Download as ppt, pdf, or txt
Download as ppt, pdf, or txt
You are on page 1of 17

CARD CLONING

Presented by CRDB Bank Plc on 18/05/2017


AGENDA
2

 Introduction
 What is card cloning?
 How and where card cloning happens
 Impact of Card cloning
 Measures to combat card fraud
 Questions and answers
 Recap
CARD CLONING
3

 The act of stealing data from one bank card and copying it on to
another card

 The second card is counterfeit (cloned/skimmed/fake).

 The cloned card is then used to make transactions on ATMs, POS


terminals and online
HOW AND WHERE CARD CLONING OCCURS
4

 At a merchant location (the second swipe scenario) (Fisrt swipe on


POS Second on skimming device)
 At ATMs
 Hacking (Websites while transmitting data from one organization to
another)
 Negligence by card holders
HOW AND WHERE CARD CLONING OCCURS
5

 Storage (hacking into e-business databases then try to extort the


merchant or post account numbers on bulletin boards)
 Internal compromise (the importance of data security)
 Electronic pick pocketers
 Phishing attempts
SAMPLE OF PHISHING ATTEMPTS
6
HOW AND WHERE CARD CLONING OCCURS
7
HOW AND WHERE CARD CLONING OCCURS
8

AT ATMs
HOW AND WHERE CARD CLONING OCCURS
9

WHITE PLASTIC
HOW AND WHERE CARD CLONING OCCURS
10

COUNTERFEIT CARDS SALES DRAFT


SKIMMING START TO FINISH (RESTAURANT
SCENARIO)
11
WHO MIGHT TARGET CARD HOLDERS?
12

 Petty criminals
 Organised crime syndicates
 Genuine cardholders’ family members
 Merchant staff
WHAT FACTORS MIGHT ATTRACT CRIMINALS?
13

 Merchants selling goods that criminals want


 Merchant staff who do not follow correct acceptance procedures
 Weaknesses of the system e.g. Proper security at ATMs and storage
of card holder data
WHY DOES CARD CLONING MATTER?
14

 Country's reputation (tourists, investors, international agencies)


 Financial loss to individuals
 Loss of public confidence in banking sector
 Banks loosing capital
MEASURES TO COMBAT CARD FRAUD
15

 Keeping up to date with changes in technology and card payment


industry(EMV,PCI DSS,ISO 27001-Banks have to comply)
 Laws that specifically target bank card fraud (Cyber laws)

 Educate the public (campaigns)


 Education internally within the police force from the first level
support staff
MEASURES TO COMBAT CARD FRAUD
16

 Create awareness to ATM police as one of the main cash out


points
 Performing regular examinations and risk assessments of card
issuers(
 Publishing standards, guidance, and guidelines for protecting
cardholder information and monitoring for fraudulent activity
(TBA,BOT)
17

You might also like