Are Contactless Cards Cloneable?

Payment Facilitator, contactless card security

Close-up hand asia woman people work in small sme coffee cafe shop store owner use cashless wifi qr code nfc scan app smart pos reader sale in take out food drink order in urban city life contactless.

Contactless card security has become an increasingly important concern as tap-to-pay adoption grows around the world. While contactless cards offer consumers faster and more convenient transactions, older implementations can create opportunities for criminals to capture payment credentials and potentially clone cards for fraudulent use.

Financial institutions and payment processors can reduce contactless card fraud by adopting stronger security standards and identifying suspicious transaction patterns that may indicate cloning. As contactless and NFC-based mobile payments continue to expand, technologies such as tokenization can provide another important layer of protection by reducing the exposure of reusable payment credentials.

Contactless are not norm here in the U.S., but stealing the information from these cards presents a real and present danger to many consumers in in those regions where their use is commonplace. The article provides both the how the crime is committed, as well as how consumers can best make it more difficult to have their payment method ‘cloned’.

At present customers need to insist that banks provide them with safe contactless cards that conform to up-to-date international security standards. Secure contactless card implementations do exist, but many banks are currently not making use of these methods. While the legacy modes are sometimes required for successful transactions, there exist secure implementations of these modes that are not easily cloneable.

Furthermore, payment processors can update their systems to detect cloned cards and block them. Any cloning method will cause a detectable change in the payment details due to the sequential nature of payments. A break in the sequence is an indication that card cloning may have occurred.

While not as much a problem in the U.S., the technology being utilized is indeed similar to that of NFC transactions via mobile devices. The expanding use of tokenization in electronic payments methodologies will help to alleviate a significant number of payment credential cloning.

The growth of contactless payments makes protecting payment credentials increasingly important for issuers, processors, merchants, and consumers. Banks can strengthen contactless card security by moving away from vulnerable legacy implementations, while processors can use transaction data to detect irregularities associated with cloned cards.

Tokenization can further reduce these risks as electronic and mobile payments evolve. By replacing sensitive payment credentials with values that have limited usefulness if compromised, tokenization can make it substantially more difficult for criminals to successfully reuse stolen payment information.

Overview by Joseph Walent, Senior Analyst, Emerging Technologies at Mercator Advisory Group

Read the full story here

Exit mobile version