#14unit 1online security and payment system

Credit card fraud / Theft

Theft and misuse of payment card information.

5-mark Exam Answer

5-mark answer

Credit card fraud is the theft and misuse of payment card information and is a major e-commerce security threat. Laudon and Traver note that the leading causes have shifted over time from physical card theft to systematic server hacking.

  • 1.Past: lost/stolen cards, employee theft, false identities
  • 2.Present: systematic hacking of corporate servers
  • 3.International orders: 2× domestic fraud rate
  • 4.Identity verification is a central issue
  • 5.EMV chips help reduce fraud

In the past, the most common cause of credit card fraud was a lost or stolen card that was used by someone else, followed by employee theft of customer numbers and stolen identities (criminals applying for credit cards using false identities).

Today, the most frequent cause of stolen cards and card information is the systematic hacking and looting of a corporate server where information on millions of credit card purchases is stored. For instance, Albert Gonzalez was sentenced to 20 years in prison in 2010 for organizing one of the largest thefts of credit card numbers in American history, breaking into TJX, BJ's, Barnes & Noble, and others, stealing over 160 million card numbers and causing over $200 million in losses.

International orders have a much higher risk of being fraudulent, with fraud losses twice those of domestic orders. If an international customer places an order and later disputes it, online merchants often have no way to verify that the package was actually delivered and that the credit card holder is the person who placed the order. As a result, most online merchants will not process international orders.

A central security issue of e-commerce is the difficulty of establishing the customer's identity. Currently there is no technology that can identify a person with absolute certainty; a lost or stolen EMV card can be used until cancelled. EMV technology cannot prevent data breaches, but it makes it harder for criminals to profit from the mass theft of credit card numbers.

Albert Gonzalez and Russian co-conspirators stole 160 million card numbers from TJX and other retailers by hacking their servers — a textbook case of modern credit card fraud.

Credit card fraud has evolved from physical card theft to large-scale server hacking. Until customer identity can be guaranteed with certainty, e-commerce firms remain at higher risk than traditional offline firms, even with EMV chips in use.

credit card frauddata breachserver hackingEMVidentityinternational orders

The exam interface follows the university paper pattern: Section A & B carry 5-mark questions; Section C carries objective questions.