ST. PETERSBURG, Fla.—Taking the extra step to ask out-of-wallet questions when a new cardholder enrolls in Apple Pay is reducing the amount of Apple Pay fraud from this new payments solution, according to CU payments processors.
While reports have pegged Apple Pay fraud at 6% or higher at some FIs, PSCU and The Members Group have both experienced very low instances of Apple Pay fraud at CUs whose card programs are serviced through the processors’ call centers—one stating that these fraud cases can be counted on one hand.
A previous CUToday.info report revealed that FIs in their rush to enroll in Apple Pay have been overlooking standard security protocols, giving fraudsters an advantage by not using a second authentication factor—such as an e-mail or a text message—to confirm that individuals enrolling in Apple Pay are who they say they are. The fraudster simply obtains stolen credit card data, enrolls in the new service and then is good to tap and pay.
The 6% Apple Pay fraud is a stark contrast to six basis points, the average for mag-stripe plastic.
“The fraud cases that we have, we are not counting them in percentage points at all, we are counting them on our fingers,” said Ryan Anderson, VP of product at TMG. “We have had only a couple cases of Apple Pay fraud.”
FIs To Blame
David Hall, SVP of vendor alliance partnerships for PSCU, agreed that if Apple Pay fraud is high, then the FI is to blame. “Someone with 6% fraud, then they are obviously doing something terribly wrong. It boils down to ‘know thy member.’”
From the very start of the Apple Pay launch, PSCU’s call center has instituted an extra step when cardholders enroll in Apple Pay.
“We manage the verification and token provisioning process for our credit unions via our call center,” explained Hall. “We take the additional step of asking for things like transactional data. I don’t want to share specifics, but these are things only the consumer would know. When the card is provisioned into the wallet, it automatically generates a call from our call center for additional verification. This has curtailed fraud dramatically.”
Anderson, as well, said TMG’s call center is verifying that the token is being issued to the true cardholder. He cautioned that as CUs move quickly to adopt Apple Pay that they continue to be vigilant in fraud prevention as it can come from new angles with new payment solutions.
Anderson also noted that Apple Pay has built-in fraud-prevention steps. “For example, if the e-mail the enrollee provides does not match the e-mail in iTunes, then Apple kicks out the attempt, notifies us, and we call the person to ask out-of-wallet questions.”
Anderson termed that “yellow pathing. There is another reason why someone would fall into a yellow path, and that is if the iTunes account was created in the last 30 days. Then Apple automatically requires you to talk to the enrollee on the phone authenticate.”
Apple No Help
But one expert, Steve Mott, principal of BetterBuyDesign in Stamford, Conn., pointed out that Apple may not be a big help in detecting fraud.
“iTunes has 800-million accounts, maybe 500-million are active,” he said. “I have been told by security experts that tens of millions of these are fraudulent accounts, or accounts that have been compromised.” (6% Apple Pay Fraud Could Rise)
Cindy McGinnis, manager of digital channels at PSCU, summed up what’s ahead for banks and credit unions as the mobile payments space heats up with all kinds of different solutions.
“Knowing that mobile payments has become the Wild West, credit unions should play close attention to the fact there will all different types of fraud occurring, often in ways they have not seen before,” said McGinnis. “CUs need to keep a very close eye on mobile payments security, and harden up fraud detection and prevention methods.”
