. "With motorized skimmers or extended skimmers, only a sensory solution will protect them."

Rob Evans, director of industry marketing for Dayton, Ohio-based NCR Corp., says ATM security should be approached holistically.

"Jitter is very effective, but jitter is not all NCR recommends," he said. We also recommend the Fraudulent Device Inhibitor," which automatically sends an alert to the FI when one of its ATMs has been tampered with. The inhibitor also prevents cards-trapping. NCR's Intelligent Fraud Detection plays a similar role in that it detects changes to the ATM's fascia and actually prevents a skimming attack.

NCR has been conducting global surveys to gauge consumer confidence in the ATM.

Read the following survey results:

The ATM Industry Association is making strides to keep the industry informed about ATM-related crimes.

Read more about ATMIA's efforts:

Evans and Pollklaesener agree that using sensory technology to detect when something has been attached to an ATM is a good idea. With such technology an FI can be alerted when a change occurs, and it can then decide whether to take the affected ATM offline or not.

"We think that the best thing to do is to make the ATM the least attractive target," Evans said.

Ram raids come in a close second

Where card-skimming is primarily an FI ATM problem, ram-raid attacks are a retail/independent sales organization problem. And in the States, blunt-force attacks on the ATM have edged their way into first place among ATM-related crimes.

Off-premises machines, by their nature, are skimming deterrents, since they are always within eye-shot of a store clerk; but they're prime targets for ram raids. (Read also, Texas becomes hot spot for ATM ram raids.)

Like card-skimming, industry experts try to stay ahead of the ram-raid curve, but it's a challenge since the frequency of attacks tends to ebb and flow.

"It's just hard times," said Diebold's Istnick of the rise in ram raids. "It's just a reflection of desperation."

The industry is making strides to deter ram raids with ink-stain packs that explode when cassettes are removed, bull-horn-like alarms that go off when ATMs are shifted or moved, and by bolting ATMs more tightly to floors and foundation.

But common-sense approaches, like ensuring ATMs aren't located next to plate-glass windows or doorways - prime targets for ram raids - usually have the greatest impact, Evans said.

Increased awareness about some of those vulnerabilities has brought the industry together, Evans said. Though their vulnerabilities tend to differ, figuring out how to address ATM security from an industry perspective has narrowed the chasm between them.

"If the card-carrying public, says, for instance, 'I don't feel good about pulling out my debit card here at the bar and using the ATM,' it's a problem that affects all of us," he said. "It's a general consumer concern that really is bubbling up right now. You asked why now? Well that's why. Consumers are just picking up on this stuff."

Because of that "bubbling up" effect on public perception, NCR launched its NCR Secure initiative, a consulting service designed to help retailers and FIs up their ATM security.

Diebold initiated a similar effort last year with the launch of Playing It Safe, a Web site geared toward consumer safety at the ATM.

"One (ATM) problem is no more great than another," Evans said.

 

Related Content

Reader Comments

Add a Comment

We welcome your thoughtful comments. All comments will display your real name.

Want to participate in the discussion?

Or log in for complete access.

  • Clear
  • Post
Be the first to post a comment for this story.
Products & Services

KAL Banking/ Financial Solutions

http://global.networldalliance.com/new/images/products/KAL_Logo_SF100.gif

840/KAL-Banking-Financial-Solutions

ATM Compliance & Performance Solutions

http://global.networldalliance.com/new/images/products/4467.png

4467/ATM-Compliance-Performance-Solutions

Az-CARD

http://global.networldalliance.com/new/images/products/4585.png

4585/Az-CARD

Airis Sunlight Viewable Flat Panel LCD Display Upgrades

http://global.networldalliance.com/new/images/products/SunlightViewable100.gif

477/Airis-Sunlight-Viewable-Flat-Panel-LCD-Display-Upgrades

Tomorrow Technology Today

http://global.networldalliance.com/new/images/products/Phoenix_DW.jpg

1031/Tomorrow-Technology-Today

High Quality PCI V2.x EPP for Mini ATM- ZT598M

http://global.networldalliance.com/new/images/products/4000.png

4000/High-Quality-PCI-V2-x-EPP-for-Mini-ATM-ZT598M

Item Processing Reader Sorter Sales and Maintenance

http://global.networldalliance.com/new/images/products/780.png

780/Item-Processing-Reader-Sorter-Sales-and-Maintenance

Fully scalable and flexible - Monimax 5300XP

http://global.networldalliance.com/new/images/products/5300_xp_with_sidecar_100.gif

1160/Fully-scalable-and-flexible-Monimax-5300XP

FT5000 — Financial Through-the-Wall ATM

http://global.networldalliance.com/new/images/products/FT5000_100_0708.gif

536/FT5000-Financial-Through-the-Wall-ATM

Multi-Brand ATM Parts

http://global.networldalliance.com/new/images/products/Closeout_Parts_100.gif

1171/Multi-Brand-ATM-Parts

Request Information From Suppliers
Save time looking for suppliers. Complete this form to submit a Request for Information to our entire network of partners.
ATMIA