Top and bottom

Greyscale backing image

I just applied for yet another credit card, this time because I fancied a contactless Amex ExpressPay card to play with (I already have contactless Visa PayWave and contactless MC PayPass cards). When I read this…

MBNA today announced that the first American Express-branded, contactless credit cards in the UK will be issued for use by MBNA’s customers.

[From MBNA introduces contactless Amex card in UK]

…naturally I couldn’t resist applying. The online process was pretty painless, I have to say, and my card is apparently going to arrive in 5-7 business days. Excellent. American Express marketing has been a bit of a theme for me recently. A few days ago the morning’s junk mail included a new special offer from American Express. Now, my British Airways American Express card is my top of wallet card, for about the first four months of the year. That’s because it gives you BA miles — which are not much of an incentive — and a free BA companion ticket — which is a great incentive — once you have spent £10,000 in a year. But you can only have one. So like, I’m sure, many other who travel on business, l spend £10,000 on the BA Amex card to get the companion ticket and then I go back to using my “Middle-Class Maestro”: the John Lewis MasterCard that I pay off in full every month. This delivers an excellent 1% cashback in the form of John Lewis vouchers that are valid in Waitrose.

Anyway, I got some junk mail from Amex which says that if I go and register my Amex card at some website and then use it in eight different stores before the end of June then… sorry, I lost interest at this point and threw it into the recycling bin. It was only when I got home in the evening after a meeting with a card marketing specialist today that I determined to retrieve it and read it. As it transpires, the offer was that if I go and register my card at a particular web site and then I use it in eight of the stores listed in the leaflet before the end of June then I get a bonus 2,400 BA miles. But surely, I thought, their computer would have noticed that I stopped using the card as soon as I had the companion ticket. If BA miles were an incentive to me, then I’d still be using it, so clearly they are not. The bottom line is that I don’t understand card marketing and have absolutely no idea what the marketing people are thinking about when they come up with their special promotions. For example…

KFC outlets have been promoting the cards, ranging in value from $10 to $500 and to be used within 12 months, as a “thoughtful gift idea for any occasion”… Preventative Health Taskforce chair Professor Rob Moodie said he was shocked when he learned about KFC’s latest marketing ploy. “It’s marketing gone berserk,” he said.

[From Fury over $500 KFC gift cards as nation battles obesity crisis | News.com.au]

Personally, I think that marketing may well have started off beserk, but I get his point.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

Contactless in chaos

Greyscale backing image

When I was in Singapore a few days ago I went to Starbucks in the conference centre where the Cards Asia and NFC World Asia events were being held, accompanied by senior executive from major international financial services organisation (SEXMIF) to get a coffee. When we got there, I noticed a contactless terminal, proudly advertising that it preferred Citibank cards. We ordered a couple of coffees and the delightful young clerk smiled and cheerfully asked for $8.40 or whatever it was. After a theatrical flourish of my splendid contactless Visa card I triumphantly tapped it against the reader. Nothing. I tapped it again. Nothing. I told the attendant that I wanted to pay with contactless. Ah, he pointed out, you can’t because it’s not a Citibank card. I politely explained that it was a Visa card, and there was a Visa logo prominently displayed on the reader. He went off to get his supervisor.

IMG_0266

The super appeared to see the problem. Ah, he pointed out, the terminal isn’t ready. He proceeded to re-key the transaction into another POS terminal (they had three: two for cards, as far as I could see, and one for NETS, the domestic contactless purse.)

IMG_0269

Nothing. The terminal still didn’t display the invitation to tap and go, although the blue light was on. He told me to tap the card. I told him that it would be pointless, because the terminal wasn’t in the correct state. He insisted. I tapped. Nothing happened. SEXMIF, who was videoing all of this on his phone, presumably so that he could show his management the future of consumer payments, was having trouble keeping the camera still while laughing at me.

We cancelled the transaction out and tried again. It still didn’t work. I rummaged for my trusty Travelex pre-paid MasterCard and paid by swipe. Remember, I do this so you don’t have to.

Not only was using contactless not quicker than paying with cash, it was not quicker than paying with a cheque. Nor, for the matter, was it quicker than walking across the mall to an ATM, drawing out the cash, walking back and paying with a S$50 bill and getting the change in 5-cent coins. What a joke. It’s almost as if a double-agent from the cash-in-transit (CIT) industry has gone under deep cover and is now working for the banks, sabotaging the deployment of contactless from the very heart of the industry. After all, what consumer is going to try tapping their phone on this terminal after they’ve had these experiences with contactless cards?

The next day, on my own, and refusing to accept that contactless deployment had been damaged beyond repair by the combined actions of the acquirers and merchants, I went into another Starbucks to try again. I asked for a Latte (with an extra shot this time) and then asked if I could pay by contactless. The guy told me I needed a “white card” (I think this is what he said). I wasn’t sure what he meant, so I confidently pointed to the Visa logo on my UK Barclays debit card and, expressing full confidence in the global brand promise that has made Visa what it is today, I prepared to tap. He rekeyed the transaction, and, ta da!, the terminal lit up. I tapped! The light went amber, then green! He handed me a receipt that confirmed an offline EMV no-CVM debit transaction, and I wheeled away in triumph.

IMG_0268

But the clerk called me back. He told me that they have to swipe the card, even when the customer has paid by contactless. I was incredulous. But he was insistent. I asked him why. He said that they had to. I told him I was sure that wasn’t the case, but he insisted, and by now my use of contactless had caused a queue to build up. I didn’t want to embarrass him — it’s not his fault — but I was really curious what they needed the swipe for. So I handed over my Travelex MasterCard, and he swiped that. It charged me for the coffee again. I looked at both receipts, astonished. Then I gave him back the Travelex card and had him unwind the transaction, then gave him my debit card and he swiped that, for a reason that wasn’t clear to me. When I got home, I logged in to both accounts to see what had transpired. Nothing had been posted to the Barclays account three days after this, and when I tried to log in to Travelex it said “site down for maintenance”. Oh well.

For reference, this is what should happen in the retail environment if a retailer wants to cut cash handling, speed up serving times and increase the average spend: I ask for a coffee, the guy rings up S$6.40 and the terminal lights up, clearly displaying “6.40” and then I tap it with my card/phone and the light goes green and that’s it done. End of transaction.

In all conscience

Greyscale backing image

I’m giving a keynote at the Smart Card Alliance conference in Chicago in a couple of weeks. It’s going to be about EMV in the USA. I’ve just been mulling it over, and once again looked at Deborah Baxley’s neat summary of the immediate future for the US cards business:

Banks scrambling to replace lost fee revenue will likely shift focus to credit and prepaid, impose DDA and other fees, along with new account services and comprehensive pricing packages.

[From Changing the Game in Cards – pymnts.com]

It’s not just banks who have to rethink their strategies because of developments in the payment sector. I note that in the UK, according to the Centre for Economics & Business Research reported in Fraud Watch 6(18), nearly 100,000 people were victims of direct debt fraud last year, a direct consequence of the use of chip and PIN at retail POS. As card fraud has become more difficult, the criminals have shifted their focus. Direct debit fraud was one basis point of identity fraud cases a decade ago, now it is a tenth of all cases. Criminals have to adapt to chip and PIN just as banks and merchants do.

A GROUP of seven postmen intercepted letters containing credit cards, switched the microchips of the cards with fake ones and then delivered them to the applicants… the syndicate also had the help of a National Registration Department (NRD) officer who supplied them with the names of the mothers of the real credit card applicants

[From 7 M’sian postmen nabbed for credit card fraud]

It’s interesting to think like a criminal. Well, sometimes. In Chicago, two men were shot by guards while trying to rob a cash transit.

The dead suspect was identified as Jimmy Townsend, 52… a convicted felon and was sentenced to 10 years in prison for two separate armed robbery convictions.

[From 2 suspects shot, one fatally, in armored truck heist – Chicago Breaking News]

Armed robbery is a bizarre crime. I think I’m right in saying that in the UK the average sentence is longer than that for murder. In the US, Mr. Townsend spent years in jail for it, and then got killed doing it again. How dumb did he have to be go back to trying to rob armoured cars. If only he read the Digital Money Blog, he would have known that there are much easier targets.

The heavily-armed gang made off with the tournament jackpot of 242,000 euros ($327,000; £217,000) in early March. Police said a 28-year-old Lebanese man, the fourth arrested in connection with the raid, had been detained on Sunday.

[From BBC News – German police arrest poker tournament heist suspect]

OK, so not all of them got away, but casinos are not a bad idea for enterprising criminals. They do have lots of cash, and often the people in them will not report cash as stolen.

Masked men have stormed a packed casino near the Swiss border city of Basel, making off with hundreds of thousands of francs, prosecutors say.

About 10 raiders pulled up at the Grand Casino in two cars just after 0400 (0200 GMT) and smashed their way in, brandishing machine-guns and pistols. The French-speaking gang ordered the 600 guests and employees to the floor while they emptied registers.

[From BBC News – Switzerland casino is robbed by armed gang]

Criminals follow the path of least resistance. I hope Bankerstuff don’t mind me quoting from a marketing e-mail they sent me concerning a forthcoming webinar.

A Former Bank Robber Shares Security Insights During Live Webinar on April 28 from 2:00 – 3:00pm Eastern

Troy Evans pursued a career as a self-employed addict, drug dealer, gambler and thief for more than 15 years. Ultimately, his disregard of values and discipline resulted in a 13 year federal prison sentence. Facing the obstacles, pressures and violence of prison life, he was determined that his time behind bars would not be wasted… Having met and interviewed over 300 bank and credit union robbers he is able to give us a “look into the mind of the enemy”. Troy answers questions such as… What can financial institutions do to deter a desperate criminal?

I would have thought than an obvious idea would be to not have any cash since, as another bank robber famously remarked, he went “where the money is”? When it comes to card payments, the money is in getting hold of card details and (because of the switch to chip and PIN) PINs. Here, the criminals soon adapted their strategies to deal with the new instruments.

Victorian Police believe international crime syndicates are bribing shop workers in return for access to EFTPOS terminals as part of an elaborate scam. They believe criminals have stolen as much as $80 million from Australian bank accounts over the past year…

The syndicates install cameras in ceilings to film people entering their identification numbers.

[From EFTPOS scam costs Australians $80m – ABC News (Australian Broadcasting Corporation)]

They’re using these PINs (since they can’t make counterfeit chip and PIN cards) with the card details to withdraw cash from ATMs. Once all of the cards and ATMs are chip-only, this avenue will be closed to them. Thus while chip and PIN isn’t perfect, it’s good enough to push criminals into other channels. So: a thought experiment…

Suppose we improve the security of payment systems to the point where they cannot, effectively, be broken. Theft, fraud and hacking are not possible. Where would criminals go next? I think they’re spoilt for choice, so relatively small improvements in payment security would send them off to pasture news.

The poll of 533 firms shows that 55% experienced fraud in the last 12 months, with 61% of these hit more than once, a similar picture to the previous year. In total, 75% of the businesses participating in the study experienced online account takeover and/or online fraud.

[From Finextra: Account takeover fraud plaguing US small businesses]

SME account takeover seems much easier than armed robbery and much more profitable. The so-called man-in-the-middle attacks on OTP systems for remote access to baking accounts are an established attack vector.

According to BillingScore, 19.4% of the value of all transactions in the U.K. premium rate sector are fraudulent, or roughly £1 on every £5 spent. “With the premium rate sector in the U.K. mobile industry currently worth in the region of £700 million, this equates to £135.8 million per year being lost to fraud in the U.K. alone,” the company said.

[From UK mobile operators ‘hide’ £136m annual fraud loss]

A fifth? As opposed to a few bp in cards? I predict that any forward-looking criminal in this scenario will be eyeing up the telecommunications opportunities. So let’s look at what some forward-looking criminals are doing. I think criminals in eastern Europe are a useful barometer, because they tend to be well-educated and computer-savvy. And they get arrested for time to time so we can see what they get up to. Here’s the stash of Romanian hackers arrested last year. You will, of course, note that it does not include low maximum balance prepaid cards or accounts.

77,350 euros, 49,000 U.S. dollars, 64,860 pounds, 60,645 lei, a luxury watch, a rifle, three pistols and 150 grams of gold. 70 laptops, 165 mobile phones, 35 desktop computers, 15 modems, new servers, 10 blank cards, 2425 SIM cards…

[From CyberCrime & Doing Time: Nicolae Popescu, Romanian hacker, at large!]

So not only the usual euros and dollars, but also gold (clearly the hackers were diversifying) and also two-and-a-half thousand SIM cards. Two-and-a-half thousand! Here are people taking the messages of convergence, future-proofing and cloud payments quite seriously. As Eric Schmidt said when still with Google, if you don’t have a mobile strategy then you don’t have a strategy. Now, if you’re like me, you will wonder what on Earth they are going to do with these SIMs. Then I remembered something that I’d read a while ago.

Only days after almost two million Bulgarians registered their SIM cards, the Interior Ministry warns that new forms of abuse are appearing. According to the ministry, two cases had recently been uncovered in which telephone fraudsters had allegedly offered 50 leva to Romas for registered SIM cards, Bulgarian daily Standard reported… the Interior Ministry as saying that it expected a flood of SIM cards, registered to Romas and homeless people, to appear on the market in the coming weeks.

[From Interior Ministry warns of trade in registered pre-paid SIM cards – Bulgaria – The Sofia Echo]

Mystery solved. The answer to why there should be a significant value attached to SIM cards that you can buy for virtually nothing in any shop is, naturally, government policy. After pocketing their windfalls from selling their SIM cards, the homeless and Roma presumably went off to celebrate their good fortune, whereas the criminals went off to figure out how to create a mass supply instead of having to negotiate with individuals.

…only four months into 2010, and organised crime groups already have found ways of beating the system. In fact, there are unsuspecting people right now who are completely unaware that their mobile phones, or names and registration, are being used for serious criminal activities… Radio host Borislav Borissov found out that he was the “proud owner” of about 200 different SIM cards, all registered to his name and personal social security number.

[From Bulgarian criminals ‘beating the system’ of pre-paid SIM card registration – Bulgaria – The Sofia Echo]

I know where I’d invest my criminal dollars! Mobile is the future! No, of course, I’m just joking to make a point. If I really was going to invest dollars in a criminal enterprise, it would be in Somali pirates, except for one sticking point. I’m afraid my strict ethical position will not allow me to deal with these people.

The al Shabaab group, which professes loyalty to al Qaeda, said mobile money transfers (MMT) helped feed Western capitalism and were turning Somalia’s Muslims against Islamic banking practices.

[From Somalia’s al Shabaab bans mobile money transfers | Top News | Reuters]

I cannot do sufficient violence to my conscience to support a group who are against mobile payments.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.