Showing posts with label payments. Show all posts
Showing posts with label payments. Show all posts

Visa, Mastercard, merchants reach settlement in interchange lawsuit

on 1:25 PM

Visa and Mastercard announced a major settlement with U.S. merchants on Tuesday, potentially ending nearly two decades of litigation over the fees charged every time a credit or debit card is used in a store or restaurant.

The deal would lower and cap the fees charged by Visa and Mastercard and allow small businesses to collectively bargain for rates with the payment processors in a similar way that the large merchants do on their own now.

Industry groups for retailers both small and large said the settlement is a positive development, but far more needs to be done to remedy the current swipe-fee situation. They noted that the lowered fees would be only for a limited period of time — three to five years — after which the fees would return to their current levels.

"While this settlement is a step in the right direction and will provide a limited amount of short-term relief to small businesses, it does not solve the long-term anti-competitive rate-setting practices that are the root of this problem," said Jeff Brabant, vice president of federal government relations at the National Federation of Independent Business, a small-business advocacy group. "As long as the credit card networks, Visa and Mastercard, get to set the interchange rates for every bank that issues a credit card, anti-competitive pricing will remain, and small businesses will continue to pay artificially high rates."

Swipe fees are paid to Visa, Mastercard and other credit card companies in exchange for enabling transactions. Merchants ultimately pass on those fees to consumers who use credit or debit cards. The fees are calculated as a fixed fee plus a percentage of the sales total, typically about 1% to 3%.

Increasingly, small businesses have begun posting signs near the register warning customers that they will pay more for the same item if they do not use cash.

According to the settlement announced Tuesday, Visa and Mastercard will cap the credit interchange fees until 2030, and the companies must negotiate the fees with merchant-buying groups.

The law firm that announced the settlement put the value of the savings in swipe fees at close to $30 billion.

America’s Credit Unions is analyzing the settlement, but has concerns with several areas that could impact credit unions, including:  

  • Merchants would be permitted to surcharge Visa or Mastercard branded credit cards up to 3%; 
  • Visa and MasterCard would modify their “no-discounting” and “non-discrimination” rules to allow merchants to offer discounts to customers based on the credit or debit card issuer;  
  • Modification of the “honor all cards” rules to indicate that a merchant may accept and enable some but not all digital wallets and steer consumers to specific cards within the digital wallet; and 
  • Reduction in the interchange rate paid by merchants for the next five years.  

The settlement requires approval by the Eastern District Court of New York. 



PSCU Finds Energy Fueling Member Spending

on 9:05 AM

 Credit union members continued to increase their spending in September with rising prices, especially for energy, being a major factor, according to a PSCU report Tuesday.

PSCU, a payments CUSO based in St. Petersburg, Fla., showed overall dollars spent on credit cards in September was 13% higher than in September 2021, while the number of transactions rose 11%. Debit spending rose 6%, while transactions rose 3%.

But the PSCU Payments Index found the disparity between dollars and transactions was especially high for energy: From gasoline to utilities.

“The U.S. economy continues to face persistently high inflation, a looming recession and rising energy prices. Yet consumer purchasing activity showed continued resilience in both credit card and debit card volume in September,” the report said.

Spending for gasoline rose 26% by credit card — twice as fast as the 13% increase in transactions. By debit, spending rose 13% while transactions rose 3%.

For electricity, natural gas and water, spending rose 26% while transactions grew 12%. By debit, spending rose 14% while transactions grew 5%.

Among credit union members receiving their first deliveries of fuel oil or propane in September — typically in the north— spending for those home heating fuels rose by 50%, while transactions rose 25%. By debit, spending rose 45%, while transactions rose 14%.

The U.S. Census Bureau reported Oct. 14 that retail spending, excluding automobiles and parts, rose 9.4% in September from a year earlier.

Census found grocery store spending rose 7% in September from a year earlier, Census reported. At PSCU, spending rose 17% by credit and rose 7% by debit.

Spending at restaurants and bars rose 13% in July from a year earlier, Census reported. At PSCU, spending rose 21% by credit and rose 7% by debit.

The average credit card balance was $2,797 per active account handled by PSCU in September, up 6.1% (or $160) from a year earlier.

“Credit card balances surpassed the September 2020 results of $2,787 for the first time since the decline in card balances that began in early 2020. The credit card delinquency rate for September was 1.74%, 16 basis points lower than pre-pandemic September 2019 levels,” the report said.

The Fed’s G-19 Consumer Credit Report released Oct. 7 showed credit card balances grew 13.3% to $69.8 billion in August from a year ago, and rose 1.2% from the previous month, compared with an average July-to-August gain of 1% from August 2015 through August 2021.

The PSCU Payments Index was based on data from credit unions that have been processing payments with PSCU since January 2020. It encompassed 2.9 billion transactions valued at $144 billion of credit and debit card activity in the 12 months ending Sept. 30.

Even a small credit union couldn’t escape the demand for contactless payments

on 2:45 PM

 The primary signal of a routine errand turned scary got here at the beginning of 2020 when Debra Miles went to the pharmacy.

“I am a little bit of a germaphobe. Once I picked up a prescription they nonetheless needed me to signal, and I am like ‘yuck’,” mentioned Miles, the chief monetary officer at Astera Credit score Union, a 15,000-member credit score union based mostly in Lansing, Mich., and property of $178 million. “And a whole lot of our members felt the identical means. Abruptly the request for contactless rose.”

Miles advised her credit score union’s story at PaymentsSource’s latest Card Discussion board: Contactless occasion. Astera, which has 4 branches, was embarking on an enlargement to advertise extra flexibility in its card technique through a migration to PSCU, the St. Petersburg, Fla.-based credit score union service group.

That venture started in 2019 and remains to be underway. However the venture’s priorities modified relatively all of the sudden throughout 2020, and pushed a larger emphasis on contactless fee help.

“As a part of our analysis in January 2020 we discovered, based mostly on our location and service provider adoption, contactless was not being requested for in our space,” Miles mentioned, including that experiences much like the drug retailer began cropping up relatively rapidly after January. “A few of the retailers complained to me that I used to be not the primary one asking for contactless at their retailer.”

Contactless had all of the sudden jumped from the again burner, and have become sufficient of a necessity that it is now a part of the credit score union’s relationship-building technique. The identical companies that had been gradual to undertake EMV years in the past had begun racing to replace their terminals for contactless funds, in response to Chassidy Butler, a strategic advisor at CU Have interaction, which is advising Astera on its PSCU migration. Butler additionally spoke at Card Discussion board: Contactless.

Astera was confronted with the prospect of shedding germaphobic prospects to bigger establishments that jumped into contactless funds earlier. Every time individuals realized Miles labored for Astera, they’d start asking when the credit score union would help contactless funds. The reply is by the tip of April, Miles mentioned.

Contactless in all varieties — buying, ordering, transit ticking, funds, and ATMs — is likely one of the largest tendencies to come back out of the pandemic for retailers, if not the biggest. Banks that had been gradual so as to add contactless and cellular funds all of the sudden rushed to the expertise out of considerations of contagion or as a part of a broader transfer to e-commerce.

The impression of being with client tendencies can matter as a lot because the expertise, mentioned Butler, citing analysis from Visa that discovered 79% of fast serve chains, 77% of drug shops and 61% of grocery shops within the U.S. now settle for contactless funds, making contactless decidedly much less of an outlier.

“Contactless is not only one thing for millennials,” Butler mentioned. “The pandemic has been a terrific leveler.”

Contactless debit can also be rising sooner than contactless bank cards, Butler mentioned, citing knowledge from PSCU that discovered contactless debit rose to 18.6% of funds in 2021, from 8.4% in 2020, whereas credit score elevated to 13.6% in 2021, from 6.5% in 2020. “Often bank cards transfer sooner, however persons are involved about their funds,” Butler mentioned.

Shoppers and retailers turned conscious of those tendencies towards each debit and digital funds, creating a necessity for Astera to undertake contactless and mass card issuance to get contactless out sooner. The credit score union can also be transferring to eight-digit financial institution identification numbers forward of the April 2022 deadline from the Worldwide Requirements Group. It will accommodate tokenization for on-line commerce and the rising variety of general fee playing cards in circulation that makes it more durable to provide distinctive 6-digit identifiers.

“Members are telling us that if we now have contactless funds they’d make us their main monetary establishment,” Miles mentioned. “We all know our members ‘cheat’ on us with different monetary establishments, but when we might be their high FI — if that is one factor we may do — I used to be on board.”

As a small credit score union you will need to stand out, Miles mentioned, including a whole lot of banks and credit score unions that do enterprise close to Astera’s footprint shouldn’t have contactless funds.

“The mass issuance and contactless coming collectively make sense for us when it comes to reaching customers and when it comes to {dollars} and cents,” Miles mentioned.

NEACH Seeks Nominations for Board

on 10:06 AM

The New England ACH Association (NEACH) is seeking qualified candidates to serve on its Board of Directors.  All candidates must hold an officer position at a NEACH-member financial institution. Board members are elected for two-year terms. The Board seeks gender, racial, and geographic
diversity and officers of member financial institutions committed to helping NEACH achieve its
mission of providing strategic and operational support to its members. Additionally, the Board
endeavors to expand the expertise and perspectives represented on the Board. Candidates
should have an understanding of NEACH’s mission and the work NEACH does to improve the
payments landscape.

Interested candidates are encouraged to review the Board Responsibilities and to complete the
nomination form and questionnaire. We also ask that interested candidates complete a short
skills assessment and demographic survey.  Nominations for positions on the NEACH Board of Directors will be accepted through July 31, 2020. Completed documentation can be sent to Nicole Beck-Dowd at nbeckdown@neach.org .

Members of NEACH's 17 member board include Steve Roy, President of Tricorp FCU, and the lone Vermont board member is Caroline Carpenter, President of National Bank of Middlebury.

Equifax Settles CU Suit Over Data Breach

on 11:53 AM

Equifax has settled a lawsuit with financial institutions, most of which are credit unions, following its 2017 data breach that affected more than 147 million U.S. consumers.

CUNA initially filed the lawsuit and was later joined by both the Pennsylvania and New Jersey credit union leagues, now called CrossState, and dozens of other plaintiffs, including state leagues and individual credit unions seeking to recover costs related to reissuing cards, reimbursing members and more.

In its settlement, Equifax has agreed to:
  • Pay up to $5.5 million to settlement class members who submit valid claims documenting unreimbursed out-of-pocket expenses associated with the breach and fraud reimbursement amounts paid to customers between July 6 and Dec. 20, 2017
  • Spend a minimum of $25 million over the next two years on relevant data security measures
  • Pay settlement costs and court-approved attorneys’ fees, expenses, and service awards 

Secret Service and Treasury Issue Guidance with Tips to Spot Counterfeit Stimulus Checks

on 9:40 AM


The Secret Service, in partnership with the U.S. Department of the Treasury (Treasury), has issued guidance to help consumers, retailers and financial institutions detect counterfeit Treasury checks by knowing what to look for and where to look.

The announcement comes as millions of Americans receive their economic impact payment checks, which are being issued pursuant to the CARES Act. While over 80 million Americans received their economic impact payment checks via direct deposit to their bank accounts, millions of Americans are waiting for paper checks that will be mailed in accordance with a preset schedule beginning the end of April.

The Secret Service and the Treasury guidance outlines the following six "Quick Tips / Genuine Security Features" that a person receiving, accepting, or cashing the economic impact payment check should look for:

  • There is a new Treasury seal to the right of the Statue of Liberty. The new seal should read "Bureau of the Fiscal Service" and it replaces the old seal that read "Financial Management Service (FMS)".
  • When moisture is applied to the black ink on the seal next to the Statue of Liberty, the ink will "run" and turn red.
  • All Treasury checks are printed on watermarked paper. The watermark reads "U.S. TREASURY" and can be seen from both front and back when held up to a light source.
  • An invisible to the naked eye "protective ultraviolet overprinting" (UV) pattern is on the paper check. It consists of lines of "FMS" bracketed on the left by the FMS seal and on the right by the U.S. Seal (eaglet. As of 2013, a new ultraviolet pattern was introduced into the check that says 'FISCALSERVICE.' Either one of these UV patterns maybe be seen.
  • The back of the check is microprinted with the words "USAUSAUSA".
  • Printed on the lower right side of the Statue of Liberty will be the following information "Economic Impact Payment President Donald J. Trump".

Anyone who believes they may have a counterfeit economic impact payment check is urged to contact local law enforcement, a Secret Service field office, or the Treasury. The guidance can be accessed here.


PSCU Card Data Suggests Consumers' Stockpiling Frenzy May Be Waning

on 12:40 PM

New data from PSCU suggested that the urge to stock up on groceries and other supplies is beginning to wane.

In new research, the St. Petersburg, Fla.-based CUSO said that among its owner credit union members, credit card spending at grocery stores and supermarkets grew 24.9% year-over-year for the week of March 23, 2020, compared to the week of March 25, 2019, and debit card spending grew 10%. However, those growth rates were much lower than what PSCU saw in the preceding two weeks of March, “indicating that consumers were easing back from their ‘stock-up’ purchases conducted during the early weeks of the COVID-19 pandemic,” it noted.

PSCU also said growth rates in credit and debit card spending at drug stores and pharmacies were flattening. During the week of March 23, 2020, credit card spending in the sector grew by just 0.7%, and debit card spending actually fell 7.5%. In contrast, just a week before that, year-over-year spending at drug stores and pharmacies was up 33% for credit cards and 27.4% for debit cards.

Overall credit card spending was down 29.9% for the week of March 23, 2020, compared to the week of March 25, 2019. Debit card spending was down 18.1%, PSCU found.

“As anticipated, we began to more clearly see the negative impacts of the COVID-19 pandemic on consumer spending this week,” PSCU Advisors Plus SVP Glynn Frechette said. “As the situation evolves and more nonessential retail stores are closed, along with stay-at-home orders being put in place throughout the country, we expect continued downward pressure on consumer spend. We will continue to keep our credit unions apprised of these trends to help guide their decision-making and best serve their members in these challenging times.”

An even stronger trend has played out for gas stations, according to the data. Credit card spending was down 52.2% and debit card spending dropped 40.1% for the week of March 23, 2020, compared to the week of March 25, 2019. Lower gas prices and the giant increase in working from home likely drove the declines, PSCU noted.

Purchases of consumer goods also slumped during the week of March 23 compared to the same week of 2019, falling 18.6% for credit cards and 17.7% for debit cards.

Marriott Announces 5.2m Hotel Guest Data Breach

on 1:37 PM

Yesterday the Marriott hotel chain disclosed a security breach that impacted more than 5.2 million hotel guests who used the company's loyalty app.  According to a breach notification posted on its website, the hotel chain learned of the security breach at the end of February when it discovered a hacker had used the login credentials of two employees from one of its franchise properties to access customer information from the app's backend systems.

Marriot says the hack dated back to mid-January but did not disclose additional details about how it happened. The hotel chain said that the intruder(s) had direct access to Marriott Bonvoy loyalty data such as:

  • Contact details (e.g., name, mailing address, email address, and phone number)
  • Loyalty Account Information (e.g., account number and points balance, but not passwords)
  • Additional Personal Details (e.g., company, gender, and birthday day and month)
  • Partnerships and Affiliations (e.g., linked airline loyalty programs and numbers)
  • Preferences (e.g., stay/room preferences and language preference)
  • The hotel said that at this moment in the investigation, it did not believe that the hacker did not gain access to account passwords, account PINs, payment card information, passport information, national IDs, or driver's license numbers.
The hotel said that it doesn't believe the hacker gained access to account passwords, account PINs, payment card information, passport information, national IDs, or driver's license numbers.

Marriott launched a web portal for Bonvoy app users to check if they're one of the 5.2 million users impacted by the security breach, and what data the hacker might have accessed.

This is the second security breach Marriott disclosed in the past 16 months. In November 2019, Marriott said that hackers gained access to the Starwood Hotels reservation system, from where they stole the personal details of more than 383 million hotel guests (revised from the initial figure of 500 million). See our post-mortem coverage, here. US authorities said they suspected Chinese hackers of being behind the breach, but only put out a statement, but no official charges.

Consumers Do An About-Face on Chip Cards

on 7:03 AM

It wasn’t that long ago as issuers moved to chip cards from mag stripes that consumers were complaining about the change. But now More than half (54%) of U.S. consumers say inserting a chip card is their preferred payment method, according to a report from Ingenico Group and FreedomPay.

This is significantly more than the 11% who prefer swiping a magnetic strip card, noted LowCards.com in its analysis.

Contactless payments are increasing in popularity, though they have not taken off just yet. Only 7% of respondents said they preferred to tap their contactless cards, and 4% chose digital wallets for their payment of choice.

The research found that 84% of businesses currently accept contactless payments, but 63% of consumers do not know they can tap-to-pay, LowCards.com said.

New Research Projects 52% of ATMs Will Offer Automated Deposits by 2024

on 6:41 PM

More than half of the world’s ATMs will offer automated deposits by 2024, according to new projections from banking research and consulting firm RBR. The London, England-based firm also predicted that the United States will see tens of thousands more automated deposit terminals (ADTs) arrive in the next five years.

“In a busy world where time is of the essence, both business and retail customers no longer expect to have to queue for the teller to make everyday deposits,” RBR said. “Banks report that deposit ATMs are an efficient tool for keeping their customers satisfied, while also enabling them to migrate transactions from the teller and achieve cost savings.”

Automated deposit transactions have risen quickly in the last few years, according to the research.
“Excluding China, where a meteoric surge in mobile payments has stifled cash usage, automated deposits grew by 10% in the other core markets covered in the report, contrasting with a fall in cash withdrawals in many of the same markets. Customers increasingly appreciate the benefits offered by automated deposit such as reduced queuing, instant account crediting and out-of-hours availability,” it noted.

RBR said it expected the number of terminals in the markets in the study to hit 1.6 million by 2024, which is a 14% increase. Much of that growth will come from deposit ATMs, which will make up 52% of the ATM population by 2024, it said. In the United States, RBR estimated that 40,000 ADTs will spring up in the next five years.

ADTs do more than just accept deposits. RBR predicted that two-thirds of them will also be able to recycle cash by 2024.

“Although the technology has been available for decades, the number of deposit ATMs installed worldwide continues to demonstrate healthy growth,” RBR researcher Sam Blackwell said. “Banks are now expected to pivot further towards recycling as the ratio of withdrawals to deposits narrows and CIT costs grow, presenting increased opportunities for cost savings.”

Landry Restaurant Chain Breached

on 11:30 AM

As reported by CU InfoSecurity the Houston-based Landry's restaurant chain of over 600 restaurants, hotels, casinos and other entertainment establishments is investigating an apparent data breach after its security team found malware within a system.  The exact size and scope of the breach is not known, but Landry's began notifying customers on 12/31.  The security incident appears to have started around 3/13 and lasted until about 10/17.

This is the second time in the last 4 years that Landry's has been hit with malware targeting payment information. In 2016, the company announced it had investigated attacks at its restaurants and other properties dating back to 2014 and 2015.

It appears that some customers' payment card data was exposed as a result of the malware when waitstaff at some locations mistakenly swiped cards on terminals used to enter kitchen and bar orders, rather than on the more secure payment terminals, according to the company.

The unidentified malware tracks data found on the magnetic stripe of payment cards, and can include the cardholder name, the card number, expiration date and internal verification code. In some cases, the malware only identified the part of the magnetic stripe that contained payment card information without the cardholder name.  Because Landry's used end-to-end encryption within its point-of-sale devices, the malware couldn't read or collect most payment and credit card data it collected, the company states. But when the staff swiped cards at the other terminals, customer data may have been exposed, it acknowledges.

The potentially involved Landry establishments are listed online.

‘Weak Spot’ Leads to Rash of New Attacks Against Gas Stations, Pumps

on 10:04 AM

VISA says North American merchants that operate gas stations and gas pumps are facing a rash of attacks from cybercrime groups wanting to deploy point-of-sale malware on their networks. In two recent security alerts, VISA said its security team investigated at least five incidents of the sort, ZD Net reported.

The payments processor said cybercrime groups carried out attacks with the main purpose of gaining access to fuel dispenser merchants' networks, where they installed POS malware.
This POS malware works by continuously scraping a computer's RAM for what looks like unencrypted payment card data, which it collects, and then uploads to a remote server.

Weak Spot Identified
The VISA Payment Fraud Disruption (PFD) team says cybercrime groups appear to have found a weak spot in how gas stations and gas pump operators work. While the in-store POS terminals of some merchants might support chip transactions, most of the card readers installed on gas pumps do not.

These gas pump card readers still operate on older technology that can only read payment data from the card's magnetic stripe.

Data from these outdated card readers is sent unencrypted to the gas station's main network, where crooks have realized they can intercept it, ZD Net explained.

The attacks on fuel dispenser merchants began over the summer, VISA said. Two of the five attacks were linked to a known cybercrime operation known as FIN8.

How to Safeguard
VISA said the easiest ways for fuel dispenser merchants to safeguard customers is to either encrypt card data while it's being transferred across a network or stored in memory or shift to a chip card acceptance policy.

"Fuel dispenser merchants should take note of this activity and deploy devices that support chip wherever possible, as this will significantly lower the likelihood of these attacks," VISA said.
Fuel dispenser merchants have until October 2020 to deploy chip compatible card readers on their gas pumps.

“Starting October 2020, VISA said liability for any card fraud would shift from card issuers to the merchants, which will likely motivate many operators to update their gas pump card readers,” ZD Net said.

Checks Continue Decline; ACH & Card Payments Surge According to Fed Data

on 9:58 AM

For the first time, the number of ACH debit transfers has exceeded the number of check payments, according to a new Federal Reserve study.

Data released earlier in December showed that there were 16.6 billion ACH debit transfers in 2018 but only 14.5 billion check payments. Back in 2000, the story was much different: the year’s 2.1 billion ACH debit transfers paled in comparison to its 42.6 billion check payments.

However, the number of check payments has declined rapidly, falling 7.2% per year from 2015 to 2018. That rate was in line with drops between 2003 and 2012, but it was more than twice the 2.8% annual drop recorded over the prior three years.

"The growth of payments using debit and credit cards and the automated clearinghouse (ACH) system continued to accelerate from 2015 to 2018, while check payments continued their long-run decline,” the Federal Reserve noted in a press release.

The 2019 study included consumer, business, nonprofit and government payments in 2018 from U.S. domestic deposit accounts, prepaid debit cards, and credit cards, as well as cash withdrawals and deposits at depository institutions. 

Noncash growth rate accelerating
The study also found that noncash payments including debit card, credit card, ACH and check payments rose 6.7% per year between 2015 and 2018. The growth in debit and credit card payments accelerated too, rising 8.9% per year between 2015 and 2018, compared to a 6.8% annual growth rate between 2012 and 2015. Debit cards were used almost twice as much as credit cards in 2018, according to the data. ACH credit and debit transfers also grew faster, rising by 6% a year between 2015 and 2018, compared to 4.9% per year between 2012 and 2015.

“These core noncash payment types have retained their ability to be used in traditional ways even while they increasingly function as the means of settlement for innovative types of alternative payment methods and services, such as smartphone and internet-based services,” the Federal Reserve noted. 

Remote payments rivaling in-person
The Federal Reserve’s data also chronicled the rise of remote payments, which likely reflected continued changes in consumer shopping and financial management habits.

“For general-purpose (network-branded) cards overall, the value of remote payments in 2018 nearly equaled in-person payments, driven in part by growing e-commerce card payments and the use of cards for recurring bill payments. More than half of in-person general-purpose card payments were chip authenticated in 2018, compared to 2.0% in 2015,” the Federal Reserve noted. 

Fewer ATM withdrawals but more cash coming out
ATM visits continued to decrease, according to the data. The Federal Reserve reported 5.1 billion withdrawals in 2018, which was a 0.1 billion decrease from 2015. 

“The rate of decline for ATM cash withdrawals slowed compared with the previous three years, falling 0.9% per year from 2015 to 2018. The decline in the number, combined with an increase in value, resulted in average ATM cash withdrawals of $156 in 2018, compared to $146 in 2015,” it said.

Holiday Anti-Fraud Tips for Credit Unions

on 10:41 AM

As reported recently by Credit Union Times, Chicago-based OneSpan, provider of anti-fraud and digital identity solutions to financial institutions, offered some holiday protection tips and six predictions they suggest will shape the 2020 financial services industry.

“Fraudsters don’t take time off for the holidays and in fact, may capitalize on seasonal spikes in transaction volume to more easily evade detection. As consumers increasingly use their mobile phones as their primary device for holiday shopping, banking and other transactions, cybercriminals are also turning their attention to the mobile channel,” Will LaSala, director of security solutions at OneSpan, said.

LaSala pointed out, “Mobile malware nearly doubled in 2018 and mobile account takeovers increased 79%. It’s estimated fraud losses to banks and credit unions have topped $31 billion due to customer account takeover, new account application fraud and other types of fraud occurring in digital channels.” He recommended employing mobile app security as the key to fighting fraud not only this holiday season, but all year long.

The cybersecurity director provided some measures credit unions can implement immediately to safeguard member data, meet compliance with industry regulations and avoid becoming another data breach headline:
  • As transaction volumes increase fraudsters will use this spike to try and scam transactions and call centers. Let members know your brand will never ask them for their credentials via email, text or chat.
  • Remind staff that security standards do not need to slip. Even though transaction volumes will be higher, pay attention to those out of the ordinary requests and do not cut any corners. Stick to the processes and procedures defined throughout the entire year.
  • Mobile banking apps should protect themselves in untrusted device environments. defend any type of mobile app against sophisticated malware, they should use application shielding technology as protection.

Click here to read the full article.

Krebs on Security: Sale of 4 Million Stolen Cards Tied to Breaches at 4 Restaurant Chains

on 2:14 PM

Cybersecurity expert and journalist Brian Krebs reported last week on his blog that on November 23rd, one of the cybercrime underground’s largest bazaars for buying and selling stolen payment card data announced the immediate availability of some four million freshly-hacked debit and credit cards. Krebs said he learned that this latest batch of cards was siphoned from four different compromised restaurant chains that are most prevalent across the midwest and eastern US.

Two financial industry sources who track payment card fraud and asked to remain anonymous for this story said the four million cards were taken in breaches recently disclosed by restaurant chains Krystal (pictured orange), Moe’s (pictured gray), McAlister’s Deli (pictured green) and Schlotzsky’s (pictured blue). Krystal announced a card breach last month while the others are all part of the same Focus Brands parent company which disclosed breaches in August 2019.

KrebsOnSecurity heard the same conclusion from Gemini Advisory, a New York-based fraud intelligence company.

“Gemini found that the four breached restaurants, ranked from most to least affected, were Krystal, Moe’s, McAlister’s and Schlotzsky’s,” Gemini wrote in an analysis it shared with Krebs on Security. “Of the 1,750+ locations belonging to these restaurants, nearly 50% were breached and had customer payment card data exposed.”

Click the link to read the full article on the Krebs on Security blog.

61% w/Credit Card Debt Willing to Go Deeper For Holidays

on 3:11 PM

The holidays bring out the best and worst in people, and always tend to make consumers go into debt.

In October, CreditCards.com commissioned YouGov Plc to conduct a survey of 2,600 adults, including 2,143 credit card holders. Fieldwork was undertaken Oct. 2-4, 2019. The survey was carried out online.

Results of the survey show that 61% of those who carry a card balance are willing to add to their deficit this holiday season, compared to 30% of cardholders who do not currently have credit card debt.  And more than half (52%) of millennials surveyed said they are willing to add to their debt, as opposed to 49% of Gen Xers and 34% of baby boomers.

Check out these other notable results from the holiday debt poll:
  • Those in debt are more willing to add to it. More than half of credit card debtors (51%) said they think the holidays are a valid reason to add to their debt, but only a small percentage of those with no debt agreed (26%);
  • Kids matter. When it comes to the holidays children are the stars—almost two-thirds of parents (65%) with kids under 18 said they would be fine with adding to their card debt during the season and more than half (56%) responded that they felt it was fine to do so;
  • Genders differ. Men with credit cards are more willing to take on holiday card debt than women (50% versus 41%);
  • The right reasons? Among cardholders who are willing to take on credit card debt this holiday season, almost half (46%) said it was to please a family member or friend and a large percentage (42%) said it was to make themselves happy. Thirty-eight percent said it was to please their children and another 38% said it was to make their partners happy; and
  • The big payoff. Those surveyed shared their plans to pay off that holiday debt: More than half (57%) said they would pay more than the minimum each month, some planned to cut expenses (38%), others (21%) said they were planning to get a balance transfer card, a few (18%) said they planned to get a side gig, such as freelancing, selling on Etsy, or driving for Uber, and even fewer (16%) reported they intended to sell unneeded possessions.

The fact that more than 60% of credit card debtors are willing to go into further debt is a testament to the natural social pressure to get gifts for those you genuinely care about. The fact that 52% of millennials don’t mind going further into debt points toward not having a fundamental understanding of the consequences.

Older consumers are somewhat less likely to make these financial mistakes because they have experienced the consequences.

Men are probably more willing to go into debt over holiday spending than women because they want to feel as though they have provided for their loved ones.

Out of Network ATM Costs Reach Record High

on 4:48 PM

As reported this week in CU Times, the average out-of-network ATM withdrawal cost has reached a new record high of $4.72, according to the latest Bankrate.com Checking Account and ATM Fee Study, which surveyed non-interest and interest accounts.

This all-in fee, which includes the ATM surcharge (what ATM owners charge non-customers) as well as the penalty financial institutions charge their own customers to make out-of-network withdrawals is up 33% over the last decade.

Financial institutions are charging non-customers more than ever to use their ATMs. The average ATM surcharge increased 2% to a new record of $3.09, the 15th consecutive year establishing a new record. The average surcharge has increased in 20 of the past 21 years.

The good news, the fee charged by the accountholder’s own financial institution for using another institution’s ATM decreased 2% from $1.66 to $1.63, moving lower for the second year in a row. In fact, the number of financial institution and accounts allowing free out-of-network withdrawals is at a record high, although this still represents less than one-third of accounts (32%).

“While large banks have extensive ATM networks, many smaller banks and credit unions belong to nationwide fee-free alliances that may have significantly more ATMs available than even the ATM networks of big banks,” Greg McBride, CFA, Bankrate.com chief financial analyst said. “One other option to withdraw money for free is to get cash-back at the point of sale when using a debit card. Banks don’t charge for that and very few merchants do either.”

Among the findings:
  • Houston has the highest average out-of-network ATM fee of the 25 major metro areas examined ($5.58), while Los Angeles has the lowest ($4.15). Philadelphia has the highest average overdraft fee ($35.50) and Cincinnati has the lowest ($30.95).
  • Ninety-nine percent of non-interest checking accounts are either free by default or can become free, however less than half (42%) are free without stipulation. Forty-three percent will waive the monthly fee ($5.61, on average) based solely on direct deposit.

Push for Increased Data Security Continues

on 2:04 PM

With several high-profile data breaches hitting just in the month of August while Congress was in recess, CUNA and the state leagues are continuing their push for Capitol Hill lawmakers to enact meaningful data security legislation.

Stopping the data breaches is the subject of CUNA’s latest Member Activation Program (MAP) campaign launched in August to activate credit union members to call on their members of Congress to Act.

Specifically, CUNA and the state leagues are calling for Congress to:

  • Treat data privacy as a national security issue, as there have been more than 10,000 data breached in the U.S. since 2005, compromising nearly 12 billion consumer records. Many of these breaches are being perpetrated by foreign governments, domestic organized crime syndicates and rogue international actors using the data to fund illicit activities;
  • Fix the weak links in the system, meaning requiring all entities that hold and use consumer data be subject to strong federal data security requirements; and
  • Set a strong federal standard that preempts state laws,removing the current patchwork of various state laws, regulations and requirements that provide uneven protection and require numerous compliance resources.

CUNA has written to leadership of multiple House and Senate Committees, outlining the above principles. CUNA Chief Advocacy Officer Ryan Donovan also contacted all 535 Congressional offices in April emphasizing the economic and national security implications.

Lance Noggle, CUNA senior director of advocacy outlined why credit unions are leading the call for data security in a Credit Union Times op-ed, and has also brought the issue up with other agencies, including NCUA and the Federal Trade Commission.

The topic will be a featured discussion point with the Vermont Congressional delegation during AVCU's DC Hike-the-Hill on October 22nd

9/30 Deadline for Wendy's Data Breach Claims

on 12:54 PM

Credit unions affected by the Wendy’s data breach have until September 30th to file claims and find additional information at a website established as part of the settlement of that case.  Go to www.wendysfidatabreachsettlement.com to find the mechanism for filing claims, as well as additional information, frequently asked questions, a list of important deadlines and court documents.

Claim notices were mailed to known affected institutions but any institution who had affected cards may file a claim until September 30th. Valid claims will be paid based on the total number of cards alerted for this breach.

On February 26th the U.S. District Court for the Western District of Pennsylvania granted preliminary approval of a proposed settlement in First Choice Federal Credit Union v. The Wendy's Company, a data breach lawsuit brought by CUNA, leagues and credit unions affected by the 2016 breach.

A final approval hearing will take place November 6th.

Under the terms of the settlement:
  • Wendy's will pay $50m into a fund to compensate financial institutions that issued payment cards that were alerted on cards in connection with the data breach;
  • Wendy’s will adopt and/or maintain certain data security measures; and
  • Financial institutions will be able to file claims for reimbursement without requiring supporting documentation.

Study: Plastic Cards - Dirtiest Items People Carry

on 2:50 PM

According to a recent study by LendEDU.com, a finance website, plastic cards finish first in the race to be the dirtiest item carried around by most people.

LendEDU tested various items for their germ scores and found credit and debit cards to be near the top of the list — not as dirty as New York City park benches and rental-bike handles, for example, but more so than a urinal handle at Penn Station and more than the city's subway poles.

The 41 payment cards tested by the website had an average germ score of 285, compared with 160 for various dollar bills and 136 for coins. Lower scores indicate less bacteria, with germ scores of 10 or below recommended for restaurant surfaces. LendEDU conducted the study in early May using Hygiena's SystemSure Plus Handheld testing device.

The Penn Station urinal had a score of 163.

"When you think about all the places your cash has been and how many times it has changed hands, you realize that bills become germ-transporting vessels," noted the study's author, Michael Brown. So too for payment cards, which are "getting swiped or inserted, changing hands or sitting on bar tops," he said. Brown thinks higher germ readings for payment cards over cash us surprising.

"One might expect cash to be the filthiest since cash stays in circulation a lot longer and can travel across the country by changing hands," he wrote in the report. However, debit and credit cards are being used more often and in an increasing number of places.

The report offered several sanitizing suggestions, from wiping cards periodically to washing your hands frequently before and after use.Despite the advent of debit and credit cards and various types of electronic payments, cash remains the most frequently used payment form, according to a Federal Reserve study, with the number of bills in circulation rising for 17 straight years.

One interesting recent development, according to the Fed study, is that there are now more $100 bills out there than any other denomination, as they have emerged as a favored way to store wealth and aren't exchanged as often as many other bill types.

This supports a finding that $100 bills are the cleanest U.S. currency type examined by LendEDU, with $5 bills the dirtiest, followed by $10 and $20 bills.