MADISON, Wis.—With some CUs reporting a doubling in card fraud, it’s time for credit unions to become even more vigilant—especially those that have not converted their entire card base to EMV, credit unions and experts are cautioning.
Across the country CUs are reporting a rash of unauthorized transactions on members’ accounts, with at least one CU theorizing it’s due to crooks racing to act on mag-stripe plastic before EMV cards are fully in place with members.
CUNA Mutual Group confirmed that credit unions that have not converted to EMV may face an increased chance of having their members’ card data, in cases in which it is already in the hands of thieves, used by the crooks. Non-EMV cards have become even bigger targets, with experts reminding that criminals no longer ignore the little guys.
Robert Jarosinski, senior consultant in CUNA Mutual Group’s risk management department, confirmed concerns CUToday.info shared about cyber thieves rushing to use up the stolen mag-stripe data that’s available.
“That certainly is a motivating factor for fraudsters now. The crooks know massive card reissues are happening and coming, so if they are sitting on stolen data from an earlier breach they know it is only good until the reissue happens,” Jarosinski said. “Then, that data is useless.”
Motivated Crooks
Jarosinski said that motivation is likely contributing to the rising card fraud CUNA Mutual Group is seeing at credit unions.
“We have heard from a lot of credit unions that fraud for them has doubled this year over last, and we are just now getting into the high spending season,” said Jarosinski.
Spikes in card fraud were recently reported by at least three credit unions. A spokesperson for North Charleston, S.C.-based South Carolina FCU said that “dozens of accounts” have been affected, with “lines formed at branches across the state.” Several members said “a significant amount of money is missing,” including one member who said $1,800 had been removed from her account by someone in France, while another said her “entire account was wiped out.”
The credit union attributed the fraud to the adoption of EMV cards as crooks race to beat distribution of the more secure cards. The CU said that many of the incidents are being linked to previously announced breaches at Target, Home Depot, and other merchants.
More CUs Hit
In Canton, N.C., Champion Credit Union has confirmed that nine members have had money removed from their accounts as the result of unauthorized charges. The credit union said it is believed the breach occurred at a merchant that is common to all of the victims. A member said she had seen charges from Homestead and Miami, Fla., on her account. A third charge, all at Walmart locations, didn’t clear due to insufficient funds.
Jarosinski did not rule out that as crooks rush to use up stolen mag-stripe data, that credit unions could begin to see larger batches of cards compromised.
That is what Mainstreet Credit Union in Lenexa, Kans., believes recently happened to 300 of its members who were hit with more than $200,000 in fraudulent charges from crooks making purchases out of a company based in China.
Closer Monitoring Needed
The $378-million CU’s CEO, John Beverlin, told CUtoday.info that the losses are believed to have resulted from a retailer breach at some earlier point and the crooks “are just now getting around to using the data.”
Jarosinski advised credit unions to more closely monitor Visa and MasterCard breach alerts, and to also monitor fraud as it comes in, employing common point of purchase analysis.
“This is a faster way to detect fraud than waiting for Visa and MasterCard to send an alert, which might be a little too late,” said Jarosinski. “Watch for those common points of purchase patterns and then write fraud detection rules to counter those patterns. The important thing now is to be extra vigilant and proactive in fighting fraud through fraud rules, common point of purchase analysis, and analytics.”
