#14unit 1online security and payment system

Credit card fraud / Theft

Theft and misuse of payment card information.

Learning Objectives

  • Define credit card fraud in the e-commerce context.
  • Identify historical and modern causes of credit card fraud.
  • Explain why establishing customer identity is a central security issue.
  • Describe the role of EMV technology in reducing fraud.

Explanation

Credit card fraud is the theft and misuse of payment card information. In the past, the most common causes were lost or stolen cards and employee theft. Today, the most frequent cause is the systematic hacking and looting of corporate servers where millions of card purchases are stored.

Credit card fraud is a major e-commerce security threat that involves the theft and misuse of payment card information. In the past, the most common cause of credit card fraud was a lost or stolen card that was used by someone else, followed by employee theft of customer numbers and stolen identities (criminals applying for credit cards using false identities).

Today, the most frequent cause of stolen cards and card information is the systematic hacking and looting of a corporate server where information on millions of credit card purchases is stored. For instance, in 2010, Albert Gonzalez was sentenced to 20 years in prison for organizing one of the largest thefts of credit card numbers in American history. Along with several Russian co-conspirators, Gonzalez broke into the central computer systems of TJX, BJ's, Barnes & Noble, and other companies, stealing over 160 million card numbers and costing these firms over $200 million in losses.

International orders have a much higher risk of being fraudulent, with fraud losses twice those of domestic orders. If an international customer places an order and later disputes it, online merchants often have no way to verify that the package was actually delivered and that the credit card holder is the person who placed the order. As a result, most online merchants will not process international orders.

A central security issue of e-commerce is the difficulty of establishing the customer's identity. Currently there is no technology that can identify a person with absolute certainty. A lost or stolen EMV card can be used until the card is cancelled, just like a magnetic-strip card. Until a customer's identity can be guaranteed, online companies are at a higher risk of loss than traditional offline companies. EMV technology — chip-based cards — cannot prevent data breaches from occurring, but it makes it harder for criminals to profit from the mass theft of credit card numbers.

Key Points & Important Terms

Key Points

  • Credit card fraud is a major e-commerce security threat.
  • Past causes: lost/stolen cards, employee theft, false-identity applications.
  • Modern cause: systematic hacking of corporate servers storing card data.
  • Albert Gonzalez stole 160M+ card numbers (TJX, BJ's, Barnes & Noble).
  • International orders have 2× the fraud loss rate of domestic orders.
  • EMV chips help reduce — but don't eliminate — fraud.

Important Terms

Credit card fraud
The theft and misuse of payment card information for financial gain.
EMV technology
Chip-based card technology that makes it harder for criminals to profit from mass theft of card numbers.
Data breach
Unauthorized access to a system resulting in the theft of personal or corporate information.
Identity fraud
The unauthorized use of another person's personal data for illegal financial benefit.