By Ray Birch
TAMPA, Fla.—It’s time for credit unions to begin declining more fallback transactions in order to reduce growing fraud exposure, according to CSCU.
The increasing number of fraudulent fallback transactions, along with decline in the number of legitimate fallback transactions due to improvements in POS chip card capabilities, have combined to demand credit unions now pay more attention to this crime, said Dave Chojnacki, senior portfolio consultant with the company.
“Fallback fraud has reached the point where it is better that the credit union protect itself to keep losses to a minimum,” said Chojnacki.
Chip card fallback fraud occurs when crooks place a phony chip on a counterfeit card armed with phony mag stripe data. When the phony card is inserted into a POS terminal, the fake chip tells the reader the card is damaged and to fall back to use the mag stripe, which contains compromised card data. The fraud liability falls on the issuer. CUToday.info has reported extensively on the issue.
“Sure, some members will be inconvenienced. But those credit unions not declining fallback due to concerns over member reaction need to reconsider their position,” said Chojnacki.
Counter To Popular Position
That thinking, acknowledged Chojnacki, runs counter to the popular position held when the migration to EMV began in October of 2015. Chojnack noted that CSCU initially recommended that CUs not decline fallback transactions for the first one to two years of the migration—the reason being that many chip POS terminals were not configured properly, leading to legitimate fallback. Moreover, consumers were not yet comfortable with chip cards and did not need another pain point.
“The EMV liability shift went into effect in October 2015, nearly two years ago. And while every issuer has a different mix of tolerance for risk balanced with ensuring cardholders are never declined for reasons out of their control, it seems that the point has been reached that declining fallback will accomplish more good, or at least prevent more bad, than not declining,” said Chojnacki.
Recent data breach numbers confirm his concerns. Chojnacki said that 10% of all fraudulent transactions conducted using breached data from the Chipotle hack were due to fallback transactions, 25% of breached data being used from the Arby’s breach have come from fallback.
Chojnacki said that CSCU recently asked a number of its credit unions for their position on fallback transactions.
“There seems to be about a 50-50 split,” said Chojnacki. “One group says that declining fallback transactions is inconvenient for members, but they have to protect themselves. So they are declining more fallback transactions, and they have been getting some complaints. But they have been communicating with their cardholders to explain what has been going on.”
Still, there is a group of credit unions that feel the impact on the membership from declining fallback transactions is too great, said Chojnacki.
“They say that their members expect their cards to work all the time and the credit union should have solutions in place to protect them. Therefore, are electing to let things go as is and not decline fallback transactions,” said Chojnacki.
Chojnacki believes that eventually credit unions should move to decline all fallback transactions, but can get to that point gradually.
“Start declining where you see it happening more often and keep your finger on the pulse of this,” said Chojnacki, noting that Walmart stores remain the biggest target for crooks. “You can then expand it where you see it happening, either by specific store or by type of store.”
Fraudsters Find Weak Spots
But Chojnacki emphasized that as more issuers start declining fallback transactions at more merchants that fraudsters will continue to find merchants to exploit.
“The fraudsters always find a way to get through, so they will find the weak spots,” he said.
As CUs begin to deny more fallback transactions, they must effectively and communicate with members on an ongoing basis, said Chojnacki.
“Reach out to members and tell them there will be a change in how their card works. Explain to them so they understand that if they dip their chip and the machine calls for a swipe that their card won’t work. Let them know, however, that does not mean their card is bad and that they can still use it. Also let them know why this is happening and that you are taking these steps to prevent members from being victimized by fallback fraud.”
