Prepaid debit cards: a weak link in bank security

Advertisement
By Reuters | Updated: 11 May 2013 14:05 IST
A brazen gang of cyber criminals, who stole $45 million from bank ATMs in 27 countries, exposes an Achilles heel in the global financial industry: prepaid debit cards.

Cyber security experts and industry analysts say the burgeoning use of prepaid debit cards for everything from gift certificates to disaster relief handouts is making it easier for hackers to withdraw large amounts of money before detection.

Also see:(Hackers stole $45 million from ATMs in 27 countries: US)

Advertisement

Prepaid cards have fewer controls on them than on regular credit and debit cards issued by banks. Each prepaid card issued is like a blank slate: anonymous, new, and lacking any credit history or individual behavior pattern against which bankers and payment processors can measure activity to look for red flags.

They are also easier to hack. Raising a withdrawal limit on a prepaid card involves hacking into a system at a third-party payment processor, a company that is generally smaller than a bank and, if based outside the United States, potentially subject to looser cyber security standards.

Advertisement

"It's usually prepaid debit cards. That's the card of choice in this. The bad guys know the system and they have been able to exploit it," said Joe Petro, a managing director at Promontory Financial Group, who worked for 20 years as the head of fraud prevention and investigations for Citigroup Inc .

"The vulnerability stems from third-party processors, who may not have the same level of security systems that banks are able to have," he added. Petro was speaking generally and said he did not have direct knowledge of the $45 million heist.

Advertisement

In a globally coordinated campaign, hackers broke into two unidentified payment processing companies that handled the prepaid debit cards for two Middle Eastern banks, U.S. prosecutors said on Thursday.

Once inside the computer networks, they increased the available balance and withdrawal limits on prepaid MasterCard debit cards issued by Bank of Muscat of Oman and National Bank of Ras Al Khaimah PSC of the United Arab Emirates.

Advertisement

The criminal ring's operatives then fanned out around the world and used fraudulent prepaid cards to withdraw money from thousands of ATMs. The global scope and speed of the theft was unprecedented, cyber investigators said. In the case of Bank of Muscat, $40 million was stolen in just over 10 hours.

Experts said the use of prepaid debit cards, instead of credit cards, was not accidental. Credit cards are attached to individuals whose spending habits over time give banks and credit card companies clear patterns they can use when trying to identify unusual or illicit activity.

EVADING DETECTION
A thief moving from ATM to ATM with a personal credit card would likely quickly raise alarms, because his or her behavior would look out of place compared to the credit card user's normal activity.

"The banks are using state-of-the art defenses, but the more sophisticated actors are able to breach their networks," said Shawn Henry, the former head of cyber crime investigations at the FBI, now president of professional services at security firm CrowdStrike.

While the $45 million swindle is one of the largest ever, security experts say banks deal with similar, albeit smaller, thefts regularly - they are just rarely disclosed.

By 2013, the amount of money that was placed onto reloadable prepaid cards reached about $201.9 billion from $28.6 billion in 2009, according to a report published by Mercator Advisory Group.

"Of all the types of cards that are there, prepaid cards is the fastest growing category," said Scott Valentin, analyst with FBR Capital Markets & Co.

"With cash payments slowing and an increase in mobile payment and online commerce, the importance of these cards is only going to increase," Valentin said. "With credit cards you need to be credit worthy and with debit cards you need a bank account. Prepaid cards gets you past these two issues and as a result are extremely popular."

That has raised concerns about the need for better security around prepaid cards, and the card processing companies that service them.

For more than a decade, banks have been required by U.S. law to ensure their electronic systems and those used by their outside contractors meet certain safety requirement. U.S. banks using payment processors must have a contractual agreement that states the payment processor is meeting the same security standards the bank does.

The problem, said Doug Johnson, vice president for risk management policy at the American Bankers Association in Washington, is that U.S.-based banks, don't always find it easy to ensure that what is agreed in the contract with an overseas payment processor is really being implemented.

"I fully anticipate that regulatory agencies are going to spend increased time looking at third-party providers," Johnson said.

In the case of the two Middle Eastern banks, one used a U.S.-based credit card processor, while the other used one in India. The U.S.-based company's breach shows even third-party processors close to home can make banks vulnerable.

William B. Nelson, chief executive of a nonprofit security group advising the banking industry, said the case reminded him of the RBS WorldPay breach in 2008. In that attack, intruders into the arm of Royal Bank of Scotland took data on customers, created new cards, and then raised the daily withdrawal limits. They stole $9 million in a day.

The accused Russian mastermind of the scheme was convicted but received a suspended sentence. "It's a cash-out scheme, where they've been able to find a vulnerability in the card system," said Nelson, CEO of FS-ISAC, of the current case. "They are not really hitting bank accounts."

Also see:(Germany arrests two Dutch citizens in $45 million cyber heist case)

© Thomson Reuters 2013

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Internet
Advertisement

Related Stories

Popular Mobile Brands
  1. Google's Fitbit Air Spotted on Amazon India Ahead of Official Launch
  2. Apple Hikes Apple Music, Apple One Subscription Prices in India
  3. Vivo X300 E Launch Date Confirmed; Pre-Orders Now Live in China
  4. Honor X7e Plus 5G Launched With 8,100mAh Battery
  5. Samsung Announces 'Back to School' Deals Across These Devices in India
  6. Moto Pad 70 Groove Launching in India on July 31: Here's What It Offers
  7. Xiaomi Power Bank 5i 20000mAh to Launch in India on This Date
  8. Samsung Galaxy Z Fold 8 Leads Samsung's Foldable Production Plan: Report
  1. Google's Fitbit Air Spotted on Amazon India Ahead of Official Launch
  2. Google Reportedly Begins Rolling Out Android Backup Storage Policy Update
  3. Telegram Gets New Rich Text Editor, Communities, and Ephemeral Bot Messages
  4. Samsung's 'Back to School' Sale Brings Discounts on Galaxy S26 Series, Galaxy Book 6 Pro, Galaxy Tab S11 Ultra and More
  5. Moto Pad 70 Groove India Launch Date Announced; to Feature 9-Speaker JBL Audio System
  6. Xiaomi Power Bank 5i 20000mAh India Launch Date Confirmed; Key Features, Availability Details Revealed
  7. Portronics Pure Sound Pro X2 Home Theatre System Launched in India With 150W Sound Output, Four EQ Modes
  8. Samsung Galaxy Watch 9, Galaxy Watch Ultra 2 Design, Key Specifications Reportedly Leak Ahead of Launch
  9. Oppo K14, K14x and A6s Reportedly Receive Price Hikes in India: Check New Pricing
  10. Oppo A7 Pro Max Tipped to Feature 10,000mAh Battery, Snapdragon 4 Gen 5 SoC, and More
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.