Showing posts with label interchange. Show all posts
Showing posts with label interchange. Show all posts

Welch, Durbin, Marshall, and Vance introduce bipartisan Credit Card Competition Act of 2023

on 10:36 AM

 Bill would enhance competition and choice in the credit card network market currently dominated by the Visa-Mastercard duopoly

VermontBiz Senator Peter Welch (D-VT), Senate Majority Whip Dick Durbin (D-IL), and Senators Roger Marshall, M.D. (R-KS), and J.D. Vance (R-OH) today introduced the bipartisan, bicameral Credit Card Competition Act of 2023, legislation that would enhance competition and choice in the credit card network market which is currently dominated by the Visa-Mastercard duopoly.  Building on debit card competition reforms enacted by Congress in 2010, the bill would direct the Federal Reserve to ensure that large credit card-issuing banks offer a choice of at least two networks over which an electronic credit transaction may be processed.  Companion legislation was introduced in the House by Representatives Lance Gooden (R-TX-05) and Zoe Lofgren (D-CA-18).  


“Interchange fees put a brutal strain on our small businesses, but because of the Visa-Mastercard duopoly in the credit card network market, Main Street businesses have no choice but to pay these crushing fees or risk going under,” said Welch.  “The Credit Card Competition Act will restore choice and competition in the credit card network market, helping to bring down costs for small businesses and making it easier for these essential businesses to thrive.” 

“Credit card swipe fees inflate the prices that consumers pay for everyday purchases like groceries and gas.  It’s time to inject real competition into the credit card network market, which is dominated by the Visa-Mastercard duopoly,” said Durbin.  “This legislation, which builds upon pro-competition reforms Congress enacted in 2010, would give small businesses a meaningful choice when it comes to card networks, and it would enable innovators to gain a foothold in the credit card market.  Bringing real competition to credit card networks will help reduce swipe fees and hold down costs for Main Street merchants and their customers.”   

“When it comes to Main Street vs. Wall Street, I’ll stand with Main Street businesses, who are the backbone of our economy, every single time,” said Marshall.  “At a time of economic uncertainty and skyrocketing inflation, these credit card companies are increasing their hidden swipe fees and price gouging small businesses and consumers.  Our legislation would rein in the big banks and the credit card industry, drive down costs for convenience stores, gas stations, and other small businesses, and ultimately pass those savings down to consumers.  This legislation is the right thing to do, and I am proud to reintroduce it with bicameral and bipartisan support.” 

“Due to a lack of competition, credit card companies have been able to exponentially increase hidden processing fees over the last decade.  These fees are most retailers’ highest business expense after labor and rent.  By requiring more than one network option on credit cards, the Credit Card Competition Act would foster competition and transparency in the credit card market so that card networks would have to compete for business on fees and terms – just as we compete for our customers’ business,” Leslie G. Sarasin, President and CEO, FMI – The Food Industry Association. 

There are currently four U.S. credit card networks: Visa, Mastercard, American Express, and Discover.  Visa and Mastercard are known as “four-party” networks; they act as agents for thousands of card-issuing banks and mandate the fees and terms that the banks receive from merchants for each transaction.  Merchants have limited leverage to negotiate fee rates and terms in four-party network systems, because they cannot risk losing access to the consumers served by Visa’s and Mastercard’s member banks.   

The market power and network structure of the Visa-Mastercard duopoly has enabled them to impose fees on U.S. merchants that are among the world’s highest, charging a total of $93 billion in U.S. merchant credit card fees in 2022.   These fees include interchange or swipe fees which Visa and Mastercard require merchants to pay to issuing banks, as well as network fees that Visa and Mastercard require merchants to pay directly to them.  Consumers ultimately pay for these fees in the price of the goods and services they buy. 

Under the Credit Card Competition Act, the Federal Reserve would issue regulations, to ensure that banks in four-party card systems that have assets of over $100 billion cannot restrict the number of networks on which an electronic credit transaction may be processed to less than two unaffiliated networks, at least one of which must be outside of the top two largest networks.  This would inject real competition into the credit card market—opening the door for new market entrants such as current debit-only networks, encouraging innovation and enhanced security, creating backup options if a network crashes, and exerting competitive constraints on Visa and Mastercard’s fee rates. 

The Credit Card Competition Act is supported by organizations including the American Beverage Licensees, Armed Forces Marketing Council, Energy Marketers of America, FMI, Hispanic Leadership Fund, International Franchise Association, National Association of College Stores, National Association of Convenience Stores, National Association of Theater Owners, National Grocers Association, National Restaurant Association, National Retail Federation, National Wildlife Refuge Association, NATSO, NFIB, Retail Industry Leaders Association, SIGMA, U.S. PIRG, and over 200 state and regional business associations.  

**Recently re-introduced legislation would change the current credit card interchange system, making our current payments system less secure and hurting consumers. Tell your lawmakers to oppose changes to the current interchange system. Send a Message to Your Lawmaker here

A one-pager of the bill can be found here.   

Consumers Do An About-Face on Chip Cards

on 7:03 AM

It wasn’t that long ago as issuers moved to chip cards from mag stripes that consumers were complaining about the change. But now More than half (54%) of U.S. consumers say inserting a chip card is their preferred payment method, according to a report from Ingenico Group and FreedomPay.

This is significantly more than the 11% who prefer swiping a magnetic strip card, noted LowCards.com in its analysis.

Contactless payments are increasing in popularity, though they have not taken off just yet. Only 7% of respondents said they preferred to tap their contactless cards, and 4% chose digital wallets for their payment of choice.

The research found that 84% of businesses currently accept contactless payments, but 63% of consumers do not know they can tap-to-pay, LowCards.com said.

Landry Restaurant Chain Breached

on 11:30 AM

As reported by CU InfoSecurity the Houston-based Landry's restaurant chain of over 600 restaurants, hotels, casinos and other entertainment establishments is investigating an apparent data breach after its security team found malware within a system.  The exact size and scope of the breach is not known, but Landry's began notifying customers on 12/31.  The security incident appears to have started around 3/13 and lasted until about 10/17.

This is the second time in the last 4 years that Landry's has been hit with malware targeting payment information. In 2016, the company announced it had investigated attacks at its restaurants and other properties dating back to 2014 and 2015.

It appears that some customers' payment card data was exposed as a result of the malware when waitstaff at some locations mistakenly swiped cards on terminals used to enter kitchen and bar orders, rather than on the more secure payment terminals, according to the company.

The unidentified malware tracks data found on the magnetic stripe of payment cards, and can include the cardholder name, the card number, expiration date and internal verification code. In some cases, the malware only identified the part of the magnetic stripe that contained payment card information without the cardholder name.  Because Landry's used end-to-end encryption within its point-of-sale devices, the malware couldn't read or collect most payment and credit card data it collected, the company states. But when the staff swiped cards at the other terminals, customer data may have been exposed, it acknowledges.

The potentially involved Landry establishments are listed online.

‘Weak Spot’ Leads to Rash of New Attacks Against Gas Stations, Pumps

on 10:04 AM

VISA says North American merchants that operate gas stations and gas pumps are facing a rash of attacks from cybercrime groups wanting to deploy point-of-sale malware on their networks. In two recent security alerts, VISA said its security team investigated at least five incidents of the sort, ZD Net reported.

The payments processor said cybercrime groups carried out attacks with the main purpose of gaining access to fuel dispenser merchants' networks, where they installed POS malware.
This POS malware works by continuously scraping a computer's RAM for what looks like unencrypted payment card data, which it collects, and then uploads to a remote server.

Weak Spot Identified
The VISA Payment Fraud Disruption (PFD) team says cybercrime groups appear to have found a weak spot in how gas stations and gas pump operators work. While the in-store POS terminals of some merchants might support chip transactions, most of the card readers installed on gas pumps do not.

These gas pump card readers still operate on older technology that can only read payment data from the card's magnetic stripe.

Data from these outdated card readers is sent unencrypted to the gas station's main network, where crooks have realized they can intercept it, ZD Net explained.

The attacks on fuel dispenser merchants began over the summer, VISA said. Two of the five attacks were linked to a known cybercrime operation known as FIN8.

How to Safeguard
VISA said the easiest ways for fuel dispenser merchants to safeguard customers is to either encrypt card data while it's being transferred across a network or stored in memory or shift to a chip card acceptance policy.

"Fuel dispenser merchants should take note of this activity and deploy devices that support chip wherever possible, as this will significantly lower the likelihood of these attacks," VISA said.
Fuel dispenser merchants have until October 2020 to deploy chip compatible card readers on their gas pumps.

“Starting October 2020, VISA said liability for any card fraud would shift from card issuers to the merchants, which will likely motivate many operators to update their gas pump card readers,” ZD Net said.

Checks Continue Decline; ACH & Card Payments Surge According to Fed Data

on 9:58 AM

For the first time, the number of ACH debit transfers has exceeded the number of check payments, according to a new Federal Reserve study.

Data released earlier in December showed that there were 16.6 billion ACH debit transfers in 2018 but only 14.5 billion check payments. Back in 2000, the story was much different: the year’s 2.1 billion ACH debit transfers paled in comparison to its 42.6 billion check payments.

However, the number of check payments has declined rapidly, falling 7.2% per year from 2015 to 2018. That rate was in line with drops between 2003 and 2012, but it was more than twice the 2.8% annual drop recorded over the prior three years.

"The growth of payments using debit and credit cards and the automated clearinghouse (ACH) system continued to accelerate from 2015 to 2018, while check payments continued their long-run decline,” the Federal Reserve noted in a press release.

The 2019 study included consumer, business, nonprofit and government payments in 2018 from U.S. domestic deposit accounts, prepaid debit cards, and credit cards, as well as cash withdrawals and deposits at depository institutions. 

Noncash growth rate accelerating
The study also found that noncash payments including debit card, credit card, ACH and check payments rose 6.7% per year between 2015 and 2018. The growth in debit and credit card payments accelerated too, rising 8.9% per year between 2015 and 2018, compared to a 6.8% annual growth rate between 2012 and 2015. Debit cards were used almost twice as much as credit cards in 2018, according to the data. ACH credit and debit transfers also grew faster, rising by 6% a year between 2015 and 2018, compared to 4.9% per year between 2012 and 2015.

“These core noncash payment types have retained their ability to be used in traditional ways even while they increasingly function as the means of settlement for innovative types of alternative payment methods and services, such as smartphone and internet-based services,” the Federal Reserve noted. 

Remote payments rivaling in-person
The Federal Reserve’s data also chronicled the rise of remote payments, which likely reflected continued changes in consumer shopping and financial management habits.

“For general-purpose (network-branded) cards overall, the value of remote payments in 2018 nearly equaled in-person payments, driven in part by growing e-commerce card payments and the use of cards for recurring bill payments. More than half of in-person general-purpose card payments were chip authenticated in 2018, compared to 2.0% in 2015,” the Federal Reserve noted. 

Fewer ATM withdrawals but more cash coming out
ATM visits continued to decrease, according to the data. The Federal Reserve reported 5.1 billion withdrawals in 2018, which was a 0.1 billion decrease from 2015. 

“The rate of decline for ATM cash withdrawals slowed compared with the previous three years, falling 0.9% per year from 2015 to 2018. The decline in the number, combined with an increase in value, resulted in average ATM cash withdrawals of $156 in 2018, compared to $146 in 2015,” it said.

Out of Network ATM Costs Reach Record High

on 4:48 PM

As reported this week in CU Times, the average out-of-network ATM withdrawal cost has reached a new record high of $4.72, according to the latest Bankrate.com Checking Account and ATM Fee Study, which surveyed non-interest and interest accounts.

This all-in fee, which includes the ATM surcharge (what ATM owners charge non-customers) as well as the penalty financial institutions charge their own customers to make out-of-network withdrawals is up 33% over the last decade.

Financial institutions are charging non-customers more than ever to use their ATMs. The average ATM surcharge increased 2% to a new record of $3.09, the 15th consecutive year establishing a new record. The average surcharge has increased in 20 of the past 21 years.

The good news, the fee charged by the accountholder’s own financial institution for using another institution’s ATM decreased 2% from $1.66 to $1.63, moving lower for the second year in a row. In fact, the number of financial institution and accounts allowing free out-of-network withdrawals is at a record high, although this still represents less than one-third of accounts (32%).

“While large banks have extensive ATM networks, many smaller banks and credit unions belong to nationwide fee-free alliances that may have significantly more ATMs available than even the ATM networks of big banks,” Greg McBride, CFA, Bankrate.com chief financial analyst said. “One other option to withdraw money for free is to get cash-back at the point of sale when using a debit card. Banks don’t charge for that and very few merchants do either.”

Among the findings:
  • Houston has the highest average out-of-network ATM fee of the 25 major metro areas examined ($5.58), while Los Angeles has the lowest ($4.15). Philadelphia has the highest average overdraft fee ($35.50) and Cincinnati has the lowest ($30.95).
  • Ninety-nine percent of non-interest checking accounts are either free by default or can become free, however less than half (42%) are free without stipulation. Forty-three percent will waive the monthly fee ($5.61, on average) based solely on direct deposit.

Push for Increased Data Security Continues

on 2:04 PM

With several high-profile data breaches hitting just in the month of August while Congress was in recess, CUNA and the state leagues are continuing their push for Capitol Hill lawmakers to enact meaningful data security legislation.

Stopping the data breaches is the subject of CUNA’s latest Member Activation Program (MAP) campaign launched in August to activate credit union members to call on their members of Congress to Act.

Specifically, CUNA and the state leagues are calling for Congress to:

  • Treat data privacy as a national security issue, as there have been more than 10,000 data breached in the U.S. since 2005, compromising nearly 12 billion consumer records. Many of these breaches are being perpetrated by foreign governments, domestic organized crime syndicates and rogue international actors using the data to fund illicit activities;
  • Fix the weak links in the system, meaning requiring all entities that hold and use consumer data be subject to strong federal data security requirements; and
  • Set a strong federal standard that preempts state laws,removing the current patchwork of various state laws, regulations and requirements that provide uneven protection and require numerous compliance resources.

CUNA has written to leadership of multiple House and Senate Committees, outlining the above principles. CUNA Chief Advocacy Officer Ryan Donovan also contacted all 535 Congressional offices in April emphasizing the economic and national security implications.

Lance Noggle, CUNA senior director of advocacy outlined why credit unions are leading the call for data security in a Credit Union Times op-ed, and has also brought the issue up with other agencies, including NCUA and the Federal Trade Commission.

The topic will be a featured discussion point with the Vermont Congressional delegation during AVCU's DC Hike-the-Hill on October 22nd

9/30 Deadline for Wendy's Data Breach Claims

on 12:54 PM

Credit unions affected by the Wendy’s data breach have until September 30th to file claims and find additional information at a website established as part of the settlement of that case.  Go to www.wendysfidatabreachsettlement.com to find the mechanism for filing claims, as well as additional information, frequently asked questions, a list of important deadlines and court documents.

Claim notices were mailed to known affected institutions but any institution who had affected cards may file a claim until September 30th. Valid claims will be paid based on the total number of cards alerted for this breach.

On February 26th the U.S. District Court for the Western District of Pennsylvania granted preliminary approval of a proposed settlement in First Choice Federal Credit Union v. The Wendy's Company, a data breach lawsuit brought by CUNA, leagues and credit unions affected by the 2016 breach.

A final approval hearing will take place November 6th.

Under the terms of the settlement:
  • Wendy's will pay $50m into a fund to compensate financial institutions that issued payment cards that were alerted on cards in connection with the data breach;
  • Wendy’s will adopt and/or maintain certain data security measures; and
  • Financial institutions will be able to file claims for reimbursement without requiring supporting documentation.

Study: Plastic Cards - Dirtiest Items People Carry

on 2:50 PM

According to a recent study by LendEDU.com, a finance website, plastic cards finish first in the race to be the dirtiest item carried around by most people.

LendEDU tested various items for their germ scores and found credit and debit cards to be near the top of the list — not as dirty as New York City park benches and rental-bike handles, for example, but more so than a urinal handle at Penn Station and more than the city's subway poles.

The 41 payment cards tested by the website had an average germ score of 285, compared with 160 for various dollar bills and 136 for coins. Lower scores indicate less bacteria, with germ scores of 10 or below recommended for restaurant surfaces. LendEDU conducted the study in early May using Hygiena's SystemSure Plus Handheld testing device.

The Penn Station urinal had a score of 163.

"When you think about all the places your cash has been and how many times it has changed hands, you realize that bills become germ-transporting vessels," noted the study's author, Michael Brown. So too for payment cards, which are "getting swiped or inserted, changing hands or sitting on bar tops," he said. Brown thinks higher germ readings for payment cards over cash us surprising.

"One might expect cash to be the filthiest since cash stays in circulation a lot longer and can travel across the country by changing hands," he wrote in the report. However, debit and credit cards are being used more often and in an increasing number of places.

The report offered several sanitizing suggestions, from wiping cards periodically to washing your hands frequently before and after use.Despite the advent of debit and credit cards and various types of electronic payments, cash remains the most frequently used payment form, according to a Federal Reserve study, with the number of bills in circulation rising for 17 straight years.

One interesting recent development, according to the Fed study, is that there are now more $100 bills out there than any other denomination, as they have emerged as a favored way to store wealth and aren't exchanged as often as many other bill types.

This supports a finding that $100 bills are the cleanest U.S. currency type examined by LendEDU, with $5 bills the dirtiest, followed by $10 and $20 bills.

Vermont Ranks 3rd for Average Credit Card Debt

on 4:17 PM

A recent study by WalletHub ranked each state according to the credit card debt consumers are racking up.  At the beginning of 2019 Americans owed a total of over $1 trillion in card debt. That number is only projected to increase by the end of the year. The study analyzed credit card data from TransUnion to calculate costs and required time to pay off a median card balance per state and Washington, D.C.

Vermont ranked 3rd highest average credit card debt among all states. The median credit card debt in the Green Mountain State is $2,227, which would take 15 months and 14 days to pay off.  Only the District of Columbia and Alaska ranked higher, at 2nd and 1st respectively. In DC, median credit card debt is $3,242, which would take consumers 17 months and 12 days to eradicate.  Alaska's median credit card debt is $4,144, and would take a consumer 19 months and 11 days to pay off.

Watch the video below and see the Wallet Hub study for all of the details.

100 Million Capital One Credit Card Applications & Accounts Exposed

on 10:57 AM

Yesterday Capital One announced a data breach from March where a 33-year old software engineer gained access to more than 100 million customer accounts and credit card applications, with intent to sell the information online.

Various news outlets report that Paige Thompson is accused of breaking into a Capital One server and gaining access to 140,000 Social Security numbers, 1 million Canadian Social Insurance numbers and 80,000 bank account numbers, in addition to an undisclosed number of people's names, addresses, credit scores, credit limits, balances, and other information.

Thompson tried sharing the information with others online by posting the information on GitHub, using her full first, middle and last name and boasting on social media that she had Capital One information. She even In a channel explained how she accessed Capital One on Slack, a chat service used by businesses as well as other groups, using a special command to extract files in a Capital One directory stored on Amazon's servers.

Thompson made little effort to disguise her identity, using the screen name "erratic" on Slack, which was the same handle she used on a Twitter account and a Meetup chatroom page. Thompson also reportedly tweeted that she wanted to distribute Social Security numbers along with full names and dates of birth.

Thompson previously worked as a tech company software engineer for Amazon Web Services, the cloud hosting company that Capital One was using.  Thompson was arrested on Monday of this week.  Capital One indicated it fixed the vulnerability and that it is "unlikely that the information was used for fraud or disseminated by this individual."

Watch the CBS News video below for the full story.

Debit Card Market Share Sets 2018 Record

on 3:22 PM

As reported in Credit Union Times, debit cards gained market U.S. purchase volume market share in 2018 for the first time since 2011.  The data results from The Nilson Report, saying that debit cards accounted for 40% of purchase volume in 2018.

U.S. credit, debit and prepaid cards accounted for about $6.7 trillion of spending on goods and services in 2018. Credit cards were 54.9% of all purchase volume, down from 55.07% in 2017.

A CO-OP Financial Services survey of 240 U.S. credit unions found that most were optimistic about the future of debit card portfolios. Over a third (38%) said their credit union has issued debit cards to at least 70% of their checking account customers. Overall, debit card accounts will grow about 3% to 4% a year, CO-OP predicts.

Earlier this year, a survey by the Federal Reserve found that for many credit unions and other financial institutions not subject to the Electronic Fund Transfer Act’s interchange cap, the average interchange fee for debit transactions on single-message networks (typically PIN transactions) has continued to fall since the cap took effect in 2011. However, fraud losses for all debit and prepaid card transactions rose between 2015 and 2017.

Wendy's Data Breach: Online Claims Filing

on 3:28 PM

Financial institutions affected by the data breach at Wendy’s restaurants can now file their claims and find additional information at a website established as part of the settlement of that case, wendysfidatabreachsettlement.com. It contains a mechanism for filing claims, as well as additional information, frequently asked questions, a list of important deadlines and court documents.

Claim notices were mailed to known affected institutions but any institution who had affected cards may make a claim.  Financial institutions have until Sept. 30 to file claims. Valid claims will be paid based on the total number of alerted on cards for this breach.

On February 26 the U.S. District Court for the Western District of Pennsylvania granted preliminary approval of a proposed settlement in First Choice Federal Credit Union v. The Wendy's Company, a data breach lawsuit brought by CUNA, leagues and credit unions affected by the 2016 breach.

A final approval hearing will take place on November 6th. Under the terms of the settlement:

  • Wendy’s will pay $50 million into a fund to compensate financial institutions that issued payment cards that were alerted on cards in connection with the data breach;
  • Wendy’s will adopt and/or maintain certain data security measures; and
  • Financial institutions will be able to file claims for reimbursement without requiring supporting documentation.

2.9 Million Canadian CU Account Holders Breached

on 11:39 AM

In what is being billed as a breach of the largest financial co-operative in all of North America, a rogue employee of Desjardins Group, based in Montreal, illegally exposed the personal information of some 2.9 million credit union members.  The affected information includes names, birth dates, social insurance numbers, email addresses, phone numbers, street addresses and details on banking habits. Passwords, security questions and personal identification numbers reportedly weren’t compromised.  The incident was not billed as a “cyberattack.” 

The data breach also affected 173,000 businesses, for whom Desjardins provides merchant processig and other services.

The francophone credit union system in Quebec is different than in other provinces, and different than that of the United States.  Desjardins Group (Mouvement des caisses Desjardins in french) is a cooperative that is the largest federation of credit unions in North America, and is regarded as among the world's strongest banks according to the Banker magazine.  It was founded in 1900 in Levis, Quebec by Alphonse Desjardins, an often cited influence in U.S. credit union history.

Although there are approximately 293 credit unions (caisses populaires in french) with 1,032 locations mostly throughout Quebec serving over 7 million members, they share common data processing, branding, marketing and other centralized resources provided by Desjardins.

In addition to retail banking, Desjardins has over 20 subsidiaries providing products and services related to insurance, real estate, venture capital and brokerage. Desjardins Group provides technical assistance and various investments in over 50 developing countries.

Watch the embedded CBC video below for more details.

Wendy's $50m Data Breach Settlement

on 8:56 AM

According to Credit Union Times, Wendy's has reached settlement with a group of credit unions and leagues following a 2-1/2 year litigation over the company's 2015 data breach.

The settlement requires Wendy’s to pay $50 million to a settlement fund set up to compensate financial institutions and pay attorney fees. Subject to court approval, Wendy’s will also pay a $7,500 “service award” to each deposed plaintiff, plus $2,500 to three other financial institution plaintiffs in the class-action complaint.

The plaintiffs’ attorneys will request 30% of the settlement plus reimbursement for their costs and expenses, according to court documents. Financial institutions in the settlement class can file a claim without having to submit proof of their losses, according to a memorandum filed with the court.

The Wendy's breach affected more than 1,000 Wendy’s franchise locations and 18 million payment cards. Plaintiffs alleged that criminals sold much of the exposed data on the black market; criminals then used the data to make fraudulent transactions. That caused credit unions to cancel and reissue cards, reimburse members for fraud, as well as incur other expenses, the plaintiffs claimed.

The litigation against Wendy's was initiated by First Choice Federal Credit Union, a $43m Pennsylvania credit union serving 6,500 members.

Kay Jewelers Parent Issues Unauthorized Credit Cards, Pays $11m Fine

on 1:15 PM

Sterling Jewelers, Inc., will pay $10 million to the Consumer Financial Protection Bureau (CFPB) and $1 million to the state of New York to settle claims that it violated the Consumer Financial Protection Act (CFPA) and Truth in Lending Act (TILA).

CFPB and New York Attorney General investigations revealed that
  • employees were incented to sign customers up for in-store credit cards by setting sign-up quotas and linking the number of customers signing up to employees’ performance reviews and compensation
  • customers were misled into thinking they were signing up for a rewards program but the the information they provided was used to file credit card applications; consumers didn’t know they had signed up for a credit card until they received a credit report inquiry or the card showed up in their mailboxes.
  • in situations where customers knew they were applying for credit cards, employees misrepresented terms by telling customers they were being enrolled in “no interest” promotional financing plans when, in fact, there were monthly financing fees.
  • consumers were enrolled in credit insurance connected to their in-store credit cards without their knowledge or consent.
The jeweler took a deep dive into its credit practices back in 2016 after analysts began commenting on the amount of subprime debt weighing heavy on its books, meaning the company might have been lending to too many consumers with low credit scores.  The company announced plans to outsource its credit portfolio in May 2017, selling $1 billion worth of prime-only accounts to Alliance Data System Corp, and completed its outsourcing in July 2018.  Sterling Jewelers operates more than 1,500 jewelry stores in the U.S., including retailers such as Kay Jewelers.

Square Launches Debit Card

on 12:03 PM

Fintech payments processing company Square has launched a debit card for small businesses. The card allows sellers who use Square's point-of-sale (POS) system to access funds from sales immediately.

Square previously launched a debit card for consumers that was tied to Square Cash and marketed for Square merchants. Its application for an industrial loan corporation (ILC) charter is still pending with the Utah Department of Financial Institutions.

CUNA and credit union leagues continue to call on lawmakers and regulators to ensure a level playing field between fintechs and regulated financial institutions. While acknowledging that fintechs can offer benefits to consumers, lawmakers and regulators are being urged to insure that fintechs providing services similar to a financial institution abide by the same or similar operating requirements, from data security to consumer protection.

MLA Credit Card Fee Spreadsheet Updated

on 11:56 AM

CUNA has updated its Military Lending Act (MLA) credit card fee spreadsheet for the fourth quarter of 2018. The updated resource can be found in the CUNA Compliance Community’s “Compliance Resources” tab, and under the “Resources” tab in CUNA’s MLA e-Guide.

The spreadsheet is necessary because a credit union may exclude a bona fide credit card fee from the military annual percentage rate (MAPR) if the fee is considered “reasonable,” under the MLA rule.

This means that the fee must be less than or equal to the average fee for the same or similar product charged by five separate card issuers that each have at least $3 billion in outstanding credit card balances at any time during the three-year period
preceding the time the average is determined.

Currently, there are approximately 20 large card issuers that meet this requirement and only one of those is a credit union.

Together, these card issuers have about 260 card agreements in the Consumer Financial Protection Bureau’s Card Agreement Database, but since many appear to be Private Label cards, only around 85 of the agreements seem to be useful for MLA purposes.

The exclusion generally applies to finance charges under Regulation Z such as cash advance fees, foreign transaction fees, balance transfer fees and transaction fees for purchases and minimum interest charges. Other charges, which are not finance charges under Regulation Z, such as a late fee or an over-limit fee are not included in the calculation of the MAPR, so the exclusion does not apply.

The exclusion does not apply to fees or premiums for credit insurance, fees for a debt cancellation contract, fees for a debt suspension agreement, or to fees for a credit related ancillary product. Those fees must be included in the calculation of the MAPR.

In addition to the CompBlog, CUNA’s Compliance Community contains discussion boards and a number of other resources for credit union compliance professionals around the country.

7 Payment & Tech Trends to Watch in 2019

on 10:50 AM

Co-op Financial Services issued the following list of 7 payment and technology trends to watch in 2019:
  1. GROWING INFLUENCE OF GENERATION Z - The post-Millennial generation is 74 million strong and by 2020 is expected to surpass both Millennials and Baby Boomers as the largest demographic in America. That is a huge population of potential members that credit unions should be focused on. What does Generation Z want from their financial institution? We know they’re constantly connected to their IoT devices and have high expectations for payments: Think instant P2P, flawless security and personalized data-driven experiences. But we also know that they’re actually more money-conscious than previous generations; Almost 12 percent of Gen-Zers under the age of 18 are already saving for retirement. This opens up a whole universe of new products for and ways to engage with these potential first time members.
  2. MOBILE PAYMENTS GAIN MOMENTUM AS APIS AND OPEN BANKING PROPEL GROWTH - Although mobile payments notoriously lag behind expectations, this will change as the mobile experience becomes more integrated and secure. One way that’s already happening is through the Open Banking movement. As more banking providers and fintechs partner to build integrated mobile apps and services, this will lead to higher mobile payments usage and an evolutionary shift toward digital experience.
  3. AI REVOLUTIONIZES FRAUD DETECTION AND MEMBER RELATIONSHIPS - According to a 2018 survey from Adobe and Econsultancy, 61 percent of financial services and insurance companies are already using AI for data analysis and to improve the customer experience. AI has already been making waves but the coming year will see rapid growth in AI adoption.. We are looking forward to bringing the benefits of AI and machine learning to the fight against fraud through our COOPER Fraud Analyzer solution, currently in pilot testing and slated to launch in the coming months.
  4. PAYMENTS AS AN EXPERIENCE - This might be more accurately described as the payments “non-experience.” The rate at which payments innovation is happening leads us to think that frictionless payments experiences will become not only common, but expected. Whether it is cashierless stores like the ones Amazon has begun building or the ability to pay for gas without having to step outside your car, the payments experiences that once seemed works of science fiction are fast becoming reality.
  5. ALTERNATIVE PAYMENTS AND FINANCING GAIN NEW GROUND - Alternative payments – P2P, contactless payments, wearables and connected commerce – have seen unprecedented growth and will completely change the context of payments. Consider the fact that P2P platform Zelle saw 320 million transactions in its first year and already reaches 100 million consumers. Alternative financing is another area of payment that is poised to break out. For example, fintech incumbent Square recently announced a new program that will offer customers on-the-spot financing for large purchases when a merchant uses Square for payment processing.
  6. FINTECHS AND FINANCIAL INSTITUTIONS FIND SYNERGY - Though often thought of as competitors, fintech companies and financial institutions will begin working together. Here’s why: “Fintech startups bring agility and technological know-how to the table; legacy financial institutions provide resources and regulatory acuity that’s been honed over decades. Long-standing financial institutions are banking on their wealth of experience for security and relevance in a digital era—one in which more than 30 percent of millennials say they won’t even need a bank in the next five years,” Deloitte wrote in a Quartz post. This rings even more true for credit unions. Credit unions have the advantage of long-standing member relationships and member trust, something that fintech companies understand to be critically important. Ultimately, the synergy between technology companies and credit unions may leave us wondering why either camp was trying to function without the other – collaboration is everything.
  7. FINANCIAL SERVICES BECOME PLATFORM AND ECOSYSTEM PLAYERS - The digital revolution that transformed retail, hospitality, music, transportation and video is coming to financial services. The industries that will thrive will be the ones that can create an integrated ecosystem with a shared vision. For credit unions, that means making every member touchpoint and channel seamless, secure and integrated, with data as the connective tissue. That is our vision for CO-OP and perhaps the most important trend for credit unions to watch.
These 7 trends mark a culmination – some decades in the making – of tectonic changes in financial services and the culture at large. What’s different today is the unprecedented opportunity credit unions have to harness these forces and create momentum and growth. Change is happening at an unprecedented rate within payments. Part of that is fueled by emerging technologies, but a lot of it has to do with the shift in consumer behavior and expectations. And while this will create a number of business challenges for credit unions – it will also generate a lot of opportunities.

The theme of Co-op Financial's THINK 19 – May 6 to 9 in Miami – is “Opportunity Never Rests.” As credit unions embrace innovation and transformation, they’re creating relevance, efficiency and growth. Over the course of four days, THINK 19 will take a deep dive into the opportunities created by massive demographic shifts, the e-commerce revolution, digital transformation and new collaborations between fintech and financial services.

Join CO-OP at THINK 19, May 6-8 in Miami, for four days of keynotes, breakout presentations and networking opportunities to help grow your business. Register now and enjoy a discount Fall Savings discount off the registration price.


GovPayNow Leaks 14M+ Records

on 11:51 AM

As reported by KrebsonSecurity, a new data breach involving over 14 million consumer records dating back at least six years, including names, addresses, phone numbers and the last four digits of the payer’s credit card has been leaked.  the data breach occurred at Government Payment Service Inc. . . . used by thousands of U.S. state and local governments to accept online payments for everything from traffic citations and licensing fees to bail payments and court-ordered fines.

GovPayNet, doing business online as GovPayNow.com, serves approximately 2,300 government agencies in 35 states. GovPayNow.com displays an online receipt when consumers use it to settle state and local government fees and fines via the site. Until this past weekend it was possible to view millions of customer records simply by altering digits in the Web address displayed by each receipt.

In January of this year GovPayNet was acquired by Securus Technologies, a Texas-based company providing telecommunications services to prisons and helps law enforcement personnel keep tabs on mobile devices used by former inmates.  Securus does not have a great track record in securing data:
  • In May 2018, Securus’ service for tracking the cell phones of convicted felons was reported as being abused by law enforcement agencies to track the real-time location of mobile devices used by people who had only been suspected of committing a crime. Reportedly, authorities could use the service to track the real-time location of nearly any mobile phone in North America.
  • A short while later, it was reported that hackers had broken into Securus’ systems and stolen the online credentials for multiple law enforcement officials who used the company’s systems to track the location of suspects via their mobile phone number.
  • Another KrebsonSecurity story in May explained how Securus’ site reportedly allowed anyone to reset the password of an authorized Securus user simply by guessing the answer to one of three pre-selected security questions including:
    • What is your pet name?
    • What is your favorite color?, and
    • What town were you born in?
In other data breach incidents of 2018 . . . 
  • In April Panera Bread remedied a weakness that exposed millions of customer names, email and physical addresses, birthdays and partial credit card numbers.
  • In July, identity theft protection service LifeLock fixed an information disclosure flaw that exposed the email address of millions of subscribers.
  • In August, KrebsOnSecurity disclosed a similar flaw at work across hundreds of small bank websites run by Fiserv, a major provider of technology services to financial institutions.
Read the KrebonSecurity article online.