PINs of Omission
Jan 01, 0001
Jan 01, 0001
With the relatively new chip technology in credit cards, many observers are concerned that the lack of a PIN requirement will undermine the effectiveness of the technology and result in only a minimal reduction of credit card fraud.
What CFEs should know about the U.S.’s approaching smart card transition
By Zach Capers, CFE
May 2015
In October 2015, the U.S. will finally transition to the world of smart cards — sort of. As the deadline to adopt the more secure credit card standard swiftly approaches, many observers are concerned that the lack of a PIN requirement will undermine the effectiveness of the technology and result in only a minimal reduction of credit card fraud.
A smart card is the same size as a traditional credit card but is embedded with a memory chip or microprocessor. The technology is also known in much of the world as chip-and-PIN because the user typically must be present with the card and enter a PIN code to complete a transaction. However, rather than chip-and-pin, Americans will use a system called chip-and-signature, which — as is typical of a magnetic stripe credit card — requires a signature instead of a PIN.
The worldwide standard for smart card technology is known as EMV, which is an acronym for its developers: Europay, MasterCard and Visa. The EMV standard has already been adopted by more than 80 countries and has been proven to sharply reduce fraud related to counterfeit credit cards (magnetic stripe cards, in contrast, have proven far easier to duplicate). However, without a PIN requirement, EMV credit cards that are lost or stolen offer little more protection than the traditional magnetic stripe cards.
Fraud Liability Shift
While talk about the migration to the EMV standard has primarily focused on technology, the October deadline represents a fraud liability shift from card issuers to merchants for card-present (CP) transactions. Historically, when a card user experienced credit card fraud, the responsibility for resolving the issue was the purview of card issuers such as Visa and MasterCard. After the deadline, liability for fraudulent transactions will shift to any merchants that have not upgraded their point-of-sale terminals to process the more secure EMV credit cards.
While most major retailers are likely to be ready by the October deadline, many small businesses are scrambling to ensure that they have equipment in place to accept EMV cards. Several companies including Intuit, PayPal and Square have recently introduced affordable EMV compliant attachments for iOS and Android-based devices to fill the gap. Exceptions to the October deadline include owners of ATMs and automated fuel dispensers (AFDs), which have an extended deadline of October 2017.
Card-Not-Present Fraud
As authentication protocols are considerably weaker for card-not-present (CNP) transactions (e.g., transactions made online, over the phone, through a catalog, etc.), these channels are not expected to see a reduction in fraud; rather, CNP fraud is expected to rise significantly as it has in other countries that have switched to EMV technology. The idea is that, once one avenue for fraud is closed, criminals seek alternate methods that typically lead to an increase in online credit card fraud. However, because the PIN requirement is being left out of the EMV equation for CP transactions, it is difficult to predict how the transition will affect credit card fraud overall.
Hybrid Cards and Evolving Security Measures
Due to the ongoing transition and the extended roll-out period for ATMs and AFDs, most Americans will be using hybrid credit cards that employ both an EMV chip and a magnetic stripe for the foreseeable future. Additionally, customers receiving new cards might notice that many traditional credit card security features have evolved or changed completely. Embossed credit cards are slowly being supplanted by smooth credit cards in order to prevent physical card imprints that sometimes lead to fraud. Additionally, local bank branches are now able to produce unembossed debit cards within minutes, thus reducing the need to send cards through the mail — a process that is inherently susceptible to fraud. Some credit card issuers have even ceased printing the customer name and credit card number on the front of the card.
Securing Your Credit Card
While the use of smart cards will likely reduce some forms of credit card fraud in the U.S., customers must continue to be on guard against traditional and emerging methods of stealing credit card information. The following precautions can help reduce your chances of being victimized by credit card fraud:
Use cash when possible in situations that might require a clerk or waiter to remove your card from view.
When using a credit card online, ensure that the website and connection is secure, and never enter payment information over an open WiFi service.
Always take your receipts and destroy them with a cross-cut shredder.
Destroy credit card applications and safeguard any documents containing information that could be used to apply for credit.
Report lost or stolen credit cards immediately.
Conclusion
Many people point to the fact that individual Americans tend to have many more credit cards than people in other countries that use chip-and-pin, and that memorizing several PINs for several cards would be cumbersome. Additionally, some think that major card issuers do not have much incentive to reduce fraud because losses resulting from fraud represent such a small amount relative to their revenues. While this might be true for card issuers, those fraud losses are likely passed on to customers who could pay increased fees or interest rates as a result. With a recent report from Barclays showing that nearly half of the world’s credit card fraud occurs in the U.S., companies should not favor convenience or profits over security.