SAFE AND SECURE PAYMENTS: THE MASTERCARD APPROACH

Similar documents
Securing the Payments System. The facts about fraud prevention

Card Not Present Fraud Webinar Transcript

AUSTRALIAN PAYMENTS FRAUD DETAILS AND DATA

An Oracle White Paper July 2010 U.S. CARD FRAUD

Enhancing Payment Card Security New Measures to be Phased in from 2 nd Quarter 2010 to 1 st Quarter 2011

EMV's Role in reducing Payment Risks: a Multi-Layered Approach

EMV EMV TABLE OF CONTENTS

Introductions 1 min 4

Thoughts on PCI DSS 3.0. D. Timothy Hartzell CISSP, CISM, QSA, PA-QSA Associate Director

THE FIVE Ws OF EMV BY DAVE EWALD GLOBAL EMV CONSULTANT AND MANAGER DATACARD GROUP

Fraud Prevention and Program Security Gord Jamieson Director Risk Management & Security Visa Canada Association

Other Retail Payments Developments

EMV and Small Merchants:

Target Security Breach

PayPoint.net Gateway Guide to Identifying Fraud Risks

Chargelytics Consulting

Payments Transformation - EMV comes to the US

Online security. Defeating cybercriminals. Protecting online banking clients in a rapidly evolving online environment. The threat.

With the Target breach on everyone s mind, you may find these Customer Service Q & A s helpful.

The need for a secure & trusted payment instrument in e-commerce. Ali AlMeshal

Deception scams drive increase in financial fraud

MasterCard Special Edition

OpenEdge Research & Development Group April 2015

Frequently asked questions - Visa paywave

Global Bank Achieves Significant Savings and Increased Transaction Volume with Zero-Touch Authentication

BinBase.com REPORT: credit card fraud

Understand the Business Impact of EMV Chip Cards

ADVANTAGES OF A RISK BASED AUTHENTICATION STRATEGY FOR MASTERCARD SECURECODE

Practically Thinking: What Small Merchants Should Know about EMV

Payment Card Industry Data Security Standards

A CHASE PAYMENTECH WHITE PAPER. Expanding internationally: Strategies to combat online fraud

Statement of. Carlos Minetti. Discover Financial Services. Before the. Subcommittee on Oversight and Investigations. of the

Testimony of Scott Talbott, Sr. V.P. for Government Relations, Electronic Transactions Association (ETA)

DATA SECURITY, FRAUD PREVENTION AND COMPLIANCE

Mitigating Fraudulent CNP Transactions

A RE T HE U.S. CHIP RULES ENOUGH?

PCI and EMV Compliance Checkup

Cash 257 Merchant Services and Revenue Collection

White Paper: Are there Payment Threats Lurking in Your Hospital?

Five Steps Towards Effective Fraud Management

What Merchants Need to Know About EMV

Your Single Source. for credit, debit and pre-paid services. Fraud Risk and Mitigation

A multi-layered approach to payment card security.

EMV FAQs. Contact us at: Visit us online: VancoPayments.com

FIGHTING FRAUD: IMPROVING INFORMATION SECURITY TESTIMONY OF JOHN J. BRADY VICE PRESIDENT, MERCHANT FRAUD CONTROL MASTERCARD INTERNATIONAL

Suzanne Lynch Professor of Practice Economic Crime Utica College sl6-15 1

A Brand New Checkout Experience

A Brand New Checkout Experience

DATA BREACHES: HOW IT IMPACTS THE CUSTOMER & THE FINANCIAL INSTITUTION. Prepared For: First Citizens Federal Credit Union 3/18/2015

Heartland Secure. By: Michael English. A Heartland Payment Systems White Paper Executive Director, Product Development

Statement of. Mark Nelsen. Senior Vice President, Risk Products and Business Intelligence. Visa Inc. House Ways & Means Subcommittee.

Written Testimony of. Jason Oxman, CEO The Electronic Transactions Association

CPIM Academy. Cash 257 Merchant Services and Revenue Collection

The Impact of Emerging Payment Technologies on Retail and Hospitality Businesses. National Computer Corporation

MASTERCARD PAYMENT GATEWAY SERVICES

Online Payment Processing What You Need to Know. PayPal Business Guide

Preparing for EMV chip card acceptance

MASTERCARD SECURECODE ISSUER BEST PRACTICES

Healthcare Payment Security Is Your Patient s Card Data Exposed? May 24, 2016

RSA Adaptive Authentication For ecommerce

toast EMV in 2015: How Restaurants Can Prepare for the New Chip-and-Pin Standard

Payment Methods. The cost of doing business. Michelle Powell - BASYS Processing, Inc.

Why Data Security is Critical to Your Brand

Emerging Trends in the Payment Ecosystem: The Good, the Bad and the Ugly DAN KRAMER

EMP's vision is to be the leading electronic payments processing company in the emerging markets of Africa and the Middle East.

PCI DSS Compliance Services January 2016

Newtek, The Small Business Authority 855-2thesba thesba.com 855-2thesba

Target Data Breach Survey of Illinois Banks. Executive Summary

New Account Reference Guide

EMV and Chip Cards Key Information On What This Is, How It Works and What It Means

EMV 101: What small businesses need to know

DATA SECURITY: EVERYTHING YOU NEED TO KNOW

THE ROAD TO U.S. EMV MIGRATION Information and Strategies to Help Your Institution Make the Change

How to Help Prevent Fraud

Visa Debit processing. For ecommerce and telephone order merchants

Changing Consumer Purchasing Patterns. John Mayleben, CPP SVP, Technology and Product Development Michigan Retailers Association

Fraud Mitigation and Identity Verification for Card Not Present Transactions Overview

Arab Bank Cards User Guide

The Adoption of EMV Technology in the U.S. By Dave Ewald Global Industry Sales Consultant Datacard Group

1. Ask what your financial institution knows or has personally experienced with regard to internal and external data breaches.

Tokenization: FAQs & General Information. BACKGROUND. GENERAL INFORMATION What is Tokenization?

Visa CREDIT Card General Guidelines

Protecting the POS Answers to Your Frequently Asked Questions

EMV and Restaurants: What you need to know. Mike English. October Executive Director, Product Development Heartland Payment Systems

A Guide to EMV. Version 1.0 May Copyright 2011 EMVCo, LLC. All rights reserved.

Best Practices Guide to Electronic Banking

Protecting Cardholder Data Throughout Your Enterprise While Reducing the Costs of PCI Compliance

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows:

SellWise User Group. Thursday, February 19, 2015

Merchant Account Glossary of Terms

PREPARED STATEMENT OF SAMSUNG ELECTRONICS AMERICA. For the

Prevention Is Better Than Cure EMV and PCI

WHITE PAPER KEEPING CLIENT AND EMPLOYEE DATA SECURE DRIVES REVENUE AND BUILDS TRUST PROTECTING THE PROTECTOR

Merchant Services. How to help protect your business

Transitions in Payments: PCI Compliance, EMV & True Transactions Security

Payment Card Industry (PCI) Data Security Standard. PCI DSS Applicability in an EMV Environment A Guidance Document Version 1

Fall Conference November 19 21, 2013 Merchant Card Processing Overview

Commercial Payments Overview. Visa Commercial Partnerships October 2013

FUTURE PROOF TERMINAL QUICK REFERENCE GUIDE. Review this Quick Reference Guide to. learn how to run a sale, settle your batch

EMV and Restaurants What you need to know! November 19, 2014

Transcription:

SAFE AND SECURE PAYMENTS: THE MASTERCARD APPROACH Global point of view For nearly 50 years MasterCard has been safeguarding the way you pay. We have been innovating solutions driven by data and insights to increase the safety and security of electronic payments.

Our safety and security guarantee: we want to give consumers the peace of mind to pay with confidence, and our goal is to build a world beyond cash where every person, every payment and every device is protected. Consumers need a safe and simple experience when making a payment, wherever they are in the world and whether they tap, click or swipe. MasterCard is investing time and money to continuously enhance the technology to detect and prevent fraud so that consumers can be confident that their money is safe. In the rare event that fraud 1 does occur, we ensure consumer peace of mind by limiting or eliminating cardholder liability 2. Executive summary MasterCard is the leading technology company delivering electronic payments and the leader in safety and security Technology and payment methods are changing every day payments are becoming faster, smarter and more sophisticated. Cards remain one of the safest ways to pay, with only 6 cents for every $100 spent on major global cards lost to fraud. MasterCard s safety and security measures have already reduced this number to 5 cents. We are investing in innovative payment and security solutions so consumers have a safe, secure and convenient payment experience. Safety and security is our number one priority. MasterCard guarantees safety and security with smart technology to ensure we are always one step ahead of fraudsters 1. We are making sure consumers are protected from fraud before it even occurs 2. There is no silver bullet to fight fraud, and MasterCard has implemented multiple layers of protection to significantly reduce the risk of fraud: Unobtrusive network-wide tools help merchants and issuers identify and prevent fraud; New solutions and products in the consumer s hand empower their transactions with the latest safety and security measures; Consumers are protected by limited / zero consumer liability guarantees for fraud, with efforts underway to expand this protection by working with local regulators, banks, and merchants; MasterCard led the initiatives on EMV (with chip-embedded cards its most visible hallmark) and SecureCode technology to dramatically reduce fraud; Our network screens 1.8bn transactions every month to help detect and eliminate suspect and fraudulent activity; We are already delivering data and insights to drive increased security across any device anywhere; We are testing voice, finger print and facial recognition identification innovations to keep payments safe. 1. It is important to keep in mind that fraud is separate from the compromise (i.e., exposure) of payment account information. Due to a variety of security measures implemented by the industry and MasterCard, only a fraction of compromises result in fraud, especially if the transaction requires authentication (i.e., verification). 2. As an example, all card transactions in the US are protected by our zero liability promise, eliminating financial exposure to the consumer in the event of fraud. MasterCard is working to extend this promise to other markets / regions. 1

Key messages by constituent Our overall message is: We want to build a world beyond cashwhere every person, every payment, and every device is protected. CONSUMERS are ensured peace of mind against fraud MERCHANTS are provided a rich ecosystem that rewards their efforts to prevent fraud by providing shifts in liability ISSUERS are given sophisticated tools to improve their approval and fraud detection capabilities Mastercard s multi-layer protection As payment methods and devices change and become commonplace in every aspect of our lives whether stopping by a retail store in person or shopping online from a computer or a mobile device MasterCard s efforts have also evolved and adapted to ensure the safety of electronic payments wherever and whenever they occur. Overall, authentication is the critical element of preventing fraud in both physical (Card Present) and non-physical (Card Not Present) environments and helps determine whether: 1. The card / payment device is genuine (card / device verification), and 2. The person initiating the transaction is the authorized user (cardholder verification). While there is no silver bullet to completely stop fraud, applying a multi-layer approach that is coordinated across the industry helps reduce the risk of fraud significantly. EMV, SecureCode+, MasterCard Digital Enablement Service (MDES) and tokenization, as well as Risk Based Decisioning, are only a few examples of MasterCard s broader efforts to fight the persistent threat of fraud, be it with card present or card not present payments. MULTI-LAYER PROTECTION Expert Monitoring Solutions (EMS) Fraud Rules Manager (FRM) EMV MDES and tokenization SecureCode+ Risk Based Decisioning (RBD) 2

We process over 1,100 transactions every second about 108 transactions in the blink of an eye. We screen 1.8bn transactions every month in real time to help detect and eliminate fraud. MasterCard leverages the power of its network to monitor transactions across the globe and identify fraud. EMS (EXPERT MONITORING SOLUTIONS) and FRM (FRAUD RULES MANAGER) are at the core of MasterCard s anti-fraud efforts, underpinning our ability to detect suspicious activity and transactions and provide issuers with the tools to supplement their own fraud systems and processes. MasterCard company DataCash also offers GateKeeper:2.0, an advanced fraud and risk management solution, for merchants to keep chargebacks to a minimum whilst protecting genuine customers. The solution uses layers of sophisticated technologies, such as expertly crafted rules, Shared databases, Device ID, etc, to precisely identify a transaction s level of risk. High risk transactions are automatically rejected whilst low risk transactions are accepted. A small number of transactions that are not clearly fraudulent or genuine can be manually reviewed via an intuitive user interface which enables further analysis for a more informed decision. The solution is differentiated by a team of experts that have vast experience of fraud trends across multiple industries and achieves industry leading results. MasterCard in partnership with Visa, American Express, JCB, and China UnionPay developed and implemented the EMV specification, with the chip payment method its most visible hallmark. MasterCard has introduced the M/Chip and M/Chip Advance payment applications to secure our payments globally. The embedded chip on the plastic card along with the MasterCard payment application is significantly more secure than magnetic stripe cards and its introduction has reduced counterfeit fraud by 60-80%. Fraud losses (in CAD $mm) CAD $200 8.3 Fraud as bps of spend 9 CAD $150 6.3 6.8 6.2 6.8 73% drop in fraud dollars 8 7 6 CAD $100 CAD $50 $95 2006 $107 2007 $105 2008 $142 2009 $119 2010 3.8 $70 2011 2.0 $39 2012 5 4 3 2 1 0 EMV Timeline EMV piloted in Canada Fraud losses (CAD $mm) EMV launched liability shift and implementation Fraud as bps of spend In Canada, where Chip and PIN is commonplace (90%+ penetration), fraud declined 73% over 4 years, falling from $142 million in 2009 to only $39 million by 2012 (2.0 bps of domestic debit card volume). MasterCard continues to push for global adoption of EMV and has led efforts to encourage a fraud liability shift by late 2015 in the US, the last major market to withhold from widespread acceptance. 3

MASTERCARD DIGITAL ENABLEMENT SERVICE (MDES) will introduce a new secure platform for payments via mobile devices, including both Card Present and Card Not Present environments by late 2014. MDES substitutes the real card number with a token account number. This token is translated back to the real account number by MasterCard at the time of purchase, so the issuer can match up the transaction with the correct account. If compromised, tokens cannot be used by fraudsters to facilitate fraud. As an added benefit, the merchant only receives the token and never sees real account data, removing a further point of weakness for fraudsters to target. In 2013, MasterCard launched SECURECODE+, the latest upgrade to its SecureCode technology, which allows merchants to add another layer of security for online transactions by asking the consumer to enter a password using SecureCode+. The SecureCode+ password is only known by the account owner and the merchant can choose which transactions are required to use it.merchants do not have to use SecureCode+ if they trust the transaction and can dial their authentication needs up or down depending on the desire for further verification. SecureCode+ can also provide a liability shift for merchants: The more a merchant attempts to protect the end consumer through authentication, the more they benefit from protection against fraud. In 2013, SecureCode authenticated 1.4 billion transactions globally, reporting 28% growth in a single year. By dollar volume, SecureCode ensured the safety of about 29% of all online spend around the world. RISK BASED DECISIONING will add a third layer of security in the CNP space. Its basic premise is to use a consumer email address, device information, and account number to develop a unique online persona. Based on this digital footprint, we can seamlessly authenticate consumers with no effort on their part. Over time, this unique persona will be given a reputation score which can be used by merchants and issuers with their payment approval process. As an example, returning consumers with a high reputation score can proceed through checkout without ever having to authenticate, resulting in a faster sale with higher likelihood of satisfaction and fewer abandoned purchases. Our top priority: safety and security for consumers In the event fraud occurs, we ensure the consumer is partly or wholly shielded from financial liability or loss resulting from fraud. Consumer liability is generally determined by local regulatory conditions, and MasterCard is working with governments around the world to ensure our rules are one step ahead when it comes to protecting consumers. From a merchant and issuer perspective, the rules for determining fraud liability are complex and varied, but are aligned to reward the party that exerts the most effort to secure the transaction. OUR PROMISE TO PROTECT THE CONSUMER FROM FRAUD WILL REMAIN OUR UTMOST PRIORITY. MasterCard leverages our brand, reputation, and franchise to shield consumers from fraud. Our efforts have already reduced cardholder liability around the world, and in the US we have managed to establish a zero liability guarantee. We aim to expand this zero liability guarantee to our cardholders globally and continue to work with local regulators, banks and merchants around the world to protect the consumer. 4

APPENDIX FRAUD 101 Fraud is the financial loss associated with unauthorized use of an account, whether it is using those credentials to buy merchandise, transfer funds, withdraw money, or receive some other financial benefit. Consumers place safety and security as their first and foremost practical and emotional need for their payments. Credit and debit cards have gained prominence and ubiquity as financial instruments due to their ability to satisfy these needs. In 2012, it was estimated that US credit and debit cards experienced approximately 6 bps of fraud, and MasterCard leads the industry with an even lower figure (5 bps). THE COST OF FRAUD The US comprises 45% of global fraud, but only 24% of global spend Fraud rate by dollars Decline rate by transactions Card Not Present comprises 45% of global fraud, but only 8% of global spend 3x 6x Card Not Present fraud is still 3x greater than Card Present, despite being declined 6x more often Card Card Not Card Present (CP) Present (CNP) Present (CP) Card Not Present (CNP) Source: MasterCard data warehouse, 2013 Fraud cost the global card industry more than USD $11 billion in 2012. Despite making up less than a quarter (24%) of the world s payments volume, the United States constitutes almost half (47%) of all fraud losses, losing $5.3 billion to criminals. The fast-growing online retail space is a particular challenge. Despite being screened and declined almost 6x as often as Card Present (CP), Card Not Present (CNP) fraud is 3x higher. Global fraud cost 2012 $11.3 billion Issuer fraud cost Merchant fraud cost 63% $7.1 billion $4.2 billion 37% 6.1 5.3 5.0 In 2012, MasterCard experienced 14% less gross fraud than the global average This figure is even lower in the last 12 months All brands, global (2012) MasterCard, global (2012) MasterCard, global (last 12 months) Source: Nilson Report 2013, MasterCard data warehouse; last 12 months figure is through 3Q 2013. All cards (global) figure includes MasterCard, Visa, American Express, China Union Pay, Diners Club, and JCB. 5

For card fraud to occur, the perpetrator must successfully navigate a few major barriers: 1. Payment account information is lost, stolen, or otherwise compromised and 2. The issuer authorizes the transaction as a legitimate purchase. 3. In some cases, the perpetrator may also be required to authenticate (i.e., prove they are the legitimate cardholder). In other words, the perpetrator must find a way to obtain account data and then successfully imitate the legitimate user s typical purchase behavior when attempting to consummate a fraudulent transaction. The authorization and authentication steps are unique to cards and, as a result, only a small percentage of compromises of account data lead to fraud. ILLUSTRATIVE OVERVIEW OF CARD FRAUD PROCESS 1 Compromise / expose account data to perpetrate fraud Example compromise techniques Phishing Skimming Data Data breach breach Trick consumer into Copy static card data Hack systems that revealing personal info during a transaction handle account data Counterfeit Clone cards and use at POS Example fraud types Lost and stolen Theft of legitimate card Card not present Fraud perpetrated without card Account takeover Stolen data used to takeover or create accounts 2 Receive authorization from issuer to approve purchase Issuers rely on their own fraud detection system when deciding to approve / decline transactions MasterCard s network-wide monitoring tools aid issuer decisioning (EMS and FRM) 3 Authenticate as the real cardholder by imitating key security elements Authentication reduces fraud e.g., entering a PIN but is often not required by issuers or merchants to ensure faster speed to pay 4 Fraud results if perpetrators successfully navigate these safeguards, but in certain cases the cardholder is protected by our zero liability promise Fraud / financial loss 6

Fraud protection in practice: two case studies To illustrate the points discussed in this paper, we present two sample case studies: (1) a phishing attack to expose data which is later used to make purchases online and (2) the theft of data from a payment system to sell account information and produce counterfeit cards. FRAUD CASE STUDY #1: PHISHING COMPROMISE, CARD NOT PRESENT PROTECTIONS 1 2 3 Consumers receives email purporting to be from a trusted source (e.g., friend, reputable company etc.)asking consumer to click on the link. Clicking the link installs malware or uses social engeneering to trick consumer into revealing card account data. Informations is used to make online purchases or cline cards. With SecureCode+, however, accounts are protected by the consumer's secure password. While not technically sophisticated, phishing compromises are difficult to protect against given the consumer is often the party disclosing account information. Nonetheless, innovations such as SecureCode+ will make it much harder for fraudsters to perpetrate their activities online. 7

FRAUD CASE STUDY #2: DATA BREACH COMPROMISE, CARD PRESENT PROTECTIONS ILLUSTRATIVE EXAMPLE Administrative credentials compromised Malware installed on POS terminals Card account data captured Data used to attempt fraud Data compromise activities Perpetrators access retailer s system through compromised admin credentials (e.g. obtained through brute force, phishing, etc.) Malware installed in the POS environment to capture card date ; when swiped, card shares data with the POS However, data is stored or transmitted in clear text in the POS environment, and in some cases is encrypted too late in the process Data is now vulnerable to capture by the malware Account data sold through online black markets or directly used to attempt fraudulent purchases Fraud protection Terminals only capture the data required to process a transaction E.g. without CVC2, online/cnp fraud is difficult to commit Issuers, acquirers, and merchants can monitor for suspicious activity MasterCard can inform issuers if point of compromise is known ; issuers can decide which accounts to close and reissue vs. keep open and monitor In the event of fraud, consumers are covered in part or in full depending on local market rules and regulations If EMV had been present, cloning the chip would be extremely difficult and its use of a dynamic secure feature would make it nearly impossible to replay transactions While targeting a retailer s systems can yield millions of accounts, protections put in place by the card industry and MasterCard can effectively close down more than 90% of attempts at fraud, with even lower actual financial loss. The EMV chip and its dynamic capabilities would have made it harder for fraudsters to clone cards. In addition, new developments such as MDES and tokenization would have yielded tokens instead of real account numbers, further protecting consumers and merchants from fraudsters. However, while direct fraud costs may be relatively low, the full effects of the compromise are very serious, including the loss of confidence in the payments ecosystem, lost sales at the retailer, negative impacts on brand and reputation, and so on. While infrequent, a single major event can cost a retailer upward of $100 million in direct losses, not including other negative effects such as a drop in market capitalization / stock prices. 2014 MasterCard. Proprietary and Confidential. All rights reserved. 8