• Menú principal
    • Página de inicio
    • Zona segura
    • Presentar un reclamo
    • Hacer un pago
    • Recomendar a un amigo
    • Únete a nuestro boletín de noticias
    • Enlaces importantes
    • Glosario de seguros
    • Ver nuestro Blog
    • Localización
    • Directorio de empleados
    • En contacto con nosotros
    • Extras Página 1
    • Sobre nosotros
    • Política de privacidad
  • Automóvil
    • Automóvil seguro de hogar
    • Cotización del seguro de auto
    • Tarjeta de identificación de solicitud para póliza de automóvil
    • Solicitud de declaración y página de coberturas de la póliza de automóvil
    • Enviar información de coberturas y declaración al titular del derecho de retención
    • Añadir vehículo a política vigente de Auto
    • Retirar el vehículo de la política de Auto existente
    • Agregar controlador para póliza de automóvil vigente
    • Eliminar controlador de póliza de automóvil vigente
    • Avería mecánica
  • Propietarios de viviendas
    • Los propietarios de viviendas seguros de hogar
    • Cotización del seguro de propietarios de vivienda
    • Solicitud de declaración y coberturas para cobertura de seguro de propietarios de viviendas existentes
  • Para inquilinos
    • Página de inicio de seguro para inquilinos
    • Cotización de seguro para inquilinos
    • Mediante solicitud, declaración y coberturas página existente cobertura de seguro para inquilinos
  • Motos
    • Motos seguros de hogar
    • Cotización del seguro de motocicleta
    • Solicitar tarjeta de la identificación política de motocicleta
    • Solicitud de declaración y coberturas página política de motocicleta
    • Añadir moto a política existente
    • Quitar motos de política existente
    • Agregar controlador de a política vigente de motocicleta
    • Eliminar controlador de política existente de la motocicleta
  • Negocios & comercial
    • Negocios & comercial seguros hogar
    • Cotización del seguro de Auto comercial
    • Tarjeta de identificación de solicitud para póliza de automóvil comercial
    • Solicitud de declaración y página de coberturas de póliza de automóvil comercial
    • Añadir vehículo a política comercial Auto existente
    • Retirar el vehículo de la política comercial Auto existente
    • Agregar controlador para política comercial Auto existente
    • Eliminar controlador de política comercial Auto existente
    • Cotización de responsabilidad general
    • Los dueños de negocio (BOP) cita forma
    • Cita de compensación de trabajadores
  • Salud
    • Salud seguros de hogar
    • Cotización de seguro de salud
    • Cotización del seguro de discapacidad
    • Largo plazo cuidado cotización del seguro de
  • Vehículo recreativo
    • Casa de seguro de vehículo recreativo
    • Cotización del seguro de vehículos recreacionales
    • Solicitud tarjeta de identificación para la política del vehículo recreacional
    • Solicitud de declaración y coberturas página política del vehículo recreacional
    • Añadir vehículo recreativo a la política existente
    • Quitar vehículo recreativo de política existente
Auto Homeowners Umbrella Earthquake Commercial
Home > Es-Us > Blog > Will cardless ATM's create even more banking fraud?
THURSDAY, JANUARY 26, 2017

Will cardless ATM's create even more banking fraud?

Will cardless ATM's create even more banking fraud? Read this before you use your smartphone to get cash at an ATM! 


 

Stolen Passwords Fuel Cardless ATM Fraud

Some financial institutions are now offering so-called “cardless ATM” transactions that allow customers to withdraw cash using nothing more than their mobile phones. But as the following story illustrates, this new technology also creates an avenue for thieves to quickly and quietly convert stolen customer bank account usernames and passwords into cold hard cash. Worse still, fraudulent cardless ATM withdrawals may prove more difficult for customers to dispute because they place the victim at the scene of the crime.

San Francisco resident Kristina Markula told KrebsOnSecurity that it wasn’t until shortly after a vacation in Cancun, Mexico in early November 2016 that she first learned that Chase Bank even offered cardless ATM access. Markula said that while she was still in Mexico she tried to view her bank balance using a Chase app on her smartphone, but that the app blocked her from accessing her account.

Markula said she thought at the time that Chase had blocked her from using the app because the request came from an unusual location. After all, she didn’t have an international calling or data plan and was trying to access the account via Wi-Fi at her hotel in Mexico.

Upon returning to the United States, Markula called the number on the back of her card and was told she needed to visit the nearest Chase bank branch and present two forms of identification. At a Chase branch in San Francisco, she handed the teller a California driver’s license and her passport. The branch manager told her that someone had used her Chase online banking username and password to add a new mobile phone number to her account, and then move $2,900 from her savings to her checking account.

The manager told Markula that whoever made the change then requested that a new mobile device be added to the account, and changed the contact email address for the account. Very soon after, that same new mobile device was used to withdraw $2,900 in cash from her checking account at the Chase Bank ATM in Pembroke Pines, Fla.

A handful of U.S. banks, including Chase, have deployed ATMs that are capable of dispensing cash without requiring an ATM card. In the case of Chase ATMs, the customer approaches the cash machine with a smart phone that is already associated with a Chase account. Associating an account with the mobile app merely requires the customer to supply the app with their online banking username and password.

Users then tell the Chase app how much they want to withdraw, and the app creates a unique 7-digit code that needs to be entered at the Chase ATM (instead of numeric code, some banks offering cardless ATM withdrawals will have the app display a QR code that needs to be read by a scanner on the ATM). Assuming the code checks out, the machine dispenses the requested cash and the transaction is complete. At no time is the Chase customer asked to enter his or her 4-digit ATM card PIN.

Most financial institutions will limit traditional ATM customers to withdrawing $300-$600 per transaction, but some banks have set cardless transaction limits at much higher amounts under certain circumstances. For example, at the time Markula’s fraud occurred, the limit was set at $3,000 for withdrawals during normal bank business hours and made at Chase ATMs located at Chase branches.

Markula said the bank employees helped her close the account and file a claim to dispute the withdrawal. She said the teller and the bank manager reviewed her passport and confirmed that the disputed transaction took place during the time between which her passport was stamped by U.S. and Mexican immigration authorities. However, Markula said Chase repeatedly denied her claims.

“We wanted to thank you for providing your information while we thoroughly researched your dispute,” Chase’s customer claims department wrote in the third rejection letter sent to Markula, dated January 5, 2017. “We confirmed that the disputed charges were correct and we will not be making an adjustment to your account.”

Markula said she was dumbfounded by the rejection letter because the last time she spoke with a fraud claims manager at Chase, the manager told her that the transaction had all of the hallmarks of an account takeover.

“I’m pretty frustrated at the process so far,” said Markula, who shared with this author a detailed timeline of events before and after the disputed transaction. “Not captured in this timeline are the countless phone calls to the fraud department which is routed overseas. The time it takes to reach someone and poor communication seems designed to make one want to give up.”

KrebsOnSecurity contacted Chase today about Markula’s case. Chase spokesman Mike Fuscosaid Markula’s rejection letter was incorrect, and that further investigation revealed she had been victimized by a group of a half-dozen fraudsters who were caught using the above-described technique to empty out Chase bank accounts.

Fusco forwarded this author a link to a Fox28 story about six men from Miami, Fla. who were arrested late last year in Columbus, Ohio in connection with what authorities there called a “multi-state crime spree” targeting Chase accounts.

“We escalated it and reviewed her issue and determined she did have fraud on her account,” Fusco said.  “We’re reimbursing her and we’re really sorry. This small pilot we ran allowed a limited number of customers to access cash at Chase ATMs without a card. During the pilot we detected some fraudulent activity where a group of people were able to go online and change the customer’s information and get the one-time access code, and we immediately notified the authorities.”

Chase declined to say how many like Markula were victimized by this gang. Unfortunately, somehow Chase neglected to notify victims, as Markula’s case shows.

“It makes you wonder how many other people didn’t dispute the charges,” she said. “Thankfully, I don’t give up easily.”

Fusco said Chase had made changes to better detect these types of fraudulent transactions going forward, and that it had lowered the withdrawal limit for these types of transactions — although for security reasons Fusco declined to say what the new limit was.

Fusco also said the bank’s system should have sent out an email alert to the original email on file in the event that the email on the account is changed, but Markula said she’s confident no such email ever landed in her inbox.

Avivah Litan, a fraud analyst at Gartner Inc., says many banks see mobile authentication as the way of the future for online banking and ATM transactions. She said most banks would love to be able to move away from physical bank cards, which often need to be replaced several times a year in response to data breaches at various retailers.

“A lot of banks see cardless transactions as a great way to reduce fraud and speed up transactions, but not many are offering it yet as a feature to customers,” Litan said.

Litan said Markula’s case echoes the spike in fraud that some banks saw after Apple debuted its Apple Pay platform. Many banks chose to adopt Apple Pay without also beefing up security around how they validate new customers and new mobile devices. As a result, this allowed fraudsters to take stolen credit card numbers and expiration dates — data that previously was only good for fraudulent online transactions — tie those cards to iPhones, and use the phones to commit card fraud at brick-and-mortar stores that accepted Apple Pay.

“Identity proofing remains the weakest point in mobile banking,” Litan said. “Asking for the customer’s username and password to on-board a new mobile device isn’t enough.”

Litan said Chase should require customers who wish to conduct cardless ATM transactions to enter their PIN in addition to the one-time code. But she said even that was not enough.

Litan said Chase should have flagged the transaction as highly suspicious from the get-go, given that the fraudsters accessed her account from a new location, changed her contact email address, added a new device and withdrew just under the daily maximum — all in a very short span of time.

“ATM transactions should have much stronger fraud controls because consumers don’t have as strong protections as they do with other transactions,” Litan said. “If a customer’s card is used fraudulently at a retailer, for example, the consumer is protected by Visa and MasterCard’s zero liability rule, and they can generally expect to get their money back. But when you withdraw cash from an ATM, you’re not protected by those rules. It’s down to Regulation E and your bank’s policies.”

Under the Federal Regulation E, if a retail banking customer reports fraud, the bank must investigate the first statement of the activity plus 60 days from the date the statement was mailed by the financial institution. Unless the institution can prove the transaction wasn’t fraud, it must reimburse the consumer. However, any activity that takes place outside of the aforementioned timeframe carries unlimited liability to the consumer, as the financial institution may have been able to prevent the loss had it been reported in a timely manner.

Fusco added that consumers should beware of phishing scams, and consider asking their financial institution to secure their accounts with a special passphrase or code that needs to be supplied when authenticating with the bank over the telephone (a precaution I have long advised).

Also, if your bank offers two-step or two-factor authentication — such as the requirement to send a text-message with a one-time code to your mobile device if someone attempts to log in from an unknown device or location — please take advantage of that feature. Twofactorauth.orghas a list of banks that offer this additional security feature.

Also, as the Regulation E paragraph I hope makes clear, do not count on your bank to block fraudulent transfers, and remember that ultimately you are responsible for spotting and reporting fraudulent transactions.

Litan said she won’t be surprised if this incident gives more banks pause about moving to cardless ATM transactions.

“This is the first case I’m aware of in the United States where this type of fraud has been an issue,” she said. “I’m guessing this will slow the banks down a bit in adopting the technology because they’ll see now how easy it is for criminals to take advantage of it.”

Update, Jan. 6, 9:44 a.m. ET: Looks like Chase could have learned from the experience of NatWest, a big bank in the U.K. that experienced much the same fraud five years ago after enabling a cardless “get cash” feature.


Posted 11:00 AM

Tags: atm fraud
Share |


No Comments


Post a Comment
Required
Required (Not Displayed)
Required


All comments are moderated and stripped of HTML.

NOTICE: This blog and website are made available by the publisher for educational and informational purposes only. It is not be used as a substitute for competent insurance, legal, or tax advice from a licensed professional in your state. By using this blog site you understand that there is no broker client relationship between you and the blog and website publisher.
Blog Archive
  • 2019
  • 2018
  • 2017
  • 2016
  • 2015
  • 2014
  • 2010

  • 5 tips to protect your possessions with valuable items insurance coverage(3)
  • spring driving tips(3)
  • john o'leary monday motivation: would you do it again?(2)
  • preventing slips and falls in your home(2)
  • crime spikes on halloween: fictional ghost story or factual concern?(2)
  • 3 easy ways to get rid of fruit flies(2)
  • why 2 experts say you should clean your medicine cabinet — and their 5 key tips(2)
  • john o'leary monday motivation: what do you see?(2)
  • help keep your teens safe behind the wheel(2)
  • 10 best places to get a deal on glasses(2)
  • motivational monday(2)
  • things burglars look for before breaking into a home (and what keeps them away)(2)
  • grilling safety tips(2)
  • ez-prep (severe weather: emergency preparedness and response planning)(1)
  • false facts you believe about money(1)
  • motivational monday with john o'leary: how heroes are made(1)
  • home safety tips(1)
  • john o'leary monday motivation: leave it all behind(1)
  • the flu is a bad souvenir. here’s how a pilot stays healthy while flying(1)
  • are you protecting your family from harmful uv rays?(1)
  • why you might want to wrap your car key fob in foil(1)
  • 10 smartphone camera features that make you feel like a professional photographer(1)
  • life insurance misconceptions(1)
  • should you pay off your mortgage?(1)
  • 19 discounts seniors didn’t know they could get(1)
  • 10 simple & sustainable tips for a healthier you in 2019(1)
  • confessions of a car salesman(1)
  • 6 simple spring car care tips(1)
  • car cleaning tricks that your body shop won’t tell you about(1)
  • drinking coffee won't improve your metabolism — here's what actually works(1)
  • ridiculously simple and free ways to live a more sustainable lifestyle(1)
  • financial book clubs make learning about money more social(1)
  • 6 ways to secure your home when you're away(1)
  • monday motivation with john o’leary: a small act of caring(1)
  • family fire safety tips(1)
  • 9 healthy holiday-eating strategies(1)
  • monday motivation with john o'leary: will you see it?(1)
  • how times of trouble remind us to be grateful “if the only prayer you ever say in your entire life is thank you(1)
  • tips to keep your house plants happy and healthy(1)
  • small money moves to change your financial future(1)
  • john o’leary motivation: it’s not about you(1)
  • always bloated(1)
  • 15 times you should definitely be washing your hands and aren’t(1)
  • john o'leary monday motivation: redefining perfect(1)
  • john o'leary monday motivation: slow down and enjoy life(1)
  • john o'leary monday motivation: where do i belong(1)
  • what to do when you're hacked(1)
  • 20 ways to save money(1)
  • focus on safety all year long(1)
  • power outages(1)

View Mobile Version
QUICK LINKS

Home
About
Get a Quote
Contact

Refer a Friend Leave A Review
                          R.L. Thomas Insurance Service, Inc.

                              21021Ventura Blvd., Suite 215                         
                              Woodland Hills, CA  91364                    
                              Phone: (818) 380-1700                            
                              Fax: (818) 906-0667                                
             

                               License#: 0601754
Powered by Insurance Website Builder