Fraudsters Make Data Theft Big Business
Jan 01, 0001
Jan 01, 0001
September 2014 By Scott Patterson, CFE Those who work, shop or just like to wander in the gilded aisles of Saks Fifth Avenue department stores know just what the Manhattan-born retailer represents: Luxury. Status. The very best apparel, jewelry and sundry other merchandise money can buy. So when a ring of employees from a Saks Fifth Avenue in the Queens borough of New York decided to commit theft using “borrowed” customers’ credit card information, they must have thought to themselves: “Why go anywhere else?”
September 2014
By Scott Patterson, CFE
Those who work, shop or just like to wander in the gilded aisles of Saks Fifth Avenue department stores know just what the Manhattan-born retailer represents: Luxury. Status. The very best apparel, jewelry and sundry other merchandise money can buy. So when a ring of employees from a Saks Fifth Avenue in the Queens borough of New York decided to commit theft using “borrowed” customers’ credit card information, they must have thought to themselves: “Why go anywhere else?”
In a case of what the New York Post referred to as “binge shopping,” the crew of six employees obtained the credit card information of 22 Saks customers and spent nearly four months making illicit purchases on their accounts. The data was lifted from the store’s computer system by the gang’s ringleader, who then dispersed the information to sales associates who rang up various items (including, according to the article, hundreds of pairs of expensive shoes). After the employees were caught red-handed on store security video making the purchases, it was discovered that their haul had been worth at least $400,000.
While it is reassuring that they were caught – and some might question the wisdom of committing the fraud within their own store (where they could be easily identified on video) – their fraud still amounts to big headaches for the customers who were victimized. They face months and possibly years of dealing with law enforcement, credit card providers and credit reporting agencies. And for the retailer, there is still the challenge of recovering as much stolen merchandise possible – not to mention addressing questions regarding internal controls, employee screening and the protection of customers’ financial information.
A Small Part of a Large Concern
The Saks case is relatively small-time compared to what is happening on a more widespread scale in the retail world. The data breaches affecting Target, Neiman Marcus and other companies sent shockwaves due to their scope (in terms of customers affected). The 2013 Target breach, for example, involved information from more than 40 million credit and debit cards. News of the breach dramatically affected customers’ senses of security in dealing with Target, and the retailer’s profits in the fourth quarter of that year fell an estimated 40 percent.
Unfortunately, and as expected, the trouble did not stop there. More retailers have been hit with data breaches, the most notable being Home Depot. As in the Target case, the villain was a hacker (or hackers) and the scope of the compromised data is huge. In fact, Home Depot’s case might be the largest of its kind, surpassing Target and other retail data breaches.
Somewhat ironically, Home Depot will probably fare better than Target and other victimized retailers before it simply due to the public’s “desensitization,” if you will, to the issue of massive data thefts. That’s the gist of an article in USA TODAY that essentially suggests that the more we hear about data theft, the less we worry about it.
Getting Ahead of the Problem
Worry will come regardless, however, for any individual who learns that their credit information has been used nefariously. As in the Saks Fifth Avenue case, it might involve stolen property and having to go through the process of getting the charges reversed, possibly dealing with security and/or law enforcement personnel. Or, it could become an even more disturbing scenario. If the information is used for identity theft, the repercussions for the victim could be long-lasting and difficult to completely erase.
For fraud examiners, this type of criminal activity poses several challenges – not the least of which is that it represents more than just one type of crime. Data hacking is a computer crime – often committed from far-afield, across international borders and difficult to prosecute. Unraveling it requires specialized skills and, once uncovered, the challenge lies in trying to update protective measures and stay one step ahead of the hackers (and as the recent data thefts have shown, this might be futile).
On the other side of the fraud is the matter of how the data is used. In last year’s large retail data thefts, fraudulent charges were indeed made against customers’ credit card accounts – even ones that had been canceled. Needless to say, the information was put to criminal use quickly and investigators found themselves having to react to it. Given this scenario, it is imperative that fraud examiners be aware of the red flags of credit card fraud and the essential ways to combat it. They may be called upon by retailers, clients and individual consumers to help provide a level of protection once data has been compromised.
The ACFE’s 2014 Fraud Examiners Manual provides excellent guidelines for lessening the risk of credit card fraud. There are some behaviors that can tip off a retailer that a customer may be using a stolen or counterfeit card. Fraud examiners should urge retail clients to be alert for a customer who:
Takes a card from a pocket instead of a wallet or purse
Purchases an unusual number of expensive items
Makes random purchases, selecting items with little regard to size, quality or value
Makes several small purchases to stay under the floor limit, or asks what the floor limit is
Does not ask questions on major purchases
Signs the sales draft slowly or awkwardly
Charges expensive items on a newly valid credit card
Cannot provide photo ID when asked
Rushes the merchant or teller
Purchases a large item, such as a TV, and insists on taking it immediately, even when delivery is included in the price
Makes purchases and leaves the store, but then returns to make more purchases
Becomes argumentative with the teller or merchant while waiting for the transaction to be completed
Makes large purchases just after the store’s opening or as the store is closing
In the case of massive data thefts, the risk may be higher for card-not-present transactions, such as fraudulent purchases being made for products or services over the Internet. In such cases, merchants should be aware of the following red flags:
Larger than normal orders
Orders that include several of the same item
Orders made up of big-ticket items
Rush or overnight shipping
Shipping to an international address
Transactions with similar account numbers
Shipping to a single address, but transactions placed on multiple cards
Multiple transactions on one card over a short period of time
Multiple cards used from a single IP address
Orders from Internet addresses that make use of a free email service
Some fraudsters will actually fabricate counterfeit cards, using real card information stolen from legitimate card holders. These phony cards are usually cheap and easy to make. Fraud examiners should advise merchants to be aware of the following red flags of forged cards:
Holograms crudely stamped or badly faked with tiny bits of aluminum foil
Misspelled words on the card
Altered signature panel
Discolored
Glued
Painted
Covered with white tape
Cards that appear to be have been flattened and restamped
The fraud ring at Saks Fifth Avenue in Queens shows just how brazen credit card criminals can be. While it involved a relatively few number of victims, massive data thefts such as those committed against Target and Home Depot show the potentially large-scale danger this type of fraud can pose to individuals, retailers and the economy. Experts have made clear that more cases are on the horizon. The responsibility falls on investigators, security personnel and other anti-fraud professionals to help those who process credit card transactions to stay attuned to possible criminal behavior. Only through quick action can losses be limited and, in best-case scenarios, recovered.