ATM skimming remained a significant threat to financial institutions even as markets around the world adopted EMV chip technology. Although EMV was designed to provide stronger protection against counterfeit card fraud, the continued presence of magnetic stripes created opportunities for criminals to capture card data and exploit it in markets where mag-stripe transactions were still accepted.
The experience in Europe demonstrated why financial institutions could not rely on EMV adoption alone for ATM fraud prevention. Skimming attacks continued even in countries that had largely completed their EMV migrations, highlighting the need for banks and ATM operators to maintain layered security measures as payment technology evolved.
ATM skimming is a growing global problem, despite steps taken in Europe and other markets to curb attacks on credit and debit cards.
A new report from the European ATM Security Team shows fraud trends have continued to climb, and so have losses. For the first six months of 2011, financial losses linked to ATM skimming were reported by 64 countries, the majority of which fall outside the Single Euro Payments Area, better known as SEPA, where migrations to the Europay, MasterCard, Visa standard are, for the most part, complete.But skimming attacks remain a problem even in SEPA. In fact, attacks on ATMs were reported by all but two of the countries included in the EAST report. Seven of the 64 identified upticks in skimming, while only four experienced decreases.
So, even though SEPA countries have shifted from the magnetic stripe to the more secure chip technology, they continue to see losses. They also say they’ve found the brazenness of criminals to be escalating. Most countries included in EAST’s report said skimming devices were being left on ATMs for longer stretches of time – in some cases, for as long as a week.
EAST did not elaborate on why fraudsters felt more confident. But I suspect part of the reason is because of migrations to EMV. Now that those countries have moved away from the legacy mag-stripe (which, incidentally, continues to reign in the U.S.), they’ve acquired false senses of security.
While EMV chip technology is more secure, it remains vulnerable. Why? Because until every global market completes a migration to some form of EMV-compliant technology, mag-stripes will remain. And as long as mag-stripes exist on cards (even chip cards) in formats that can be read, they will be skimmed.
As is often the case, enterprising fraudsters find ways to follow the next opportunity. And with the adoption of EMV occurring in phased rollouts in various markets, there can be confusion by users, and opportunities for those with nefarious intentions.
This should be a warning to those FIs in the United States awaiting EMV adoption that they should not be lulled into a false sense of security. They should be wary and not let their guard down. They should ensure that anti-skimming security measures are in place at all ATMs, including EMV-enabled machines.
The persistence of ATM skimming in markets that had already migrated to EMV offered an important lesson for U.S. financial institutions. Chip technology could make card transactions more secure, but it did not eliminate every vulnerability associated with ATMs or the cards consumers used at them.
As long as magnetic stripes remained available for compatibility with markets and terminals that had not completed the EMV transition, criminals had an incentive to continue targeting card data. Fraudsters could capture information in one location and potentially exploit it elsewhere, making ATM skimming a challenge that extended beyond individual institutions or national borders.
For banks and credit unions, the response therefore needed to extend beyond simply installing EMV-enabled machines. Anti-skimming technology, regular ATM inspections, transaction monitoring, physical security, and awareness of changing fraud tactics remained important parts of a comprehensive ATM fraud prevention strategy. Institutions also needed to recognize that criminals would continue adjusting their methods as security technology improved.
The broader takeaway is that no single technology should create a false sense of security. EMV represented a major advancement in card protection, but effective ATM security required multiple layers of defense. Financial institutions that continued investing in anti-skimming measures alongside EMV adoption would be better positioned to protect cardholders, reduce fraud losses, and respond as criminals shifted their attacks toward remaining weaknesses in the payments ecosystem.
Read full article: http://www.bankinfosecurity.com/blogs.php?postID=1226







