So, here we are, living in the “future. Many of us now finally have chip cards; the G20 nations are all in the post “liability-shift” world; we’re all expecting to be living in the new paradigm.
But it is fairly clear that not all is right in the world. There are still breaches, skimming and fraud, and in fact, they are just as bad as they have ever been. Seemingly nothing has changed and depending on whom you listen to, it’s worse. To some degree, and depending on your perspective, this is pretty much the truth. There are reasons why the new playing field isn’t any better than the old one. But new technology suggests improvements are on the horizon.
For now, if you’re a merchant, now the pain is in your world. Merchants woke up on Oct. 1, the date of the card network liability shift, and now everything is pushed off on them. Worse, the hacking didn’t slow, so now the merchants are targeted on one side by hackers and moreover, the fraud losses fall on them as well. Seems that this EMV thing has been the wrong move. You have to pay for the new technology and terminals, and you’re at even greater risk than you were before.
If you’re a brick and mortar merchant, you still hear that point of sale systems are increasingly hacked, especially at restaurants and hotels. If you’re an e-commerce merchant, you’re hearing that fraud has migrated to your channel, and there is no fix yet. Both of these scenarios may appear to be materializing and perhaps as an indirect result, around a third of POS machines have been updated to EMV. It appears that there is no real incentive, as this is a lose-lose scenario.
If you’re a U.S. card issuer, you’re working as hard as ever and volumes are spiking: ATM fraud is worse than ever, fuel pumps are getting skimmed like it’s going out of style, pretty much because, well, it very well might be. New fraud types are popping up in volumes that keep teams fighting fires. It appears that while we scale our businesses, the fraudsters are scaling theirs just as fast, if not faster, and that it’s accelerating faster on their side. Compound that with the fact that the merchant EMV acceptance rate is fairly low, and it may appear to be that we’re stuck in neutral. All the re-issues of the mag stripes in the world won’t change that.
If you’re a consumer or other industry watcher, you don’t know what’s happening or what might be the truth. You might be hearing that fraud is shifting, you might be hearing that there is more insecurity in the payments ecosystem, you might be perceiving that there is more friction or you are actually getting more alerts and/or unauthorized transactions passing by your radar. Either way, it appears that there is little good coming out of this and that we’re more or less under-realizing much in the way of any benefit of this conversion. Fraud has not slowed and all stakeholders are unhappy.
The end result is that from wherever you sit, you may hear, see and perceive that there is more fraud. That all these new technologies haven’t solved the problem. That EMV is not going to improve anything or it’s just redistributing the problem. There is also a darker, more sinister fact at play here: that the hackers, fraudsters and foot soldiers on the dark side of this battle have grown in numbers as we’ve slowly moved to increase our dependency on electronic payments. And I’m sorry to burst the bubble, but this is all true. There is a ton of fraud right now, it’s still growing, and the criminal entities who have created, scaled and maintain these dark economies are presently undeterred.
Here’s why all of that is shortsighted.
There is a glimmer of hope and that glimmer is not that far in the distance: we’re just in the infancy of the adoption of new technologies that will significantly reduce the impact of fraud.
EMV has worked in the countries where it has been implemented, it has dramatically reduced counterfeit card fraud. To really put this in perspective, in the U.S. we’re only seeing about a quarter to a third of all point of sale transactions going through the EMV mode currently. So, we have a long way to go before the benefits really take hold.
Tokenization is showing us that we will further protect the ecosystem with dynamic data that will inevitably be a stronger and more widely supported standard. Authentication is improving and being deployed with less friction using our mobile devices. Fraud alerts are more precisely applied than they have ever been, and are more directly fed to us. This is a transitional period, and unfortunately, the transition is going to be long… perhaps another 2-5 years until we have a real ring around counterfeit card fraud once we take into consideration all possible manifestations of the mag stripe in our ecosystem.
And as we have to be accepting that it’s not going to all fall into place overnight. It’s a period of change where a shuffling of security elements between merchants, terminals and issuers will be exploited by an increasingly target-sensitive fraudster and hacker.
With every new technology, in payments or in any consumer goods, there are typically teething problems… and this is a very complex, global problem where no simple answers exist. The investments in security we are making today can and do pay dividends.
In every new breach, it becomes increasingly clear that the business that was compromised may not have put security first, or didn’t adequately prepare for environmental shifts. It is right now that we are in the transition period, and if investments in security have not been made, it is now time to make them, or find oneself in the position of being left behind when the hacker, fraudster or ne'er-do-well sets their sights on your organization.
It’s said that luck favors the prepared, and while it may appear that our newest preparations aren’t immediately realizing their desired result, it will certainly be realized that the organizations that didn’t adequately prepare for this transitional environment are the same as those that are actually impacted. Further, EMV is in fact already working for those who moved forward with it. The merchants who already adopted EMV are far less susceptible to suffering from hacking and fraud, and won’t be in the news as the victim of the latest event. The issuers who issue EMV chip cards already have less counterfeit fraud liabilities even when their customers shop at merchants that didn’t transition to the new standard. That’s how it appears from the inside looking out—right now. That’s why EMV is going to work, and why we need and will get more technologies like it. So, let’s not say this is a burst of the EMV bubble, this is just a bit of chop in the EMV froth.
Seth Ruden is senior fraud consultant for the Americas for ACI Worldwide.