PRINCETON JUNCTION, N.J.—Merchants are working diligently today to address U.S. card not present (CNP) fraud, a crime that has grown faster than many experts expected due to consumers’ interest in online shopping taking off this past year.
It was expected that when the EMV liability shift occurred in October of 2015 that crooks would begin to move some of their focus from POS theft to online. However, thieves’ interest here has been piqued, as consumers gravitate quickly to digital purchasing.
U.S. consumers’ attention to online buying is now a “seismic shift from in-store to online activity,” stated ACI Worldwide chief product officer Mike Braatz in a release. The company late last year forecast that U.S. CNP fraud attempt rates were expected to increase 43% by volume during the latest holiday shopping season over the same period in 2015.
According to Javelin Strategy and Research, CNP fraud spiked by 40% in 2016 over 2015.
Fraud Moving Online
In 2016 global online sales were projected to reach $216.32 billion—a 16.7% rise from the previous year—before rising to $250.28 billion in 2017, according to Global Risk Technologies, which expects CNP fraud to become more acute if the industry does not confront the problem now.
“As we knew before we got into EMV, one of the byproducts would be counterfeit fraud moving from the physical point of sale and start to attack the major card not present channels,” said Randy Vanderhoof, director of the U.S. Payments Forum. “But we are seeing it becoming a bigger problem faster because four years ago we could not predict the rate of acceleration in the online shopping channels.”
Vanderhoof said that the U.S. Payments Forum has been speaking with merchants and issuers for years about how CNP fraud will be increasing.
“We have educated merchants on the fact this shift will happen, bringing together various subject matter experts on card not present fraud and risk mitigation techniques to provide merchants and issuers with the best available knowledge on how they can implement CNP prevention measures, and at the same time work to prevent fraud at the point of sale.”
But Vanderhoof said that the rapid movement to online shopping has significantly raised total dollars spent via the channel, naturally increasing fraud dollar losses.
“Retailers in the last two years have been focused on upgrading their POS terminals to EMV and maybe have not been putting as much focus as they should on implementing more security measures online,” said Vanderhoof. “I think we will see an acceleration of their online efforts, because merchants don’t want to see the EMV investment they made in protecting their point of sale transactions being exchanged for increased online fraud.”
Be Part Of Solution
Vanderhoof is advising issuers to play a big part in solutions.
“I tell issuers that their customers’ shopping behaviors are changing and that they have to adjust to the changing market,” he said. “They have to become more aggressive partners in trying to address the card not present fraud problem.”
The U.S. Payments Forum, Vanderhoof said, is “encouraged” by the number of effective fraud risk mitigation tools coming to market to assist in fighting online card fraud.
“A number of service providers are delivering more transaction-level data to be used to better risk score online transactions,” explained Vanderhoof.
The new information being gathered includes data points such as the IP address of where transactions are originating, shoppers’ previous online shopping behaviors, types of products shoppers typically buy, and how much they spend.
“Merchants use analytics tools that measure these types of transaction details, in addition to the payment data that is keyed in,” said Vanderhoof. “By doing so merchants can stop fraud earlier in the checkout process and reduce a large number of fraudulent transactions that come through their systems.”
Tokenization, now used by digital wallets at the point of sale and considered the next big step in the fraud fight, is expected to make a big dent in CNP fraud when fully instituted online, Vanderhoof agreed.
Vanderhoof added that when 3D Secure version 2.0 is available—now in specification form—that the industry-wide messaging protocol for online authentication will be a significant advancement in the fight against online fraud.
“This will provide a means for merchants to utilize additional analytical data present in transactions and have the payment brands and issuers actually come up with a risk score and present it back to the merchant to ask, ‘Do you want to request additional information for this transaction or not?’”
As CUToday.info has reported, another means to fight online fraud is a dynamic CVV code.
Oberthur Technologies
French digital security company Oberthur Technologies has developed a digital display powered by a micro-thin battery. It will change the three or four-digit CVV number on the back of credit and debit cards as often as 72 times every 24 hours. Engineers have managed to squeeze it all into a regular, 0.76 millimeter-thick card. However, the roadblock to adoption is that the “Motion Code” plastic ranges from $5 to $12 per card based on volume.
Vanderhoof noted that during 2017 the U.S. Payments Forum is prioritizing the importance of addressing fraud in the card not present environment in online and mobile channels. The Forum’s Card Not Present Fraud Working Committee and Mobile and Contactless Working Committee are launching projects to provide best practices and educational resources on how to help secure these channels.
